For the past several years, the UK’s approach to regulating cryptoassets has centered on one primary objective: reducing financial crime. Firms seeking authorisation under the Money Laundering Regulations invested heavily in customer due diligence, sanctions screening, transaction monitoring, and AML controls.
Those obligations remain essential, but they no longer define the full scope of regulatory progress.
The FCA’s recently published Overview of Our Cryptoassets Regime Policy Statements marks a significant milestone in the UK’s regulatory journey. The FCA describes the package as a “major step forward”, introducing a comprehensive regulatory regime that moves “well beyond the anti-money laundering and financial promotions standards that previously defined our role in this market.”
That marks an important shift. For compliance leaders, the question is no longer whether a firm has appropriate financial crime controls. The question is whether your organisation is prepared to operate as a fully regulated financial services business.
The FCA Is Raising the Standard for Crypto Firms
The FCA’s policy statements introduce a broad regulatory framework that spans every aspect of how crypto firms operate.
Alongside detailed requirements for regulated cryptoasset activities, the package includes the final policy on:
- Prudential Requirements for Cryptoasset Firms (PS26/12)
- Stablecoin Issuance (PS26/10)
- Regulated cryptoasset Activities (PS26/11)
- Admissions and Disclosures and Market Abuse Regime for Cryptoassets (PS26/9)
- Application of FCA Handbook for Regulated Cryptoasset Activities (PS26/13)
The FCA has also published finalised guidance on the application of the Consumer Duty to cryptoasset firms, operational resilience, and its approach to international cryptoasset firms. In addition, it is consulting on non-Handbook guidance concerning the overall risk assessment under COREPRU and CRYPTOPRU.
Taken together, these publications demonstrate that compliance expectations now extend far beyond financial crime.
Financial Crime Is Now One Part of a Broader Compliance Framework
AML remains a critical regulatory obligation, but it is increasingly one component of a much wider governance framework.
The FCA is applying existing financial services expectations across crypto firms, including the Consumer Duty, the SM&CR, operational resilience requirements, financial crime frameworks, and broader systems and controls.
That means compliance teams should be asking broader questions.
- Does the board understand its regulatory responsibilities?
- Are governance arrangements fit for a regulated business?
- Can the firm demonstrate operational resilience during periods of disruption?
- Are prudential risks appropriately identified and managed?
- How are outsourcing arrangements and technology risks being governed?
These questions supplement AML requirements rather than replace them.
How Regulatory Maturity Can Help Crypto Firms Prepare for FCA Authorisation
One of the strongest messages emerging from the FCA’s policy statements is that the regulator wants well-run firms to thrive.
The regime is designed to strengthen consumer confidence, improve market integrity, encourage innovation, support sustainable growth, and create predictable standards for firms operating in the UK.
For firms, this means compliance is becoming more than a regulatory exercise. Strong governance, effective risk management, operational resilience, and robust safeguarding arrangements all contribute to building confidence with regulators, investors, counterparties, and customers.
In an increasingly competitive market, regulatory maturity can become a commercial advantage.
How Crypto Firms Can Prepare for the FCA’s New Cryptoasset Regime
The FCA has made clear that firms currently registered under the Money Laundering Regulations will not automatically transition into the new regime. Firms carrying out regulated cryptoasset activities will need to obtain authorisation under the Financial Services and Markets Act and demonstrate that they meet the Threshold Conditions.
The application window for firms wishing to rely on the transitional savings provisions is expected to run from 30 September 2026 to 28 February 2027, giving firms a limited window to prepare.
Waiting until authorisation applications open is unlikely to be enough. Instead, firms should begin evaluating whether their governance structures, operating models, compliance frameworks, and risk management capabilities reflect the direction of travel outlined by the FCA.
Financial crime remains fundamental, but it is no longer the defining compliance challenge for UK crypto firms. The FCA’s new regime expects firms to demonstrate mature governance, operational resilience, prudential strength, and effective enterprise-wide risk management alongside robust AML controls.
Five Practical Steps Crypto Firms Should Take to Prepare for FCA Authorisation
Preparing for the UK’s crypto regime requires more than updating AML policies.
Firms should consider taking the following steps:
Review Governance Arrangements
Ensure that board accountability and decision-making responsibilities are clearly defined.
Assess Operational Resilience
Identify critical business services, technology dependencies, and third-party risks.
Evaluate Prudential Readiness
Measure risk against the FCA’s new prudential framework and overall risk assessment expectations.
Strengthen Compliance Frameworks
Align with the wider FCA Handbook, Consumer Duty, and systems and controls requirements.
Develop an Authorisation Readiness Plan
Identify regulatory gaps before the application window opens.
Taking these actions now will help firms move from regulatory compliance to regulatory readiness.
Building Resilience Today Supports Growth Tomorrow
The FCA’s latest policy statements represent more than another regulatory milestone.
They signal a new phase for the UK’s crypto market, one where firms are expected to meet many of the same standards as established financial services organisations.
For firms, that presents both a challenge and an opportunity.
Those that view compliance as a strategic capability rather than a regulatory obligation will be better positioned to navigate future change, build stakeholder confidence, and support long-term growth.
Get Ready for What’s Next in UK Crypto Regulation
Success under the UK’s new crypto regime requires expertise across compliance, governance, prudential risk, technology, and digital assets.
ACA supports crypto-native firms and traditional financial services organisations through:
- Authorisation readiness assessments and gap analysis
- Regulatory strategy and permissions mapping
- Governance and operating model reviews
- Compliance framework design and enhancement
- Financial crime, AML, and customer due diligence control assessments
- Managed AML operations, including KYC onboarding, sanctions screening, ongoing monitoring, and remediation
- Prudential and wind-down planning support
- Safeguarding and custody control reviews
- Cyber oversight, technology risk, and operational resilience assessments
- Risk management framework support
- Market abuse monitoring arrangements and surveillance framework reviews
- Outsourcing and third-party risk assessments
- Internal audit and independent assurance
- Tokenisation and digital asset business model support
- Ongoing compliance and regulatory support
Whether you’re preparing for authorisation, strengthening existing controls, or expanding your digital asset offering, ACA can help you build a compliance framework that is proportionate, practical, and aligned with the FCA’s evolving expectations.
The UK’s crypto regime is entering a new phase. ACA can help crypto-native firms and financial services organisations assess their current state, identify gaps, and develop a practical roadmap for the UK’s evolving cryptoasset regime.
Connect with us today to discuss how your organisation can prepare for the UK’s evolving crypto regulatory landscape.
Frequently Asked Questions
What is the FCA’s new cryptoasset regime?
Is AML compliance enough for UK crypto firms?
No. AML compliance remains important, but the FCA’s emerging cryptoasset regime is expected to require firms to demonstrate broader regulatory maturity across governance, risk management, operational resilience, prudential planning, and consumer protection.
What should crypto firms do to prepare for FCA authorisation?
How will the FCA’s crypto regime affect financial services firms entering digital assets?
Why does regulatory maturity matter for crypto firms?
Regulatory maturity may help crypto firms evidence stronger governance, improve investor and counterparty confidence, and prepare for more detailed supervisory engagement under the UK’s evolving cryptoasset regime.
Skip to content