M&A · UAE Market Entry

Regulated Licence Acquisition in the UAE: Buying Permission without Buying Hidden Failure

A transaction-control system for acquiring a UAE regulated platform while preserving permission scope, approvals, capital, controls and Day-One continuity.

Regulated Licence Acquisition in the UAE: Buying Permission without Buying Hidden Failure
Quick answer

Define the regulated transaction perimeter and map every governing authority; reconstruct the licence instrument, public status, permitted activities, conditions and actual revenue model; determine controller, corporate, competition and sector approval requirements; engage the regulator with a credible ownership, funding, governance and business-plan pack; assess controllers, approved individuals, supervisory history, enforcement and complaints; rebuild prudential capital, liquidity, client-asset, custody, financial-crime, conduct, governance, outsourcing, cyber, data and reporting controls; secure fees, insurance, tax, contracts, people, premises and technology; quantify remediation and licence value; align transaction protection, conditions precedent and closing; then issue an auditable licence-continuity certificate for Day One.

Abstract

Acquiring a regulated business in the United Arab Emirates can provide market access, specialist capability and an operating platform, yet the buyer does not acquire an unrestricted permission detached from the target's conduct and controls. A licence is issued by a particular authority to a particular legal person for defined activities, products, customers and conditions.

Ownership changes may require prior approval or notification; directors and senior managers may require fitness-and-propriety assessment; material acquisitions, business transfers, outsourcing changes and licence variations may follow separate procedures. Historical breaches, remediation commitments, prudential shortfalls, client-asset weaknesses or unsupported business lines can impair continuity even when the public register shows an active licence.

This paper develops a forty-module acquisition-control system for banks, finance companies, insurers, payment firms, capital-markets businesses, virtual-asset service providers and other regulated targets in the UAE. It reflects the current federal commercial-company framework, the Central Bank's in-force merger, acquisition, significant-shareholder and fitness-and-propriety requirements, the DFSA and ADGM FSRA controller regimes, VARA's activity-specific licensing model, the federal economic-concentration regime and established international supervisory principles.

Five figures and five tables convert legal scope, approval sequencing, control health, scenario economics and Day-One continuity into transaction evidence. Numerical values are illustrative analytical scenarios. Each party should obtain current legal and regulatory advice for the target, authority, licence and transaction structure.

JEL Classification: G21, G24, G28, G34, K22

Keywords: UAE regulated licence acquisition, change of control, regulatory due diligence, licence conditions, fit and proper, prudential capital, transaction approval, Day One

This Matchpoint Insight presents the web edition of Matchpoint Partners' research. The supporting paper contains the full framework, structures, worked examples and source material.

Read the full research paper   Explore our UAE Market Entry practice

1. Define the licence-acquisition perimeter

The buyer, target and transaction advisers should identify the buyer, target, regulated entities, branches, controllers, sellers, activities, customers, jurisdictions and transaction steps. The controlled deliverable is a regulated-transaction perimeter. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [1][2].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that a share acquisition can be modelled as a transferable permission while the regulator assesses the legal person, controllers and operating reality. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

2. Map every governing authority and law

The buyer, target and transaction advisers should identify corporate, sector, financial-free-zone, competition, foreign-ownership, data, sanctions and employment decision makers. The controlled deliverable is a regulatory responsibility map. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [2][3].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that one approval can be mistaken for permission to complete every corporate and regulated step. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

3. Reconstruct the licensed activity map

The buyer, target and transaction advisers should translate each licence instrument and rulebook into permitted services, products, customer classes, channels and territorial limits. The controlled deliverable is an activity-permission matrix. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [4][5].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that commercial descriptions can extend beyond the precise regulated permissions held. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

4. Verify status against public registers

The buyer, target and transaction advisers should compare regulator, registrar and free-zone records with certificates, renewals, notices and internal regulatory correspondence. The controlled deliverable is a verified licence-status file. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [5][6].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that an active register entry can coexist with conditions, arrears, remediation or a pending restriction. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

5. Catalogue conditions and restrictions

The buyer, target and transaction advisers should record every licence condition, endorsement, limitation, waiver, undertaking, expiry, review date and regulator expectation. The controlled deliverable is a conditions register. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [6][7].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that conditions can be buried in approval letters or supervisory correspondence outside the public licence. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

