Global Law Experts Logo
fintech m&a due diligence

Fintech M&A in Indonesia 2026: a Practical Regulatory Due Diligence Checklist

By Global Law Experts
– posted 1 hour ago

Fintech M&A due diligence in Indonesia has become one of the most demanding areas of transactional legal work as buyers navigate a regulatory landscape that has tightened materially heading into 2026. In-house counsel, private equity and strategic investors, M&A advisors and fintech founders all face the same challenge: a target may look commercially attractive, but hidden licensing, data and foreign-ownership issues can delay or derail a deal. This guide translates the rules of the Financial Services Authority (OJK), Bank Indonesia (BI), the Ministry of Communication and Digital Affairs (Komdigi) and the Ministry of Investment/BKPM into an actionable, lawyer-led checklist. It sets out approval triggers, the documents to request, the red flags to watch for, and realistic timelines.

The aim is to give acquirers a practical framework they can apply from the moment a term sheet is signed through to post-close integration.

Who this is for: in-house counsel at acquirers, private equity and strategic investors, M&A advisors and fintech founders preparing an acquisition in Indonesia.

What it delivers: a 2026-updated regulatory due diligence checklist for fintech and bank targets, with timelines, documents to request, red flags and post-close integration tasks.

Quick overview, the regulatory ecosystem for fintech M&A in Indonesia

Any effective fintech M&A due diligence Indonesia exercise begins by mapping the regulators whose consent or notification a deal may require. Indonesia does not operate a single financial-technology regulator; instead, oversight is distributed across several agencies whose remits frequently overlap in a fintech transaction. Understanding which body controls which activity determines the filings, the documents you must gather, and the realistic path to closing.

The principal actors are the OJK, Bank Indonesia, the Ministry of Communication and Digital Affairs (Komdigi) and the Ministry of Investment/BKPM. Where hardware such as payment terminals is imported, the Ministry of Finance and the Directorate General of Customs and Excise may also feature, and the Directorate General of Intellectual Property (DGIP) governs the registration record for trademarks, patents and software-related rights. Tax authorities sit behind all of this. A buyer must approach coordination between these bodies deliberately, because approvals are rarely sequential in a way that is convenient for a deal timetable.

It is worth noting a significant recent development: under Law No. 4 of 2023 on the Development and Strengthening of the Financial Sector (commonly known as the “P2SK Law”), supervision of certain fintech activities, including peer-to-peer lending and crypto-asset trading, has been consolidated under the OJK, with the transfer of crypto-asset oversight from the former commodity futures regulator (Bappebti). Buyers should confirm the current supervisory owner of any activity relevant to the target.

OJK: bank and financial services approvals

The OJK is the primary authority for banks, digital banks and a broad range of licensed non-bank financial institutions, including many lending and financing fintechs. It regulates change of control, imposes fit-and-proper testing on controlling shareholders and directors, and sets minimum capital expectations. For any target holding an OJK licence, prior approval or a no-objection process is normally engaged when control changes. Buyers should treat OJK engagement as a gating item, not an afterthought, and confirm early whether the target’s licence class carries transfer restrictions or ongoing supervisory conditions.

Bank Indonesia: payment systems and PSP oversight

Bank Indonesia supervises the payment system, including e-money issuers, payment gateways and other payment service providers, and it oversees settlement infrastructure. Under the framework established by Bank Indonesia Regulation on Payment System Services (PJP licensing), payment service providers are categorised and licensed by BI. Where a target participates in the national payment system, a change of control can trigger notification or approval requirements, and BI expects continuity of settlement operations to be assured. Because payment licences frequently sit alongside other regulated activities, a buyer must confirm precisely which BI registrations the target holds, whether they are transferable, and what conditions attach. Payment integrations with banks and switching networks also depend on the target maintaining its BI standing.

Komdigi and PDP: PSE registration and personal data rules

The Ministry of Communication and Digital Affairs (Komdigi, formerly Kominfo) administers Electronic System Provider (PSE) registration and enforces implementing rules relating to electronic systems and transactions. A fintech that operates a digital platform is generally required to register as a Private Scope PSE, and failure to do so can expose the business to administrative sanctions, including access restrictions. Personal data protection is governed by Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”), which established a comprehensive framework and provides for a supervisory authority.

In a fintech M&A due diligence Indonesia review, confirming the target’s PSE status and its lawful basis for cross-border data transfers is essential, because gaps here are among the most common causes of delayed closings.

Which transactions trigger formal approvals?

