COMPLEX LICENSING EXPERTS
Contact Us

Services · FinTech

FinTech Licensing

FinTech licensing in the UAE.

Payment providers, e-money wallets, lenders, neobanks and Open Finance platforms — licensed under the Central Bank, ADGM or the DFSA. We tell you which regulator fits, what capital it takes, how long it runs, and then we build the whole application.

Confidential & non-binding · Same-day response in UAE hours

3
Regimes — CBUAE, ADGM, DFSA
6
Core FinTech licence types
6–12
Typical months to licence
AED 100k+
Min. capital, activity-dependent

IN SHORT

Any FinTech that holds or moves customer money onshore in the UAE needs a Central Bank licence. Free-zone FinTechs can instead license under ADGM or the DFSA. Which one depends on your activity, your customers and where you set up.

The CBUAE licenses payments, e-money, lending and banking across onshore UAE. ADGM and the DFSA regulate the same activities inside their common-law free zones, with sandboxes for early-stage firms. If your product touches customer funds, the perimeter is strict — a perimeter analysis settles which regime, and which category, before you spend anything.

Regulators
CBUAE · ADGM · DFSA
onshore vs free zone
Who needs one
Payments, e-money,
lending, digital banks
Indicative capital
AED 100k – 1.5m+
by activity & regulator
Timeline
6–12 months
faster when well-prepared
Foreign owners
Allowed
UAE entity + substance required

BUSINESS MODELS

What you do decides what you need.

Financial regulators licence by activity, not by label. Here are the FinTech models we license most — each with the regulator that fits, the indicative capital, and the obligations that come with it.

Payment services (PSP)
API-first, fast-growing

Payment accounts, card issuing, merchant acquiring, segregation and fund transfers — moving money without necessarily holding customer balances. The CBUAE's Retail Payment Services regime (Category I–IV).

Primary regulator
CBUAE (RPSCS) or ADGM / DFSA
Indicative capital
AED 100k – 3m, by category
Key obligations
Safeguarding, AML, conduct, tech resilience
Typical timeline
6–10 months
E-money & wallets (SVF)
Holds customer float

Holding customer funds in a wallet or prepaid instrument — device-based or non-device based e-money. The moment you hold balances, you're in Stored Value Facility territory.

Primary regulator
CBUAE (SVF)
Indicative capital
AED 15m + ACF ≥ 5% of float
Key obligations
Float segregation, bank guarantee, liquidity
Typical timeline
8–12 months
Lending & BNPL
Credit provider

Extending credit, consumer or corporate — instalment lending, BNPL and financing — without taking demand deposits. A finance-company permission onshore, or the free-zone equivalent.

Primary regulator
CBUAE (finance company) / ADGM / DFSA
Indicative capital
Activity-based; higher onshore
Key obligations
Responsible lending, disclosure, AML
Typical timeline
8–12 months
Digital banks & neobanks
Highest scrutiny

Taking deposits and offering the full banking permission through a digital-first model. The heaviest licence, and only the Central Bank can grant it.

Primary regulator
CBUAE (bank)
Indicative capital
Substantial — hundreds of millions
Key obligations
Prudential capital, governance, resilience
Typical timeline
12+ months
Open Finance & infrastructure
API & data

Account-information and payment-initiation services, and the API infrastructure behind Open Finance — a dedicated CBUAE framework since 2024.

Primary regulator
CBUAE (Open Finance)
First step
Scope & role classification
Key obligations
API standards, consent, data security
Typical timeline
Varies by role

MAKE THE CALL

Onshore or free zone? Here's the quick way to read it.

The right regulator turns on where your customers are and whether you touch their money onshore. These are the patterns we see most.

If you...
Serve the mass UAE market & hold customer money

You issue wallets, move payments or lend to consumers nationwide — that's onshore, and only the Central Bank can license it.

→ CBUAE · onshore
If you...
Serve institutions & want a common-law base

You're B2B or wealth-facing and want an English-common-law jurisdiction with a sandbox to test.

