Our Expert in United Arab Emirates
No results available
Who this is for: in-house counsel, compliance officers, ADGM- and DIFC-licensed firms, cross-border corporate advisers, and private wealth managers operating across UAE free zones.
What you will get: a summary of the issues raised where a firm conducts regulated services without the correct authorisation, the legal basis under DIFC law, a practical compliance checklist, an ADGM versus DIFC comparison table, and recommended next steps for firms and counsel.
Enforcement action by the Dubai Financial Services Authority (DFSA) against firms that carry on unauthorised financial services sends an unmistakable message to businesses operating across the United Arab Emirates’ two financial free zones: regulatory licences do not cross-qualify. Where the DFSA finds that a firm has carried on regulated financial services in or from the Dubai International Financial Centre (DIFC) while holding authorisation only from the Abu Dhabi Global Market’s Financial Services Regulatory Authority (FSRA), enforcement can follow. Such cases confirm that an ADGM licence confers no right to conduct regulated activity in the DIFC, and that operational conveniences, shared offices, common branding, personnel working across sites, can convert everyday business practice into a regulatory breach.
For cross-border corporate teams, this is a defining area of free-zone regulatory perimeter risk in the UAE. Readers should consult the DFSA’s published enforcement decisions for the precise facts, findings and penalties in any individual matter.
DFSA enforcement over unauthorised activity typically arises where the regulator identifies regulated financial services carried on in the DIFC by a firm that is not DFSA-authorised. A firm’s authorisation may sit instead with the FSRA in the ADGM, or with an overseas regulator. Where the DFSA finds that such a firm advises on financial products and arranges deals in investments connected to clients in or from the DIFC, activities that require DFSA authorisation under DIFC law, a breach of the general prohibition can be established.
A recurring feature in these matters is the relationship between an authorised entity and a connected entity maintaining a presence in the DIFC. Where employees associated with a regulated business operate from DIFC office space, and the distinction between entities is not made clear to clients, the firm can present an operational footprint in the DIFC without the authorisation that activity demands. The regulator may treat this blurring of entity lines and premises as a core part of the breach rather than an incidental administrative lapse.
DFSA findings often turn on conduct that took place over a defined window rather than years of accumulated activity. Enforcement can therefore arise from a focused period of regulated conduct conducted without the correct licence. This reinforces that the regulator will act on discrete, identifiable breaches rather than waiting for a pattern to develop. For compliance teams, the lesson is that exposure can crystallise quickly once regulated activity touches DIFC clients or premises without the proper authorisation in place.
The DFSA’s enforcement leadership has consistently underscored the central principle that authorisation by another regulator does not substitute for DFSA authorisation when a firm operates in or from the DIFC. The regulator’s position is direct: firms cannot rely on an ADGM licence to justify carrying on regulated activity within the DIFC perimeter. Where senior management is aware of the issue, enforcement commentary tends to frame the breach as avoidable. Readers should consult the DFSA’s published decisions for the exact wording of the regulator’s conclusions and attributed statements.
DFSA financial penalties commonly reflect a two-stage calculation. The regulator assesses a penalty figure and may then apply a reduction where the firm settles the matter. Settlement discounts are a standard feature of DFSA enforcement practice: a firm that resolves a case at an early stage, rather than contesting it through a full process, can secure a reduction in the financial penalty. The discount does not dilute the substance of the finding, the breach stands on the record, but it incentivises cooperation and efficient resolution. The precise percentage and amounts in any case are set out in the relevant published decision.
The legal foundation for DFSA action against unauthorised activity lies in the DIFC Regulatory Law (Law No. 1 of 2004, as amended). The Law establishes a general prohibition against carrying on a financial service in or from the DIFC without the appropriate DFSA authorisation. The prohibition is territorial and activity-based: it is triggered when a regulated financial service is carried on within the DIFC’s boundaries or conducted outward from the DIFC, regardless of where the firm may hold other licences. For the precise statutory text and current article numbering, counsel should refer to the official DIFC legislation repository.
The general-prohibition framework is deliberately broad. It is designed to protect the integrity of the DIFC’s regulatory perimeter by ensuring that any firm touching regulated activity within that perimeter falls under DFSA oversight. A firm authorised elsewhere, in the ADGM, in an overseas jurisdiction, or anywhere outside the DIFC, gains no automatic entitlement to operate inside the DIFC. DFSA enforcement in cross-free-zone scenarios is a textbook application of this principle.
