Managing Regulatory Due Diligence for Cross-Border Investors in Financial and Digital Asset Businesses
Introduction:
Cross-border investments in financial services and digital asset businesses present unique regulatory challenges that extend well beyond traditional legal or financial due diligence. Whether an investor is acquiring a licensed payment service provider, a securities business, a digital asset exchange, or a fintech company operating under sector-specific regulation, the value of the transaction can depend as much on the target’s regulatory standing as on its commercial performance.
Unlike ordinary commercial businesses, regulated entities operate under continuing supervision. Their ability to conduct business depends not only on maintaining the necessary licenses but also on demonstrating ongoing compliance with governance requirements, prudential standards, anti-money laundering obligations, cybersecurity controls, and consumer protection rules. A company with strong financial performance may nevertheless represent a significant acquisition risk if its regulatory compliance has deteriorated or if it is subject to undisclosed supervisory concerns.
For cross-border investors unfamiliar with the Thai regulatory landscape, regulatory due diligence is therefore not merely a legal exercise. It is an essential component of transaction risk assessment and should begin early in the acquisition process.
Looking Beyond the License:
One of the most common misconceptions among foreign investors is that verifying the existence of a regulatory license is sufficient. In reality, the existence of a license represents only the starting point of the analysis.
Many regulated businesses have evolved over time, expanding their products and services beyond the scope originally contemplated when their licenses were granted. A fintech company may initially have operated as an electronic payment platform before introducing digital lending, cross-border remittance services, or digital asset-related products. Each new business activity may require separate regulatory approval or may be subject to different supervisory requirements.
Regulatory due diligence should therefore examine whether every revenue-generating activity falls within the scope of the target’s existing licenses and whether any exemptions relied upon remain available. It is equally important to determine whether any license conditions have been imposed by regulators and whether the company has complied with those conditions throughout its operations.
Regulatory Approval May Determine Whether the Transaction Can Close:
Unlike acquisitions involving ordinary commercial companies, transactions involving regulated financial businesses frequently require regulatory approval before completion. In some sectors, a change in significant shareholding or control may not become legally effective until the relevant regulator has approved the transaction. Other regulatory regimes may require post-closing notifications or impose “fit and proper” assessments on incoming shareholders, directors, or senior management.
Consequently, regulatory due diligence should identify not only the approvals required for the target’s day-to-day operations but also those triggered by the proposed acquisition itself. Failure to identify these requirements early can delay completion, affect financing arrangements, or require restructuring of the transaction.
Cross-border investors should also consider whether foreign ownership restrictions, residency requirements, or limitations on board composition may influence the post-closing governance structure.
Compliance Culture Often Matters More Than Written Policies:
Modern financial regulators increasingly assess how compliance operates in practice rather than whether a company simply maintains a complete set of written policies.
Accordingly, regulatory due diligence should extend beyond reviewing compliance manuals and internal procedures. Investors should seek evidence that compliance functions are adequately resourced, that internal reporting mechanisms operate effectively, and that senior management actively oversees regulatory risk.
The company’s interactions with regulators may provide particularly valuable insight. Inspection reports, supervisory correspondence, warning letters, remediation plans, and historical enforcement actions often reveal recurring compliance weaknesses that are not apparent from corporate documentation alone. Even where no formal penalties have been imposed, repeated supervisory findings may indicate weaknesses in governance or internal controls that require significant remediation after closing.
Technology Risk Has Become a Core Regulatory Issue:
Technology is now central to regulatory supervision of financial institutions and digital asset businesses. Cybersecurity failures, operational disruptions, and weaknesses in technology governance increasingly attract regulatory attention regardless of whether they result in customer losses.
For investors, this means regulatory due diligence should include an assessment of cybersecurity governance, incident response procedures, disaster recovery planning, outsourcing arrangements, cloud service management, and operational resilience frameworks. Businesses operating digital asset platforms should also be assessed for wallet security, custody arrangements, transaction monitoring systems, and market surveillance capabilities.
