If your business carries on cryptoasset activity in scope of the Money Laundering Regulations 2017, you must register with the FCA before you begin trading in the UK. Registration is not a badge of approval. It brings you under FCA AML/CTF supervision, and the deadline pressure is real: the FSMA authorisation gateway opens ahead of the new regime's start in late 2027, which changes how existing applicants should sequence their filings now.
Who needs FCA crypto registration: in-scope activities and the FCA's tests
Registration under the MLRs is mandatory for firms providing in-scope cryptoasset services in the UK, and the FCA applies two tests before anything else: is the activity itself in scope, and is it carried on in the UK. Both must be satisfied.
The perimeter catches a broad range of business models, not just exchanges:
- Exchange providers converting fiat to crypto or crypto to crypto
- Custodian wallet providers holding private keys on behalf of clients
- Cryptoasset ATM operators
- Issuers conducting in-scope activity connected to UK consumers
- Peer-to-peer platforms facilitating matched trading
Overseas firms are frequently caught out here. Marketing to UK residents, holding UK client funds, or operating UK-facing infrastructure can all trigger the "carried on in the UK" limb even where the parent entity sits abroad. If you serve UK consumers from an offshore base, treat that as a live registration question, not a technicality to defer.
How to apply: forms, business plan and documentary evidence
A complete FCA crypto registration application rests on documentary depth, and the FCA is explicit about what it expects to see before it will assess a filing as ready. Gaps here are the single biggest cause of delay.
- Application form and administrative documents. Corporate structure charts, ownership disclosures, and confirmation of the legal entity applying.
- A comprehensive business plan. Revenue model, target markets, volumes, third-party dependencies, and how the crypto activity fits the wider group.
- Governance evidence. Organisational charts, biographies of key individuals, and fit-and-proper documentation for directors, senior managers, and the MLRO.
- Operational evidence. AML/CTF policies, procedures, process maps, and technology specifications showing how controls actually run day to day, not just how they are described on paper.
Firms that already hold other FCA permissions sometimes assume existing AML infrastructure will suffice. It rarely does: assessors expect crypto-specific risk coverage layered onto whatever framework already exists, not a repackaged version of it. If your firm previously held e-money or payments permissions, budget time to rebuild the risk assessment around crypto-specific typologies rather than lifting it wholesale from an old application.
AML/CTF controls the FCA will assess
The FCA's AML/CTF review centres on whether your controls are proportionate, documented, and demonstrably operational. Four elements dominate the assessment:
- BWRA and CRA. The Business Wide Risk Assessment and Customer Risk Assessment need a clear methodology, defined risk factors, and evidence of how customers are scored and segmented, not a generic template.
- MLRO appointment. The Money Laundering Reporting Officer must show genuine seniority, relevant experience, and authority to escalate, with training records for wider staff.
- Transaction monitoring. Rules, thresholds, and blockchain analytics tooling need to be configured and tested, with a working SARs process behind them.
- Travel Rule compliance. Flow-of-funds diagrams and data-sharing arrangements between VASPs must show originator and beneficiary information moving correctly.
Calibrating monitoring thresholds against volume and risk, rather than applying a flat rule to every transaction, follows the FATF risk-based approach that international standards recommend for virtual assets.
Pro Tip: Submit configured transaction-monitoring rules and a flow-of-funds diagram with your initial filing rather than promising to build them post-approval. Assessors treat these as evidence the controls actually exist, and their presence tends to shorten the assessment window.
Timelines, fees and the FSMA gateway: making the timing choice

The FCA has set out transitional dates that firms need to plan around now, not later. Applications submitted after 30 September 2026 risk not being determined before the FSMA authorisation gateway opens, which pushes firms toward the new regime rather than MLR registration.
The new regime itself starts on 25 October 2027, and firms straddling both frameworks need to think about whether to pursue MLR registration as an interim step or wait and apply directly for FSMA authorisation once the gateway opens. Fee treatment differs between the two routes, and firms weighing both should model the regulated activities and conduct baseline set out in PS26/11 before committing resource to either path.
After registration: supervision, ongoing compliance and enforcement risk
Registration is the start of supervision, not the end of scrutiny. Firms carry ongoing obligations: periodic reporting, timely notification of material changes (new products, ownership changes, key personnel departures), and responsiveness to supervisory requests.

The FCA has also been clear that registration must never be presented as an endorsement of a firm's business model or products. Marketing language implying regulatory approval is itself a compliance risk. Weak monitoring, stale risk assessments, and unresponsive MLROs are the recurring enforcement triggers, and outcomes range from supervisory conditions through to registration refusal or removal for existing firms that let controls drift.
Common application pitfalls and a pre-submission checklist
Most refusals trace back to a handful of recurring deficiencies rather than uncommon legal issues:
- BWRA and CRA methodologies that read as generic rather than tailored to the firm's actual product mix
- Transaction monitoring thresholds set without reference to real volume or typology data
- An MLRO appointment that lacks demonstrable seniority or crypto-specific experience
- Missing or incomplete travel rule flow-of-funds diagrams
If your internal team lacks the bandwidth to build BWRA methodology, configure monitoring thresholds, or draft travel rule documentation from scratch, that is precisely the point to bring in specialist legal or technical support, before submission rather than after a deficiency letter arrives. Firms already navigating other frameworks may also find it useful to review UK crypto business rules alongside a practical AML compliance checklist and a broader cryptocurrency risk management checklist when calibrating monitoring thresholds.
How Cryptoverselawyers supports FCA registration applications
Cryptoverselawyers advises crypto and fintech businesses across multiple regulatory frameworks, including UK-facing engagements for firms navigating FCA registration. Typical mandates include drafting BWRA and CRA methodology, supporting MLRO appointment and fit-and-proper documentation, building travel rule flow-of-funds architecture, and managing the application project end to end.
Firms typically engage specialist support several months ahead of their intended filing date, since document preparation and internal control testing take longer than most compliance teams initially budget. Given the FSMA gateway timeline, that lead time now matters more than it has in previous cycles.
Board-level perspective: governance and readiness for FCA scrutiny
Boards too often treat FCA registration as a compliance-team task rather than a governance obligation the board itself must evidence. Assessors look for minuted board oversight of AML risk, not just a policy document. Three actions matter now: assign explicit board-level ownership of the BWRA, require quarterly reporting on monitoring effectiveness, and document MLRO independence in board minutes. Firms that can show this evidence tend to move through supervisory engagement faster and face materially lower enforcement exposure.
— CRYPTOVERSE
Get regulator-ready support for your FCA registration application
Cryptoverselawyers is the alternative to building an FCA registration application from scratch with a stretched internal team. Where a generalist firm might treat crypto AML as an afterthought bolted onto existing frameworks, our practice works exclusively across virtual asset regulation, which means the BWRA methodology, MLRO documentation, and travel rule architecture are built for crypto-specific risk from the outset, not retrofitted after a deficiency letter.
Our engagements typically cover business plan review, AML/CTF framework drafting, MLRO support, and full application project management, with the same regulatory depth we bring to clients navigating VARA, DFSA, and other frameworks across 30-plus jurisdictions. If your firm is weighing registration under the MLRs against the FSMA gateway timeline, get in touch to scope your application and confirm a realistic submission date before the window narrows further.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- Cryptoassets: How to apply for registration | FCA
- FATF guidance: Risk-based approach for virtual assets (2021)

