Operating a crypto business in the United Kingdom without maintaining a current, correctly scoped registration is not a technical oversight – it is an enforcement trigger. The Financial Conduct Authority (FCA), the UK's primary financial services regulator, supervises cryptoasset firms under the Money Laundering Regulations (MLR), and any business conducting registerable activity without a live, accurately described registration faces the prospect of enforcement action, debanking and reputational damage that can close a business faster than any market downturn.
UK cryptoasset registration under the MLR is not a one-time approval. It requires active maintenance: firms must notify the FCA of material changes and, where the scope of activity shifts, seek a formal variation. As regulatory expectations tighten – MiCA is reshaping the comparative environment across the Channel, and the FCA's own roadmap moves toward a full regulatory authorisation regime for crypto – the stakes of getting renewal and variation wrong are rising. This page maps the process, the cross-border interaction points and the decision logic for firms managing their UK position today.
What the FCA regime actually requires from registered firms
The FCA's MLR registration is the current entry point for crypto businesses operating in the UK – covering exchange activity, peer-to-peer platform operation, custody and certain other virtual asset service provider (VASP) functions. Registration is not the same as full financial-services authorisation under the Financial Services and Markets Act, but the FCA treats it with comparable seriousness. Firms on the register must maintain accurate representations of their business model, AML/CFT controls, ownership structure and the scope of activity they perform.
The FCA publishes and actively curates its register. A firm whose real-world activity drifts from its registered description – whether through product expansion, a new custody vertical or a change in the customer base served – is operating outside the terms of its registration. The FCA has the power to cancel or suspend a registration where it is not satisfied that the firm meets the MLR standards. Enforcement outcomes in this area have ranged from private warnings to public cancellation with named findings.
In our practice, we see firms most commonly run into difficulty at two moments: when they add a new product without revisiting their registration scope, and when ownership or control changes hands without a timely notification to the regulator. Both are avoidable with structured internal governance.
What triggers a variation of your UK crypto registration?
A variation is required whenever a registered firm intends to carry on an activity that falls outside the scope described in its existing registration – or when a material change in the firm's structure, ownership or control occurs. The FCA expects proactive notification; firms should not assume silence constitutes consent.
Common variation triggers include: adding custody services to an exchange-only registration; expanding from a white-label model to proprietary exchange operation; onboarding institutional clients under conditions materially different from the original risk assessment; or completing a change-of-control transaction that alters the individuals regarded as beneficial owners or senior managers. The FCA's fitness-and-propriety assessment applies to new controllers and key function holders, not just on initial registration.
The variation process broadly mirrors initial registration in structure: an updated application, revised AML/CFT documentation, updated business-model description and, typically, a re-examination of the control environment. The timeline for a variation depends on the complexity of the change and the state of the firm's existing file with the FCA. Straightforward notifications typically resolve in a matter of weeks; substantive variations involving a new activity or a controller assessment take longer. Write to us before you commit to the transaction or product launch – the sequencing matters.
For a scoped assessment of your variation position before you announce an expansion or a deal, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking counterparties – change the analysis and the sequencing.
Is there a formal renewal obligation – and what ongoing obligations persist?
The MLR registration does not expire on a fixed annual cycle in the way that some offshore licences renew by date – but that does not mean a set-and-forget posture is acceptable. Ongoing obligations under the MLR are continuous: AML policies must remain effective and current, risk assessments must be updated as the business changes, and the FCA may require firms to re-demonstrate their controls at any time.
In practice, the moments that function as de facto renewal checkpoints are: annual AML/CFT policy review, changes to the firm's MLRO or compliance officer, and the FCA's own supervisory cycle. The FCA has initiated proactive outreach programmes to registered firms, asking for updated information on business activity and control arrangements. A firm that cannot respond promptly with current, coherent documentation is signalling a control weakness that invites deeper scrutiny.
The financial-promotion regime adds a separate ongoing layer. The FCA's rules on crypto financial promotions – covering the communication of invitations or inducements to engage in investment activity related to qualifying cryptoassets – apply to registered and authorised firms alike, and the standards are enforced actively. Any marketing material referencing UK persons must be reviewed against current FCA guidance, which has been updated significantly in recent cycles.