Not every acquisition requires the same filings, and the trigger depends on the target’s licences and the transaction structure. As a starting point, buyers should assume that a change of control in any OJK-licensed institution, a BI-supervised payment participant, or a PSE handling regulated data will attract regulatory attention. Foreign acquirers add a further layer through the Ministry of Investment/BKPM, which administers the investment regime and sectoral foreign-ownership rules.

Common triggers include the purchase of shares in a licensed bank or digital bank, the acquisition of control over a licensed fintech offering payment or lending services, and any transaction that alters the ultimate beneficial ownership of a regulated entity. For foreign investors, investment filings and reporting through the OSS (Online Single Submission) system administered by BKPM are typically required, and the applicable ownership ceiling must be confirmed against the current investment rules. Data-related issues may also surface if the transaction changes how or where personal data is processed, potentially requiring updates to the PSE record. Large transactions may also require post-merger notification to the Business Competition Supervisory Commission (KPPU) where the relevant asset or turnover thresholds are met.

Share purchase vs asset purchase, regulatory differences

The structure you choose changes the regulatory profile of a deal. A share purchase keeps the licensed entity intact, which preserves its licences and registrations but also inherits every historic liability, supervisory condition and enforcement exposure attached to that entity. Change-of-control approvals from the OJK and, where relevant, notification to BI, are the central concern. An asset purchase can leave certain liabilities behind, but licences held by the target are generally not transferable with the assets; the buyer may need to apply for new authorisations or surrender and re-apply. That reapplication risk is often decisive in fintech deals, because a period without a valid licence can halt operations.

The right structure depends on the licence portfolio, the liability profile and the buyer’s tolerance for reapplication delay.

Conversion risks where the fintech holds regulated licences

Where a target holds e-money, remittance or payment-gateway authorisations, licence conversion risk must be assessed early. Some authorisations cannot simply follow a change of control; the regulator may require a fresh fit-and-proper assessment, revised capital, or an entirely new application. If the licence lapses or is suspended during the transition, the business may be unable to process transactions, eroding value overnight. A careful fintech due diligence checklist confirms transferability in writing, tests the regulator’s likely position through early engagement, and builds the outcome into conditions precedent so that closing does not proceed without regulatory certainty on the licences that drive the target’s revenue.

The practical regulatory due diligence checklist, by legal area

This is the operational core of any fintech M&A due diligence Indonesia project. The checklist below is organised by legal area. For each, it identifies the documents to request, the red flags that warrant escalation, and the way findings should feed into the purchase agreement through conditions precedent, representations and warranties, and covenants. Buyers should assign a risk rating, High, Medium or Low, to each finding so that the deal team can prioritise remediation and price adjustment.

Corporate and ownership

Establish a clean chain of title before anything else. Verify the ultimate beneficial owners, reconstruct the cap table from incorporation, and confirm that historic foreign investments complied with the applicable investment approvals. Review shareholder agreements for change-of-control clauses, pre-emptive rights, drag-along and tag-along provisions, and any anti-assignment terms that could impede the transfer. Check whether escrow or lock-up arrangements bind existing shareholders.

  • Documents to request. Full cap table history, all shareholder agreements, prior share purchase agreements, evidence of past FDI approvals and OSS/BKPM filings.
  • Red flags. Undisclosed nominee arrangements, foreign ownership above the permitted ceiling, missing historic approvals, or unresolved pre-emptive rights.
  • Deal protections. A condition precedent requiring a clean, verified cap table; sellers’ warranties on beneficial ownership; and indemnities for any historic FDI non-compliance.

Licensing and regulatory compliance

Licensing sits at the heart of fintech M&A due diligence Indonesia because the target’s value depends on its authorisations remaining valid through the transaction. Inventory every OJK licence, every BI payment-system registration, and any exemptions the business relies upon. Establish whether each licence is transferable on a change of control and what the regulator will require. Review all correspondence with the OJK and BI for supervisory actions, warnings, remediation directives or capital conditions.

  • Documents to request. All licences and registrations, complete regulator correspondence, any no-objection letters, and records of past supervisory or enforcement actions.
  • Red flags. Expired or conditional licences, unresolved supervisory directives, licences that cannot survive a change of control, or reliance on informal exemptions.
  • Deal protections. A condition precedent requiring regulator no-objection; a covenant obliging the seller to cooperate on filings; and an indemnity for undisclosed licence non-compliance.

Data protection and PSE registration

Data is frequently where deals stall. Confirm the target’s PSE registration status with Komdigi and verify that the certificate is current and correctly scoped. Under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022), cross-border data transfers require a lawful basis, so map every flow of personal data offshore and confirm the mechanism relied upon. Review data processing agreements with vendors, consent records, retention practices and the outputs of any data protection impact assessments.

