Introduction

Written for the analyst with a live decision, not the project team

Most crypto compliance content is written for the person managing the FSMA authorisation project. This is written for the person who has to make a real decision on a real customer before that project finishes. Those are different jobs, and the timeline that matters for one is not the timeline that matters for the other.

๐Ÿ’ก
Perimeter uncertainty is becoming a finding, not a grey area
In our view, perimeter uncertainty, not knowing whether your firm's activity is in scope of the new regime, is not a neutral grey area to sort out later, it is increasingly a governance and risk management issue in its own right. The FCA's April 2026 consultation on cryptoasset perimeter guidance (CP26/13) is itself a signal that firms are expected to reach a clear, defensible position on scope well ahead of the authorisation gateway opening, not treat classification as something to work out once enforcement pressure arrives. Treating this as tomorrow's problem is itself becoming today's finding.
Section 01

What counts as a cryptoasset, in terms that actually matter to you

Skip the blockchain explainer. For a working analyst, a cryptoasset is defined by what triggers a regulatory duty, not by how the technology functions underneath. Under the Money Laundering Regulations, a cryptoasset is a cryptographically secured digital representation of value or contractual rights, transferable and storable electronically. The definition is wide on purpose: exchange tokens, stablecoins, and a broad range of digital assets all sit inside it. The operative question is never really is this crypto, it is does dealing in this trigger a registration duty.

Section 02

Owning crypto and dealing in crypto are two different questions

These get conflated constantly, and the conflation causes real onboarding mistakes. An individual holding cryptoassets personally, in their own wallet, for their own account, triggers no FCA registration duty at all. Ownership is unregulated.

The duty attaches to the business providing the service, not the person holding the asset. Exchange cryptoassets for money or other cryptoassets by way of business, or safeguard cryptoassets or the private keys controlling them on behalf of customers, and you are a cryptoasset exchange provider or custodian wallet provider under the Money Laundering Regulations. That duty has been in force since 10 January 2020. Nothing about that changes this year.

Section 03

Two regimes are live at once right now, and that is the actual complication

RegimeStatus nowWhat it coversKey date
MLR registrationIn force, has been since 2020AML and counter terrorist financing supervision onlyOngoing
FSMA cryptoasset authorisationApplication gateway opens 30 September 2026Full financial services authorisation, stablecoin issuance, safeguarding, arranging deals, stakingRegime commences 25 October 2027

Registration under the MLRs does not convert into FSMA authorisation, and does not guarantee it. A firm correctly registered and supervised since 2020 still has to make a fresh case under the new regime. This is not a formality layered on top of what already exists, it is a separate gate.

A firm that has done everything right under the old regime can still fail the new one, because they are not the same test.
Section 04

The AML and sanctions obligations that sit underneath both regimes

A registered cryptoasset business carries the core MLR duties any MLR-regulated firm carries, though exactly how those duties apply varies by the specific regulated activity the firm performs: a business wide risk assessment, customer due diligence and enhanced due diligence where warranted, ongoing transaction monitoring, staff training, and suspicious activity reporting. Sanctions and PEP screening sit under a separate regime, UK financial sanctions law, not the MLRs, and that obligation applies regardless of MLR registration status. Either way, the firm needs an MLRO who genuinely understands cryptoassets, not a traditional finance background stretched thin to cover it.

The Travel Rule, the one obligation that is genuinely crypto specific

1

Part 7A only applies to a defined "cryptoasset transfer"

Regulation 64B defines this narrowly: either a transfer between cryptoasset businesses, or an unhosted wallet transfer as defined there. Not every movement of a cryptoasset on a blockchain is a "cryptoasset transfer" for Part 7A purposes.

โ†“
2

Two transfer types are excluded entirely, not by value

Regulation 64A(2) excludes transfers within Article 3.9 of the funds transfer regulation. Regulation 64A(3) excludes transfers where both the originator and the beneficiary are cryptoasset businesses acting on their own behalf. Neither exclusion depends on the transfer's value.

โ†“
3

Base originator and beneficiary information travels with every covered transfer, no threshold

Regulation 64C(1) and (5) require the originator's business to attach both parties' names, the registered or trading name of any party that is a firm, and account numbers or a unique transaction identifier for both originator and beneficiary. No monetary threshold applies, and the transfer must not proceed without it. A narrow batch-file exception under Regulation 64C(7) lets qualifying transfers to a beneficiary business operating wholly outside the UK carry this information at the batch level instead of on every constituent transfer.

