Cases
Supervision
Authorisation
Regulatory Perimeter
© 2026 Dentons. All rights reserved. Attorney Advertising. Dentons is a global legal practice providing client services worldwide through its member firms and affiliates. This website and its publications are not designed to provide legal or other advice and you should not take, or refrain from taking, action based on its content.
Crypto Hub Financial Regulation
Keeping pace with evolving financial regulation of cryptoassets is an essential part of doing business in the UK. The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 is reshaping how cryptoassets are regulated in the UK. This dedicated portal provides short informative guides to assist firms preparing for cryptoasset regulation. Please check in with the team for the latest updates and to discuss the further support we can provide, including toolkits and training on the new regime and FCA regulation.
Katharine HarlePartner D +44 20 7320 6573
Email
Andrew BarberPartnerD +44 20 7246 7291
Lauren O’RiordanSenior AssociateD +44 20 7246 7493
Jess CookeSenior Associate D +44 20 7246 7073
Ann ZhengSenior Associate D +44 20 7246 7025
Venetia JacksonCounselD +44 20 7246 7783
Your key contacts
Sophia RahmanAssociateD +44 20 7320 3849
Jane BassettAssociate D +44 20 7246 7628
Nicole McAnultyAssociate D +44 131 228 7071
Crypto-readiness diagnostic tool
Regulatory & Investigations team contacts:
Zeena SalehPartnerD +44 20 7320 3830
Jo DimmockPartner D +44 207 246 7659
Additional contacts
Chris BrennanPartner D +44 20 7246 7746
Craig NeilsonPartner D +44 33 0222 1912
Joe CollingwoodPartner D +44 20 7320 5494
Territorial Scope
July, 2026
Read more
Assets and Activities
Stablecoin regulation in the UK
August, 2026
Cryptoasset regulation in the UK: the current framework and the road to October 2027
Cryptoassets Series
July 2026
The UK's approach to cryptoasset regulation is undergoing its most significant transformation since the emergence of the sector. Historically, cryptoasset businesses have only fallen within the UK's regulated activities regime where their activities involved existing specified investments. From October 2027, a bespoke regulatory framework will bring a much wider range of cryptoasset activities within the regulated activity perimeter. This article summarises the current position, upcoming changes and key steps firms should be taking now.
The UK's financial services framework is primarily contained in the Financial Services and Markets Act 2000 (FSMA). In accordance with the "general prohibition" at section 19 FSMA, unless an exclusion or exemption applies, a person cannot carry on a regulated activity by way of business in the UK, unless they are authorised by the FCA or PRA. A regulated activity generally arises where an activity specified in the Financial Services and Markets Act 2000 (Regulated Activities) Order 2001 (RAO) is carried on in relation to a specified investment. Breaching the general prohibition is a criminal offence and can result in agreements being unenforceable and regulatory enforcement action. For crypto firms considering the application of the regulated activities regime to their business, the key question has traditionally been whether a cryptoasset falls within an existing category of specified investment. However, this is all set to change on 25 October 2027.
What is the UK's regulated activities regime and why does it matter for crypto firms?
In PS19/22, the FCA explained how the existing regulated activities regime applies to cryptoassets. The FCA emphasised that the legal and regulatory treatment of a token depends on its rights and characteristics rather than the terminology used by the issuer. In summary:
How are cryptoassets regulated under the existing regulated activities regime
Security Tokens
These tokens have characteristics that give rise to rights and obligations similar to those associated with traditional specified investments, such as shares, debt instruments or units in collective investment schemes. As such, security tokens include, for example, tokenised shares and tokenised bonds.
Exchange Tokens
Token Type
Description
Regulatory Status
Security tokens are within the scope of the existing regulated activities regime. The term has evolved to be used as shorthand for any token that is a specified investment of any kind (other than e-money, which falls into its own distinct category).
These are cryptoassets that are neither issued nor backed by a central authority and are designed primarily to function as a means of exchange. They are typically decentralised and facilitate the purchase and sale of goods and services without the need for traditional intermediaries.
In most cases, exchange tokens fall outside the existing regulated activities regime. This is because, generally, exchange tokens do not grant holders the rights associated with specified investments.
These tokens provide holders with access to an existing or future product or service but do not confer rights equivalent to those attached to specified investments.
Often, utility tokens are not specified investments because they do not grant holders the rights associated with specified investments, such as shares and debt instruments. However, even in those cases, they may still fall within the definition of electronic money (e-money), as may other types of cryptoassets. Where this is the case, activities involving such tokens may be subject to regulation.
Utility Tokens
Subject to certain exceptions, e-money is electronically (including magnetically) stored monetary value as represented by a claim on the e-money issuer that is: (a)
These tokens are subject to the UK's e-money framework established by the Electronic Money Regulations 2011. Firms issuing e-money must ensure they have the correct permissions and follow the relevant rules and regulations.
E-Money
The new regulated cryptoasset activities
What changes are coming under the UK’s new cryptoasset regime?
The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (the "Crypto Regulations") will introduce bespoke regulated activities for cryptoassets. From 25 October 2027, firms carrying on any of the new regulated cryptoasset activities, by way of business in the UK will need to be FCA authorised under Part 4A FSMA, unless an exclusion or exemption applies.
The existing regulated activities relevant to cryptoassets
The Crypto Regulations introduce a new definition of "specified investment cryptoassets" that have always been subject to the regulated activities regime – replacing the FCA's previous taxonomy of cryptoassets set out in PS19/22 – namely, security tokens, exchange tokens and utility tokens. Regulated activities under the existing regime that are relevant to specified investment cryptoassets will continue to be regulated following the introduction of the Crypto Regulations.
The business test
Activities in the UK are only regulated activities if they are carried on "by way of business" (section 22 of the Financial Services and Markets Act 2000). HM Treasury has the power to specify what is meant "by way of business" for any particular activity. In the case of cryptoasset activities, the Crypto Regulations provide that the cryptoasset activities will only be carried out "by way of business" if a person "carries on the business of engaging in" those activities. This test applies to both the new cryptoasset activities and the existing regulated activities relevant to cryptoassets.
Consequences for cryptoasset businesses
As a result, depending on the particular cryptoasset and activity in question, a firm carrying on cryptoasset business with a UK nexus will need to consider: whether they are carrying on one of the new regulated cryptoasset activities in relation to a "qualifying cryptoasset" or "qualifying stablecoin" – or in the case of the new regulated safeguarding cryptoasset activity, in relation to a specified investment cryptoasset; whether they are carrying on an existing regulated activity in relation to a specified investment cryptoasset; and whether in relation to any cryptoasset activity they are carrying on, they are carrying on the business of engaging in that activity.
What are "qualifying cryptoassets", "qualifying stablecoins" and "cryptoasset specified investments"?
issued on receipt of funds for the purpose of making payment transactions; and
accepted by a person other than the electronic money issuer.
(b)
The table below provides a high-level summary of the new regulated cryptoasset activities:
What are the new regulated cryptoasset activities?
Qualifying cryptoassets
Subject to certain exceptions, a qualifying cryptoasset: (a)
Qualifying stablecoins
Qualifying stablecoin is a category of qualifying cryptoassets that is designed, or represented as being designed, to maintain a stable value by reference to a single fiat currency. To support that stable value, fiat currency and/or other assets (commonly referred to as backing assets) are held for that purpose. Qualifying cryptoassets that maintain their value through algorithmic methods or other means without underlying backing assets do not constitute qualifying stablecoin.
In overview, examples of assets excluded from the definition include: e-money, specified investment cryptoassets other than qualifying cryptoassets or e-money (which is separately excluded from the definition), fiat currency, central bank digital currencies – as well as cryptoassets that can only be redeemed with the issuer or used within a "limited network".
is a cryptographically secured digital representation of value or contractual rights that: (i) can be transferred, stored or traded electronically; and (ii) uses technology supporting the recording or storage of data (which may include distributed ledger technology); and
meets the following requirements (i) fungible; (ii) transferable (including where the cryptoasset confers transferable rights); and (iii) not solely record of value or contractual rights (including rights in another cryptoasset).