  • Documents to request. Komdigi PSE registration certificate, privacy policies, a full data inventory, DPAs with processors, consent records and DPIA results.
  • Red flags. No PSE registration, cross-border transfers without lawful basis, weak or absent DPAs, missing DPIAs, and inadequate consent capture.
  • Deal protections. A condition precedent that PSE registration is remediated pre-close; warranties on data compliance; and an escrow sized to any remediation cost.

AML/CFT and sanctions screening

Financial-crime compliance is a supervisory priority. Test the target’s KYC standards, the quality of its AML/CFT programme, and its record of filing suspicious transaction reports to the Financial Transaction Reports and Analysis Centre (PPATK). Confirm whether the target has faced any adverse enforcement relating to money laundering or sanctions.

  • Documents to request. AML manuals and policies, STR logs, transaction-monitoring records, and any regulator audit reports.
  • Red flags. Weak KYC onboarding, unfiled or late STRs, no independent AML audit, or adverse regulator findings.
  • Deal protections. Warranties on AML compliance and indemnities for pre-close financial-crime liabilities.

IP, technology and open-source risk

A fintech’s core code is often its principal asset, so confirm ownership. Verify that all contributors, including contractors and founders, assigned their rights, and cross-check registered marks and any patents against the DGIP record to confirm chain of title. Audit third-party dependencies and open-source licences for copyleft obligations that could compromise proprietary code.

  • Documents to request. IP assignment agreements, contributor agreements, source-control evidence, open-source licence audits, and DGIP registration extracts.
  • Red flags. Unassigned founder or contractor code, copyleft contamination, or registered IP that does not sit with the target.
  • Deal protections. Warranties on IP ownership, remediation of assignments as a condition precedent, and consideration of software escrow.

Operational resilience and outsourcing

Fintechs depend on outsourced infrastructure, so a robust fintech due diligence checklist examines vendor continuity. Review cloud arrangements, disaster recovery and business continuity plans, and any independent assurance such as SOC reports. Confirm that key vendor contracts survive a change of control or can be novated without disruption.

  • Documents to request. Vendor and cloud contracts, continuity and disaster-recovery plans, and third-party audit or assurance reports.
  • Red flags. Vendor contracts with change-of-control termination rights, single points of failure, or absent continuity testing.

Tax, customs and foreign exchange

Confirm the target’s tax position, including any unpaid liabilities and the robustness of its transfer-pricing documentation. Where the business imports payment terminals or hardware, review customs declarations. Confirm compliance with Bank Indonesia foreign-exchange reporting where relevant.

  • Documents to request. Tax filings, transfer-pricing studies, customs declarations and FX reporting records.
  • Red flags. Undocumented related-party pricing, unpaid assessments, or missing FX reports.

Employment and benefit liabilities

Review employment contracts, accrued entitlements and the enforceability of restrictive covenants under Indonesian labour law (as amended by the Job Creation Law and its implementing regulations). Quantify severance exposure, which can be significant.

  • Documents to request. Employment files, payroll records and severance calculations.
  • Red flags. Understated severance provisions or unenforceable non-compete clauses relied upon commercially.

Litigation and enforcement checks

Identify all live disputes, investigations and enforcement correspondence. Regulator letters and settlement agreements can reveal risks not otherwise disclosed.

  • Documents to request. Court filings, regulator letters, and settlement or consent agreements.
  • Red flags. Ongoing investigations, unresolved fines, or a pattern of enforcement contact.

Special checklist, buying a bank or digital bank versus a fintech

The intensity of a review changes sharply depending on whether the target is a bank or a non-bank fintech. A bank acquisition in Indonesia is materially heavier than a payment-service provider deal, because the OJK applies rigorous change-of-control approvals, minimum capital expectations and fit-and-proper testing to controlling shareholders. For a non-bank fintech, the focus tends to shift toward data, PSE status, intellectual property and vendor continuity. Buyers should also decide whether to acquire directly or through a local special-purpose vehicle, a choice that interacts with foreign-ownership rules and tax structuring.

Issue / Approval Fintech (non-bank PSP) Digital bank / bank acquisition
Regulator(s) involved Komdigi, OJK (if licensed), BI (payment systems) OJK (primary), BI (if payment systems), BKPM for foreign investor filings
Licence transferability Often limited; surrender and re-application common Strict OJK change-of-control approvals; capital and fit-and-proper checks
Typical timeline Several months (depending on PSE and data fixes) Substantially longer (OJK/BI approvals, remediation)
Key DD focus Data/PSE, IP, AML, vendor continuity Capital adequacy, governance, regulatory enforcement history

For bank targets, expect additional conditions precedent: OJK approval of the acquirer, satisfaction of fit-and-proper standards for proposed controllers and directors, and confirmation of capital adequacy against the OJK’s current minimum core-capital requirements. These requirements are difficult to compress, so a buyer should build them into the timetable from the outset rather than treating them as closing formalities.

