FCA Crypto Authorisation Gateway Opens: What UK Firms Must Do Now
The FCA has opened its application gateway for cryptoasset firm authorisations under FSMA Part 4A, and the window to get preparations right is not generous. For accounting firms advising digital asset businesses, CFOs inside those businesses, and auditors signing off on their financial statements, this is not a distant compliance milestone: it is an active deadline with direct implications for how digital asset activity is structured, recorded, and reported today.
From AML Registration to Full FSMA Authorisation
Until now, most UK cryptoasset firms have operated under the Financial Conduct Authority's Anti-Money Laundering registration regime, a lighter-touch gateway introduced under the Money Laundering Regulations. That regime was always meant to be temporary. The new FSMA Part 4A authorisation framework is the permanent replacement, and it carries a materially higher bar.
What the shift actually means
Under Part 4A, a cryptoasset firm must satisfy the FCA's threshold conditions, the same conditions applied to banks, brokers, and investment managers. These cover legal status, location of offices, adequate resources, business model suitability, and fitness and propriety of controllers and senior managers. The FCA will scrutinise governance arrangements, financial resilience, systems and controls, and the firm's capacity to meet ongoing regulatory obligations, not just whether it has an AML policy in place.
The practical effect is that cryptoasset businesses that have grown accustomed to the lighter AML registration requirements will need to rebuild their compliance architecture from the ground up in several areas. Controllers, nominated officers, and senior managers will each face individual assessment. Financial promotions will need to comply with rules that are already live for the broader market. Client assets, where applicable, will need to be segregated and documented in ways the FCA can verify.
The timeline pressure
With the gateway now open, firms that delay their preparation risk two compounding problems. First, they may miss internal readiness deadlines if they underestimate the work involved in producing a credible Part 4A application. Second, the FCA's own processing capacity means that early, well-prepared applications are more likely to receive focused engagement than late, incomplete ones. Firms should treat the gateway opening as the starting gun, not a distant signal.
Key Authorisation Considerations for Cryptoasset Firms
KPMG's UK Authorisations team, which has direct experience supporting firms through FSMA Part 4A applications, has identified several preparation areas that firms need to address before submitting. These map closely to what accounting and finance teams are already responsible for delivering, which is why the CFO and the external auditor need to be in the room from day one.
Governance and senior management arrangements
The FCA expects applicants to demonstrate that the business is effectively directed and controlled from the UK. For cryptoasset firms with distributed teams or offshore technology infrastructure, this requires careful thought about where decisions are actually made and how that can be evidenced. The Senior Managers and Certification Regime, where applicable, assigns individual accountability to named individuals, and the application must map responsibilities clearly. Accounting firms advising clients on this should be reviewing organisational charts, board minutes, and delegation frameworks now.
Financial resources and capital adequacy
The FCA will want to see that the firm holds adequate financial resources relative to the risks it carries. For cryptoasset firms, those risks can include operational exposures from custody arrangements, counterparty risk from trading activity, and the volatility of crypto assets held on the balance sheet. The application will need to include financial projections that are credible and stress-tested, not just aspirational. This is precisely where robust crypto accounting software and well-maintained digital asset accounting records become directly relevant: if the books cannot produce reliable, auditable figures on demand, the application will stall.
Systems, controls, and AML arrangements
While the AML registration requirement was the previous gateway condition, the Part 4A application goes significantly further. The FCA will assess the quality of transaction monitoring, the adequacy of know-your-customer processes, and how the firm handles suspicious activity reporting. For firms that have relied on manual or informal controls during the AML registration phase, this is a significant gap to close. Automated monitoring that produces auditable outputs, rather than spreadsheets and ad-hoc reviews, will need to be in place and demonstrably operational before submission. For context on what behavioural detection looks like in practice, see our earlier piece on how AML behavioural detection flags suspect wallets.
Financial promotions and consumer protections
The FCA's financial promotions regime for cryptoassets has been live since October 2023 for FCA-authorised firms. Applicants must demonstrate that their marketing and communications already comply with these rules, including clear risk warnings, fair and balanced presentation, and appropriate target market restrictions. Compliance teams should audit all existing promotional materials as part of the application process, not as an afterthought.
Accounting and Record-Keeping Implications
The authorisation process itself generates a significant accounting and documentation burden. The FCA will require financial statements, management accounts, and projections that are consistent, internally coherent, and reconcilable to underlying transaction data. For firms holding or transacting in cryptoassets on their own account, this means the accounting treatment of those assets must already be correct and consistently applied.