The phrases “carrying on” and “in or from the DIFC” do significant work under the Regulatory Law. “Carrying on” captures activity conducted by way of business, repeated, organised, commercial conduct rather than a one-off act. “In or from the DIFC” extends the perimeter to activity physically conducted within the zone and to activity directed outward from a DIFC base. Where staff operate from DIFC premises and advise or arrange deals connected to that base, the conduct can fall squarely within the provision. Importantly, the client’s location is not the sole test: the firm’s own operational footprint in the DIFC can establish jurisdiction.
Firms must therefore assess not only where their clients sit, but where their people, premises and activities are genuinely situated.
The DFSA holds a wide suite of enforcement powers against unauthorised activity. These include imposing financial penalties, requiring remediation, issuing public censures, and pursuing compensatory or injunctive relief where the circumstances justify it. The regulator may also take steps to restrain ongoing unauthorised conduct. The choice and scale of remedy turn on the severity of the breach and the presence of aggravating or mitigating factors. The combination of a monetary penalty and a published decision reflects the DFSA’s dual objectives: penalising the specific conduct and deterring the wider market from treating free-zone boundaries as interchangeable.
DFSA enforcement in this area turns on a distinction that is easy to state but easy to overlook in practice: the DIFC and the ADGM are separate regulatory jurisdictions with separate regulators, separate authorisation regimes, and separate territorial perimeters. The table below sets out the key differences relevant to cross-border corporate planning.
| Feature | DIFC / DFSA | ADGM / FSRA |
|---|---|---|
| Regulatory authority | Dubai Financial Services Authority (DFSA) | Financial Services Regulatory Authority (FSRA) |
| Territorial scope | DIFC free zone; activities in or from the DIFC must be DFSA-authorised | ADGM free zone; activities in or from the ADGM must be FSRA-authorised |
| Licensing implication | DFSA authorisation required to advise on or arrange investments in or from the DIFC | FSRA authorisation required to advise on or arrange investments in or from the ADGM |
| Cross-qualification | No automatic cross-qualification; separate authorisation needed | No automatic cross-qualification; separate authorisation needed |
| Common risk triggers | Staff working in DIFC premises; branding or signage implying DFSA authorisation | Staff working in ADGM premises while servicing DIFC clients |
| Enforcement approach | Direct enforcement against unauthorised activity; fines and remediation | Enforcement by the FSRA within its jurisdiction; cooperation with the DFSA possible |
Both free zones operate common-law-based frameworks and host sophisticated financial businesses, which can create a false sense of interchangeability. In reality, the two regimes are distinct legal environments. A firm’s status in one confers nothing in the other. Consult the ADGM’s FSRA framework and the DFSA’s materials directly when mapping where authorisation is required.
The most important takeaway is that an ADGM licence does not substitute for DFSA authorisation when a firm operates in or from the DIFC. The two regulators derive their powers from separate legal foundations. The FSRA’s authorisation extends to activity in and from the ADGM; it has no reach into the DIFC perimeter governed by the DFSA under the Regulatory Law. A firm that wishes to serve clients across both zones must either obtain authorisation in each jurisdiction where it carries on regulated activity, or carefully structure its operations so that regulated activity in each zone is conducted only by the entity properly authorised there.
Convenience, such as sharing an office, co-locating staff, or using a common brand, cannot bridge this gap. The perimeter is legal, not merely administrative.
Breaches in this area are rarely obscure technicalities. They typically stem from a combination of operational arrangements and governance shortcomings that together bring regulated activity into the DIFC without authorisation. Where staff connected to a regulated business operate from DIFC premises associated with a connected entity, and the separation between the authorised entity and the DIFC-based entity is not made clear to clients, the firm presents a DIFC footprint from the client’s perspective. The DFSA may treat this conflation of entities, premises and client-facing presentation as the substance of the unauthorised activity.
Compounding the operational issue is the governance dimension. Where the regulator finds that senior management was aware of the position and did not act to correct it, that awareness weighs heavily. Awareness without remediation is the kind of factor that transforms a correctable error into an enforcement matter with teeth. For boards and compliance functions, these decisions are a reminder that knowledge of a regulatory risk carries an obligation to respond.
