Think you can just set up a crypto exchange in London and start trading? Think again. The days of the "Wild West" for digital assets in the UK are long gone. If you’re running a crypto business here, you’re operating under one of the strictest Anti-Money Laundering (AML) regimes in the world. And if you think you’ve got it figured out based on what was true two years ago, you might be walking into a trap.
As of September 2026, the regulatory landscape has shifted dramatically. The Financial Conduct Authority (FCA) isn’t just watching; they’re actively purging non-compliant firms. Recent data shows that nearly 90% of initial applications failed. Why? Because most businesses underestimate the depth of customer due diligence required. This guide breaks down exactly what you need to do to survive-and thrive-under the current rules, including the massive changes coming with the transition to the new FSMA framework.
The Core Regulatory Framework: MLRs and Beyond
At the heart of your compliance obligations lies the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, commonly known as the MLR 2017. While this regulation predates the crypto boom, it was expanded significantly in January 2020 to explicitly cover cryptoasset exchange providers and custodian wallet providers. But don’t let the date fool you. The rules have evolved through multiple amendments, most notably with draft regulations published in April 2025 that tightened requirements further.
You aren’t just dealing with old laws. You are navigating a dual regime. Until the full implementation of the Financial Services and Markets Act (FSMA) framework-which is now fully active in late 2025 and into 2026-you operate under both the traditional AML rules and emerging financial services standards. This creates a complex web where you must satisfy the FCA’s AML supervision while preparing for broader licensing requirements. HM Treasury oversees the legislative side, but the FCA holds the keys to your operational license.
| Entity | Primary Role | Key Responsibility |
|---|---|---|
| FCA | Primary Regulator | Registration, supervision, enforcement of AML rules |
| HM Treasury | Legislative Oversight | Drafting regulations, setting policy direction |
| Bank of England | Systemic Risk | Assessing stability risks posed by crypto markets |
| OFSI | Sanctions Enforcement | Screening transactions against sanctions lists |
Who Needs to Register? It’s Broader Than You Think
A common mistake is assuming only big exchanges like Coinbase or Binance need to worry. If you offer any service that involves exchanging virtual currencies for money or vice versa, or if you provide custody services, you likely fall under the scope. This includes peer-to-peer platforms, brokers, and even some DeFi interfaces if they act as intermediaries.
The definition of a "cryptoasset business" hinges on whether you are carrying out these activities "by way of business." If you’re doing it occasionally for friends, you’re probably fine. If you’re charging fees, marketing your services, and processing regular transactions, the FCA expects you to register. Failure to register before starting operations is a criminal offense. Yes, you read that right. Operating unregistered can lead to prosecution, not just fines.
As of mid-2025, there were only about 147 registered firms on the FCA register, down from over 180 earlier in the year. This attrition highlights how difficult it is to stay compliant. Many firms simply couldn’t meet the ongoing monitoring standards and chose to exit the market rather than face enforcement action.
Customer Due Diligence: The Heartbeat of Compliance
If you take nothing else from this article, remember this: Customer Due Diligence (CDD) is not a box-ticking exercise. It’s a continuous process. Under the updated guidelines, you must identify and verify your customers using at least two independent sources of information. For individuals, this usually means government-issued ID plus proof of address. For corporate entities, you need to drill down to the ultimate beneficial owners (UBOs).
Here is where things get tricky for crypto. Traditional banks rely heavily on credit scores and employment history. In crypto, you often lack that historical data. So, you need to lean harder on behavioral analysis. Where did their funds come from? Is the wallet address associated with high-risk jurisdictions? The FCA expects a risk-based approach. If a customer is sending large volumes from a mixmaster service, you need to ask questions. If they are a Politically Exposed Person (PEP), you need Enhanced Due Diligence (EDD).
Recent amendments lowered the threshold for notifying changes in control from 25% to 10%. If someone buys 10% of your company, you must notify the FCA. This is stricter than the EU’s 20% standard, reflecting the UK’s precautionary stance on ownership transparency. Don’t ignore small share transfers; they can trigger significant regulatory reporting duties.
The Travel Rule: Tracking the Money Trail
You’ve heard of the Travel Rule, but are you actually implementing it correctly? Implemented in 2022 and refined since, this rule requires you to collect and share specific information for transactions exceeding £1,000. This includes the name, account number, and address of both the originator and the beneficiary.
The challenge isn’t collecting this data; it’s sharing it securely with other institutions. If you send Bitcoin to an exchange in Singapore, do they know who sent it? If you receive Ethereum from a US firm, do you know who owns the wallet? Non-compliance here is a frequent cause of failed registrations. About 40% of firms initially struggled with transaction monitoring systems capable of handling this volume of data in real-time.
Don’t rely on manual checks. With millions of transactions flowing through the sector annually, automation is key. You need blockchain analytics tools integrated directly into your KYC workflows. These tools flag suspicious patterns, such as rapid movement of funds through multiple wallets (layering) or interactions with sanctioned addresses.
Common Pitfalls That Kill Registrations
Why do so many firms fail? The FCA’s threat assessment reveals three main culprits: inadequate risk assessments, insufficient senior management oversight, and poor transaction monitoring. Let’s unpack these.
- Inadequate Risk Assessments: Many firms use generic templates. The FCA wants a bespoke assessment tailored to your specific business model, customer base, and geographic reach. If you serve clients in high-risk countries, your risk rating must reflect that.
