Introduction

Written for the analyst with a live decision, not the project team

Most crypto compliance content is written for the person managing the FSMA authorisation project. This is written for the person who has to make a real decision on a real customer before that project finishes. Those are different jobs, and the timeline that matters for one is not the timeline that matters for the other.

๐Ÿ’ก
Perimeter uncertainty is becoming a finding, not a grey area
As of this year, recent FCA facing legal commentary describes perimeter uncertainty, not knowing whether your firm's activity is in scope of the new regime, as something regulators increasingly treat as a governance and risk management issue, not a neutral grey area to sort out later. Treating this as tomorrow's problem is itself becoming today's finding.
Section 01

What counts as a cryptoasset, in terms that actually matter to you

Skip the blockchain explainer. For a working analyst, a cryptoasset is defined by what triggers a regulatory duty, not by how the technology functions underneath. Under the Money Laundering Regulations, a cryptoasset is a cryptographically secured digital representation of value or contractual rights, transferable and storable electronically. The definition is wide on purpose: exchange tokens, stablecoins, and a broad range of digital assets all sit inside it. The operative question is never really is this crypto, it is does dealing in this trigger a registration duty.

Section 02

Owning crypto and dealing in crypto are two different questions

These get conflated constantly, and the conflation causes real onboarding mistakes. An individual holding cryptoassets personally, in their own wallet, for their own account, triggers no FCA registration duty at all. Ownership is unregulated.

The duty attaches to the business providing the service, not the person holding the asset. Exchange cryptoassets for money or other cryptoassets by way of business, or safeguard cryptoassets or the private keys controlling them on behalf of customers, and you are a cryptoasset exchange provider or custodian wallet provider under the Money Laundering Regulations. That duty has been in force since 10 January 2020. Nothing about that changes this year.

Section 03

Two regimes are live at once right now, and that is the actual complication

RegimeStatus nowWhat it coversKey date
MLR registrationIn force, has been since 2020AML and counter terrorist financing supervision onlyOngoing
FSMA cryptoasset authorisationApplication gateway opens 30 September 2026Full financial services authorisation, stablecoin issuance, safeguarding, arranging deals, stakingRegime commences 25 October 2027

Registration under the MLRs does not convert into FSMA authorisation, and does not guarantee it. A firm correctly registered and supervised since 2020 still has to make a fresh case under the new regime. This is not a formality layered on top of what already exists, it is a separate gate.

A firm that has done everything right under the old regime can still fail the new one, because they are not the same test.
Section 04

The AML and sanctions obligations that sit underneath both regimes

A registered cryptoasset business carries the same core duties as any regulated firm: a business wide risk assessment, customer due diligence and enhanced due diligence where warranted, sanctions and PEP screening, ongoing transaction monitoring, staff training, and suspicious activity reporting, with an MLRO who genuinely understands cryptoassets, not a traditional finance background stretched thin to cover it.

The Travel Rule, the one obligation that is genuinely crypto specific

1

Customer initiates a cryptoasset transfer above the applicable threshold

The transfer enters the regulated pathway once it clears the threshold at which the information requirement applies.

โ†“
2

Originator information is attached to the transfer before it leaves

Name and account identifier for the originator travel with the transfer itself, not separately after the fact.

โ†“
3

Receiving cryptoasset business must confirm it can identify the beneficiary

The business on the receiving side has to be able to identify who is receiving the value.

โ†“
4

If the counterparty is an unhosted wallet, there is no regulated party on the other end

With no regulated business to exchange this information with, this is where most real friction sits.

Since 1 September 2023, Part 7A of the Money Laundering Regulations has required this information to travel with certain cryptoasset transfers. It is the direct crypto equivalent of correspondent banking information requirements.

Section 05

Why crypto KYC does not map cleanly onto a traditional onboarding checklist

โš ๏ธ
Standard due diligence does not tell you where the coins came from
Standard due diligence confirms who opened the account. It tells you nothing about where the coins already sitting in that wallet came from before your customer took control of them. Source of funds, for a crypto customer, increasingly means tracing on chain activity backward, not just reading a bank statement.

Crypto specific enhanced due diligence requirements for certain correspondent style relationships come into force on 1 February 2027, formalising what many firms already do informally, treating unhosted wallet counterparties and lower transparency jurisdictions with a materially higher bar than a standard retail crypto customer.

Knowledge check

Two distinctions that cause real onboarding mistakes

๐Ÿง  Knowledge check
A customer holds cryptoassets personally in their own wallet and has never exchanged or safeguarded assets for anyone else. Do they need to register with the FCA?
๐Ÿง  Knowledge check
Your firm is MLR registered and has been since 2021. Does that registration guarantee FSMA authorisation once the new regime commences?
๐Ÿ›ก๏ธ Put it into practice
Screen a wallet linked customer's name against live sanctions and PEP data
Free, no login. See how identity screening works before you apply it to a live crypto case.
Screen a name โ†’
FAQ

Frequently asked questions

Does personally owning crypto require any FCA registration? +
No. Registration duties apply to businesses providing exchange or custody services by way of business, not to individuals holding assets for themselves.
If my firm is already MLR registered, do we need to do anything before 2027? +
Yes. Registration under the MLRs does not automatically carry over. Firms should be doing perimeter analysis now to understand which new regulated activities apply to them, ahead of the application gateway opening 30 September 2026.
What is the single most crypto specific AML obligation, separate from standard KYC and screening? +
The Travel Rule, in force since 1 September 2023, requiring originator and beneficiary information to travel with qualifying cryptoasset transfers.