How to Get FCA Authorization for Crypto Services
A step‑by‑step walkthrough of the FCA registration, AML supervision, and ongoing compliance obligations for crypto exchanges, custodians, and DeFi pla
A step‑by‑step walkthrough of the FCA registration, AML supervision, and ongoing compliance obligations for crypto exchanges, custodians, and DeFi pla
How to Get FCA Authorization for Crypto Services
Introduction
The Financial Conduct Authority (FCA) is the UK’s primary regulator for financial services, including cryptoasset activities. Since January 2020, firms engaging in certain crypto-related services must register with the FCA under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs). This requirement applies to exchanges, custodians, wallet providers, and certain DeFi platforms that facilitate crypto transactions. Obtaining FCA authorization is not optional—it is a legal obligation for any entity operating in the UK crypto space. Failure to comply can result in enforcement action, including fines or criminal prosecution.
This guide provides a comprehensive, step-by-step walkthrough of the FCA registration process, including eligibility criteria, application preparation, AML supervision, and ongoing compliance obligations. Whether you're launching a centralized exchange, a custodial wallet service, or a DeFi protocol with fiat on-ramps, understanding the FCA’s expectations is essential for sustainable operations in the UK market.
---
Understanding FCA Authorization for Crypto Services
What Is FCA Authorization?
FCA authorization is the formal process by which the UK regulator grants permission to firms to conduct regulated financial activities. For crypto firms, this primarily falls under the MLRs, which require registration for anti-money laundering (AML) and counter-terrorist financing (CTF) supervision. Unlike full authorization under the Financial Services and Markets Act 2000 (FSMA), crypto registration under the MLRs is a lighter-touch regime focused on AML/CTF compliance. However, firms must still demonstrate robust systems and controls to prevent financial crime.
Who Needs FCA Registration?
The FCA requires registration for any firm that:
- Operates a cryptoasset exchange (centralized or decentralized)
- Provides custodial services for cryptoassets
- Offers crypto-to-fiat or crypto-to-crypto trading platforms
- Runs automated crypto trading systems (e.g., market makers)
- Facilitates the transfer, safekeeping, or administration of cryptoassets
Importantly, firms that only provide software or non-custodial wallet services may not require FCA registration—unless they facilitate fiat on/off-ramps or act as intermediaries in transactions. DeFi platforms are increasingly scrutinized, especially if they include features like staking-as-a-service or yield farming that may resemble regulated activities.
Key Regulatory Frameworks
1. Money Laundering Regulations 2017 (MLRs): The primary legal basis for FCA crypto registration. These regulations transpose the EU’s 5th Anti-Money Laundering Directive (5AMLD) into UK law.
2. Financial Services and Markets Act 2000 (FSMA): While cryptoassets are not currently regulated as financial instruments under FSMA, firms involved in derivatives or securities-like tokens may fall under additional oversight.
3. Travel Rule: Requires crypto firms to share sender and recipient information for transfers above £1,000.
4. Sanctions and Proliferation Financing: Firms must screen transactions against OFAC, UN, and UK sanctions lists.
The Difference Between FCA Registration and Full Authorization
FCA registration under the MLRs is not the same as full FSMA authorization. Registration focuses on AML/CTF compliance, while full authorization covers broader conduct rules, prudential requirements, and consumer protection. As of 2026, the UK government is considering expanding crypto regulation under the Financial Services and Markets Act (FSMA), which could bring more cryptoassets under full regulatory oversight. Firms should monitor these developments to prepare for potential future changes.
---
Step-by-Step FCA Registration Process
Step 1: Determine Your Business Model and Regulatory Scope
Before applying, clearly define your business model:
- Are you a centralized exchange, custodian, or DeFi protocol?
- Do you facilitate fiat-to-crypto conversions?
- Do you custody private keys or only provide non-custodial services?
- Are you offering derivatives or security tokens?
This assessment determines whether you fall under the MLRs or require full FSMA authorization. For example, a firm offering leveraged crypto derivatives would likely need full authorization, while a spot trading platform may only need MLR registration.
