← Back to blog

Stablecoin regulation 2026: the UK compliance framework

July 25, 2026
Stablecoin regulation 2026: the UK compliance framework

The Financial Conduct Authority (FCA) and HM Treasury now hold direct regulatory authority over qualifying stablecoins used in UK retail payments, following amendments to the Financial Services and Markets Act 2000 (FSMA 2000) that took effect in 2026. The FCA's joint regulatory approach with the Bank of England establishes a dual-track regime: the FCA authorises and supervises stablecoin issuers and custodians, while the Bank of England retains oversight of systemic issuers whose failure could threaten financial stability. For compliance officers and general counsel, the practical effect is a licensing obligation that sits squarely within the existing authorised payments and e-money framework, with additional prudential, governance, and AML/CFT layers specific to digital assets.

Key compliance reference points for 2026:

  • Authorisation requirement: Any firm issuing a qualifying stablecoin or providing custody of qualifying stablecoins for use in UK retail payments must obtain FCA authorisation under the amended FSMA 2000 regime.
  • Transitional window: Final UK rule publications are expected within 2026 to early 2027, with transitional provisions allowing existing operators a defined adaptation period before full enforcement applies.
  • Systemic designation: Issuers reaching systemic scale face concurrent Bank of England supervision under the Financial Market Infrastructure regime.
  • Global alignment: The UK framework draws on FATF standards and is designed to interoperate with the EU's Markets in Crypto-Assets Regulation (MiCA) and, to a lesser extent, the US GENIUS Act.
  • AML/CFT obligations: Travel Rule compliance and transaction monitoring are mandatory from the point of authorisation, not deferred to a later phase.

1. UK regulatory mandate and licensable activities for stablecoins

The FCA's statutory remit over stablecoins derives from the FSMA 2000 as amended by the Financial Services and Markets Act 2023 and subsequent secondary legislation. The regime targets what the FCA designates as "qualifying stablecoins": fiat-referenced digital assets used as a means of payment or settlement within the UK. Algorithmic stablecoins and commodity-backed tokens fall outside this specific regime but may attract regulation under separate crypto asset or investment frameworks depending on their characteristics.

Licensable activities under the 2026 framework include:

  • Issuance of qualifying stablecoins to UK retail or institutional users.
  • Custody of qualifying stablecoins on behalf of third parties.
  • Facilitation of payments using qualifying stablecoins, including payment system participation.
  • Exchange services converting qualifying stablecoins to fiat or other digital assets where the stablecoin is the primary instrument.

Firms already authorised under the Payment Services Regulations 2017 or holding an e-money licence must apply for a variation of permission rather than a fresh authorisation, though the substantive requirements are equivalent. The FCA has confirmed that overseas issuers marketing qualifying stablecoins to UK users must either obtain UK authorisation or operate through an FCA-authorised distributor. Cross-border issuers should note that the "overseas persons" exemption available under certain FSMA 2000 provisions does not extend to retail-facing stablecoin activity.

Exemptions are narrow. Intra-group issuance for treasury management purposes and limited-network tokens used solely within a closed-loop system may qualify for exclusion, but the FCA has signalled it will apply these exclusions strictly. Any ambiguity should be resolved through a formal supervisory engagement before launch, not assumed.


2. Capital and prudential standards for stablecoin issuers in the UK

The FCA's prudential requirements for stablecoin issuers are modelled on the e-money institution framework but with material enhancements reflecting the systemic risk profile of large-scale stablecoin issuance.

Core capital and liquidity requirements:

  • Minimum own funds: Issuers must maintain own funds calculated as a percentage of the outstanding float, with the FCA applying a tiered approach based on issuance volume. The specific thresholds are set out in the FCA's Consultation Paper on the stablecoin regime and are subject to finalisation within the 2026 rulemaking cycle.
  • Reserve asset quality: Reserves backing qualifying stablecoins must be held in high-quality liquid assets, including central bank deposits, short-dated government securities, and money market instruments meeting FCA-specified credit and liquidity criteria. Rehypothecation of reserve assets is prohibited.
  • Same-day redemption: Issuers must maintain liquidity sufficient to honour same-day redemption requests at par value, with no gates or suspension mechanisms permitted for retail holders.
  • Capital buffers: A capital conservation buffer above the minimum own funds requirement is expected, calibrated to the issuer's operational risk profile and stress-tested against redemption scenarios.
  • Prudential modelling: The FCA expects issuers to conduct and document Internal Capital Adequacy Assessment Process (ICAAP)-equivalent exercises, covering credit risk on reserve assets, operational risk, and liquidity stress scenarios.

