Do you need FCA crypto authorisation or AML registration?
One of the first questions cryptoasset firms ask is deceptively simple: do we need to be registered or authorised by the FCA?
The answer depends on what the firm does, where it does it, who it serves and which regime is being considered. At present, many UK cryptoasset businesses are primarily subject to the FCA’s supervision under the Money Laundering Regulations and the financial promotions regime. The new regime will go much further, bringing specified cryptoasset activities into the FSMA authorisation framework.
Firms should be careful not to treat those regimes as interchangeable. They serve different purposes, impose different obligations and require different evidence. Firms should ensure their compliance framework reflects the regime that applies to their activities.
AML registration is not FSMA authorisation
FCA crypto registration under the current regime is focused on anti-money laundering and counter-terrorist financing. Cryptoasset exchange providers and custodian wallet providers that are in scope must register with the FCA under the Money Laundering Regulations before carrying on relevant business in the UK.
That registration is important, but it is not a general licence to conduct all cryptoasset activity. It does not mean the FCA has approved the firm’s wider conduct, prudential resources, market abuse arrangements, safeguarding framework, Consumer Duty implementation or business model in the same way as a FSMA authorisation assessment.
This distinction between AML registration and FSMA authorisation will become more important as the new regime commences. A firm that is already registered under the MLRs should not assume that registration automatically confers permission to carry on regulated cryptoasset activities. The firm will need to assess which activities it carries on and whether it requires Part 4A permission or a variation of permission.
Financial promotions are a separate question
A firm may be outside the MLR registration regime but still exposed to the financial promotions restriction if it communicates invitations or inducements to engage in cryptoasset activity to UK consumers. The financial promotions regime is about how products and services are marketed. It is not the same as registration or authorisation.
That creates a practical trap. A firm may conclude that it does not need MLR registration because it has no UK establishment. But if it markets cryptoasset services to UK consumers, it may still need to consider how those promotions are lawfully communicated or approved.
Payment firms, e-money institutions, and on- and off-ramp providers should also be alert to this. The FCA has specifically warned about fiat-to-crypto and crypto-to-fiat ramp services being provided to firms that may be illegally promoting to UK consumers. The risk is not limited to the crypto firm itself. Firms providing payment rails can become part of the regulatory problem if they facilitate activity without adequate due diligence.
The future regime is based on regulated activities
The new FSMA cryptoasset regime will focus on regulated activities. Firms will need to map their business model against the perimeter. That analysis should include activities such as operating a qualifying cryptoasset trading platform, safeguarding cryptoassets, dealing, arranging, lending and borrowing, staking and issuing qualifying stablecoins.
The perimeter assessment should be granular. A group may have several entities performing different functions: one contracting with customers, another operating technology, another providing custody, another arranging transactions, another issuing a token and another providing fiat payment rails. The regulatory answer may differ for each entity.
This is why a superficial “are we a crypto firm?” analysis is not enough. The question is: which legal person carries on which activity, in relation to which asset, for which customer, from which location, and through which contractual structure?
What firms should be doing now
Firms considering FCA crypto registration or future FCA authorisation should prepare a permissions map. This should identify:
- the current MLR registration position;
- any existing FSMA permissions;
- any payment services or e-money permissions;
- all cryptoasset activities currently carried on;
- proposed future activities;
- the legal entity performing each activity;
- the UK territorial nexus;
- financial promotions routes;
- any reliance on third parties;
- expected changes under the new regime.
This map should be owned by senior management and kept under review. It will be central to FCA authorisation application planning and provide valuable guidance during discussions with advisers, auditors, investors and regulators.
Practical insight
The most common perimeter problems arise where firms focus on the product rather than the activity. A token, wallet or platform label will rarely answer the question. The firm needs to analyse what it actually does and ensure the supporting information accurately reflects those activities..
For example, a firm may describe itself as a technology provider. Still, if it controls customer onboarding, transaction execution, custody arrangements or customer communications, the FCA may look beyond that label. Equally, a firm may describe itself as overseas, but still create UK regulatory issues through UK-facing promotions, UK customers, UK staff, UK operations or UK group entities.
Why Part 4A permission and FCA authorisation matter
A poor perimeter analysis can undermine the entire authorisation project. If the firm applies for the wrong permissions, fails to include a key activity, or misunderstands which entity is in scope, the FCA may have significant concerns about the firm’s understanding of its regulatory obligations.
That is avoidable. Perimeter analysis should be one of the first workstreams, not a footnote at the end of the application.
**Download our complimentary C&G Guide to FCA Cryptoasset Authorisation and Regulation** for a practical framework for mapping permissions, regulated activities and application readiness.

