top of page

FCA Compliance for UK Cryptoasset Providers 2026: Complete Guide

  • 1 day ago
  • 14 min read
FCA Compliance for UK Cryptoasset Providers 2026: Complete Guide

UK cryptoasset compliance sits between two regulatory frameworks in 2026. Firms carrying on current in-scope cryptoasset exchange or custodian wallet activities remain subject to FCA registration and supervision under the Money Laundering Regulations, while cryptoasset financial promotions are already governed by the UK financial promotions regime. At the same time, the FCA has now finalised most of the rules for the new FSMA cryptoasset regime expected to commence on 25 October 2027, meaning firms need to operate compliantly today while building for a materially broader future authorisation framework.


The future regime is not simply an expanded AML registration. FCA-authorised crypto firms will be subject to activity-specific permissions, the Consumer Duty where applicable, COBS conduct requirements, SMCR, operational resilience, complaints and redress, financial crime controls, prudential requirements under COREPRU and CRYPTOPRU, CASS 17 custody requirements and new crypto market conduct rules. The main FCA application window is scheduled to open on 30 September 2026 and close on 28 February 2027, so 2026 is now a regulatory transition year rather than a distant planning period.


UK crypto compliance requirements at a glance

Area

2026 position

Money Laundering Regulations

Current FCA registration and AML supervision continues until the new regime commences

Crypto financial promotions

Already in force for qualifying cryptoasset promotions to UK consumers

FSMA crypto authorisation

New regime expected to commence 25 October 2027

Main application window

Scheduled for 30 September 2026 to 28 February 2027

Consumer Duty

Final FCA framework applies to relevant future authorised crypto activities, subject to scope and exclusions

COBS

Conduct rules apply to relevant crypto services under the future framework

CASS 17

New safeguarding regime for qualifying cryptoasset custody

COREPRU and CRYPTOPRU

New capital, liquidity and prudential framework

SMCR and Conduct Rules

Future authorised crypto firms come within the accountability framework according to final rules

Operational resilience

FCA final guidance applies to future authorised crypto firms

CRYPTO sourcebook

Admissions, disclosures, market abuse and activity-specific crypto rules

DISP and FOS

Complaints and redress framework applies according to scope

Financial crime

AML, sanctions, fraud and broader systems and controls remain central


The FCA's new regime for cryptoasset regulation should be the starting point for transition planning. The regulator published its major final rules and guidance package on 30 June 2026, with those rules designed to apply to firms granted permission to carry on the new regulated cryptoasset activities on or after commencement. Existing MLR registration does not automatically convert into FSMA authorisation.


Current MLR registration remains a live requirement

Until the new FSMA regime starts, businesses carrying on in-scope cryptoasset exchange provider or custodian wallet provider activities in the UK remain subject to the Money Laundering Regulations and FCA registration requirements. Registered firms must maintain appropriate business-wide and customer risk assessments, due diligence, enhanced due diligence, ongoing monitoring, transaction monitoring, sanctions controls and suspicious activity reporting. They should also maintain governance and evidence capable of demonstrating that the framework operates effectively in practice.


The current regime is narrower than the future FSMA framework, but it should not be treated as light-touch regulation. The FCA has historically scrutinised crypto firms closely on ownership, business models, source of funds, customer risk, transaction monitoring and management capability. Weaknesses identified during current supervision can also affect the credibility of the firm's future FSMA application.


Existing firms should therefore use the current MLR control environment as the foundation for transition. Strong customer-risk methodology, transaction monitoring, governance and regulatory engagement history can all support future authorisation, while unresolved AML findings should be remediated before the new application is submitted. A firm should not assume that the FCA will disregard its existing supervisory history when assessing full authorisation.


Existing registration will not convert automatically into authorisation

The move from MLR registration to FSMA authorisation is one of the most important changes for existing UK crypto businesses. The FCA has confirmed that registration under the Money Laundering Regulations does not automatically become permission under the new regime. Firms that intend to continue carrying on activities that become regulated must apply for the appropriate Part 4A permissions.


This transition is broader than updating existing AML documents. The firm needs to map the new regulated activities, determine which permissions apply, assess whether its legal entity and governance remain appropriate and build the conduct, prudential, client-asset and operational framework required by the final FCA rules. The regulatory business plan, financial forecasts, policies and controls should describe one coherent future operating model.


