Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.Włączony AI-, zintegrowany ESG- i globalnie podłączeni księgowi i doradcy. Audyt, podatki, doradztwo, finanse korporacyjne i 16 specjalistycznych filarów usług.
All insights

Digital Assets Regulation UK: A Practical Guide

Digital assets regulation UK explained for crypto and fintech businesses, covering FCA authorisation, FSMA, stablecoins, tax and compliance readiness.

17 September 2026

For crypto and fintech businesses, UK regulation is moving from a narrow focus on anti-money-laundering controls and financial promotions towards a broader authorisation and conduct framework. Firms must distinguish rules that apply now from requirements scheduled to take effect. They must also build evidence that their governance, controls, and operating model can withstand scrutiny.

As of September 2026, digital assets regulation UK combines existing FCA requirements with a planned regime covering trading platforms, intermediaries, custody, stablecoin issuance, and staking arrangements. The FCA has stated that firms can apply for authorisation from 30 September 2026, ahead of the mandatory regime scheduled for 25 October 2027. See the FCA's current timetable and rules overview.

Readiness is not the same as registration. Boards and compliance leaders need a clear view of which services they provide and which regulatory perimeter each service may enter. They also need to connect those obligations with tax, customer protection, financial crime, and operational resilience. The starting point is to map the framework itself, including the distinctions between different types of digital asset and activity.

Explore UK regulatory compliance advisory

What does digital assets regulation in the UK cover?

The starting point is classification. A digital asset is anything of value represented digitally or electronically, while a cryptoasset is a digital asset whose ownership is recorded on a distributed ledger. The latter category includes assets secured by encryption and typically supported by distributed-ledger technology, but the technology alone does not determine the legal treatment.

Several terms are particularly important:

  • Stablecoin: a cryptocurrency backed by real-world assets and designed to maintain its value against a national currency, such as the US dollar.
  • Security token: a cryptoasset that records ownership of a financial security, such as shares or debt.
  • Exchange and utility tokens: widely traded cryptoassets that have historically often sat outside the FCA's core conduct perimeter, subject to the specific features and activities involved.

That last qualification matters. Historically, whether a cryptoasset activity was regulated depended on whether it fell within existing legislation. Including the Financial Services and Markets Act 2000 (FSMA), the Electronic Money Regulations, or the Payment Services Regulations. Tokenised securities that qualified as specified investments were already regulated under FSMA, while many exchange and utility-token activities were not within the same core conduct perimeter. Businesses therefore needed to assess both the token and what they did with it.

As of September 2026, the framework is moving from that activity-by-activity perimeter towards a broader, dedicated regime. The UK's strategy builds on FSMA, the FCA Handbook and the PRA Rulebook, supported by targeted secondary legislation and updated requirements. Planned measures are intended to bring specific activities, including stablecoin issuance and certain trading or exchange services, within the regulatory perimeter. They are not interchangeable with the rules already in force.

Existing requirements can still apply now. These include financial-promotion restrictions and anti-money-laundering obligations under the Money Laundering Regulations. The FCA has stated that, until the new rules take effect in October 2027, its crypto oversight remains focused on financial promotions and anti-money-laundering controls. It has also indicated that firms can apply for authorisation from 30 September 2026, ahead of the mandatory regime scheduled for 25 October 2027.

For a board or compliance team, the practical question is therefore not simply whether the business is "in crypto". It is which asset types, services, customer relationships and payment flows are involved, and which obligations apply at each stage. A structured regulatory compliance consulting review can help map that perimeter without treating proposed requirements as current law.

What are the FCA registration and authorisation requirements?

As of September 2026, a cryptoasset business should distinguish between the rules already applying to its activities and the wider FCA authorisation regime that is scheduled to follow. That distinction matters because registration under one requirement does not, by itself, demonstrate that a firm is ready for the broader obligations expected under the developing digital assets regulation UK framework.

The current baseline includes anti-money laundering obligations under the Money Laundering Regulations and restrictions on financial promotions. The FCA's crypto oversight is expected to remain focused on those areas until the new rules take effect in October 2027. Firms promoting cryptoassets to UK consumers therefore need controls over who approves promotions, what risk information is presented, and how customer and transaction risks are assessed. The precise perimeter still requires careful activity-by-activity analysis.

