Summary
FCA registration under the MLRs does not become Part 4A permission. It supplies no statutory conversion, grandfathering right, or presumption of approval. Financial Services and Markets Act 2000, ss 19, 55A, 55E and 55L; Money Laundering Regulations 2017, regs 54 and 58A.
An MLR-only firm must apply for authorisation. A firm already authorised under FSMA must apply to vary its permission. Financial Services and Markets Act 2000, ss 55A, 55H and 55U.
The firm must map its actual services to each new regulated cryptoasset activity. Its present MLR category does not settle that scope. Financial Services and Markets Act 2000 (Regulated Activities) Order 2001, Part 2, Chapter 2B.
The FCA expects the application period to open on 30 September 2026 and to close on 28 February 2027. A complete application inside that period gives the strongest statutory continuity position. FCA direction under SI 2026/102, reg 52.
A qualifying in-window applicant may continue while its application stays undetermined, or while a refusal stays open to review. The saving also covers any overseas person in the applicant's group. SI 2026/102, reg 53(1) and (2).
The saving is not authorisation, guarantees no approval, and ends two years after the full commencement day. The FCA may direct a qualifying firm into the restricted transition instead. SI 2026/102, regs 53(1)(c), 53(3) and 55(3).
Three groups enter the restricted transition: a late applicant still undetermined at commencement, an applicant that withdraws before commencement, and an in-window applicant whose refusal is closed to review. Each may perform pre-existing contracts only. SI 2026/102, regs 55, 56 and 60.
A firm without a valid application before commencement receives no saving and no transition. It must complete its UK run-off before 25 October 2027. Financial Services and Markets Act 2000, ss 19, 20 and 23; SI 2026/102, Part 7.
The FCA does not plan to extend Financial Services Compensation Scheme cover to the new cryptoasset activities, although complaints handling and Financial Ombudsman Service access apply. Customer disclosures must state that position. FCA PS26/13.
The board should treat this as a new full-scope authorisation project. The critical work is permission mapping, Threshold Conditions evidence, rulebook implementation, filing quality, and a funded run-off plan.
MLR registration does not convert into Part 4A permission
MLR registration and FSMA authorisation arise under different statutes and serve different purposes.
An MLR-registered cryptoasset exchange provider or custodian wallet provider has passed the registration test under the Money Laundering Regulations 2017. That status satisfies the MLR registration condition for the MLR-defined business, subject to anti-money-laundering supervision. It does not make the firm an authorised person under FSMA.
FSMA section 19 prohibits an unauthorised person from carrying on a regulated activity in the United Kingdom unless an exemption applies. Part 4A supplies the route to permission. An MLR-only firm must apply under section 55A and provide the information required by section 55U. The FCA specifies the regulated activities covered by permission under section 55E. It may impose requirements under section 55L.
The Cryptoassets Regulations add cryptoasset activities to the Regulated Activities Order. They do not deem MLR-registered firms authorised. They also contain no conversion mechanism for an MLR registration. The FCA's gateway notice therefore confirms the statutory position rather than creating it. Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, SI 2026/102, reg 40(5); FCA, Cryptoassets: How the gateway will operate, updated 8 July 2026.
A firm already authorised under FSMA stands differently. It remains authorised, but its existing permission does not expand automatically. It must seek a variation under section 55H for each new cryptoasset activity.
MLR history is relevant evidence
The FCA may use a firm's operating history and MLR controls when assessing a Part 4A application. That evidence can support the financial-crime, controller, management, and systems sections of the application.
The evidential value depends on actual performance. A registration entry alone proves neither effective operation nor present compliance. Open remediation, weak transaction monitoring, late reporting, poor sanctions controls, or incomplete customer files may instead damage the application.
The Part 4A test is wider than the MLR registration test. The FCA must assess the applicable Threshold Conditions. These cover the location of offices, effective supervision, appropriate resources, suitability, and the business model. Financial Services and Markets Act 2000, s 55B and Sch 6, paras 2B to 2F.
The firm must also show that it can comply from authorisation. Future promises will carry less weight than implemented controls, tested systems, named owners, funded resources, and board-approved evidence.
Until commencement, an in-scope firm must retain its MLR registration and comply with the MLRs. The FCA will assess overlapping MLR and FSMA applications separately.
MLR duties do not simply disappear at commencement. A firm authorised for the new activities will generally fall outside the separate cryptoasset registration requirement and must instead inform the FCA. Other firms may remain subject to MLR registration. Money Laundering Regulations 2017, regs 56 and 56B, as amended by SI 2026/102, reg 48. The FCA maintains the cryptoasset register under regulation 54(1A). The firm should therefore run the MLR and FSMA workstreams together.
