/
/
/
Controls, Compliance and Certification: How the FCA SYSC Rules Apply to Cryptoasset Firms under the New UK Cryptoasset Regime

Controls, Compliance and Certification: How the FCA SYSC Rules Apply to Cryptoasset Firms under the New UK Cryptoasset Regime

As part of our series of articles exploring the new cryptoasset regulatory regime established by the Financial Services Markets Act 2000 (Cryptoasset) Regulations 2026 (the “Cryptoasset Regulations”), we will cover how the Senior Management Arrangements, Systems and Controls sourcebook (the “SYSC”) applies to cryptoasset businesses in the UK.

The SYSC is a broad sourcebook in the FCA Handbook covering the accountability of senior managers under the Senior Managers and Certification Regime (“SMCR”), general organisational requirements, risk control, financial crime and compliance. Aspects of SYSC have always applied to traditional finance firms that are authorised under the Financial Services Markets Act (FSMA), with specific obligations kicking in from the moment the firm is authorised, changes its business scope or meets certain thresholds.

The FCA’s decision to apply the existing SYSC framework to cryptoasset firms will require businesses to adapt founder-led, technology-driven and often globally dispersed operating models to a regulatory environment focused on individual accountability, clear allocation of responsibilities and robust governance for regulated cryptoasset activities. The FCA has emphasised that the SYSC requirements are deliberately high-level and technology-neutral, meaning that bespoke rules for cryptoasset firms are generally unnecessary. Consistent with this approach, firms carrying on multiple regulated activities will be required to comply with the SYSC provisions applicable to each activity.

Why the FCA is Applying SYSC Requirements to Cryptoasset Firms

In the industry’s early years, founders of protocols and cryptoasset businesses could often avoid meaningful accountability for losses caused by exploits, infrastructure failures or governance deficiencies by invoking decentralisation. A founder might contend, for example, that “governance tokens determine every decision and are distributed among hundreds of wallets”, or that “the validators reached the decision collectively”. After several hard lessons, however, the preferences of market participants appear to be evolving. The absolutist proposition that “code is law” is increasingly giving way to an acceptance that some identifiable person or body should retain the capacity and bear the responsibility to intervene where losses arise from technological, operational or governance failures rather than ordinary market risk.

The FCA’s position is essentially that, where individuals retain meaningful control over a cryptoasset business or protocol, they should not be able to shield themselves from accountability by disappearing behind the language of decentralisation when something goes wrong. Decentralisation can nevertheless remain at the protocol layer, particularly where removing intermediaries creates genuine value. The key is transparency: users should be told clearly which risks fall within the firm’s ability and responsibility to address, and which are inherent features of the protocol or ordinary market risks for which no recourse is available. Applying the SYSC framework would provide potential benefits of strengthened governance, personal responsibility and a clear allocation of responsibilities within the regulated cryptoasset firm.

Governance, Systems and Controls Requirements under SYSC

SYSC 4 (general organisational requirements), 5 (employees’ skills, knowledge and expertise), 9 (record-keeping), 10 (conflicts of interest) and 18 (whistleblowing) form a substantial part of the organisational control framework.

Qualifying cryptoasset firms will need to apportion responsibilities of senior personnel, draft general organisational requirements including how the firm controls administrative keys and smart-contract upgrades where relevant, name persons who effectively direct the business, upgrade the skills, knowledge and expertise for employees, agents and other relevant persons where servicing retail clients for certain qualifying cryptoasset activities. Firms will also have to keep records for business continuity and internal organisation (including all services and transactions) in an orderly manner.

Before the introduction of the regulatory regime, conflicts of interest were (and still are) not uncommon within cryptoasset businesses and their wider group structures. A familiar example arises where a project team launches a new token while retaining a substantial allocation on separate side wallets, or acquiring tokens on preferential terms, before they become available to the public. The business may then use its resources to promote the token and stimulate demand among retail investors, thereby increasing its value. Insiders may subsequently sell their holdings at a significant profit, leaving retail investors exposed to losses when the price falls. The application of SYSC 10 should require firms, as part of their wider conduct and consumer protection obligations, to identify, prevent or appropriately manage and disclose such conflicts at both entity and group level. Depending on the firm’s activities, relevant controls may include restrictions on dealing by staff and connected persons, and fair and consistent order-handling arrangements.

Similar to traditional finance firms, SYSC 18 requires cryptoasset firms to set up internal procedures to handle whistleblowing.

How the Senior Managers and Certification Regime (SM&CR) Applies to Cryptoasset Firms

SYSC 22 to SYSC 27 effectively form the SM&CR regime, which applies to qualifying cryptoasset firms. The current tiering of limited, core, and enhanced firms will apply to cryptoasset firms too. Under the final policy statement PS26/13 published in June 2026, the final “enhanced” thresholds specifically set to capture high-impact crypto activities are £20 billion for stablecoin issuers (as a three-year rolling average) and £100 billion in combined ‘client cryptoassets’ and ‘safe custody assets’ for cryptoasset custodians.

The FCA will also allocate prescribed responsibilities to senior management functions (SMFs). Some have argued that SM&CR would not work well for international management structures in cryptoasset firms, where currently key senior responsibilities may be given to individuals based overseas. However, the FCA has stated they may approve SMF applications for individuals based overseas, such as where an individual within the wider group is responsible for implementing the firm’s strategy in the UK entity. As per PS26/13, the FCA states that the general expectation when authorising a firm, and approving its SMF applications, is that ‘mind and management’ should be, and should continue to be, located in the UK. The FCA expects senior managers holding the MLRO (SMF17) and Compliance Oversight (SMF16) roles to work from the firm’s principal place of business in the UK.

