FCA Opens Crypto Authorization Window Ahead of 2027 Regime
The Financial Conduct Authority has started accepting applications for crypto firm authorization, setting a hard deadline of 28 February 2027 for firms that want to continue operating in the UK when the new regime goes live on 25 October 2027. The clock is running, and the FCA has already signalled that this will not be a formality: approval is explicitly not guaranteed, and existing Money Laundering Regulations registration carries no automatic weight in the new process.
What the New Regime Actually Covers
The regulatory framework published in June 2026 brings a substantially wider range of digital asset activities under FCA oversight. This is not simply a tidying exercise; the scope expansion is meaningful for firms that may have operated in adjacent areas without a direct FCA relationship.
Activities now in scope
Under the incoming rules, firms facilitating trading, transaction execution, staking, and digital asset custody will all require FCA authorization. The regime also introduces requirements around cryptoasset admissions and disclosures, market abuse prevention, prudential standards, and consumer protection obligations. That combination of market-conduct and prudential requirements in a single authorization scope is a significant shift from the current patchwork, where anti-money-laundering registration and separate conduct rules operated largely in parallel.
Why staking and DeFi-adjacent services matter
The explicit inclusion of staking is particularly notable. Firms that offer staking products, whether as a core service or as an ancillary feature of a custody arrangement, will need to assess whether their current corporate and operational structure is sufficient to meet FCA standards. DeFi-adjacent services that involve intermediating user funds or facilitating on-chain transactions may also fall within scope, depending on how the FCA applies the definitions in the final rules. Firms operating in those areas should seek legal analysis of their specific activities rather than assume they fall outside the perimeter.
The Application Process and What the FCA Will Assess
The FCA has been clear that the authorization window is not a conversion process for existing registrations. Firms already registered under the Money Laundering Regulations cannot simply roll that status forward. Every applicant, whether a long-standing MLR-registered entity or a newer market entrant, will be assessed against the same standards from scratch.
The four assessment pillars
According to the regulator, applications will be evaluated across four areas: consumer protection, customer-asset safeguarding, market integrity, and financial resilience. Each of these carries distinct documentation and evidential requirements. Consumer protection will focus on how firms treat retail and professional clients across the product lifecycle. Asset safeguarding requirements will likely demand clear segregation of client assets, reconciliation procedures, and audit trails that are transparent enough to support a recovery scenario. Market integrity standards address surveillance, conflict-of-interest management, and the prevention of market abuse. Financial resilience requirements will scrutinize capital adequacy, liquidity buffers, and wind-down planning.
Transitional permissions while applications are assessed
One practical relief built into the process: firms that submit applications within the window and meet the relevant transitional conditions are permitted to continue providing specified cryptoasset services while their applications are under review. That includes taking on new business. This transitional protection is meaningful, but it is conditional on applying by 28 February 2027 and on satisfying the transitional criteria. Firms that miss the deadline or fall outside the conditions lose that protection entirely.
What MLR-Registered Firms Must Understand Now
The message from both the FCA and industry bodies is unambiguous: MLR registration is not a shortcut. Emma Banymandhub, CEO of The Payments Association, put it plainly in a statement to The Block, urging all firms, including those currently holding MLR registration, to approach this as a completely fresh authorization exercise and to be realistic about the standards they will need to meet. She also flagged the importance of proportionate implementation, particularly for smaller and scaling firms.
For accounting and compliance teams supporting MLR-registered crypto businesses, this means the authorization application will demand a level of internal documentation and governance that may significantly exceed what was required for initial MLR registration. The gap between the two is not trivial.
The broader background to all of this is worth keeping in mind. The UK has been building toward a comprehensive digital asset framework across multiple years. Earlier coverage of the UK digital asset regulatory framework expansion set out the policy direction that has now arrived at this practical delivery stage. What was previously a roadmap is now a deadline.
Accounting and Finance Implications for Firms
Authorization is a legal milestone, but it carries direct consequences for how a firm's finances and books need to be structured. Compliance teams and CFOs should not treat this purely as a regulatory affairs matter.
