In brief
Cryptoasset firms operating in the UK or dealing with UK consumers are likely to need full Financial Conduct Authority (FCA) authorisation from October 2027. With the FCA’s “gateway” for applications opening soon – on 30 September 2026 – firms should be preparing now for life under the new regime. The FCA regime imposes broad regulatory and supervisory requirements similar to those applying to traditional financial services, many of which will be completely new to crypto firms seeking to enter the regulated space and, therefore, is likely to require a significant uplift of internal policies, controls, procedures and documentation even for firms currently registered with the FCA or in other jurisdictions. Importantly, the new regime has a wide territorial scope. Firms dealing with UK customers from overseas should therefore consider as a priority whether they may require a UK, FCA-regulated entity in order to comply with the new regime. In this Briefing, we provide a short checklist of points for firms to think about as part of their preparations. You can read more about the scope of the new regime in our earlier alert.
In more detail
As noted, the FCA’s authorisation gateway is expected to open on 30 September 2026. Cryptoasset firms doing (or planning to do) business in the UK should therefore review their current and planned activities now to determine whether they fall within scope and which specific permissions they may require from FCA, so that any authorisation application is framed correctly. Firms that expect to require authorisation should be engaging with the process now, to ensure they are prepared to move quickly once the gateway opens. In particular, firms new to FCA authorisation should think about the following key considerations:
- Check whether you can meet the FCA’s Threshold Conditions. The “Threshold Conditions” are the key baseline expectations, set out in legislation, that all firms need to meet in order to become and remain FCA-authorised. If your firm is incorporated in the UK, your head office should be located in the UK, and the FCA will expect key decision-making generally to take place there. Applications from firms with limited UK substance, which are largely governed by overseas management, are likely to be viewed negatively by the FCA. Your business model must be suitable for the cryptoasset services and activities you intend to undertake, and you must have adequate financial and non-financial resources to deliver on your business plan. Skeleton operations in the UK are unlikely to be accepted by the FCA. Your legal and operational structure must also allow the FCA to supervise the firm effectively, including through adequate and reliable flows of information to the FCA. The FCA may reject applications if a firm repeatedly misses deadlines and fails to provide adequate and accurate information. When preparing for the authorisation gateway, you should think about your resourcing of the application process, and ensure you will be able to respond to follow-ups promptly and are prepared to engage closely with the FCA throughout the process.
- Reflect on your governance structure. The FCA is a sophisticated regulator and is recognised as setting a benchmark internationally regarding its expectations on governance, for example through its Senior Managers and Certification Regime (SMCR). The expectations for newly authorised cryptoasset firms will represent a step up for firms who currently hold anti-money laundering (AML) registration with the FCA in the UK, or which hold authorisations or licenses in jurisdictions with lighter touch oversight regimes. Think now about whether your board and governance arrangements are appropriate for the size, complexity and risk profile of your business. Your board should have the right balance of skills, experience and independence, with appropriate senior representation from key control functions. Make sure the governance arrangements are in place to ensure that the board receives the information it needs to make well-informed decisions, and that directors are able to provide meaningful challenge to the business. Consider whether non-executive directors (NEDs) may be required or appropriate for your business model, scale and risk profile – although having NEDs is not a mandatory requirement for all firms, their presence can provide comfort to the FCA regarding the degree of independent challenge being exercised by the board. For FCA authorised firms, appropriate governance structures are a core FCA focus and poor management information flows, vague lines of responsibility and failure to provide appropriate challenge have all formed part of the FCA’s findings in enforcement cases in recent years.
- Consider your senior management appointments. The SMCR will apply to cryptoasset firms: start mapping out who your senior managers will be, what they will be responsible for and whether they meet the FCA’s fitness and propriety expectations. Senior managers should understand that the SMCR is designed to create clear individual accountability within regulated firms and should be trained on the implications of their role within an FCA regulated firm. The FCA will expect responsibilities to be allocated clearly and documented appropriately, with limited scope for ambiguity as to who is accountable for key business functions. Key holders/candidates for senior management roles may, depending on the firm’s positioning, be required to attend interviews with the FCA, and any such individuals will need to be well prepared. Think about whether any other individuals will need to be certified, and whether your governance documents, reporting lines and statements of responsibilities clearly reflect how the business will be managed in practice. For employees who become subject to the SMCR for the first time, the new responsibilities and risks may feel daunting. You should be prepared to provide practical guidance to employees on what SMCR means for them. If you are currently registered with the FCA under the UK’s AML regime, remember that the fit and proper requirements applying to authorised firms are broader than those under the Money Laundering Regulations (MLRs).