The permissions map determines the application
The new activities cover distinct functions. They include issuing a qualifying stablecoin in the United Kingdom; safeguarding qualifying cryptoassets and relevant specified investment cryptoassets; arranging safeguarding; operating a qualifying cryptoasset trading platform; dealing as principal; dealing as agent; arranging deals; making arrangements with a view to transactions; and qualifying cryptoasset staking. Regulated Activities Order 2001, Part 2, Chapter 2B, inserted by SI 2026/102, reg 40(5). The Regulations cross-refer to article 9N for safeguarding and article 9Z6 for qualifying cryptoasset staking.
The legal analysis must follow the service, asset, contract, and customer journey. It should not follow product labels or the current MLR registration description.
The firm should map each activity by legal entity. It should record who contracts, holds keys, controls wallets, routes orders, sets prices, executes trades, selects validators, receives rewards, and carries customer money. Outsourcing does not necessarily remove the applicant's regulated role.
The map must also test territorial scope. The new activities can capture services conducted in or to the United Kingdom. An overseas group should identify the UK-facing entity, branch, personnel, customer route, website, marketing flow, and operational location.
Token classification needs a separate file. A token may be a qualifying cryptoasset, qualifying stablecoin, relevant specified investment cryptoasset, electronic money, or another specified investment. One token can trigger different rules across issuance, trading, custody, payments, and promotions.
The output should be a permissions schedule. It should link every service to the proposed permission, exclusion, limitation, customer type, asset type, and legal entity. The regulatory business plan, contracts, policies, forecasts, and website must tell the same story. The section 21 financial-promotion route needs a separate transition plan.
Application timing controls business continuity
Application during the FCA window
The FCA expects the application period to open on 30 September 2026 and to close on 28 February 2027. Its published direction under regulation 52 sets that period. Filing early inside the period is the prudent course.
Regulation 53 supplies a saving for an applicant that filed during the period. It applies where the FCA has not determined the application, or has refused it and the refusal remains open to review. For that applicant, Parts 3 to 6 of the Cryptoassets Regulations are treated as not having come into force, for the activity to which the application relates. The saving extends to any overseas person in the same group as the applicant. SI 2026/102, reg 53(1) and (2).
The saving permits continuity while the FCA or Upper Tribunal process remains live. It is not Part 4A permission. The firm must not describe itself as authorised for the new activities.
Unlike the restricted transition, regulation 53 does not confine the firm to pre-existing contracts. The saving stops at the end of two years beginning with the full commencement day. SI 2026/102, reg 53(3).
The saving does not apply to a firm the FCA has directed into the transition under regulation 55(3). The FCA may give that direction where an application has been refused but remains open to review. It must also consider the direction necessary for one of three purposes: the prevention, detection, investigation or prosecution of a criminal offence, the protection of consumers, or the advancement of its objectives. SI 2026/102, regs 53(1)(c) and 55(3).
The filing must be valid. A rushed shell submission may be rejected for missing minimum information. A rejected submission, without a later valid filing, is treated as no application for transition purposes.
A firm using the saving must notify the FCA as soon as reasonably practicable after the full commencement day. It must notify the FCA again when it stops using the saving. SI 2026/102, reg 54.
Application after 28 February 2027 but before commencement
A firm may apply after the window closes. The FCA need not expedite the case because it was filed late.
If the FCA has not granted the required permission by 25 October 2027, the firm enters the statutory transition by operation of law, if it meets regulation 55. The transition is a run-off mechanism, not a late filing grace period for ordinary business.
The exemption applies only so far as necessary to perform contracts made before entry into transition. The firm cannot enter new contracts with existing UK customers. It cannot onboard new UK customers. Its financial promotions must be limited to those necessary for pre-existing contracts. SI 2026/102, regs 56 and 60.
The transition lasts no more than two years. The FCA may narrow its scope, impose conditions, cancel it, require information, publish information, and issue a public censure. SI 2026/102, regs 59, 61, 62 and 63. The firm must notify the FCA and each party to a pre-existing contract. The notice must state that the firm is not authorised. It must also state whether asset protection, dispute resolution, or compensation cover has materially changed. SI 2026/102, regs 57 and 58.
Refusal or withdrawal by an in-window applicant
The restricted transition is not confined to late filers. A firm that applied during the period also enters it where the application is no longer open to review before commencement. The same applies where the firm withdraws the application before commencement. The same pre-existing-contract limit then applies. That route gives an unsuccessful in-window applicant an orderly two-year exit rather than an immediate stop.