Subject to certain exceptions, a cryptoasset specified investment: (a)
Examples of assets excluded from the definition include: cryptoassets that can only be redeemed with the issuer or used within a "limited network".
is a cryptographically secured digital representation of value or contractual rights that: (i) can be transferred, stored or traded electronically; and (ii) that uses technology supporting the recording or storage of data (which may include distributed ledger technology);
meets the following requirements (i) fungible; (ii) transferable (including where the cryptoasset confers transferable rights); and (iii) not solely record of value or contractual rights (including rights in another cryptoasset); and
(c)
is a "specified investment" under the RAO (other than a qualifying cryptoasset), including where the asset is a right to or an interest in a specified investment (e.g. a token on a blockchain that represents an interest in or right to an equity).
Specified Investment
Cryptoasset specified investments
Issuing qualifying stablecoins (Article 9M RAO)
A firm established in the UK will be carrying on this regulated activity where they carry-on all of the following components of the activity or arrange for another to do so on their behalf. These are: (a)
(b) (c) The activity is only within scope where all components of the issuance process are carried on in the UK. This includes stablecoins that have been created by the issuer itself or by another member of its group.
offering the stablecoin; undertaking to redeem the stablecoin; and having responsibility for maintaining the stablecoin's value.
Safeguarding of qualifying cryptoassets and specified investment cryptoassets (Article 9N RAO)
This new regulated cryptoasset activity involves: (a) (b) regardless of whether the cryptoasset is owned by the customer or the firm, provided that the safeguarding is on behalf of another person and the firm has the requisite degree of control over the cryptoasset.
Operating a qualifying cryptoasset trading platform (QCATP) (Article 9S RAO)
A QCATP is a system that brings together, or facilitates bringing together, multiple third-party buying and selling interests in qualifying cryptoassets, resulting in transactions where qualifying cryptoassets are exchanged for money (including electronic money) or other qualifying cryptoassets.
Dealing in qualifying cryptoassets as principal (Article 9T RAO)
Buying, selling subscribing for or underwriting qualifying cryptoassets on own account.
the safeguarding of a qualifying cryptoasset or a relevant specified investment cryptoasset on behalf of another person; or arranging for a person to carry on that activity
New Regulated Cryptoasset Activity
Summary
Specified Investment Cryptoassets
Qualifying Stablecoin
Qualifying Cryptoassets
Arranging (bringing about) deals in qualifying cryptoassets (Article 9Y(1) RAO)
Making arrangements for another person (whether as principal or agent) to buy, sell, subscribe for or underwrite qualifying cryptoassets.
Making arrangements with a view to deals in qualifying cryptoassets (Article 9Y(2) RAO)
Making arrangements with a view to a person who participates in the arrangements (whether as principal or agent) buying, selling, subscribing for or underwriting qualifying cryptoassets.
Qualifying cryptoasset staking (Article 9Z6 RAO)
Arranging qualifying cryptoasset staking involves making arrangements on behalf of another person (whether as principal or agent) for blockchain validation using qualifying cryptoassets.
This is not a standalone regulated activity. However, draft FCA guidance (discussed below) explains that, where cryptoasset lending or borrowing involves buying, selling or subscribing for qualifying cryptoassets, it will typically fall within the dealing and/or arranging activities discussed above. The safeguarding activity may also be engaged.
Cryptoasset lending and borrowing
Dealing as agent in qualifying cryptoassets (Article 9W RAO)
Buying, selling subscribing for or underwriting qualifying cryptoassets as agent for another person.
Dealing in investments as principal (Article 14 RAO)
Buying, selling subscribing for or underwriting certain kinds of investments.
Existing Regulated Activity
In addition to the new regulated safeguarding activity, examples of existing regulated activities that are potentially relevant to cryptoasset specified investments include:
What are the existing regulated activities that are relevant to "specified investment cryptoassets"?
Dealing in investments as agent (Article 21 RAO)
Buying, selling, subscribing for or underwriting certain kinds of investment as agent for another person.
Arranging (bringing about) deals in investments (Article 25(1) RAO)
Making arrangements for another person (whether as principal or agent) to buy, sell, subscribe for or underwrite certain kinds of investment.
Making arrangements with a view to transactions (Article 25(2) RAO)
Making arrangements with a view to a person who participates in the arrangements (whether as principal or agent) buying, selling, subscribing for or underwriting certain kinds of investments.
Managing investments (Article 37 RAO)
Managing portfolios containing certain types of assets belonging (beneficially) to another person in circumstances involving the exercise of discretion.
Advising on investments (Article 53 RAO)
buying, selling, subscribing for, exchanging, redeeming, holding or underwriting the investment; or exercising (or not exercising) any right conferred by such an investment to buy, sell, subscribe for, exchange or redeem the investment.
Advising an investor holding certain kinds of investments or prospective investors in such investments on the merits of that person (whether as principal or agent): (a) (b)
Sending dematerialised instructions (Article 45(1) RAO)
This relates to the operation of the system for electronic transfer of title to certain kinds of investments.
Operating a multilateral or organised trading facility (Article 25D and 25DA RAO)
By way of example, venues that provide a platform for certain kinds of investments may potentially be multi-lateral trading facilities (MTFs) or organised trading facilities (OTFs).
In April 2026, the FCA published CP26/13 containing draft guidance for a new chapter of its Perimeter Guidance Manual (the "Draft Guidance"). The Draft Guidance explains the FCA's interpretation of the new cryptoasset perimeter, including when activities are carried on in the UK, how overseas firms may be affected and how the new regulated cryptoasset activities interact with the existing regulated activities framework. Firms should familiarise themselves with the Draft Guidance and review their crypto-related activities to consider whether they will need to obtain FCA authorisation in readiness for 25 October 2027. This will depend on a number of factors including whether: the activities carried on amount to regulated cryptoasset activity; the activities are considered to take place in the UK, or otherwisedeemed to take place in the UK, and so fall within the territorial scope of the regime; the activities are carried on "by way of business" as interpreted for cryptoasset activities; the conditions of any available exclusions are met (where an exclusion applies a firm will not be deemed to carry on the regulated activity to which it relates); and the conditions of any available exemptions apply (such that the firm will be exempt from the FCA authorisation requirement). The FCA consultation on the Draft Guidance closed on 3 June 2026 and the regulator has indicated that final guidance is expected during September 2026.
Next steps
The authorisation gateway will open on 30 September 2026 and close on 28 February 2027. Firms currently registered under the UK's money laundering regime should note that MLR registration will not automatically convert into FCA authorisation. In addition, crypto firms with Part 4A permissions to carry on existing regulated activities may need to apply for a variation of permissions if they intend to carry on any of the new regulated cryptoasset activities.
When can firms apply for authorisation?
Assess whether current or planned activities fall within the new regime.Consider whether new permissions will be required.Prepare your application for authorisation or a variation of existing permissions in time to submit during the application window. Identify staff who will be senior managers early and prepare senior manager applications. Conduct a gap analysis against FCA threshold conditions, FCA rules and expectations on authorisation. Ensure staff training programmes are in place for senior managers and operational staff on the FCA's rules and expectations for cryptoasset firms. For more information on authorisation requirements see our other articles on the Cryptohub. To discuss cryptoasset activities and authorisation, please contact anyone in the Dentons Regulatory & Investigations team.
Key tasks for firms
Back
UK cryptoasset regime: territorial scope
Note: At the time of preparation of this article, whilst final regulations have been made, the FCA has not yet published its final perimeter guidance. The position below reflects the draft guidance as published in CP26/13 and will be updated when the finalised guidance is published.
The UK's regulated activity regime, enshrined in Part 4A of the Financial Services and Markets Act 2000 (FSMA) only applies to regulated activities carried on in the course of business "in the UK". In the absence of an available exclusion or exemption, the UK cryptoasset regime will apply where a person carries on regulated cryptoasset activity in the UK for the purposes of section 19 FSMA (the General Prohibition). This will be a key issue for both: overseas crypto firms servicing UK customers or carrying on cryptoasset activity with UK counterparties; and UK-based firms conducting crypto business in the UK and overseas. HM Treasury’s Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 (the Crypto Regulations), read together with the FCA’s draft perimeter guidance in CP26/13 (the Draft Guidance), provide important guidance on how the territorial analysis is expected to operate. It is critical to be clear on whether or not activities are within the scope of UK regulation because carrying on financial services activities in the UK without appropriate authorisation is a breach of the general prohibition and a criminal offence.