The planned regime is broader. The FCA says trading platforms, intermediaries, custodians, stablecoin issuers, and firms arranging staking are expected to obtain FCA authorisation to operate in the UK. The government also describes the future framework as bringing crypto firms within established transparency standards, with rules intended to provide greater legal clarity and consumer protection. These are forward-looking requirements, not a statement that every firm is already subject to the final regime.

The FCA has announced that its authorisation gateway is scheduled to open on 30 September 2026. The published application window is 30 September 2026 to 28 February 2027, ahead of the mandatory regime scheduled for 25 October 2027. The FCA has also encouraged firms to prepare early and use its pre-application support meetings. Dates and implementation details should be checked against the latest FCA publications, particularly as further policy material on the regulatory perimeter was planned for September 2026.

A practical readiness checklist

  • Map the activities. Document whether the business operates a platform, provides custody, intermediates trades, issues a stablecoin, arranges staking, or performs another activity that may fall within the future perimeter.
  • Test the current baseline. Review AML governance, customer due diligence, suspicious activity escalation, record keeping, and financial-promotion approval processes.
  • Build an authorisation file. Prepare the business model, governance structure, responsible individuals, systems and controls, prudential information, and evidence of operational resilience in a form that can support an FCA application.
  • Plan for transition. Assign ownership for the application timetable, monitor FCA policy updates, and use pre-application engagement where appropriate.

Registration or a successful application should not be treated as a substitute for ongoing compliance. The future framework is intended to cover conduct, transparency, consumer outcomes, and operational controls as well as regulatory status. Businesses should obtain advice on their specific facts before relying on any interpretation or making an application.

How do FSMA and market-conduct rules affect crypto businesses?

For a crypto business, regulatory analysis should begin with the activity being performed, not the label attached to the token or platform. The UK framework builds on the Financial Services and Markets Act 2000 (FSMA), the FCA Handbook and the PRA Rulebook, supported by targeted secondary legislation where appropriate. Historically, the answer depended on whether an activity fell within existing FSMA, electronic-money or payment-services rules. That perimeter is now being extended through the developing cryptoasset regime, so conclusions should be dated and reviewed as policy takes effect.

A tokenised instrument that qualifies as a specified investment, such as a tokenised security, can already be regulated under FSMA. By contrast, many exchange and utility tokens have historically sat outside the FCA's core conduct perimeter, although financial-promotion restrictions and anti-money-laundering requirements have still applied. The planned framework is intended to bring specified crypto activities, including certain trading or exchange services and stablecoin issuance, within the regulatory perimeter. The FCA's published timetable states that the mandatory regime is scheduled to take effect on 25 October 2027, subject to the applicable rules and transitional arrangements.

Admissions, disclosures and market abuse

Classification determines which controls a business must design around issuance, admission and secondary-market activity. The FCA's final policy package includes rules for cryptoasset admissions and disclosures, alongside a market-abuse regime covering risks such as insider trading and market manipulation. In practice, firms should identify who controls material information, how it is recorded and escalated, and which communications could influence a market. Listing, token launch and exchange procedures should therefore include documented approval, disclosure and surveillance responsibilities rather than treating marketing as separate from compliance.

Consumer Duty and governance

The FCA has said it applied established financial-services standards where crypto risks are comparable, including the Consumer Duty. That makes governance broader than obtaining registration or authorisation. Boards and senior managers should be able to evidence how the customer proposition is designed. How risks and limitations are explained, how foreseeable harm is monitored and how issues are remediated. The precise obligations will depend on the activity, customer type, distribution model and applicable phase of the regime.

A defensible control framework should map each product and service to its legal classification, regulator, permissions, conduct obligations, disclosure requirements and accountable owner. Revisit that map when a business adds custody, brokerage, staking, issuance or payment functionality. In digital assets regulation UK, activity classification is the foundation for proportionate governance, not a one-off legal exercise.

Sources: FSMA framework and cryptoasset perimeter; FCA admissions, disclosures and market-abuse policy package; FCA market-integrity and Consumer Duty position.

How are stablecoins and payment arrangements regulated?

Stablecoins sit at the intersection of cryptoasset, payments and financial-services regulation. They are cryptocurrencies designed to maintain value against a national currency and backed by real-world assets, although the legal treatment depends on the token's structure, issuer, use and underlying rights. A token that represents shares or debt may already be a security token and fall within the existing Financial Services and Markets Act 2000 (FSMA) perimeter.

