Knowledge Hub Scenario Lab About Try the tool →
🎯 Stablecoin Series · Authorisation Scoping

UK Stablecoin Regulation 2026: Who Actually Needs Authorisation

A classification framework for the enacted regime: what legally counts as a qualifying stablecoin, and who the law treats as issuing one once the work is split across entities.

Written by Pratik Zanke

📜 Practitioner Level ⚖ Regulatory Classification
Section A

What legally counts as a stablecoin?

Start with the question a lot of guidance answers backwards. The commercial market talks about fiat-backed stablecoins, crypto-collateralised stablecoins, algorithmic stablecoins, commodity-referenced tokens, electronic money tokens, wrapped representations of all of the above. None of those labels appear in UK financial services law. What appears in law is a two-step test, and a token either passes it or it doesn't, regardless of what its issuer calls it on a website.

Source. Article 88F of the Regulated Activities Order defines a "qualifying cryptoasset" as one that is fungible, transferable, not solely a record of value or contractual rights, and not caught by a short list of exclusions, the main one for this guide being electronic money.1 Article 88G then narrows that further: a "qualifying stablecoin" is a qualifying cryptoasset that seeks or purports to maintain a stable value against a single fiat currency, and that holds fiat currency or other assets, backing assets, for the purpose of maintaining that value.1 Both limbs have to be true at once.

Application. This is where the commercial taxonomy actually earns its place, not as a set of legal categories, but as a set of candidates to test against the statute. A fiat-backed token holding cash and short-dated government debt against a sterling peg passes the test cleanly. A token that pegs to gold, or to another cryptoasset, fails the first limb outright: article 88G(3) says a non-fiat reference doesn't qualify even if that reference happens to be priced in fiat terms elsewhere.1 A token that maintains its peg through an algorithm rather than held assets fails the second limb; the FCA's own guidance, published alongside the enacted regime, states plainly that a mechanism relying partly or wholly on algorithmic methods rather than backing assets does not produce a qualifying stablecoin.2 That guidance is the FCA's interpretation of what the backing-assets requirement means in practice, not wording in article 88G itself, and the distinction matters because the statute is what a court would apply if the FCA's own reading were ever challenged.

A wrapped token, one issued in exchange for holding or locking up another cryptoasset, raises its own question. The FCA's guidance says a wrapped token isn't automatically a qualifying stablecoin merely because the thing it wraps is one; it has to independently meet the article 88G test, and the same guidance says that's unlikely given how article 88G(3) treats a reference to another cryptoasset.2 Whether providing the wrapping service itself amounts to a separately regulated activity isn't a single yes-or-no answer: PERG 18.8.7 treats wrapping and bridging services as fact-specific, not distinct regulated activities in their own right, and whether a given arrangement crosses into dealing, arranging, or, where it's run on a custodial basis, safeguarding depends on how that arrangement is structured, assessed case by case rather than settled by the label "wrapping service" alone.2

Action. Before applying anything else in this guide, run the token through articles 88F and 88G directly. Every classification question after this one, who's issuing, who's safeguarding, who's dealing, assumes the answer to this one is already settled.

Guardrail, stated plainly

Fiat-backed, crypto-collateralised, algorithmic, commodity-referenced, electronic-money-token and wrapped are working descriptions, not statutory categories. Nothing in this guide should present them as though the RAO itself uses those words.

Section B

Who is "issuing" a qualifying stablecoin?

Being the name on a stablecoin doesn't make you its issuer for authorisation purposes. Article 9M defines issuing as a single activity built from three conditions that all have to be true of the same person, not three independent triggers any one of which is enough.

Source. Under article 9M(1)-(2), a person (A) is issuing a qualifying stablecoin only where: A offers, or arranges for another to offer, the stablecoin for sale or subscription from a UK establishment; the stablecoin was created by, or on behalf of, A or a member of A's group; and A carries on, from a UK establishment, both undertaking or arranging redemption and holding or arranging the holding of the backing assets.1 Article 9M(3) then narrows the offering limb specifically: "the activity in paragraph (2)(a) does not include the minting of a qualifying stablecoin," minting being the point at which the token first exists as an identifiable asset on the blockchain, in transferable form. That exclusion touches the offering limb only. It says nothing about redemption or backing-asset holding, not because those limbs also exclude minting, but because minting was never part of either of them in the first place: undertaking redemption and holding backing assets are things a person actually has to go and do, and minting a token doesn't get anyone any distance toward doing either one.1

Application. The three-limb structure matters most when the work is split across entities, which is the normal way a stablecoin programme is actually built: one company designs the token and holds the brand relationship with customers, another operates redemption, a third custodies the backing assets. Article 9M(4)(c) answers who's on the hook in that situation directly: where all of the offering, redemption and backing-asset-holding activities are in fact carried on by another person (B) under arrangements A has made, only A is treated as carrying on the issuing activity. B isn't.1 That's a deliberate design choice, not an oversight, it means a group can genuinely outsource operational delivery of a stablecoin without multiplying who needs a Part 4A permission for issuing it, provided the arrangement genuinely covers everything and A remains the party who arranged it.

That "provided" is doing real work. If A has only arranged for B to handle two of the three limbs, and A is carrying on the third itself directly, 9M(4)(c) doesn't apply in the same clean way, because the provision is about all of the activities in 2(a) and 2(c) sitting with B, not most of them. Worked Scenario 1 below tests exactly where that line falls.

Action. Before treating an outsourcing arrangement as removing an authorisation obligation from the entity that designed the token, map every one of the three 9M(2) limbs, offering, redemption, backing-asset holding, to the specific entity actually carrying it out today, not the entity that would ideally be carrying it out on an org chart. Article 9M(4)(c) protects an arrangement that's genuinely complete. It doesn't protect a partial one.

🧩
The Missing Limb
A partial outsourcing arrangement gets read as though it were the complete one that actually moves the issuing obligation.
Risk
Two of the three 9M(2) limbs sit with an outsourced operator, and that gets treated as enough to clear the design company of the issuing activity.
Signal
Article 9M(4)(c) only applies where another person carries on all of the offering, redemption and backing-asset-holding limbs, not most of them, under arrangements the first party made.
Response
Map each of the three limbs to the entity actually carrying it out today before concluding an outsourcing arrangement has moved who is treated as issuing.
⚖
Worked Scenario 1 · Outsourcing and the issuing activity
The Split Operation
⚖
What do you do?Make the call

A UK-based fintech designs and markets a sterling-referenced stablecoin under its own brand. Under one set of contractual arrangements it has put in place, a separate UK-authorised operations firm handles everything else: it processes sales of the stablecoin to customers, it undertakes redemption, and it holds the backing assets. The design company created the token, holds the brand relationship, and made the arrangements; it does not itself carry out the offering, the redemption, or the custody of the backing assets. All three of those activities sit entirely with the operations firm.

Section C

Who is "safeguarding" a qualifying stablecoin?

Section B answered who issues a stablecoin. That's a separate question from who holds it for someone else afterward, and the law treats it as a separate activity, with its own test, not a subcategory of issuing.

