Dubai Financial Services Authority
You know your business. What's unclear is which DFSA category it falls into, the base capital and prudential cushion it demands, and how to clear authorisation without stalling. That's the part we own — from perimeter analysis to the licence, and the compliance that follows.
Confidential & non-binding · Same-day response in UAE hours
LICENCE CATEGORIES
The DFSA is the independent regulator of financial services in and from the DIFC — an English-language common-law jurisdiction with its own courts.
It doesn't licence by label; the activities you carry out determine which of five prudential categories you fall into, and the heavier the activity, the heavier the capital and scrutiny. Picking the right category, then evidencing the controls behind it, is where most applications succeed or fail.
Deposit-taking and dealing as principal — the full banking permission.
Dealing in investments as principal, including matched-principal dealing, market-making and underwriting.
Executing and arranging deals on behalf of clients.
Providing custody for, or acting as trustee of, a fund.
Managing assets, collective investment funds, custody (non-fund) and PSIAs.
Payment services and stored value — capital scales with transaction volume.
Advising on investments, arranging deals and marketing funds — no client money held.
An institution running its entire business under Sharia — with Sharia governance layered on top of the underlying category.
MARKET
The DIFC is a top-global financial centre and the region's deepest pool of regulated capital — home to hundreds of asset managers, hedge funds and family offices, and every category of global bank. A DFSA licence puts you inside an English-language common-law jurisdiction with its own courts, and in January 2026 the DFSA modernised its crypto-token regime to a firm-led suitability model.
WHY DIFC
The UAE offers more than one regulator, and the right choice depends on who you serve. VARA suits crypto-native operators onshore in Dubai; ADGM's FSRA mirrors DIFC in Abu Dhabi. But if your clients are institutions, funds and banks, the DFSA's common-law framework carries the most weight. Here's how it sits against the alternatives.
CAPITAL
The DFSA sets capital as the highest of your category's base capital, a risk-based requirement, and — where you hold client assets — an Expenditure-Based Capital Minimum. Since the 2025 prudential reforms, most Category 3 and 4 firms that don't hold client assets simply hold liquid assets equal to their base capital instead. It's a runway question, not just a filing one. Select a category to see the layers.
*Base capital figures reflect the DFSA's published PIB Module and should be reconfirmed against the current Rulebook for your exact category.
PROCESS
DFSA authorisation runs in two stages: you earn an In-Principle Approval before you build and deposit capital, then satisfy the conditions to get the final licence — so problems surface early, not after you've committed.
We confirm your activities fall within the DFSA's remit and map them to the correct prudential category before a dirham is spent.
Submit the Regulatory Business Plan, financial projections, AML/CFT and risk frameworks, and personal questionnaires for Controllers.
The DFSA reviews the file, holds meetings, and issues an IPA setting the conditions you must satisfy. No financial services yet.
Incorporate in the DIFC, secure a physical office, put systems and controls in place, make key hires and deposit the required paid-up capital.
The DFSA confirms your Authorised Individuals, controls and capital are genuinely in place and every IPA condition has been met.
Final Authorisation is issued for your category and permitted activities — and your live supervisory obligations begin.
You're authorised to operate — live supervisory obligations begin from day one.
The four things the DFSA pushes back on most — and the four we harden before you file.
Boards and Authorised Individuals without genuine financial-services track record.
Evidence that doesn't cleanly meet base capital, the risk-based figure and liquidity together.
Off-the-shelf policies not tailored to your specific category and risk profile.
Infrastructure and controls below the DFSA's technology and resilience expectations.
REQUIREMENTS
The category sets your capital. But authorisation turns on a wider set of requirements — the ones applicants most often underestimate. Here's the full checklist, in the DFSA's own terms.
A company incorporated in the DIFC (or, in limited cases, a registered branch). Financial services must be carried on in or from the Centre — crypto-token activity in particular requires DIFC incorporation.
The base capital for your category, and capital equal to the higher of base, risk-based and — where you hold client assets — an Expenditure-Based Capital Minimum. Firms not holding client assets hold liquid assets equal to their base capital.
Approved role holders — a Senior Executive Officer resident in the UAE plus Finance Officer, Compliance Officer and MLRO. Given the DFSA's technology focus, a CISO is expected for tech-intensive firms.
Genuine local substance is expected: a real DIFC office, secured as part of satisfying your In-Principle Approval conditions — not a flexi-desk afterthought.
Controllers, directors and Authorised Individuals must pass the DFSA's fit-and-proper assessment — competence, experience, financial soundness and integrity. The DFSA screens the people, not just the paperwork.
An adequate governance framework, clear division of responsibility, conflicts-of-interest management and internal controls proportionate to your scale and complexity — evidenced, not asserted.
Compliance with the DFSA's AML Module and Conduct of Business rules: AML/CFT procedures, sanctions screening, client-money and client-asset protection, and — for crypto — documented token-suitability assessments.
