Operating an exchange, custody service or crypto payments business in the United Kingdom without the right regulatory authorisation is not a recoverable mistake. The Financial Conduct Authority (FCA) has enforcement powers that include prohibition, financial penalties and criminal referral. Banks that identify an unregistered cryptoasset business frequently close accounts without notice. The question for any operator targeting UK customers, using UK banking, or holding UK users' assets is therefore not whether to engage with the UK regime – it is how to do so in a way that sustains the business.
This guide sets out the UK regulatory regime for virtual asset service providers (VASPs – businesses offering crypto exchange, transfer, custody or related services), the FCA's authorisation and registration tracks, the AML and financial-promotion obligations that layer on top, and the cross-border structuring questions any business with a UK nexus must resolve before it goes live.
The FCA and the UK Regulatory Perimeter
The FCA is the primary regulator for cryptoasset businesses operating in or from the United Kingdom, and it runs two distinct tracks. The first is cryptoasset registration under the Money Laundering Regulations (MLR) – the AML-only gateway that applies to businesses whose crypto activities do not constitute regulated financial services. The second is full regulatory authorisation under the Financial Services and Markets Act, which applies where the crypto activity maps to a regulated activity such as operating an electronic money institution, managing collective investments or dealing as principal.
Understanding which track applies to your business is the threshold question. An exchange that converts fiat to crypto and holds assets on behalf of retail users typically sits in the MLR registration track for its core exchange function. The same exchange that offers staking, yield products or tokenised securities may cross into the FSMA perimeter simultaneously. The FCA is explicit: the legal analysis must follow the substance of the activity, not the label the operator applies to it.
The UK has also enacted financial-promotion rules for cryptoassets. Any communication that is a financial promotion for a qualifying cryptoasset must either be made by an FCA-authorised person or approved by one. The regime covers marketing to UK persons regardless of where the promoter is established – a point that catches offshore operators that assume their foreign licence solves the UK marketing question.
What Does Cryptoasset Registration Under the MLR Require?
MLR registration is the baseline authorisation for most crypto exchanges, custody providers and peer-to-peer platforms operating in the UK. The process requires the FCA to be satisfied on three connected grounds: that the firm's AML and counter-financing-of-terrorism (CFT) systems are adequate, that the firm's controllers and key individuals are fit and proper, and that the business model is sufficiently articulated that the FCA can assess its risks.
In our practice, firms that underestimate the depth of that assessment consistently stall. The FCA's registration process has evolved significantly since the initial wave of applications. Examiners now expect documented customer risk-assessment methodologies, transaction-monitoring rules calibrated to the firm's specific product set, and demonstrated senior management accountability for financial crime prevention.
The timeline for registration is not fixed by statute and varies by the quality of the application and the FCA's queue. Operators we advise are routinely told to plan for a period measured in multiple months from submission of a complete file. Incomplete applications restart the clock. The FCA publishes its current processing statistics, and those figures move; the time to build into any launch plan is best confirmed by reference to the FCA's live guidance at the point of submission rather than anecdotal benchmarks.
Capital requirements for the MLR registration track are not set at a fixed minimum in the same way as an EMI licence, but the FCA will assess whether the business has sufficient financial resources to operate and wind down in an orderly way. Operators with thin capital bases have seen applications refused on this ground.
Who Needs a UK Crypto Licence? The Nexus Question
The UK registration requirement bites where a business is "carrying on" a cryptoasset activity in the United Kingdom. That territorial test turns on multiple factors: where the entity is incorporated, where its senior management operates, where its customers are located, and where the relevant contractual and operational functions are performed.
A business incorporated outside the UK but actively marketing to UK users, denominating services in sterling, or running customer support from a UK address will typically be within scope. The FCA does not accept the proposition that offshore incorporation alone places a business outside the UK regime.
This nexus analysis is critical for the cross-border operator. A group that operates a holding company in the Cayman Islands, a technology subsidiary in Lithuania and a sales function in the UK may need MLR registration – and possibly FSMA authorisation – for the UK entity. The parent's MiCA CASP status in an EU member state does not passport into the United Kingdom after the UK's departure from the EU. Each jurisdiction layer must be assessed on its own terms.
The FCA's published Unregistered Cryptoasset Businesses list names firms that market to UK persons without registration. Appearing on that list has immediate banking and partnership consequences, and the FCA has pursued enforcement against firms on it. The reputational damage is difficult to reverse quickly.
For a scoped assessment of your UK nexus and whether registration applies, contact OBOLUS at info@oboluslaw.com. The analysis above describes the standard test. Your entity structure, user base and banking arrangements change the outcome.
The AML and Travel Rule Obligations That Attach to Registration
MLR registration is not a light-touch gateway – it imports the full suite of UK AML and CFT obligations drawn from the FATF Recommendations, including Recommendation 15 on virtual assets and the Travel Rule (the obligation to pass originator and beneficiary data with a qualifying transfer). The UK's Travel Rule regime is among the more developed in the major hubs, and the FCA expects registered firms to have systems capable of sending, receiving and holding Travel Rule data at the point of customer onboarding, not as a retrofit.