Source. Article 9N(1) makes two things specified activities in their own right: safeguarding a qualifying cryptoasset, or a relevant specified investment cryptoasset, on behalf of another, and arranging for someone else to carry on that safeguarding.1 Article 9N(2)(a) defines safeguarding by a control-based test: a person (C) is treated as safeguarding the asset if C has control of it through any means that would let C bring about a transfer of its benefit to another, including to C itself. Article 9N(4) says the means of control include holding or storing the means of access, or appointing someone else to do that holding or storing, and article 9N(5)(e) states expressly that "means of access" includes a private cryptographic key.1 Articles 9O to 9R then carve out four specific situations from the article 9N(1) activity: 9O, where the activity happens under arrangements operated by a connected authorised cryptoasset custodian that assumes an equivalent responsibility; 9P, unremunerated introductions by an unconnected party to an authorised cryptoasset custodian; 9Q, temporary holding to facilitate settlement of a transaction; and 9R, which covers acting as an agent for instructions where a third party undertakes the safeguarding directly to the principal, safeguarding activity that involves no holding-out as providing such a service, and safeguarding held for the purpose of dealing activity that would fall within article 9T but for the article 9V(1)(e) exclusion.1

Application. It's easy to read "holding" in this section and assume it's the same holding already dealt with in Section B, the backing-asset limb of article 9M(2)(c)(ii). It isn't. Section B's backing-asset limb is about an issuer's own reserve, typically cash and short-dated government debt, not a cryptoasset at all in most fiat-backed structures, and it goes to whether that person is issuing the stablecoin. Article 9N is about a different asset and a different relationship entirely: who holds the qualifying stablecoin token itself on behalf of a customer, the way a wallet provider, an exchange, or a custodian does once the token exists and is out in circulation. A firm can be entirely uninvolved in issuing a stablecoin under article 9M and still be safeguarding it under article 9N, simply by holding customer balances in a wallet it controls.

The control-based test matters because it looks past who is named as custodian on paper and asks who actually holds the means of access, in practice that usually means whoever holds the private keys, or has appointed someone else to hold them on their behalf. A firm that has genuinely handed off key custody to a connected, authorised custodian under article 9O, or whose role is limited to a brief settlement-window hold under article 9Q, may fall outside the article 9N(1) activity even though it appears in the transaction chain. The four exclusions in 9O to 9R are narrow and fact-specific, they don't turn on a firm's marketing description of its own role, and none of them apply automatically just because another regulated entity is somewhere in the picture.

Action. Before concluding that a firm is, or isn't, safeguarding a qualifying stablecoin, identify who actually holds or controls the means of access to it, not who is named as the responsible custodian in a customer contract. Then check whether that specific holding fits one of the four narrow exclusions in articles 9O to 9R. Keep this analysis separate from Section B's issuing question: a firm can be an issuer without being a safeguarder, a safeguarder without being an issuer, or both at once, and each activity is authorised, or excluded, on its own terms.

Section D

What activity is a stablecoin trading platform, dealer, or arranger carrying on?

Sections B and C dealt with issuing and holding a stablecoin. This section deals with trading it. Trading platforms, dealing as principal, dealing as agent, and arranging deals are four separate specified activities, not four labels for the same thing, and a single firm often carries on more than one of them at once without realising it has crossed from one provision into another.

Source. Article 9S makes operating a qualifying cryptoasset trading platform a specified activity in a single, standalone provision, with no exclusions set out in the article itself.1 Article 9T makes buying, selling, subscribing for or underwriting a qualifying cryptoasset as principal a specified activity; article 9U excludes transactions absent specific holding-out or public-solicitation conduct by the person entering them, except that this exclusion does not apply where the person acts as bare trustee or nominee for another; and article 9V excludes stablecoin creation and design, minting, no-consideration transfers, automatically-created reward distributions, employee or partner issuer sales, capital-raising private sales of self-created tokens, same-group-only principal trades, and any activity separately specified by articles 9M, 9S or 9Z6.1 Article 9W makes the same conduct a specified activity where it's carried on as agent rather than principal; article 9X excludes the same stablecoin-specific categories as article 9V, minus capital-raising sales and same-group trades, but unlike article 9U it contains no holding-out or solicitation test at all.1 Article 9Y makes two things specified activities: arrangements for another to deal in a qualifying cryptoasset, and arrangements made with a view to a participant dealing; articles 9Z to 9Z5 exclude arrangements that do not, or would not, bring about the transaction, introductions made solely to an authorised person, arrangements that merely enable communication between the parties, arrangements for transactions the arranger itself enters as principal or agent, trustee or personal representative arrangements carrying no remuneration beyond that role, and the same stablecoin-specific categories again.1 Article 9Z6 sits alongside all three: it makes arranging, as principal or agent, for qualifying cryptoasset staking a specified activity in its own right, with its own separate exclusions, and it matters to this guide only because articles 9V, 9X and 9Z5 each exclude 9Z6-specified activity from the dealing-as-principal, dealing-as-agent and arranging perimeter respectively.1

Application. The trading platform provision is the least forgiving of the four: article 9S has no exclusion written into it at all, so a firm running an order book or matching engine for a qualifying stablecoin is caught the moment it does that, regardless of how it describes the service to customers. Dealing as principal and dealing as agent read almost identically to each other, buying or selling a stablecoin from a firm's own inventory versus executing a customer's order against the market, but they diverge on one point that matters in practice: principal dealing under article 9U can fall outside the activity where there's no holding-out or public solicitation involved, while agent dealing under article 9X gives up that escape route entirely. A firm executing orders as agent can't rely on having kept a low profile the way a principal dealer sometimes can. Arranging is the activity most likely to apply to a firm that never touches the stablecoin itself, a platform that connects two counterparties, or that introduces a customer to an already-authorised dealer, and the 9Z to 9Z2 exclusions are the ones that do the most work here: introducing solely to an authorised person, or merely letting two parties communicate, can take a firm outside article 9Y even while it sits in the middle of the transaction. Staking is worth flagging only to rule it out: where a stablecoin is used in blockchain validation, that conduct is assessed under article 9Z6 and its own exclusions, not folded into the dealing or arranging analysis above.

Across all three provisions, the same handful of issuer-side activities keep reappearing in the exclusion lists, stablecoin creation and design, minting, no-consideration transfers, reward distributions, and employee or partner sales. That repetition isn't an accident. Those activities already have a home under article 9M, and excluding them from dealing, agent dealing and arranging stops the same conduct being double-counted as a second, separate specified activity on top of issuing.

Action. Identify which of the four provisions, trading platform, principal dealing, agent dealing, or arranging, the conduct actually falls under before looking for an exclusion, since the available exclusions differ by provision and an argument that works for a principal dealer under article 9U won't necessarily work for an agent dealer under article 9X. Where staking is involved, route the analysis to article 9Z6 directly rather than testing it against articles 9T, 9W or 9Y.

Section E

Two exclusions that cut across every activity in this guide

Two further exclusions in the Regulated Activities Order don't belong to any single specified activity covered so far. They apply across the safeguarding activity in Section C and the dealing and arranging activities in Section D, which is reason enough to treat them on their own rather than folding them into either.

