top of page

UK Crypto Regulation 2027: Why FCA Authorisation Is More Than a Licensing Exercise

Aug 12
10 min read

The UK is moving crypto firms from a relatively narrow AML and financial-promotions perimeter into full FSMA regulation. The challenge is not simply completing an application — it is building the governance, prudential, safeguarding and operational framework behind it.


UK crypto regulation is moving into a very different phase.


Until now, many crypto firms have known the Financial Conduct Authority primarily through anti-money laundering requirements and the financial promotions regime.

From October 2027, that relationship is expected to become much broader.


The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 bring a range of cryptoasset activities into the mainstream UK financial-services perimeter. The FCA has now published the main package of rules that will apply to authorised firms, while the dedicated application window opens on 30 September 2026.


It may be tempting to treat the transition as a licensing project: identify the permissions, prepare the documents, submit the application and answer FCA questions.


That would underestimate the change.


For many firms, FSMA authorisation will introduce a much wider framework covering governance, senior-management accountability, conduct, prudential resources, safeguarding, operational resilience, financial crime and regulatory reporting. Different business models will also face activity-specific requirements for areas such as custody, staking, stablecoin issuance and trading platforms.


The application is therefore only the visible part of the project.


The harder task is making sure that the business described in the application actually exists in the firm's governance, systems, controls and day-to-day decisions.


The real shift is from registration to regulation


The difference is particularly important for firms already registered with the FCA under the Money Laundering Regulations.


Existing MLR registration does not convert automatically into FSMA authorisation.


Crypto firms that fall within the new regulated perimeter will need to obtain the relevant authorisation. Firms that are already authorised under FSMA for other activities will need to consider whether their permissions must be varied.


That distinction is more than procedural.


An MLR-registered firm may already have a mature financial-crime framework, customer risk methodology, transaction monitoring, blockchain analytics and established AML governance.


Those arrangements remain valuable.


But they do not, by themselves, demonstrate that the firm is ready to operate as a fully authorised financial-services business.


The new regime asks a broader question.


Not simply:

Does the firm have appropriate AML controls?

But:

Is the business appropriately governed, adequately resourced and capable of meeting its regulatory obligations on an ongoing basis?


That changes where preparation should begin. Not with the application form.

With the business model.


The perimeter has to match the business as it really operates


The new regime covers activities including qualifying stablecoin issuance, cryptoasset safeguarding, operating qualifying cryptoasset trading platforms, principal and agent dealing, arranging transactions and qualifying cryptoasset staking.


But identifying a regulated activity from a list is only the first step. A firm also needs to understand how that activity appears in practice.


Who provides the service? Which legal entity performs it? Where is the activity carried out? Who interacts with the customer? Who holds assets or private keys? Which group entities and third parties are involved? Where are execution and settlement decisions made?


These questions matter because permissions cannot be separated from the operating model behind them.


The FCA's application process reflects this. Crypto-specific parts of the application will depend on what the applicant actually does, and even the FCA's pre-application process expects firms to provide meaningful information about their products, customers and analysis of the regulated activities involved.


A perimeter assessment therefore cannot sit in isolation. It needs to connect to the entity structure, customer journey, governance model, systems and controls that support the activity.


Authorisation starts before the application is submitted


The FCA's preparation guidance is unusually clear on this point.


Firms are expected to determine which permissions they need, compare their current arrangements with the new FSMA requirements, identify gaps and develop a realistic implementation plan agreed at board level.


That plan should establish accountability, the changes required, how they will be delivered and when they will be completed.


This suggests a very different sequence from the traditional "licence pack" approach.


Business model → perimeter → gap analysis → governance decisions → implementation → documentation → evidence → application


The order matters.


Policies should document the operating model being built. They should not be used to create the appearance of one.


That is particularly relevant for firms with an existing MLR policy suite. Reusing existing documents may be efficient, but expanding a policy with additional regulatory language will not fix a missing process, unclear responsibility or system limitation underneath it.


Governance needs to work beyond the organisation chart


FSMA authorisation also changes the role of governance documentation.


The FCA is applying the Senior Managers and Certification Regime to cryptoasset firms, alongside wider systems-and-controls requirements. Responsibilities need to be allocated clearly, senior individuals must be suitable for their roles, and the governance framework has to support effective oversight.


