FCA registration under the Money Laundering Regulations will not automatically convert into authorisation under the UK’s new cryptoasset regime.
Existing cryptoasset exchange providers and custodian wallet providers registered with the FCA under the MLRs must apply for full FSMA authorisation if they intend to continue carrying on activities that become regulated when the new regime starts on 25 October 2027. The main application window opens on 30 September 2026 and closes on 28 February 2027.
This is not simply a re-registration exercise. MLR registration focuses principally on anti-money laundering, counter-terrorist financing and proliferation-financing controls, whereas FSMA authorisation introduces a substantially broader regulatory framework covering governance, senior management, prudential resources, conduct, Consumer Duty, operational resilience, complaints, regulatory reporting and activity-specific requirements.
Existing firms should therefore use 2026 to assess the gap between their current operating model and the standards they will need to meet as fully authorised FCA firms.
MLR registration and FSMA authorisation are fundamentally different
The current MLR regime requires in-scope cryptoasset businesses carrying on business in the UK to register with the FCA before commencing regulated AML activities.
The FCA assesses the firm’s business model, ownership, key individuals, AML framework, customer risk, transaction monitoring and other financial-crime controls. Registration confirms that the business has met the requirements to operate under the MLR framework; it is not full FSMA authorisation.
Under the new regime, regulated cryptoasset activities will sit within the same statutory architecture used for wider UK financial services. Firms will require Part 4A permission under FSMA and will become subject to the FCA’s threshold conditions, Principles for Businesses, Senior Managers regime, prudential requirements and other Handbook obligations.
An existing firm may therefore have strong AML controls and still face a substantial authorisation gap.
MLR registration versus FSMA authorisation
| Area | MLR registration | New FSMA crypto authorisation |
|---|---|---|
| Regulatory basis | Money Laundering Regulations | Financial Services and Markets Act |
| Primary focus | AML, CTF and proliferation financing | Full financial-services regulation |
| Automatic conversion | Not applicable | No automatic conversion from MLR registration |
| Governance | Fit and proper / AML-focused | Threshold conditions, governance and Senior Managers |
| Prudential capital | No equivalent CRYPTOPRU regime | COREPRU and CRYPTOPRU requirements |
| Consumer Duty | Not generally applied through MLR registration | Applies where relevant under FCA rules |
| Operational resilience | Not a standalone MLR framework | FCA operational resilience requirements apply |
| Complaints / FOS | Limited under MLR regime | Wider complaints framework for regulated activities |
| Activity permissions | Registration categories | Specific FSMA regulated cryptoasset permissions |
| Regulatory reporting | Primarily MLR-related obligations | Wider FCA regulatory reporting |
The practical consequence is that the existing compliance framework should be used as a foundation, but firms should not assume it can simply be repackaged into a FSMA application.
What happens to existing MLR registrations?
Until the new FSMA regime commences, firms carrying on in-scope cryptoasset activities under the MLRs must continue to comply with the current registration requirement.
The FCA has made clear that existing MLR-registered firms still need to secure authorisation for any activities that become regulated under FSMA. There is no automatic conversion, grandfathering or guaranteed approval simply because a firm is already on the FCA cryptoasset register.
The FCA will consider the firm’s existing regulatory history as part of the authorisation process. A strong record of AML compliance, timely reporting, transparent regulatory engagement and effective governance can support the application, while unresolved weaknesses or poor supervisory history can create additional scrutiny.
Existing firms should therefore treat the transition as both an authorisation exercise and a regulatory-readiness exercise.
When should an existing crypto firm apply?
The main FCA application period runs from 30 September 2026 to 28 February 2027.
The FCA expects firms intending to operate under the new regime to apply during this window and has encouraged early submission. Applications submitted within the period are expected to be determined before commencement where possible.
Where a firm applies during the application period but the FCA has not finally determined the application by 25 October 2027, saving provisions can allow the firm to continue providing relevant cryptoasset services while its application remains under assessment.
This creates an important distinction between firms that apply during the main window and those that wait until later. Applying within the window provides substantially stronger business-continuity protection.
Existing firms should therefore work backwards from the submission date rather than from the 2027 commencement date.
What if an existing firm applies after 28 February 2027?
The FCA will still accept applications outside the main application period, but late applicants face greater commercial risk.
The FCA has stated that it will not expedite an application to compensate for late submission. If the firm has not obtained authorisation when the new regime starts, it can enter the statutory transitional provision while its application is determined.
That transitional regime is restrictive. The firm may only carry on new regulated cryptoasset activities to the extent necessary to perform pre-existing contracts entered into before it entered the transitional provision.
It will not be able to enter into new contracts with existing UK customers or onboard new UK customers.
For an active crypto business, this can effectively place growth on hold until the FCA reaches a decision.
What happens if an MLR firm does not apply at all?
A firm that does not intend to apply for FSMA authorisation must run off its regulated UK cryptoasset business before the new regime starts.
Firms that fail to do so risk conducting unauthorised regulated business and breaching the FSMA general prohibition.