Source. Article 9Z10 excludes activity carried on by a supplier of goods or services to a customer generally, but that general exclusion is switched off for article 9N safeguarding so far as it applies to relevant specified investment cryptoassets, while a narrower, related-sale-or-supply version of the exclusion continues to apply specifically to articles 9T, 9W and 9Y. Article 9Z11 excludes activity incidental to a profession or business, but only where four conditions are all satisfied at once: a close factual connection making the activity a necessary ancillary to the profession or business; the activity not providing a systematic source of income; no marketing of the incidental activity beyond disclosure as a necessary ancillary; and the profession or business being supervised by a body listed under the Financial Services and Markets Act 2000 (Designated Professional Bodies) Order 2001.1

Application. Article 9Z10 treats safeguarding differently from dealing and arranging on purpose. A general supplier-of-services exclusion would otherwise let a wallet-hosting or infrastructure provider argue it's simply supplying a service to its customers, exactly the kind of argument the control-based test in Section C exists to cut through, so the exclusion is switched off for cryptoasset safeguarding specifically. For dealing and arranging under articles 9T, 9W and 9Y, a narrower related-sale exclusion still survives, aimed at genuine incidental sales rather than a business built around them. Article 9Z11 is a cumulative test, not a menu: a firm doesn't get to satisfy one or two of the four conditions and call the rest close enough. It's built for a solicitor or accountant handling a client's stablecoin incidentally to the underlying professional work, supervised by a recognised professional body, not for a fintech whose core business happens to touch cryptoassets and that markets itself accordingly.

Action. Before relying on either exclusion, confirm which specified activity is actually in play, since article 9Z10 works differently for safeguarding than it does for dealing and arranging. For article 9Z11, check all four conditions individually rather than assessing the activity as a whole; failing even one of them, most often the systematic-income or no-marketing condition, removes the exclusion entirely.

Section F

Territorial scope, UK and overseas issuers

Every section so far has assumed an issuer whose activity sits in the UK. That assumption doesn't hold for a stablecoin designed overseas, or issued by a group with no UK head office, and the territorial test is where that assumption gets tested directly, along with what happens to the analysis when it fails.

Source. PERG 18.3.5 states that issuing a qualifying stablecoin is considered to be carried on in the UK where the offering, redemption, and maintaining value are carried on from, or arranged to be carried on from, an establishment in the UK. Separately, under section 418(6B) of the Act, a person who is not themselves acting from an establishment in the UK is deemed to be carrying out this regulated activity in the UK where all the elements of the issuing activity are being carried out in the UK on their behalf. An overseas person arranging for all elements of issuing a qualifying stablecoin to be undertaken in the UK is therefore treated as carrying on the article 9M activity in the UK. Where that regulated activity is carried on by way of business, FCA authorisation is required unless a relevant exemption, saving or transitional provision applies.2 PERG 18.8.5-18.8.6 addresses the other side of this: where a person undertakes issuance or redemption for a qualifying stablecoin but does not fall within the scope of the issuing activity, including because they don't meet this territorial test, they may still require a dealing permission. An overseas issuer who isn't considered to be issuing a qualifying stablecoin in the UK will likely not benefit from the specific article 9M issuance exclusions from dealing as principal, dealing as agent or arranging. Other applicable exclusions, and the separate territorial scope of the relevant dealing or arranging activity itself, still have to be considered, and a person who arranges issuance or redemption on the overseas issuer's behalf may itself require an arranging permission.2

Application. Article 9M(2)(a) and (c), already covered in Section B, requires an issuer's offering, redemption and backing-asset-holding activity to be carried on from a UK establishment. That's the direct route into UK territorial scope, and an issuer whose activity genuinely sits overseas fails it. But failing the direct test isn't the end of the analysis, section 418(6B) provides a second, deeming route: an overseas person who arranges for every element of issuing, not most of them, to be carried out in the UK on their behalf is treated as carrying on the activity in the UK regardless of where the person themselves is based. The word "all" is doing the same kind of work here that "provided" did for article 9M(4)(c) in Section B: a fully onshored arrangement triggers deeming, a partially onshored one doesn't. And where an overseas issuer fails both the direct test and the deeming test, that isn't necessarily good news for it, PERG 18.8.5-18.8.6 exists precisely because the article 9M issuance exclusions that would otherwise keep issuer-side conduct out of dealing and arranging classification, covered in Section D, are keyed to the issuing activity itself. No UK issuing activity means no exclusion, which means the overseas issuer's UK-directed conduct has to be tested against the ordinary dealing and arranging provisions, on their own separate territorial terms, rather than assumed to fall outside UK regulation altogether.

Separate from the activity-level question is how an issuer with UK exposure has to be structured. The FCA's AICF guidance sets a default expectation that international cryptoasset firms will operate through a UK legal entity rather than a branch, and that default applies specifically to firms solo-regulated by the FCA. Dual-regulated firms, FCA and PRA together, are the exception: they may operate cryptoasset activity from a UK branch instead if they demonstrate, at the authorisation gateway and on an ongoing basis, that they meet the threshold conditions from that branch, assessed case by case with the PRA as lead regulator. This matters differently depending on where a firm starts from, already FSMA-authorised for other activities and needing a variation of permission, MLR-registered for cryptoasset activity but not yet FSMA-authorised, or using the section 21 gateway and not yet either, and the FCA's own finalised guidance on this sits in FG26/7, which this guide treats as the next-level source if a more granular answer is needed.3

Action. Run the territorial test in two stages, not one: first, whether the issuer's offering, redemption and value-maintenance activity is itself carried on from a UK establishment; second, if not, whether the issuer has arranged for all of those elements, not some of them, to be carried out in the UK on its behalf. If both fail, don't conclude the issuer is outside UK scope, check instead whether its UK-directed conduct needs a dealing or arranging permission under Section D's tests. Separately, and regardless of the answer on activity-level scope, check the issuer's own legal structure against the AICF default of a UK legal entity, unless it is dual-regulated and can demonstrate branch-level compliance with the threshold conditions.

🌐
The Offshore Shortcut
No UK head office gets treated as the end of the UK-scope question, when a second test can still reach the issuer.
Risk
An overseas issuer with no UK establishment is written off as outside UK authorisation the moment the direct territorial test fails.
Signal
Section 418(6B) deems an overseas person to be issuing in the UK where all the elements of the activity, not some of them, are carried out here on its behalf.
Response
Run the direct establishment test first, then the deeming provision, and check the dealing or arranging tests if both fail, before concluding an overseas issuer sits outside UK scope.
Classification Diagram

Which regulated activity applies, by actor, and does it change overseas?

Sections B through F each work through one activity in isolation. Read together as a single starting point by actor, an issuer, a custodian, a dealer or arranger, and a firm whose real business is paying or being paid rather than dealing in stablecoins, the same tests resolve into four short routes. Each node cites the section it comes from; nothing here is a new test, it is the existing tests laid out by who is asking, not what activity is being asked about.