→ ADGM or DFSA
If you...
Are early-stage and want to test first

You want to prove a model live, within a restricted scope, before committing to a full licence.

→ ADGM RegLab / DFSA ITL

COMPARE THE REGIMES

CBUAE vs ADGM vs DFSA for FinTech.

The same activity can be licensed in more than one place. Here's how they differ on the things that drive the decision.

CBUAE
ADGM
DFSA
Jurisdiction
Onshore UAE
ADGM free zone
DIFC free zone
Legal system
UAE federal law
English common law
English common law
Deposits / e-money
Yes — the only route
Within ADGM
Within DIFC
Market reach
Full onshore UAE
Free zone + cross-border
Free zone + cross-border
Sandbox
Case-by-case
RegLab innovation
Testing Licence
Best for
Consumer payments, wallets, lending
B2B & institutional FinTech
Institution-facing in DIFC

COST & CAPITAL

What a FinTech licence actually costs.

There's no single sticker price — the total is driven by your activity, regulator and how you build. These are the real cost lines to plan against.

Cost line
What drives it
Indicative range
Minimum capital — SVF
E-money / wallet float
AED 15m + 5% of float
Minimum capital — RPSCS
Payment category I–IV
AED 100k – 3m
Application & licence fees
Regulator & activity
AED 40k–150k+
Annual supervision fee
Regulator & category
Recurring
Safeguarding & bank guarantee
Float protection (SVF)
Scope-dependent
Key personnel
Compliance, MLRO, finance
Salaried roles
Tech, audit & advisory
Systems, pen-test, build
Fixed-scope with KOLL

HOW TO APPLY

How to get a FinTech licence in the UAE.

Each regulator runs a two-stage process — initial approval before you build and deposit capital, then the full licence once controls are genuinely in place. Here's the path, end to end.

01
Perimeter analysis & regulator selection

We assess your activities against the CBUAE, ADGM and DFSA and confirm the regulator and category that fit your model, customers and market.

Output: scope & regulator recommendationTime: 1–3 weeks
02
Entity set-up & structuring

Incorporate the right UAE entity, structure ownership and governance, and secure the office and substance the regulator expects.

Output: licence-ready entityTime: 3–6 weeks
03
Application & policy pack

We build the full submission — business plan, financial model, AML/CFT, safeguarding and risk frameworks, and fit-and-proper files for controllers.

Output: complete applicationTime: 4–8 weeks
04
Initial (in-principle) approval

The regulator reviews the file, holds meetings and issues initial approval setting the conditions to satisfy before launch.

Output: initial approvalTime: 2–4 months
05
Build-out & final authorisation

Stand up systems and safeguarding, deposit capital, complete hires and pass readiness review — then the full licence is issued.

Output: operating licenceTime: 2–4 months
06
Live compliance

AML/KYT monitoring, safeguarding reconciliation, reporting and audit begin. We run them on our own RegTech from day one.

Output: ongoing complianceTime: continuous

THE KOLL GROUP DIFFERENCE

Most advisors stop at the application. We don't.

Getting the licence is one thing. Staying licensed — with compliance that holds up to supervision and security that holds up to attack — is another. We're the only Dubai advisor that carries all three in-house.

Advisory

End-to-end application handling

We don't coach from the sidelines. We run the whole file — perimeter analysis, entity, capital structuring, the full application and every round of regulator questions — through to authorisation.

Compliance Technology

VerifiX — our RegTech

Safeguarding reconciliation, transaction monitoring and regulatory reporting on our own platform — so the controls you're approved on are the controls you actually run.

Cybersecurity

ITSEC — security assurance

Payment infrastructure and customer data live or die on security. Our sister firm ITSEC delivers the penetration testing, cyber controls and audit evidence in-house.

Three disciplines competitors outsource to three vendors. With KOLL Group it's one engagement, one accountable team — advisory, RegTech and cybersecurity under one roof.

AVOID THESE

Where FinTech applications go wrong.

The same mistakes stall applications again and again. Here are the ones we harden against before you file.

