UK FCA Crypto Gateway: KYC Compliance Checklist 2026
The FCA crypto authorisation gateway opens 30 September 2026. Firms have five months to apply. Here is what KYC compliance teams must prepare now.

Sixteen days from today, the Financial Conduct Authority opens the authorisation gateway for UK cryptoasset firms. The window runs from 30 September 2026 to 28 February 2027. Firms that fail to apply in time cannot legally operate under the new regime that takes effect on 25 October 2027.
This is not a renewal of the existing anti-money laundering registration. It is a wholesale shift into the Financial Services and Markets Act 2000 framework — the same framework that governs banks, brokers and fund managers. The KYC and identity verification obligations that come with it are proportionately heavier.
What the regime covers, who must apply, and what a compliance team needs to build in the next twelve months: that is the ground covered below.
From MLR Registration to FSMA Authorisation
Every cryptoasset exchange provider and custodian wallet provider active in the UK has, since 2020, operated under Money Laundering Regulations registration with the FCA. Registration is an AML/CFT gateway — it verifies that a firm has adequate anti-money laundering controls. It is not a licence to conduct regulated financial services.
The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, made by Parliament on 4 February 2026, changed that. From 25 October 2027, conducting a regulated cryptoasset activity without FCA permission is a criminal offence.
The difference in practice:
| Dimension | MLR Registration | FSMA Authorisation |
|---|---|---|
| Legal basis | Proceeds of Crime Act / Money Laundering Regulations | Financial Services and Markets Act 2000 |
| Scope | AML/CFT controls only | Prudential, conduct, market integrity, AML |
| Threshold Conditions | None | Capital adequacy, governance, competency |
| KYC obligations | Risk-based AML due diligence | Full customer due diligence + conduct rules + suitability |
| Ongoing supervision | AML-focused inspections | Full FCA supervisory relationship |
| Criminal penalty for non-compliance | Civil enforcement, registration cancellation | Criminal offence |
Existing MLR-registered firms do not automatically receive FSMA permission. Every firm must apply through the gateway.
Who Must Apply
The new regime brings eight categories of regulated cryptoasset activity within the FCA's perimeter:
- Operating a UK qualifying cryptoasset trading platform (QCATP)
- Dealing in cryptoassets as principal
- Dealing in cryptoassets as agent
- Arranging deals in cryptoassets
- Safeguarding cryptoassets (custody)
- Operating a cryptoasset lending and borrowing platform
- Arranging staking of cryptoassets
- Issuing qualifying stablecoins
Firms conducting any of these activities from the UK — or marketing them into the UK — need to be in the gateway by 28 February 2027. That date is not the point of compliance: it is the application deadline. The FCA will process applications and issue decisions before the regime commences on 25 October 2027. Firms that submit after the deadline face a gap during which they cannot legally continue operating.
Overseas firms operating cross-border into the UK are also in scope. The FCA's perimeter extends to firms actively targeting UK retail clients regardless of the jurisdiction from which they operate.
KYC Requirements Under the New Regime
The regulatory uplift on identity verification is substantial. MLR registration required a risk-based customer due diligence programme. FSMA authorisation requires the same, plus a conduct layer drawn from the FCA's wider Handbook.
Customer Due Diligence: The Baseline Stays But Deepens
Standard CDD requirements remain. What the authorisation regime adds:
Appropriateness assessments. Trading platforms and intermediaries must assess whether cryptoassets are appropriate for each retail customer. That requires a verified identity to anchor the assessment — pseudonymous onboarding is no longer compatible with the regime.
Enhanced disclosures tied to verified identity. Lending, borrowing and staking platforms must provide enhanced disclosures — including over-collateralisation requirements and negative balance protection — to identified customers. The disclosure cannot be delivered without a live identity record.
Stablecoin redemption. PS26/11, the policy statement covering conduct rules, confirms that the KYC check must complete before the redemption period for qualifying stablecoins begins. A stablecoin issuer that allows redemption before identity verification clears is out of compliance from day one of the new regime.
Safeguarding and Custody
Firms providing cryptoasset custody services must comply with a new Client Assets Sourcebook chapter — CASS 17 — adapted for crypto. The safeguarding requirements include:
- Segregation of client assets with documentary evidence of ownership
- Reconciliation of records against ledger positions
- Private key management policies reviewed at least annually
- Client communications that identify the custodian's legal obligations with precision
Each of these functions ties back to a verified customer identity. A custody firm that cannot demonstrate continuous identity coverage across its client book will fail the CASS 17 audit.
Correspondent Relationship EDD
Under a new regulation 34A inserted into the MLRs by the June 2026 amendment, cryptoasset businesses must apply Enhanced Due Diligence before establishing correspondent relationships with other cryptoasset firms. This takes effect 1 February 2027 — ahead of the full FSMA regime — but preparing for it alongside the authorisation application is the only practical approach.
Read the full breakdown of the June 2026 MLR amendment: UK AML 2026: New Rules for Crypto, Effective June 30.
The Authorisation Timeline in Practice
The FCA expects to determine all applications received during the gateway window before 25 October 2027. That gives the authority roughly thirteen months from the close of the gateway to process every submission. Processing times will vary by application complexity.
A firm that applies on 1 October 2026 has the maximum available processing runway. A firm that applies on 28 February 2027 is relying on the FCA completing its review in under nine months — possible, but tighter.
The authorisation application itself is demanding. It requires:
- A regulatory business plan covering all cryptoasset activities
- Financial projections with capital adequacy analysis
- Governance arrangements — senior management function holders, conflicts of interest policy
- An AML/CFT programme that meets both MLR and FSMA standards