Systemic issuers designated by the Bank of England face additional requirements under the Financial Market Infrastructure regime, including recovery and resolution planning obligations. For non-systemic issuers, the FCA's supervisory expectations on capital modelling are nonetheless demanding: firms should anticipate detailed scrutiny of reserve composition, stress-testing methodology, and liquidity management frameworks during authorisation and ongoing supervision.

Pro Tip: Build your ICAAP-equivalent documentation before submitting your FCA authorisation application. Supervisors will request it early in the review process, and a well-constructed document signals operational maturity that accelerates approval timelines.

Hands reviewing regulatory capital standards document


3. What governance and control requirements apply under the UK framework?

Board-level accountability sits at the centre of the FCA's governance expectations for stablecoin issuers. The FCA's Senior Managers and Certification Regime (SM&CR) applies in full, meaning that specific individuals must be approved as Senior Managers with defined responsibilities for compliance, risk, and financial crime.

Required governance and control elements:

  • Senior Manager functions: A Chief Risk Officer (or equivalent) and a Money Laundering Reporting Officer (MLRO) must be FCA-approved individuals. The board must include at least one independent non-executive director with relevant financial services experience.
  • Risk committee: Issuers above a defined size threshold must establish a board-level risk committee with oversight of reserve management, operational risk, and AML/CFT programme effectiveness.
  • Internal controls framework: Written policies and procedures must cover reserve asset management, redemption processing, transaction monitoring, incident response, and outsourcing arrangements. These must be reviewed and approved by the board at least annually.
  • Segregation of client assets: Reserve assets backing client-held stablecoins must be held in segregated accounts, legally ring-fenced from the issuer's own assets. The FCA's Client Assets Sourcebook (CASS) principles apply by analogy, and issuers should structure their custody arrangements accordingly.
  • Disclosure obligations: Issuers must publish a white paper equivalent disclosing reserve composition, redemption terms, governance structure, and risk factors. Material changes require prior FCA notification and updated disclosure.
  • Regulatory reporting: Periodic returns to the FCA covering outstanding issuance, reserve asset composition, redemption volumes, and capital adequacy are mandatory. The FCA has indicated quarterly reporting as the baseline, with monthly reporting for systemic issuers.

Outsourcing arrangements, particularly for custody and technology infrastructure, require prior FCA notification and must comply with the FCA's operational resilience framework. Boards retain accountability for outsourced functions and cannot delegate regulatory responsibility to third-party providers.


4. AML/CFT and Travel Rule implications for stablecoin issuers in the UK

AML/CFT obligations represent the most operationally demanding aspect of the UK stablecoin compliance framework, and the area where enforcement risk is highest in the near term. The UK's Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLRs), as amended, apply to stablecoin issuers as a category of cryptoasset exchange provider and custodian wallet provider.

Core AML/CFT programme requirements:

  • Risk assessment: A documented firm-wide risk assessment covering customer types, geographies, transaction patterns, and product features is mandatory. This must be reviewed at least annually and updated following material changes to the business model.
  • MLRO designation: An FCA-approved MLRO must be appointed, with direct board access and sufficient resources to discharge the function effectively.
  • Customer due diligence (CDD): Enhanced due diligence applies to high-risk customers, politically exposed persons, and transactions above prescribed thresholds. Simplified CDD is not available for stablecoin issuance given the inherent anonymity risk.
  • Suspicious activity reporting: Issuers must file Suspicious Activity Reports (SARs) with the National Crime Agency (NCA) where suspicion of money laundering or terrorist financing arises. The consent regime under the Proceeds of Crime Act 2002 applies.
  • Travel Rule compliance: Under the UK's implementation of the Financial Action Task Force (FATF) Travel Rule, issuers must collect, verify, and transmit originator and beneficiary information for transfers above £1,000. Real-time transaction monitoring and customer identity verification are required to meet these obligations. The FCA expects issuers to have technical solutions in place at the point of authorisation, not as a post-authorisation remediation project.
  • Sanctions screening: All transactions must be screened against the UK Sanctions List maintained by the Office of Financial Sanctions Implementation (OFSI), as well as relevant UN and EU-derived designations retained in UK law post-Brexit.