Firms should also consider the timing of application carefully. The main application window is intended to provide a route for firms to be assessed before commencement and to access applicable saving provisions where the statutory conditions are met. Waiting until late in the transition can create significant business-continuity risk.


The future regulatory perimeter is much broader

The new regime brings a range of cryptoasset activities into FSMA regulation. Depending on the model, activities can include operating a qualifying cryptoasset trading platform, safeguarding qualifying cryptoassets, dealing as principal or agent, arranging transactions, staking, certain lending or borrowing activities and issuing qualifying stablecoins. A single platform can therefore require several permissions.


The perimeter analysis should follow the actual customer journey rather than the commercial label used by the business. An exchange may also safeguard customer assets, a staking service may have custody elements and a lending platform may carry out several regulated activities depending on how contracts and assets move. Legal entity allocation also matters where different group companies perform different functions.


International firms need additional analysis because the new regime has specific cross-border and UK presence rules. Where a foreign business serves UK consumers, authorisation can be required even if the firm operates from overseas, while the treatment of purely institutional cross-border business can differ. The final structure should therefore be settled before the application is drafted.


Crypto financial promotions are already regulated

The financial promotions regime applies now, independently of the 2027 authorisation regime. Qualifying cryptoasset promotions made to UK consumers must be communicated or approved through a lawful route and comply with the applicable FCA rules, including requirements around fairness, risk warnings, customer categorisation and other restrictions. An overseas firm can fall within the promotions regime even where it does not currently require MLR registration in the UK.


Website content, apps, social media, influencers, affiliates and referral campaigns should therefore be included within the compliance framework. The firm should maintain approval and review processes, control versions of live promotions and ensure that customer incentives or promotional language remain within the rules. Marketing teams should not treat UK targeting as a purely commercial decision.


The future authorisation regime will not replace the need for financial promotions compliance. Authorised firms will continue to be responsible for communications within the relevant framework, and Consumer Duty and COBS will add broader conduct expectations. Firms should therefore build promotion governance that can transition into the future regime rather than creating a temporary process for 2026.


Consumer Duty will apply to relevant authorised crypto firms

The FCA finalised its approach to applying the Consumer Duty to relevant regulated cryptoasset activities in June 2026. The Duty will require in-scope firms to deliver good outcomes across products and services, price and value, consumer understanding and consumer support, subject to the detailed scope and specified exclusions. This represents a significant change from the current MLR-only relationship for many firms.


Crypto products create particular Consumer Duty challenges because customers can face volatility, complex technology, custody risk, irreversible transfers and products whose economic characteristics are difficult to understand. Firms should therefore consider target markets, customer understanding and foreseeable harm at product-design stage rather than relying primarily on risk warnings. The customer journey should help users understand material features and consequences without presenting complex or high-risk activity as ordinary savings behaviour.


Support is equally important. Account restrictions, lost access, fraud, transfer errors and complaints can leave customers unable to recover or use assets, so operational processes should provide effective routes to resolution. Outcome monitoring should identify whether particular products or customer groups experience materially worse outcomes.


COBS creates a wider conduct framework

The FCA's final crypto conduct package applies relevant parts of COBS to future authorised cryptoasset firms. The exact requirements depend on the activity and customer, but firms should expect more structured obligations around communications, client relationships and conduct than under current MLR registration. Policies should therefore be mapped to the future permission set rather than written as a generic conduct manual.


Conduct risk can arise through order handling, execution, conflicts, pricing, disclosures and product design. A trading platform, broker and custodian face different issues, so controls should be proportionate to the activity. Where the firm uses algorithms or automated execution, governance should be capable of explaining how the system produces customer outcomes and how errors are detected.


The FCA's future conduct rules should be read with Consumer Duty rather than in isolation. Meeting a detailed COBS rule does not necessarily demonstrate that a retail customer received a good outcome, while Consumer Duty does not remove the need to comply with specific conduct requirements. Compliance monitoring should therefore test both.