- Senior Management Oversight: You can’t just hire a compliance officer and walk away. Senior managers must demonstrate they understand the risks. They need to be involved in decision-making, not just signing off reports. If the FCA interviews your board and they can’t explain your AML controls, you’ll fail.
- Poor Transaction Monitoring: False positives are a plague. Industry data suggests crypto firms experience false positive rates of nearly 30%, compared to 12% in traditional banking. If your system flags every legitimate trade as suspicious, your team will suffer alert fatigue and miss real threats.
Another major issue is the interpretation of "Politically Exposed Persons." Crypto firms often apply EDD too broadly or too narrowly. There is no one-size-fits-all answer. You must document why you classified someone as a PEP and what steps you took to mitigate the risk.
Costs and Timelines: Preparing for the Reality
Compliance isn’t cheap. According to recent industry surveys, the average cost for initial compliance setup is around £287,500. Ongoing annual costs hover around £142,300 per firm. These figures include software licenses, legal advice, staff training, and external audits.
Time is another critical factor. The FCA states that firms should complete registration within three months of commencing business. However, reality tells a different story. The average processing time is over nine months. Most successful applicants spend six to nine months just preparing their application. Rushing this phase leads to rejections and costly delays.
Many firms hire external consultants because the internal expertise gap is wide. Nearly 80% of registrants used third-party advisors. While this adds to the cost, it often saves money in the long run by avoiding the expensive cycle of resubmission and remediation.
Looking Ahead: The FSMA Transition
We are currently living through a pivotal moment. The transition from the standalone AML registration to the comprehensive FSMA licensing regime is underway. By early 2026, the dual regime will largely disappear, replaced by a unified licensing structure. This aims to reduce the regulatory burden for compliant firms by targeting a 40% reduction in administrative overhead by 2027.
However, this consolidation comes with a catch. Analysts predict that the number of regulated crypto entities could drop by 35-40% as smaller players fold or merge. The UK is positioning itself as a "premium but selective" jurisdiction. You won’t see thousands of tiny startups popping up overnight. Instead, expect a market dominated by well-capitalized, highly compliant firms.
If you are planning to enter the UK market now, assume the bar will be raised, not lowered. The focus is shifting from mere registration to sustained operational excellence. The Bank of England has warned that regulatory uncertainty during transitions can drive investment elsewhere, but those who stick it out gain credibility that opens doors to institutional partnerships.
Practical Steps for Compliance Success
So, what should you do today? Here is a checklist to keep you on track:
- Audit Your Current State: Do you have a documented AML policy? When was it last updated? If it’s older than six months, refresh it.
- Review Your Tech Stack: Can your systems screen against 12+ sanctions lists in real-time? If not, upgrade immediately. OFSI reported that 41% of firms failed this basic requirement initially.
- Train Your Team: Compliance staff need at least 35 hours of specialized training annually. General finance knowledge isn’t enough. They need to understand blockchain forensics.
- Engage Early with the FCA: Don’t wait until you’re ready to launch. Start conversations with the regulator early. Their expectations can change, and early feedback is invaluable.
- Document Everything: Keep records for five years. Every decision, every risk assessment, every customer interaction needs a paper trail. If you can’t prove it, it didn’t happen.
The UK’s AML rules for crypto are tough, but they are clear. The ambiguity that plagued the early years has been replaced by rigorous standards. For businesses willing to invest in robust compliance infrastructure, the rewards are substantial access to the UK’s deep liquidity pools and institutional capital. For those hoping to cut corners, the door is firmly shut.
Do I need to register with the FCA if I only handle stablecoins?
Yes, generally speaking. If you are exchanging fiat currency for stablecoins or vice versa as part of a business activity, you are considered a cryptoasset exchange provider. The type of token doesn’t exempt you from the Money Laundering Regulations. You must assess your specific business model, but pure peer-to-peer transfers without intermediation might differ. Always seek professional advice if unsure.
What happens if my FCA application is rejected?
If your application is rejected, you typically have a short window to appeal or submit a new application after addressing the deficiencies. During this time, you cannot carry out regulated activities. Continuing to operate without approval can result in criminal charges. Many firms choose to cease operations temporarily until they secure approval to avoid penalties.
How does the Travel Rule affect small transactions?
The Travel Rule applies to transfers exceeding £1,000. For transactions below this threshold, you still need to perform Customer Due Diligence, but you may not need to transmit the full originator and beneficiary details to the counterparty institution. However, you must retain this information internally for audit purposes.
Are NFTs covered by UK AML regulations?
It depends on the function of the NFT. If an NFT acts primarily as a payment method or a store of value similar to a cryptocurrency, it may fall under the definition of a cryptoasset. If it is purely a unique digital collectible with no fungibility or payment utility, it might be excluded. However, the FCA takes a substance-over-form approach, so if it functions like money, it’s likely regulated.
Can I outsource all my AML compliance?
You can outsource tasks like identity verification and transaction monitoring to third-party providers. However, the responsibility for compliance remains with your business. You cannot outsource accountability. Senior management must oversee the outsourced processes and ensure they meet FCA standards. Regular audits of your vendors are essential.
More Articles
Sterling Finance Crypto Exchange Review: Is It Safe or a Scam in 2026?
Sterling Finance review reveals critical risks: near-zero liquidity, 88% price drop, and confusion with a fraudulent broker. Avoid STR token due to extreme slippage and abandoned status.