For larger or more complex firms, the requirements become more detailed. But even at the basic level, the practical question is the same:


Who is responsible for what, and can the firm demonstrate it?


Consider a crypto custodian.


It is not enough to identify a senior manager as responsible for safeguarding.


The firm also needs to know who owns private-key risk, who oversees reconciliation exceptions, who monitors third-party custodians, who receives operational incidents and who has the authority to restrict withdrawals during a security event.


Those responsibilities should remain consistent across governance documents, procedures, management information and incident arrangements.


When different documents assign the same decision to different people, that is not simply a drafting problem. It is unclear accountability.


Prudential regulation brings risk assessment closer to strategy


The new prudential framework will be another major adjustment for many crypto businesses.


The FCA has created COREPRU and CRYPTOPRU requirements covering areas such as capital, liquidity, concentration risk, stress testing and wind-down planning.


One of the more important elements is the overall risk assessment. Its purpose is not simply to calculate another capital requirement. It is intended to help the firm assess whether its financial and non-financial resources remain adequate for the risks created by its activities.


That assessment has to sit within the firm's governance and risk-management framework. This matters because prudential risk cannot be separated from business decisions.


A new custody model, an outsourced validator arrangement, expansion into another activity or greater reliance on a group company may alter operational risk, concentration exposure, liquidity requirements or wind-down assumptions.


Risk assessment therefore needs to influence strategy. And strategic decisions need to feed back into the prudential framework.


Safeguarding is a control chain, not a custody policy


Custody provides perhaps the clearest example of why authorisation cannot be solved through documentation alone.


The FCA's new CASS 17 framework introduces detailed requirements for safeguarding client cryptoassets.


The rules address areas including trust arrangements, records, means of access, reconciliations, discrepancies, shortfalls and the use of third parties.


Importantly, the reconciliation framework distinguishes between internal records and external evidence.


A firm calculates what it should be holding from its own books and records, while confirming the resources actually held using independent external information. The point is obvious but important: a reconciliation cannot reliably identify discrepancies if both sides of the comparison come from the same source.


For a custodian, the operating chain therefore looks something like:


client entitlement → cryptoasset records → wallet and key controls → third-party arrangements → reconciliation → exception management → remediation


Every link matters. A detailed safeguarding policy is useful only if the records, systems and responsibilities behind it produce the same result in practice.


Operational resilience has to reflect the actual technology


The same issue appears in the FCA's cryptoasset operational-resilience guidance.


The FCA is applying its existing operational-resilience framework to relevant crypto firms, including requirements around important business services, impact tolerances, dependency mapping and scenario testing.


But crypto introduces dependencies that do not always look like traditional financial-services infrastructure.


Private keys can be compromised. Smart-contract code can fail. Validator services can become unavailable or behave incorrectly. A custodian may depend on MPC or HSM providers. A trading platform may rely on cloud infrastructure and external liquidity providers.


These dependencies need to appear in the resilience framework.


A staking provider that outsources validator operations cannot simply state that "third-party risk is monitored". It needs to understand whether validator services support an important business service, what happens if one fails, how the failure is detected, what alternatives exist and whether customer harm can remain within the firm's impact tolerance.


A custodian faces the same issue with key generation, signing infrastructure, wallet access and recovery.


The resilience map has to describe the technology the business actually depends on.


AML becomes one part of a wider financial-crime framework


Financial crime does not become less important under FSMA. Instead, it sits inside a broader regulatory environment.


The FCA is extending its financial-crime systems-and-controls framework to authorised crypto firms, including expectations around policies and procedures, risk assessments, senior-management responsibility and the MLRO function.


Crypto-specific risks remain relevant. Mixers, tumblers and other anonymity-enhancing technologies do not disappear from the risk assessment, and blockchain analytics remain an important control tool.


What changes is the surrounding governance.


An AML decision may now interact directly with safeguarding, customer communications, complaints handling, operational processes and regulatory reporting.


A wallet restriction, for example, is not only a financial-crime event. It may also affect access to client assets, operational procedures and customer outcomes.


That is why financial-crime controls cannot be designed as a self-contained AML framework.