6. Test the operating model against permissions

The buyer, target and transaction advisers should map actual revenue, contracts, marketing, onboarding, booking, custody, advice, arranging and distribution to authorised activities. The controlled deliverable is a permission-to-revenue bridge. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [7][8].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that historic revenue can depend on activities the target was never authorised to conduct. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

7. Determine controller approval requirements

The buyer, target and transaction advisers should identify direct and indirect controllers, threshold crossings, increases, decreases, branch notifications and prior-approval triggers. The controlled deliverable is a controller approval analysis. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [9][10].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that completion can occur before a mandatory regulator approval or notification is effective. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

8. Sequence early regulator engagement

The buyer, target and transaction advisers should prepare the transaction rationale, proposed controllers, funding, governance, business plan and sensitive issues for confidential engagement. The controlled deliverable is a regulator engagement plan. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [10][11].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that late engagement can expose a fatal eligibility concern after diligence and financing costs are committed. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

Table 1. Regulatory perimeter and approvals

DecisionPrimary evidenceRelease gate
licence scopeinstrument and rulebookactivity match
controlownership and thresholdsprior approval
competitionmarket and nexus analysisclearance or exclusion
corporateresolutions and filingsvalid completion

Statutory periods are stated where labelled; other entries are analytical controls.

Figure 1. Licence-to-operation evidence cascade
Figure 1. Licence-to-operation evidence cascade

Illustrative analytical scenario; transaction evidence should replace model values.

9. Validate seller and corporate authority

The buyer, target and transaction advisers should confirm title, constitutional power, board and shareholder approvals, merger mechanics, creditor rights and competent-authority filings. The controlled deliverable is a corporate authority memorandum. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [2][12].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that a sector approval cannot cure defective title, authority or corporate process. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

10. Assess ownership and group transparency

The buyer, target and transaction advisers should trace natural-person ownership, control, nominees, trusts, affiliates and regulated group relationships before and after closing. The controlled deliverable is a pre-and-post control chart. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [13][14].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that opaque or complex ownership can impede supervision and controller acceptability. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

11. Assess controller fitness and financial soundness

The buyer, target and transaction advisers should test integrity, reputation, competence, financial conduct, conflicts, independence, resources and supervisory history. The controlled deliverable is a controller suitability file. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [15][16].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that an acquisition vehicle can lack transparent capital, governance or a credible long-term ownership rationale. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

12. Assess approved individuals and key functions

The buyer, target and transaction advisers should identify designated functions, authorisations, succession risk, vacancies, residency, time commitment and regulator non-objections. The controlled deliverable is a key-person continuity schedule. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [16][17].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that the licence can remain legally active while required control roles are vacant or dependent on departing sellers. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

13. Reconstruct the supervisory history

The buyer, target and transaction advisers should review inspections, thematic reviews, risk ratings, findings, attestations, commitments, waivers and closure evidence. The controlled deliverable is a supervisory history ledger. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [18][19].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that management summaries can omit unresolved repeat findings or informal regulator expectations. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

14. Investigate enforcement and complaints

The buyer, target and transaction advisers should search public action, private notices, customer complaints, ombudsman matters, litigation, whistleblowing and misconduct records. The controlled deliverable is an enforcement-and-conduct assessment. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [19][20].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that small historical events can reveal systemic control or governance failure. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

15. Recalculate prudential capital

The buyer, target and transaction advisers should rebuild eligible capital, deductions, risk exposures, buffers, concentration and post-deal headroom under the applicable rules. The controlled deliverable is a prudential capital bridge. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [21][22].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that book equity or purchase price can be confused with regulatory capital available after acquisition adjustments. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

16. Model liquidity and funding continuity

The buyer, target and transaction advisers should test liquidity resources, encumbrance, committed facilities, stress outflows, intragroup funding and change-of-control clauses. The controlled deliverable is a closing liquidity plan. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [22][23].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that funding can disappear or become ineligible when ownership changes. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

Table 2. Hidden-failure evidence architecture

DomainEvidenceFailure response
permissionrevenue-to-activity bridgestop unsupported line
prudentialcapital and liquidity rebuildfund or reprice
conductcomplaints and remediationquantify redress
operationscritical-service testssecure continuity

Statutory periods are stated where labelled; other entries are analytical controls.

Figure 2. Control-health profile
Figure 2. Control-health profile

Illustrative analytical scenario; transaction evidence should replace model values.