1. Why does territorial scope matter under the new UK cryptoasset regime?
Not comprehensively. The meaning of "in the UK" for the purposes of the regulated activities regime is not defined in FSMA itself. Whether an activity is carried on in the UK is a fact-specific analysis and may depend on a number of different factors. These include, for example: (i) the nature of the activity itself; (ii) the location from which the service is provided; (iii) the location of the customer receiving the service; and (iv) whether the provider is a UK firm or an overseas firm. For example:
2. Does FSMA define when an activity is carried on “in the UK”?
It is possible for UK firms to carry on regulated activities in the UK even where their services are provided to overseas customers.
UK firm (UK registered office or UK head office)
Overseas firms (non-UK head office)
It is possible for overseas firms that provide services from a non-UK location to carry on regulated activities in the UK where their services are provided to UK customers.
The question of whether an activity falls within the UK perimeter and its territorial scope is highly fact-specific and requires a careful analysis of the circumstances. It cannot be assumed that, because an arrangement involves a smart contract, the blockchain or decentralised elements, it is not within the territorial scope of UK regulation. In addition, firms should not assume that exclusions or exemptions with which they may be familiar, such as the Overseas Persons Exemption, will automatically apply. The new cryptoasset regulatory regime does not include many of the existing exemptions that apply to other types of investment activity. Any firm carrying on any cryptoasset activity that connects to the UK or a UK consumer will need to consider whether this is within the scope of the UK regulatory regime.
Section 418 FSMA extends the ordinary meaning of in the UK for the purposes of the regulated activities regime by setting out circumstances where a person's activities will be deemed to take place in the UK regardless of whether they ordinarily would. This is particularly relevant to firms that carry on regulated activities on a cross-border basis. By way of example, under section 418 FSMA:
3. What is the role of section 418 FSMA?
A UK firm's activities will be deemed to take place in the UK if the day-to-day management of carrying on the regulated activity is the responsibility of: (i) that UK firm's UK registered office (or head office); or (ii) one of their UK establishments. This is the case regardless of where the customer is located.
The activities of an overseas firm will be deemed to take place in the UK where the regulated activity is carried on from one of their UK establishments. This is the case regardless of where the customer is located.
As a result, when considering whether a person's activities fall within the territorial scope of the regulated activities regime, it is necessary to ask the following questions: Will the activity be deemed to be carried on in the UK under section 418 FSMA? If the deeming provisions do not apply, would the activity ordinarily be regarded as being carried on in the UK in any event?
The Crypto Regulations amend section 418 FSMA to expand the circumstances where an activity would ordinarily be treated as occurring in the UK:
4. How do the Crypto Regulations affect section 418 FSMA?
For these regulated cryptoasset activities, where firms are involved in the sale or subscription of a qualifying cryptoasset to, or by, a UK "consumer"[1], the activity will be deemed to take place in the UK, regardless of whether it ordinarily would. As a result, if an overseas firm carries on any of these regulated cryptoasset activities for UK consumers, their activities will be deemed to take place in the UK – unless a UK authorised trading platform, or a UK authorised dealer as principal, intermediates between the overseas firm and the UK consumer in the relevant sale or subscription. Accordingly, in the Draft Guidance, the FCA notes that if an overseas firm carries on these activities from outside the UK and is involved only in dealing in qualifying cryptoassets with UK institutional clients, the overseas firm should not therefore be required to be authorised, unless those institutional clients are acting as intermediaries between the overseas cryptoasset firm and UK consumers.
In the FCA's view, ordinarily, safeguarding cryptoassets activity is assumed to be the location of the safeguarding operations. Therefore – regardless of the location of the customer – the key question in this respect is where the requisite degree of control over the cryptoasset to bring about a transfer of its benefit is being exercised (or where it could be exercised). However, section 418 FSMA goes one step further by extending the circumstances where a person will be considered to safeguard cryptoassets (or arrange for cryptoasset safeguarding) in the UK beyond the ordinary application. Under section 418 FSMA, overseas firms will be deemed to carry on the safeguarding cryptoassets activity (or arranging safeguarding of cryptoassets activity) in the UK where: the activity is carried out on behalf of a UK consumer; and the overseas firm is not carrying on the activity at the direction of another person who is appropriately FCA authorised.
(5) (6)
Safeguarding cryptoassets Arranging cryptoasset safeguarding
Arrangements made by or for persons in the UK for arranging qualifying cryptoasset staking, which occurs in the UK, are seen as being carried on in the UK for the purposes of the regulated activities regime. Section 418 FSMA extends this so that firms will be deemed to carry on the safeguarding cryptoassets activity (or arranging safeguarding of cryptoassets activity) in the UK where: the activity is carried out on behalf of a UK consumer; and the firm is not carrying on the activity at the direction of another person who is appropriately FCA authorised.
(7)
Arranging qualifying cryptoasset staking
There are three components to issuing qualifying stablecoin in the UK. These are: offering; redemption; and maintaining the value of a qualifying stablecoin. Firms undertaking all three of these activities – or arranging for them to be undertaken on their behalf – from an establishment in the UK will be brought within the territorial scope of the regulated activity for issuance. In addition: under section 418 FSMA, an overseas firm that is not acting from a UK establishment, but is nonetheless arranging for all three of the components to be carried out in the UK on its behalf, will also require authorisation as a UK issuer; and a person operating from an establishment outside the UK could also be regarded as carrying out this regulated crypto activity in the UK where they assume an undertaking to redeem a qualifying stablecoin from a person that is carrying out the issuing of qualifying stablecoin in the UK. Note: The position in relation to stablecoin activities especially in relation to stablecoin payments is currently under consideration by the UK Government and further changes may occur to the territorial scope of the stablecoin regime.
(8)
Issuing qualifying stablecoin
Review their crypto-related activity to identify what activities they are carrying out. For each new regulated activity, identify whether the activity will be performed from a UK establishment or from overseas. For UK firms, identify whether the day-to-day management of the activity will be the responsibility of a UK establishment. Identify whether the firm's customer base includes UK customers. Where there are UK customers whether these are consumers or institutional customers. Taking into account the above, whether their activities will fall within the territorial scope of the regulated activities regime. Please contact a member of the Dentons Regulatory & Investigations team if you would like to discuss the territorial scope of UK cryptoasset regulation.
5. What should crypto firms be doing to prepare now?
[1] For these purposes, a "consumer" means an individual in the UK who is acting for a purpose other than for any trade, business or profession carried on by that individual.
(1) (2) (3) (4)
Operating a qualifying cryptoasset trading platform (CATP) Dealing in qualifying cryptoassets as principal Dealing in qualifying cryptoassets as agent Arranging deals in qualifying cryptoassets
Stablecoin regulation in the UK: a practical guide for firms
The UK's stablecoin regime is taking shape around a dual regulation system, whereby the greater the role a stablecoin plays in the payments system, the more intensive the regulation becomes. For firms considering issuing or using stablecoins in the UK, the key distinction is between: • non-systemic UK-issued qualifying stablecoins, which are regulated primarily by the Financial Conduct Authority (FCA); and• systemic stablecoins, which are stablecoins that are widely used for corporate or retail transactions and would be capable of disrupting the financial system if it failed. They come under joint FCA and Bank of England supervision once they have been recognised by HM Treasury. For firms, stablecoin regulation is relevant at the authorisation stage as it affects the design of the stablecoin itself. The regulation imposes requirements on a stablecoin's reserve asset, redemption arrangements, governance, disclosures, treasury operations and, potentially, access to payment systems.
The starting point for a UK issuer is the FCA regime. Issuing a qualifying stablecoin is a regulated activity and an authorised issuer will need to comply with the FCA's detailed requirements governing the assets backing the stablecoin, redemption and disclosures. The position changes if the stablecoin grows sufficiently large or important that HM Treasury recognises it as systemic. At that point, the issuer moves into joint FCA and Bank of England regulation. Systemic status is determined by:• the number of stablecoins in circulation; and• other considerations including the stablecoin's scale, use, substitutability and interconnectedness with the wider financial system. For firms intending to scale, they must take into consideration that the business initially regulated by the FCA may ultimately need to transition into the systemic framework.
Which regime applies?
Backing assets sit at the heart of both regimes. Under the FCA regime, an issuer must maintain a pool of assets sufficient to back the stablecoins it has issued. That pool must be segregated from the issuer's own assets and other stablecoin pools, and held on statutory trust for token holders. The range of permitted assets is deliberately conservative. Core backing assets include on-demand deposits and short-term government debt. At least 5% of the backing pool must be held in on-demand deposits so that the issuer has liquidity available to meet redemptions. Additional requirements apply where an issuer chooses to hold certain expanded backing assets. For a firm designing a stablecoin, the issuer needs systems capable of: • monitoring the value and composition of backing assets;• carrying out appropriate reconciliations;• managing custodians and concentration risk;• maintaining sufficient liquidity for redemptions; and• keeping backing assets legally and operationally separate from the firm's own assets. The requirements become more prescriptive for systemic stablecoins. The Bank's framework requires, in steady state, backing assets to comprise 70% short-term UK government debt securities and 30% in central bank deposits.A firm with ambitions to become a major stablecoin issuer should therefore consider early whether its treasury model could ultimately support the Bank's requirements.
