Five lessons from FTX every crypto firm should learn before applying to the FCA
The FTX crypto collapse will continue to shape crypto regulation for years to come. It is easy to describe it as a fraud case and move on. That would miss the regulatory lessons.
For firms preparing for FCA crypto authorisation, FTX is a case study in what regulators are now determined to test: client asset protection, conflicts, related-party arrangements, group governance, financial resources, record-keeping, disclosures, senior management accountability, and wind-down.
The point is not that every crypto firm resembles FTX. The point is that regulators have seen what can happen when a fast-growing crypto group combines customer assets, trading activity, affiliates, opaque governance and weak controls. The new UK regime should be read against that background.
1. Customer asset protection must be evidenced
The central safeguarding question arising from FTX is not whether management says customer assets are safe. It is a matter of whether the firm can prove it.
That means clear client asset records, wallet controls, reconciliations, segregation, third-party custody oversight, private key governance, liability analysis, contractual clarity and wind-down arrangements. Firms should be able to explain how assets are controlled in normal operation and how they would be returned if the firm or a key service provider failed.
This is where cryptoasset custody starts to look much more like CASS. The technology is different, but the regulatory concern is familiar: can customers’ assets be identified, protected and returned without avoidable delay or loss?
2. Conflicts cannot be managed informally
One of the most important lessons from the FTX collapse is the danger of related-party complexity. Exchanges, market-makers, proprietary trading affiliates, token issuers, custodians, and lending businesses may be part of the same group or operate under common control. That creates conflicts.
A crypto firm seeking authorisation should identify conflicts at the business model stage. Does the platform trade against clients? Does a group affiliate provide liquidity? Does the firm list or promote tokens issued by connected parties? Are customer assets used in lending, staking or collateral arrangements? Is there any preferential access to data, order flow or execution?
The answer may not always be that the activity is prohibited. But the firm must identify, manage, disclose and evidence the control framework.
3. Group structure and FCA supervision
International crypto firms and groups often use multiple entities across several jurisdictions. That can be commercially sensible, but it can also make supervision difficult.
The FCA will want to understand which entity does what, where staff are located, where systems are controlled, who contracts with customers, who holds assets, who owns the technology, who receives revenue, who provides liquidity and who makes decisions. If the UK firm depends on offshore affiliates for core functions, those dependencies must be documented, controlled, and subject to supervision.
A group chart is not enough. The application should explain the operating model.
4. Wind-down planning and financial resilience must be practical
The FTX bankruptcy also demonstrates why wind-down planning matters. Crypto firms can move from confidence to crisis quickly. Market events, cyber incidents, liquidity stress, regulatory action, banking disruption or loss of a key service provider can rapidly affect the ability to operate.
An FCA-ready wind-down plan should explain triggers, governance decisions, communications, customer asset return, liquidity, key personnel, legal dependencies, technology access, third-party cooperation and insolvency steps. It should be based on the actual business, not a generic template.
5. Culture and governance are control issues
Governance is sometimes discussed as though it were limited to board minutes and committee terms of reference. It is broader than that. It is about whether the firm has people with the knowledge, independence, information and authority to challenge the business.
A board cannot oversee what it does not understand. A compliance function cannot monitor controls it cannot access. A UK entity cannot be accountable for decisions made elsewhere without visibility or authority. A risk framework cannot work if commercial growth always wins.
Those are not abstract governance points. They are the issues that determine whether a firm can be trusted with regulated activity.
Practical insight for firms preparing for FCA crypto authorisation
Before applying for authorisation, senior management should ask:
- Can we evidence where customer assets are at all times?
- Can we explain every related-party arrangement?
- Can we show how conflicts are identified and escalated?
- Can the UK firm control outsourced or group-provided services?
- Do we have realistic wind-down triggers?
- Would our board MI identify emerging stress?
- Do our customer disclosures match what actually happens?
If the answer is unclear, the firm is not yet ready.
How C&G can help with FCA crypto authorisation
C&G helps crypto firms preparing for FCA authorisation translate regulatory expectations into practical operating models. The lessons from FTX are not merely crypto. They are lessons about governance, client asset protection, conflicts, prudential resilience and senior management accountability – all areas in which the FCA has long-standing expectations across regulated financial services.
**Download our complimentary C&G Guide to FCA Cryptoasset Authorisation and Regulation** for further practical insight into safeguarding, governance and authorisation readiness.