17. Verify client-money and client-asset controls

The buyer, target and transaction advisers should reconcile segregation, safeguarding, custody, trust status, bank accounts, daily records, breaks and insolvency protections. The controlled deliverable is a client-asset assurance file. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [24][25].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that unreconciled client balances can create restitution, capital and licence-continuity risk. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

18. Test safeguarding, custody and settlement

The buyer, target and transaction advisers should map asset ownership, sub-custodians, wallets, settlement agents, payment flows, access rights and business-continuity arrangements. The controlled deliverable is a custody-and-settlement control map. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [25][26].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that legal title and operational access can diverge during a control transition. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

19. Reperform financial-crime controls

The buyer, target and transaction advisers should test customer risk, beneficial ownership, source evidence, screening, transaction monitoring, reporting and remediation. The controlled deliverable is an AML and sanctions diligence file. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [27][28].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that a licence acquisition can import backlogs, weak risk classifications or customers outside the buyer's appetite. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

20. Test sanctions and proliferation-financing exposure

The buyer, target and transaction advisers should screen controllers, customers, counterparties, assets, vessels, geographies and payment routes against current obligations. The controlled deliverable is a sanctions exposure memorandum. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [28][29].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that indirect ownership, sectoral restrictions or transaction routes can create exposure without an exact name match. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

21. Assess conduct and customer outcomes

The buyer, target and transaction advisers should review disclosures, suitability, conflicts, fees, marketing, vulnerable customers, complaints, remediation and product governance. The controlled deliverable is a conduct-risk assessment. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [30][31].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that profitable products can contain undisclosed remediation or unsuitable-customer exposure. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

22. Evaluate governance and delegated authority

The buyer, target and transaction advisers should map boards, committees, reserved matters, policies, approvals, management information and escalation across the group. The controlled deliverable is a governance effectiveness matrix. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [16][32].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that formal committees can exist without reliable information, challenge or accountable decisions. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

23. Test compliance, risk and internal audit

The buyer, target and transaction advisers should assess independence, competence, staffing, plans, monitoring, assurance coverage, issue ageing and access to the board. The controlled deliverable is a three-lines capability review. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [17][33].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that required control functions can be under-resourced, conflicted or dependent on one person. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

24. Reassess outsourcing and cloud arrangements

The buyer, target and transaction advisers should catalogue material providers, approvals, locations, audit rights, subcontractors, exit plans, concentration and change clauses. The controlled deliverable is an outsourcing transition register. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [34][35].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that a provider consent, regulator non-objection or data-access dependency can fail at closing. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

Table 3. Approval critical path

StageControlled outputDependency
pre-signregulator engagementcredible controller pack
signingconditional transactionrisk allocation
reviewcomplete applicationtimely responses
closingeffective approvalscapital and people

Statutory periods are stated where labelled; other entries are analytical controls.

Figure 3. Approval readiness
Figure 3. Approval readiness

Illustrative analytical scenario; transaction evidence should replace model values.

25. Test cyber and operational resilience

The buyer, target and transaction advisers should review critical services, threat controls, incidents, recovery objectives, penetration testing, backups, crisis governance and third parties. The controlled deliverable is an operational-resilience readiness file. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [35][36].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that the target can meet ordinary uptime while remaining unable to recover a critical regulated service. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

26. Map data protection and residency

The buyer, target and transaction advisers should identify personal and confidential data, lawful bases, notices, transfers, localisation, retention, access and breach obligations. The controlled deliverable is a transaction data-governance plan. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [37][38].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that diligence, migration or buyer integration can create an unlawful transfer or supervisory access gap. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

27. Rebuild regulatory reporting accuracy

The buyer, target and transaction advisers should trace prudential, conduct, AML, transaction, incident and statistical returns to source systems and accountable sign-off. The controlled deliverable is a regulatory-reporting lineage map. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [18][39].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that accepted returns can contain manual overrides, classification errors or unreported resubmissions. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

28. Reconcile fees, levies and renewals

The buyer, target and transaction advisers should verify application fees, annual fees, fines, insurance, capital deposits, licence renewals and outstanding invoices. The controlled deliverable is a regulatory obligations calendar. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [5][40].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that small unpaid amounts or missed renewals can signal weak licence administration. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

29. Verify required insurance coverage

The buyer, target and transaction advisers should test professional indemnity, cyber, crime, directors' cover, run-off, exclusions, limits, deductibles and change-of-control effects. The controlled deliverable is an insurance continuity schedule. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [41][42].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that coverage can terminate, narrow or exclude known regulatory matters when control changes. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