Read the same routes as a plain-text walkthrough
  1. Issuer. Check whether all three Section B limbs, offering, redemption, backing-asset holding, sit with this person or group. If they do, check whether that activity is carried on from a UK establishment (Section F). If not, check whether the person has arranged for every element, not some of them, to be carried out in the UK on its behalf; if so, section 418(6B) deems it a UK issuing activity, and FCA authorisation is required where that activity is carried on by way of business, unless a relevant exemption, saving or transitional provision applies. If neither territorial test is met, the person is not caught as an issuer, but the same conduct may still need checking against the dealer/arranger route.
  2. Custodian. Check whether this person controls the asset under Section C's test, any means of bringing about a transfer of its benefit, including holding the means of access such as a private key. If they do, check whether one of the four narrow exclusions in articles 9O to 9R applies. If none does, the safeguarding activity under article 9N(1) applies. Section F's overseas test was built for issuing only, so a custodian's territorial position has to be checked separately, not assumed.
  3. Dealer or arranger. Identify which Section D provision the conduct actually falls under: operating a platform (article 9S, no exclusion available), dealing as principal (article 9T), dealing as agent (article 9W), or arranging (article 9Y); route staking conduct to article 9Z6 instead. Check that provision's own exclusion. If none applies, the activity is caught. The territorial scope for this route is separate from the issuer's test and isn't worked out in detail in this guide, so check it independently.
  4. Payment-activity firm. If the firm's stablecoin activity is limited to paying or being paid for its own goods or services, check Section E's narrower article 9Z10 related-sale exclusion first, then article 9Z11's four cumulative conditions, necessary ancillary, no systematic income, no marketing beyond ancillary disclosure, and a Designated Professional Body-supervised business. Failing even one article 9Z11 condition removes that exclusion entirely. If neither exclusion fits, the firm is tested as an ordinary dealer or arranger under the Section D route above, including that route's own territorial caveat.
🌐
Worked Scenario 2 · Territorial scope and the deeming provision
The Overseas Issuer
⚖
What do you do?Make the call

A stablecoin issuer is incorporated and headquartered outside the UK. It designs the token, sets the redemption terms, and determines the value-maintenance methodology entirely from its overseas head office. It has, however, engaged a UK-based operations firm under a single outsourcing arrangement, structurally similar to Scenario 1's, under which that UK firm carries out the entire offering to customers, the entire redemption process, and the entire holding of the backing assets, all from the UK, under arrangements the overseas issuer has made.

Section G

Commencement, the application window, and the saving and transitional provisions

Sections B to F establish which activities are regulated and for whom. This section covers when authorisation actually has to be in place, and what protects a firm whose application is still moving through the FCA when that date arrives.

Source. Subject to the preparatory-commencement carve-out below, the Regulations come into force on 25 October 2027, defined as the "full commencement day."1 For a defined set of preparatory purposes only, they come into force earlier, at the end of the 21-day period beginning the day after the day they are made: enabling the FCA to make or approve rules, give guidance or directions, and take other preparatory steps; enabling Part 4A permission, permission variation, section 55NA and section 59 approval applications to be made and determined for the newly regulated activities; and enabling the FCA to exercise its Part 4A and Part 5 powers over those activities.1 The cryptoasset authorisation application period itself runs from 30 September 2026 to 28 February 2027, set by the FCA under Part 7 of the Regulations, which requires the period to be at least 28 days long and to close at least 28 days before full commencement.4

The saving provision protects a firm that applied for authorisation, or a variation of permission, within that window and whose application is not yet finally determined at full commencement, including where it has referred an FCA refusal to the Upper Tribunal and the Tribunal hasn't yet decided. Such a firm may continue providing cryptoasset services, not merely wind them down, until the application is finally determined, but it must notify the FCA that it is relying on the provision as soon as reasonably practicable after full commencement, and notify the FCA again when it stops relying on it. Even during an open Tribunal referral, the FCA can direct the firm into the transitional provision instead, where it considers this necessary for preventing, detecting, investigating or prosecuting a criminal offence, for consumer protection, or for advancing its own objectives; and if the Tribunal ultimately upholds the FCA's refusal, the firm moves into the transitional provision to exit the market in an orderly manner.4 The transitional provision is a separate, more restrictive mechanism: it exempts an eligible firm from the general prohibition, or from the equivalent restriction for firms already FSMA-authorised, but only for the new cryptoasset activities and only to the extent necessary to perform a pre-existing contract entered into before the firm entered the provision, with no new contracts permitted. Eligibility combines window timing with whether the application is still live at commencement, not window timing alone: an applicant who applied after the window closed but before full commencement, and whose application is undetermined at commencement, enters the transitional provision automatically; an in-window applicant whose application is finally refused with no live Tribunal review, or who withdraws, before commencement also falls into the transitional provision rather than the saving provision, because nothing live remains at commencement for the saving provision to protect. A firm that never applies gets neither mechanism and must wind down before commencement or risk breaching the general prohibition outright. The maximum wind-down period under the transitional provision is two years from full commencement, and it carries its own notification duties, on entry, on exit, and to each counterparty of a pre-existing contract, along with restrictions on financial promotions and continuing FCA powers to amend, condition, cancel, investigate or publicise a firm's use of it.5

Application. The two mechanisms reward different things. A firm that applies within the 30 September 2026 to 28 February 2027 window and is still waiting for a decision when full commencement arrives keeps operating close to normally under the saving provision. A firm that applies late, after the window closes but before commencement, and is still waiting at commencement, is dropped straight into the transitional provision's wind-down-only regime instead, with no route to the more generous protection regardless of how strong its application is. The sharper trap sits with in-window applicants: applying on time doesn't itself guarantee saving-provision protection, because that protection depends on the application still being live at commencement. A firm that applied in September 2026 but was refused, with no Tribunal referral pending, in the summer of 2027 falls into the transitional provision from that point, not the saving provision, even though it did everything right by the calendar. Preparatory commencement is what makes the whole structure workable in practice: because the Regulations take effect early for the specific purpose of letting the FCA build the gateway and take applications, the application window is already open from 30 September 2026, nearly thirteen months before full commencement itself, giving firms most of a year to get an application in before the saving-versus-transitional distinction starts to matter at all.

Action. Before treating a firm's pending application as protected, check three things in sequence: whether it applied within the 30 September 2026 to 28 February 2027 window; whether the application remains live, not refused with no pending Tribunal referral, and not withdrawn, at full commencement; and whether the FCA has exercised its power to move the firm into the transitional provision regardless of window timing. Only a firm clearing all three sits in the saving provision. A firm that applied but fails any of them sits in the transitional provision's wind-down-only regime, and a firm that never applied sits outside both, on borrowed time until full commencement.

🕰
The Frozen Clock
A single headline commencement date gets carried forward from an old summary as though the regime were still waiting on it, when several of its clocks have already moved.
Risk
A vendor note, news piece or earlier advisory memo is cited for "the" stablecoin commencement date, carrying forward whatever was true only on the day that source was written.
Signal
This regime runs on more than one date at once, preparatory commencement, the application window, full commencement on 25 October 2027, and, on MLR's separate track (Section H), Schedule 6B provisions that took effect around 30 June 2026, already behind us as of this guide's own drafting date.
Response
Check a provision's own commencement date against a primary source or a maintained tracker, and confirm this guide's own data-date, before relying on a secondary summary's stated date as still current.
Section H

The parallel MLR registration regime

Everything in Sections B to G sits under FSMA authorisation. A firm that is, or needs to become, registered under the Money Laundering Regulations 2017 is subject to a materially different regime running on its own separate timeline, and the two should not be read as one continuous transition toward a single date.

