In the first of two articles exploring the UK’s cryotoasset market, Rohini Gupta, CEO of FinregE analyses the five pillars of the comprehensive framework.
The UK cryptoasset market is entering a new era of regulatory maturity. The Financial Conduct Authority (FCA) has issued its policy statements for the cryptoasset regime, moving the sector towards a comprehensive framework for admissions, disclosures, market abuse, stablecoin issuance and regulated cryptoasset activities.
This is not another regulatory update for crypto companies. This is a change in the way cryptoasset businesses will be authorised, supervised and required to operate in the UK.
The FCA says the package is part of the UK’s Cryptoasset Roadmap and that the regime will have clear and predictable rules across the full range of regulated cryptoasset activities. The Cryptoassets Regulations for the first time bring a broad range of cryptoasset activities within the FCA’s regulatory perimeter (rather than the anti-money laundering and financial promotions standards that have previously defined the FCA’s role in the market). The full scope of regulated activities is expected to expand from 25 October 2027, and this will provide firms with a clear period of time to prepare.
The message to firms is clear: crypto compliance can no longer be simply a narrow registration, marketing or financial crime play. The new regime will require a complete regulatory operating model.
From crypto registration to regulatory accountability
So far, many crypto firms have focused on a relatively narrow range of UK regulatory touchpoints like anti-money laundering registration, financial promotions compliance and consumer risk warnings. All that is changed by the new regime.
The FCA’s policy package sets out a wider regulatory architecture. This includes who is able to operate, what activities are regulated, how assets are admitted to trading, how stablecoins are issued and backed, how firms should manage capital and liquidity and how firms should demonstrate good customer outcomes, resilience and governance.
So, the compliance question is changing for crypto firms. The question has shifted from: ‘Can we deliver this cryptoasset service in the UK?’
The better question now is ‘Can we evidence that our governance, systems, disclosures, prudential resources, customer protections and operational controls are meeting FCA expectations on an ongoing basis?’
That is a very different test. It takes firms from perimeter analysis to operating model readiness.
The FCA cryptoasset regime is built around interconnected obligations
Taking each FCA policy statement in isolation would be a mistake. In practice, the documents are indeed tightly coupled.
The FCA policy statements are relevant to firms which carry on, or seek to carry on, one or more regulated cryptoasset activities or designated activities under the Cryptoassets Regulations. This includes firms that are registered under the Money Laundering Regulations, firms that are subject to the Financial Promotions regime, firms that deal with qualifying stablecoins or qualifying cryptoassets, overseas firms that want to provide services to UK consumers and traditional finance firms that are thinking about entering the cryptoasset markets.
The package includes five core policy statements:
In addition, the FCA has published guidance on Consumer Duty, operational resilience and international cryptoasset firms, which we will discuss in our second article on the topic.
This interconnectedness matters. A cryptoasset trading platform may need to consider admissions and disclosures, market abuse controls, Consumer Duty, operational resilience, safeguarding, prudential requirements, reporting and international firm expectations at the same time.
The practical problem, then, is not simply to understand each rule. It’s knowing how the rules interrelate across the business.
Key consultation papers behind the package include:
- CP25/14, CP25/40 and CP26/4, which underpin the regulated cryptoasset activities framework in PS26/11.
- CP25/41, which underpins admissions, disclosures and the Market Abuse Regime for Cryptoassets in PS26/9 and is also relevant to stablecoin issuance in PS26/10.
- CP25/15 and CP25/42, which underpin the prudential regime in PS26/12, including COREPRU, CRYPTOPRU and the overall risk assessment.
- CP25/25 and CP26/4, which underpin the application of the FCA Handbook to regulated cryptoasset activities in PS26/13, including Consumer Duty, SYSC, SM&CR, CASS, DISP and regulatory reporting.
This raises a crucial implementation lesson: enterprises should not base their 2027 preparation programme solely on final policy announcements. They should also read the consultation documents to better understand the FCA’s policy rationale, respondent feedback, and areas where final rules were revised. This background can help businesses make better decisions when applying the rules to complex or new cryptoasset business models.
The five pillars of the FCA cryptoasset regime
PS26/9 establishes final guidelines for admissions and disclosures, as well as a market abuse regime for cryptoassets. The guidelines aim to promote market integrity, increase transparency, and strengthen consumer protection while recognising the nature and risks of cryptoasset markets.
The role of UK qualifying cryptocurrency trading platforms (UK QCATPs) has shifted significantly. Retail UK QCATPs will serve as gatekeepers for trading admissions. Before a qualifying cryptoasset, other than a UK-issued qualifying stablecoin, is admitted to trading, retail UK QCATPs must conduct due diligence and ensure that a qualifying cryptoasset disclosure document is published and uploaded to the FCA-owned centralised repository, subject to certain exceptions.
