UAE · Financial Regulatory Map

Fintech regulation:
from feature to license

There is no single “fintech license” in the UAE. We analyze the product into money acceptance, account, transfer, loan, investment, custody, token and data - then we determine the regulator.

CBUAEfederal bank and payments
DFSAfinance in DIFC
FSRAfinance at ADGM
Before the coderegulatory perimeter

01

Regulator map

CBUAE

Banks, finance companies, exchange business, stored value, retail payments, payment tokens and federal financial infrastructure.

DFSA

Regulated financial services provided to or from the DIFC.

FSRA

Regulated financial services in ADGM, including applicable digital-asset activities.

SCA/VARA and others

Securities and virtual-asset perimeter outside the relevant financial zones - by product, territory and current regulations.

Territory boundary

Registration of a company in a free zone does not automatically transfer the financial license to the mainland or to another financial zone.

02

Functions first, technology second

The regulator does not look at the words “platform”, “wallet” or “marketplace”, but at the user’s rights and money. A single model may include multiple regulated features and require permits or licensed partners.

Money flow
Who accepts, stores, transfers and returns funds
Account
Who opens a payment account or maintains a balance?
Credit
Who makes the credit decision, finances and collects
Investment
Who advises, arranges, deals, manages or holds assets
Token / crypto
Token function, issuance, exchange, custody, transfer and settlement
Geography
Where is the client, entity, marketing, server, agent and actual service

03

Retail payments, wallets, acquiring and transfers

The Federal RPSCS Regulation covers, in particular, payment account issuance, payment instruments, merchant acquiring, aggregation, domestic and cross-border fund transfers, payment initiation and account information services. The exact category determines the capital and ongoing obligations.

License
Category and permitted services based on actual product flow
Funds
Safeguarding, settlement, reconciliation and prohibition of unauthorized use
AML
CDD, wire-transfer data, sanctions, monitoring and suspicious reporting
Technology
Security, access, outsourcing, incident response and business continuity
Users
Terms, disclosures, complaints, refunds and consumer protection

04

Banking, lending and stored value

Accepting deposits, providing loans, finance company activity, exchange business and stored-value products have their own modes. A partnership with a bank does not make an unregulated company a bank: the roles, branding, customer contract, risk and balance sheet must be separated.

Deposit-taking
Banking function; You cannot disguise the payment balance as a deposit
Lending
Source of funds, underwriting, pricing, collections and consumer rules
Stored value
Issuance, reserve/safeguarding and redemption under a special regime
Bank-as-a-Service
The responsibility of a licensed bank and fintech is distributed by agreement and regulatory approval

05

DIFC and DFSA

A DIFC company that provides financial services in or from the DIFC is authorized by the DFSA and receives a Financial Services Permission with specific activities and conditions. The Registrar of Companies commercial license does not replace DFSA authorization.

Perimeter
Dealing, arranging, advising, managing, custody, funds, credit and other activities
Category
Defines prudential capital and personnel requirements
People
Board, senior executive, compliance, MLRO, finance and risk functions
Documents
Regulatory business plan, financial projections, manuals, systems and outsourcing
Market
Restrictions on client type, product and geography are reflected in permission

06

ADGM and FSRA

In ADGM, a person receives a Financial Services Permission for certain Regulated Activities. Before submission, designs the legal entity, controllers, governance, capital, systems and operating model; The digital asset framework only applies to functions within its perimeter.

FSRA
Authorization and supervision of Regulated Activities
RA
Registration of a legal entity and commercial license
Sequence
Regulatory dialogue and incorporation are coordinated
Substance
Responsible persons, management, systems and records must be real in ADGM

07

Virtual assets and payment tokens

The regulator is determined by the asset function and territory. Payment token may fall into the federal CBUAE regime; virtual-asset activities in Dubai outside DIFC may be subject to VARA; ADGM operates under the FSRA framework. Securities-like product additionally requires investment perimeter analysis.

Issuance
Who issues, promises redemption and holds reserve
Exchange / brokerage
Who performs, mixes or routes orders
Custody
Who controls private keys and is responsible for return
Payments
Is it possible to use an asset as a means of payment and where?
Marketing
To whom and from what territory is the product offered?
Do not mix

“Cryptolicense” does not mean automatic permission for fiat payments, deposit-taking, securities or banking services.

08

What does the licensed project contain?

Business

Products, customers, countries, distribution, revenue and three-year projections.

Governance

Controllers, board, senior management, compliance, risk and internal audit.

Controls

AML, sanctions, safeguarding, conduct, complaints and regulatory reporting.

Technology

Architecture, cybersecurity, outsourcing, cloud, data, BCP/DR and audit trail.

09

Ongoing compliance

The license specifies a permanent operating standard. Significant changes to product, controllers, key persons, outsourcing or geography may require prior approval.

Prudential
Capital, liquidity, safeguarding and regulatory returns
Conduct
Client classification, disclosures, suitability, complaints and conflicts
Financial crime
Risk assessment, CDD/EDD, sanctions, TM, STR and independent testing
Technology
Incidents, penetration tests, access, change management and vendors
Governance
Board information, compliance monitoring and remediation

10

Launch route

  1. 01

    Draw a complete customer journey and money/data flow.

  2. 02

    Qualify each function and territory.

  3. 03

    Select CBUAE, DIFC/DFSA, ADGM/FSRA or other applicable circuit.

  4. 04

    Define your own license, affiliate model, and prohibited features.

  5. 05

    Prepare governance, capital, manuals, systems and evidence before submission.

Regulatory framework

Official rules for each circuit

The perimeter is confirmed before product development and again before any significant change.

01

CBUAE — Licensing

The official licensing outline and register of banks, finance companies, exchange businesses, PSP and other organizations.

Open official source
02

CBUAE — Retail Payment Services and Card Schemes Regulation

Categories payment services, licensing, capital, safeguarding, AML and ongoing requirements.

Open official source
03

CBUAE — Payment Token Services Regulation

Federal mode of payment tokens, issuers, conversion, custody/transfer and related registrations.

Open official source
04

DFSA — Doing Business with the DFSA

Official entry into the financial activity authorization process in the DIFC.

Open official source
05

ADGM FSRA — Application for Financial Services Permission

The official form and information base for regulated activities in ADGM.

Open official source

Regulatory perimeter

Let's break down the product into licensed functions

We will prepare a legal map, structure, partnership model and authorization plan.

Discuss the fintech project
WAWhatsAppTGTelegram