Senior management awareness and failure to act typically operate as aggravating factors, they increase the seriousness of the conduct in the regulator’s assessment. Aggravating factors commonly include a firm’s knowledge of the breach, the duration of the conduct, and any disregard of internal compliance advice. On the other side, mitigating factors reduce exposure: early and genuine cooperation, prompt remediation, and settlement all weigh in a firm’s favour. A settlement discount reflects mitigation through resolution, with the net penalty being the product of balancing these competing considerations against the starting figure.
The practical lessons are clear. First, corporate structure must map cleanly to regulatory authorisation: the entity that carries on regulated activity in a given zone must be the entity authorised there. Second, branding and signage must not imply authorisation that does not exist; a shared brand across free zones can mislead clients and attract scrutiny. Third, client communications must make entity separation explicit, so that a client always knows which regulated entity is providing which service and under whose authorisation. Where these three elements are aligned, the risk of an inadvertent perimeter breach falls sharply.
DFSA enforcement in this area gives compliance teams a concrete template for self-assessment. The following checklist translates the lessons into actionable controls for firms with a footprint across UAE free zones.
Embedding this checklist into a firm’s compliance calendar converts the lessons into durable protection. The goal is to ensure that the firm’s real-world operations never drift ahead of its authorisations.
Beyond the firm penalised, DFSA enforcement over unauthorised activity carries implications across the market. For clients, it is a reminder to verify that the firm advising them holds the correct authorisation for the jurisdiction in which it operates. For intermediaries, it highlights the reputational and contractual risk of referring clients to, or partnering with, firms whose perimeter position is unclear. For counsel, it reinforces the need to allocate regulatory risk carefully in contracts and to advise clients on the limits of any single authorisation.
Clients should treat regulatory authorisation as a core due diligence item. Confirm the exact legal entity that will provide the service and the regulator that authorises it. Check the relevant public register to verify the firm’s status and the scope of its permissions. Ask for the firm’s regulatory reference and confirm that the authorisation covers the specific activity, advising, arranging, or managing, being provided. Where a firm operates across both the DIFC and ADGM, ask explicitly which entity is serving you in which zone, and request written confirmation of that position before proceeding.
Where counsel identify a possible perimeter breach, the priority is controlled remediation. Advise the client to pause the activity in question where appropriate, conduct a privileged internal review, and assess whether proactive disclosure to the relevant regulator is warranted. Early, honest engagement with the DFSA or FSRA tends to support mitigation and settlement outcomes. Counsel should also review affected client relationships to determine whether notifications are required and whether any contracts need amendment. A documented remediation plan, approved at board level, demonstrates the responsiveness that regulators expect.
Verifying authorisation is straightforward and should be routine. Consult the DFSA’s public register of authorised firms and individuals, available through the DFSA’s official website. Search for the exact legal entity name, confirm that the firm is listed, and review the scope of its permissions and any licence conditions. Ask the firm directly for its DFSA firm reference and cross-check it against the register. A firm that cannot or will not provide this should prompt further inquiry.
If you suspect a firm is carrying on unauthorised activity in or from the DIFC, document your observations, preserve relevant communications, and take legal advice. The DFSA accepts reports of suspected misconduct through its official contact channels, and counsel can advise on the appropriate escalation. For clients uncertain about a firm’s status, a short written query asking the firm to confirm its authorising regulator and permissions often resolves the question quickly, and creates a useful record.
DFSA enforcement over unauthorised activity fits a broader pattern directed at protecting the integrity of the DIFC’s regulatory perimeter. The regulator has consistently signalled that it will act where firms carry on regulated services without the correct authorisation, including in cross-free-zone arrangements. Industry observers expect continued scrutiny of firms that maintain overlapping footprints across the DIFC and ADGM, particularly where shared premises, co-located staff, or common branding obscure which entity is authorised to do what. The likely practical effect is heightened diligence by firms and their advisers when structuring operations that span both zones.
DFSA enforcement over unauthorised DIFC financial services delivers one durable lesson: regulatory licences do not cross-qualify between the UAE’s financial free zones. Operational convenience, shared offices, common branding, co-located staff, cannot substitute for the authorisation that regulated activity in or from the DIFC demands. Firms operating across the DIFC and ADGM should map their perimeter, align structure to authorisation, and treat entity separation as a compliance priority. For tailored advice on managing a cross-free-zone footprint, speak to a cross-border corporate specialist.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Arsen Khachikian at AKTA, a member of the Global Law Experts network.
posted 4 minutes ago
posted 24 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
No results available
Find the right Legal Expert for your business
Send welcome message