Foreign ownership limits for fintech and digital bank acquisitions

Foreign investors must confirm the applicable ownership ceiling before committing capital. The Ministry of Investment/BKPM administers the investment regime and the sectoral rules, anchored in the Investment Law and the “Positive Investment List” issued under implementing regulations, that determine how much of a target a foreign acquirer may hold. Some fintech activities permit foreign majority ownership, while certain regulated activities carry specific restrictions or conditions. Because the position varies by activity, the correct approach is to classify the target’s business lines precisely (by reference to the applicable Indonesian business classification, KBLI) and confirm each against the current rules rather than assuming a single ceiling applies across the group.

This crosswalk matters because BKPM clearance interacts with OJK and BI approvals. A structure that satisfies the ownership rules may still fail if the OJK is not comfortable with the ultimate controller, and vice versa. Foreign buyers should therefore sequence investment confirmation alongside regulator engagement, and consider whether a local SPV or a phased acquisition better fits the applicable limits. Getting this wrong is not a technicality: an ownership breach can invalidate the transaction or trigger unwinding, which is why foreign-ownership analysis belongs at the front of any cross-border fintech M&A Indonesia workstream.

Timelines and practical closing strategies

Realistic scheduling is what separates a smooth deal from a stalled one. As the comparison table shows, non-bank fintech transactions commonly close within a few months where PSE and data gaps are fixed, while bank and digital-bank acquisitions frequently run considerably longer once OJK and BI approvals and any remediation are factored in. These are planning ranges, not guarantees; the actual duration depends on the target’s compliance posture and the regulators’ workload.

Practical strategies help compress the calendar. Run filings in parallel where the rules permit, rather than waiting for one approval before starting the next. Use staged closings so that non-regulated elements can complete while approvals remain outstanding. Deploy escrow and holdbacks to bridge residual regulatory risk, and impose interim management covenants so the target continues to operate compliantly between signing and completion.

Sample timeline matrix

Milestone Fintech (non-bank) Bank / digital bank
Confirm licences, PSE status and ownership ceiling Early stage Early stage
Submit investment / BKPM filing (foreign acquirer) Early stage Early stage
Regulator engagement (OJK / BI) Mid stage, several months Extended, potentially many months
Remediate PSE / data gaps Concurrent Concurrent
Closing Within several months Substantially longer

The message from the matrix is to submit concurrently and remediate in parallel. Sequential filings almost always extend the timetable beyond what commercial parties will tolerate.

Drafting deal protections and remediation paths

Diligence findings are only useful if they are reflected in the transaction documents. A disciplined fintech M&A due diligence Indonesia review feeds directly into representations and warranties, conditions precedent, covenants and indemnities. Model the representations to cover licensing validity, PSE registration, data compliance, AML standards and IP ownership. Size the escrow to the identified regulatory exposure, and secure specific indemnities for undisclosed licence non-compliance rather than relying on general warranty cover.

Buyers should also negotiate a regulatory-engagement covenant obliging the seller to cooperate fully with filings, and consider limited step-in rights that allow the buyer to influence remediation before closing. Completion adjustments can be used where remediation costs are quantified during diligence.

Recommended conditions precedent for regulatory approvals

At a minimum, make closing conditional on receipt of OJK approval or no-objection where a licensed entity is involved, on any required BI clearance for payment participants, on confirmation of the investment/BKPM position for foreign acquirers, and on remediation of any PSE registration or data-transfer gap. Draft each condition so that it identifies the specific approval, the responsible party for obtaining it, and a long-stop date after which either party may walk away. Vague conditions invite disputes; precise conditions keep the timetable honest.

Remediation roadmaps when PSE or data gaps are discovered

When diligence reveals a missing PSE registration or an unlawful cross-border transfer, do not simply price the risk and proceed. Build a remediation roadmap that sets out the corrective steps, the responsible owner, the sequence and the deadline. For PSE gaps, that means completing registration with Komdigi before or immediately after closing depending on operational risk. For data transfers, it means establishing a lawful basis and updating DPAs. Where remediation cannot complete before closing, tie the outstanding items to escrow release and to a covenant compelling completion within a fixed period.

Post-close integration checklist

Completion is not the finish line. A structured post-close programme protects the value the deal was intended to capture and keeps the acquired business compliant during transition.