What does an issuer need to do with the backing assets?
A regulated stablecoin must be genuinely redeemable at par. Under the FCA regime, holders must generally be able to redeem their stablecoins for their face value in the relevant fiat currency, with redemption completed by the end of the next business day once the issuer has received the stablecoin and completed the required financial crime checks. There are limited circumstances in which that timing may not apply, including where completing the redemption would breach a legal requirement or where a valid suspension applies. Systemic stablecoins face a tighter standard. The Bank expects redemption at face value without undue constraint or cost and, once a full redemption request has been received, completion as soon as practicable and within 24 hours. In practice, firms should design redemption processes around more than the contractual right to redeem. They will need sufficient: • liquidity;• operational capacity;• wallet and payment infrastructure;• financial crime controls; and• business continuity arrangements, to deliver redemption within the required timeframe, including during periods of market stress.
How quickly must holders be able to redeem?
The FCA regime also imposes a structured disclosure obligation. Before a qualifying stablecoin is offered or admitted to trading, its issuer must publish a Qualifying Cryptoasset Disclosure Document (QCDD) and upload it to the FCA's centralised repository. The document must give holders sufficient information to understand matters including the stablecoin, its backing assets, redemption arrangements and associated risks. Information must be clear, fair and not misleading, and certain fast-moving information must be updated at least quarterly. Firms will need reliable systems for producing and verifying information on matters such as how many stablecoins they have in circulation, the composition of their backing assets, any redemption activity, and material product and occupational risks. Those systems will also become increasingly important if the stablecoin subsequently enters the systemic regime.
What must firms disclose?
Systemic regulation introduces additional prudential and operational requirements because the consequences of failure are potentially much greater. Alongside more prescriptive backing asset rules, systemic issuers must maintain financial resources to deal with general business risks and separate reserves designed to address risks to token holders and the costs of an orderly wind-down or insolvency. The Bank also expects systemic issuers ultimately to obtain direct access to payment systems, rather than relying indefinitely on a sponsoring participant, in order to reduce operational and counterparty risk. There is also an initial issuance guardrail for each systemic stablecoin restricting them to an initial maximum issuance of £40 billion. The Bank intends for that restriction to be loosened and ultimately removed as risks associated with large-scale adoption are addressed. These requirements mean that firms expecting significant growth should consider systemic readiness as part of the design of the business, rather than attempting to retrofit it once systemic designation becomes likely.
What changes are required if the stablecoin becomes systemic?
For firms developing a UK stablecoin proposition, five workstreams deserve particular attention from the outset. • Regulatory perimeter: Determine whether the proposed product constitutes a UK qualifying stablecoin and which activities around its issuance, distribution, safeguarding and use in payments will be regulated. • Treasury and safeguarding: Design the backing pool, custody structure and reconciliation processes around the regulatory requirements rather than treating reserve management as a purely commercial matter. • Redemption: Build financial crime, liquidity and operational processes that can support the FCA's redemption timetable and, where scale is anticipated, the Bank's 24-hour systemic standard. • Governance and data: Establish clear board and senior management accountability, supported by reliable information on backing assets, redemptions, operational resilience and compliance. • Scalability: Firms expecting substantial adoption should assess at an early stage how they would transition from FCA-only supervision to joint FCA and Bank regulation, including the consequences for treasury, capital, reserves and payment system access.
What should firms be doing now?
The UK regime is intended to allow regulated stablecoins to develop as payment instruments while applying additional safeguards once they become important to financial stability. The FCA regime is due to come into force on 25 October 2027, while further Bank of England guidance and implementation materials are expected as the systemic regime develops. The key practical message for firms is therefore to design for regulation from the outset. Stablecoin compliance reaches directly into product design, treasury, custody, redemption, governance, financial crime controls and technology. Firms that expect their stablecoin to scale should also build with the possibility of systemic regulation firmly in mind. We have designed a flowchart to assist navigating the stablecoin regime.
The direction of travel
Regulator
• Authorised and supervised by the FCA
• Segregated backing pool held on statutory trust• Core assets: on-demand deposits and short-term government debt• At least 5% of pool in on-demand deposits
Backing assets
• Redeem at par by end of next business day after receipt of request and financial crime checks• Limited exceptions may apply
Redemtion
• Publish QCDD before offer/admission to trading• Clear, fair and not misleading• Fast-moving information updated quarterly
Design for transition
FCA Regime
Has HM Treasury recognised the stablecoin as systemic?
NO non-systemic
Disclosures and data
• If the stablecoin may scale, test whether treasury, redemption, data and governance can move from FCA-only to systemic standards
Joint FCA and Bank of England regulation
• Capital and liquidity requirements• Separate reserves for token holder and wind-down risks• Direct payment system access expected over time
Additionalrequirements
• FCA disclosure obligations continue• Enhanced data/reporting expectations
• Redeem at par as soon as practicable and within 24 hours
• Steady state: 70% short-term UK government debt and 30% in central bank deposits• Stricter treasury and concentration requirements
• Joint supervision by the FCA and the Bank of England
YES systemic
What Makes a Successful Application
Timeline
Authorisations
Steps to Regulation
For more information, please consult the FCA Crypto Roadmap here.
PASS pre application meetings take place
FG: Approach to international cryptoasset firms PS26/13: Application of FCA Handbook for Regulated Cryptoasset Activities PS26/11: Regulated Cryptoasset Activities FG26/5: Application of the Consumer Duty to cryptoasset firms FG: Cryptoasset operational resilience PS26/12: A Prudential Regime for Cryptoasset Firms GC26/5: Non-Handbook Guidance on CRYPTOPRU 7: overall risk assessment for CRYPTOPRU firms PS26/9: Admissions & Disclosures and Market Abuse Regime for Cryptoassets PS26/10: Stablecoin issuance GC26/4: Non-Handbook Guidance on COREPRU 7: Overall risk assessment | FCA
30 June 2026
30 September 2026
28 February 2027
25 October 2027
Meetings to be pre-booked as soon as possible. Opportunity to discuss plans and ask questions before sumitting the application. Questions should focus on understanding the FCA's expectations for an authorisation applicion. Firms must have considered which permissions they may need to apply for ahead of the PASS meating and be ready to share a version of their business plan, target market and key personnel.
Policy Statements published
Application Period Starts
Firms are able to submit completed applications for the authorisation for any of the new cryptoasset activities if they wish to operate after October 2027
Application Period Ends
This marks the end of the transitional period, if firms do not intend to apply, they must wind down their UK cryptoasset activities before the new regime starts. Firms at this stage must be ready for regulation when the regime takes effect.
New regime expected to come into force
Firms that want to conduct regulated cryptoasset activities in the UK will need FCA authorisation, or risk falling under the general prohibition under s.19 FSMA
What makes a successful application for authorisation?
In the authorisation process, the FCA is assessing whether a firm should be admitted to the regulated sector in the UK and be able to do business in the UK. The FCA must be satisfied that the threshold conditions set out in Schedule 6 to the Financial Services and Markets Act 2000 are met and that there is nothing else that would impact on meeting its operational objectives. The threshold conditions cover location of offices, ability to be supervised, the resources of a firm, the fitness and propriety of those running the firm and the firm's business model. For crypto firms, adequate resources will mean meeting the prudential requirements applicable to the crypto business being carried out. The authorisations process is rigorous. The FCA is concerned to ensure that any firm it authorises will meet the regulatory standards in the UK and will not be at imminent risk of failing. The FCA scrutinises applications and supporting documentation carefully to ensure that its standards for authorisation are met. It communicates with firms regularly throughout the process with follow up questions and potentially requests for documentation. This gives firms a useful opportunity to gauge the prospects of success for their application and to withdraw if they need more time to answer the FCA's questions. It is important that before applying for authorisation, firms are, as the FCA terms it, "ready, willing and organised". This minimises the risk that applications are deemed "incomplete" on submission and ensures that the application process proceeds as smoothly as possible. Firms seeking authorisation should be prepared to dedicate a sufficient amount of time to the preparation of the application and supporting documentation to achieve this.
