UK Plans to Expand Its Digital Asset Regulatory Framework
HM Treasury is preparing a consultation on a broad new set of crypto rules that would be inserted into the Financial Services and Markets Bill, the legislation currently moving through Parliament. The proposals go well beyond the stablecoin supervision measures already in the Bill: they would restrict foreign crypto companies from accessing UK markets without meeting defined conditions, introduce explicit consumer protection requirements, and create mechanisms for the orderly wind-down of failed crypto businesses. For accounting firms, auditors, and CFOs, this signals a step-change in the compliance environment, one that requires action on record-keeping, counterparty due diligence, and financial statement disclosures well before any rules come into force.
What HM Treasury Is Proposing and Why Now
The UK's relationship with crypto regulation has been uneven. Earlier, Prime Minister Rishi Sunak, then serving as Chancellor, set out an ambition for the UK to become a hub for crypto innovation. That aspiration was broadly welcomed by industry, but it sat alongside an FCA that held a solid AML registration regime for cryptoasset businesses yet lacked a legislative mandate to police market conduct in crypto markets. The forthcoming consultation is designed to close that gap.
The three pillars of the proposed rules
Based on what has been reported, the consultation is expected to cover three broad areas:
- Foreign firm access restrictions. Crypto businesses headquartered outside the UK would face conditions before they can serve UK customers or markets. This mirrors the third-country regime logic embedded in the EU's MiCA framework, and it has direct implications for any firm whose clients use offshore exchanges.
- Consumer protection requirements. These would likely include standards for how crypto products are marketed, disclosed, and sold to retail and professional customers. The FCA has already published guidance on cryptoasset advertising, so this pillar builds on existing supervisory expectations rather than starting from scratch.
- Orderly wind-down provisions. The absence of clear rules on what happens when a crypto firm collapses has been a live problem. The proposed amendments would introduce a framework for managing firm failure in a way that protects client assets and minimises contagion, a concern that has become acute following high-profile exchange collapses globally.
The legislative vehicle
Attaching these measures to the Financial Services and Markets Bill rather than creating standalone legislation is a deliberate choice. It accelerates the timeline for giving the FCA formal rule-making powers in this area, and it means the new regime will sit within the same statutory architecture as the rest of UK financial services regulation. Firms already regulated under FSMA will find the obligations conceptually familiar, even if the crypto-specific details are new.
How the UK Compares to the EU, Hong Kong, and the US
The UK's move does not happen in isolation. Three other major jurisdictions took significant regulatory steps in the same period, and firms with cross-border exposure need to track all of them simultaneously.
EU: MiCA nears completion
The EU's Markets in Crypto-Assets regulation is in its final legislative stages. MiCA is a comprehensive framework: it requires cryptoasset exchanges and other service providers to safeguard customer funds, meet prudential standards, and put anti-market-manipulation controls in place. EU lawmakers have argued publicly that a MiCA-type regime in place globally could have reduced the severity of recent exchange failures. The crypto industry's response to MiCA has been largely constructive, with participants welcoming the regulatory clarity even as compliance costs rise.
For UK firms, the comparison matters commercially. Some industry voices have warned that the UK's historically fragmented approach to crypto oversight could allow France and other EU members to position themselves as the preferred domicile for crypto innovation within a clear regulatory perimeter. HM Treasury's consultation is partly a response to that competitive pressure.
Hong Kong: mandatory VASP licensing now law
Hong Kong's Legislative Council passed the Anti-Money Laundering and Counter-Terrorist Financing (Amendment) Bill 2022, which converts the previously voluntary licensing framework for crypto firms into a mandatory regime. Under the new law, virtual asset service providers (VASPs) must obtain a licence from the Securities and Futures Commission before offering services in Hong Kong. Licensing brings with it AML requirements, KYC obligations, transaction monitoring, and compliance with the Financial Action Task Force (FATF) Travel Rule, which requires VASPs to share customer data on crypto transfers with counterparty service providers.
The shift from opt-in to mandatory licensing is significant. Firms that previously operated in Hong Kong under the SFC's voluntary framework now face a hard deadline to meet full licensing conditions. Counterparty due diligence for any firm transacting with Hong Kong-based VASPs must reflect this change.
US: the SEC raises the disclosure bar
The SEC's Division of Corporation Finance issued a staff statement directing companies under SEC oversight to disclose material exposure to crypto markets, citing the direct impact of recent exchange failures on broader financial stability. The statement included a sample letter setting out the questions firms should work through when assessing whether their crypto-related risk exposure is material enough to require disclosure in public filings.
SEC Chair Gary Gensler separately reaffirmed that enforcement actions against unregistered crypto securities trading platforms will continue. Combined, these two signals mean that US-listed companies and their auditors face rising disclosure scrutiny, and that firms providing audit or assurance services to such clients need clear processes for assessing and documenting crypto exposure at the financial statement level.
The US Federal Trade Commission is also investigating multiple crypto firms for potentially deceptive advertising practices, adding a consumer protection enforcement dimension that complements the SEC's securities-focused work.
Accounting and Audit Implications for Firms
Regulatory expansion across these four jurisdictions creates concrete work for accounting practices and in-house finance teams. The obligations do not all sit neatly in the future: several are live now.