Technology deficiencies may not immediately affect valuation but can require substantial investment after completion to satisfy regulatory expectations.
AML and Financial Crime Controls Remain High-Risk Areas:
Anti-money laundering and counter-terrorism financing compliance continues to be among the highest enforcement priorities for financial regulators. Deficiencies in customer due diligence, transaction monitoring, sanctions screening, or suspicious transaction reporting can expose regulated businesses to substantial regulatory sanctions and reputational damage.
Investors should therefore evaluate not only the target’s written AML policies but also the effectiveness of their implementation. Questions such as how high-risk customers are identified, how beneficial ownership is verified, and how suspicious transactions are escalated can provide a clearer picture of the target’s compliance maturity than policy documents alone.
Where previous regulatory inspections have identified AML deficiencies, investors should assess whether remediation has been completed and whether regulators remain satisfied with the company’s corrective measures.
Data Protection and Outsourcing Should Not Be Overlooked:
Financial institutions increasingly rely on external service providers for cloud infrastructure, customer verification, payment processing, and cybersecurity services. While outsourcing may improve operational efficiency, regulators continue to emphasize that responsibility for regulatory compliance ultimately remains with the licensed entity.
Accordingly, regulatory due diligence should review the contractual framework governing outsourced services, the company’s oversight of critical vendors, and its contingency planning should key service providers become unavailable.
Similarly, businesses handling significant volumes of customer information should be assessed for compliance with personal data protection requirements, particularly where customer information is transferred across borders or processed by third-party vendors.
Due Diligence Findings Should Shape Transaction Documents:
Regulatory due diligence should not end with the preparation of a report. Its findings should directly influence transaction structuring and the allocation of risk between buyer and seller.
Where significant compliance concerns are identified, investors may seek enhanced representations and warranties regarding licensing, regulatory compliance, anti-money laundering controls, cybersecurity, and data protection. Specific indemnities may be appropriate for known regulatory investigations or historical compliance failures. In some cases, buyers may also require identified deficiencies to be remediated as conditions precedent before closing.
Integrating regulatory due diligence into transaction documentation helps ensure that regulatory risks are appropriately allocated and reduces the likelihood of post-completion disputes.
Conclusion:
As financial regulation becomes increasingly complex and technology-driven, regulatory due diligence has evolved from a narrow licensing review into a comprehensive assessment of an institution’s regulatory health. For cross-border investors, understanding how a target interacts with regulators, manages compliance risks, and maintains operational resilience is often as important as evaluating its financial performance.
A well-executed regulatory due diligence exercise enables investors to identify hidden regulatory exposures, anticipate approval requirements, negotiate more effective contractual protections, and develop realistic post-acquisition integration plans. In regulated financial and digital asset sectors, it is often the quality of regulatory compliance—not simply the quality of the business—that ultimately determines whether an investment achieves its intended value.
Key Takeaways:
- In acquisitions involving financial and digital asset businesses, robust regulatory due diligence is essential to preserving investment value and minimizing post-closing regulatory exposure.
- Regulatory due diligence should evaluate the target’s overall regulatory health rather than simply confirming the existence of licenses.
- Investors should assess governance, supervisory history, AML/CTF controls, cybersecurity, data protection, outsourcing arrangements, and change-of-control requirements alongside licensing compliance.
- Early identification of regulatory risks helps facilitate transaction planning, regulatory approvals, and appropriate contractual risk allocation.
Author: Panisa Suwanmatajarn, Managing Partner.
Other Articles
- Consumer Enforcement Intensifies for EV Businesses as Complaint Cases Rise and Labeling Expectations Increase
- TCCT Establishes Two Subcommittees to Strengthen Trade Competition Oversight
- NBTC Issues AI Governance Guidelines for Telecom Licensees
- Thailand Revises Visa Exemption Scheme: Shorter Stay Periods and a New Country-Based Category System
- Thailand Responds to U.S. Section 301 Review: Trade Negotiations, Regulatory Reforms and Business Implications
- Thailand Moves to Expand Access to Altruistic Surrogacy Following Marriage Equality