1. What is the FCA looking for?
For firms looking to be authorised from the start of the crypto regulatory regime, the FCA application window runs from 30 September 2026 until 28 February 2027. The regime will apply from 25 October 2027. If a firm submits an application within the application window but it has not been determined before the regime commences, it will enter into a "saving provision" where it can continue to provide services until its application has been determined. If an application is refused or withdrawn either before the regime commences or whilst the firm is in the "saving provision", the firm will be able to use a transitional provision to exit the market in an orderly way.
2. Timeframes, savings and transitional provisions
Preliminary tasks
An essential preliminary task is the perimeter analysis of the firm's activities. An authorisation application must specify the particular activities and products that a firm seeks FCA authorisation for. The FCA expects firms to have analysed their business to determine what activities they require permission to undertake. The FCA may ask questions about the analysis undertaken and may ask to see any supporting documentation in relation to a perimeter analysis. Firms should also ensure that their basic corporate structure and base of operations is settled before commencing an authorisation application. Issues such as location of offices and ability to be effectively supervised go to satisfaction of the threshold conditions, whilst the corporate ownership structure and controllers of the firm are all matters that need to be disclosed and approvals sought in the authorisation process.
3. What do firms need to provide?
To apply for authorisation firms need to complete the application form providing all the requested information for the activities they are seeking authorisation for, provide financial information and pay the required fee. The form needs to be accompanied by a pack of relevant documents including the firm's polices and procedures.
The application
The FCA is generally less concerned with the form of an application than with its substance. Supporting materials can be submitted in a variety of formats, including documents, spreadsheets and presentations. What matters is whether the application demonstrates that the firm understands the regulatory framework, has identified the risks associated with its activities and has implemented appropriate systems and controls to manage those risks. The regulator recognises that businesses evolve over time and does not necessarily expect a firm to have reached its ultimate operating model at the point of application. However, firms should be able to demonstrate that their current governance and control framework is appropriate for their proposed activities and that they have credible plans to scale those arrangements as the business grows. The strongest applications are typically those that present a clear and coherent picture of the business. In practice, this means demonstrating: (a) a well-defined and credible business model; (b) effective governance and accountability arrangements; (c) robust financial crime controls; (d) appropriate systems, resources and operational capabilities; (e) a thorough understanding of the risks associated with the firm's activities; and (f) evidence that policies and procedures are capable of operating effectively in practice.
The regulatory business plan
The regulatory business plan is one of the most important documents in the application. It must: (a) be specific to the firm's business; (b) explain how the firm's specific activities align to the permissions sought; (c) set out how the firm will market itself and the customer journey; (d) cover governance of the firm including where key staff are based overseas; (e) address the Consumer Duty including where it does not apply and why; (f) outline how the firm will comply with regulatory requirements; (g) detail the firm's complaints process; (h) outline staff training and incentives approach; (i) address capital resources; and (j) provide an outline of policies and procedures specific to the firm's business model. More detail is generally better than less detail. Firms should also consider the purpose of the document when preparing it and frame it to explain clearly to the FCA what their business is and how it operates. This is particularly important in the cryptoasset sector, where business models are often innovative and technology-driven. If the FCA struggles to understand how a business operates, firms should expect a more detailed and potentially longer authorisation process. Firms should expect to be challenged by the FCA if their business plan sets out growth projections that on the face of it will be ambitious to achieve. In these circumstances the FCA is likely to want to understand both the prospects of achieving the stated growth and how the firm will continue to maintain compliance with standards when scaling at such speed.
Policies and procedures
Whilst the FCA accepts that some documentation may be in near final mode, for example any outsourcing arrangements, all documentation submitted with an application should be final or as close to final as possible. As with the business plan, all documentation should be specific to the firm's business model and risk profile. Policies should not simply restate regulatory requirements. Instead, they should demonstrate how those requirements apply to the firm's particular activities and how compliance will be achieved in practice. This means setting out the procedures that will be applied in practice by staff and being clear on the controls in place to ensure procedures are followed. In many cases risk assessments are required as part of the application, which again should be appropriately detailed and specific to the firm's business model. Where third party tools are used, firms should clearly explain the third-party systems and tools they rely on, including those used for sanctions screening, politically exposed person checks, customer due diligence and transaction monitoring. For any outsourcing arrangements, firms should also explain the controls they have in place to meet governance requirements for those arrangements. All firms seeking cryptoasset authorisation will need to provide their compliance monitoring plan including their financial crime prevention framework, their complaints policy and their cryptoasset records management policy. Other specific policies are required depending on the activities for which authorisation is being sought.
Senior management
In addition to the firm's information, an application for authorisation also has implications for key individuals in the firm's management. All authorised firms are required to have approved senior managers, whose number and roles are determined by the nature of the firm. Senior managers are responsible for key functions in the business and must be approved by the FCA as being fit and proper to perform their roles. As part of the authorisation and approval process, senior managers can expect to be interviewed by the FCA to ascertain their understanding of the firm's business and the regulatory obligations on the firm and the senior manager. When applying for authorisation, it is helpful to identify senior managers early in the process, invest in regulatory training and prepare thoroughly for FCA engagement. The FCA has confirmed that the SM&CR will apply in full to authorised cryptoasset firms, and application forms and processes will need to be prepared on this basis. However, in light of the ongoing review of the SM&CR regime by HM Treasury, the FCA intends to provide a modification by consent deferring assessment of the certification regime compliance during the authorisation gateway whilst HM Treasury finalises the changes.
The gateway for making authorisation applications for cryptoasset activities opens on 30 September 2026 and closes on 28 February 2027. Following this date, all authorisation applications will be assessed on normal timeframes and may not be determined before the regulatory regime starts. Firms looking to apply in the gateway window should consider the following points in preparing their authorisation applications to maximise the chances that these are considered complete on submission and to ensure that the firm is well positioned to address any questions the FCA has during the process. The FCA has indicated that it anticipates significant volumes of applications and that firms should bear this in mind when applying for authorisation or to vary their existing permissions to include cryptoasset activities. Tasks for firms: (a) (b) (c) (d) (e) (f) (g) (h) (i) (j) (k) (l) (m) (n)
4. What should firms be doing now?
identifying which activities may become regulated; assessing how multiple cryptoasset activities interact across the business; reviewing territorial scope and cross-border services; conducting a gap analysis against the anticipated FSMA requirements evaluating governance, systems and controls or documentation against FCA expectations and enhancing it as necessary; preparing financial information including historical financial statements, forward looking projections and quantification of how they are meeting the prudential requirements; reviewing financial promotions and customer communications; developing a realistic authorisation project plan, approved at board level, ahead of the application window that clearly identifies: (i) who is accountable for delivery;(ii) the changes required;(iii) how those changes will be implemented; and (iv) the timetable for completion. evaluating the resources, expertise and budget required to support both the authorisation process and ongoing regulatory compliance; considering obtaining legal, regulatory and compliance support at an early stage to help navigate the transition and avoid unnecessary delays during the application process; preparing policies and procedures to meet compliance standards expected under FCA final rules; identifying senior managers and preparing applications for approval; reviewing existing operational resilience requirements (including how to identify and address cyber risks), identifying cryptoasset-specific vulnerabilities via mapping and ensuring compliance with FCA expectations; embedding robust AML and CTF frameworks tailored to unique crypto risks; and ensuring staff training on regulatory requirements is planned and timetabled ahead of 27 October 2027.
Consumer Duty
Conduct Rules
SMCR
FCA crypto conduct rules: what firms need to do
The FCA's proposed cryptoasset regime is taking shape through a series of consultations that will apply large parts of the existing FCA Handbook to regulated cryptoasset activities. Taken together, the final rules set out in PS26/11, PS26/12 and PS 26/13 will require cryptoasset firms to implement conduct, governance and client protection standards broadly comparable to those applying in traditional financial services, while adapting those requirements to the specific features of cryptoassets. This article provides a high-level summary of the principal conduct requirements proposed by the FCA and the practical steps firms should be considering now. Specific crypto product rules around stablecoin, admission to trading on platforms etc are proposed to be included in a new CRYPTO sourcebook and are covered in other articles on this hub. Cryptoasset firms should analyse their activities and the rules that will apply to them and develop a plan for compliance. If your firm would like assistance with this process, we have a range of tools that can assist in identifying and mapping requirements applicable to individual firm models.