Asset classification and measurement
Under UK GAAP and IFRS as adopted in the UK, cryptoassets do not yet have a single prescribed standard, but the accounting policy choices a firm makes will be visible in the financial statements submitted with any application. The FCA will not audit the accounting directly, but inconsistencies between the stated business model and the accounting treatment, such as a custody firm that capitalises client assets rather than disclosing them as off-balance-sheet obligations, will raise questions. Firms should ensure their crypto bookkeeping software is configured to distinguish between proprietary holdings, client assets held in custody, and collateral positions.
Regulatory capital calculations
Once authorised, firms will face ongoing capital reporting obligations. The data infrastructure required to support those reports needs to exist before the FCA authorises the firm, because the regulator will ask how the firm intends to meet ongoing returns. Digital asset accounting software that integrates with regulatory reporting templates will reduce the operational risk of missing a return after authorisation is granted.
Audit trail requirements
The FCA's supervisory approach relies heavily on the ability to reconstruct events from records. For cryptoasset firms, this means transaction-level data needs to be immutable, timestamped, and linked to the counterparty identification records produced by KYC processes. Firms whose current record-keeping relies on exchange-generated PDFs rather than API-level data ingestion into a proper accounting system face the most remediation work. This is also the area where accounting advisers can add the most value in the pre-application phase, helping clients identify gaps and source the right digital asset accounting software before the FCA comes asking.
What Accounting Firms and CFOs Should Do Now
The preparation work for a Part 4A application is not linear, and several workstreams need to run in parallel. The accounting and finance function sits at the centre of most of them.
Immediate actions
First, map every cryptoasset activity the business conducts against the regulated perimeter the FCA has defined. Activities that fall within scope require authorisation; those that do not still need to be documented clearly so the application boundary is crisp. Second, commission an internal readiness review against the FCA's threshold conditions, treating it as a dry run for what the regulator will assess. Third, review the firm's current accounting policies for digital assets and ensure they are documented, consistently applied, and defensible under UK GAAP or IFRS. Fourth, assess whether the current crypto accounting software and data infrastructure can produce the reports the FCA will require, both for the application and on an ongoing basis after authorisation.
Longer-term structuring
Firms that intend to expand their cryptoasset activities after authorisation should consider how the authorisation perimeter will accommodate future products. Adding a new regulated activity after initial authorisation requires a variation of permission, a further FCA process. Building the right perimeter into the initial application is more efficient than returning to the FCA repeatedly. For accounting advisers, this is also a conversation about how the chart of accounts, revenue recognition policies, and segment reporting should be structured to reflect a potentially expanding product set.
The broader European regulatory context is also worth watching. As ESMA's 2027 digital innovation supervisory priority makes clear, regulators across the region are tightening their grip on digital asset firms simultaneously. UK firms with any EU nexus need to consider how their Part 4A authorisation interacts with MiCA obligations or any EU passporting decisions.
Frequently Asked Questions
What is the FCA's FSMA Part 4A authorisation and why does it matter for cryptoasset firms?
Part 4A of the Financial Services and Markets Act is the statutory gateway through which firms obtain permission to carry on regulated financial services activities in the UK. As the FCA brings cryptoasset activities within the regulated perimeter, firms must apply through this gateway rather than relying on the lighter AML registration that previously served as the main FCA touchpoint for crypto businesses. The threshold conditions firms must meet are materially more demanding, covering governance, financial resources, systems and controls, and individual fitness and propriety.
How does the authorisation process affect a firm's accounting and financial records?
The application requires auditable financial statements, management accounts, and capital projections. These documents must be internally consistent and reconcilable to underlying transaction data. Accounting policies for digital assets need to be documented and consistently applied. Weaknesses in record-keeping or inconsistent treatment of cryptoassets will slow the application or prompt the FCA to request further information, extending the process.
Does the FCA's crypto authorisation regime apply to firms already registered under the Money Laundering Regulations?
Yes. The AML registration was always a transitional measure. Firms currently registered under the MLRs for cryptoasset activity need to apply for full Part 4A authorisation through the new gateway. Operating without that authorisation once the transitional period ends would constitute a regulatory breach.
What role does crypto accounting software play in a successful Part 4A application?
The FCA expects firms to demonstrate that their systems and controls are adequate on an ongoing basis, not just at the point of application. Firms need to show they can produce reliable, auditable financial data, distinguish client assets from proprietary holdings, and support transaction monitoring. Digital asset accounting software that integrates with KYC data and generates auditable outputs is a practical prerequisite, not a nice-to-have, for a credible application.
What should external auditors and accounting advisers prioritise when supporting a client through this process?
Three areas stand out. First, review and document the client's accounting policies for digital assets and confirm they are consistent with the stated business model. Second, assess whether the client's data infrastructure can support the FCA's ongoing reporting requirements after authorisation, not just the initial application. Third, map the regulated perimeter carefully so the application covers all in-scope activities without creating ambiguity about out-of-scope operations. Early involvement reduces the risk of last-minute remediation that delays the submission.
Source: KPMG
