EST · MMXXVI
Home/Jurisdictions/United Kingdom/VASP licence application in United Kingdom
Licensing & Registration

VASP licence application in United Kingdom

Vasp licence application in United Kingdom. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

The UK Crypto Registration Regime: What an Inbound Business Faces

Operating a virtual asset service provider (VASP) – a business offering crypto exchange, custody, transfer or related services – in the United Kingdom without the right regulatory standing exposes that business to criminal prosecution, civil enforcement, frozen payment rails and abrupt account closure. The Financial Conduct Authority (FCA) administers the UK regime under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations, commonly called the Money Laundering Regulations (MLR), which require every cryptoasset business carrying on activity in the UK to register before it begins operating. MiCA has no territorial effect in the UK post-Brexit; the FCA operates its own independent regime. Regulators in the leading hubs increasingly expect businesses to hold registration before onboarding UK-based clients, not after.

A VASP licence application in the United Kingdom is, strictly speaking, a registration rather than a full licence – but the FCA's gatekeeping is substantive. The regulator applies a rigorous fitness-and-propriety test, a detailed AML/CFT systems review and, for any business touching financial promotions, a separate approval obligation. The process involves multiple assessment stages, and the FCA has historically used a meaningful rejection rate to signal supervisory seriousness.

This page maps the UK registration process from first principles: who must register, what the FCA looks for, how the cross-border reality of a multinational crypto business complicates the application, and where common applications go wrong.


Who Must Register with the FCA?

Any business carrying on cryptoasset activities in the UK – or targeting UK customers from abroad – is within scope of the MLR registration requirement. The FCA's territorial reach is not limited to UK-incorporated entities. A Cayman-incorporated exchange onboarding UK retail users, a BVI custody vehicle offering services to UK family offices, or a Malta-based token issuer marketing to UK professional investors may all fall within the obligation, depending on where the activity is directed and where the customer is located.

The FCA treats the following as core in-scope activities: exchanging cryptoassets for fiat or other cryptoassets, operating a cryptoasset exchange platform, executing cryptoasset orders, and providing custody or administration of cryptoassets on behalf of clients. Token issuance alone does not typically trigger FCA cryptoasset registration, but it may trigger the financial-promotions regime separately.

Critically, the UK also applies financial-promotion rules to cryptoasset marketing. Since October 2023, a business communicating a financial promotion relating to a "qualifying cryptoasset" must either be FCA-authorised for that purpose or have its communication approved by an FCA-authorised person. This is a distinct obligation from MLR registration, and many inbound operators fail to appreciate that they may need both.

In our practice, we regularly advise businesses that assumed their EU or offshore registration created a lawful basis to serve UK users. That assumption is incorrect. The UK left the EU regulatory perimeter at the end of the Brexit transition period, and MiCA passporting has no effect in the UK. Each regime must be addressed independently.


What Does the FCA Actually Assess?

The FCA's cryptoasset registration assessment turns on four pillars: the fitness and propriety of controllers and beneficial owners; the adequacy of the AML/CFT systems and controls; the business model and the risk it presents; and, for certain activities, the operational resilience of the platform.

Fitness and propriety means the FCA will scrutinise every individual who holds a qualifying interest in the applicant entity – typically any person holding ten percent or more of the shares or voting rights. Criminal records, regulatory sanctions in other jurisdictions, insolvency history and adverse civil findings all count against an applicant. The FCA has declined applications where a controller held a prior adverse finding from a non-UK regulator, even where that finding involved a different business. Controllers must expect a thorough review.

The AML/CFT systems review is where many applications stall. The FCA expects a documented risk assessment that is specific to the business's product, client profile and geographic footprint. A generic AML policy copied from a third-party template is unlikely to satisfy the regulator. The FCA wants to see that the business has identified its highest-risk client types and transaction flows and has designed controls proportionate to those risks – including Travel Rule compliance (the obligation, originating from FATF Recommendation 15, to pass originator and beneficiary information alongside virtual asset transfers).

The FCA publishes detailed guidance on the standards it expects. In our cross-border practice, we have seen applications rejected not because the applicant lacked controls, but because those controls were not documented to a standard that evidenced senior management ownership. Regulators want to see the board, not only the compliance team, visibly responsible for AML governance.


If you are assessing whether your business needs FCA registration or a financial-promotion approval, the right time to get a legal read is before you onboard your first UK customer. The process above describes the standard path. Your facts – the entity structure, the user base, the product mix, the banking – change the analysis materially. Map your options with OBOLUS before you commit.


How Does the FCA Registration Process Work in Practice?

The FCA registration process for cryptoasset businesses proceeds through several defined stages, each with distinct documentation requirements and decision points. Understanding the sequence matters: a premature or incomplete filing wastes months and, in some circumstances, triggers a formal rejection that must be disclosed in future applications to other regulators.