No valid application before 25 October 2027
A firm that does not submit a valid application before commencement has no saving and no transition. It must finish its UK run-off before the new activities commence.
Continued business by an MLR-only firm would engage FSMA section 19. A contravention can constitute the section 23 offence. An already authorised firm that acts outside its permission breaches section 20 and faces the consequences available under FSMA.
The practical cut-off must precede 25 October 2027. Contract termination, asset return, complaints, records, customer notices, vendor exit, and financial-promotion withdrawal require lead time. A plan that starts on commencement is already late.
The FSMA gateway tests more than financial crime controls
The FCA will assess the whole applicant. MLR controls address only part of that assessment.
Core requirements include the Threshold Conditions, Principles for Businesses, senior manager accountability, systems and controls, conduct rules, customer treatment, complaints, operational resilience, financial crime controls, and prudential resources. The final cryptoasset materials also apply the Consumer Duty where its scope is met. FCA PS26/12, PS26/13 and FG26/5 to FG26/7.
The rules sit in named sourcebooks. Conduct of the new activities runs through the Cryptoasset sourcebook, CRYPTO 2 for stablecoin issuers and CRYPTO 5 to CRYPTO 10 for other regulated cryptoasset activities. Safeguarding of stablecoin backing assets runs through CASS 16, and safeguarding by cryptoasset custodians through CASS 17. Prudential duties run through COREPRU and CRYPTOPRU. Cross-cutting duties come through COBS, DISP, SYSC, SUP and the Senior Managers and Certification Regime. FCA PS26/10, PS26/11, PS26/12 and PS26/13.
Activity-specific duties add further work. Custodians must address client cryptoasset records, ownership, reconciliation, key control, and applicable client-money rules. Trading venues and intermediaries need order handling, execution, conflicts, disclosures, admissions, and market-abuse controls. Staking, lending, and borrowing services require tailored contracts, consent, disclosures, records, and customer protections. Stablecoin issuers face backing-asset, safeguarding, redemption, and disclosure rules. FCA PS26/9 to PS26/11.
Consumer protection has a stated limit. The FCA does not plan to extend Financial Services Compensation Scheme cover to the new regulated cryptoasset activities, while complaints handling and Financial Ombudsman Service access do apply. FCA PS26/13. Customer terms, disclosures, and promotions must state that position accurately, and the transition notice to contract parties must address it.
The application must show that each control works within the applicant entity. Group policies help only where the entity has authority, resources, data access, and tested oversight.
Immediate preparation priorities
Fix the applicant and perimeter
Confirm the applicant legal entity, UK establishment, group dependencies, controllers, close links, and current permissions. Complete a written perimeter opinion for every product and transaction flow. Reconcile that opinion with the MLR scope and financial-promotion route.
Build the permission and requirements schedule
List each requested activity, asset class, customer type, territorial limit, exclusion, and proposed limitation. Identify permissions that should not be requested. Overbroad applications can expose weak capability. Narrow applications can leave core revenue outside permission.
Prove the Threshold Conditions
Prepare current evidence for resources, liquidity, capital, staffing, senior manager competence, outsourcing, audit, technology, data, incident response, complaints, and wind-down. Link each document to a named Threshold Condition and FCA rule.
Financial forecasts should match the legal perimeter and operating plan. They should show authorisation costs, prudential resources, stress assumptions, group funding terms, and run-off funding.
Close the rulebook gaps
Compare current controls with CRYPTO, CASS 16, CASS 17, COREPRU, CRYPTOPRU, and the Handbook provisions applied by PS26/13, together with FG26/5 to FG26/7. Give priority to customer outcomes, Consumer Duty, operational resilience, prudential calculations, client assets, market conduct, senior manager accountability, and regulatory reporting.
Each gap needs an owner, budget, completion date, testing record, and board decision. Material controls should operate before filing where practicable.
Assemble a consistent evidence pack
The FCA's application materials cover the regulatory business plan, permissions, senior managers, controllers, close links, organisation, forecasts, technology, financial crime, compliance monitoring, complaints, promotions, and cryptoasset records. Activity modules add custody, stablecoin, staking, trading, and intermediary questions. The FCA published an information document on the application form and an updated financial data template on 8 July 2026. It stated that the form wording was still being finalised.
The evidence must be internally consistent. Revenue should follow the requested permissions. Contracts should match the stated customer journey. Wallet architecture should match custody analysis. Outsourcing agreements should support the claimed control model.