How does a UK registration interact with cross-border operations?
A UK MLR registration does not passport. It covers regulated activity carried on in the UK or directed at UK persons, but it does not authorise the firm to operate as a VASP in EU member states, in the Gulf, or in any other jurisdiction. This is a recurring structural tension for businesses that use the UK as a holding or tech hub while serving customers across multiple regions.
The cross-border picture has become more complex since MiCA took effect. An entity with a CASP (crypto-asset service provider) authorisation in an EU member state can passport across the EEA – but that passport does not extend to the UK post-Brexit. A group operating in both markets needs two separate regulatory relationships. The FCA and ESMA have not established a mutual-recognition arrangement, and there is no credible sign of one in the near term.
We regularly advise businesses that sit between the UK and EU: typically a trading entity in an EU jurisdiction for the MiCA passport, a UK-registered entity for the domestic market, and holding or IP structures optimised around a third jurisdiction. The banking layer is equally multi-jurisdictional – EMI accounts, crypto-native banking and correspondent relationships each carry their own onboarding requirements and must be scoped alongside the licence architecture, not after it.
For a business with users or banking counterparties in the Gulf or Asia-Pacific, VARA in Dubai, ADGM's FSRA in Abu Dhabi, MAS in Singapore and the SFC in Hong Kong each carry their own registration or licensing obligations. A UK registration does not satisfy any of them. We map the full stack before the business commits to a structure that creates an enforcement gap in one of the operating markets.
What goes wrong: common failure points in UK registration management
The most consistent failure pattern we observe is an incomplete change-notification trail. A firm registers, then grows – new products, new controllers, new custody arrangements, a rebrand – without revisiting its FCA file at each step. By the time the FCA runs a supervisory review, the gap between the registered description and the live business is substantial. At that point, the firm is managing a regulatory conversation under pressure rather than at its own initiative.
A second failure pattern involves AML documentation that was robust at point of registration but has not evolved with the business. Risk assessments referencing a product set that no longer exists, or MLRO sign-offs that pre-date a significant expansion into higher-risk customer segments, are common findings. The FCA has been explicit that AML/CFT expectations for crypto firms are not lower than those for equivalent regulated entities in other sectors.
A third – and increasingly visible – failure point is the financial-promotion gap. Firms correctly registered under the MLR have issued marketing communications without ensuring they are compliant with the FCA's crypto promotion rules, or without having those communications approved by an authorised person. The FCA has taken enforcement action in this area and has publicly named firms for non-compliant promotions.
In a recent matter, a payments and custody firm operating out of the UK and an EU member state had allowed its UK registration description to fall materially out of date following a custody product launch. We reviewed the full registration file, prepared a variation application and updated the AML/CFT documentation to reflect the live product set. The variation was submitted before a scheduled FCA supervisory outreach and the firm was able to respond to the regulator from a position of current compliance rather than reactive remediation.
The FCA's broader crypto regulatory roadmap and what it means for registered firms
The FCA's current MLR registration is a transitional mechanism. The UK government has been developing a fuller regulatory regime for cryptoasset activities that would move firms from registration to formal authorisation, closer to the model applied to investment firms and payment institutions under the Financial Services and Markets Act.
The direction of travel is toward higher standards – more granular fitness-and-propriety assessments, capital or resource requirements, consumer-duty obligations and conduct rules applied to cryptoasset business. Firms that have maintained clean, well-documented registrations and strong AML/CFT controls will be better positioned to transition to the authorisation regime. Firms that have deferred compliance will face that transition from a more difficult starting position.
For inbound businesses – particularly those considering the UK as a hub alongside an EU MiCA-authorised entity – the question is not whether to engage with the FCA regime, but how to structure that engagement to anticipate the authorisation pathway. We advise clients to treat the current registration as a pilot authorisation: build the governance, documentation and control infrastructure now, and the transition cost will be materially lower.
If a prior FCA application stalled or your registration is out of date with your current business, contact OBOLUS at info@oboluslaw.com. A second read can surface the structural gap and the route forward before the FCA raises it first.