Onshore vs free-zone mix-up

Choosing a free-zone licence when your customers are onshore — then finding you can't serve them. Perimeter analysis first.

Underestimating safeguarding

Customer float not properly segregated, with capital that misses the base-plus-float-overlay requirement.

Generic, off-the-shelf AML

Policies not tailored to your activity and risk profile draw immediate regulator pushback.

Weak tech & resilience evidence

Infrastructure and controls below the regulator's technology and resilience expectations.

Controllers without track record

Senior management without genuine, verifiable financial-services experience won't clear fit-and-proper.

Treating capital as a one-off

Capital is held on an ongoing basis, not spent at filing. Under-planning the runway is a costly error.

GET FLUENT

The vocabulary, defined.

The terms that come up in every FinTech licensing conversation.

SVF

Stored Value Facility — the CBUAE licence to hold customer funds in a wallet or prepaid instrument in four categories.

RPSCS

Retail Payment Services & Card Schemes — the CBUAE regime for payment providers.

Float

The pool of customer money an e-money issuer holds — segregated and safeguarded, never the firm's own.

Aggregate Capital Funds

A capital overlay of at least 5% of float that an SVF must hold above minimum paid-up capital.

Open Finance

The CBUAE framework for consented sharing of financial data and payment initiation via APIs.

Safeguarding

Keeping customer funds separate and protected so customers rank first if the firm fails.

MLRO

Money Laundering Reporting Officer — the approved person accountable for AML/CFT compliance.

Initial approval

The first-stage sign-off that lets you build and satisfy conditions before the full licence is granted.

Finance company

A CBUAE-licensed lender that extends credit without taking demand deposits.

Sandbox

ADGM's RegLab and the DFSA's ITL — restricted-scope environments to test innovative products live.

GO DEEPER

The regulators behind this service.

Every FinTech route runs through one of these regimes. Read the full guide to the one that fits your model.

CBUAE — Central Bank

Banking, payments, e-money and lending across onshore UAE.

Read the guide →
ADGM — FSRA

Common-law free zone with the RegLab FinTech sandbox.

Read the guide →
DFSA — DIFC

Institution-facing financial services with the Innovation Testing Licence.

Read the guide →

FAQ

FinTech licensing questions.

CBUAE, ADGM or DFSA for a FinTech?

It depends on whether you touch customer money onshore. If you issue wallets, move payments or lend to consumers across the UAE, that's onshore and only the Central Bank (CBUAE) can license it. If you're B2B, institutional or want a common-law base and a sandbox, ADGM's FSRA or the DFSA in the DIFC fit. We confirm the right regime in a perimeter analysis before anything is filed.

What is the difference between an SVF and an RPSCS licence?

An SVF (Stored Value Facility) licence is required the moment you hold customer balances in a wallet or prepaid instrument. RPSCS (Retail Payment Services & Card Schemes) covers payment accounts, card issuing and fund transfers without necessarily holding balances — a lighter regime with categories I to IV.

What capital do I need?

It varies sharply by category. Minimum capital ranges from around AED 100k for lighter payment categories up to AED 15m plus a float overlay for e-money issuers, and substantially more for a digital bank. We size the requirement against your specific model.

Can I launch before a full licence?

In some cases, yes. ADGM's RegLab and the DFSA's Innovation Testing Licence let early-stage FinTechs test a product live, within a restricted scope, before committing to a full licence. We help assess whether a sandbox route fits your model.

How long does FinTech authorisation take?

Initial approval typically lands in 2–4 months, with a further 2–4 months to build out systems, capital and controls before the full licence — 6–12 months end to end for most categories, though a digital bank licence can take 12 months or more.

What happens after approval?

Live compliance begins immediately — AML/KYT monitoring, safeguarding reconciliation and reporting. We run these on our own RegTech so the controls you were approved on are the controls you actually operate.

Building trust in payments

Map your FinTech licence in one conversation.

Tell us your goals. In one confidential call we'll confirm the framework you need, the right structure, a realistic timeline and the exact next steps.