What makes a strong FCA crypto authorisation application?

Cryptoasset firms preparing for FCA authorisation should resist the temptation to begin by writing policies.

Policies matter. But they are not the application. A strong crypto authorisation application should show that the firm understands its business model and risks, has the right people, has adequate resources, and has implemented controls that can operate in practice.

The FCA’s authorisation process is not a box-ticking exercise. It is a gateway assessment. The question is whether the applicant meets the relevant conditions and can be supervised effectively. For cryptoasset firms, that assessment is likely to be detailed because the market is fast-moving, cross-border, technologically complex and associated with significant financial crime, consumer protection and market integrity risks.

Start with a clear crypto business model

The application should explain what the firm does in plain English. It should avoid vague descriptions such as “digital asset solutions” or “blockchain infrastructure” and instead set out:

  • the products and services offered;
  • the assets involved;
  • the target customers;
  • the customer journey;
  • the contractual structure;
  • the transaction flow;
  • the custody model;
  • the revenue model;
  • the jurisdictions involved;
  • the group entities and third parties involved.

If the FCA cannot understand the business, it cannot assess the risks. If the firm cannot explain the business clearly, that may itself raise concerns.

Explain the FCA permissions logic

The crypto authorisation application should include a clear analysis of permissions. Which regulated activities is the firm applying for? Why? Which activities are not being applied for? Why not? Which exclusions or assumptions are being relied on? How will the firm prevent activity drifting outside its permissions?

This is particularly important for firms with multiple business lines. An exchange may also hold custody of assets, arrange deals, provide staking, operate lending products, or provide fiat on- and off-ramps through group entities. A stablecoin issuer may also operate wallets, distribution arrangements or payment functionality. An international platform may have UK and non-UK order books, as well as affiliates and service companies.

The permissions analysis should be consistent with the business plan, financial projections, customer terms, organisational chart, outsourcing arrangements and compliance monitoring plan.

Governance needs to be real

Crypto firms often grow quickly and informally. That can be a strength commercially, but it is not enough for authorisation. The FCA will expect governance arrangements that match the nature, scale and complexity of the business.

A strong application should explain the board and committee structure, senior management responsibilities, reporting lines, conflicts management, risk ownership and management information. It should also explain how the UK entity will control outsourced or group-provided functions.

This is especially important for international firms. The FCA will want to know where decisions are made and whether the UK firm can be supervised effectively. A UK entity that merely books revenue while key decisions are made offshore is unlikely to be a comfortable model.

Financial crime will be a central workstream

Financial crime should not be treated as one policy among many. For cryptoasset firms, it will be a core authorisation issue.

The application should include a business-wide financial crime risk assessment, customer risk methodology, CDD and EDD procedures, sanctions controls, wallet screening, Travel Rule arrangements, transaction monitoring, suspicious activity reporting, staff training and governance escalation. Firms should also explain how blockchain analytics are used, where they are not used, and how the firm validates the effectiveness of those tools.

The FCA will not be reassured by generic AML policies lifted from another sector. The framework needs to reflect the firm’s actual products, customers, assets, jurisdictions, delivery channels and wallet flows.

Cryptoasset safeguarding and custody must be operationally detailed

For firms safeguarding client cryptoassets, the FCA will expect more than a statement that assets are held securely. The application should explain wallet architecture, private key governance, signing arrangements, segregation, reconciliations, client asset records, third-party custody, incident response, liability, disclosures and wind-down.

This is where firms should learn from CASS and payments safeguarding. The key question is not simply whether assets are safe in normal operation. It is about whether the firm can identify, protect, and return client assets under stress, including during operational disruption or insolvency.

Prudential Requirements and wind-down planning should not be left until the end

Crypto firms should prepare early for capital, liquidity, concentration risk, stress testing and wind-down planning under the FCA’s new crypto regime. The FCA will expect firms to understand how their risks translate into financial resources and how the business could be wound down in an orderly way.

Wind-down planning should be practical. It should identify triggers, funding, key staff, third-party dependencies, customer communications, asset return processes, technology dependencies, legal constraints and insolvency considerations. A plan that says the firm would stop taking new clients is not enough.

Practical insight: Building a strong crypto authorisation application

A strong application pack should be internally consistent. The risk assessment should match the business plan. The compliance monitoring plan should test the controls described in the policies. The financial projections should reflect the permissions sought. The governance structure should match the outsourcing model. The wind-down plan should reflect the actual custody and customer arrangements.

Inconsistent applications create unnecessary FCA questions and delay.

How C&G can help with FCA crypto authorisation

C&G has assisted capital markets firms with a range of permission- and authorisation-related work, with a strong track record of successful outcomes. That experience is directly relevant to crypto firms preparing for the FCA gateway. A successful crypto authorisation application will need to be detailed, credible and evidence-based.. It will also require advisers who understand cryptoasset regulation and how the FCA assesses regulated businesses in practice.

**Download our complimentary C&G Guide to FCA Cryptoasset Authorisation and Regulation** for a practical authorisation readiness framework.