As of September 2026, the UK framework is developing rather than operating as one single stablecoin rulebook. The FCA has published a policy statement addressing stablecoin issuance, while its wider planned framework brings stablecoin issuance and certain exchange or trading services within the regulatory perimeter. These measures should be read as part of the UK's broader digital assets regulation uk programme, with implementation and transitional requirements requiring careful monitoring. See the FCA's crypto rules announcement, the overview of the UK framework, and the UK cryptoasset regulatory tracker.

How regulators may approach stablecoin and payment activities

Activity

Regulatory question

Practical implication

Issuing a stablecoin

Does the token and its reserve model fall within the FCA's planned cryptoasset issuance regime?

Document the token's rights, reserve assets, redemption model, governance and prudential arrangements. FCA authorisation may be required under the planned framework.

Using a qualifying UK-issued stablecoin for payments

HM Treasury has proposed bringing qualifying payment stablecoins within the payments perimeter.

Assess whether the model could involve payment services or e-money obligations, and avoid treating a consultation proposal as current law.

Operating a payment or e-money service involving cryptoassets

Which requirements under the Payment Services Regulations 2017 or Electronic Money Regulations 2011 apply?

Map wallets, safeguarding, client funds, redemption, complaints and operational controls to the relevant permissions and responsibilities.

Systemic stablecoin activity

The FCA and Bank of England are consulting on how FCA rules may apply if HM Treasury recognises an issuer as systemic.

Monitor the consultation and prepare for potentially enhanced supervision, including central-bank involvement. This is a developing proposal, not a universal current requirement.

HM Treasury published a consultation on modernising payment services and e-money regulation on 14 July 2026. The proposal would retain the core perimeter and definitions in legislation while potentially moving detailed firm-facing requirements into the FCA Handbook. Businesses should therefore maintain a regulatory map that distinguishes current AML and financial-promotion duties from proposed authorisation, payments and e-money requirements. That distinction is central to credible compliance planning and board reporting.

What should UK crypto businesses know about tax and controls?

Tax treatment should be mapped alongside the operating model, not left until the annual return. The relevant questions include what the business issues, holds, lends, pools, exchanges, or accepts as payment. Teams should also identify which entity undertakes each activity and how transactions are valued, recorded, and reconciled. The UK's tokenisation delivery plan identifies tax, financial crime, identity, and resilience as part of the wider implementation agenda. This shows why tax data should connect to governance and control design rather than sit in isolation. The delivery plan covers these areas across its industry action groups.

Separate current obligations from proposed tax changes

HMRC published draft legislation on 13 July 2026 covering the tax treatment of stablecoins, cryptoasset loans and liquidity pools. These are proposals, not a substitute for checking the rules that apply to the business now. The draft measure was proposed to apply from 6 April 2027 for individuals and trustees, and from 1 April 2027 for companies. Those dates differ, and senior teams should not collapse them into a single generic 2027 deadline. Both the publication status and the proposed effective date should be recorded in the business's regulatory change log. The HMRC draft measures and proposed dates are summarised here.

Current obligations may still include financial-promotion restrictions and anti-money-laundering requirements under the Money Laundering Regulations. The FCA has also published non-Handbook guidance covering areas such as Consumer Duty, international cryptoasset firms and operational resilience. These requirements and guidance should be assessed separately from future tax legislation, with clear ownership for monitoring updates. Existing UK crypto-related requirements include financial-promotion and anti-money-laundering controls.

Build an evidence trail that can withstand review

At a practical level, businesses should retain complete transaction records, wallet and exchange statements, token valuations, loan terms, liquidity-pool activity, fees, counterparties, and relevant entity allocations. Reconcile on-chain activity to the general ledger and investigate unmatched items promptly. Document valuation methods, approvals, adjustments, and the treatment of transfers between connected entities. This is particularly important where one transaction may affect tax, financial crime monitoring, customer disclosures, and management reporting.

Because the treatment of particular arrangements can depend on the facts, a specialist adviser should review the operating model and proposed changes before implementation. This is general information, not personal tax advice. For background on one related area, see our guide to UK capital gains tax.

How can a specialist advisor help build regulatory readiness?