Source. This paragraph is FinCrimeRadar's own interpretive synthesis of how two instruments fit together, not a direct quotation of either. "Cryptoasset exchange provider" and "custodian wallet provider" are pre-existing MLR 2017 registration categories under regulation 14A; the amending instrument that introduces the new correspondent due diligence and change-of-control provisions cross-references regulation 14A throughout without amending it, which confirms the category already existed beforehand, though this guide does not independently pin down which earlier instrument first inserted it. MLR registration runs under a different legal basis, registration, than the new FSMA-authorised activities created for stablecoin issuing, safeguarding, dealing and arranging: these are two parallel regimes with different populations and different legal bases, not one regime with a single transition date. The amending instrument itself carries three separate commencement dates for its cryptoasset-relevant provisions, and none of them line up with each other or with the FSMA commencement structure in Section G except by coincidence. New regulation 34A, requiring enhanced correspondent due diligence, commences 1 February 2027. A new Schedule 6B, applying the FSMA change-of-control regime to registered cryptoasset businesses, has its own split commencement: paragraphs 1, 2 and 5, covering businesses registered before 25 October 2027, plus the shared interpretation provisions, took effect approximately 30 June 2026, twenty-one days after the instrument's 9 June 2026 making date; paragraphs 3 and 4, covering businesses registered on or after 25 October 2027, take effect on that date itself. General MLR housekeeping provisions in the same instrument also took effect approximately 30 June 2026.6

Regulation 34A requires a cryptoasset exchange provider or custodian wallet provider with a correspondent relationship involving regulation 14A-type services with a similar overseas provider to go beyond existing correspondent measures: gathering enough information to understand the overseas provider's business fully; assessing its reputation and supervision quality from credible public sources; assessing its AML and counter-terrorist-financing controls; obtaining senior management approval before establishing a new relationship; documenting each party's responsibilities; and being satisfied the overseas provider carries out, and can evidence, customer due diligence for its own direct-access customers. It separately bans correspondent relationships with shell banks outright, and requires enhanced measures to avoid relationships with institutions known to let their accounts be used by one. Schedule 6B applies the existing FSMA change-of-control regime to registered cryptoasset exchange providers and custodian wallet providers, with thresholds that vary by trigger rather than a single flat figure: the initial acquiring-control trigger is 10% of shares or voting power, significant influence, or beneficial-owner status under the relevant MLR provisions, while separate increasing-control and reducing-or-ceasing-control triggers use 20/30/50% step thresholds crossed in either direction.6

Application. Both Schedule 6B provisions and the general MLR housekeeping provisions took effect around 30 June 2026, which as of this guide's drafting date has already passed. A firm registered under regulation 14A before 25 October 2027 is not waiting for a future obligation here; the change-of-control regime in Schedule 6B paragraphs 1, 2 and 5 already applies to it now. That's easy to miss if a reader assumes every cryptoasset-related date in this guide is still ahead of full commencement; this particular one isn't. Regulation 34A's correspondent due diligence obligations, by contrast, genuinely are still ahead, arriving 1 February 2027, on a clock that runs independently of both the FSMA application window and full commencement in Section G. Registration under regulation 14A doesn't convert into FSMA authorisation automatically either; a firm needs to apply afresh for the new regulated activities covered in this guide, and a firm already FSMA-authorised for other business needs a variation of permission rather than a fresh application, though this specific point is background rather than something independently checked against MLR 2017's own registration text in this pass.5

Action. Before telling a firm it has until 25 October 2027 to sort out its position, identify which regime, FSMA authorisation or MLR registration, and which specific provision within it, actually governs the obligation being discussed. For a firm already registered under regulation 14A, check Schedule 6B's change-of-control obligations now, since the paragraphs covering pre-25-October-2027 registrations are already in force, not pending. Track regulation 34A's 1 February 2027 date on its own terms, separately from the saving and transitional mechanics in Section G, since the two regimes run on entirely different clocks and neither commencement date substitutes for the other.

🥛
The Borrowed Badge
An existing MLR registration gets worn as though it already covers the new FSMA-authorised activities, when it runs on a different legal basis entirely.
Risk
A firm already registered under regulation 14A assumes that status satisfies, or will automatically roll into, the authorisation the new stablecoin issuing, safeguarding, dealing and arranging activities require.
Signal
MLR registration and FSMA authorisation run on separate legal bases and separate clocks, and Schedule 6B's change-of-control paragraphs for firms registered before 25 October 2027 are already in force now, not waiting for full commencement.
Response
Identify which regime, and which specific provision within it, actually governs the obligation in question, and check a regulation 14A firm's Schedule 6B position today rather than assuming registration alone covers it.
Section I

CASS treatment of an issuer's money

Section B established which entity is treated as issuing a qualifying stablecoin. This section covers what happens to that entity's money once it is, and the position is a deliberate departure from the default client money regime, not a gap the default regime happens to fill.

Source. CASS 7, the ordinary client money chapter, is disapplied in full for firms carrying on the issuing activity, covering all money arising from stablecoin issuance, not only money held as backing assets. That is a broader final position than the original consultation proposal, which had only proposed clarifying that backing-funds-account money specifically was not client money; the final rule instead removes issuers from CASS 7 entirely for issuance-related money. An issuer may still be subject to other CASS chapters for other lines of business it runs, in which case its backing assets must not be held in the same backing funds account as money held under any other CASS chapter. The existing banking exemption, for credit institutions and approved banks holding money as a deposit rather than client money, is unchanged.3 CASS 16 is the chapter that actually governs the backing funds account: the FCA's final position is that an issuer must not hold backing assets in the same account as money held in respect of any other CASS chapter. This is the same reserve Sections A, B and F call backing assets; CASS 16 just governs it at the level of the account it sits in, not a different pool of money. The consultation-stage proposal framed this as an application of the general CASS 1.2.11R segregation-by-chapter rule to CASS 16 specifically; the final "Our response" text confirms the segregation substance survived into the final rule but doesn't itself re-cite that rule number, so the CASS 1.2.11R citation traces to the consultation paragraph rather than the adopted final-rule text, worth knowing before citing it as though the final rule itself uses that number.3

Application. This connects directly to article 9M(2)(c)(ii) from Section B, the backing-asset-holding limb that makes an entity an issuer in the first place: it is precisely that backing-asset money CASS 16 governs, while CASS 7's full disapplication exists so issuance-related money is never mistaken for ordinary client money under the general regime. The practical risk shows up where a single entity is both an issuer under Section B and something else, a dealer under Section D, for instance: the CASS 7 disapplication only reaches issuance-related money, so that entity's other business generates its own client money obligations under whatever chapter applies to that business, and the two pools cannot share an account. Backing assets sit in the CASS 16 backing funds account; everything else sits wherever its own CASS chapter puts it.

Action. Before treating a stablecoin issuer's money as either ordinary client money or as falling outside CASS protection altogether, identify whether it arises from the issuing activity in Section B, in which case CASS 7 is disapplied and CASS 16 governs instead, or from a separate line of business the same entity happens to run, in which case that business's own CASS chapter applies and its money cannot be commingled with the CASS 16 backing funds account.

