What Are You Actually Buying?When acquiring a regulated crypto or fintech company, the buyer is acquiring more than the legal entity itself. Four elements are particularly important.
The Regulatory PositionThe first element is the company's existing regulatory position. This includes the authorisation or registration itself, the activities covered by it, its conditions and limitations, and the regulatory framework under which the company operates. The buyer needs to understand whether that regulatory position matches the business it intends to continue or develop.
The Regulatory HistoryThe company also comes with its history as a regulated entity. This may include previous licensing submissions, regulatory correspondence, examinations or inspections, remediation work, reporting history, and any outstanding regulatory matters. The purpose is to understand whether there are unresolved issues that may become relevant after the ownership change.
The Existing Business InfrastructureAn operating regulated company may already have an established business infrastructure. Depending on the target, this can include customers, transaction history, compliance procedures, employees and management arrangements, banking and payment relationships, technology providers, commercial contracts and intellectual property. These elements can form part of the value of the acquisition, but they can also create obligations that need to be understood before closing.
The Scope for the Buyer's BusinessExisting licences cover current operations, not future expansion. If a deal involves launching new products, targeting different customer segments, or entering new markets, the buyer must assess whether the current authorisation can actually support that roadmap.
The Acquisition RoadmapAlthough the regulatory requirements differ between jurisdictions, the overall acquisition process usually follows a similar sequence.
1. Target and regulatory due diligence. The buyer reviews the company, its ownership and UBO structure, licence and regulatory status, regulatory history, compliance framework, customer and transaction history, banking and provider relationships, contracts, IP and outstanding liabilities.
2. Regulatory and transaction assessment. The parties determine whether the acquisition triggers any change-of-control, ownership, notification, approval or registration requirements.
The transaction structure also matters. A share acquisition generally leaves the buyer with the licensed entity and its existing obligations, while an asset acquisition involves selected assets rather than the company itself. As licences are often attached to the licensed entity, the appropriate structure depends on what the buyer intends to acquire and operate.
3. Regulatory approvals and notifications. Where required, the relevant regulator is notified or asked to approve the proposed ownership or control change. Depending on the jurisdiction, this may involve information about the buyer, UBOs, directors, source of funds, business plans or other aspects of the proposed transaction. These requirements can also affect the transaction timeline and, in some cases, whether closing can take place before the relevant regulatory process is completed.
4. Closing and corporate updates. Once the applicable conditions are satisfied, the transaction can proceed to closing. Corporate records, ownership information and regulatory registrations are updated where required.
5. Post-acquisition compliance and operational transition. The buyer then addresses any compliance gaps, updates policies and procedures, reviews management and MLRO arrangements, and completes any required onboarding or re-approval processes with banks, PSPs and other providers.
6. Business launch or transition. The business can continue operating or implement any planned changes once the relevant regulatory, compliance and operational requirements have been satisfied.
This is the common framework. The actual roadmap can, however, change materially depending on the jurisdiction, licence, transaction structure and intended business model.
The Buyer's Documents and Information ChecklistA regulated acquisition normally requires information from several areas. The exact package depends on the jurisdiction, target and transaction structure, but buyers commonly need access to:
Corporate Documents- Certificate of incorporation and constitutional documents
- Corporate structure and ownership information
- Shareholder and UBO information
- Board and management information
- Existing corporate registers and resolutions
- Material corporate agreements
Regulatory Documents- Licence, registration or authorisation
- Original licensing or registration submissions
- Regulatory correspondence
- Regulatory reports and filings
- Inspection or examination records, where applicable
- Records of remediation or corrective actions
- Previous ownership or control change submissions
Compliance Materials- AML/KYC policies and procedures
- Compliance manuals and internal controls
- Risk assessments
- Customer due diligence procedures
- Transaction monitoring framework
- Sanctions and screening procedures
- Relevant compliance reviews or audit reports
Business and Operational Information- Customer and transaction information
- Banking, PSP and other provider relationships
- Material commercial contracts
- Technology and service-provider arrangements
- Employee and management information
- Intellectual property documentation
- Information on material disputes, claims or liabilities
Transaction Materials- Proposed transaction structure
- Share purchase or asset purchase documentation
- Information on the proposed buyer and UBOs
- Source-of-funds information, where required
- Business plan or post-acquisition operating model
- Regulatory application or notification materials
This information gives the parties the documentation needed to assess the target, prepare the transaction, and complete any applicable regulatory process.
How the Process Differs by JurisdictionThe general acquisition methodology remains broadly the same. What changes is the specific regulatory perimeter that applies to the target and the transaction.
EuropeUnder MiCA, acquisition of a CASP is specifically addressed through the qualifying-holdings regime. A proposed acquirer must notify the relevant competent authority when acquiring or increasing a qualifying holding so that the proportion of voting rights or capital reaches or exceeds 20%, 30% or 50%, or where the CASP becomes the acquirer's subsidiary. Each threshold represents a further level of ownership that may trigger additional regulatory assessment.
Procedural details and supervisory practice can vary between Member States, so the transaction should be assessed against the specific national competent authority and the actual authorisation.
El SalvadorEl Salvador is particularly relevant for buyers because the Digital Asset Service Provider (PSAD/DASP) regime is administered by the CNAD, which maintains a public register showing registered providers and their activities.
For an acquisition, the distinctive point is the treatment of changes in shareholding composition. CNAD's published process for relevant events includes changes in shareholding composition and requires information concerning shareholders, their participation, identification documents and applicable beneficial-owner information.
The buyer should establish early in the transaction:
- current PSAD registration status;
- the exact activities it is registered for;
- current shareholders and beneficial owners;
- what action the proposed ownership change requires from CNAD;
Costa RicaCosta Rica requires a different starting point because there is no single crypto licence that answers the regulatory question for every business model. For a potential acquisition, the analysis should begin with the activity rather than the label "crypto company". A business providing payments, financial services, virtual-asset services or another regulated activity may fall within a different regulatory perimeter.
The practical acquisition question is: what does the target actually do, which authority oversees that activity, and what registration or authorisation does the entity currently rely on? From there, ownership, AML, and any other applicable requirements can be assessed for that specific structure.
United StatesThe United States does not have a single national crypto licence covering all business models. The acquisition analysis therefore starts with the target's activities and maps them across the applicable federal and state regimes:
Entity → Activities → States → Federal perimeter → Existing approvals
Depending on the business, the buyer may need to assess FinCEN/MSB status, state money-transmission licences, state-specific regimes, and securities or commodities regulation specific to the product.
ConclusionThere is no single acquisition process that applies to every regulated crypto or fintech company. The overall logic is usually similar. What changes from case to case is the regulatory regime, the structure of the transaction, the target's existing position and the business the buyer intends to operate.
For this reason, a regulated acquisition requires more than checking whether a licence exists. It requires a coordinated review of the regulatory position, transaction structure, documentation and intended business model.
If you are considering the acquisition of a regulated crypto, fintech or blockchain company, AMLZone can support the process with regulatory due diligence, document preparation and review, ownership-change requirements, regulatory submissions, and project coordination through the transaction and transition.