CASS 17 creates a dedicated crypto custody regime

Firms safeguarding qualifying cryptoassets will be subject to CASS 17 under the future regime. The final rules create a detailed client-asset framework covering trust arrangements, records, daily reconciliations, means of access such as private keys, third-party custodians and the treatment of shortfalls or discrepancies. This is a substantial move beyond current AML-focused custody registration.


Custody architecture needs to be considered from both legal and technical perspectives. Wallet structures, omnibus arrangements, private key controls, multi-party computation, recovery processes and sub-custody relationships should correspond with the firm's trust and record-keeping framework. Legal documents cannot compensate for a system that cannot identify individual customer entitlements accurately.


Daily reconciliation will be especially important. The firm needs an internal record of what customers are entitled to and a reliable method of comparing that requirement with the cryptoasset resource actually held. Breaks should be investigated, evidenced and escalated rather than corrected invisibly through ledger adjustments.


Third-party crypto custody does not remove responsibility

A future FCA-authorised firm can use third-party custodians subject to the applicable CASS 17 requirements, but outsourcing custody does not remove the firm's regulatory accountability where it has undertaken to safeguard the assets. Due diligence needs to consider the provider's regulatory status, financial strength, security, operational capability, jurisdiction, insolvency protections and use of further sub-custodians. The contractual framework should support the customer ownership and trust structure required by UK rules.


International custody chains deserve particular scrutiny. Customer assets may be held through several legal entities or jurisdictions, and the UK firm should understand what happens if one provider fails or access is disrupted. Recognition of trust arrangements and insolvency treatment should be assessed rather than inferred from the provider's reputation.


Ongoing oversight should include financial and operational changes. A third-party custodian can remain technologically available while its regulatory, financial or legal risk deteriorates. Review arrangements should therefore be capable of identifying material changes before customer assets are threatened.


CRYPTOPRU introduces formal capital requirements

The future prudential regime is contained in COREPRU and CRYPTOPRU. Permanent minimum requirements vary by activity, with final FCA rules setting £75,000 for certain agent and arranging activities, £150,000 for custody, trading-platform and staking activities, £350,000 for qualifying stablecoin issuance and £750,000 for dealing as principal. The firm's actual own-funds requirement can be higher because fixed overhead and applicable K-factor calculations also apply.


Custodians are subject to K-RCS, calculated at 0.04% of average relevant cryptoassets safeguarded under the detailed methodology. Other K-factors apply to areas such as stablecoin issuance, staking, orders, trading flow, principal positions, counterparty default and concentration depending on the business. Firms should model how capital changes as activity grows rather than budgeting only for the permanent minimum at authorisation.


Liquidity and overall risk assessment also matter. The firm should hold appropriate liquid resources and assess whether formulaic minimums are sufficient given its own risks and wind-down requirements. Financial forecasts, prudential calculations and the regulatory business plan should therefore use consistent operating assumptions.


Stablecoin issuers face additional requirements

UK issuers of qualifying stablecoins will require the relevant FCA permission and are subject to a specialist framework covering backing assets, redemption, governance, disclosures, safeguarding of the backing pool and prudential requirements. The FCA's final stablecoin rules were published in June 2026 and should be incorporated into any 2026 authorisation programme. Stablecoin compliance is therefore considerably broader than maintaining reserves in a bank account.


An issuer needs to understand how each token remains fully backed, which assets are eligible, how redemption works and how backing assets are protected from the issuer's insolvency. Liquidity needs to support redemptions while regulatory capital protects the business itself. These are distinct but connected prudential concepts.


Where a stablecoin is also used within payment services, the regulatory analysis can extend into the UK payments and e-money framework. Buckingham Capital Consulting specialises in that payments and e-money intersection, including the structuring of products that combine fiat payment services with stablecoin rails.


SMCR creates individual accountability

Future authorised cryptoasset firms come within the FCA's accountability framework according to the final rules. Senior responsibilities should be allocated clearly across governance, financial crime, prudential risk, custody, operational resilience and customer outcomes. The purpose is to ensure that the regulated firm has identifiable people with sufficient authority and competence to own its major regulatory risks.


Fitness and propriety should be supported by evidence rather than treated as a one-time application test. Competence, conduct, regulatory history and performance should be reviewed where required, and relevant employees need Conduct Rules training appropriate to their roles. A rapidly scaling crypto business should ensure governance capacity increases with the complexity and customer impact of its activities.