The FCA will apply the client categorisation framework to cryptoasset firms, with the final rules in PS26/13 also applying to firms conducting regulated cryptoasset activities.
1. Client categorisation
Key developments
Client categorisation will be a significant shift for currently unauthorised cryptoasset firms. The FCA is focussed on ensuring that cryptoassets are available to appropriately experienced and resourced clients whilst ensuring that clients who do not have this expertise or this level of resource are not exposed to high-risk products. Firms will need to prepare to administer tests for treating clients as elective professionals and ensure that processes record decisions and supporting evidence clearly.
What firms will need to do
The COBS sourcebook will generally apply to the carrying on of regulated cryptoasset activities subject to certain matters being dealt with in specific rules contained in the new CRYPTO sourcebook. The matters subject to specific rules in CRYPTO will be dealing and managing, cancellation and reporting information to clients, whilst the more general obligations around communications, inducements and appropriateness remain in COBS. The objective is to ensure firms act honestly, fairly and professionally when dealing with clients.
2. Conduct of Business Standards (COBS)
Categorise clients as retail, professional or eligible counterparties
Review onboarding processes and ensure categorisation occurs before relevant services are provided.
Apply appropriate conduct protections based on client category
Ensure disclosures, suitability and other conduct obligations are linked to categorisation status.
Requirement
Practical implications
Implement procedures for elective professional client assessments
Develop assessment frameworks and evidential records.
Reassess existing client populations where categorisation standards change
Identify legacy client classifications requiring review.
Maintain records supporting categorisation decisions
Retain evidence of assessments, client information and rationale.
Act honestly, fairly and professionally (COBS 2)
Embed conduct standards throughout customer journeys.
Provide fair, clear and not misleading communications (COBS 4). Note that UK issued stablecoins will be excluded from certain marketing restrictions. In addition the CRYPTO sourcebook may contain additional requirements depending on the product
Review customer disclosures, websites and app interfaces.
Deliver appropriate information to clients (COBS 6) – information about the firm and its services should be provided to customers. Additional information on safeguarding around trust arrangements and the risks of not using a trust arrangement must be supplied by firms safeguarding cryptoassets
Provide information on products, services, risks, costs and charges.
Manage inducements appropriately (COBS 2.3)
Review referral, distribution and incentive arrangements.
Provide written client agreements and retain records of this.
Provide client agreements (COBS 8)
Ensure that policies are in place to comply with this and not distribute products to clients who don't meet the necessary criteria.
Apply appropriateness tests (COBS 10) which will require asking clients specific questions and in the case of cryptoasset lending and borrowing, assessing knowledge and experience of these products
Firms will need to consult both COBS and the new CRYPTO sourcebook to ascertain the full degree of rules applicable to their cryptoasset offering and design processes that can meet these requirements.
Safeguarding of cryptoassets will be a new regulated activity from October 2027. A new CASS 17 will set out the applicable rules for safeguarding crpytoassets whether these are qualifying cryptoassets or specific investment cryptoassets. It will also set out the rules applicable to various types of crypto activities that may involve safeguarding, whether this is staking, cryptoasset lending or posting collateral under a borrowing arrangement. PS26/11 extends the FCA's safeguarding framework and develops proposals for custody of both cryptoassets and specified investment cryptoassets (SICs).
3. Safeguarding of cryptoassets and specified investment cryptoassets
Safeguard client cryptoassets appropriately, establishing a trust mechanism for safeguarding
Establish custody arrangements and operational controls.
Maintain clear segregation of client assets subject only to permitted operational surplus and exit routes
Separate client assets from firm assets and ensure processes are in place for operating any operational surplus.
Keep accurate records and reconciliations
Reconcile holdings regularly and investigate discrepancies promptly.
Protect private keys and custody infrastructure
Implement robust operational resilience and security controls.
Maintain arrangements for transfers and withdrawals
Ensure clients can access and transfer assets appropriately.
Establish procedures for insolvency and wind-down scenarios
Document client asset return processes.
The safeguarding of funds and maintaining the pool at the correct level has been a significant issue in payments firms in recent years and it can be expected that the FCA will scrutinise cryptoasset safeguarding carefully to ensure that it is providing the level of protection expected.
Where client money is involved in connection with certain cryptoasset activities, the rules in CASS 7 will apply. This will cover client money situations arising with issuing stablecoin, firms safeguarding cryptoassets (both qualifying cryptoasset and those that are specified investments) and firms undertaking activities involving client money used to acquire or dispose of cryptoasset, where they receive or hold money on behalf of clients as part of execution, dealing or arranging activities within scope of designated investment business. It should be noted that backing assets for issuing stablecoin are subject to CASS 16 and not CASS 7. There are two important areas of CASS 7 that are disapplied in the case of cryptoasset: The professional client opt-out The delivery versus payment exemption for commercial settlement systems where the delivery obligation is in respect of client cryptoasset Cryptoasset firms who hold or receive client money at any point will need to carefully review CASS 7 and ensure that they are in a position to comply with all the relevant obligations. CASS compliance has been an ongoing focus for the FCA. Firms will need to ensure that they have robust record keeping processes and are able to meet the daily reconciliation requirements in the rules.
4. Client money
The core principles from the FCA Handbook, found in SYSC (General organisational requirements), COND (threshold conditions), PRIN (principles for business), GEN and SUP (Supervision manual) will all be applied to cryptoasset firms broadly in line with traditional regulated firms.
5. High-Level Standards
Meet Threshold Conditions
Demonstrate suitability, effective supervision and appropriate resources.
Meet Prudential Requirements
Maintain adequate capital, stress testing and financial resilience.
Comply with Principles for Businesses
Embed conduct expectations throughout operations.
Maintain effective systems and controls
Ensure governance and oversight arrangements are proportionate to business activities. This extends also to ensuring that oversight of any outsourced arrangements is maintained.
Comply with Reporting Requirements
Ensure arrangements are in place to comply with submission of baseline returns, supplementary data collections (from the commencement of the regime) and ongoing post-implementation refinement of these returns.
Cooperate openly with the FCA
Establish regulatory engagement processes.
These are all areas examined closely by the FCA in any application for authorisation, so firms should consider at an early stage taking the following steps: (a) Review governance frameworks. (b) Assess board oversight arrangements. (c) Evaluate operational and financial resources. (d) Document control frameworks.
In the same way as is applicable to other authorised firms, the FCA intends to ensure that cryptoasset firms have appropriately qualified and experienced staff working for them. These will apply only where a cryptoasset firm is carrying on activities analogous to the investment activities, such as safeguarding, dealing in cryptoassets and arranging staking.
6. Training and competence
Ensure staff are competent for their roles
Develop role-specific competence frameworks.
Provide appropriate training
Deliver initial and ongoing training programmes.
Assess competence on an ongoing basis
Implement monitoring and review processes.
Maintain training records
Evidence compliance and supervisory oversight.
Ensure specialist knowledge where required
Address technical cryptoasset risks and products.
The FCA has confirmed that only the ESG rules applicable to all FCA authorised firms will apply to cryptoasset firms. Cryptoasset firms will not be able to use sustainability labels. They will also need to ensure that any sustainability references are clear, fair and not misleading and are consistent with the sustainability characteristics of the product or service.
7. ESG requirements
For firms new to the FCA's regulatory framework and approach, early preparation is essential to ensuring that the firm is ready to comply with the rules once the regulatory regime commences. The FCA's regulatory regime includes requirements on firms to notify the FCA when there is a significant breach of any rules, especially where this causes any harm to customers. This requirement applies from the point of authorisation and the FCA will expect to see that firms are familiar with the conduct requirements applicable to them in the authorisation process. To discuss how the conduct rules may apply to your firm and your particular business model and to discuss how we can assist you in preparing for authorisation, please contact any member of the Dentons team for a confidential conversation.
8. Conclusions
Consumer Duty under the new cryptoasset regime
Cryptoasset firms under the new cryptoasset regime will need to comply with the Consumer Duty whenever they are conducting business that involves a retail customer somewhere in the distribution chain. This is a significant shift for the crypto sector. Until now, much of the UK’s crypto regulatory framework has focused on anti-money laundering controls and financial promotions. Under the new regime, crypto firms authorised by the FCA will be expected to operate to standards broadly equivalent to those applied across traditional financial services, under the principle of “same risk, same regulatory outcome". For crypto firms, the Consumer Duty will represent a structural change in how firms design and price products, communicate with users, manage conflicts, handle complaints, and deliver customer outcomes.