Use the FCA's PASS process only with a developed permissions analysis and supporting material. The FCA rejects meeting requests that carry no meaningful supporting information. PASS is optional and free. It provides no advice, safe harbour, or approval signal.
Maintain a parallel exit plan
The board should approve a funded run-off plan even where authorisation remains the objective. The plan should state trigger dates for closing products, stopping onboarding, restricting promotions, returning assets, terminating contracts, preserving records, and notifying customers.
A timely application reduces continuity risk. It does not remove refusal risk. The firm should set internal decision dates well before the statutory dates.
Principal contrary arguments
- Prior MLR scrutiny does not create a right to conversion. Parliament created a separate Part 4A process and separate continuation provisions.
- A timely filing does not amount to authorisation. It preserves a statutory position while the decision remains unresolved. The FCA can still refuse, impose requirements, or direct transition where the legislation permits.
- A late filing does not preserve ordinary growth. If unresolved at commencement, it supports pre-existing contract run-off only.
- An in-window refusal is not an immediate cliff. Once the refusal is no longer open to review, the firm moves into the restricted transition and runs off over a maximum of two years. That is an exit route, not a trading position.
- A PASS meeting does not bind the FCA. The FCA does not provide legal advice through PASS and requires meaningful preparation before engagement.
- MLR registration may improve the evidence base. It may also expose a poor compliance history. The result turns on the quality of current controls and the full FSMA case.
Open Questions
Each entry states how the answer could change the result and the next record needed.
- Applicant entity and territorial facts. Confirm which entity contracts with UK customers, carries the activity, employs decision-makers, controls technology, and holds assets. A different entity may require a different application or permission set. The reg 53(2) group extension makes the group chart directly relevant to continuity.
- Article-level perimeter under RAO Chapter 2B. Confirm each activity against the article numbers in the Regulated Activities Order as amended. Article 9N for safeguarding and article 9Z6 for staking are confirmed from the SI's own cross-references. The article numbers for issuing qualifying stablecoin, arranging safeguarding, operating a trading platform, dealing, and arranging deals changed between the 2025 draft order and the made instrument and were not opened article by article in this pass.
- MLR reg 14A and the commencement of reg 56B. Confirm the definitional provision for cryptoasset exchange providers and custodian wallet providers, and confirm when the amendments made by SI 2026/102, reg 48 take effect. Whether the firm must keep, surrender, or convert its MLR position depends on that timing.
- Product-by-product perimeter. Classify every token and service under Chapter 2B, existing specified-investment provisions, electronic-money law, payments law, and the financial-promotion rules. The result can change the permission request and the applicant.
- Current FCA record. Review MLR assessments, supervisory letters, data requests, breach logs, remediation, suspicious-activity reporting controls, sanctions testing, and financial-promotion history. Adverse history can affect suitability.
- Controllers, close links, and senior managers. Confirm ownership, voting rights, influence, group funding, overseas supervision, individual roles, fitness, time commitment, and regulatory references.
- Custody and money flows. Obtain wallet diagrams, key-control procedures, title analysis, reconciliation design, insolvency analysis, settlement-float treatment, and client-money flows. These facts control CASS 17 scope and any CASS 16 stablecoin obligations.
- Prudential model. Calculate the applicable permanent minimum, fixed-overhead, K-factor, liquid-asset, concentration, and wind-down needs under PS26/12, COREPRU and CRYPTOPRU. Group capital is not automatically applicant capital.
- Application-form release. The FCA's 2026-07-08 page published an application-form information document and an updated financial data template, and stated that question wording was still being finalised. Recheck the form, template, fees, directions, and notification mechanics when the gateway opens on 2026-09-30.
- Pending perimeter amendments. HM Treasury published a draft amending statutory instrument in April 2026, covering stablecoin payments, lending and borrowing involving UK qualifying stablecoin, and competitiveness changes. It was not treated as enacted law in Part I. Recheck the enacted text before finalising any stablecoin permissions opinion.
- Pending FCA work. Further consultation is expected on financial crime through the Financial Crime Guide, on resolution of cryptoasset custodians, and on DeFi. Two prudential guidance consultations closed for feedback on 2026-07-30. Any of these can change implementation detail before 2027.
- Exit feasibility. Quantify the time needed to stop onboarding, restrict promotions, terminate contracts, return assets, transfer custody, resolve complaints, preserve records, and finance run-off.
- Continuation eligibility. Confirm that the firm's actual pre-commencement activities, application status, and submission quality satisfy the exact Part 7 conditions. MLR registration alone does not establish eligibility.