  • Update licences and registrations. Reflect the new ownership on OJK and BI records and confirm any conditions attached to approval have been met.
  • Re-register or update the PSE if required. Where the change of control or data-processing arrangements alter the PSE scope, update the Komdigi record promptly.
  • Refresh data processing agreements. Align DPAs and privacy notices with the new group structure and confirm the lawful basis for any transfers.
  • Transfer payment integrations. Confirm that switching, settlement and bank integrations continue uninterrupted under the new ownership.
  • File change-of-control notices. Submit any outstanding notifications to regulators (including any KPPU merger notification if thresholds are met) and update public disclosures where required.
  • Migrate customer data lawfully. Any consolidation of customer data across the group must rest on a documented legal basis.

Practical examples and short case studies

Composite, illustrative examples show how these principles play out. In a successful cross-border acquisition of a payment-service provider, the buyer confirmed PSE status and the foreign-ownership ceiling early, ran the investment filing in parallel with OJK engagement, and remediated a minor data-transfer gap through updated DPAs before closing. Early classification of the target’s activities avoided any ownership breach, and precise conditions precedent kept the timetable on track.

By contrast, a deal that ignored data compliance stalled badly. Diligence uncovered a lapsed PSE registration and cross-border transfers without a lawful basis, discovered too late to remediate before the intended completion date. The parties were forced to renegotiate, introduce a larger escrow, and add a remediation covenant, pushing closing out significantly. The lesson is consistent: treat PSE and data verification as gating items in every fintech M&A due diligence Indonesia project, not as second-order concerns.

Conclusion and next steps

Fintech M&A due diligence in Indonesia rewards buyers who plan for the regulatory reality rather than the commercial ideal. The distributed oversight of the OJK, Bank Indonesia, Komdigi and BKPM means that approvals, data checks, foreign-ownership analysis, licensing transferability, IP and tax must all be addressed in a single, coordinated workstream. Map the regulators early, request the right documents, rate every finding for risk, and translate the results into precise conditions precedent, warranties and indemnities. Sequence filings in parallel, remediate PSE and data gaps before they threaten closing, and carry the discipline through to post-close integration. Buyers who follow a structured, lawyer-led checklist close faster, price risk accurately, and avoid the enforcement exposure that catches less prepared acquirers.

For tailored due diligence support, contact us through the Technology practice, Indonesia.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Putu Raditya Nugraha at UMBRA – Strategic Legal Solutions, a member of the Global Law Experts network.

Sources

  1. Otoritas Jasa Keuangan (OJK)
  2. Bank Indonesia (BI)
  3. Ministry of Communication and Digital Affairs (Komdigi)
  4. Ministry of Investment / BKPM
  5. Directorate General of Intellectual Property (DGIP)
  6. National Legislation Portal (peraturan.go.id)
  7. JDIH, State Secretariat Legal Documentation
  8. Mahkamah Agung (Supreme Court of Indonesia)

FAQs

What regulatory approvals are required to acquire a fintech or bank in Indonesia?
It depends on the target’s licences and structure. A bank or digital-bank acquisition engages the OJK as the primary regulator, with Bank Indonesia involved where payment systems are affected. A licensed fintech may require OJK approval and BI clearance for payment activities, while Komdigi governs PSE registration and the PDP Law governs data compliance. Foreign acquirers additionally file through the investment regime administered by BKPM. Change-of-control clauses in shareholder agreements, and any KPPU merger notification where thresholds are met, should also be checked.
Non-bank fintech transactions typically close within a few months where PSE and data gaps are remediated. Bank and digital-bank acquisitions generally take considerably longer, driven by capital, governance and fit-and-proper checks. These are planning ranges and vary with the target’s compliance posture and the regulators’ workload.
It depends on the activity and the applicable ownership rules under the current Positive Investment List. Some fintech activities allow foreign majority ownership, while certain regulated activities carry restrictions or conditions. Classify each business line precisely and confirm the applicable ceiling with BKPM and the relevant sectoral regulator before committing.
The most common issues are a missing or mis-scoped Komdigi PSE registration, cross-border data transfers without a lawful basis under the PDP Law, weak data processing agreements, absent data protection impact assessments, and inadequate consent records. Each should be verified early and remediated before closing.
Tailored representations and warranties, escrow and specific indemnities for regulatory liabilities, conditions precedent tied to regulator approvals, a regulatory-engagement covenant, and completion adjustments where remediation costs are quantified. Together these allocate regulatory risk fairly and keep the timetable disciplined.
Specialism
Country
Practice Area
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Fintech M&A in Indonesia 2026: a Practical Regulatory Due Diligence Checklist

Send welcome message

Custom Message