Section J

CASS treatment of safeguarding firms

Article 9N, covered in Section C, treats safeguarding a qualifying cryptoasset and safeguarding a relevant specified investment cryptoasset as one regulated activity. The CASS conduct regime that governs how a firm actually has to hold each of them does not follow that activity boundary, and that mismatch is exactly the kind of gap where a firm can correctly identify that it is safeguarding and still apply the wrong custody rulebook to it.

Source. CASS 17 applies to a firm safeguarding qualifying cryptoassets within the scope of that chapter, that is, the qualifying-cryptoasset limb of the article 9N safeguarding activity specifically, not the relevant-specified-investment-cryptoasset limb.3 RSIC custody is not under CASS 17 at all: a firm safeguarding an RSIC is instead subject to CASS 6, described in the FCA's own wording as applying "for the time being," an explicitly provisional arrangement rather than a settled one, with the FCA separately inviting industry feedback through its tokenisation call for input to shape the longer-term custody rules for RSICs. A related clarification in CASS 7.14.5G confirms that a firm safeguarding RSICs under CASS 6 remains within CASS 7 scope for any client money arising in connection with that safeguarding, consistent with the position that already applied to firms in CASS 6 before this regime existed.3 Separately again, CASS 8, the mandate rules, does not apply to a firm safeguarding cryptoassets within the meaning of article 9N. The FCA draws the two concepts of "control" apart deliberately: CASS 8's control is a firm's authority to instruct or direct a client's assets, while article 9N's control is a firm's ability to bring about a transfer of the benefit of a client's cryptoassets, different tests that happen to share a word. A CASS 8 mandate, a discretionary manager's power of attorney over cryptoassets, for example, can still exist alongside this, but the mandate-holder is not thereby the article 9N safeguarding firm; it is instead in a position to instruct that firm. Whether CASS 8 applies to non-custodial staking depends on whether the firm holds mandate authority meeting all five conditions in CASS 8.2.1R, and the FCA states most existing non-custodial staking models do not currently involve that kind of authority.3

Application. A firm that has correctly worked through Section C's control-based test and concluded it is safeguarding under article 9N still has one further, asset-specific question to answer before it knows which custody rulebook governs: is the asset a qualifying cryptoasset, in which case CASS 17 applies, or an RSIC, in which case CASS 6 applies instead, on a provisional basis the FCA may still revise. Getting this second question wrong, applying CASS 17's rulebook to an RSIC, or CASS 6's to a qualifying cryptoasset, is a live version of the misclassification risk worth naming directly: the firm correctly identified that it was safeguarding, and still put the client's assets in the wrong regulatory trust because it treated the two asset types as interchangeable. CASS 8 raises a related but distinct risk in the same custody chain: a firm shouldn't assume that holding a discretionary mandate over cryptoassets makes it the article 9N safeguarding firm, or that being the safeguarding firm means no one else in the chain holds a CASS 8 mandate over the same assets. The two roles test for different things and can sit with two different entities at once.

Action. Once a firm has established that it is safeguarding under article 9N in Section C, classify the specific asset by type, qualifying cryptoasset or RSIC, before applying CASS 17 or CASS 6, and treat the RSIC position as provisional rather than settled given the FCA's own "for the time being" framing. Separately, check whether any party in the custody chain holds a CASS 8 mandate to instruct the safeguarding firm, since that is a different question from who is actually carrying out the safeguarding.

🔒
The Wrong Trust
Getting the safeguarding question right doesn't guarantee the client's assets land in the right custody rulebook.
Risk
A firm applies CASS 17 to an RSIC, or CASS 6 to a qualifying cryptoasset, or assumes whoever holds a CASS 8 mandate is automatically the article 9N safeguarding firm.
Signal
CASS 17 governs qualifying cryptoassets, CASS 6 governs RSICs on a "for the time being" basis the FCA may revise, and CASS 8's control test tests for something different from article 9N's, so the two roles can sit with different entities.
Response
Classify the asset type before choosing between CASS 17 and CASS 6, and check separately whether anyone in the chain holds a CASS 8 mandate rather than assuming it tracks the safeguarding role.
Section K

CASS 7 protections that survive for other cryptoasset business

Section I's full disapplication of CASS 7 is specific to the issuing activity. For the dealing, agency dealing, arranging and trading-platform activities in Section D, ordinary CASS 7 client money protection still applies, and the FCA has deliberately switched off two carve-outs that would otherwise have softened it.

Source. The professional client opt-out under CASS 7 is disapplied for money held in connection with qualifying cryptoasset activities. The FCA states it does not consider an opt-out appropriate "at this stage," given heightened risk and the current extent of vertical integration and market concentration, and that it will continue to monitor its position as the regime develops, framed explicitly as a current-state position rather than a necessarily permanent one.3 The delivery-versus-payment exemption for commercial settlement systems is separately disapplied where the delivery obligation concerns client cryptoassets. Where a firm receives money ahead of delivery, in a pre-funding arrangement, for example, it is holding client money during the settlement period, and the FCA has confirmed that money must be safeguarded under CASS 7 for the duration of that period. The FCA states it will keep both the DvP position and the definition of "commercial settlement system" under review as settlement models evolve.3

Application. Both carve-outs would, outside the cryptoasset context, let a firm treat certain money as sitting outside CASS 7's protective scope: professional clients are often assumed sophisticated enough to accept reduced segregation protection by choice, and DvP-style settlement often lets money move through a brief window without acquiring client money status at all. The FCA has switched both off specifically for cryptoasset business. A dealer, agency dealer, arranger or trading platform under Section D cannot rely on a customer's professional-client status to avoid segregating that customer's money, and cannot rely on a DvP-style settlement structure to avoid treating pre-funded money as client money during the settlement window. Both positions are explicitly tied by the FCA to current conditions, heightened risk and market concentration for the opt-out, evolving settlement models for the DvP position, rather than presented as permanent features of the regime, which matters for how confidently a reader should rely on either one holding indefinitely.

Action. Before letting a professional-client classification or a DvP-style settlement structure move money outside CASS 7 for a cryptoasset business, confirm the activity in question is a dealing, agency dealing, arranging or trading-platform activity under Section D, rather than the issuing activity already fully carved out under Section I, and treat both disapplications as current FCA policy rather than a fixed statutory position that cannot change.

Section L

The due diligence framework checklist

Everything in Sections B to K is analysis. This section turns it into the practical checklist a practitioner runs before dealing with an issuer, and it is deliberately built in two tiers, so a reader can tell at a glance which fields sit on an enforceable disclosure duty and which are this guide's own judgement about what a thorough review should also cover. Nothing here is an interactive tool; it is a fixed list to work through by hand.

Source. Category 1 covers fields that trace to an actual FCA-mandated disclosure or prudential obligation.