The interaction between Travel Rule obligations and the pseudonymous nature of blockchain transactions creates genuine technical complexity. Issuers transacting with unhosted wallets must apply risk-based measures to identify the beneficial owner, and the FCA has indicated it will not accept blanket refusal to transact with unhosted wallets as a compliant approach.

Pro Tip: Engage a specialist Travel Rule compliance solution (such as those built to FATF Recommendation 16 standards) before your authorisation application. The FCA will ask for a detailed description of your transaction monitoring architecture, and a credible technical answer is a prerequisite for approval.


5. Technology and custody controls mandated for compliance

The FCA's technology and custody requirements for stablecoin issuers reflect both consumer protection objectives and the operational resilience standards that apply across regulated financial services.

Mandatory technology and custody controls:

  • Approved custody model: Reserve assets must be held through a custody arrangement that provides legal segregation, independent verification, and daily reconciliation. Issuers using third-party custodians must ensure those custodians are themselves FCA-authorised or operating under an equivalent overseas regime recognised by the FCA.
  • Reserve transparency: Issuers must publish monthly attestations of reserve composition, verified by an independent auditor. The FCA has indicated that real-time reserve dashboards, while not yet mandatory, will be expected as the market matures.
  • Redemption infrastructure: Technical systems must support same-day redemption at par for retail holders, with no single point of failure in the redemption process. Business continuity and disaster recovery plans must be tested at least annually.
  • Transaction record-keeping: Issuers must maintain immutable records of all issuance, redemption, and transfer transactions for a minimum of five years, in a format accessible to FCA supervisors on request.
  • Data security: Personal data processed in connection with CDD and Travel Rule compliance must be handled in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Data minimisation and purpose limitation principles apply.
  • Operational resilience: Issuers must identify their important business services, set impact tolerances for disruption, and demonstrate the ability to remain within those tolerances through scenario testing. The FCA's operational resilience policy statement sets the baseline standard.

Technology outsourcing to cloud providers or blockchain infrastructure vendors does not transfer regulatory responsibility. The board must satisfy itself that outsourced arrangements meet FCA standards, and material outsourcing agreements require prior notification to the regulator.


Professional using tablet with compliance checklist on desk

6. Enforcement exposure and penalty framework under UK stablecoin regulations

The FCA's enforcement powers in relation to stablecoin issuers are broad and, in practice, extend well beyond financial penalties. Compliance officers and boards should understand the full spectrum of supervisory tools available to the regulator.

FCA enforcement powers and mechanisms:

  • Licence revocation and variation: The FCA may cancel or vary an authorisation where a firm fails to meet threshold conditions, breaches regulatory requirements, or poses a risk to consumers or market integrity. This power can be exercised on an urgent basis without prior notice where consumer harm is imminent.
  • Financial penalties: The FCA's penalty framework applies a revenue-based calculation for serious breaches, with no statutory cap. Penalties for AML/CFT failures have historically been among the largest imposed by the FCA across all regulated sectors.
  • Public censure: Where a financial penalty is not appropriate, the FCA may issue a public statement of censure, which carries significant reputational consequences for licensed firms.
  • Skilled persons reviews: Under Section 166 of FSMA 2000, the FCA may require a firm to commission an independent review of its systems and controls at the firm's own expense. This is a frequently used supervisory tool in the early stages of a compliance concern.
  • Enforcement investigations: Formal investigations may be opened where the FCA suspects serious regulatory breaches, including AML/CFT failures, misleading disclosures, or unauthorised activity. Investigations carry significant management distraction and legal cost, irrespective of outcome.
  • Criminal prosecution: For the most serious offences, including operating without authorisation and deliberate AML/CFT failures, the FCA may refer matters to the Crown Prosecution Service or pursue prosecution directly under FSMA 2000 or the Proceeds of Crime Act 2002.