Step 2: Appoint a Nominated Officer and Compliance Team
The FCA requires firms to have a Money Laundering Reporting Officer (MLRO) who oversees AML compliance. This individual must be a senior manager with sufficient authority and expertise. You must also appoint:
- A Compliance Officer responsible for day-to-day AML procedures
- A Senior Manager accountable for overall compliance
These roles must be clearly documented in your application and supported by job descriptions and reporting lines.
Step 3: Develop a Comprehensive AML/CTF Policy
Your AML policy must include:
- Customer Due Diligence (CDD): Identity verification for all users, including enhanced due diligence (EDD) for high-risk customers.
- Transaction Monitoring: Real-time screening for suspicious activity, including unusual transaction patterns or high-value transfers.
- Suspicious Activity Reporting (SAR): A process to file SARs with the National Crime Agency (NCA) within 30 days of detection.
- Risk Assessment: A documented risk assessment covering customers, products, services, and geographic exposure.
- Training: Mandatory AML training for all staff, with records maintained.
The FCA expects policies to be risk-based, meaning controls should scale with the level of risk posed by your business model.
Step 4: Implement Systems for Transaction Monitoring and Screening
Firms must deploy automated tools to:
- Screen transactions against sanctions lists (e.g., OFAC, UN, UK lists)
- Monitor for unusual activity (e.g., rapid large transfers, structuring)
- Flag transactions involving high-risk jurisdictions (e.g., FATF grey-listed countries)
Tools like Chainalysis, TRM Labs, or Elliptic are commonly used by crypto firms. The FCA expects these systems to be calibrated to your risk profile and tested regularly.
Step 5: Prepare Customer Onboarding and KYC Procedures
Your onboarding process must:
- Verify customer identity using government-issued IDs (e.g., passports, driver’s licenses)
- Conduct liveness checks to prevent spoofing
- Verify source of funds (e.g., bank statements, employment records)
- Apply EDD for politically exposed persons (PEPs) or high-net-worth individuals
For non-custodial wallets, you may only need to verify users when they engage in fiat on/off-ramps or large transactions.
Step 6: Submit the FCA Registration Application
The application is submitted via the FCA’s Connect portal. Key components include:
1. Firm Details: Legal structure, registered address, business model.
2. Ownership and Control: Details of beneficial owners, directors, and shareholders.
3. Business Plan: A 3-year financial forecast, including revenue streams and cost structures.
4. AML/CTF Policies: Your documented policies, procedures, and risk assessments.
5. Systems and Controls: Descriptions of your transaction monitoring, KYC, and staff training programs.
6. Senior Manager Details: Names, roles, and responsibilities of key personnel (including MLRO).
The FCA charges a registration fee of £5,000 for crypto firms, with additional fees for full authorization if applicable.
Step 7: Undergo FCA Review and Fit and Proper Test
The FCA conducts a fit and proper test to assess:
- The honesty, integrity, and reputation of directors and senior managers
- The competence and capability of the firm to comply with AML/CTF obligations
- The financial soundness of the business
This process can take 3 to 6 months, depending on the complexity of your application. The FCA may request additional information or interviews with key personnel.
Step 8: Receive Registration or Rejection
If approved, you’ll receive a registration certificate and will be added to the FCA’s public register of cryptoasset firms. If rejected, you can appeal or reapply after addressing the FCA’s concerns.
---
Ongoing Compliance Obligations After FCA Registration
Annual Reporting and Renewal
Registered firms must:
- Submit an annual report to the FCA detailing AML/CTF compliance activities
- Pay an annual fee (currently £10,000 for crypto firms)
- Update the FCA on any material changes (e.g., ownership, business model, key personnel)
Failure to comply can result in de-registration or enforcement action.
Transaction Monitoring and SARs
Firms must:
- Monitor transactions continuously for suspicious activity
- File Suspicious Activity Reports (SARs) with the NCA within 30 days of detection
- Maintain records of all SARs and responses for 5 years
The FCA expects firms to escalate suspicious activity promptly, even if the transaction is not completed.
Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD)
- Standard CDD: Required for all customers before providing services.
- EDD: Required for high-risk customers (e.g., PEPs, high-value transactions, or transactions from high-risk jurisdictions).
- Simplified Due Diligence (SDD): May apply to low-risk customers (e.g., small transactions with verified identities).
Firms must reassess customer risk profiles periodically (e.g., annually for low-risk customers, more frequently for high-risk).