โ†“
4

Extra verification-grade information runs on two separate routes, not one threshold

If every cryptoasset business executing the transfer operates in the UK, the beneficiary's business can request the further Regulation 64C(6) information and must receive it within three working days, no threshold on this route (Reg 64C(2)). If not every executing business is UK-based, that further information must automatically accompany the transfer once it, aggregated with linked transfers, reaches ยฃ800 (Reg 64C(4), amended from EUR 1,000 by SI 2026/621 reg 32, effective 30 June 2026). For an individual originator, paragraph (6) asks for one of: a customer identification number, an address, an identity document number, or date and place of birth (alternatives, not a checklist to satisfy in full).

โ†“
5

Unhosted wallet transfers run under their own rule, with their own ยฃ800 threshold

A transfer to or from an unhosted wallet is itself a defined "cryptoasset transfer" under Regulation 64B, not a gap in the regime. With no receiving business to exchange full Part 7A information with, Regulation 64G instead lets the firm request specified information from its own customer, with enhanced information required once the transfer meets ยฃ800 (Reg 64G(1)(b), amended from EUR 1,000 by the same SI 2026/621, reg 33), a separate threshold from Reg 64C(4)'s, not the same provision. This is where most real friction sits.

Since 1 September 2023, Part 7A of the Money Laundering Regulations has applied this regime to every cryptoasset transfer within Regulation 64B's definition, unless a Regulation 64A(2) or (3) exclusion applies. Whether Part 7A applies at all does not depend on value, only specific additional-information elements within it do, and those run on different rules depending on where the businesses involved are based. It is the direct crypto equivalent of correspondent banking information requirements.

Section 05

Why crypto KYC does not map cleanly onto a traditional onboarding checklist

โš ๏ธ
Standard due diligence does not tell you where the coins came from
Standard due diligence confirms who opened the account. It tells you nothing about where the coins already sitting in that wallet came from before your customer took control of them. Source of funds, for a crypto customer, increasingly means tracing on chain activity backward, not just reading a bank statement.

From 1 February 2027, Regulation 34A introduces a specific enhanced due diligence requirement for cryptoasset exchange providers and custodian wallet providers that have, or propose to have, a correspondent relationship with a similar provider based in a third country, mirroring the correspondent banking EDD model: understanding the respondent's business, assessing its reputation and supervision quality from credible public sources, and assessing its AML/CTF controls. It does not create a general rule about unhosted wallets or lower transparency jurisdictions across the board, those remain matters for the firm's own risk-based judgement outside this specific correspondent relationship gateway.

Knowledge check

Two distinctions that cause real onboarding mistakes

๐Ÿง  Knowledge check
A customer holds cryptoassets personally in their own wallet and has never exchanged or safeguarded assets for anyone else. Do they need to register with the FCA?
๐Ÿง  Knowledge check
Your firm is MLR registered and has been since 2021. Does that registration guarantee FSMA authorisation once the new regime commences?
๐Ÿ›ก๏ธ Put it into practice
Screen a wallet linked customer's name against live sanctions and PEP data
Free, no login. See how identity screening works before you apply it to a live crypto case.
Screen a name โ†’
FAQ

Frequently asked questions

Does personally owning crypto require any FCA registration? +
No. Registration duties apply to businesses providing exchange or custody services by way of business, not to individuals holding assets for themselves.
If my firm is already MLR registered, do we need to do anything before 2027? +
Yes. Registration under the MLRs does not automatically carry over. Firms should be doing perimeter analysis now to understand which new regulated activities apply to them, ahead of the application gateway opening 30 September 2026.
What is the single most crypto specific AML obligation, separate from standard KYC and screening? +
The Travel Rule (Part 7A MLR 2017), in force since 1 September 2023, requires originator and beneficiary information to travel with every cryptoasset transfer that falls within Regulation 64B's definition, with no value threshold on that base requirement. Only certain additional verification details are gated by a threshold, currently ยฃ800, and which threshold applies (Reg 64C(4) or Reg 64G(1)(b)) depends on where the cryptoasset businesses involved are based, and whether an unhosted wallet is involved.
Continue Reading

Related topics