Written by: Tasawar Ulhaq, Director
Reviewed by: Saracens Solicitors UAE Team
Buying or selling a DFSA- or FSRA-regulated financial business in the UAE involves a layer of process that a standard corporate acquisition does not: change-in-control approval from the relevant regulator, deep regulatory due diligence into the target’s historic compliance record, and deal documentation structured around conditions precedent that a normal M&A timetable does not usually need to accommodate. Deals that treat this as a standard share purchase, with regulatory approval bolted on as an afterthought, are the ones that run into delay or, in the worst cases, collapse late in the process.
Change-in-Control Approval: The First Gate
Both the DFSA and FSRA require prior regulatory approval before a person acquires “control” of a regulated entity, a threshold typically triggered well below full ownership, often starting around 10% of shares or voting rights, and certainly triggered by any acquisition giving the buyer the ability to direct the target’s management. This means the transaction cannot simply complete on signature of a share purchase agreement; completion needs to be conditional on the regulator’s approval of the new controller, which involves its own application, background checks on the buyer (and often its ultimate beneficial owners), and an assessment of the buyer’s fitness and propriety to control a regulated entity.
Timing the Deal Around Approval
Change-in-control approval timelines vary depending on the complexity of the buyer’s own structure and the completeness of the application, but should be built into the deal timetable from the term sheet stage, not treated as a formality to be handled after signing. A poorly prepared application, incomplete beneficial ownership information, unexplained source-of-funds gaps, can add months to a transaction that was otherwise ready to complete.
Regulatory Due Diligence: What Buyers Need to Check
Regulatory due diligence on a DFSA- or FSRA-regulated target should go well beyond the standard corporate, financial and tax workstreams. Buyers need to review the target’s regulatory history, any past enforcement actions, breach notifications, or supervisory findings, the adequacy of its current compliance, AML and risk management framework relative to its licensed activities, and whether its licence permissions actually match what the business is doing in practice. A target operating slightly outside the scope of its existing licence is a more common finding than buyers expect, and one that needs to be resolved, or at least clearly understood and priced, before completion.
Historic Compliance Liabilities
A buyer typically inherits responsibility for a regulated target’s historic conduct once the acquisition completes, including exposure to client complaints, regulatory investigations that may not yet be public, and potential remediation costs for past compliance failures. Warranties and indemnities in the purchase agreement need to address these risks specifically, generic warranties about “compliance with applicable law” are rarely sufficient for a regulated financial business, where the specific regulatory history needs to be disclosed, investigated and, where appropriate, indemnified against.
Conditions Precedent and Deal Structuring
In addition to change-in-control approval, deals involving regulated businesses commonly include conditions precedent around retention of key licensed individuals (many DFSA and FSRA licences require named individuals in specified controlled functions, and losing them mid-transaction can jeopardise the licence itself), continuity of client contracts that may contain change-of-control provisions of their own, and, where relevant, novation or assignment of the target’s regulatory permissions. Sellers should identify these dependencies early, since some — particularly retention of key personnel, need active management well before completion, not just disclosure in a data room.
Frequently Asked Questions / Questions & Answers
Do I need regulatory approval to buy shares in a DIFC-regulated company?
Yes, if the acquisition would give you control, typically defined by reference to a shareholding or voting threshold, often around 10% or above, or the ability to direct the company’s management. Prior DFSA or FSRA approval is required before completion.
How long does change-in-control approval take in the DIFC or ADGM?
Timelines vary with the complexity of the buyer’s structure and the completeness of the application, but should be planned for well in advance and built into the transaction timetable rather than treated as a quick formality after signing.
Does a buyer inherit a regulated target’s historic compliance problems?
Generally, yes, the buyer typically takes on the regulated entity with its existing licence, regulatory history and potential liabilities intact, which is why regulatory due diligence and carefully drafted warranties and indemnities are essential before completion.
What happens if key licensed individuals leave during the sale process?
This can jeopardise the target’s licence if those individuals hold specified controlled functions required by the DFSA or FSRA. Retention arrangements for key personnel should be addressed as part of deal structuring, not left until after completion.
Can a sale of a regulated business complete before regulatory approval is granted?
No. Change-in-control approval is a condition precedent to completion for DFSA- and FSRA-regulated entities; the transaction cannot lawfully complete, in terms of the actual change of control, before the relevant approval is obtained.
