AML & Financial Crime

FCA Crypto Authorisation in 2026: What Compliance Teams Should Prepare Before the Gateway Opens

FCA crypto authorisation requires a coherent operating model connecting permissions, governance, financial crime controls, outsourcing and evidence rather than a policy-heavy application pack.

By Jonas Adam Mohamed Osman AbdelghafourPublished 27 August 2026Last reviewed 27 August 2026

Why this matters now

ICA highlighted FCA crypto authorisation as an August 2026 priority, with the new gateway expected to open on 30 September 2026. The key compliance lesson is that authorisation is not a document-production exercise. Firms need to demonstrate that the proposed regulated business, governance and controls form one coherent operating model.

Map activities before drafting

Crypto firms should identify exactly which activities each legal entity performs, which customer types are served, where assets and funds flow, which permissions are required and where third parties are involved. Weak activity mapping creates inconsistencies throughout the application.

Regulatory business plan

The regulatory business plan should explain the actual operating model, not repeat marketing language. It should connect products, customer journeys, revenue, governance, risk appetite, technology, outsourcing and financial crime controls.

Evidence, not policy libraries

Policies matter, but regulators need to understand whether controls are embedded. Firms should be able to show governance minutes, management information, compliance monitoring, financial crime risk assessments, onboarding evidence, transaction-monitoring governance, wallet-screening processes, incident records and oversight of outsourced providers.

Financial crime risk

Crypto businesses need a coherent framework for customer risk, blockchain analytics, sanctions, source of funds, transaction monitoring, wallet exposure, fraud and suspicious activity reporting. Each component should align with the stated business model.

Ongoing supervision

Authorisation should be treated as the beginning of the supervisory relationship. Firms that build application packs around a temporary target state risk failing immediately after approval. The correct objective is a sustainable compliance architecture.

Conclusion

The strongest crypto applications will be those that tell one consistent story: what the firm does, who is accountable, what can go wrong, how risks are controlled and what evidence shows that those controls actually operate.

Related reading

See Regulatory Compliance, AML & Financial Crime and Governance, Risk and Compliance.

About the author

Jonas Adam Mohamed Osman Abdelghafour is a risk and compliance expert advising banks, insurers, payment institutions and asset managers on governance, financial crime, AI oversight and enterprise risk across UK and EU regimes. See qualifications and services, or get in touch to discuss an engagement.

*This article discusses regulatory frameworks in general terms and is not legal advice. Jurisdictional interpretation should be confirmed with qualified counsel.*

Sources

The International Compliance Association is cited here as an editorial source for current compliance issues. No affiliation with, or endorsement by, the ICA is claimed or implied.

Frequently asked questions

Why this matters now?

ICA highlighted FCA crypto authorisation as an August 2026 priority, with the new gateway expected to open on 30 September 2026. The key compliance lesson is that authorisation is not a document-production exercise. Firms need to demonstrate that the proposed regulated business, governance and controls form one coherent operating model.

What should risk leaders know about map activities before drafting?

Crypto firms should identify exactly which activities each legal entity performs, which customer types are served, where assets and funds flow, which permissions are required and where third parties are involved. Weak activity mapping creates inconsistencies throughout the application.

What should risk leaders know about regulatory business plan?

The regulatory business plan should explain the actual operating model, not repeat marketing language. It should connect products, customer journeys, revenue, governance, risk appetite, technology, outsourcing and financial crime controls.

What should risk leaders know about evidence, not policy libraries?

Policies matter, but regulators need to understand whether controls are embedded. Firms should be able to show governance minutes, management information, compliance monitoring, financial crime risk assessments, onboarding evidence, transaction-monitoring governance, wallet-screening processes, incident records and oversight of outsourced providers.

What should risk leaders know about financial crime risk?

Crypto businesses need a coherent framework for customer risk, blockchain analytics, sanctions, source of funds, transaction monitoring, wallet exposure, fraud and suspicious activity reporting. Each component should align with the stated business model.