The process begins with pre-application preparation. This means incorporating or confirming the UK entity structure, completing a detailed gap analysis of the existing AML/CFT framework against FCA expectations, conducting fitness-and-propriety reviews on all controllers, and preparing the full application pack. The application pack typically comprises: a detailed business description; an AML/CFT policies-and-procedures document; a risk assessment covering clients, products and geographies; a financial crime compliance framework including sanctions screening, transaction monitoring and suspicious activity reporting procedures; a management structure chart; and individual questionnaires for all qualifying controllers.

The FCA then conducts an initial completeness review. Incomplete applications are returned. Once an application is accepted as complete, the substantive assessment begins. The FCA may issue information requests during this period – effectively supplementary questions seeking clarification or additional evidence on specific points. Failure to respond promptly or comprehensively to an information request is itself grounds for the FCA to refuse the application.

The FCA does not publish a binding decision timeline. In our experience, and consistent with industry-wide observation, processing timelines have varied considerably. Businesses should plan for the process to extend over multiple months. Where an application presents novel features – a complex controller structure, multi-jurisdictional ownership, an unusual product – the timeline tends to extend further.

If the FCA proposes to refuse, the applicant receives a warning notice and has an opportunity to make representations. A final decision notice follows. The applicant may refer a refusal to the Upper Tribunal (Tax and Chancery Chamber), but that is a costly and time-consuming route that few businesses elect to pursue.


What Is the Cross-Border Reality for an Inbound Operator?

Most businesses applying for FCA cryptoasset registration are not UK-only operations. They are multinational digital-asset businesses – exchanges, custodians or token platforms – that hold one or more licences or registrations in other jurisdictions and are adding the UK to their regulatory map. This cross-border reality creates a specific set of complications that a purely domestic application does not.

The first is group structure. The FCA assesses the applicant entity, but it also looks through the group to understand the ultimate beneficial owners and the wider regulatory posture of the group. A group that holds a VARA licence in Dubai, a CASP authorisation (Crypto-Asset Service Provider authorisation) under MiCA in an EU member state, or a Payment Services Act digital-payment-token licence from the MAS in Singapore will be scrutinised for the quality of group-level AML governance and whether group policies are consistent across jurisdictions. Inconsistency between the UK-facing AML framework and the group's broader policies raises questions the FCA is likely to ask.

The second is banking. UK banks retain significant discretion over whether to provide accounts to cryptoasset businesses, including FCA-registered ones. Registration is a necessary condition for accessing UK financial infrastructure, but it is not sufficient. Many operators find that, even after completing FCA registration, banking relationships require their own protracted negotiation. We map both the regulatory and the banking access questions together – the licence without the bank account solves only half the problem.

The third is financial promotions. An EU-licensed business that markets to UK users without FCA-authorised promotion approval is in breach of UK law regardless of its home jurisdiction's authorisation. Post-Brexit, the FCA has actively enforced this obligation, and the reputational consequences of an enforcement finding in the UK damage licence applications in other jurisdictions.

A fourth consideration is data. The UK operates its own data-protection regime under the UK GDPR and the Data Protection Act. Businesses transferring customer data between the UK entity and group entities in non-adequate jurisdictions must address data-transfer mechanisms. This is a live issue for businesses with data infrastructure in the UAE, Singapore or the United States.


What Are the Most Common Reasons UK Crypto Applications Fail?

FCA cryptoasset registration applications fail for a consistent set of reasons, most of which are avoidable with adequate preparation.

The most frequent cause is an AML/CFT framework that is not calibrated to the specific business. The FCA does not expect perfection on day one, but it expects evidence that the business understands its own risk profile and has designed proportionate controls. Generic frameworks, undated risk assessments, and policies that reference EU-specific regulatory language (a sign the document was recycled from an MiCA application) all raise red flags.

The second most common cause is a controller structure that has not been pre-screened. Businesses with complex holding structures – layers of BVI or Cayman holding companies, ultimate beneficial owners in sanctioned or high-risk jurisdictions, or controllers with prior adverse findings – face a much harder path. The FCA is systematic about UBO verification, and surprises discovered mid-process are difficult to correct after filing.

Third is an underestimation of the financial-promotions obligation. Many inbound operators focus exclusively on the registration question and are unaware that their existing marketing materials and website content may already be in breach of UK financial-promotions rules. The FCA can take enforcement action in respect of unlawful promotions independently of the registration process.

Fourth – and underappreciated – is the absence of a UK nexus. The FCA has, in some cases, questioned whether a thin UK subsidiary with no genuine operations, staff or senior management presence meets the substantive requirements for registration. A letterbox entity is unlikely to succeed.

In our cross-border practice, we have seen all four failure modes. Each is addressable, but only if it is identified before filing – not after a warning notice has issued.


