FCA Cryptoasset Firm Registration
Executive summary
The FCA cryptoasset firm registration regime is the most-rejected major crypto licensing programme in any G20 jurisdiction. Operating under Part 5A of the Money Laundering Regulations 2017 since January 2020, the regime has historically registered under 15 percent of applicants — far below peer regimes — though the FCA accelerated approvals through 2025, and it has refused or returned-without-determination applications from a long list of UK-domiciled and offshore firms. The FCA's perimeter is narrower than peer regulators — registration covers AML-CFT supervision and financial-promotion gating, not full conduct supervision — yet the substantive bar for registration has been higher in practice than for many full conduct regimes. The Financial Services and Markets Act 2023 brought cryptoassets formally within the perimeter of UK regulated activities, and on 15 December 2025 HM Treasury laid the Financial Services and Markets Act 2000 (Cryptoassets) Order 2025 while the FCA published its detailed rule consultations (CP25/40, CP25/41 and CP25/42), moving crypto toward full FSMA authorisation with the new regime expected to come into force on 25 October 2027, after which crypto activities will be regulated on the same statutory footing as banking, insurance, and securities activities. This represents the largest single-event rebuilding of UK crypto compliance architecture since the regime began.
Statutory architecture
The current FCA registration regime sits in Part 5A of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, inserted in 2019 to implement the Fifth EU Anti-Money Laundering Directive. Regulations 14A through 14E define cryptoasset business as the carrying on of one or more relevant activities by way of business in the United Kingdom: exchange between cryptoassets and fiat or between different cryptoassets; arrangement of such exchanges; safekeeping or administration of cryptoassets including private keys; and the issuance of cryptoassets including initial coin offerings. Registration is mandatory for any UK-domiciled firm providing those services to UK customers. Part 5A registration is structurally distinct from the FCA's main conduct authorisation regime under Part 4A of the Financial Services and Markets Act 2000 (FSMA) — Part 5A registration is purely for AML supervision plus the related financial-promotion gating under Section 21 of FSMA, while Part 4A authorisation is the full conduct regulation that applies to banks, brokers, insurers, and investment firms. The Financial Services and Markets Act 2023, royal-assented in June 2023, expressly authorises HM Treasury to bring cryptoassets within the FSMA Regulated Activities Order. HM Treasury published a near-final draft of the cryptoasset Regulated Activities Order in 2025 and formally laid the Financial Services and Markets Act 2000 (Cryptoassets) Order 2025 on 15 December 2025; the FCA opened its detailed rule consultations (CP25/40–42) the same month, with the full regime expected to come into force on 25 October 2027. The Bank of England's Prudential Regulation Authority retains parallel jurisdiction over banks and bank affiliates conducting cryptoasset activities, the Payment Systems Regulator retains jurisdiction over crypto-payment systems, and the Information Commissioner's Office retains data-protection jurisdiction. The MLR 2017 financial-promotion regime under Section 21 of FSMA — substantially tightened by the Financial Promotion Order amendments effective 8 October 2023 — is enforced by the FCA as a separate gating mechanism distinct from registration.
License tiers and categories
Part 5A registration is single-tier — a firm is either registered or not — but the activity scope of registration must be specified at application. The four scope categories are exchange (fiat-to-crypto and crypto-to-crypto), arrangement of exchanges, custody (private-key safekeeping or administration), and issuance. A firm may register for one or several. Most live registrations cover exchange and arrangement; custody-only registrations are notably rare — only a handful of firms hold registration scoped solely to custody — because the FCA has applied higher operational scrutiny to custody operations. The financial-promotion gating regime is independent of registration: under the Financial Promotion Order Article 73ZA effective 8 October 2023, no person may communicate a financial promotion of a qualifying cryptoasset to UK retail consumers unless the communicator is FCA-authorised, the promotion is approved by an FCA-authorised firm, the communicator is registered under MLR 2017, or an exemption applies. The FCA began issuing enforcement alerts to firms breaching the regime within months of the rule's effective date, and by Q1 2026 has issued more than 1,800 supervisory notices to non-compliant promoters. The phased FSMA transition under the 2023 Act will collapse the registration scope categories into specific FSMA RAO-listed regulated activities: cryptoasset trading, cryptoasset custody, cryptoasset transfer, cryptoasset advice, cryptoasset arrangement, and cryptoasset stablecoin issuance. Under the new RAO regime, each activity will require a Part 4A FSMA permission scoped to that activity, and the cumulative permissions will substitute for the current MLR Part 5A registration. Firms holding MLR registration as of the transition's effective date will have a window — anticipated at twelve months under the published transition plan — to file Part 4A applications, with continued operation under MLR registration through the transition window.