The DFSA expects technology risk, resilience and cyber controls proportionate to your business — penetration testing, business continuity and incident-response — with professional indemnity and other insurance on top.
DIFFERENCE
Getting the licence is one thing. Staying licensed — with compliance that holds up to supervision and security that holds up to attack — is another. We're the only Dubai advisor that carries all three in-house, so nothing gets handed off and dropped.
We don't coach from the sidelines. We run the whole file — perimeter analysis, entity, capital structuring, the full Regulatory Business Plan and every round of DFSA questions — through to authorisation.
AML/KYT screening, transaction monitoring and regulatory reporting on our own platform — so the controls you're approved on are the controls you actually run, not a slide deck.
The DFSA holds technology and cyber resilience to a high bar. Our sister firm ITSEC delivers the penetration testing, cyber controls and audit evidence in-house — a capability no other licensing advisor has.
Three disciplines competitors outsource to three vendors. With KOLL Group it's one engagement, one accountable team — advisory, RegTech and cybersecurity under one roof.
HOW WE HELP
We map your activities to the correct DFSA category and confirm what is — and isn't — in scope before you commit capital or time.
We prepare the Regulatory Business Plan, AML/CFT policy pack and Authorised Individual documentation, defend it through review — then keep you compliant after authorisation: AML, KYC, governance, reporting and audit.
The DFSA expects technology risk and cyber resilience proportionate to your business. As part of ITSEC, we bring penetration testing, CISO and incident-response into the application from day one — where others outsource it later.
LIGHTER PATH
The DFSA runs alternative routes alongside the five prudential categories — and choosing the right entry point can save months and capital. Two sit next to full authorisation, and mistaking one for the other is a common, costly error.
The DFSA's ITL lets FinTech and digital-asset firms test innovative products live, within a restricted scope and tailored conditions, before committing to a full licence — a genuine on-ramp for new models.
Watch the exit: the ITL is time-limited and scope-restricted. Scaling beyond the test parameters means migrating to a full DFSA category licence — which we plan for from the start.
A holding company, consultancy or tech developer may only need a DIFC Authority non-financial licence — not DFSA authorisation. A foreign firm marketing its group's services can instead take a DFSA Representative Office licence.
Watch the perimeter: a Representative Office may only market and refer — it cannot conclude deals or hold client money. Cross that line and a full category licence is triggered.
OBLIGATION
The DFSA supervises actively and enforces its rules. Its toolkit escalates with the breach, and includes:
Contested decisions are referred to the independent Financial Markets Tribunal, and onward to the DIFC Courts — a full common-law appeal path. Staying ahead of obligations is cheaper than answering for them.
Where KOLL takes it from here
Authorisation is one part of the engagement. We also handle regulatory and compliance advisory across the application, RegTech implementation for KYC, transaction monitoring and reporting, cybersecurity assurance for licensed firms, and ongoing compliance after your licence.
FAQ
It depends on the activities you carry out — the DFSA licenses by activity, not by label. The five categories run from Category 1 (accepting deposits) down to Category 5 (advising and arranging), with sub-types for principal dealing, agency dealing, fund custody, asset management and money services, plus a separate track for Islamic financial institutions. We confirm the right category in a perimeter analysis before anything is filed.
The DFSA regulates the DIFC under independent common law with its own courts and serves banks, funds and institutions across full financial services plus crypto; VARA is Dubai's onshore virtual-asset regulator, covering virtual assets only under UAE civil law. If you need conventional financial services as well as crypto, or DIFC's institutional weight, the DFSA is the better fit.
Capital is the highest of three figures: your category's base capital, a risk-based requirement, and — where you hold client assets — an Expenditure-Based Capital Minimum. Firms not holding client assets instead hold liquid assets equal to their base capital. Category 1 (accepting deposits) and Category 5 both sit at USD 10,000,000; the lowest base capital in the framework is USD 30,000, at the bottom of the Category 4 range.
Since 12 January 2026 the DFSA no longer keeps a list of Recognised Crypto Tokens — firms determine, on a reasoned and documented basis, that each token is suitable, layered on top of your underlying category licence, and firms must be incorporated in the DIFC to carry it on.
The ITL lets FinTech and digital-asset firms test innovative products live, within a restricted scope and tailored conditions, before committing to a full category licence. It's time-limited and scope-restricted — scaling beyond the test parameters means migrating to a full DFSA licence.
Yes. Genuine local substance is expected: a real DIFC office secured as part of satisfying your In-Principle Approval conditions, plus a DIFC-resident Senior Executive Officer among your Authorised Individuals.
Typically 6–12 months end-to-end for well-prepared applicants — around 2–4 months to In-Principle Approval, then a further period for build-out, capital deposit and final review before Authorisation is granted.
Building trust in the DIFC
Tell us your goals. In one confidential call we'll confirm the services you need, the right structure, a realistic timeline and the exact next steps.