Our Expert in Indonesia
No results available
Fintech M&A due diligence in Indonesia has become one of the most demanding areas of transactional legal work as buyers navigate a regulatory landscape that has tightened materially heading into 2026. In-house counsel, private equity and strategic investors, M&A advisors and fintech founders all face the same challenge: a target may look commercially attractive, but hidden licensing, data and foreign-ownership issues can delay or derail a deal. This guide translates the rules of the Financial Services Authority (OJK), Bank Indonesia (BI), the Ministry of Communication and Digital Affairs (Komdigi) and the Ministry of Investment/BKPM into an actionable, lawyer-led checklist. It sets out approval triggers, the documents to request, the red flags to watch for, and realistic timelines.
The aim is to give acquirers a practical framework they can apply from the moment a term sheet is signed through to post-close integration.
Who this is for: in-house counsel at acquirers, private equity and strategic investors, M&A advisors and fintech founders preparing an acquisition in Indonesia.
What it delivers: a 2026-updated regulatory due diligence checklist for fintech and bank targets, with timelines, documents to request, red flags and post-close integration tasks.
Any effective fintech M&A due diligence Indonesia exercise begins by mapping the regulators whose consent or notification a deal may require. Indonesia does not operate a single financial-technology regulator; instead, oversight is distributed across several agencies whose remits frequently overlap in a fintech transaction. Understanding which body controls which activity determines the filings, the documents you must gather, and the realistic path to closing.
The principal actors are the OJK, Bank Indonesia, the Ministry of Communication and Digital Affairs (Komdigi) and the Ministry of Investment/BKPM. Where hardware such as payment terminals is imported, the Ministry of Finance and the Directorate General of Customs and Excise may also feature, and the Directorate General of Intellectual Property (DGIP) governs the registration record for trademarks, patents and software-related rights. Tax authorities sit behind all of this. A buyer must approach coordination between these bodies deliberately, because approvals are rarely sequential in a way that is convenient for a deal timetable.
It is worth noting a significant recent development: under Law No. 4 of 2023 on the Development and Strengthening of the Financial Sector (commonly known as the “P2SK Law”), supervision of certain fintech activities, including peer-to-peer lending and crypto-asset trading, has been consolidated under the OJK, with the transfer of crypto-asset oversight from the former commodity futures regulator (Bappebti). Buyers should confirm the current supervisory owner of any activity relevant to the target.
The OJK is the primary authority for banks, digital banks and a broad range of licensed non-bank financial institutions, including many lending and financing fintechs. It regulates change of control, imposes fit-and-proper testing on controlling shareholders and directors, and sets minimum capital expectations. For any target holding an OJK licence, prior approval or a no-objection process is normally engaged when control changes. Buyers should treat OJK engagement as a gating item, not an afterthought, and confirm early whether the target’s licence class carries transfer restrictions or ongoing supervisory conditions.
Bank Indonesia supervises the payment system, including e-money issuers, payment gateways and other payment service providers, and it oversees settlement infrastructure. Under the framework established by Bank Indonesia Regulation on Payment System Services (PJP licensing), payment service providers are categorised and licensed by BI. Where a target participates in the national payment system, a change of control can trigger notification or approval requirements, and BI expects continuity of settlement operations to be assured. Because payment licences frequently sit alongside other regulated activities, a buyer must confirm precisely which BI registrations the target holds, whether they are transferable, and what conditions attach. Payment integrations with banks and switching networks also depend on the target maintaining its BI standing.
The Ministry of Communication and Digital Affairs (Komdigi, formerly Kominfo) administers Electronic System Provider (PSE) registration and enforces implementing rules relating to electronic systems and transactions. A fintech that operates a digital platform is generally required to register as a Private Scope PSE, and failure to do so can expose the business to administrative sanctions, including access restrictions. Personal data protection is governed by Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), which established a comprehensive framework and provides for a supervisory authority.
In a fintech M&A due diligence Indonesia review, confirming the target’s PSE status and its lawful basis for cross-border data transfers is essential, because gaps here are among the most common causes of delayed closings.