30. Assess tax, substance and transfer pricing

The buyer, target and transaction advisers should reconcile entity residence, permanent establishment, corporate tax, VAT, substance, intercompany services and acquisition structure. The controlled deliverable is a tax-and-substance transition plan. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [43][44].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that the licensed entity can rely on group arrangements that become unsustainable or mispriced after separation. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

31. Identify contract and counterparty consents

The buyer, target and transaction advisers should review customers, banks, custodians, exchanges, insurers, vendors, landlords and distributors for regulatory and control-change rights. The controlled deliverable is a consent critical-path register. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [42][45].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that commercial continuity can fail even when the regulator approves the new controller. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

32. Secure employees, visas and control functions

The buyer, target and transaction advisers should map retention, immigration, secondments, remuneration, restrictive covenants, certification and succession for regulated roles. The controlled deliverable is a regulated-workforce plan. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [17][31].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that key permissions and controls can depend on individuals who will not transfer or remain. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

Table 4. Illustrative acquisition economics

ScenarioDelay daysRemediation indexContinuity score
clean platform101294
conditional licence353878
control-function gaps606157
permission mismatch1208921

Statutory periods are stated where labelled; other entries are analytical controls.

Figure 4. Hidden-failure value at risk
Figure 4. Hidden-failure value at risk

Illustrative analytical scenario; transaction evidence should replace model values.

33. Confirm premises, entity and free-zone requirements

The buyer, target and transaction advisers should verify legal form, registered office, physical presence, records, local staffing, branch limits and commercial-licence alignment. The controlled deliverable is an operating-footprint compliance file. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [2][6].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that a buyer can acquire a sector licence while losing the premises or entity conditions that support it. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

34. Protect technology and intellectual property

The buyer, target and transaction advisers should verify software ownership, licences, models, data rights, source-code access, security, vendor permissions and separation dependencies. The controlled deliverable is a technology entitlement map. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [35][38].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that critical systems can belong to the seller or prohibit assignment to the acquired entity. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

35. Identify related-party and conflict exposure

The buyer, target and transaction advisers should map intragroup services, financing, referrals, commissions, shared customers, directors and non-arm's-length arrangements. The controlled deliverable is a conflicts and separation register. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [30][32].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that revenue or capital can depend on related parties whose support ends at closing. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

36. Convert remediation into executable conditions

The buyer, target and transaction advisers should classify findings by legal breach, supervisory commitment, closing dependency, Day-One control and post-close action. The controlled deliverable is a remediation dependency plan. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [18][19].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that generic undertakings can defer a licence-threatening weakness without funding or accountable evidence. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

37. Value the regulated platform and hidden failure

The buyer, target and transaction advisers should separate permission scarcity, customers, people, systems and capital from remediation cost, approval risk and revenue attrition. The controlled deliverable is a probability-weighted licence value model. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [21][45].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that headline multiples can capitalise revenue that cannot continue within approved permissions. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

38. Translate diligence into transaction protection

The buyer, target and transaction advisers should draft specific warranties, disclosures, indemnities, covenants, escrow, price adjustment, termination and regulator cooperation. The controlled deliverable is an evidence-backed risk allocation schedule. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [12][41].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that broad compliance warranties can offer weak recovery for known or structurally uninsurable failure. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

39. Control signing, approval and closing

The buyer, target and transaction advisers should align regulator decisions, competition clearance, financing, consents, capital, appointments, migrations and long-stop mechanics. The controlled deliverable is a regulated closing checklist. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [3][9].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that parties can sign an executable corporate deal whose regulatory conditions cannot be satisfied in sequence. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

40. Issue the licence-continuity certificate

The buyer, target and transaction advisers should reconcile permissions, controllers, people, capital, customers, assets, systems, contracts, approvals, open issues and Day-One owners. The controlled deliverable is an auditable licence-continuity certificate. Record the applicable authority, legal source, licence instrument, evidence owner, reviewer, conclusion, approval date, unresolved dependency and refresh trigger [11][36].

Test the legal requirement against the target's actual business rather than relying on labels. Reconcile public registers, regulator correspondence, constitutional records, policies, systems, customer files, financial records, management information and independent assurance.