This is a significant regulatory development. Trading platforms won’t just list assets. They will be required to demonstrate established admission procedures, due diligence, disclosure review, and information accessibility.
The market abuse regime is similarly significant. Market Abuse Regime for Cryptoassets (MARC) will prohibit insider trading, illegal disclosure of inside information, and market manipulation. It will also impose proportionate system and control requirements on UK QCATPs and intermediates, with additional obligations for big UK QCATPs, such as on-chain monitoring and cross-platform information exchange.
The thought-leadership point is that cryptocurrency trading platforms are increasingly taking on the role of regulated market infrastructure. The FCA is pushing platforms not only to enable access to cryptoassets, but also to assist defend market integrity.
Stablecoins are at the heart of the UK’s digital asset objectives. However, stablecoins can only serve as trustworthy instruments if users believe in their backing, redemption, security, and disclosure.
PS26/10 establishes final standards for non-systemic UK-issued qualified stablecoins, including issuance, backing assets, redemption, safeguarding, and disclosure. According to the FCA, these guidelines are meant to establish a reasonable baseline for stablecoin supply while also promoting stability, consumer confidence, and market integrity.
The final framework has several significant modifications. The FCA has simplified the backing asset composition requirement, confirmed statutory trust arrangements for backing assets, removed unallocated backing fund accounts, adjusted redemption timelines so that KYC checks are completed before the redemption period begins, allowed limited intragroup custody subject to safeguards, allowed a 5% excess in the backing asset pool, clarified redemption requirements in the secondary market, and strengthened access to historical disc
This demonstrates that the FCA’s approach is more than just limiting risk. It is about establishing trust via proof.
Stablecoin issuers must demonstrate trust in the following ways:
- Ensure transparent asset backing mechanisms.
- Robust safeguarding controls.
- Provide accurate and accessible disclosures.
- Effective redemption mechanisms.
- Effective reconciliation and record-keeping.
- Establish accountability for third-party dependencies.
PS26/11 establishes final rules and advice for regulated cryptoasset operations as specified by the Regulated activities Order. These include running a qualifying cryptoasset trading platform, dealing, arranging, lending and borrowing, staking, safekeeping, and the FCA’s current stance on decentralised finance.
The FCA has maintained the general framework while making specific changes and offering further guidance. Principal dealers, for example, are no longer required to disclose information prior to trading. The FCA has further defined expectations for optimal execution, stating that firms should check pricing from at least three credible UK licensed execution venues whenever practicable, without needing mechanical transaction-by-transaction checks if overall procedures are successful.
The regime includes retail protections, changes to collateral and auto-staking restrictions, and record-keeping requirements for lending, borrowing, and staking. The safeguarding obligations under CASS 17 will apply, with amendments to reflect cryptoasset custody. The FCA intends to proceed with Decentralised Finance (DeFi) on the assumption that regulations apply where there is an identifiable controlling entity, with further guidance to come on how decentralisation would be assessed.
Firms must take extra precautions in this area. Business models in crypto are frequently modular. A single customer journey can include trading, custody, staking, lending, liquidity routing, third-party wallets, and international infrastructure. Each activity may raise various regulatory expectations.
A corporation cannot assess readiness solely at the entity level. It must assess readiness at activity, product, service and customer journey level.
The prudential regime is one of the most essential components of the FCA’s package since it places financial resilience at the centre of cryptocurrency regulation.
PS26/12 establishes the final prudential framework for regulated cryptoasset enterprises, including capital, liquidity, risk management, and public disclosure obligations. The framework is intended to offer a strong and proportionate prudential foundation for enterprises engaged in regulated cryptoasset activities.
Who are CRYPTOPRU firms?
The prudential regime introduces CRYPTOPRU, a cryptoasset-specific prudential handbook. COREPRU specifies basic prudential standards that apply to all FCA regulatory regimes, whereas CRYPTOPRU specifies sector-specific criteria for enterprises conducting regulated cryptoasset operations. In practice, a CRYPTOPRU firm is one that falls under the cryptoasset prudential regime and must consider both COREPRU and CRYPTOPRU when assessing capital, liquidity, concentration risk, disclosure, and overall risk assessment duties.
This is significant since many cryptocurrency enterprises have never functioned under a prudential environment of this nature. The FCA’s guideline on CRYPTOPRU 7 emphasises that the overall risk assessment is not meant to be a one-time document. It is a continual process in which organisations evaluate their risk appetite, risk mitigation, own funds, liquid assets, stress scenarios, recovery steps, and wind-down plans.