Regulatory readiness is an operating programme, not a form-filling exercise. A specialist advisor can help a crypto business translate the emerging UK framework into accountable decisions, documented controls, and evidence that can withstand regulatory scrutiny. The following six-step roadmap provides a practical starting point.

  1. Scope the activities. Document what the business actually does, including trading, intermediation, custody, stablecoin issuance, staking, payments, and technology services. The FCA identifies trading platforms, intermediaries, custodians, stablecoin issuers, and staking arrangers among the firms expected to obtain authorisation under the planned regime. Read the FCA's regulatory update.
  2. Map permissions and the transition. For each activity, identify the relevant permission, entity, jurisdiction, customer segment, and implementation date. Separate current obligations from future requirements. The FCA has encouraged firms to prepare and offers pre-application support meetings, but preparation is not the same as approval or authorisation.
  3. Build governance and controls. Assign board ownership, senior managers, compliance responsibilities, escalation routes, and management information. The control framework should cover financial promotions, anti-money-laundering obligations, conflicts, conduct, complaints, outsourcing, and safeguarding where relevant. FCA guidance also addresses Consumer Duty, international firms, and operational resilience, so controls should be tested against those expectations rather than documented only on paper. Review the current regulatory tracker.
  4. Prepare records and disclosures. Create an evidence register covering policies, risk assessments, customer communications, token or product documentation, transaction records, training, incidents, and control testing. The government describes the incoming regime as intended to provide legal clarity and strengthen consumer confidence. But a registration or application record alone does not demonstrate that the business is well controlled.
  5. Test resilience. Run practical scenarios involving a cyber incident, service outage, failed settlement, key-person absence, compromised wallet, data loss, or a material compliance breach. DLT may improve efficiency, enable faster settlement, and support transaction monitoring. But those potential benefits do not remove the need for recovery plans, manual workarounds, and clear decision rights.
  6. Establish monitoring and review. Set a recurring cycle for regulatory change, permissions, risk appetite, customer outcomes, financial crime indicators, tax records, reconciliations, and control effectiveness. A partner-led advisor can challenge assumptions and help management prioritise remediation while keeping responsibility with the business. Explore regulatory compliance consulting or the wider UK regulatory compliance advisory guide for further context.

Request a consultation about digital assets regulatory readiness

Frequently Asked Questions

Is cryptoasset trading regulated in the UK?

Yes, but the position depends on the activity and the asset. Existing requirements include anti-money laundering controls and financial promotion restrictions. The broader FCA regime is scheduled to become mandatory on 25 October 2027, with the application window scheduled to run from 30 September 2026 to 28 February 2027. The FCA has published the transition timetable.

Does every crypto business need FCA authorisation?

No. A business must assess its activities, products, customer base, and UK presence against the applicable perimeter. The planned regime specifically includes trading platforms, intermediaries, custodians, stablecoin issuers, and firms arranging staking. Registration or authorisation is not, by itself, evidence that every compliance obligation has been met.

How does FSMA affect digital asset businesses?

FSMA provides part of the framework for determining whether an asset or activity is a regulated financial service. Tokenised securities that qualify as specified investments can already fall within FSMA, while other cryptoasset activities may be brought within the perimeter through targeted rules. Classification should therefore precede product launch, marketing, and distribution decisions.

Are stablecoins regulated in the UK?

Stablecoin treatment depends on how the token is issued and used. The FCA and Bank of England are developing the supervisory approach, while HM Treasury has proposed bringing qualifying UK-issued stablecoins used for payments within the payments perimeter. Businesses should distinguish current requirements from proposals and monitor final rules before relying on a particular structure.

What tax records should a crypto business maintain?

Maintain complete transaction histories, wallet and exchange reconciliations, valuation methodology, loan and liquidity-pool records, and clear ownership and approval controls. HMRC published draft legislation on stablecoins, cryptoasset loans, and liquidity pools on 13 July 2026. With proposed commencement dates in 2027, so businesses should obtain advice before treating draft measures as settled law.

Ready to assess your regulatory readiness?

Digital assets regulation in the UK is developing across authorisation, financial promotions, stablecoins, tax, and governance. A structured review can help your leadership team identify practical priorities, clarify responsibilities, and prepare evidence for the next stage of growth. To discuss your position with Aureliant Global, request a consultation about digital assets regulatory readiness. You can also call +44 20 7967 1177 for an initial conversation.