- Develop a clear playbook for identifying, escalating and responding to regulatory issues. Authorised firms are subject to extensive systems and controls obligations, and the FCA has broad supervisory, investigative and enforcement powers. Review your issue escalation policies and internal reporting lines to ensure they are fit for a regulated environment, so that potential problems are identified, assessed and escalated quickly. The FCA has a particular focus on having adequate whistleblowing arrangements and ensuring whistleblowers receive proper protection. Think about how you will engage with the FCA in practice, including under Principle 11, which requires authorised firms to deal with the FCA in an open and cooperative way and to disclose matters of which the FCA would reasonably expect notice. Be ready to assess whether customers have been affected when things go wrong, decide whether remediation is needed and put remediation actions into practice. The FCA's approach to enforcement in the financial services sector demonstrates that it will act swiftly where firms fail to self-identify issues, escalate them appropriately, or engage transparently with the regulator. Building a strong compliance culture from the outset – rather than retrofitting it after authorisation – is essential. The FCA places particular importance on transparency and proactive identification and reporting of potential issues impacting the firm.
- Strengthen your approach to financial crime compliance. Although the requirements under the MLRs will continue to apply as under the current registration regime, the nature of the FCA’s supervision will change once a firm becomes authorised. The FCA is likely to be more proactive around thematic work in the cryptoassets space following authorisation, and will be in a better position to “join the dots" between compliance failings in one area of the business with another, such as financial crime. The FCA will be able to take enforcement action under both the MLRs and its wider Rules – including the Principles – where a firm’s AML, sanctions, counter-fraud or other financial crime compliance falls short. As the FCA has repeatedly warned, the crypto industry’s approach to AML has, in general, fallen short of regulatory expectations, and we expect the regulator to scrutinise crypto firms’ financial crime controls closely, including through supervisory and enforcement action or during the authorisation phase. The FCA also frequently uses its powers to require the appointment of an external, independent “Skilled Person” to review aspects of firms’ compliance frameworks, particularly in the AML space. Authorised firms must also address the wider financial crime framework, including market abuse prevention and sanctions compliance. Your policies and procedures should therefore be sufficient to address the full range of financial crime obligations that will apply. Firms that have operated under the MLRs registration regime should not assume that their existing financial crime frameworks will meet the higher bar expected of FCA-authorised firms, particularly given the extension of the wider FCA framework beyond AML/CTF to encompass other areas of financial crime. A thorough gap analysis is advisable before the gateway opens.
- Prepare core policies and procedures and build the evidence base for your application. The FCA will expect applicants to demonstrate how their governance, risk management, compliance monitoring, financial crime controls, outsourcing arrangements and customer-facing processes will operate in practice. This means having clear policies and procedures, and being able to evidence how they are embedded in the business and supported by appropriate systems, controls and management information. If you deal with retail customers, you should also prepare for more detailed conduct, disclosure, complaints-handling and customer protection expectations. The FCA has signalled that consumer protection in the cryptoasset sector is a priority, and firms offering products or services to retail customers should expect particularly close scrutiny of their customer-facing practices. Preparing policies and procedures that are tailored to your business can take time and this should be built into your application timelines. The robustness of information security architecture is likely to be a key focus area.
- If you are part of a global group, make sure your UK entity can stand on its own. Firms within global groups should consider carefully how their UK operations will be governed and overseen. Your UK entity must be capable of complying with UK regulatory requirements on a standalone basis, including the Threshold Conditions (see above). This means looking closely at where key decisions are made, where senior management is based, how information flows to the UK entity, and whether the UK business has the resources and control it needs to operate in a regulated environment. Think about your outsourcing arrangements: it is common (and acceptable) for certain processes and operations to be outsourced intragroup, but you will need to ensure that the UK entity’s board and senior management have sufficient oversight, contractual rights, information flows and operational control in relation to intragroup outsourcing arrangements. Carry out a gap analysis now to identify where SLAs, outsourcing policies or governance arrangements may need to be strengthened. Global groups should also consider how the UK regime interacts with regulatory requirements in other jurisdictions in which they operate, and whether a coherent cross-border regulatory strategy is needed. Where there are failings/issues which arise in relation to group-wide controls that impact upon the UK entity, processes will need to be in place to ensure timely escalation to the UK entity’s senior management so that the UK implications can be considered and any relevant notifications made to the FCA or other UK authorities.
- If you operate cross-border into the UK, check whether you will need FCA authorisation. If you are based overseas but carry on cryptoasset business in the UK/with UK customers, review your current and planned activities carefully to determine whether you will fall within scope of the new regime. The perimeter of the new regime has been deliberately drawn widely to capture overseas firms where they deal with consumers. Overseas firms should not assume that the absence of a UK establishment means FCA authorisation will not be required. In some cases, firms may fall within scope even where services are provided cross‑border from outside the UK, particularly where retail customers are involved. Assess whether your current cross-border model remains viable and what changes may be needed to satisfy the Threshold Conditions.
Firms that expect to fall within scope should begin preparing their authorisation strategy, gap analysis and supporting documentation now. Early preparation is likely to be particularly important for firms seeking to establish UK operations or adapt existing cross‑border business models.
Our team regularly advises existing businesses and new market entrants on FCA authorisation requirements and regulatory engagement. Please contact any of the authors, or your usual Baker McKenzie contact, to discuss how the new regime may affect your business.