Big Ideas, Real Impact.
See the regulatory risk before it becomes deal risk.
Clearhaven helps investors, acquirers and financial institutions understand the regulatory and financial crime exposure inside fintech and crypto businesses.
We identify the issues that could affect valuation, regulatory approval, integration or future growth, then explain what they mean for the transaction.
Regulatory due diligence that follows the business
A regulated status does not tell you how well a firm is run.
Permissions may not cover the full business model. Compliance controls may have fallen behind growth. Safeguarding records may be unreliable. Regulator correspondence may contain unresolved issues that have yet to reach the board.
Our review follows the product, customer journey, funds flow, governance, technology and control evidence. The scope is shaped around the transaction and the decisions that need to be made.
Fintech and payments due diligence
We conduct regulatory due diligence on payment institutions, electronic money institutions, embedded finance providers, digital wallets, remittance businesses, open banking firms and other regulated fintechs.
Our review can cover:
Regulatory permissions and business activities
Payment institution and EMI authorisation status
Regulatory perimeter and unregulated services
Safeguarding arrangements and reconciliations
Capital, liquidity and prudential requirements
AML, sanctions, fraud and transaction monitoring
Customer onboarding and risk classification
Consumer outcomes, complaints and disclosures
Governance and management responsibilities
Agents, distributors and commercial partners
Outsourcing and operational resilience
Regulatory reporting and notification history
Open regulatory findings and remediation
Change in control requirements
We focus on the areas most likely to create financial exposure, regulatory delay or operational disruption after completion.
Crypto and digital asset due diligence
Crypto businesses require a different level of scrutiny.
The regulatory position can depend on the assets, services, customers, legal entities and countries involved. A group may hold a registration in one jurisdiction while providing wider services through entities with a less certain regulatory status.
We support due diligence on crypto exchanges, custodians, brokers, wallet providers, trading platforms, stablecoin businesses, token issuers and blockchain-based financial services.
Our crypto regulatory due diligence can cover:
MiCA and CASP authorisation status
UK cryptoasset registration and regulatory readiness
Services provided in each jurisdiction
Cross-border activity and market access
Token and cryptoasset classification
Custody and protection of client assets
Wallet governance and key management
AML, sanctions and blockchain analytics
Source of funds and source of wealth controls
Crypto transaction monitoring
Travel Rule compliance
Market abuse and conflicts of interest
ICT risk, DORA and operational resilience
Banking and payment partner dependencies
Outsourcing and critical service providers
Regulatory enquiries, investigations and enforcement history
The review gives the transaction team a clear view of where the business stands today and what may need to change under new ownership.
Financial crime due diligence
Weak financial crime controls can create substantial exposure for an investor or acquirer.
We assess whether the firm’s AML and sanctions framework reflects its customers, products, transaction flows and geographic reach. We also test whether the controls described in policies are supported by operational evidence.
This can include:
Business-wide financial crime risk assessment
Customer due diligence and enhanced due diligence
Customer risk-rating methodology
PEP and sanctions screening
Transaction monitoring rules and alert handling
Blockchain analytics and wallet screening
Fraud controls and account restrictions
Suspicious activity reporting
Management information and board oversight
Quality assurance and independent testing
Backlogs, control failures and remediation programmes
Where weaknesses are identified, we assess their scale, likely cause and potential effect on the transaction.
Due diligence for investments, acquisitions and partnerships
Clearhaven supports:
Private equity and venture capital investors
Strategic acquirers
Banks and financial institutions
Fintech and crypto businesses making acquisitions
Firms entering embedded finance partnerships
Boards assessing new products or markets
Legal and transaction advisory teams
Our work can support an initial investment, full acquisition, minority stake, joint venture, commercial partnership or entry into a regulated market.
What you receive
Red-flag review
A focused assessment of the most material regulatory and financial crime risks, completed around the transaction timetable.
Full regulatory due diligence
A detailed review of the target’s regulatory position, governance, compliance framework, control environment and regulatory history.
Clear transaction implications
Each finding is linked to its potential effect on regulatory approval, deal timing, operating costs, integration or future growth.
Management questions
Targeted questions for management, compliance leaders and advisers based on the issues identified during the review.
Remediation assessment
A practical view of the work required, including priorities, dependencies and the resources likely to be needed.
Post-deal plan
A structured compliance and regulatory plan for the first phase of ownership, focused on the risks that need early attention.
How we work
Define the real scope
We identify the products, entities, jurisdictions and regulatory questions that matter to the transaction.
Review the evidence
We examine policies, governance records, regulatory correspondence, management information, customer journeys and control outputs. Interviews with management and key control owners help establish how the business operates in practice.
Explain the impact
Findings are written for decision-makers. The report sets out the issue, supporting evidence, potential exposure and the action required.
Senior practitioners throughout
Our regulatory due diligence is led by senior practitioners with more than 20 years of experience across regulation, industry and consulting.
The team includes former leaders of regulatory units, Heads of Compliance, MLROs, COOs, CEOs and Big Four partners. Our experience includes regulatory supervision, fintech and crypto authorisation, financial crime investigations, complex remediation and large-scale operational transformation.
This allows us to assess the control issue itself and understand what it would take to fix it after the transaction.
Understand the risk before you commit
Tell us about the transaction, the target and the decisions you need to make. We will define a focused regulatory due diligence scope around your timetable.
Frequently Asked Questions
-
Fintech regulatory due diligence assesses whether a business has the correct permissions, meets its regulatory obligations and operates effective compliance controls. It helps investors and acquirers understand risks that may affect the transaction or create liabilities after completion.
-
Legal due diligence establishes the firm’s legal obligations, contracts and potential liabilities. Regulatory due diligence looks more closely at how the business operates, whether its permissions match its activities and whether its compliance controls work in practice.
The two workstreams are complementary.
-
A crypto due diligence review can cover licensing, MiCA and CASP readiness, UK crypto regulation, custody, client assets, AML, sanctions, blockchain analytics, the Travel Rule, operational resilience and cross-border activity.
The scope depends on the services, assets and jurisdictions involved.
-
A change in ownership or control can require prior notification or approval from the relevant regulator.
In the UK, this can apply to acquisitions of authorised payment institutions and electronic money institutions. MiCA also provides for the regulatory assessment of proposed acquisitions of qualifying holdings in authorised CASPs.
The applicable thresholds and process depend on the ownership structure and jurisdiction.
-
The review should begin early enough for findings to influence the transaction. An initial red-flag assessment can identify the areas that require deeper investigation before signing.
-
Yes. We can turn the due diligence findings into a prioritised remediation plan and support delivery, governance, regulatory engagement and compliance integration after completion.
-
The timetable depends on the transaction, target and scope. We can provide an accelerated red-flag review or a more detailed assessment aligned with the wider due diligence process.