Balance sheet and capital adequacy
The financial resilience pillar of the FCA assessment will require firms to demonstrate adequate capital and, almost certainly, a credible wind-down plan. For accounting teams, this means ensuring that the firm's balance sheet is presented in a way that clearly distinguishes proprietary assets from client assets, that any digital assets held in a fiduciary capacity are properly segregated in the books and records, and that capital ratios are calculated and documented in line with whatever prudential standards the FCA specifies for the relevant firm category. Firms using crypto accounting software to manage on-chain positions should verify that their systems produce reports that satisfy these requirements cleanly, without manual reconciliation work that introduces error risk.
Client asset safeguarding and reconciliation
The safeguarding pillar will require robust reconciliation between on-chain balances and internal ledgers. For firms holding digital assets on behalf of clients, daily or near-real-time reconciliation is likely to become an expectation rather than a best practice. Digital asset accounting software that can ingest wallet-level data, map it to client accounts, and produce audit-ready reports will be a practical necessity rather than an optional upgrade. Auditors advising these firms should be asking about reconciliation frequency and exception-handling processes now, ahead of any application review.
Governance documentation
The FCA application process will require evidence of governance frameworks, not just policies on paper. Board minutes, risk committee terms of reference, conflict-of-interest registers, and approved persons records will all be relevant. Finance directors and CFOs at crypto businesses should start collecting and reviewing that documentation immediately. The February 2027 deadline sounds distant; the preparation time is not.
Implications for Accounting Firms and Auditors
Practices that serve UK crypto clients have their own preparation work to do. Audit engagements for FCA-authorized crypto firms will carry higher evidential standards than those for MLR-registered entities. Auditors will need to be comfortable opining on client asset segregation, financial resilience, and compliance with the new conduct rules, all of which may require updated engagement letters, new audit procedures, and potentially specialist training.
For firms advising on the application itself, the scope of the engagement should be clearly defined: legal authorization advice, compliance gap analysis, financial resilience assessment, and audit-readiness review are four distinct workstreams that may need to be resourced separately. Understanding the engineering decisions shaping on-chain AML screening is increasingly relevant context for practices advising on the technical side of compliance infrastructure.
The FCA has also indicated that it expects applications to reflect realistic self-assessment. Firms that overstate their readiness are likely to face prolonged review or refusal, and accounting advisers should be prepared to deliver frank assessments of where their clients' governance and financial reporting currently falls short of the incoming standards.
Key Dates at a Glance
| Date | Event |
|---|---|
| June 2026 | UK crypto regulatory framework published, setting scope of activities requiring authorization |
| 30 September 2026 | FCA begins accepting authorization applications |
| 28 February 2027 | Deadline for submitting an application to benefit from transitional permissions |
| 25 October 2027 | New FCA crypto regime takes effect |
Frequently Asked Questions
Does my existing MLR registration convert automatically into FCA authorization?
No. The FCA has confirmed that registration under the Money Laundering Regulations does not carry over. Every firm, regardless of its current status, must apply through the new authorization process and demonstrate compliance with the incoming standards from scratch.
What happens if a firm applies during the window but has not yet received a decision by October 2027?
Firms that apply by 28 February 2027 and satisfy the relevant transitional conditions are permitted to continue providing specified cryptoasset services, including taking on new business, while their applications are being assessed. This transitional protection is conditional on meeting the criteria and on submitting within the deadline.
Which crypto activities fall within the new authorization scope?
The framework covers firms facilitating trading, transaction execution, staking, and digital asset custody. It also introduces requirements around cryptoasset admissions and disclosures, market abuse, prudential standards, and consumer protection. Firms with DeFi-adjacent or intermediary activities should seek specific legal advice on whether their services are captured.
What will the FCA actually assess in an authorization application?
The FCA has identified four pillars: consumer protection, customer-asset safeguarding, market integrity, and financial resilience. Each requires substantive evidence, not just policy documents. Governance frameworks, capital adequacy, client asset reconciliation procedures, and market surveillance arrangements are all likely to be scrutinized.
How should accounting firms prepare their crypto clients for the application process?
Practices should begin with a gap analysis across the four FCA assessment pillars. Key workstreams include reviewing client asset segregation in the books and records, assessing capital and liquidity positions against anticipated prudential requirements, auditing governance documentation, and verifying that crypto bookkeeping software or digital asset accounting software produces audit-ready reports without manual reconciliation gaps. The February 2027 deadline requires starting this work now.
Source: The Block
