/
/
/
Cryptoasset FCA Authorisation: Common Application Mistakes and How to Avoid Them

Cryptoasset FCA Authorisation: Common Application Mistakes and How to Avoid Them

As the UK moves closer to implementing its expanded cryptoasset regulatory regime, an increasing number of firms are preparing for Financial Conduct Authority (FCA) authorisation for the first time. For many, this represents a significant shift from operating in a largely unregulated environment to one that requires robust governance, controls and oversight.

However, FCA authorisation is not a procedural exercise. Applications are subject to detailed scrutiny, and many firms underestimate the level of preparation required. Weak or incomplete applications can result in significant delays, requests for further information or outright refusal.

Understanding the FCA’s expectations and addressing common weaknesses early can significantly improve your chances of a successful outcome.

Understanding the FCA’s expectations

The FCA’s approach to cryptoasset regulation is risk-focused and outcomes-driven. Firms are expected to demonstrate that they can operate in a way that protects consumers, maintains market integrity and prevents financial crime.

This means that your application must go beyond simply describing your business model. You need to show how your governance, systems and controls support compliant and responsible operations in practice.

In particular, the FCA will expect clear evidence that:

  • your business model is well understood and properly documented
  • risks have been identified and are actively managed
  • governance arrangements are appropriate for the scale and complexity of your activities
  • senior management understands its responsibilities

Applications that are overly high-level or lack detail are a common cause of delay. The FCA expects substance and clarity, not generic statements.

Determining whether your activities require authorisation

Before starting an application, it is critical to assess whether your activities fall within the scope of FCA regulation. This is not always straightforward, particularly given the evolving nature of cryptoassets and business models. Activities such as operating a crypto exchange, issuing tokens, providing custody services or facilitating transactions may all trigger regulatory requirements, depending on how they are structured.

A key risk at this stage is misclassification. Some firms assume they are not within scope, only to discover later that authorisation is required. Others adopt an overly cautious approach, leading to unnecessary complexity.

Clarity at the outset allows you to structure your application appropriately and avoid delays further down the line. It also ensures that your regulatory strategy aligns with your commercial objectives.

Governance deficiencies that delay applications

Governance is one of the most common areas where applications fall short. The FCA places significant emphasis on the role of senior management in overseeing regulated activities and ensuring compliance.

Weak governance structures often include unclear reporting lines, insufficient board oversight or a lack of suitably experienced individuals in key roles. In some cases, firms fail to demonstrate that decision-making processes are properly documented or that risks are escalated effectively.

Strong governance requires more than a formal structure. It should show how the business operates in practice and how decisions are made. This includes having clearly defined roles and responsibilities, effective oversight arrangements and a culture of accountability. Without this, the FCA is likely to question whether the firm can meet its ongoing regulatory obligations.

AML and financial crime controls

Anti-money laundering (AML) and financial crime controls are central to the FCA’s assessment of cryptoasset firms. Given the inherent risks associated with digital assets, this is an area of intense scrutiny. If your cryptoasset business is already registered with the FCA under the Money Laundering Regulations, that registration will not automatically convert into authorisation under the incoming UK cryptoasset regime. If you intend to continue carrying on in-scope cryptoasset regulated activities in or to the UK once the new regime comes into force, expected on 25 October 2027, you will need to secure the relevant FCA authorisation under FSMA in advance.. I

If you intend to apply for authorisation under the new regime without prior MLR registration, do note that FCA authorisation applications for companies in other areas of finance such as payment services, investment firms or insurance brokers  have been impacted because AML frameworks are underdeveloped or not tailored to the specific risks of the business. Generic policies, copied from other sectors, are unlikely to be sufficient.

Your controls should address the full lifecycle of your operations, from customer onboarding and due diligence to transaction monitoring and reporting. This includes identifying high-risk customers, detecting suspicious activity and ensuring that appropriate escalation procedures are in place.

Firms should be prepared to demonstrate how their systems operate in practice. This includes providing detailed descriptions of processes, supporting documentation and, where relevant, evidence of testing and monitoring. A well-developed AML framework is not only a regulatory requirement but also a key factor in building trust with clients and counterparties.