Financial statement disclosures
The SEC's staff statement is the clearest signal that crypto-related risk must be reflected in financial statements where it is material. For firms preparing or auditing accounts for entities with direct crypto holdings, indirect exposure through counterparties, or revenue streams linked to crypto markets, the disclosure question is no longer optional. Under both IFRS and US GAAP, management needs to assess whether crypto exposure constitutes a material uncertainty, a contingent liability, or a risk factor requiring narrative disclosure.
Robust crypto accounting software is essential here: without a consolidated, auditable view of token holdings, counterparty relationships, and transaction history, neither management nor auditors can make that materiality assessment with confidence. Digital asset accounting software that integrates on-chain data with general ledger entries reduces the manual reconciliation burden and creates the audit trail that regulators and standard-setters increasingly expect.
AML and KYC programme updates
The Hong Kong mandatory licensing regime and the UK's proposed consumer protection and foreign-firm-access rules both tighten the AML and KYC requirements that apply to VASPs and, by extension, to the financial institutions and professional firms that service them. The FATF Travel Rule is now embedded in Hong Kong law, and similar provisions are expected to feature in the UK consultation. Accounting firms acting as business introducers, agents, or advisers to crypto businesses need to review whether their own AML frameworks adequately cover these counterparty risks. For background on how real-time asset freezes create parallel AML and accounting obligations, see our analysis of how stablecoin freezes create AML and accounting obligations.
Counterparty and indirect exposure mapping
The SEC's emphasis on indirect exposure is a reminder that a firm does not need to hold crypto directly to face material risk. Loans to crypto businesses, treasury accounts held at crypto-adjacent banks, or significant client relationships with VASPs can all create exposure that needs to be identified, measured, and disclosed. Crypto bookkeeping software with VASP entity mapping capabilities makes this process tractable; without it, firms are relying on manual spreadsheets that are difficult to audit and easy to get wrong.
The evolving threat of identity fraud at onboarding also remains relevant: for a detailed look at how synthetic identity attacks are undermining KYC controls, see our piece on deepfake fraud and what it means for KYC programmes.
What Firms Should Do Before the UK Consultation Closes
The consultation has not yet launched, which creates a window for firms to prepare rather than react. Three priorities stand out.
Map your clients' VASP relationships now
The proposed restriction on foreign crypto firms accessing UK markets will require firms to identify which of their clients are using offshore exchanges or custody providers. That mapping exercise takes time. Starting it before draft rules are published means you are ready to advise clients on the compliance gap rather than scrambling to identify it after the fact.
Review wind-down and contingency accounting policies
The proposed wind-down provisions signal that regulators expect crypto businesses to have credible recovery and resolution plans. Accounting firms advising crypto businesses should be reviewing whether their clients have adequate policies for asset segregation, client money protection, and going-concern assessment. The same review is relevant for any entity with material exposure to a crypto counterparty that could itself face financial distress.
Align your digital asset accounting software stack with multi-jurisdictional requirements
MiCA, the Hong Kong licensing regime, and the anticipated UK rules all have reporting and record-keeping dimensions. Firms operating across these jurisdictions need a single source of truth for transaction data, not separate manual processes for each jurisdiction. Digital asset accounting software that supports multi-jurisdiction reporting reduces duplication and makes regulatory examinations significantly less disruptive.
Frequently Asked Questions
What is HM Treasury consulting on, and when will the consultation launch?
HM Treasury is preparing to consult on additions to the Financial Services and Markets Bill that would restrict foreign crypto firms' UK market access, strengthen consumer protection in crypto, and introduce orderly wind-down requirements for failed crypto businesses. The consultation was expected to launch in early 2023 based on information available at the time of reporting; firms should monitor HM Treasury and FCA channels for the formal launch date and response window.
How does the UK's proposed framework compare to MiCA?
MiCA is a comprehensive, directly applicable regulation covering cryptoasset issuers and service providers across all EU member states. The UK's proposals are still at consultation stage and narrower in initial scope, but the direction of travel is similar: mandatory licensing, consumer protection obligations, and prudential requirements for VASPs. The key difference is that MiCA is closer to final form, while the UK regime is still being shaped through consultation.
What does Hong Kong's new VASP licensing law require in practice?
All virtual asset service providers operating in or from Hong Kong must obtain a licence from the Securities and Futures Commission. Licensing conditions include AML and KYC procedures, transaction monitoring, and compliance with the FATF Travel Rule, which requires VASPs to pass customer identification data to counterparty VASPs on transfers above the relevant threshold. The previous opt-in framework has been replaced; there is no longer a choice about whether to apply.
What does the SEC's disclosure statement mean for companies with indirect crypto exposure?
The SEC's Division of Corporation Finance made clear that material exposure to crypto markets must be disclosed in public filings, and that indirect exposure, through loans, counterparty relationships, or revenue dependencies, counts. Companies and their auditors need to assess whether any crypto-linked risk is material under applicable accounting standards and, if so, ensure it is reflected in risk factor disclosures, management discussion sections, or financial statement notes.
How should accounting firms update their AML programmes in response to these developments?
Firms should review whether their client due diligence and ongoing monitoring procedures adequately cover crypto-specific risks, including exposure to VASPs in jurisdictions now subject to mandatory licensing. Where firms act as advisers or intermediaries for crypto businesses, they should confirm that their AML policies reflect the Travel Rule obligations now embedded in Hong Kong law and likely to appear in the UK and EU frameworks. Regular VASP risk assessments and counterparty mapping should be built into the annual compliance review cycle.
Source: Elliptic