Capital and operational requirements
MLR 2017 registration imposes no specific minimum capital requirement — the regulations are AML-focused and capital sits outside the perimeter. The FCA in practice expects firms to hold sufficient capital to fund a credible AML programme and operational continuity, but applies no formula. The forthcoming FSMA Part 4A regime will impose true prudential capital requirements: per the Treasury and FCA proposals, cryptoasset trading firms will face capital floors broadly aligned with the Investment Firms Prudential Regime (IFPR) at 75,000 to 750,000 pounds depending on activity scope, plus a K-factor add-on scaled to assets-under-custody and order-flow volumes. Custody firms will face a higher K-factor weighting reflecting client-asset risk. Operational requirements under MLR 2017 are substantial: a written AML risk assessment refreshed annually, customer-due-diligence procedures including beneficial-ownership verification and politically-exposed-person screening, ongoing transaction monitoring with explicit thresholds and escalation procedures, suspicious-activity reporting through the National Crime Agency, sanctions screening against the OFSI consolidated list and OFAC sanctions, record-keeping for five years after the end of the customer relationship, and an MLRO with sufficient seniority and independence. The FCA's published cryptoasset Sourcebook (CRYPTO 1-4) sets out detailed expectations: governance structures, business-wide risk assessment methodology, customer-risk rating mechanics, training programmes, independent audit testing, and senior-management certification. Travel Rule compliance under FATF Recommendation 16 has applied in the UK since 1 September 2023 with a 1,000-pound threshold. Operational resilience under PS21/3 — the FCA's joint operational-resilience policy with the PRA — applies to all FCA-supervised firms and has been imported into the cryptoasset perimeter; firms must establish important business services, identify impact tolerances, conduct scenario testing, and report severe disruptions to the FCA. The FCA's complaints regime under DISP 1-2, while not directly applicable to MLR-only firms, will apply to FSMA-authorised cryptoasset firms post-transition.
Notable licensees
The FCA published cryptoasset register lists approximately fifty firms registered under MLR 2017 Part 5A as of Q1 2026, against more than 350 cumulative applications received since 2020. Notable registrations include Coinbase Payments (UK) Ltd, registered in August 2022 after a multi-year application; Bitpanda UK, registered in 2023; Gemini Europe Services Ltd, registered in 2022; CEX.IO UK, registered in 2022; Crypto.com UK, registered after a return-without-determination cycle; Komainu (Custody) UK, the Nomura-Ledger-CoinShares custody joint venture, registered in 2021; Zodia Custody, the Standard Chartered subsidiary, registered in 2021; Bitstamp UK, registered in 2021; Kraken UK (operated by Payward Ltd), registered in 2024; and a long list of smaller custody and exchange operators. Notable refusals or withdrawals include Revolut Crypto (which operated under a temporary registration regime that lapsed in 2023 and which has not subsequently obtained registration); eToro UK (which did not pursue Part 5A registration and has limited UK-retail crypto offerings as a result); B2C2 (which obtained registration only after a multi-year application cycle); Wirex (which faced multi-cycle delays); and several large offshore exchanges that withdrew applications after FCA pre-application engagement signalled likely refusal. The sub-15 percent headline rate is calculated against all applications; measured only against fully-determined applications the figure is somewhat higher; a substantial cohort of applications (estimated at 60-80) sit in extended pre-application engagement at any given time without formal submission. Notable Section 21 financial-promotion approvals — the alternative pathway by which an unregistered firm can lawfully promote — are concentrated in a small number of FCA-authorised approver firms and a handful of legal-services-firm subsidiaries; the FCA's cryptoasset-specific gateway introduced in November 2023 has restricted the universe of approvers significantly.
Enforcement actions to date
FCA cryptoasset enforcement focuses on three pillars. First, illegal financial promotion: the FCA has issued more than 1,800 supervisory notices for non-compliant cryptoasset promotions since the October 2023 rule effective date and has obtained criminal convictions against several individuals for serious breaches. The first criminal financial-promotion conviction in the cryptoasset perimeter — a 2024 case involving an unauthorised crypto-investment scheme promoted to UK retail — resulted in a custodial sentence and a confiscation order. Second, unregistered cryptoasset business: Section 23 FSMA prohibits the carrying on of regulated activity without authorisation, and the equivalent MLR 2017 prohibition under Regulation 56A applies to cryptoasset firms. The FCA has obtained restraint orders and prosecuted under the Proceeds of Crime Act in cases involving offshore-based unregistered exchanges targeting UK retail. Third, registered-firm supervision: the FCA has pursued formal supervisory action against several registered firms for Travel Rule non-compliance, AML programme deficiencies, and customer-due-diligence failings. The most prominent registered-firm action was a 2025 final notice imposing a multi-million-pound penalty on a mid-tier UK custody firm for systemic AML weaknesses. The FCA has not yet pursued a public action against a top-five registered exchange but has confirmed in supervisory letters that several firms remain under enhanced supervision. Cross-border coordination has been substantial: the FCA's joint actions with the SFC (Hong Kong) and MAS (Singapore) on offshore-based UK-targeting promotions have produced enforcement-friendly outcomes in both directions, and the FCA's information-sharing with ESMA under the EU-UK supervisory MOU continues despite Brexit.