Technical expertise also matters. A board cannot oversee custody, trading or staking effectively if it lacks enough understanding to challenge the people or vendors controlling critical systems. Regulatory, financial and technical governance should therefore work together rather than operate in isolated committees.


Operational resilience is part of the future framework

The FCA has issued final guidance on operational resilience for authorised cryptoasset firms. Exchanges, custodians and other digital-asset providers depend heavily on wallet infrastructure, blockchain nodes, cloud services, identity systems, market data and third parties, making operational disruption capable of creating rapid and widespread customer harm. The resilience framework should therefore identify important services and the dependencies supporting them.


Scenario testing should consider failures that are specific to crypto as well as conventional technology outages. Private key compromise, chain congestion, protocol disruption, failed third-party custody, loss of blockchain connectivity and major cyber incidents can each affect the firm's ability to deliver critical services. The response plan should identify both operational recovery and customer communication.


Outsourcing does not remove responsibility. The firm should understand concentration, sub-outsourcing and exit risk and retain enough internal capability to supervise providers. Operational resilience should be designed before authorisation rather than left until after launch.


Market abuse controls will become a major new obligation

The future regime includes a cryptoasset market abuse framework. Firms operating trading venues or participating in relevant market activity will need controls capable of identifying and addressing insider dealing, unlawful disclosure, manipulation and other forms of abusive behaviour. This brings a level of market conduct oversight that current MLR registration does not provide.


Trading platforms should consider surveillance, order and transaction data, conflicts, governance and escalation. The control environment should be proportionate to the assets and activity on the platform and capable of adapting to crypto-specific manipulation techniques. Market abuse should also connect with financial crime where the same behaviour raises broader criminal concerns.


Evidence and reporting will be important. Automated surveillance can produce large volumes of alerts, so the firm needs calibrated models, trained investigators and governance capable of distinguishing genuine concerns from ordinary market behaviour. The objective is an effective surveillance framework rather than the appearance of monitoring.


Complaints and redress will become more formalised

The future FCA regime brings crypto firms within a more formal complaints and redress framework according to the applicable rules. Firms should therefore develop procedures for receiving, investigating, resolving and recording complaints and understand when eligible customers can access the Financial Ombudsman Service. Existing customer-service tickets should not be assumed to satisfy regulatory complaint handling requirements automatically.


Complaint data should feed into Consumer Duty and operational monitoring. Recurring complaints about withdrawals, account freezes, execution, custody or fees can indicate systemic weaknesses rather than isolated dissatisfaction. Root-cause analysis should identify whether broader remediation or product change is required.

The firm should also consider how complaints interact with immutable transactions or external protocols.


Technical irreversibility does not remove the need to investigate the service the regulated firm provided and determine whether customer harm arose from its own systems, communications or controls. Clear contractual allocation cannot replace regulatory responsibility where the rules impose it on the firm.


Financial crime remains central under the future regime

Full FSMA authorisation will add new conduct and prudential obligations but will not reduce the importance of AML, sanctions and fraud controls. The firm should maintain a business-wide risk assessment, customer-risk methodology, due diligence, ongoing monitoring, blockchain analytics where appropriate, transaction monitoring, sanctions controls and suspicious activity reporting proportionate to its activities. Risk assessments should reflect both on-chain and off-chain components of the business.


Blockchain analytics can improve visibility but should not be treated as a substitute for judgement. Firms need to understand the methodology and limitations of external tools, calibrate risk thresholds and investigate alerts in the context of customer information and transaction purpose. Self-hosted wallets and cross-chain activity can require additional analysis rather than simple automated scoring.


Financial crime controls should also connect with custody, trading and Consumer Duty. For example, freezing access because of a financial crime alert can create customer-support and complaint issues that need governed processes. The regulatory framework should therefore treat the customer relationship as one connected system.


International groups need a credible UK operating model

The FCA's final approach to international cryptoasset firms generally expects solo-regulated firms requiring UK authorisation to operate regulated activities through a UK legal entity with sufficient local presence and resources, subject to specific exceptions. Certain qualifying cryptoasset trading platform structures and dual-regulated firms can receive different treatment. An overseas licence does not itself passport into the UK.