Operational resilience requirements

Operational resilience has become a significant focus for regulators and is particularly relevant in the context of technology-driven businesses such as cryptoasset firms.

The FCA expects firms to identify their important business services, assess potential vulnerabilities and ensure that they can continue operating in the event of disruption. This includes managing risks related to cyber security, third-party providers and system failures. Applications often fall short where operational resilience is treated as an afterthought. High-level statements about continuity planning are unlikely to satisfy the regulator.

Instead, you should be able to demonstrate a clear understanding of:

  • your critical systems and dependencies
  • potential points of failure
  • response and recovery plans
  • testing and review processes

Embedding resilience into your operational model is essential, both for regulatory approval and for maintaining client confidence.

Financial resources and prudential expectations

The FCA will also assess whether your business has sufficient financial resources to operate sustainably. This includes considering capital adequacy, liquidity and access to funding. Applications can be delayed where financial projections are unrealistic, unsupported or inconsistent with the business model. The FCA expects firms to provide credible forecasts, supported by clear assumptions and evidence.

It is also important to demonstrate that your business can withstand periods of stress. This may involve scenario planning or sensitivity analysis to show how your financial position would respond to adverse conditions. A strong financial foundation is critical not only for authorisation but also for long-term growth and stability.

Preparing for authorisation in practice

Successful applications are the result of careful planning and preparation. Firms that take a strategic approach are better able to anticipate issues, address weaknesses and present a clear and coherent case to the FCA.

In practice, this involves:

  • conducting a gap analysis against FCA expectations
  • reviewing and strengthening governance arrangements
  • developing tailored AML and compliance frameworks
  • ensuring operational resilience is clearly documented
  • preparing robust financial projections
  • aligning your application with your long-term business strategy

Importantly, preparation should not be limited to documentation. The FCA will expect your business to operate in line with what is set out in your application from day one. Taking the time to get this right can significantly reduce the risk of delay and improve your chances of approval. With the FCA Pre-Application Support Service (PASS) meetings now officially open, it is a good opportunity for businesses to discuss business models and expectations with the FCA ahead of the opening of the formal authorisation gateway on 30 September 2026.

Supporting your FCA authorisation journey

Applying for FCA authorisation in the cryptoasset sector is a complex and resource-intensive process. Not to mention, it is a novel process. However, with the right preparation and support, it can also be an opportunity to strengthen your business and position it for sustainable growth.

We provide practical, commercially focused advice on structuring your application, addressing regulatory expectations and avoiding common pitfalls. From initial scoping and gap analysis through to drafting documentation and engaging with the FCA, we support you at every stage. Our aim is not only to help you achieve authorisation, but to ensure that your business is well positioned to operate successfully within the regulatory framework.

If you are preparing for FCA authorisation or want to understand how the new regime applies to your business, early advice can make a significant difference. Contact us to discuss your plans and how we can support you in achieving a successful outcome.

This reflects the law and market position at the date of publication and is written as a general guide. It does not contain definitive legal advice, which should be sought in relation to a specific matter.

Authors

Shen
Shennind Awat-Ranai
Solicitor
0118 907 8394
shennind.awat-ranai@hc.law

Want to read more?

Explore our latest insights.

Related posts

Business team analyzing blockchain and cybersecurity dashboard in modern office, strategic planning for digital transformation and fintech innovation

Cryptoasset FCA Authorisation: Common Application Mistakes and How to Avoid Them

As the UK moves closer to implementing its expanded cryptoasset regulatory regime, an increasing number of firms are preparing for…
Business partnership handshake with digital network technology and corporate collaboration concept

Controls, Compliance and Certification: How the FCA SYSC Rules Apply to Cryptoasset Firms under the New UK Cryptoasset Regime

As part of our series of articles exploring the new cryptoasset regulatory regime established by the Financial Services Markets Act…
Cyber security, personal data privacy protection, secure online banking, and encrypted digital transaction safety Concept. Businessman using smartphone and laptop with shield and padlock icons.

UK Cryptoasset Authorisation: Are You Ready?

The UK’s new cryptoasset regulatory regime is coming into force on 25 October 2027, bringing a wide range of digital…