Not every acquisition requires the same filings, and the trigger depends on the target’s licences and the transaction structure. As a starting point, buyers should assume that a change of control in any OJK-licensed institution, a BI-supervised payment participant, or a PSE handling regulated data will attract regulatory attention. Foreign acquirers add a further layer through the Ministry of Investment/BKPM, which administers the investment regime and sectoral foreign-ownership rules.
Common triggers include the purchase of shares in a licensed bank or digital bank, the acquisition of control over a licensed fintech offering payment or lending services, and any transaction that alters the ultimate beneficial ownership of a regulated entity. For foreign investors, investment filings and reporting through the OSS (Online Single Submission) system administered by BKPM are typically required, and the applicable ownership ceiling must be confirmed against the current investment rules. Data-related issues may also surface if the transaction changes how or where personal data is processed, potentially requiring updates to the PSE record. Large transactions may also require post-merger notification to the Business Competition Supervisory Commission (KPPU) where the relevant asset or turnover thresholds are met.
The structure you choose changes the regulatory profile of a deal. A share purchase keeps the licensed entity intact, which preserves its licences and registrations but also inherits every historic liability, supervisory condition and enforcement exposure attached to that entity. Change-of-control approvals from the OJK and, where relevant, notification to BI, are the central concern. An asset purchase can leave certain liabilities behind, but licences held by the target are generally not transferable with the assets; the buyer may need to apply for new authorisations or surrender and re-apply. That reapplication risk is often decisive in fintech deals, because a period without a valid licence can halt operations.
The right structure depends on the licence portfolio, the liability profile and the buyer’s tolerance for reapplication delay.
Where a target holds e-money, remittance or payment-gateway authorisations, licence conversion risk must be assessed early. Some authorisations cannot simply follow a change of control; the regulator may require a fresh fit-and-proper assessment, revised capital, or an entirely new application. If the licence lapses or is suspended during the transition, the business may be unable to process transactions, eroding value overnight. A careful fintech due diligence checklist confirms transferability in writing, tests the regulator’s likely position through early engagement, and builds the outcome into conditions precedent so that closing does not proceed without regulatory certainty on the licences that drive the target’s revenue.
This is the operational core of any fintech M&A due diligence Indonesia project. The checklist below is organised by legal area. For each, it identifies the documents to request, the red flags that warrant escalation, and the way findings should feed into the purchase agreement through conditions precedent, representations and warranties, and covenants. Buyers should assign a risk rating, High, Medium or Low, to each finding so that the deal team can prioritise remediation and price adjustment.
Establish a clean chain of title before anything else. Verify the ultimate beneficial owners, reconstruct the cap table from incorporation, and confirm that historic foreign investments complied with the applicable investment approvals. Review shareholder agreements for change-of-control clauses, pre-emptive rights, drag-along and tag-along provisions, and any anti-assignment terms that could impede the transfer. Check whether escrow or lock-up arrangements bind existing shareholders.
Licensing sits at the heart of fintech M&A due diligence Indonesia because the target’s value depends on its authorisations remaining valid through the transaction. Inventory every OJK licence, every BI payment-system registration, and any exemptions the business relies upon. Establish whether each licence is transferable on a change of control and what the regulator will require. Review all correspondence with the OJK and BI for supervisory actions, warnings, remediation directives or capital conditions.
Data is frequently where deals stall. Confirm the target’s PSE registration status with Komdigi and verify that the certificate is current and correctly scoped. Under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022), cross-border data transfers require a lawful basis, so map every flow of personal data offshore and confirm the mechanism relied upon. Review data processing agreements with vendors, consent records, retention practices and the outputs of any data protection impact assessments.
Financial-crime compliance is a supervisory priority. Test the target’s KYC standards, the quality of its AML/CFT programme, and its record of filing suspicious transaction reports to the Financial Transaction Reports and Analysis Centre (PPATK). Confirm whether the target has faced any adverse enforcement relating to money laundering or sanctions.
A fintech’s core code is often its principal asset, so confirm ownership. Verify that all contributors, including contractors and founders, assigned their rights, and cross-check registered marks and any patents against the DGIP record to confirm chain of title. Audit third-party dependencies and open-source licences for copyleft obligations that could compromise proprietary code.