In practice, this means that a registered VASP must implement a customer due-diligence programme aligned to its specific risk profile, screen transactions against sanctions lists (including OFAC, OFSI and UN designations), maintain transaction records for a prescribed period, and report suspicious activity to the National Crime Agency via the Suspicious Activity Report regime.
The FCA has been explicit that it views the quality of transaction monitoring as a key indicator of a firm's AML culture. Firms using off-the-shelf rule sets without calibration to their product risk profile have been criticised in supervisory correspondence and in published decision notices. We have seen firms invest significant time post-registration retrofitting monitoring systems that should have been built to specification before the application was filed.
For operators running cross-border rails – for instance, a UK-registered business routing transfers through a non-UK exchange – the Travel Rule creates a counterparty compliance dependency. If the receiving VASP in another jurisdiction does not have compatible systems, the UK operator faces a choice: hold the transfer, request the data through an alternative channel, or refuse to process it. Building that decision tree into operations before launch is considerably less expensive than managing it retrospectively under regulatory scrutiny.
Financial Promotion Rules: What Does Marketing to UK Users Require?
The UK's financial-promotion regime for cryptoassets represents a significant compliance layer on top of registration, and one that catches offshore operators with surprising regularity. Any promotional communication for a qualifying cryptoasset that is capable of having an effect in the United Kingdom must comply with the regime.
In concrete terms: a non-UK VASP running social media advertising targeted at UK users needs either FCA authorisation itself or a communication approved by an FCA-authorised person. The cryptoasset financial promotion rules require clear risk warnings, restrictions on certain incentives and mandatory cooling-off provisions. The FCA has taken action against firms – including those operating entirely offshore – for non-compliant promotions reaching UK persons.
For a business whose UK revenue is meaningful but whose primary licensing is in another hub, the cost-benefit analysis is real. Applying for full UK registration may be justified by the market. Alternatively, the firm may structure its UK marketing through an authorised approver arrangement while limiting the scope of services available to UK users until full registration is in place. Neither path is frictionless. We regularly advise clients on the practical implementation of both approaches, including the documentation requirements that authorised approvers now impose following the FCA's enhanced approval rules.
Electronic Money and Payment Institution Licences: Where Crypto and Payments Converge
A number of crypto business models require authorisation under the payments or electronic money regime, not just MLR registration. This matters because the two tracks carry materially different obligations, capital requirements and supervisory relationships with the FCA.
An operator that issues stored-value instruments, processes payment transactions for merchants or provides account information services is likely within the scope of the Electronic Money Institution or Payment Institution regimes. Crypto wallets that hold fiat alongside digital assets, and platforms that convert stablecoins to fiat for merchant settlement, frequently straddle both tracks.
The FCA's FSMA perimeter also captures arrangements that might be characterised as collective investment schemes – a real risk for tokenised fund products and yield-generating protocols that pool users' assets and apply a strategy. Operating a collective investment scheme without authorisation carries criminal liability in the UK, and the fact that the underlying assets are digital does not change that analysis.
In a matter we advised on earlier this year, a payments-adjacent crypto firm had structured its product as a simple exchange to avoid the EMI track, but the FCA's pre-application feedback indicated the product functionally issued e-money. Restructuring the product architecture before application – rather than after – avoided a multi-month delay and a capital-raising exercise at an inconvenient point in the product cycle. Early-stage structuring advice of this kind is among the most economically efficient legal spend a crypto business can make.
How Does the UK Compare for an Inbound Operator?
The United Kingdom occupies a distinctive position among the leading digital-asset jurisdictions. Its common-law courts are among the most effective forums for crypto asset recovery globally – England and Wales produced the landmark ruling in AA v Persons Unknown [2019] that confirmed crypto as property subject to proprietary injunctions, and the courts have continued to develop that jurisprudence at pace. That legal infrastructure is an asset for any business whose customer relationships could give rise to disputes requiring court intervention.
On the licensing side, the UK is neither the fastest nor the least demanding hub. Jurisdictions with expedited digital-asset regimes – the AIFC in Kazakhstan, certain Caribbean registries – can offer quicker time-to-market. EU CASP authorisation under MiCA, obtained in a member state such as Lithuania or Malta, provides passport access to the entire EU27 market that the UK cannot currently replicate.
The decision matrix for the inbound operator therefore turns on three axes. First: is the UK market strategically necessary, or is EU access the priority? If the latter, an EU CASP route followed by a separate UK registration on a delayed timetable may be the most efficient sequence. Second: does the business model generate the kind of dispute exposure – complex asset recovery, cross-border enforcement – where UK court access is a genuine operational asset? If so, maintaining a UK presence has value beyond the regulatory cost. Third: is the business's institutional counterparty base – banks, payment processors, prime brokers – UK-centric? UK banking for crypto businesses remains selective, and registration with the FCA is typically a threshold condition for UK banking relationships, not a guarantee of one.