The transition plan therefore needs to be explicit. Every existing MLR-registered firm should decide whether it intends to seek authorisation, change its business model so that regulated activities cease, or exit the relevant UK market.
Doing nothing is not a viable regulatory strategy.
The board should document the decision and ensure there is enough time either to prepare a high-quality application or to complete an orderly run-off.
Step 1: map the new regulated activities
The first task is to identify which activities the firm will carry on after October 2027.
The new regime regulates a broader set of activities than the existing MLR registration categories. Depending on the business model, permissions may be required for operating a qualifying cryptoasset trading platform, safeguarding cryptoassets, dealing as principal or agent, arranging transactions, staking, lending and borrowing or issuing qualifying stablecoins.
An existing MLR-registered exchange may therefore require several FSMA permissions rather than one direct replacement for its current registration.
The permission mapping should follow the actual customer journey and operating model. The firm should identify which legal entity performs each activity, what assets are involved, where customers are located and which third parties participate in the service.
This exercise should be completed before the application documents are drafted because the permission profile drives the regulatory framework that follows.
Step 2: carry out a full FSMA gap assessment
The FCA has expressly encouraged existing firms to carry out a gap analysis against the new regime.
This should go considerably beyond comparing policy documents. The review should examine whether governance, staffing, systems, financial resources, customer processes and technology are capable of satisfying the new requirements.
Areas likely to require attention include board and senior management arrangements, regulatory capital, liquidity, Consumer Duty, complaints, operational resilience, outsourcing, product governance, conflicts, financial promotions, regulatory reporting and activity-specific requirements.
Custodians will need to assess their arrangements against CASS 17 and the wider custody framework. Trading platforms and intermediaries will have separate market and conduct requirements, while stablecoin issuers face detailed backing, redemption and prudential obligations.
The result should be a prioritised implementation plan rather than a list of theoretical gaps.
Step 3: strengthen governance and senior management
Existing crypto firms often have governance structures designed around commercial growth and AML compliance rather than full FCA authorisation.
The Senior Managers and Certification Regime will apply under the new framework. Senior responsibilities must therefore be clearly allocated, and the FCA will assess whether the management team has sufficient experience, capacity and authority to run a regulated financial-services business.
This can require changes to the board, compliance function or wider management structure.
The firm should identify who will own financial crime, customer outcomes, prudential risk, operational resilience, client assets and other material regulatory responsibilities. It should also ensure that management information supports meaningful oversight.
The governance framework should be operating before application rather than described merely as a future intention.
Step 4: assess capital and prudential requirements
Existing MLR-registered firms do not currently operate under the new CRYPTOPRU regime.
FSMA authorisation introduces formal own funds and liquidity requirements linked to the activities carried on, the firm’s expenditure, transaction volumes and risk profile.
Permanent minimum requirements range from £75,000 for certain agency and arranging activities to £750,000 for dealing as principal. Crypto custody and trading-platform activities have a £150,000 permanent minimum, while qualifying stablecoin issuance carries a £350,000 minimum.
These figures are floors rather than the final capital requirement.
The firm must calculate its fixed overheads requirement, applicable K-factors and wider financial adequacy requirements. It must also maintain appropriate liquid assets and assess the resources needed to manage stress and wind-down.
A capital gap identified late in the application process can delay or derail authorisation, so prudential modelling should begin early.
Step 5: review customer treatment and Consumer Duty
MLR registration does not apply the same conduct framework that firms will face under FSMA.
Firms serving retail customers should assess product design, target markets, price and value, consumer understanding and customer support against Consumer Duty requirements.
This can require changes to onboarding, disclosures, customer communications, fee structures and support processes.
The FCA will expect firms to consider foreseeable harm and monitor the outcomes customers receive rather than relying solely on risk disclosures.
Complaints handling also needs to be reviewed. Eligible complaints concerning regulated activities will sit within a wider FCA complaints framework and can involve access to the Financial Ombudsman Service.
Existing customer journeys should therefore be tested against the future conduct regime rather than assumed to be acceptable because they currently operate under the MLR framework.
Step 6: implement operational resilience properly
The new regime brings authorised crypto firms within the FCA’s wider operational resilience expectations.
Firms need to identify important business services, understand the systems and dependencies supporting them, establish appropriate impact tolerances and test their ability to remain within those tolerances during disruption.
For exchanges and custodians, this can include wallet access, trading systems, withdrawals, deposits, order execution and customer support.
Reliance on cloud providers, blockchain infrastructure, liquidity venues, custodians and other critical suppliers should also be mapped.
A generic business continuity policy will not be enough. The firm needs evidence that it understands how operational disruption could harm customers and can recover or continue critical services appropriately.
Step 7: prepare the application as one coherent regulatory case
A common application weakness is inconsistency between the business plan, financial forecasts, policies and application responses.
The FCA should receive one coherent description of the business.