Fintechs depend on outsourced infrastructure, so a robust fintech due diligence checklist examines vendor continuity. Review cloud arrangements, disaster recovery and business continuity plans, and any independent assurance such as SOC reports. Confirm that key vendor contracts survive a change of control or can be novated without disruption.
Confirm the target’s tax position, including any unpaid liabilities and the robustness of its transfer-pricing documentation. Where the business imports payment terminals or hardware, review customs declarations. Confirm compliance with Bank Indonesia foreign-exchange reporting where relevant.
Review employment contracts, accrued entitlements and the enforceability of restrictive covenants under Indonesian labour law (as amended by the Job Creation Law and its implementing regulations). Quantify severance exposure, which can be significant.
Identify all live disputes, investigations and enforcement correspondence. Regulator letters and settlement agreements can reveal risks not otherwise disclosed.
The intensity of a review changes sharply depending on whether the target is a bank or a non-bank fintech. A bank acquisition in Indonesia is materially heavier than a payment-service provider deal, because the OJK applies rigorous change-of-control approvals, minimum capital expectations and fit-and-proper testing to controlling shareholders. For a non-bank fintech, the focus tends to shift toward data, PSE status, intellectual property and vendor continuity. Buyers should also decide whether to acquire directly or through a local special-purpose vehicle, a choice that interacts with foreign-ownership rules and tax structuring.
| Issue / Approval | Fintech (non-bank PSP) | Digital bank / bank acquisition |
|---|---|---|
| Regulator(s) involved | Komdigi, OJK (if licensed), BI (payment systems) | OJK (primary), BI (if payment systems), BKPM for foreign investor filings |
| Licence transferability | Often limited; surrender and re-application common | Strict OJK change-of-control approvals; capital and fit-and-proper checks |
| Typical timeline | Several months (depending on PSE and data fixes) | Substantially longer (OJK/BI approvals, remediation) |
| Key DD focus | Data/PSE, IP, AML, vendor continuity | Capital adequacy, governance, regulatory enforcement history |
For bank targets, expect additional conditions precedent: OJK approval of the acquirer, satisfaction of fit-and-proper standards for proposed controllers and directors, and confirmation of capital adequacy against the OJK’s current minimum core-capital requirements. These requirements are difficult to compress, so a buyer should build them into the timetable from the outset rather than treating them as closing formalities.
Foreign investors must confirm the applicable ownership ceiling before committing capital. The Ministry of Investment/BKPM administers the investment regime and the sectoral rules, anchored in the Investment Law and the “Positive Investment List” issued under implementing regulations, that determine how much of a target a foreign acquirer may hold. Some fintech activities permit foreign majority ownership, while certain regulated activities carry specific restrictions or conditions. Because the position varies by activity, the correct approach is to classify the target’s business lines precisely (by reference to the applicable Indonesian business classification, KBLI) and confirm each against the current rules rather than assuming a single ceiling applies across the group.
This crosswalk matters because BKPM clearance interacts with OJK and BI approvals. A structure that satisfies the ownership rules may still fail if the OJK is not comfortable with the ultimate controller, and vice versa. Foreign buyers should therefore sequence investment confirmation alongside regulator engagement, and consider whether a local SPV or a phased acquisition better fits the applicable limits. Getting this wrong is not a technicality: an ownership breach can invalidate the transaction or trigger unwinding, which is why foreign-ownership analysis belongs at the front of any cross-border fintech M&A Indonesia workstream.
Realistic scheduling is what separates a smooth deal from a stalled one. As the comparison table shows, non-bank fintech transactions commonly close within a few months where PSE and data gaps are fixed, while bank and digital-bank acquisitions frequently run considerably longer once OJK and BI approvals and any remediation are factored in. These are planning ranges, not guarantees; the actual duration depends on the target’s compliance posture and the regulators’ workload.