Overall, the FCA wants to ensure, in line with the FCA’s accountability and governance objectives, that an SMF manager is identifiable, responsible and accountable for the relevant areas of the firm’s activities.

Operational Resilience Requirements for Cryptoasset Firms

Operational resilience refers to the ability to prevent, adapt, respond to, recover and learn from operational incidents and disruptions. SYSC 15A is the FCA’s operational resilience framework and applies to in-scope firms carrying out financial service activities. It includes requirements covering understanding and mapping the people, processes, technology, facilities and information needed to deliver each important business service, including testing within set impact tolerances. This aligns with wider FCA operational resilience expectations for financial services firms. SYSC 4 and 7 complement the framework and set out risk management and control requirements to help firms maintain robust business operations and incident management. SYSC 8 sets requirements around a firm’s arrangements for the functions it outsources.

Cryptoasset businesses must identify the circumstances in which disruption to an important business service could cause intolerable harm. This requires firms to define measurable impact tolerances, document them in appropriate policies and procedures, and use severe but plausible scenario testing to demonstrate their ability to remain within those tolerances. Relevant services may include customer access to accounts and cryptoassets, custody and asset return, trading-platform operation, price formation and order matching, staking and unstaking, and collateral management. Where custody, oracle services, cloud providers or another critical function is outsourced, the firm remains responsible for assessing and monitoring the resilience of the provider, it cannot outsource accountability. It should therefore test the consequences of the outsourced custodian’s failure, for example, and maintain workable contingency, substitution and exit arrangements. Clear communication channels need to exist and work in practice too.

The FCA considers that the risks posed by the activities in this sector and the reliance on technology in providing essential activities are such that applying SYSC 15A to cryptoasset firms remains appropriate and proportionate to ensure their approach is designed to manage disruptions effectively, protecting consumers and preserving market integrity without undermining technology and hindering innovation.

Financial Crime, AML and Compliance Requirements

All FSMA-authorised cryptoasset firms must implement traditional financial crime controls under SYSC 6. As stated in our article https://herrington-carmichael.com/insights/commercial-law/from-experimental-to-established-breaking-down-the-uks-new-cryptoasset-regime/ the new regime does not operate in isolation. Existing frameworks like the Anti-Money Laundering (AML) framework continue to apply alongside it.

While firms remain subject to Money Laundering Regulations, SYSC 6 places financial crime into a wider framework of corporate governance and continuous oversight, rather than focusing narrowly on AML/CTF, so qualifying cryptoasset firms will not require a separate crypto business anti-money laundering registration.

As stated above, the FCA will require an allocation of a specific director or senior manager to oversee compliance (SMF16) and as the money laundering reporting officer (SMF17). SYSC 6 also requires that these officers report directly to the governing body or board of directors of the business.

Preparing for Compliance under the New Cryptoasset Regime

The future success of the regulated cryptoasset market will depend on firms pursuing growth and operational maturity in tandem. A resilient technological and governance framework should not be viewed as a constraint on expansion, but as the foundation that enables sustainable growth. This will require firms to consider whether their infrastructure, controls and third-party providers can scale with the business, and whether they can be adapted as its activities, customer base and risk profile evolve. Authorisation is therefore only the starting point: firms will need to continue investing in their systems, people and governance to ensure that the infrastructure supporting the business does not fall behind its commercial ambitions. Regulatory compliance and operational resilience should be treated not as a one-off exercise, but as a continuous process of assessment, testing and improvement throughout the firm’s development.

Our Financial Services team advises cryptoasset businesses on FCA authorisation, governance, compliance and regulatory requirements. By providing practical, commercially focused advice, we help firms navigate the new cryptoasset regime with confidence.

To discuss how the new regulatory framework may affect your business, please contact us.

This reflects the law and market position at the date of publication and is written as a general guide. It does not contain definitive legal advice, which should be sought in relation to a specific matter.

Authors

Mark Chapman PNG
Mark Chapman
General Counsel, Head of Commercial & Regulatory
01276 854 928
mark.chapman@hc.law
Shen
Shennind Awat-Ranai
Solicitor
0118 907 8394
shennind.awat-ranai@hc.law

Want to read more?

Explore our latest insights.

Related posts

Business partnership handshake with digital network technology and corporate collaboration concept

Controls, Compliance and Certification: How the FCA SYSC Rules Apply to Cryptoasset Firms under the New UK Cryptoasset Regime

As part of our series of articles exploring the new cryptoasset regulatory regime established by the Financial Services Markets Act…
Cyber security, personal data privacy protection, secure online banking, and encrypted digital transaction safety Concept. Businessman using smartphone and laptop with shield and padlock icons.

UK Cryptoasset Authorisation: Are You Ready?

The UK’s new cryptoasset regulatory regime is coming into force on 25 October 2027, bringing a wide range of digital…
Teamwork process, business people working pointing laptop comput

Navigating Cookie Choices: Consent, Pay Models and the DUA Act’s Compliance Landscape

As businesses operating online services continue to rely on data-driven ways to efficiently target their audience and advertise, there has…