For CRYPTOPRU businesses, the practical difficulty will be to connect prudential analysis to operational reality. Custody models, technical dependencies, customer withdrawal behaviour, staking or validator risk, market volatility, outsourcing, cyber risk, and extreme yet believable stress scenarios must all be considered when assessing capital and liquidity.
Why MIFIDPRU firms also need to pay attention
The regime also affects enterprises that are already subject to MIFIDPRU. According to PS26/12, the FCA has modified MIFIDPRU to address the interaction with CRYPTOPRU on own funds and own funds requirement elements. It further states that if a company is licensed under both CRYPTOPRU and MIFIDPRU, it must adhere to both regimes.
This means that investment firms entering cryptoasset markets shouldn’t presume that their existing MIFIDPRU framework will automatically address the new cryptoasset prudential standards. They will need to determine where existing governance, capital planning, ICARA-style processes, liquidity monitoring, concentration risk processes, and transparency arrangements may be reused and where CRYPTOPRU necessitates extra crypto-specific analysis.
This is especially important for traditional financial institutions entering into cryptocurrency services. Their challenge may not be to create prudential governance from scratch, but rather to apply existing prudential disciplines to a new risk profile: cryptoasset volatility, custody and safeguarding, smart contract and private key risks, validator exposures, digital infrastructure dependencies, and market abuse surveillance.
The FCA has conducted targeted recalibrations to improve proportionality and usability. These include lowering the operational risk K-factor capital need for stablecoin issuance from 2% to 1%, simplifying the market risk framework, and implementing a more proportional public disclosure regime.
Under the updated market risk framework, cryptoassets that can be prudently priced and admitted to a UK qualified cryptoasset trading platform would face a single 40% net risk position requirement for K-NCP (net cryptoasset position) and a 40% volatility adjustment for K-CCD (counterparty credit default). Cryptoassets that do not fulfil these requirements are withdrawn from regulatory capital and subject to a 100% volatility adjustment for K-CCD.
Prudential compliance must consequently be linked to risk assessment, treasury, custody, technological resilience, governance, and regulatory reporting.
PS26/13 enforces important FCA Handbook responsibilities for regulated cryptoasset activities. These are conduct, governance, resilience, redress, and reporting. The FCA says that most enterprises that engage in regulated cryptoasset operations will be subject to requirements such as the Consumer Duty, COBS, DISP, access to the Financial Ombudsman Service, SYSC, SM&CR, ESG, CASS, and regulatory reporting.
This is a significant step toward the institutionalisation of crypto compliance. Crypto companies will need to think like regulated financial services providers. This includes:
- Accountability for senior management and governance.
- Documented systems and controls.
- Provide straightforward customer communication.
- Ensuring fair value and product governance.
- Handle complaints and provide remedies.
- Mapping and testing operational resilience.
- Safeguarding and custody frameworks.
- Continuous regulatory reporting.
The FCA’s approach also confirms that compliance with activity-specific rules will not automatically meet Consumer Duty obligations. Firms must continue to evaluate how they sell and deliver products and services to retail customers.
This is an important point. Firms should not think that technical compliance with crypto-specific regulations is sufficient. They must also demonstrate customer outcomes.
In the next article in this series we will examine prudential requirements, Consumer Duty, operational resilience, governance, redress and reporting, suggesting a way forward for preparation before 2027.
How FinregE can help
The FCA’s cryptoasset regime presents significant implementation challenges for enterprises. Multiple policy statements and guidance documents must be interpreted, mapped, tracked, and implemented across business units, legal entities, products, controls, and accountable owners.
FinregE facilitates the transition from regulatory publication to regulatory execution.
FinregE enables organisations to turn complicated regulatory updates into structured obligations, connect those responsibilities to policies and controls, allocate ownership, manage implementation actions, and keep an audit trail of regulatory readiness.
With FinregE firms can:
- monitor FCA publications and linked updates;
- identify which documents affect each business model;
- map obligations from PS26/9 to PS26/13 and related guidance;
- connect regulatory requirements to internal policies, controls and risk frameworks;
- assign actions to compliance, legal, risk, operations, technology and senior management teams;
- evidence implementation progress ahead of the 2027 regime expansion;
- maintain a defensible record of decisions, interpretations and remediation.
The FCA regime is not just a one-time modification. It marks the start of a more mature UK cryptocurrency regulatory landscape. Firms require systems capable of managing continual change.
Book a demo to explore how FinregE can help businesses transform complicated regulatory changes into structured obligations, mapping controls, and implementation evidence.