AML/CFT breaches attract the most severe enforcement outcomes. The FCA has consistently treated inadequate transaction monitoring, deficient CDD, and failure to file SARs as priority enforcement areas. Stablecoin issuers should anticipate that their AML/CFT frameworks will receive close scrutiny during both the authorisation process and ongoing supervision.


7. Practical structuring considerations for stablecoin issuance and compliance

Structuring decisions made at the outset of a stablecoin issuance project have long-term compliance and commercial consequences. The following considerations reflect the FCA's supervisory expectations and the practical realities of operating within the UK framework.

Entity structure and licensing pathway:

  • A UK-incorporated entity is required for direct FCA authorisation as a stablecoin issuer. Overseas entities may distribute qualifying stablecoins in the UK through an FCA-authorised entity, but the issuer itself must be authorised if it targets UK retail users directly.
  • Firms already holding an e-money licence or payment institution authorisation should apply for a variation of permission, which is typically faster than a fresh application but requires the same substantive compliance infrastructure.
  • For groups with existing regulated entities, consider whether the stablecoin issuance function should sit within the existing regulated entity or in a dedicated subsidiary. A dedicated subsidiary provides cleaner regulatory perimeter management but requires standalone capital and governance.

Capital and liquidity management:

  • Model your capital requirements against the FCA's tiered framework before launch. Undercapitalisation at authorisation is a common cause of application delay or rejection.
  • Reserve asset selection should prioritise FCA-eligible instruments from day one. Transitioning reserve assets post-authorisation to meet FCA standards creates operational risk and supervisory concern.

AML/CFT and technology integration:

  • Implement your AML/CFT programme, including Travel Rule solution, transaction monitoring system, and sanctions screening, before submitting your authorisation application. The FCA will conduct a detailed assessment of these systems as part of the review.
  • Engage your MLRO and compliance team in the product design process. AML/CFT controls are most effective, and least operationally disruptive, when built into the product architecture rather than retrofitted.

For firms considering multi-jurisdictional issuance, the UK crypto licensing decision tree provides a structured framework for mapping FCA authorisation requirements against other regulatory pathways. Understanding the interaction between UK authorisation and overseas licensing is particularly important for issuers targeting both UK and EU markets under MiCA.


8. How does UK stablecoin regulation compare globally in 2026?

The UK, US, and EU have each developed distinct but broadly convergent frameworks for stablecoin regulation in 2026. For UK-based issuers operating internationally, understanding the material differences is a prerequisite for cross-border compliance planning.

DimensionUK (FCA/HM Treasury)US (GENIUS Act)EU (MiCA)
Primary regulatorFCA, Bank of EnglandOCC, Federal Reserve, FDIC, state regulatorsNational competent authorities, EBA
Issuer authorisationFCA authorisation under amended FSMA 2000Federal or state licence as permitted payment stablecoin issuerAuthorisation as e-money institution or credit institution
Reserve requirementsHigh-quality liquid assets, no rehypothecation1:1 backing in approved assets, public disclosure1:1 backing, investment in secure low-risk assets
AML/CFTUK MLRs, FATF Travel Rule, OFSI sanctionsBank Secrecy Act, FinCEN/OFAC rulesAMLD6, Travel Rule, EU sanctions
Enforcement timelineAuthorisation required from 2026; transitional window to early 2027GENIUS Act enforcement begins 18 January 2027MiCA stablecoin provisions effective; full application ongoing
Yield prohibitionNot explicitly prohibited; subject to e-money rulesProhibited under GENIUS Act for payment stablecoinsProhibited for e-money tokens under MiCA
Cross-border accessOverseas issuers require UK authorisation or FCA-authorised distributorForeign issuers must register with OCC; state-level regimes available for issuers under $10bnPassporting available within EEA; third-country issuers face restrictions

Infographic comparing UK, US, and EU stablecoin regulations

The GENIUS Act, enacted on 18 July 2025, creates a federal payment stablecoin framework in the US mandating capital, liquidity, AML compliance, and licensing overseen by multiple agencies. Key implementing regulations missed the 18 July 2026 rulemaking deadline, compressing the industry's transition window ahead of the 18 January 2027 enforcement date. Practitioners advising US-facing issuers recommend aligning with the most stringent pending rules now rather than waiting for final text.