Subject to limited exemptions[1], the FCA will apply Principle 12 and PRIN 2A (the core Consumer Duty framework) to authorised cryptoasset firms in the same way it applies to other authorised firms under the Financial Services and Markets Act 2000 (FSMA), including payment firms. The Duty consists of: A consumer principle requiring firms to “act to deliver good outcomes for retail customers”. Three cross-cutting obligations. Four detailed consumer outcomes covering products, value, understanding, and support. Importantly, the FCA is not applying a separate or lighter crypto-specific Duty. Instead, the regulator has supplemented the existing framework with targeted guidance in FG26/5 explaining how the Duty should operate in crypto markets. This reflects the FCA’s view that cryptoasset firms should be held to comparable standards of retail consumer protection as traditional financial institutions.
The FCA’s Approach
Products and Services
The Four Consumer Duty Outcomes in Crypto
[1] Admission and disclosure activities and trading on a UK overseas qualifying cryptoasset trading platform (QCATP).
At the consultation stage, the FCA highlighted a number of risks and features of cryptoasset activities that meant that in the FCA's view it was important to apply the Duty to cryptoasset activities. These included structural risks in crypto markets arising from the fact that crypto markets differ materially from traditional finance. Retail consumers often transact directly on cryptoasset trading platforms without the intermediaries typically present in securities markets. As a result, this creates heightened risks around product design, disclosures, pricing, consumer understanding and customer support. Several examples of harm already observed in crypto markets were identified, including: unsuitable and highly complex products being sold to retail consumers who may not fully understand the associated risks, particularly in areas such as crypto lending, derivatives and leveraged products; inadequate disclosure and transparency around product risks and firm practices; harmful commercial practices, including unclear communications and barriers that hinder consumers from properly assessing products and services; poor or limited complaints handling and redress mechanisms, leaving consumers with limited avenues for compensation when problems arise; and weak safeguarding and custody arrangements, including failures in governance and private key management that have resulted in significant consumer losses and limited recovery options following firm failures.
Why the FCA Believes the Duty Matters in Crypto
In its final response, the FCA confirmed application of the Duty to cryptoasset firms subject to two key exceptions: Trading between participants on a UK QCATP – the Duty will not apply here because equivalent protections exist in CRYPTO 6 in the FCA Handbook. Public offers and admissions to trading of qualifying cryptoassets other than UK issued qualifying stablecoins – these activities are covered by bespoke admissions and disclosure rules, but UK issuers of qualifying stablecoins will need to consider if anything additional is required to comply with the Duty given the potential for UK issued stablecoin to be used as digital money. For UK QCATPS, whilst trading between participants is not caught by the Duty, other aspects of the UK QCATPs activities will be caught and UK QCATPs will need to ensure that they are clear what is in scope of the Duty and what is not.
The products and services outcome requires firms manufacturing cryptoasset and services to ensure products are designed to meet the needs, objectives, and characteristics of an identified target market and firms distributing such products to ensure that they reach the correct target market. Firms must first identify their role in the distribution chain – either manufacturer or distributor. FG26/5 sets out how these terms apply to cryptoasset firms: Manufacturers include issuers of qualifying cryptoasset and stablecoins, UK QCATPs providing the service of trading on the QCATP and operators of cryptoasset lending and borrowing services. Distributors include cryptoasset intermediaries and UK QCATPs offering cryptoasset on their platforms. Firms may be both manufacturer of one part and distributor of another. A UK QCATP could be manufacturer of its trading service and distributor of the assets being traded. Firms will need to carefully analyse their roles to ensure that they understand and apply the Duty correctly. To meet the outcomes based expectations of the Duty, firms will need to evidence: Clear target market identification; Suitability of distribution channels; Ongoing product monitoring; Appropriate treatment of vulnerable customers; and Robust governance over new token listings and product launches. Even where cryptoassets may be issued by entities outside the UK regulatory perimeter or may have no identifiable issuer at all, the Duty does not cease to operate. Distributors remain responsible for taking all reasonable steps to understand the product, assess its risks, identify an appropriate target market and distribute the product accordingly. Where manufacturers are unregulated or unknown, firms are expected to assess publicly available information, consider the reliability and provenance of available information, evaluate market size and liquidity, and determine whether any gaps in information themselves indicate heightened consumer risk. The FCA also expects firms to monitor the design and distribution of cryptoasset products taking proactive steps to avoid causing foreseeable harm through introducing friction, monitoring distribution and modifying, withdrawing or discontinuing products that no longer meet the needs of the target market.[2]
Price and Value
Despite the volatility of many cryptoassets, the Price and Value outcome will continue to apply to crypto firms. The FCA's position is clear: crypto volatility does not remove firms’ obligations to ensure a “reasonable relationship” between price and benefit. Fair value assessments must be carried out in the context of each individual product and service. Firms are expected to ensure there is a reasonable relationship between the price paid by consumers and the benefits they receive. In particular, the FCA considers firms should assess: the benefits the product is intended to provide and whether those benefits are credible; the characteristics, needs and objectives of the likely target market; whether vulnerable customers are less likely to receive fair value; whether distributor fees, spreads or other charges, as well as non-financial frictions undermine overall value; and whether remuneration arrangements within the distribution chain adversely affect value. Firms should consider each product separately, noting that crypto products vary significantly and present different value propositions to customers. Again, distributors cannot rely on an absence of manufacturer information (e.g. where a manufacturer has not undertaken a fair value assessment) and are expected to exercise their own reasonable judgement regarding fair value.[3]
Consumer Understanding and Appropriateness Testing
Consumer understanding is likely to become one of the most operationally intensive areas of compliance for crypto firms. The FCA wants firms to communicate in ways that allow consumers to make “effective, timely and properly informed” decisions, which intersects directly with the existing financial promotions regime for cryptoassets. The high-risk nature of some cryptoasset products and services make consumer understanding crucial to achieving good outcomes. The FCA expects firms to support customer understanding throughout the product or service lifecycle. This stretches from initial marketing through to post-sale services. A key warning from the FCA is that cryptoasset firms should avoid designing or delivering communications in a way that exploits consumers' information asymmetries or behavioural biases. The FCA notes that many retail customers will lack familiarity with cryptoasset products and may see these products as exciting and innovative, supported by online influencers. Firms are encouraged to:
Test and monitor their communications; Ensure critical information is provided in good time; Consider additional tools to help customers understand complex products; Ensure that the support includes help with understanding wallet structures and safeguarding arrangements; Avoid using dense legal language or blockchain jargon; Ensure they communicate with customers at appropriate times, such as when contractual variations are made or customer circumstances change. As with all Consumer Duty requirements, it will be important that firms are able to evidence the operation of their processes and that they are monitoring to ensure that these processes do deliver good outcomes for customers.
Consumer Support and Complaints Handling
The consumer support outcome requires firms to provide support throughout the product lifecycle, including during wallet freezes, protocol upgrades, staking failures, and other operational issues that may affect access to customer assets.[4] In particular, firms should not create unreasonable barriers during the lifecycle of a product (e.g. at closure or withdrawal). In crypto markets, this is particularly significant because many firms have historically operated with limited customer service infrastructure. Consumer support is an outcome that extends throughout the customer's journey with a firm. The FCA emphasises that support has to be accessible, responsive and tailored to the risks and complexity of the product. In particular, cryptoasset firms will need to consider how they identify customers with characteristics of vulnerability and ensure that support is accessible to those customers. In the specific context of cryptoassets, the FCA highlights the following expectations: No friction in accessing private keys, exporting transaction history, switching or withdrawing to self-custody; Where possible customers impacted by slashing events or other protocol changes should be supported by firms; Good practice includes providing a dedicated, easily accessible channel for customers to report vulnerabilities, scams or security incidents; Poor practice includes opaque and extended withdrawal holds and multiple steps and delays to access help; and Poor practice also includes interfaces that highlight yields or gains whilst obscuring risks or support options. Cryptoasset firms subject to the Duty will need to consider carefully how support mechanisms are designed to meet FCA expectations and deliver good outcomes to all customers. Staff training on these expectations should be undertaken well in advance of regulated services commencing.