A Recent Example: Restructuring Before Filing

In a recent matter, a digital-asset exchange holding an existing registration in a Gulf jurisdiction sought to expand into the UK market. The group had a layered holding structure, with the operating entity three levels below the ultimate parent. During our pre-filing review, we identified that one of the intermediate holding companies had a majority shareholder who had previously been subject to an adverse finding by a non-UK regulator – a fact not flagged during the client's own internal review. We worked with allied counsel in the relevant jurisdiction to restructure the intermediate holding layer before filing, removing the controller question from the application entirely. The application was submitted on a clean basis and proceeded without an information request on controller fitness. The exchange subsequently completed its UK registration within the expected timeline.


Which Profile Should Apply Directly – and Which Should Restructure First?

The right path to UK FCA registration depends heavily on the applicant's starting position. Different operator profiles face different risk factors and preparation requirements.

Profile A: An EU-licensed CASP under MiCA with clean controllers and a UK subsidiary already in place. This operator is closest to a straightforward application. The group's AML framework will need UK-specific adaptation (MiCA and UK MLR are not identical), and the financial-promotions posture must be reviewed. But the underlying compliance infrastructure is likely to be serviceable. Indicative preparation-to-filing timeline: measured in weeks to a few months. Key risk: underestimating the financial-promotions gap.

Profile B: A VARA-licensed exchange expanding from Dubai with a complex group structure. The VARA rulebooks are substantive, and a VARA-licensed operator typically has a well-developed AML framework. However, the group structure must be analysed for UK controller-fitness purposes, and the banking question in the UK is distinct from the regulatory question. Indicative preparation-to-filing timeline: several months, longer if restructuring is required. Key risk: controller-screening surprises and the banking gap after registration.

Profile C: A startup with no prior regulatory registration, seeking a UK entity as its first regulated presence. This is the highest-difficulty path. The FCA expects a credible, operational compliance framework – not a plan to build one. Without prior regulatory experience, the applicant must invest in building AML governance from scratch, and must demonstrate that senior management has genuine experience in financial crime compliance. Indicative preparation-to-filing timeline: six months or more is not unusual. Key risk: under-resourced AML function and an inability to respond adequately to FCA information requests.

In our practice, we regularly advise businesses at all three stages. The consistent lesson is that the preparation phase determines the outcome far more than the filing itself.


If your application stalled, or if a prior registration attempt was rejected by the FCA, a structured second review can surface the reason and the route forward. We have worked through complex controller and AML remediation situations before refiling. Contact OBOLUS to discuss your position.


Addressing a Common Assumption: Is a Single Offshore Registration Enough?

A common assumption among operators expanding internationally is that a well-regarded offshore registration – whether in the Cayman Islands under CIMA, the BVI under the VASP Act 2022, or a smaller jurisdiction – provides a sufficient regulatory basis to serve clients in the UK. That assumption is wrong, and acting on it carries serious consequences.

The UK MLR applies to any cryptoasset business that carries on activity by way of business in the UK, regardless of where the business is incorporated or licensed. "Activity in the UK" encompasses directing services at UK-resident customers. The FCA does not recognise equivalence with offshore registration frameworks for this purpose. Operating in the UK without MLR registration is a criminal offence. The FCA has the power to impose civil financial penalties, issue public censures, require business cessation and – in serious cases – refer matters to the Crown Prosecution Service.

The practical consequence is that businesses with offshore structures serving UK clients must either register the relevant entity in the UK or restructure to ensure that UK-resident customers are served only through a UK-registered entity. Neither path is without cost or time. Building the registration obligation in from the start is always cheaper than remediation.


Related at OBOLUS


FAQ

How long does a crypto licence take to obtain?

In the United Kingdom, the FCA does not publish a binding decision timeline for cryptoasset registration. Processing times have varied considerably across applications, and businesses should plan for a process measured in multiple months from the date of a complete application. Complexity – including layered controller structures, multi-jurisdictional group ownership, or novel product features – typically extends the timeline. Preparation before filing materially affects total elapsed time.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on where your customers are, where your banking will sit, what activities you carry on, and your growth roadmap. The UK is necessary for businesses targeting UK users; it is not a substitute for EU authorisation under MiCA, a VARA licence in Dubai, or MAS licensing in Singapore. Most scaled operators require a multi-jurisdiction licence stack. We map that stack against the specific business before recommending a sequencing.

Do I need a separate custody licence?

Under the UK MLR regime, custody of cryptoassets on behalf of clients is an in-scope cryptoasset activity that requires registration. If the same entity carries on both exchange and custody activities, a single registration covering both activities is the typical structure. However, where custody is provided through a structurally separate entity – common in institutional models – that entity must register independently. The position is assessed entity by entity, not at group level.


OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that the structure is right before the first regulatory filing, not after. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound VASP registration strategy and multi-jurisdiction licence structuring for digital-asset businesses entering regulated markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours