The 7 Questions Every Buyer Should Ask Before Acquiring a Licensed Fintech

22 July 2026
#Due_Diligence#Fintech_M&A#Buyer_Checklist#Licence_Transfer#AML_Compliance#DORA#Change_of_Control#Pre-LOI
Ihor Vlasov

Ihor Vlasov

Author

The 7 Questions Every Buyer Should Ask Before Acquiring a Licensed Fintech
4 min read

Fintech acquisition due diligence questions are not generic business acquisition questions with a fintech label. A licensed financial business has a regulatory relationship, a compliance programme, and a supervisory history that don't appear in revenue multiples or EBITDA adjustments — and that every serious buyer needs to interrogate before signing an LOI. The questions below target the seven specific failure modes that consistently surface in licensed fintech acquisitions: the items where first-time buyers discover, after signing, what they should have confirmed before.

Key Takeaways

  • Fintech acquisition due diligence questions target a specific category of risk that general M&A frameworks miss — the licence, the AML programme, and the regulatory relationship are as material as the revenue

  • The average FinCEN enforcement penalty in 2025 was $12.7 million — while the annual cost of a well-structured AML programme for a mid-stage fintech is $200,000 to $500,000. The cost-benefit arithmetic of asking these questions before close is not ambiguous

  • DORA entered into application in January 2025 — only approximately 33% of major European financial institutions were confident they met all requirements by the deadline. The buyer inherits every ICT third-party obligation at close

  • A licence under active regulatory review is a liability, not an asset — and a register check showing "active" status does not reveal open remediation requirements, supervisory correspondence, or conditions attached to the authorisation

  • Contracts that terminate on change of control — card scheme agreements, banking partner arrangements, key client contracts — are not visible in headline financials but can eliminate the revenue the multiple was applied to

Question 1: Is the licence actually clean — or just active?

Question 1: Is the licence actually clean — or just active?

A register check confirms whether a licence exists. It does not reveal whether the regulator has issued remediation requirements, whether supervisory correspondence has flagged governance concerns, or whether the licence carries conditions that limit the scope of permitted activities.

Regulatory compliance due diligence should review all regulatory obligations, licences, permits, and certifications required for the target company's operation — with an eye toward identifying any potential violations or non-compliance. Request the full supervisory correspondence file for at least the past three years. The absence of findings in the register and the presence of a clean correspondence file are two different things.

Question 2: What does the licence cover — and what does the entity actually do?

A Payment Institution licence does not permit the issuance of electronic money or the holding of client balances for future use without a separate EMI authorisation. A CASP authorisation for exchange services does not extend to custody without the relevant service category. The most common compliance gap in licensed fintech acquisitions is an entity conducting activities that fall outside the boundary of its authorisation.

Map the entity's actual commercial activities against the authorised scope of its licence — product by product, revenue line by revenue line. Any activity outside the licensed scope is a compliance problem the buyer acquires at close, not a legacy issue they inherit from the seller's decisions.

Question 3: Does the AML programme function without the founders?

The five pillars of AML compliance are non-negotiable: a BSA/AML compliance officer, written policies, training, independent testing, and risk-based customer due diligence. Transaction monitoring is where fintechs fail most often — regulators expect firms to understand their monitoring methodology, including rules, thresholds, and exceptions.

The question is not whether an AML programme exists. It is whether it is documented, independently tested, and operational without the founders managing it. A compliance programme that runs through the founder's judgment and relationships is not a transferable compliance asset — it is a dependency that disappears at close.

Question 4: What happens to this licence on change of control?

Question 4: What happens to this licence on change of control?

Several regulators require explicit approval before a change of control takes effect, and that approval process reviews the acquirer as much as the acquired entity. In the UK, the FCA must approve any acquisition of a controlling stake in an authorised firm — a process that commonly runs 60 working days or longer. In the EU, national competent authority clearance is required under the Payment Services Directive. In Singapore, MAS approval is required before control of a licensed payment institution changes hands.

Some licences do not transfer automatically at all — a change of control triggers a requirement for the acquiring entity to make a fresh application. Confirming the change-of-control mechanism for the specific licence type and jurisdiction before LOI prevents the most common source of post-signing delay.

Question 5: Who does the revenue actually belong to?

Revenue that depends on the founder's personal relationships, verbal arrangements with key clients, or contracts that contain change-of-control termination clauses is not revenue that transfers at close. The buyer needs to know every vendor obligation that survives closing, every contract that terminates on change of control, and every renewal that falls due before integration completes.

Revenue concentration above 30 to 40% in a single client is the most consistent structural reason a fintech trades below its headline valuation. A buyer who doesn't identify that concentration before LOI discovers it in the first operating quarter after close — when the client relationship that generated 40% of revenue begins renegotiating its terms under a new owner.

Question 6: What does DORA compliance look like in the ICT vendor stack?

DORA entered into full application in January 2025, and 2026 is when national competent authorities are actively enforcing it. Every KYC, AML screening, and identity verification tool is an ICT third-party service provider under DORA Articles 28–44 — not "might be," but is. That classification carries mandatory due diligence, specific contractual clauses, and ongoing oversight obligations.

The enforcement dynamic shifted between 2025 and 2026. Examiners now ask for documentation — the Register of Information, vendor contracts with Article 30 provisions, incident notification records. Verbal assurances and "in progress" answers are no longer accepted, and first formal enforcement actions for reporting failures are expected in H2 2026.

A buyer acquiring a EU-licensed fintech in 2026 inherits every ICT third-party obligation at close. The question is whether those obligations are documented, contracted, and manageable — or whether they represent an undisclosed compliance gap that will surface in the first regulatory examination after the acquisition.

Question 7: What does integration actually look like in the first 90 days?

The most underasked question in fintech M&A is not about the licence or the revenue — it is about operational continuity. Can the technology operate without the founding team? Are the internal procedures documented well enough for a new operator to run them? Which third-party contracts require the founding team's signatures or relationships to maintain?

In payment and fintech transactions, technology failure is business failure. Platform resilience, security, compliance, and transaction integrity are directly linked to revenue continuity and customer trust. A buyer who has mapped the integration dependencies before LOI structures the deal to protect against them — through escrow arrangements, earn-out conditions, or transition service agreements. A buyer who discovers them after close negotiates from a weaker position against a seller who has already been paid.

Conclusion

Fintech acquisition due diligence questions are the difference between a buyer who closes on the asset they priced and one who closes on a different asset at the same price. Every item on this list is knowable before LOI — the question is whether the buyer has built the process to find it in advance. For buyers evaluating licensed fintech assets with pre-screened documentation across licence status, compliance history, and regulatory standing, N5Deal presents the information that these seven questions require. A full catalogue of available assets is at n5deal.com.

Disclaimer

This page is for informational purposes only. It does not constitute legal, financial, or regulatory advice. Readers should consult qualified professionals before making any decisions.

Comments

Frequently Asked Questions

Clear, concise info to help you understand the process!

Licence scope versus actual activities — specifically, whether the entity conducts any commercial activities outside the boundaries of its current authorisation. This is the most common compliance gap that surfaces in licensed fintech diligence and the one that most consistently produces post-signing valuation adjustments.
Between 60 working days and several months, depending on the jurisdiction and the acquiring entity's own regulatory profile. The FCA requires explicit approval for any acquisition of a controlling stake in an authorised firm. EU national competent authorities require clearance under the Payment Services Directive. Singapore's MAS requires approval before control changes hands. Building this timeline into the deal structure before LOI prevents the most common source of post-signing delay.
DORA is the EU Digital Operational Resilience Act, in full application since January 2025. It imposes mandatory due diligence, contractual requirements, and ongoing oversight obligations for every ICT third-party service provider used by an EU-licensed financial entity — including KYC tools, AML screening platforms, and identity verification services. A buyer acquiring an EU-licensed fintech inherits all of those obligations at close. The question before LOI is whether they are documented and manageable, or an undisclosed compliance gap.
The 7 Questions Every Buyer Should Ask Before Acquiring a Licensed Fintech | N5Deal