Why FCA Crypto Authorisation Is More Than an Application Exercise

Crypto regulation in the UK is entering a decisive phase. As the FCA develops its future cryptoasset framework, attention is naturally turning towards authorisation. Firms are trying to understand what permissions they may need, when the authorisation gateway will open, and how the new regime could affect their business models.

What many firms may underestimate is the scale of change the FCA is signalling.

There is still a tendency to view authorisation as a regulatory application process: complete the application, provide supporting documentation, respond to FCA questions, and secure approval.

The FCA’s recent discussion paper (DP25/1) and consultations (CP25/14 and CP25/15) suggest that the regulator is focused on much more than the application itself and indicate the likely scope of the future regime. The focus is expanding beyond financial crime controls towards governance, customer protection, operational resilience, prudential soundness, market integrity, and the unique risks associated with cryptoasset activities such as custody, safeguarding, and the management of digital assets.

In that sense, FCA crypto authorisation is less about obtaining a licence and more about demonstrating that a business is capable of operating within a regulated financial services environment.

The FCA Is Signalling a Different Standard for Crypto Firms

The FCA’s recent proposals provide a useful indication of where the future regime is heading. For many crypto-native firms, this represents a significant shift.

Historically, regulatory engagement has often focused on anti-money laundering controls and financial crime prevention. While those areas remain critically important, the proposed regime broadens the conversation considerably.

The FCA is increasingly focused on governance, the safeguarding of client cryptoassets, private key management, monitoring financial crime and market abuse risks, and firms’ ability to continue operating during periods of disruption.

This is about more than compliance. The regulator wants to understand whether firms can evidence robust decision-making, effective oversight, appropriate financial resources, secure custody arrangements, effective safeguarding controls, and sustainable operating models. That is a very different discussion from whether a policy exists on paper.

The Application Is Only One Part of the Process

One of the most common misconceptions is that authorisation is the end of the process. In reality, it marks the start of ongoing FCA supervision.

Expectations around governance, risk management, reporting, compliance monitoring, operational resilience, and financial resources do not disappear once approval is granted. If anything, scrutiny increases.

This is consistent with the FCA’s wider approach across financial services. Authorisation establishes that a firm meets the relevant standards at the point of approval, but those standards must continue to be met on an ongoing basis.

This is why firms that focus exclusively on producing application documentation can find themselves in a difficult position. A strong submission may help support authorisation, but it does not necessarily mean the underlying operating model is ready for life as a regulated business.

The FCA is likely to look beyond what firms say they will do and focus on whether they can demonstrate how those arrangements operate in practice. Increasingly, authorisation is becoming a test of execution rather than intention.

Investors and Counterparties Are Likely to Look More Closely at Operational Readiness

There is also a commercial dimension for these developments. As crypto firms move toward a more comprehensive regulatory framework, governance, controls, and operational resilience are likely to receive greater attention from investors, banking partners, service providers, and counterparties.

This is not a new concept. In traditional financial services, institutional due diligence often extends well beyond investment strategy or product capability. Governance arrangements, risk management frameworks, operational resilience, safeguarding of assets, and senior management oversight are all commonly reviewed as part of the assessment process.

Increasingly, firms should be prepared to answer questions such as:

  • How are client assets safeguarded?
  • How are private keys secured and governed?
  • How are custody and safeguarding arrangements structured?
  • Who is accountable for key decisions?
  • How is operational risk monitored and reported?
  • What happens if a critical service provider fails?
  • How does the firm manage financial crime and market abuse risks?

These questions are no longer asked only by regulators.

For firms seeking to attract institutional clients, counterparties, or strategic partners, the ability to answer them clearly and confidently may become increasingly important.

The FCA Is Increasingly Focused on Resilience

Another theme emerging from the FCA’s recent publications is resilience. The regulator wants firms to think beyond growth scenarios and consider how they would respond under stress.

This includes operational disruption, technology failures, cyber incidents, liquidity challenges, third-party outages, and even orderly wind-down scenarios.

For crypto firms, these questions are particularly important because many business models depend on a combination of technology infrastructure, custody providers, blockchain networks, liquidity venues, and other third parties that sit outside the firm’s direct control.

A disruption affecting a custodian, blockchain network, stablecoin arrangement, technology provider, or liquidity venue can have a direct impact on a firm’s ability to operate. Understanding those dependencies and managing the associated risks is becoming an increasingly important part of regulatory readiness.

This is not simply satisfying regulatory expectations. It is about building businesses that can continue to operate effectively when conditions become challenging. The firms that invest in resilience today are likely to be better positioned from both a regulatory and commercial perspective.

How Crypto Firms Can Prepare for FCA Authorisation

While the FCA continues to refine the final framework, firms do not need to wait before taking action. The consultations already provide a clear indication of the areas likely to receive regulatory attention.

Practical steps include:

  • Reviewing business activities against the proposed regulatory perimeter
  • Conducting an authorisation readiness assessment
  • Evaluating governance and accountability frameworks
  • Reviewing prudential resources and wind-down planning
  • Assessing safeguarding, custody, and private key management arrangements
  • Strengthening financial crime and market abuse controls
  • Testing operational resilience capabilities
  • Reviewing third-party risk management arrangements
  • Identifying gaps between existing controls and future regulatory expectations

Perhaps most importantly, firms should focus on evidence. The FCA is unlikely to be persuaded by policy documents alone. It will increasingly expect firms to demonstrate that controls operate effectively in practice and that senior management understands the risks facing the business.

Ultimately, the FCA is trying to determine whether a crypto firm is ready to operate within a regulated financial system. The firms that are likely to be best positioned under the new regime will be those that can demonstrate effective governance, secure custody and safeguarding arrangements, financial resilience, operational readiness, and clear accountability, not just a well-prepared application.

FCA Crypto Authorisation Support for Digital Asset Firms

Preparing for FCA crypto authorisation requires more than interpreting regulatory requirements. Firms must translate those requirements into practical governance structures, operating models, and control frameworks that can withstand regulatory scrutiny.

Prepare for authorisation and ongoing supervision with support across:

  • Authorisation readiness assessments and gap analysis
  • Regulatory strategy and permissions mapping
  • Governance and operating model reviews
  • Compliance framework design and enhancement
  • Financial crime, AML, and customer due diligence control assessments
  • Prudential and wind-down planning support
  • Safeguarding and custody control reviews
  • Cyber oversight, technology risk, and operational resilience assessments
  • Risk management framework support
  • Market abuse monitoring arrangements and surveillance framework reviews
  • Outsourcing and third-party risk assessments
  • Internal audit and independent assurance
  • Tokenisation and digital asset business model support
  • Ongoing compliance and regulatory support

Learn how ACA helps firms move beyond application preparation to build sustainable, credible, and resilient regulated businesses.

Whether you are a crypto-native business preparing for authorisation or an established financial services firm expanding into digital assets, early preparation can make a significant difference.

Assess your readiness and develop a practical roadmap towards FCA crypto authorisation.

Further Resources

Listen to our on-demand webcasts to learn more about preparing for FCA crypto regulation and the growing role of tokenisation in financial markets.