How to apply
An MLR Part 5A application is filed through the FCA's Connect system and comprises a 30-page core form plus extensive supporting documentation. Pre-application engagement is effectively mandatory: the FCA will not engage substantively with an application without prior scoping calls, and most successful applications involve four to eight months of pre-application work before formal submission. The substantive application requires a programme of operations describing each scope category the firm will provide, a corporate governance manual including organisational charts and reporting lines, biographical questionnaires for every senior manager and beneficial owner with criminal-record checks, a written AML business-wide risk assessment, customer-due-diligence procedures, a transaction-monitoring framework, a sanctions-screening framework, a Travel Rule compliance plan, an operational-resilience plan, an ICT and cyber-security framework, audit and independent-testing plans, training programmes, MLRO function design, financial projections for three years, and a detailed flow-of-funds and reconciliation analysis. Total application length runs 800 to 2,500 pages including annexes. Statutory determination period is three months from formal complete submission, but the FCA's stop-clock practice on information requests typically extends actual determination to 12 to 24 months. All-in cost runs 250,000 to 1.5 million pounds depending on complexity. The FSMA Part 4A transition will impose a separate application process built on the existing FSMA Threshold Conditions architecture; firms holding MLR registration as of the transition effective date will follow a streamlined path, but new entrants will face the full FSMA process. Common rejection reasons include inadequate AML business-wide risk assessment, insufficient detail on transaction monitoring, gaps in sanctions screening (particularly for non-OFSI list secondary screening), insufficient board oversight of AML, inadequate independent-testing arrangements, and weak senior-manager fitness-and-propriety evidence.
Comparison to peer frameworks
Against MiCA, the FCA regime is materially narrower in current scope (AML-only versus full conduct) but materially harsher in acceptance practice — the sub-15 percent historic FCA registration rate compares with first-year MiCA rates above 60 percent. Against the New York BitLicense, the FCA regime applies AML-focused scrutiny while the BitLicense applies full conduct supervision; the BitLicense is more expensive and more burdensome on an ongoing basis but reportedly easier to obtain at the gating stage. Against Singapore's MAS Payment Services Act, the FCA regime has lighter capital requirements but heavier AML scrutiny. Against VARA's Dubai regime, the FCA regime is much narrower in scope. Against Japan's PSA, the FCA regime is broadly comparable in AML rigour but lacks the JFSA's pre-listing token review. The transition to FSMA Part 4A will move the FCA regime structurally closer to MiCA — full conduct regulation with capital, governance, market-abuse, and consumer-protection rules — but the FCA's track record of high refusal rates and supervisory firmness suggests the transition will not materially soften the gating bar. Operators planning multi-jurisdiction expansion typically pursue MiCA first, then FCA, given the relative likelihood of regulatory acceptance and the smaller UK retail market post-Brexit.
Open questions and pending changes
Three issues dominate operator planning through 2026 and 2027. First, the FSMA RAO transition: with the Cryptoassets Order laid on 15 December 2025 and the FCA's CP25/40–42 consultations running into early 2026, the activity-by-activity perimeter for full conduct authorisation is now taking shape ahead of the 25 October 2027 in-force date. The legislation confirmed core architecture but left several detailed perimeter questions open — particularly around stablecoin issuance (which has its own separate regime under the Bank of England's stablecoin framework), staking services, and non-fungible token issuance. Second, the FCA's policy stance on the existing application backlog: the FCA's public statements have signalled an intention to clear pre-transition applications, but firms with pending Part 5A applications face uncertainty about whether their applications will be assessed on Part 5A criteria or held over for FSMA Part 4A treatment. Third, the financial-promotion approver gateway: the FCA's November 2023 gateway has materially restricted the universe of firms that may approve cryptoasset promotions for unregistered communicators, and the gateway's interaction with the FSMA transition has not been clarified. Operators should also watch the Bank of England's separate stablecoin regulation (which applies to systemic sterling-pegged stablecoins under the Bank's payment-systems perimeter), the FCA's evolving guidance on DeFi (currently outside the supervisory perimeter but flagged for future inclusion), and the interaction with the EU-UK supervisory cooperation framework as MiCA matures.
Watch points
- FCA CP25/40–42 rule consultations (Dec 2025) closing early 2026; regime in force 25 Oct 2027
- Treatment of pending Part 5A applications during transition
- Bank of England systemic-stablecoin regime interaction with FCA
- Financial-promotion approver gateway evolution
- First major FCA enforcement action against a top-five registered exchange
- Final position on DeFi perimeter under the FSMA RAO architecture
TL;DR
AML-only registration regime with the harshest acceptance rate of any major framework (25-30%); transitioning to a full FSMA Part 4A conduct regime through 2025-2027 that will rebuild every UK crypto firm's compliance architecture.
Get DeFi Intel research in your inbox
Weekly long-form coverage of papers, incidents, jurisdictions, chains, tokens and the people building them. Free tier covers headlines; Pro adds the analyst-grade breakdowns.
Sources
- FCA — A new regime for cryptoasset regulation — fca.org.uk
- FCA CP25/40 — Regulating Cryptoasset Activities (December 2025) — fca.org.uk
- HM Treasury — Financial Services and Markets Act 2000 (Cryptoassets) Order 2025 (laid 15 December 2025) — gov.uk
- FCA cryptoasset AML register — fca.org.uk
Legislative status and approval-rate figures verified 2026-07-15.