International groups should map which entity contracts with customers, controls assets, operates technology and makes regulated decisions. Intra-group outsourcing can be appropriate, but the UK firm should retain sufficient authority, information and capability to meet its obligations. A shell company with nominal local management is unlikely to provide a credible regulatory model.


Capital, governance, tax, contracts and technology should therefore be designed together. Changing the group structure while an application is under assessment can create significant regulatory delay. The UK market-entry strategy should be settled before the authorisation file is developed in detail.


What should cryptoasset providers do during 2026?

Existing firms should conduct a structured gap assessment between their current MLR and financial promotions framework and the future FSMA rules. The review should map permissions, governance, Consumer Duty, COBS, prudential requirements, operational resilience, financial crime, complaints and any CASS 17 or market abuse obligations that apply. Gaps should be prioritised by the time and operational change required to fix them.


The firm should then build the application and implementation plan around one target operating model. Policies should describe systems and processes that are already designed or capable of implementation rather than promises to build the compliance framework after authorisation. Financial forecasts should incorporate the cost of capital, staff, technology and compliance required under the future regime.


Firms should also review historic FCA issues before applying. Outstanding MLR remediation, weak transaction monitoring or problematic financial promotions can undermine the regulator's confidence in the future application. Resolving known issues early is likely to be more effective than explaining them after the case officer raises them.


How Buckingham Capital Consulting can help

Buckingham Capital Consulting supports cryptoasset businesses where financial crime, payments, e-money, stablecoins and wider regulated financial infrastructure intersect. We can conduct regulatory gap assessments covering current MLR controls, financial promotions, financial crime, governance and readiness for the future FCA framework, with particular depth where the business also provides regulated payment or e-money services. The review can be converted into a prioritised implementation programme for the 2026 to 2027 transition.


For standalone FSMA crypto authorisation, custody and broader crypto regulatory structuring, BCC can coordinate with specialist Regulatory Counsel support where appropriate while retaining responsibility for the payments and e-money workstream. This avoids forcing complex hybrid models into one regulatory category and allows each permission set to be addressed by the relevant specialist team. Stablecoin and payment models often benefit from that combined approach because several regulatory regimes can apply to the same customer journey. To discuss UK crypto compliance, financial crime, stablecoin payment structuring or a broader regulatory gap assessment, contact Buckingham Capital Consulting.


Frequently asked questions

What FCA rules apply to UK cryptoasset providers in 2026?

Current in-scope cryptoasset exchange and custodian wallet providers remain subject to FCA registration and supervision under the Money Laundering Regulations, and the crypto financial promotions regime already applies to relevant promotions. The FCA has also finalised most of the rules for the new FSMA crypto regime expected to commence on 25 October 2027. Firms therefore need to comply with the current framework while preparing for future authorisation.


Does FCA MLR registration automatically become a crypto licence under FSMA?

No. Existing registration does not automatically convert into Part 4A permission under the new regime. Firms carrying on activities that become regulated need to apply for the relevant permissions and demonstrate compliance with a materially broader conduct, prudential and governance framework.


Will Consumer Duty apply to crypto firms?

Yes, the FCA has finalised the application of the Consumer Duty to relevant authorised cryptoasset activities, subject to its detailed scope and specified exclusions. In-scope firms need to consider products and services, fair value, consumer understanding and support. The Duty will apply alongside activity-specific conduct requirements rather than replace them.


What is CASS 17?

CASS 17 is the FCA's new client-asset sourcebook for safeguarding qualifying cryptoassets. It covers trust arrangements, records, daily reconciliations, key and means-of-access controls, third-party custodians and related protections. It will apply to firms with the relevant custody permission under the future regime.


What capital will FCA-authorised crypto firms need?

The future CRYPTOPRU framework sets different permanent minimum requirements by activity, ranging from £75,000 for certain arranging and agency activities to £750,000 for dealing as principal. Custody and trading-platform activities have a £150,000 permanent minimum and qualifying stablecoin issuance has a £350,000 minimum. Fixed overhead, K-factor, liquidity and overall risk requirements can make the actual amount higher.


#FCA Compliance for UK Cryptoasset Providers 2026: Complete Guide

 
 
bottom of page