The regulatory business plan should explain ownership, products, customers, regulated activities, revenue, transaction flows, governance, outsourcing, technology and growth strategy. Financial forecasts should use assumptions consistent with those plans.
Policies should then reflect how the business actually operates rather than generic templates.
The application should also explain how the firm has moved from its current MLR framework to the new FSMA standard and provide evidence that key changes have already been implemented.
The strongest applications describe an operating regulatory framework, not a list of changes that will be made after authorisation.
What about firms applying for MLR registration now?
MLR registration remains relevant until the new FSMA regime commences.
A new cryptoasset business that wants to carry on current MLR-regulated services before October 2027 may still need MLR registration. However, once the FSMA authorisation gateway opens on 30 September 2026, the FCA will encourage firms to focus on securing FSMA authorisation rather than starting a separate MLR registration process unless there is a clear reason to do so.
Where a firm seeks MLR registration after the FSMA gateway opens, the FCA expects it to engage with the Pre-Application Support Service and explain why registration is still needed.
The FCA has also stated that an MLR registration application cannot itself be treated as a FSMA authorisation application.
Businesses entering the market during this transitional period should therefore consider carefully whether the commercial value of obtaining MLR registration before October 2027 justifies running two regulatory processes.
Existing systems and controls still have value
The transition does not mean existing MLR work is wasted.
A mature financial crime framework can provide a strong foundation for FSMA authorisation. Customer risk assessment, transaction monitoring, sanctions controls, governance records and regulatory engagement history can all help demonstrate that the firm already operates within a regulated environment.
The key is to identify what can be retained and what must be expanded.
For example, the existing business-wide risk assessment may remain useful but need to sit within a broader enterprise risk framework. Current AML governance may remain relevant but require integration into Senior Managers responsibilities and wider board reporting.
A disciplined transition should therefore build on the existing framework rather than replace everything unnecessarily.
FCA supervisory history will matter
Existing MLR firms enter the authorisation process with a regulatory track record.
The FCA will already have information about the firm’s registration history, regulatory submissions, supervisory engagement and any concerns raised during its time on the register.
This can be advantageous where the firm has demonstrated strong compliance and transparent engagement.
It can also create risk where there are unresolved weaknesses, overdue remediation or recurring concerns.
Firms should therefore review historic FCA correspondence and ensure outstanding matters are addressed before submission.
An authorisation application that presents the business as fully compliant while leaving known supervisory issues unresolved is unlikely to inspire confidence.
Should firms use the FCA Pre-Application Support Service?
The FCA offers an optional Pre-Application Support Service for cryptoasset firms.
A meeting can be useful where the business has a complex permission profile, group structure or regulatory question that genuinely benefits from early FCA engagement.
The FCA will not provide legal advice or determine the firm’s permissions for it. Firms requesting a meeting must provide meaningful information about the proposed business model, products, customer types and regulated-activity analysis.
Existing MLR firms should therefore complete enough preparatory work to make the discussion useful.
The purpose should be to test or clarify a developed regulatory position rather than ask the FCA to design the authorisation strategy.
How Regulatory Counsel can help
Regulatory Counsel supports existing FCA-registered cryptoasset firms through the transition from MLR registration to full FSMA authorisation.
We begin with a detailed regulatory gap assessment covering permissions, governance, prudential resources, customer treatment, financial crime, operational resilience and activity-specific requirements.
We then develop the authorisation workstream, including the regulatory business plan, application forms, financial forecasts, capital calculations, governance framework, Consumer Duty, complaints, risk management, operational resilience, outsourcing, wind-down planning and the policies and procedures required for the firm’s regulated activities.
For custody firms, this can include CASS 17. For stablecoin issuers, it includes backing and redemption requirements. Trading platforms, intermediaries, staking providers and other businesses require their own activity-specific framework.
We manage the application through submission and FCA information requests through to determination.
Existing MLR firms should treat the transition as a regulatory transformation project rather than a form-filling exercise. Starting early provides time to remediate weaknesses before they become application issues.
Contact Regulatory Counsel to discuss your MLR-to-FSMA transition or FCA cryptoasset authorisation application.
Frequently Asked Questions
No. Existing FCA MLR registration does not automatically convert into FSMA authorisation. Firms carrying on activities regulated under the new regime must apply for the relevant Part 4A permissions.
The main application window runs from 30 September 2026 to 28 February 2027. Existing firms should aim to apply during this period and preferably early enough to allow the FCA sufficient time to assess the application.
Where an eligible firm submitted its application during the application period, saving provisions can allow it to continue relevant services while the FCA reaches a final decision, subject to the applicable statutory requirements.
A late applicant may enter the transitional provision if it has not obtained authorisation before commencement. While in that regime, it may generally only carry on regulated cryptoasset activities necessary to perform pre-existing contracts and cannot freely onboard new UK customers or enter new contracts.
Yes, the MLR regime continues until the new FSMA framework commences. However, once the FSMA gateway opens, the FCA will encourage firms to focus on FSMA authorisation and expects firms seeking a new MLR registration after that point to explain why they still need it.