- A comprehensive KYC framework with documented customer risk tiers
- Evidence that systems and controls are operational, not merely planned
- Technology and infrastructure descriptions covering custody, key management and transaction monitoring
Point six is the one that catches firms. The FCA expects evidence of a working KYC programme at the time of application — not a blueprint for one to be built before the regime starts.
The Parallel MiCA Dynamic
UK and EU firms operating across jurisdictions face a coordination challenge. MiCA — which delivered the EU Travel Rule as a mandatory requirement from 1 July 2026 — runs on different technical standards from the UK FCA framework. A firm regulated in both jurisdictions manages two parallel sets of identity requirements.
The UK Travel Rule, under the MLR amendment effective June 30, requires originator and beneficiary data on all cryptoasset transfers above £1,000. MiCA's Travel Rule has no minimum threshold. The data fields overlap but are not identical.
For the full MiCA picture: The MiCA Travel Rule: What CASPs Still Get Wrong.
What Perpetual KYC Means for the New Regime
The FSMA framework is not a one-time onboarding filter. The FCA expects ongoing risk monitoring, periodic re-verification and the ability to demonstrate continuous identity coverage across the client book at any supervisory inspection.
That is the definition of Perpetual KYC — the shift from event-triggered reverification to continuous risk-based monitoring. Firms that built their compliance stack around a point-in-time onboarding check will need to rebuild it before they can file a credible authorisation application.
The mechanics of Perpetual KYC: Perpetual KYC: Moving Beyond One-Time Verification.
How AI Agents Change the Build Cost
A manual approach to the FCA's identity requirements is mathematically difficult at scale. A trading platform with 100,000 customers, running periodic re-verification annually, generates roughly 8,300 identity reviews per month. At a manual review rate of ten minutes each, that is 1,400 labour hours per month on re-verification alone — before a single new onboarding is processed.
Joinble's AI agents restructure that equation. Continuous risk monitoring runs across the entire customer base without triggering a full re-verification for every customer. Risk-event routing means only the customers whose risk profile has materially changed reach the review queue. The FCA's expectation of ongoing monitoring is satisfied; the cost of satisfying it drops by roughly 80%.
For firms building their FSMA authorisation application now, integrating an agentic KYC layer is not a feature enhancement — it is a prerequisite for demonstrating that the KYC programme is operationally sustainable at the supervision standard the new regime expects.
What to Build Before the Application
Working backwards from the 30 September 2026 gateway opening and a realistic 90-day application preparation window, firms that are not yet in active preparation are behind.
The critical path:
- Perimeter analysis — confirm which regulated activities the firm conducts and whether any business lines fall outside the new scope
- Gap assessment against Threshold Conditions — capital adequacy, governance, conflicts policy, fitness and propriety of senior managers
- KYC programme audit — document current customer risk tiers, CDD processes, EDD triggers, ongoing monitoring cadence and evidence trails
- Custody and safeguarding review — map current key management, segregation and reconciliation processes against CASS 17
- Technology uplift — identify gaps in transaction monitoring, identity verification coverage and perpetual monitoring capability
- Application drafting — regulatory business plan, AML programme documentation, governance pack
Steps one through five must be complete before step six begins. The FCA does not treat an authorisation application as a consultation process.
FAQ
Does MLR registration count toward the FSMA authorisation process? No. MLR registration is a separate process under separate legislation. It confers no credit in the FSMA authorisation assessment. Firms must apply through the FCA gateway as a new authorisation, not a transfer or conversion.
Can a firm continue operating after 25 October 2027 if its application is still under review? Yes, provided the application was submitted during the gateway window (before 28 February 2027). Firms with pending applications can continue their existing activities while the FCA processes their submission. Firms that miss the gateway window cannot.
Are DeFi protocols in scope? Decentralised protocols without a legal entity operating or controlling the platform from the UK are likely outside scope. However, a UK-incorporated entity that develops, deploys or commercially promotes a DeFi protocol that conducts regulated activities is likely in scope. The FCA has signalled it will take a substance-over-form approach.
What KYC documentation will the FCA expect at application? The FCA expects a documented AML/CFT programme at the application stage — not a commitment to build one. This includes customer risk methodology, CDD and EDD procedures, transaction monitoring thresholds, suspicious activity reporting workflows and a training register. Gaps at application stage are grounds for refusal, not a starting point for dialogue.
How does the UK Travel Rule interact with FSMA authorisation? The Travel Rule applies under the MLRs from June 30, 2026, independently of FSMA authorisation status. A firm must comply with the Travel Rule now regardless of where it stands in the authorisation process. FSMA authorisation does not replace or extend Travel Rule obligations.
What happens to existing MLR registrations after the FSMA regime starts? The FCA has indicated that MLR registration requirements for cryptoasset activities will be subsumed into the FSMA framework once the regime is live. Firms that obtain FSMA permission will not need to maintain a separate MLR registration for their cryptoasset activities. Firms that do not obtain permission will lose both.
Related Articles

UK AML 2026: New Rules for Crypto, Effective June 30
Parliament approved 15 UK AML reforms on June 9. Most take effect June 30. Crypto firms face the deepest changes. Here's your compliance checklist.

FATF July 2026: Stablecoins Fuel 84% of Crypto Crime
FATF's July 2026 report reveals stablecoins now drive 84% of illicit crypto flows, with $154 billion laundered in 2025. What every CASP must do now.

Post-MiCA: What 80% Exit Means for Crypto KYC
After MiCA's July 2026 deadline eliminated 80% of EU crypto exchanges, licensed CASPs still face critical KYC gaps that regulators are closing in on.