In the second of two articles exploring the UK’s cryotoasset market, Rohini Gupta, CEO of FinregE, examines prudential requirements, Consumer Duty, operational resilience, governance, redress and reporting.
(For the first article in this series please see here)
The application of Consumer Duty to cryptoasset enterprises is one of the most important aspects of the FCA’s regulation.
The FCA has clarified that the Duty will apply to all cryptoasset firms, with limited exceptions for Admissions and Disclosures operations and trading on a UK QCATP.
This presents a practical challenge. Cryptoasset products can be volatile, technically difficult, and rely on infrastructure that users may not completely comprehend. The FCA understands that businesses are not required to prevent all harm or remove all investment risk. Firms are expected to have a reasonable confidence that clients understand the risks associated with cryptoasset products and services.
Consumer Duty: Testing the customer journey, not just the product
Firms’ consumer duty readiness should therefore include:
- Testing customer understanding of important product risks.
- Avoid focusing too much on yield, price appreciation, or speculative rewards.
- Clarifying risks associated with custody, withdrawal, staking, and third-party transactions.
- Provide support during outages, wallet freezes, protocol upgrades, or market stress.
- Designing consumer journeys with suitable friction.
- Making it easier for customers to withdraw, transfer, complain, and seek assistance.
The FCA’s guidelines also emphasise the importance of distributors in achieving positive results, even where the cryptoasset producer is unregulated, unknown, or outside the scope of the Duty.
This is particularly relevant for cryptoasset platforms and intermediaries that make assets available to retail customers. The responsibility does not disappear because the token issuer is overseas, decentralised or difficult to identify.
Operational resilience becomes a crypto-specific control challenge
Cryptoasset firms are technology firms as much as financial services firms. That makes operational resilience a critical component of the new regime.
PS26/13 confirms that the FCA is expanding its operational resilience framework to include licensed cryptoasset firms. This covers expectations under SYSC 4, SYSC 7, SYSC 8, and SYSC 15A.
The FCA’s operational resilience guideline focuses on risks that are particularly relevant to cryptoasset enterprises, such as code vulnerabilities, private key security, validator risks, service disruptions, cyber risks, and new risks related to artificial intelligence and quantum computing.
Firms will need to identify their critical business services, map dependencies, and simulate severe but plausible disruption scenarios. The FCA’s guidelines provide examples of testing scenarios such as data corruption, wallet balance manipulation, key third-party outages, blockchain node service interruptions, hostile node activity, Oracle manipulation, insider threats, cyberattacks, and compounding disruption events.
This is not a paper exercise. Crypto enterprises will need to relate operational resilience to their actual technical architecture.
For example:
- What happens when a custodian or node provider fails?
- What happens when a smart contract vulnerability is exploited?
- What happens if a validator gets slashed?
- What happens if a wallet service is frozen due to market volatility?
- What happens if client transaction records get corrupted?
- What happens if a cyberattack and a third-party outage occur simultaneously?
Firms that can demonstrate resilience across people, processes, technology, third parties, data, and governance will outperform under the new regime.
International crypto firms need to treat UK access as a structural decision
The FCA has also issued guidance on its approach to multinational cryptoasset firms. The intention is that enterprises seeking FCA authorisation should conduct regulated cryptoasset activities through a UK legal entity. There are rare circumstances where the FCA believes it is appropriate for overseas cryptoasset firms servicing UK customers through a UK branch to be approved as a qualified cryptoasset trading platform operator, provided that the home regulator provides equal levels of regulatory protection and standards.
The guideline is applicable to firms that seek FSMA authorisation in the UK, including firms that are already licensed for non-crypto activity, crypto MLR-registered enterprises that are not yet FSMA-authorised, and firms who already serve UK consumers via the section 21 Gateway.
This has strategic consequences for global companies. UK market access is more than just a licensing issue. It might require considerations concerning entity structure, governance, supervision, operational content, branch models, and responsibility.
International enterprises should consequently start early. Waiting until the authorisation window closes may result in insufficient time to build and demonstrate an operational model that meets FCA requirements.
What firms should do now
The 2027 implementation timeline may appear distant, but the scale of change is significant. Firms should not wait until the regime is about to start before undertaking preparation activities.
The procedures listed below should be included in every practical preparedness programme.
- Confirm which actions are within scope.
Firms should compare their present and proposed cryptoasset operations to those regulated and designated under the regime. This should include running a cryptocurrency trading platform, acting as a principal or agent, arranging transactions, securing cryptoassets, issuing qualifying stablecoins, lending and borrowing, staking, public offers and admissions to trading and providing abroad services to UK consumers.
- Create an obligation inventory.
The FCA bundle is too huge for manual reading alone. Firms should organise their policy statements and recommendations into a systematic obligation inventory.
Each responsibility should be identified by its source document, rule or guidance reference, business activity, product or service, customer type, function owner, policy impact, control impact, evidence required and implementation deadline.
- Map obligations to policies, controls and owners
Once duties have been defined, they should be linked to internal governance. This includes policies and procedures, compliance monitoring, systems and controls, customer communications, risk assessments, operational resilience documentation, board and committee governance, senior management duties, reporting procedures, and audit evidence.
This is where many businesses will find gaps. Having a policy is not sufficient. The firm must demonstrate that the policy is implemented, owned, monitored and documented.
- Identify gaps in the operational model
A thorough gap analysis should include authorisation readiness, governance and SM&CR, Consumer Duty, admissions and disclosure processes, market abuse surveillance, stablecoin backing and redemption, custody and safeguarding, prudential resources, operational resilience, third-party risk, regulatory reporting, complaints and redress, record-keeping, and an audit trail.
- Create a 2026-2027 implementation roadmap.
The implementation strategy should not be a general compliance project plan. It should be organised by regulatory dependency.
A QCATP, for example, may be required to prioritise activity and perimeter analysis, authorisation structure, admission rulebook and due diligence process, QCDD workflow, market abuse controls, operational resilience mapping, Consumer Duty customer journey review, prudential assessment, reporting and evidence framework and board sign-off and implementation assurance.
The real challenge: connecting regulatory change to operational execution
The FCA cryptoasset regime is difficult because it encompasses regulatory disciplines that have traditionally been dealt individually.
Consumer duty is intrinsically connected with admissions and disclosures. Controls against market abuse are inextricably linked to surveillance technology. Disclosures about stablecoins are inextricably linked to their backing assets and redemption processes. Prudential requirements cannot be divorced from operational resilience or third-party risk. International company authorisation is inextricably linked to legal entity structure and supervisory access.
This is why organisations require an integrated regulatory change strategy.
Firms who just read FCA documents will not succeed. They will be capable of translating those documents into:
- Structured obligations.
- Accountable owners.
- Mapped controls.
- Changes in business procedures.
- Evidence packs.
- Implementation dashboards.
- Board-level oversight.
This is the distinction between regulatory awareness and regulatory readiness.
Conclusion: 2027 is closer than it looks
The FCA’s cryptoasset regime is a turning point for the UK market. Crypto enterprises would be expected to provide more transparent disclosures, greater governance, better client results, robust prudential resources, effective operational resilience, and credible evidence of compliance.
A clear regulatory framework can help to build trust, ensure market integrity, and promote responsible innovation. However, the implementation burden should not be underestimated.
Firms should make good use of the period before October 2027. The firms that start now, comprehend the interconnectedness of the FCA’s policy package, and establish a regulatory operating model that can withstand authorisation, supervision, and market stress will be the best prepared.
The future of UK cryptocurrency compliance will not be determined by whether corporations read the new guidelines. It will be determined by whether they can demonstrate that they are prepared to work under them.
The 2027 deadline may appear far off, but preparation begins today.
How FinregE can help
While the initial phase of FCA cryptoasset compliance demands careful attention to regulatory publications and guidance, the real challenge lies in maintaining momentum beyond implementation. This is where FinregE transforms from a compliance tool into a strategic advantage.
From Regulatory Noise to Actionable Intelligence
Rather than manually tracking scattered policy documents across your organisation, FinregE creates a centralised hub that converts regulatory updates into clear, assignable tasks. The platform bridges the gap between understanding what the FCA requires and actually executing those requirements across your business.
FinregE supports your organisation by:
- Tracking regulatory evolution – Stay ahead of FCA publications and understand their relevance to your specific business model
- Connecting obligations to operations – Link PS26/9 through PS26/13 requirements directly to your internal policies, controls, and risk management systems
- Distributing accountability – Assign clear ownership across compliance, legal, risk, operations, technology, and executive leadership
- Documenting your compliance journey – Create an auditable record of interpretations, decisions, and remediation steps
- Measuring progress – Track implementation milestones as you work toward the 2027 regime expansion
Beyond One-Time Compliance
The FCA’s cryptoasset framework represents the foundation of an evolving UK digital asset regulatory environment, not a single compliance checkpoint. Organisations need infrastructure that adapts to continuous regulatory change.
FinregE positions firms to not only meet current requirements but to build the operational resilience needed for whatever comes next in the maturing cryptocurrency regulatory landscape.
Book a demo to discover how FinregE converts complex regulatory updates into structured obligations, mapped controls, and verifiable implementation records.


