The UK’s cryptoasset regime is finally here – but it isn’t really about crypto

The UK’s new cryptoasset regulatory framework is often described as a crypto regime. That is understandable, but it is not the most useful way for firms to think about it.

The more practical point is this: FCA crypto authorisation is about applying familiar financial services disciplines to cryptoasset business models. Authorisation, governance, safeguarding, prudential resources, market integrity, Consumer Duty, financial crime controls, operational resilience and senior management accountability are not new concepts. What is new is the way those concepts are being applied to exchanges, custodians, stablecoin issuers, staking providers, lenders, arrangers and international crypto groups.

The distinction is important. Firms that treat the new regulations as just another set of crypto rules may overlook what the FCA will actually assess. The FCA will want to know not only what the technology does but also who controls the firm, how decisions are made, how risks are identified, how customer assets are protected, how conflicts are managed, how financial crimes are prevented, how the firm can wind down, and whether senior management comprehends the regulated activities being conducted.

The regime is built from familiar components

Examine the key components for various entities in the trading ecosystem. Trading platforms require rules, access criteria, structured market arrangements, conflict management systems, transparency measures, record-keeping, and market abuse controls. Custodians must implement safeguarding arrangements, conduct reconciliations, manage wallet governance, control private keys, ensure third-party oversight, and provide client disclosures. Stablecoin issuers need backing assets, clear redemption processes, asset segregation, trust arrangements, and full disclosures. Intermediaries should focus on conduct controls, order-handling practices, governance for best execution, and transparent customer reporting. 

In addition to the above, all firms in this sector need to prioritise prudential resources, operational resilience, financial crime prevention measures, the implementation of Consumer Duty, and accountability from senior management.

All of these requirements are closely aligned with the existing regulatory frameworks that govern investment firms, payment institutions, e-money institutions, and wholesale market participants. Therefore, crypto firms should not only focus on crypto-specific policy statements. They should also explore lessons from established regulations such as the Client Assets Sourcebook (CASS), the Investment Firm Prudential Regime (IFPR), the Internal Capital Adequacy Assessment (ICARA), the payment services regime, market abuse enforcement measures, financial promotions supervision, operational resilience efforts, and the practices surrounding FCA authorisations.

The FCA will expect evidence, not aspiration

A common mistake in authorisation projects is to assume that policies are enough.  They are not. The new cryptoasset regime will be no different. The FCA will expect firms to demonstrate that the operating model is real, resourced and capable of being supervised. Firms should also be able to demonstrate that their target operating model is fully understood, appropriately resourced and capable of operating within the regulatory framework.

That means firms should be able to explain, in practical terms, how their businesses work. Who holds customer assets? What happens if a wallet provider fails? How are private keys controlled? Which entity contracts with the client? Which entity books the trade? Where are decisions made? What does the UK board receive? What happens if a suspicious wallet interacts with the platform? How is a stablecoin redemption processed? What triggers a wind-down? How does the firm evidence that customer communications are understood?

The application should not read like a theory of compliance. It should read like a firm that is ready to operate.

Crypto firms should learn from traditional finance

The strongest crypto authorisation projects are likely to borrow heavily from existing regulated sectors.

Investment firms can offer valuable insights to crypto firms in several key areas. From investment firms, crypto firms can learn how to build effective governance structures, develop permission maps, maintain risk registers, conduct compliance monitoring, implement market abuse surveillance, and establish prudential frameworks. 

In the realm of payments and e-money, they can gain knowledge about safeguarding customer funds, conducting reconciliations, ensuring operational resilience, managing financial crime risks, and tracking customer fund flows. 

When it comes to Client Asset Sourcebook (CASS), crypto firms can understand the importance of maintaining accurate records, segregating assets, preparing resolution packs, and overseeing third-party arrangements. 

Additionally, through the Investment Firms Prudential Regime (IFPR) and Internal Capital Adequacy Assessment (ICARA) frameworks, they can learn to assess risks, evaluate capital and liquidity needs, conduct stress tests, and systematically plan for wind-down procedures. 

Finally, from the Consumer Duty guidelines, they will recognise that disclosure is insufficient if customers do not fully understand the product or if the support journey fails to meet their needs.

This is where many crypto firms will need to change their mindset. The question is not simply, “What does the crypto rule say?” The better question is, “What would the FCA expect a well-run regulated firm to have in place?”

The international dimension matters

Many crypto groups are international. Some will already be preparing for the Markets in Crypto-Assets Regulation (MiCA). Others will operate through offshore entities, EU crypto-asset service providers (CASPs), payment institutions, technology companies and local UK entities. That creates a risk of duplicated policies, inconsistent controls and unclear accountability.

The better approach is to build one global control architecture and then create local UK and EU overlays. Core controls – governance, financial crime, safeguarding, market integrity, operational resilience and prudential planning – should be designed consistently. The local overlays should then explain where the UK regime, MiCA or another jurisdiction requires something different.

That approach is more efficient, but it only works if the firm has properly mapped the group structure, activities, permissions, booking model, outsourcing, customer journeys, and ownership of controls.

Practical insight

Firms should start with a gap analysis, but it should not be a spreadsheet exercise. It should test whether the firm can explain and evidence the following:

  • which regulated activities it carries on;
  • which legal entity carries them on;
  • which customers are in scope;
  • which assets and services are covered;
  • where key decisions are made;
  • how customer assets are controlled;
  • how financial crime risks are managed;
  • what MI senior management receives; and
  • what happens if the business fails.

That is the start of an FCA-ready authorisation project under the UK’s cryptoasset regime.

How C&G can help

C&G Regulatory Solutions has experience advising cryptoasset firms on the regulatory perimeter and crypto financial promotions, alongside extensive practical experience across FCA authorisations, variations of permission, capital markets, payments, e-money, prudential regulation, governance and financial crime. That combination matters because the new crypto regime is not being built in isolation. It is the FCA applying familiar regulatory expectations to a new sector.

We also help firms develop and review regulatory business plans that accurately reflect their operating model and support robust FCA crypto authorisation applications.

**Download our complimentary C&G Guide to FCA Cryptoasset Authorisation and Regulation** for a practical overview of the new regime and the steps firms should be considering now.