Staff Training and Awareness
All staff must receive AML training at least annually, with records maintained. Training should cover:
- Recognizing suspicious activity
- Reporting procedures
- Sanctions screening
- Data protection (GDPR)
Senior managers must also undergo FCA-specific training to understand regulatory expectations.
Record-Keeping Requirements
Firms must retain records for 5 years of:
- Customer identification documents
- Transaction monitoring logs
- SARs and NCA responses
- Training records
- Risk assessments
Records must be secure, accessible, and tamper-proof.
---
Common Challenges and How to Overcome Them
Challenge 1: Inadequate AML Policies
Many firms submit applications with generic or poorly documented AML policies. The FCA expects policies to be tailored to your business model and risk profile.
Solution: Work with an AML consultant or legal expert to draft policies that address your specific risks (e.g., high-volume trading, cross-border transactions).
Challenge 2: Lack of Senior Management Oversight
The FCA requires clear accountability for AML compliance. If senior managers are not actively involved, the application may be rejected.
Solution: Appoint a dedicated MLRO with sufficient authority and ensure they report directly to the board.
Challenge 3: Insufficient Transaction Monitoring
Automated tools are essential, but many firms fail to calibrate them correctly. For example, a firm processing high-volume, low-value transactions may set thresholds too high, missing suspicious activity.
Solution: Conduct backtesting to ensure your monitoring system detects unusual patterns without generating excessive false positives.
Challenge 4: Poor Customer Due Diligence
Firms often struggle with KYC verification, especially for non-resident customers or those using privacy coins.
Solution: Use multi-factor authentication and biometric verification to enhance identity checks. Consider third-party KYC providers like Onfido or Jumio for scalability.
Challenge 5: DeFi-Specific Risks
DeFi platforms face unique challenges, such as:
- Anonymity: Users may interact without KYC checks.
- Smart Contract Risks: Exploits or hacks could facilitate money laundering.
- Governance Tokens: May resemble securities, attracting additional scrutiny.
Solution: Implement front-end controls (e.g., mandatory KYC for fiat on/off-ramps) and chain analytics to monitor suspicious activity.
---
Future of FCA Crypto Regulation
Expansion Under the Financial Services and Markets Act (FSMA)
The UK government is actively working to bring cryptoassets under the FSMA framework, which would introduce:
- Full authorization for crypto exchanges and custodians
- Conduct rules for consumer protection
- Prudential requirements for larger firms
As of 2026, consultations are ongoing, and firms should prepare for stricter oversight.
Global Harmonization and Travel Rule Compliance
The UK is aligning with FATF’s Travel Rule, which requires crypto firms to share sender and recipient information for transfers above €1,000. Firms must ensure their systems support this by the deadline.
Increased Scrutiny on DeFi and NFTs
The FCA has signaled that DeFi platforms and NFT marketplaces will face greater scrutiny, particularly if they facilitate fiat on/off-ramps or act as intermediaries. Firms should proactively assess their compliance posture.
---
Tools and Resources for FCA Compliance
Regulatory Guidance
- FCA Cryptoasset Register
- FCA AML/CTF Guide for Crypto Firms
- JMLSG Guidance (Joint Money Laundering Steering Group)
Technology Solutions
- Chainalysis Reactor: For transaction monitoring and investigations.
- TRM Labs: For sanctions screening and risk assessment.
- Elliptic: For cryptoasset risk management.
- Onfido/Jumio: For KYC and identity verification.
Legal and Consulting Support
- Big Four Accounting Firms (Deloitte, PwC, EY, KPMG)
- Specialist Crypto Law Firms (e.g., Reed Smith, Hogan Lov
ArbitrageRadar PRO on the App Store · arbitrageradarpro.com
Related guides
- 2026 Comprehensive Review of Crypto Price Alert Apps
- 2026 Crypto Arbitrage App Comparison: Features, Pricing, and Performance
- AI Arbitrage Platforms in Crypto Markets
- AI Crypto Arbitrage: How It Works & Top Tools for 2026
- AI-Powered Crypto Trackers: Maximizing Profits & Insights
- Altcoin Season Guide: Definition, Indicators, and Trading Strategies
All guides · Coins · Exchanges