Decision logic: which profile needs what action now
The right action depends on where the firm sits in its regulatory lifecycle. Three profiles recur in our practice.
A firm registered under the MLR that has expanded its product set since initial registration needs a variation application. The priority is to audit the gap between the registered description and the live business, update the AML/CFT documentation, and submit the variation before the next supervisory interaction. The timeline for that process varies by complexity, but early action is always preferable to reactive disclosure.
A firm approaching the market for the first time – typically an EU-licensed entity expanding into the UK, or a non-EU group building a multi-jurisdiction stack – needs to assess whether its planned UK activity triggers MLR registration requirements, whether the financial-promotion rules apply to its communications directed at UK persons, and how the UK entity sits within the broader group structure from a tax and banking perspective. Those three questions interact, and they should be resolved together before the entity is established.
A firm that is already registered and operating cleanly needs an ongoing compliance programme: annual AML/CFT policy review, change-notification protocols embedded in its governance, and a marketing-approval process for all communications that could reach UK persons. The cost of that programme is a fraction of the cost of a supervisory investigation.
Banking and tax interaction for UK-registered crypto firms
Registration under the MLR does not resolve banking. UK banks and EMIs remain cautious in their approach to crypto-business onboarding, and a current FCA registration is necessary but rarely sufficient. Firms typically need to demonstrate a clear and documented business model, a clean AML/CFT framework and an identifiable, verifiable customer base before a UK banking relationship is established. The due-diligence expectations from the banking side broadly mirror those of the FCA itself – which means a well-prepared registration file also accelerates banking onboarding.
From a tax perspective, the UK's approach to cryptoassets is set by HMRC guidance: exchange tokens, utility tokens and security tokens each attract different treatment for corporation tax, VAT and capital gains purposes. The tax position of a UK-registered entity that holds or transfers tokens as part of its business operations needs to be assessed at the structuring stage, not as an afterthought when the first set of accounts is prepared. For groups with entities in multiple jurisdictions, transfer pricing and permanent establishment considerations add a further layer.
We have seen groups optimise the licence architecture while leaving the tax structure misaligned – resulting in a well-licensed business with an avoidable tax exposure. The licence, the banking and the tax stack should be mapped together.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – how we scope and manage licence applications across 70+ jurisdictions.
- How to choose a crypto licensing jurisdiction – a decision guide covering the principal operating and holding hubs.
- Crypto fraud and asset recovery in Georgia – cross-border recovery options for businesses with Georgian nexus.
FAQ
How long does a crypto licence take to obtain?
Under the FCA's MLR registration process, timelines vary materially by the completeness of the application and the complexity of the business model. A well-prepared first application from a straightforward business has historically resolved in a matter of months; more complex applications or those requiring additional FCA queries take considerably longer. Under the anticipated full authorisation regime, timelines are expected to extend further. Early preparation of the AML/CFT documentation and the business-model description is the single most reliable way to reduce the time in process.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right jurisdiction depends on where your users are, where your banking counterparties sit, what activities you perform and what regulatory relationships you need to maintain. For a business serving EU persons, a MiCA CASP authorisation from a member state provides a passport; the UK does not benefit from that passport post-Brexit. A common structure pairs a UK-registered entity for domestic activity with an EU-authorised entity for continental operations, and possibly a third jurisdiction for holding or custody. We map that stack for each client before any entity is incorporated.
Do I need a separate custody licence?
In the UK, custody of cryptoassets is a registerable activity under the MLR where it falls within the defined VASP activity categories. A firm registered solely as an exchange that begins holding client assets in a custody arrangement – even incidentally – may be operating outside its registered scope. Under the anticipated full authorisation regime, custody is expected to be treated as a discrete regulated activity with its own requirements. Firms planning to offer custody services should assess whether a variation to their current registration is needed and how to position for the authorisation regime ahead of the transition.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence, banking and tax stack across operating, custody and payment layers before you commit to a structure – so the architecture holds under regulatory scrutiny from day one. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in FCA registration management, multi-jurisdiction licensing architecture and VASP authorisation across the UK and EU.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.