Category 1 · FCA-mandated

The technical control fields, smart contract administrator, freeze authority, upgrade authority, bridges, and supported blockchains, are not free-standing FCA requirements in their own right. They are this guide's own practitioner decomposition of the disclosure duty in regulation 13 of SI 2026/102: regulation 13(1)(a)(ii) requires disclosure of the underlying technology, including any protocol and consensus mechanism; 13(1)(a)(iii) requires disclosure of the governance mechanisms of the qualifying cryptoasset; 13(1)(e) requires disclosure of any matters relating to control of the cryptoasset, including any person exerting such control, that may impact its price or value. The underlying duty is FCA-mandated; these five field names are how this guide checks it, not language regulation 13 itself uses.1

The reserve composition and custodian fields cover: core backing assets limited to short-term deposits and short-term government debt instruments; an on-demand deposit requirement of 5% of the backing pool in on-demand deposits only, applying to all UK stablecoin issuers; expanded backing assets, longer-dated government debt, PDCNAV money market funds, and repurchase agreements, permitted with FCA notification and compliance with the Backing Asset Composition Requirement; a separate Core Backing Asset Requirement equal to the higher of 5% of the backing pool or the highest daily redemption percentage over the past 180 redemption days, recalculated on every redemption day, with on-demand deposits unable to double-count toward it; single-currency backing only, matching the stablecoin's own denomination; up to 5% excess permitted in the backing pool following internal reconciliation; full 1:1 backing required at all times other than for permanently burned tokens; and a reserve custodian that may be intragroup, not necessarily an unconnected third party, subject to a 20% cap on backing pool value, SYSC 10 conflicts-of-interest obligations, periodic diversification review, and signed acknowledgement letters reviewed at least annually.7 This "backing pool" is PS26/10's own prudential framing of the same reserve that Sections A, B and I discuss as backing assets and the CASS 16 backing funds account respectively, sized and tested under different rules for a different purpose.

The redemption and disclosure fields cover: a universal right to redeem at par value; a T+1 redemption timeline triggered by the issuer's receipt of the stablecoin being redeemed, not by the redemption request itself, meaning AML and KYC checks must be completed before that clock starts rather than within the T+1 window; the availability of reliance on other firms' KYC checks under MLR regulation 39 where the T+1 timeline would otherwise conflict with money laundering legislation; a contract between the issuer and each person it issues stablecoins to, covering redemption conditions and passing effectively to secondary-market holders; reserve disclosure updated at least every three months for fast-changing information such as circulation and backing pool value, and whenever inaccurate for more static information; backing assets disclosed only by asset-type category, not by individual position; a five-year disclosure retention requirement; only custodians holding more than 20% of the backing pool named in disclosures; a Digital Token Identifier under ISO 24165, or an equivalent identifier, disclosed; and a Stablecoin QCDD required before sale or subscription, aligned to at least match website disclosures. The issuer itself remains solely responsible for the QCDD's content, accuracy and updates, not any third-party platform that admits the stablecoin to trading, though this specific point rests on the FCA's own restatement of that responsibility rather than on this guide having independently checked the underlying provision's primary text.7

The independent assurance field requires an annual independent review of the accuracy of the issuer's statements, over the preceding 12 months, about the 1:1 ratio between the backing asset pool and the stablecoin pool, carried out to a reasonable-assurance-engagement standard by a reviewer meeting FCA-specified qualifications that are not limited to Companies Act auditors, crypto-specific technical, custody, valuation or systems expertise is explicitly accepted. Firms must publish a statement from the reviewer covering the outcome, review date and qualifications as soon as practicable, and must designate a specific senior manager responsible for the quarterly disclosure declaration. The FCA has expressly rejected lower-assurance alternatives raised in consultation, including on-chain verification and reliance on existing financial statements, as insufficient.7

Category 2 · Practitioner judgement, no FCA mandate

Category 2 covers fields with no FCA-mandated disclosure basis found in the material reviewed for this guide. Historical depegs, sanctions exposure, and previous enforcement incidents reflect standard KYB and AML investigative practice; no FCA source reviewed for this guide requires disclosure of any of the three. Concentration risk arising from a limited pool of unconnected custodians is included on the same basis, and with one further caveat: a citation for this specific concern, attributed to the Bank of England's own CASS 17 instrument text, was checked directly against the material reviewed for this guide and could not be verified. CASS is an FCA sourcebook, not a Bank of England instrument; no Bank of England text on this point was found; and the quoted language does not appear in the FCA text actually checked. Concentration risk therefore appears here purely as this guide's own analytical judgement, with no regulatory citation behind it, not as a paraphrase of anything any regulator has said.

Application. The two categories are kept visibly separate because a gap in each means something different. A gap in a Category 1 field is a potential failure to meet an actual disclosure or prudential obligation, and should be treated as a compliance finding requiring escalation. A gap in a Category 2 field is a practice observation, this guide's own view that a thorough review should also ask the question, not evidence that the issuer has failed to comply with anything the FCA has mandated. Collapsing the two into one undifferentiated list would let a reader treat "no sanctions-exposure disclosure policy" as the same kind of finding as "no independent assurance review," when only the second is something the FCA has actually required. The technical control fields sit in between the two categories in a way worth calling out on their own terms: the disclosure duty behind them is real and FCA-mandated, but the five field names a reviewer actually checks against are this guide's own decomposition of that duty, so citing "freeze authority" as if it were FCA terminology would overstate what regulation 13 itself says.

Action. Work through Category 1 first, and escalate any gap found there as a potential breach of a disclosure or prudential obligation. Work through Category 2 second, and record any gap found there as a practice weakness in a due diligence report, never as a finding that the issuer has breached an FCA requirement. Where the technical control fields are used, keep a note that the field names are this guide's decomposition of regulation 13, not regulatory terminology, so a report built on this checklist doesn't misattribute them to the FCA.

📋
The Generic Checklist
A due diligence list that doesn't separate an enforceable duty from the reviewer's own judgement turns every gap into the same finding.
Risk
A missing sanctions-exposure note and a missing independent assurance review get logged in a due diligence report as the same class of failure.
Signal
This guide's own checklist keeps Category 1, fields tracing to an FCA-mandated disclosure such as regulation 13's technology, governance and control disclosures, separate from Category 2, fields with no FCA-mandated basis such as historical depegs or sanctions exposure.
Response
Escalate a Category 1 gap as a potential breach of a disclosure or prudential obligation, and record a Category 2 gap as a practice weakness, never as an FCA finding.
Quick Reference

At a glance

The same six patterns, regrouped as a single reference. Each one is the risk that makes a classification step look routine, the signal that gives it away, and the response that fits.