Trading platforms face a broader market-integrity role


For qualifying cryptoasset trading platforms, the shift goes even further.


The new framework introduces admissions and disclosure requirements alongside a dedicated Market Abuse Regime for Cryptoassets.


The platform's control environment therefore extends beyond onboarding customers and monitoring transactions for financial crime. It also needs to address asset admission, disclosure, conflicts, trading behaviour, inside information and market-abuse surveillance.


This is a meaningful change in the role of compliance. The firm is no longer looking only at the customer. It is also looking at the integrity of the market it operates.


Stablecoin issuance requires its own operating model


Stablecoin issuers face a different architecture again.


The FCA's final framework for UK-issued qualifying stablecoins covers backing assets, safeguarding, redemption and disclosure, including the use of a statutory trust for the backing asset pool.


That creates another connected chain:


issuance → backing assets → safeguarding → reconciliation → liquidity → redemption → disclosure


The controls required for this business are not the same as those required for a trading platform, custodian or staking provider.


That is an important practical point for implementation.


There is no single "UK crypto compliance framework" that can simply be adapted by changing the firm's name and services. The documentation and controls have to follow the activity.


International firms need real UK substance


The position of international crypto groups is another area where operating reality matters.


The FCA's baseline expectation is that firms requiring UK authorisation will conduct regulated cryptoasset activities through a UK legal entity, subject to limited exceptions.


But incorporation alone is not enough.


For effective supervision, the FCA is also interested in where control functions, leadership and meaningful decision-making sit. Its international-firms guidance refers expressly to maintaining an appropriate amount of "mind and management" in the UK.


That can create difficult questions for global groups.


A UK company may exist on paper while technology, compliance expertise, product decisions, risk management and senior leadership remain concentrated elsewhere.


An authorisation project therefore needs to establish more than where the company is registered. It needs to show what the UK business actually controls.


The transitional provision is not extra time to keep growing


The transitional arrangements also need to be understood carefully.


They are designed for orderly run-off, not as an extension of the authorisation deadline.


An eligible firm operating under the transitional provision may carry on regulated cryptoasset activities only to the extent necessary to perform contracts that already existed before it entered the provision.


It cannot use the period to enter into new contracts with new UK customers or even new contracts with existing UK customers.


That makes preparation before commencement commercially important. A firm that intends to continue building its UK business cannot treat transitional run-off as a substitute for authorisation readiness.


What readiness should look like


A useful readiness exercise should therefore test the connections between the firm's major regulatory components.


Does the proposed perimeter match the business model?


Do the permissions being requested match the customer journeys and legal entities actually delivering the service?


Do governance responsibilities correspond to those permissions?


Does the risk framework cover the same services and dependencies shown in the operational-resilience map?


Do safeguarding records match the real wallet and key architecture?


Do outsourcing and third-party arrangements capture the providers on which important services depend?


Does the prudential assessment reflect the risks created by those dependencies?


And does management information allow senior managers to see whether the controls for which they are responsible are actually working?


These questions reveal more about readiness than asking whether every required policy has been drafted. A firm can have a complete document set and still have an incomplete regulatory operating model.


Lynsora perspective


The UK crypto regime is often described as the arrival of full FCA regulation for cryptoassets.


For firms, the change is more fundamental.


It moves many businesses from a framework centred largely on AML and financial promotions into one where the FCA assesses the organisation as a financial-services firm: its business model, governance, resources, conduct, safeguarding arrangements, operational resilience and ability to remain compliant after authorisation.


That makes readiness an implementation exercise before it becomes an application exercise. The application should describe the outcome of that work. It should not be the place where the work begins.


A credible authorisation framework needs to connect:


what the firm does → what permissions it needs → who is accountable → what risks arise → which controls manage them → how those controls operate → what evidence demonstrates that they work


The difficult part of FCA authorisation may therefore not be producing the documents required for the gateway.


It will be ensuring that those documents describe a firm that actually exists.

The real test of UK crypto authorisation will be whether the business described to the FCA can be recognised in the firm's governance, systems, controls and day-to-day decisions.

Official sources


Disclaimer


This article is provided for general information purposes only and does not constitute legal, regulatory or professional advice.


Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page