The principal execution risk is that boards and regulators can receive fragmented conclusions without one accountable go-live decision. Measure the effect on approval probability, regulatory capital, customer continuity, revenue quality, remediation cost, financing, closing timing, contractual protection, reputation and enterprise value.

Convert the conclusion into diligence requests, regulator submissions, valuation adjustments, transaction documents, conditions precedent, covenants, escrow or holdback, Day-One controls and post-close monitoring. Preserve a dated evidence trail and obtain specialist advice for the target's authority, licence and structure.

Table 5. Licence-continuity certificate

DomainEvidenceApproval owner
permissionscope and condition matchlegal and compliance
supervisionfindings and commitmentsboard risk committee
resourcescapital, people and systemsdeal committee
Day Onecontrols and monitoringaccountable executive

Statutory periods are stated where labelled; other entries are analytical controls.

Figure 5. Day-One continuity
Figure 5. Day-One continuity

Illustrative analytical scenario; transaction evidence should replace model values.

References

  1. CBUAE Rulebook, Article 125 Merger and Acquisition, https://rulebook.centralbank.ae/en/rulebook/article-125-merger-and-acquisition
  2. UAE Legislation, Federal Decree-Law No. 32 of 2021 on Commercial Companies, https://www.uaelegislation.gov.ae/en/legislations/1542/download
  3. UAE Legislation, Federal Decree-Law No. 36 of 2023 Regulating Competition, https://uaelegislation.gov.ae/en/legislations/2161
  4. CBUAE, Licensing, https://www.centralbank.ae/en/licensing/
  5. DFSA, Public Register, https://www.dfsa.ae/public-register
  6. ADGM FSRA, Public Register, https://www.adgm.com/public-registers/fsra
  7. DFSA, Expanding Your Business, https://www.dfsa.ae/what-we-do/authorisation-services/expanding-your-business
  8. VARA, Licensed Activities, https://www.vara.ae/en/licenses-and-register/licensed-activities/
  9. DFSA, Request for Amendment to Ownership or Control Structure, https://services.dfsa.ae/authorised-person/authorised-firm-request-for-amendment-to-ownership-or-control-structure-authorized-persons-supervise/
  10. DFSA, Frequently Asked Questions on Change in Control and Licence Variation, https://www.dfsa.ae/download_file/view/183/475
  11. Basel Committee, Core Principles for Effective Banking Supervision, https://www.bis.org/bcbs/publ/d573.htm
  12. UAE Legislation, Commercial Companies Law Part Seven, https://uaelegislation.gov.ae/en/legislations/1542
  13. UAE Legislation, Cabinet Resolution No. 109 of 2023 Regulating Real Beneficiary Procedures, https://uaelegislation.gov.ae/en/legislations/2176/download
  14. FATF, Guidance on Beneficial Ownership of Legal Persons, https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-Beneficial-Ownership-Legal-Persons.html
  15. CBUAE Rulebook, Fit and Proper Criteria, https://rulebook.centralbank.ae/en/rulebook/article-7-fit-and-proper-criteria
  16. CBUAE Rulebook, Fit and Proper Process, https://rulebook.centralbank.ae/en/rulebook/article-6-fit-and-proper-process
  17. DFSA Rulebook, General Module, https://dfsaen.thomsonreuters.com/rulebook/general-module-gen
  18. CBUAE, Supervision, https://www.centralbank.ae/en/our-operations/supervision/
  19. DFSA, Enforcement, https://www.dfsa.ae/what-we-do/enforcement
  20. CBUAE, Consumer Protection, https://www.centralbank.ae/en/consumer/
  21. Basel Committee, Basel Framework, https://www.bis.org/basel_framework/
  22. CBUAE Rulebook, Banks' Significant Shareholder Regulation, https://rulebook.centralbank.ae/en/entiresection/48
  23. Basel Committee, Principles for Sound Liquidity Risk Management, https://www.bis.org/publ/bcbs144.htm
  24. IOSCO, Objectives and Principles of Securities Regulation, https://www.iosco.org/library/pubdocs/pdf/IOSCOPD561.pdf
  25. DFSA Rulebook, Client Assets Module, https://dfsaen.thomsonreuters.com/rulebook/client-assets-module-cob
  26. VARA, Custody Services Rulebook, https://rulebooks.vara.ae/rulebook/custody-services-rulebook
  27. UAE Legislation, Federal Decree-Law No. 10 of 2025 Regarding AML, CFT and Proliferation Financing, https://www.moet.gov.ae/en/financial-crimes-legislations
  28. CBUAE, AML/CFT Supervision, https://www.centralbank.ae/en/our-operations/anti-money-laundering-aml/
  29. UAE Executive Office for Control and Non-Proliferation, Targeted Financial Sanctions, https://www.uaeiec.gov.ae/en-us/our-work/targeted-financial-sanctions/
  30. IOSCO, Principles on Client Protection and Market Conduct, https://www.iosco.org/library/pubdocs/pdf/IOSCOPD561.pdf
  31. CBUAE Rulebook, Consumer Protection Regulation and Standards, https://rulebook.centralbank.ae/en/rulebook/consumer-protection-regulation
  32. OECD, G20/OECD Principles of Corporate Governance 2023, https://www.oecd.org/corporate/principles-corporate-governance/
  33. Institute of Internal Auditors, Global Internal Audit Standards, https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/
  34. CBUAE Rulebook, Outsourcing Regulation for Banks, https://rulebook.centralbank.ae/en/rulebook/outsourcing-regulation-banks
  35. Basel Committee, Principles for Operational Resilience, https://www.bis.org/bcbs/publ/d516.htm
  36. CBUAE, Operational Risk and Resilience, https://www.centralbank.ae/en/our-operations/supervision/
  37. UAE Legislation, Federal Decree-Law No. 45 of 2021 Regarding Personal Data Protection, https://uaelegislation.gov.ae/en/legislations/1972
  38. DIFC, Data Protection Law and Regulations, https://www.difc.com/business/operating/data-protection
  39. BCBS, Principles for Effective Risk Data Aggregation and Risk Reporting, https://www.bis.org/publ/bcbs239.htm
  40. DFSA Rulebook, Fees Module, https://dfsaen.thomsonreuters.com/rulebook/fees-module-fer
  41. International Bar Association, Model Share Purchase Agreement, https://www.ibanet.org/
  42. IAIS, Insurance Core Principles, https://www.iaisweb.org/activities-topics/standard-setting/icps-and-comframe/
  43. UAE Federal Tax Authority, Corporate Tax, https://tax.gov.ae/en/taxes/corporate.tax.aspx
  44. OECD, Transfer Pricing Guidelines, https://www.oecd.org/tax/transfer-pricing/oecd-transfer-pricing-guidelines-for-multinational-enterprises-and-tax-administrations-20769717.htm
  45. World Bank, Bank Regulation and Supervision Survey, https://www.worldbank.org/en/research/brief/BRSS
Questions, answered