🧩
The Missing Limb
A partial outsourcing arrangement gets read as though it were the complete one that actually moves the issuing obligation.
Risk
Two of three 9M(2) limbs outsourced gets treated as clearing the design company of issuing.
Signal
9M(4)(c) only applies where all three limbs, not most, sit with the other party.
Response
Map every limb to the entity actually carrying it out today.
🌐
The Offshore Shortcut
No UK head office gets treated as the end of the UK-scope question, when a second test can still reach the issuer.
Risk
Failing the direct establishment test gets read as failing UK scope outright.
Signal
Section 418(6B) deems UK issuing where ALL elements are arranged to run here.
Response
Run the establishment test, then the deeming test, before concluding scope.
🥛
The Borrowed Badge
An existing MLR registration gets worn as though it already covers the new FSMA-authorised activities.
Risk
Regulation 14A registration assumed to satisfy or convert into FSMA authorisation.
Signal
Separate legal bases, separate clocks; Schedule 6B's pre-2027 paragraphs are already in force.
Response
Identify which regime and provision governs, and check Schedule 6B status now.
🔒
The Wrong Trust
Getting the safeguarding question right doesn't guarantee the assets land in the right custody rulebook.
Risk
CASS 17 and CASS 6 treated as interchangeable, or a CASS 8 mandate mistaken for safeguarding.
Signal
CASS 17 covers qualifying cryptoassets, CASS 6 covers RSICs provisionally; CASS 8's test differs from 9N's.
Response
Classify the asset type first, and check mandate-holding separately from safeguarding.
📋
The Generic Checklist
A due diligence list that doesn't separate an enforceable duty from judgement turns every gap into the same finding.
Risk
A missing disclosure and a missing practice observation logged as the same failure.
Signal
Category 1 traces to an FCA-mandated duty; Category 2 is this guide's own judgement.
Response
Escalate Category 1 gaps as potential breaches; log Category 2 gaps as practice weaknesses only.
🕰
The Frozen Clock
A single headline commencement date gets carried forward as though the regime were still waiting on it, when several of its clocks have already moved.
Risk
A stale vendor note or old memo is cited for "the" commencement date.
Signal
Preparatory commencement, the application window, full commencement, and MLR's own Schedule 6B dates all run separately, some already passed.
Response
Check a provision's own date against a primary source or a maintained tracker, not a secondary summary.
Evidence and Methodology

Primary sources

Every numbered citation above points to one of the seven documents below. Several citations share a source, since a single statutory instrument or FCA policy statement is cited at multiple different articles, regulations or chapters; the specific provision is named in the guide's own text at the point it is used, not repeated here.

  1. The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (SI 2026/102), legislation.gov.uk, made 4 February 2026.
  2. FCA, Policy Statement PS26/18, Cryptoasset Perimeter Guidance, Financial Conduct Authority, 16 September 2026.
  3. FCA Policy Statement PS26/13, "Crypto Regime: Application of FCA Handbook for Regulated Cryptoasset Activities", Financial Conduct Authority, 30 June 2026.
  4. FCA, "Cryptoassets: How the gateway will operate", Financial Conduct Authority, 8 July 2026.
  5. FCA, "Cryptoassets: The transitional provision", Financial Conduct Authority, 24 August 2026.
  6. The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 (SI 2026/621), legislation.gov.uk, made 9 June 2026.
  7. FCA Policy Statement PS26/10, "Crypto Regime: Stablecoin issuance", Financial Conduct Authority, 30 June 2026.

Knowledge Check

Seven questions on the trickier distinctions from Sections A through L, not the card titles.
1. A design company has arranged for an operations firm to handle redemption and backing-asset custody, but the design company still runs the customer-facing offering itself. Does article 9M(4)(c) protect the design company from being treated as issuing?
2. An overseas issuer arranges for a UK firm to carry out redemption and backing-asset custody, but keeps the customer-facing offering under its own overseas operation. Does section 418(6B)'s deeming provision treat it as issuing in the UK?
3. A firm correctly identifies that it is safeguarding a relevant specified investment cryptoasset (RSIC) under article 9N. It then applies CASS 17 to that asset, and treats a discretionary manager holding a CASS 8 mandate over it as the article 9N safeguarding firm. What's wrong here?
4. A firm has been registered under MLR regulation 14A since before 25 October 2027. Does Schedule 6B's change-of-control regime already apply to it, or is that still a future obligation tied to full commencement?
5. A due diligence review finds an issuer has no independent assurance review on file, and separately no sanctions-exposure disclosure policy. How should the review report treat the two gaps?
6. A firm executes customer orders for a qualifying stablecoin as agent, with no public marketing or solicitation of its own. Can it rely on the same "no holding-out" escape that protects a low-profile principal dealer under article 9U?
7. A fintech's core business touches cryptoassets, but it argues its stablecoin-related activity is incidental to that business. It satisfies three of article 9Z11's four conditions, but it does market the activity beyond disclosing it as a necessary ancillary. Does the exclusion apply?
0/7
Frequently Asked

FAQ

Is a token that a platform markets as an "algorithmic stablecoin" automatically outside UK stablecoin regulation? +
Not automatically, and the marketing label decides nothing. Article 88G's two-limb test asks whether the token seeks to maintain a stable value against a single fiat currency and holds fiat currency or other assets for that purpose. A purely algorithmic model holding no stabilisation assets fails the second limb outright, and the FCA's own PERG 18.4.5 guidance extends that same conclusion to a mechanism relying partly, not just wholly, on algorithmic methods rather than backing assets. Run the token through articles 88F and 88G directly, per Section A, rather than relying on how it's marketed.
If a stablecoin issuer outsources redemption and custody to another regulated firm, does that firm become the one needing authorisation to issue? +
Not automatically, and not by default either. Article 9M(4)(c) says that where another person (B) genuinely carries on all three limbs, offering, redemption and backing-asset holding, under arrangements the first party (A) made, only A is treated as carrying on the issuing activity, not B. That protects a complete outsourcing arrangement; it doesn't create a new issuing obligation for the operations firm. A partial arrangement, where A still carries out one of the three limbs itself, doesn't get 9M(4)(c)'s protection at all, per Section B and Worked Scenario 1.
If a stablecoin issuer has no UK office at all, is it automatically outside UK regulation? +
Not automatically. Run the territorial test in two stages, per Section F. First, whether the issuer's offering, redemption and value-maintenance activity is itself carried on from a UK establishment. Second, if not, whether the issuer has arranged for all of those elements, not some of them, to be carried out in the UK on its behalf, which triggers section 418(6B)'s deeming provision. If both fail, that still isn't the end of it: PERG 18.8.5-18.8.6 means the issuer's UK-directed conduct may still need a dealing or arranging permission, tested under Section D's separate provisions.
If a business only uses stablecoins to pay its own suppliers, is it definitely excluded from the dealing or arranging perimeter? +
Not as a settled, blanket rule, and this guide doesn't present it as one. Section E's article 9Z10 carries a narrower related-sale exclusion that can cover genuine incidental sales, and article 9Z11's incidental-business exclusion is available separately, but only where all four of its conditions hold at once, necessary ancillary, no systematic income, no marketing beyond ancillary disclosure, and a Designated Professional Body-supervised business. Failing even one of those conditions removes the exclusion entirely, and if neither exclusion fits the facts, the firm is tested as an ordinary dealer or arranger under Section D like anyone else. The classification diagram's payment-activity-firm lane walks through this same route; treat it as fact-specific, not resolved in the firm's favour by default.
If an issuer has no sanctions-screening or historical-depeg disclosure policy, has it breached an FCA requirement? +
Not necessarily, and Section L's due diligence checklist is built specifically to keep this distinction visible. Historical depegs, sanctions exposure and previous enforcement incidents sit in Category 2: no FCA source reviewed for this guide requires disclosure of any of the three, so a gap there is a practice observation, this guide's own view that a thorough review should also ask the question, not evidence of a compliance breach. A gap in a Category 1 field, such as the independent assurance review, is different and should be escalated as a potential breach of an actual disclosure or prudential obligation. Collapsing the two into one undifferentiated finding overstates what the FCA has actually required.