Under the GENIUS Act, state-level regimes are available to issuers with a consolidated total outstanding issuance of not more than $10,000,000,000, provided the state regime is substantially similar to the federal framework. Rigorous certification reviews apply, and the Secretary of the Treasury sets the principles for determining substantial similarity.

The EU's MiCA regulation classifies stablecoins as either asset-referenced tokens or e-money tokens, each with distinct capital, governance, and reserve requirements. UK issuers seeking EU market access post-Brexit must obtain separate MiCA authorisation; the UK regime does not provide passporting rights into the EEA. For a detailed analysis of the EU framework, the MiCA regulatory overview provides a practical reference point.

For UK businesses considering global issuance strategies, the multi-jurisdiction crypto regulation guide covers the interaction between UK, US, EU, and other major frameworks in detail. Understanding how cryptocurrency trading works within these regulatory parameters is also useful context for compliance teams new to digital asset markets.


The compliance imperative: a perspective from CRYPTOVERSE

The most common mistake we see in stablecoin compliance planning is treating the FCA authorisation process as the finish line rather than the starting point. Firms invest heavily in preparing their application, obtain authorisation, and then discover that the ongoing supervisory relationship demands a level of operational maturity that was not fully anticipated. The FCA's expectations on governance, capital modelling, and AML/CFT do not diminish after authorisation; they intensify as the regulator gains a clearer picture of the business.

The global regulatory convergence underway in 2026 creates both a challenge and an opportunity for UK-based issuers. The challenge is obvious: operating across UK, US, and EU jurisdictions requires compliance with three distinct but overlapping frameworks, each with its own supervisory culture and enforcement priorities. The opportunity is less frequently discussed. Firms that build their compliance infrastructure to the highest common standard across all three regimes, rather than calibrating separately to each, achieve a structural advantage. They spend less time on remediation, face fewer supervisory queries, and are better positioned to scale into new markets without rebuilding their compliance architecture from scratch.

Board engagement is the single most important variable in compliance outcomes. Stablecoin issuers where the board treats AML/CFT and prudential requirements as operational matters delegated entirely to the compliance function consistently underperform against supervisory expectations. The FCA's SM&CR framework is designed precisely to prevent this: it places personal accountability on named individuals and creates direct lines of responsibility that cannot be obscured by organisational complexity. Boards that engage substantively with their compliance obligations, ask hard questions of their compliance teams, and allocate adequate resources to AML/CFT infrastructure are the ones that avoid enforcement action.

The Travel Rule deserves particular attention. It is the area where the gap between regulatory expectation and operational reality remains widest across the industry. Many issuers have implemented transaction monitoring systems that satisfy the letter of the requirement for on-chain transfers between hosted wallets, but have not adequately addressed the unhosted wallet problem. The FCA has signalled that this gap will be a supervisory priority. Issuers that have not yet developed a documented, risk-based approach to unhosted wallet transactions should treat this as urgent.


Navigating the FCA's stablecoin authorisation process, building a compliant AML/CFT programme, and managing cross-border obligations under MiCA and the GENIUS Act simultaneously is a significant undertaking. Cryptoverselawyers provides end-to-end legal support for stablecoin issuers at every stage of that process, from pre-application regulatory mapping through to ongoing supervisory engagement and enforcement response.

Cryptoverselawyers

Cryptoverselawyers advises across the UK's FCA framework, the UAE's five crypto regulators (VARA, SCA, DFSA, FSRA, and CBUAE), and more than 30 jurisdictions worldwide. For issuers considering multi-jurisdictional structures, the firm's digital asset legal services cover the full lifecycle of a regulated stablecoin business, including entity structuring, governance framework design, AML/CTF policy drafting, and capital adequacy modelling. For those exploring UAE-based issuance as part of a global strategy, Cryptoverselawyers's VARA licensing advisory provides a direct route to one of the world's most developed virtual asset regulatory frameworks.

To discuss your stablecoin authorisation requirements or compliance framework, contact Cryptoverselawyers directly through the firm's website at cryptoverselawyers.io.