Regulated Licence Acquisition in the UAE: frequently asked questions

A licence generally attaches to the authorised legal person, defined activities and regulatory conditions. A share acquisition may preserve the entity, yet the ownership change, new controllers, business plan and key appointments can require approval or notification.

Review the licence instrument, conditions, endorsements, correspondence, supervisory findings, approved individuals, actual revenue activities, capital, client assets, complaints, outsourcing, reporting and remediation evidence.

Engage early enough to test controller eligibility, transaction structure, required applications and information expectations before the deal becomes dependent on an unworkable approval path.

Bridge each condition to affected revenue, cost, capital, customers and timing. Apply probability-weighted downside for restricted activities, remediation, approval delay, attrition and failure to achieve the buyer's intended operating model.

It maps each material revenue stream and customer proposition to the exact regulated activity, product, customer class, booking entity, channel and territorial permission that authorises it.

High-impact examples include unauthorised activity, unresolved supervisory findings, capital deficits, client-asset breaks, financial-crime backlogs, weak control functions, fragile outsourcing, cyber-recovery gaps and departing approved individuals.

Use specific warranties, disclosures, indemnities, conduct covenants, regulator cooperation, conditions precedent, capital and staffing requirements, remediation milestones, escrow or holdback, long-stop mechanics and termination rights.

Include licence scope and conditions, controller approvals, key individuals, capital and liquidity, customer and asset controls, systems, contracts, regulatory findings, closing evidence, Day-One owners, exceptions and monitoring dates.

This publication is general information for professional audiences. It is not investment, legal or tax advice, and it is not an offer or solicitation. Readers should verify current legal, regulatory and tax requirements with qualified advisers.

Apply this insight to a live decision

Discuss the financing, capital allocation or transaction implications with a Matchpoint partner.

WhatsApp