Practical strategies help compress the calendar. Run filings in parallel where the rules permit, rather than waiting for one approval before starting the next. Use staged closings so that non-regulated elements can complete while approvals remain outstanding. Deploy escrow and holdbacks to bridge residual regulatory risk, and impose interim management covenants so the target continues to operate compliantly between signing and completion.
| Milestone | Fintech (non-bank) | Bank / digital bank |
|---|---|---|
| Confirm licences, PSE status and ownership ceiling | Early stage | Early stage |
| Submit investment / BKPM filing (foreign acquirer) | Early stage | Early stage |
| Regulator engagement (OJK / BI) | Mid stage, several months | Extended, potentially many months |
| Remediate PSE / data gaps | Concurrent | Concurrent |
| Closing | Within several months | Substantially longer |
The message from the matrix is to submit concurrently and remediate in parallel. Sequential filings almost always extend the timetable beyond what commercial parties will tolerate.
Diligence findings are only useful if they are reflected in the transaction documents. A disciplined fintech M&A due diligence Indonesia review feeds directly into representations and warranties, conditions precedent, covenants and indemnities. Model the representations to cover licensing validity, PSE registration, data compliance, AML standards and IP ownership. Size the escrow to the identified regulatory exposure, and secure specific indemnities for undisclosed licence non-compliance rather than relying on general warranty cover.
Buyers should also negotiate a regulatory-engagement covenant obliging the seller to cooperate fully with filings, and consider limited step-in rights that allow the buyer to influence remediation before closing. Completion adjustments can be used where remediation costs are quantified during diligence.
At a minimum, make closing conditional on receipt of OJK approval or no-objection where a licensed entity is involved, on any required BI clearance for payment participants, on confirmation of the investment/BKPM position for foreign acquirers, and on remediation of any PSE registration or data-transfer gap. Draft each condition so that it identifies the specific approval, the responsible party for obtaining it, and a long-stop date after which either party may walk away. Vague conditions invite disputes; precise conditions keep the timetable honest.
When diligence reveals a missing PSE registration or an unlawful cross-border transfer, do not simply price the risk and proceed. Build a remediation roadmap that sets out the corrective steps, the responsible owner, the sequence and the deadline. For PSE gaps, that means completing registration with Komdigi before or immediately after closing depending on operational risk. For data transfers, it means establishing a lawful basis and updating DPAs. Where remediation cannot complete before closing, tie the outstanding items to escrow release and to a covenant compelling completion within a fixed period.
Completion is not the finish line. A structured post-close programme protects the value the deal was intended to capture and keeps the acquired business compliant during transition.
Composite, illustrative examples show how these principles play out. In a successful cross-border acquisition of a payment-service provider, the buyer confirmed PSE status and the foreign-ownership ceiling early, ran the investment filing in parallel with OJK engagement, and remediated a minor data-transfer gap through updated DPAs before closing. Early classification of the target’s activities avoided any ownership breach, and precise conditions precedent kept the timetable on track.
By contrast, a deal that ignored data compliance stalled badly. Diligence uncovered a lapsed PSE registration and cross-border transfers without a lawful basis, discovered too late to remediate before the intended completion date. The parties were forced to renegotiate, introduce a larger escrow, and add a remediation covenant, pushing closing out significantly. The lesson is consistent: treat PSE and data verification as gating items in every fintech M&A due diligence Indonesia project, not as second-order concerns.
Fintech M&A due diligence in Indonesia rewards buyers who plan for the regulatory reality rather than the commercial ideal. The distributed oversight of the OJK, Bank Indonesia, Komdigi and BKPM means that approvals, data checks, foreign-ownership analysis, licensing transferability, IP and tax must all be addressed in a single, coordinated workstream. Map the regulators early, request the right documents, rate every finding for risk, and translate the results into precise conditions precedent, warranties and indemnities. Sequence filings in parallel, remediate PSE and data gaps before they threaten closing, and carry the discipline through to post-close integration. Buyers who follow a structured, lawyer-led checklist close faster, price risk accurately, and avoid the enforcement exposure that catches less prepared acquirers.
For tailored due diligence support, contact us through the Technology practice, Indonesia.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Putu Raditya Nugraha at UMBRA – Strategic Legal Solutions, a member of the Global Law Experts network.
posted 2 minutes ago
posted 6 minutes ago
posted 22 minutes ago
posted 26 minutes ago
posted 49 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Send welcome message