If a prior application stalled or a banking relationship closed, a structured review can identify the underlying gap and the path forward. Write to OBOLUS at info@oboluslaw.com.
Tax and Banking Interaction for UK Crypto Businesses
The UK tax treatment of cryptoassets is determined by HMRC rather than the FCA, and the two regimes operate independently. For businesses – as distinct from individuals – the core question is whether crypto activity generates income or capital gains, how staking and lending receipts are characterised, and what VAT treatment applies to exchange services and token issuance.
HMRC's published guidance treats cryptoassets as property for capital-gains purposes. Exchange businesses that trade as principal face a different analysis from those acting purely as agents. Token issuers must consider whether proceeds constitute trading income, whether any element constitutes an advance receipt, and whether the token itself creates a VAT supply. Each of these questions turns on the specific facts of the product and the business model.
UK banking for registered cryptoasset businesses has improved but remains selective. The major clearing banks continue to apply heightened due-diligence requirements and in some cases maintain categorical restrictions on crypto business accounts. EMI-issued accounts have filled some of the gap, but institutional-grade banking – the kind needed for significant fiat-on-ramp volumes – typically requires a registered UK entity, a documented compliance programme and in some cases a direct relationship with the bank's financial-crime team before account opening. We map banking options as part of the licence-stack analysis we conduct for clients entering the UK market, because the banking question and the licensing question cannot be resolved independently of each other.
Self-Assessment Checklist for UK Crypto Market Entry
Before submitting a UK application or marketing to UK users, operators should be able to answer the following questions with documented evidence:
- Has the business conducted a written nexus analysis establishing whether its activities constitute "carrying on" a cryptoasset business in the UK?
- Has a legal opinion addressed whether any product features trigger the FSMA perimeter (collective investment scheme, e-money issuance, dealing in securities)?
- Is a written AML/CFT risk assessment in place, calibrated to the firm's specific product, customer and geographic risk profile?
- Are transaction-monitoring rules documented, tested against the firm's actual transaction typologies, and assigned to a named accountable individual?
- Does the firm have a Travel Rule solution deployed or contracted, capable of sending and receiving counterparty data from day one of operations?
- Are all UK-facing financial promotions either issued by an FCA-authorised person or approved under the financial-promotion approval regime?
- Has a banking strategy been agreed, with at least one account provider that has confirmed it will service a registered cryptoasset business?
- Are the key individuals who will appear on the registration application prepared for an FCA fit-and-proper assessment, including documentation of their professional background and any prior regulatory history?
Operators who cannot answer each of these questions affirmatively before submitting are filing prematurely. The FCA's information-request process during registration review can add months to a timeline when foundational documentation is absent.
Related at OBOLUS
- Digital-Asset Licensing and Registration – the firm's cross-jurisdictional licensing practice and approach
- VASP Licence Application in Ireland – EU CASP-track entry via Ireland for operators weighing UK versus EU access
- Transaction Monitoring Setup for Early-Stage Founders – building a compliant AML system before the FCA reviews it
FAQ
How long does a crypto licence take to obtain?
UK MLR registration timelines vary and are not fixed by statute. The FCA's processing time depends on the quality of the application and its current workload. A well-prepared file submitted with complete AML documentation, fit-and-proper evidence and a clear business model description typically progresses faster than an application that requires multiple rounds of information requests. Operators should plan for a period measured in several months from submission of a complete application. The FCA publishes current registration statistics, and those figures change; checking them at the point of submission gives the most accurate current picture.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right choice depends on where your customers are, where your banking will sit, what services you offer and what your institutional counterparties require. A business targeting EU customers may prioritise MiCA CASP authorisation in a member state such as Lithuania or Malta. A business whose primary market is the UK needs FCA registration regardless. Many operators run multi-jurisdiction structures, with allied counsel coordinating across the relevant hubs. We map the full licence, banking and tax stack before recommending a sequence.
Do I need a separate custody licence?
In the UK, custody of cryptoassets for clients is a registrable activity under the MLR regime, and some custody models also engage the FSMA perimeter. Whether a standalone custody licence is required depends on whether the custody function is operated by the same entity as the exchange or by a separate legal entity, and whether the custody model involves any pooling or discretionary management of assets. The answer is fact-specific. Operators building custody layers into a broader product should obtain a written analysis of the regulatory characterisation before committing to an entity structure.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. Digital assets are the entirety of our practice – we do not advise on unrelated matters, and our team has no institutional conflicts with the crypto sector. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the compliance, AML and tax structuring that sits around all of it. We map the licence stack across the operating, custody and payment layers before clients commit to a structure. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing and Jurisdictions Analyst – specialist in digital-asset regulatory authorisation across EU, UK and offshore hubs, with a focus on multi-jurisdiction entry sequencing and CASP/VASP application preparation.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.