[2] FG26/5 at 4.13 [3] FG26/5 at 4.26 [4] FG26/5 at 4.43
Authorised cryptoasset firms will be expected to comply with the Consumer Duty. Firms should begin planning now to put themselves in the best position for successful authorisation and compliance with FCA expectations. Key areas of focus should include: reviewing product governance frameworks, including target market identification and oversight of token listings and new product launches; assessing pricing structures, spreads and fee models to ensure products can demonstrate fair value; reviewing customer communications, financial promotions and disclosures to ensure they are fair, clear and not misleading; enhancing appropriateness testing frameworks and onboarding journeys to align with the COBS 10 requirements; assessing whether automated onboarding and execution-only models provide sufficient customer understanding safeguards; strengthening complaints handling, customer support and redress procedures in line with DISP expectations; reviewing safeguarding, custody and operational resilience arrangements, including oversight of third-party providers; implementing governance and monitoring frameworks capable of evidencing good customer outcomes under the Consumer Duty; enhancing management information, reporting and vulnerability monitoring processes; conducting regulatory gap analyses against Consumer Duty; and assessing staff training needs on the Consumer Duty and planning a training programme to ensure all staff working on activities impacting on retail customers are trained ahead of the regulatory regime commencing. Contact any member of the Dentons Regulatory & Investigations team if you would like to discuss preparation for the future UK cryptoasset regime.
What Should Crypto Firms Be Doing Now?
What is changing for cryptoasset firms under the future UK regime?The future UK cryptoasset regime is expected to come into force from 25 October 2027 and will move crypto firms from the current MLR registration framework to a broader regulatory regime under the Financial Services and Markets 2000 (FSMA) focused on governance, accountability and conduct standards. Will cryptoasset firms need to comply with the Consumer Duty?Yes. Under the new regime, FCA-authorised cryptoasset firms will be expected to comply with the Consumer Duty in the same way as other authorised firms under the FSMA (subject to limited exemptions). Why is this significant?It marks a shift from a regime focused mainly on anti-money laundering and financial promotions to one focused on customer outcomes, governance, product design, pricing, communications, complaints and support. Is there alighter crypto-specific version of the Consumer Duty?No. Principle 12 and PRIN 2A will apply in full to crypto firms, supplemented by targeted crypto-specific guidance. However, the FCA recognises the Duty needs to apply proportionately to a firm's business model. Why does the FCA think the Duty matters in crypto?Because retail consumers often deal directly with crypto platforms and may face heightened risks around complex products, poor disclosures, weak support, limited redress and inadequate safeguarding. What will firms need to do on products and services?Firms will need to define target markets, monitor products, assess distribution channels, consider vulnerable customers and maintain strong governance over token listings and product launches. How will fair value apply?Crypto firms will need to show a reasonable relationship between the price customers pay and the benefits they receive, including in relation to fees, spreads and pricing models. What changes are expected around consumer understanding?Firms will need clearer communications, stronger risk warnings and more robust appropriateness testing, including questions covering the matters in COBS 10 Annex 4G, which will become a binding rule. Will complaints handling rules apply?Yes. The FCA will apply DISP complaint handling requirements to authorised crypto firms, including procedures for fair investigation, redress and Financial Ombudsman referral rights. Will FSCS protection apply to cryptoasset activities?No. The FCA will not extend FSCS protection to cryptoasset activities, so customers would not be compensated by the FSCS for investment losses. What should firms do now?Firms should start gap analyses and implementation planning across product governance, pricing, disclosures, onboarding, appropriateness testing, complaints, safeguarding, monitoring and Consumer Duty governance. How can Dentons help?Dentons can support crypto firms with Consumer Duty implementation, FCA authorisation, product governance, financial promotions, complaints handling, safeguarding, operational resilience and regulatory gap analyses.
Q&A
SM&CR and the UK Cryptoasset Regime: What Firms Should Be Doing Now Ahead of 2027
A key component of the new cryptoasset regulatory regime is the application of the Senior Managers and Certification Regime (SM&CR). While authorised firms under the Financial Services and Markets Act 2000 (FSMA) are already familiar with the framework, a large number of cryptoasset businesses may be engaging with these requirements in depth for the first time. The existing SM&CR framework will apply to cryptoasset firms, including Senior Management Functions, Certification Functions, Prescribed Responsibilities and Conduct Rules. Cryptoasset firms will need to demonstrate robust governance, effective oversight, appropriate systems and controls and mature compliance frameworks in order to operate successfully under the future regime.
For many cryptoasset firms, the move from MLR registration to full FSMA authorisation will involve a significant increase in regulatory expectations, particularly in relation to governance, board oversight and individual accountability. The FCA is increasingly focused on whether boards and senior management teams can demonstrate effective governance in practice, rather than simply maintaining formal structures on paper. In recent consultation materials, the FCA highlighted concerns observed across parts of the cryptoasset sector where responsibilities were overly concentrated in a small number of founders or senior individuals, with insufficient challenge, oversight or independent governance. The collapse of the cryptoasset exchange FTX was specifically referenced as an example of the risks arising from unclear allocation of responsibilities, unmanaged conflicts of interest and weak governance arrangements.[1] Against this backdrop, boards under the future regime will be expected to demonstrate clear oversight of key business risks, effective challenge and escalation processes and robust decision-making frameworks supported by adequate management information and governance controls. Firms should also consider whether governance arrangements remain appropriate as the business grows, particularly where individuals hold multiple roles or responsibilities across group entities.
Board and Senior Manager Accountability
[1] CP25/25, Application of FCA Handbook for Regulated Cryptoasset Activities, 3.29. [2] New regime for cryptoassets regulation – Introduction to the Senior Managers and Certification Regime (SM&CR) webinar, PS 26/13 at page 36. [3] PS26/13 at page 35
There are three categories of firms under the SM&CR: Limited Scope; Core; and Enhanced, with the level of regulatory obligations increasing depending on the size, complexity and potential impact of the firm. The FCA currently expects most cryptoasset firms will fall within the “Core” SM&CR category, although firms with more complex structures or significant custody operations may face enhanced requirements.[2] Individuals performing Senior Management Functions (SMFs) must: obtain FCA approval before carrying out their roles; have clearly documented Statements of Responsibilities (SoRs) setting out the areas for which they are accountable; and be subject to ongoing monitoring by the firm to ensure they remain fit and proper (F&P assessment). The FCA has repeatedly indicated that these documents (i.e. the SoRs and F&P assessments) are likely to be reviewed closely in the event of a regulatory issue or supervisory concern. Firms should also assess whether SMFs have sufficient capacity, resources and proximity to the business areas they oversee to exercise effective oversight in practice. This includes considering factors such as role allocation, reporting lines and the location of key individuals. The FCA's policy is that mind and management should be located in the UK. Physical location is particularly considered when the FCA assesses applications for Compliance (SMF16) and MLRO (SMF17) roles. The FCA's expectation is that individuals performing these roles will work from the firm's principal place of business in the UK.[3]
Alongside the Senior Managers Regime, firms will also need to consider the application of the Certification Regime. This applies to individuals who are not SMFs, but whose roles could nevertheless pose a risk of significant harm to the firm or its customers. Depending on the firm’s business model, this may include individuals involved in client dealing, arranging transactions in cryptoassets or proprietary trading activities. The regime places responsibility on firms themselves to assess and certify that relevant individuals are fit and proper to perform their roles on appointment and at least annually thereafter. The FCA has also confirmed that, pending wider reforms to the SM&CR, it intends to use a "modification by consent" approach during the authorisation gateway. This is intended to defer firms' compliance with certain aspects of the Certification Regime until the wider SM&CR reforms have been finalised, avoiding firms having to implement requirements that may shortly change.
Certification Regime
Fitness and propriety assessments continue to be an area of significant FCA focus and are expected to play a central role in cryptoasset authorisations. The FCA has reinforced that FSMA fitness and propriety expectations are broader than those currently applied under the MLR regime. Firms should not assume that existing recruitment and due diligence processes will satisfy future regulatory expectations.[4] The FCA expects firms to assess honesty, integrity and reputation, competence and capability and financial soundness on both appointment and an ongoing basis. There will also be an increased focus on non-financial misconduct considerations. Firms should not overlook past behaviour that could undermine confidence in the individual or the wider institution. In practice, firms should ensure that fitness and propriety assessments are properly documented and supported by robust evidence, including: employment and regulatory references; criminal and financial checks where appropriate; interview assessments; competency evaluations; and documented rationale for appointment decisions. Where concerns are identified but firms nevertheless proceed with an appointment, the FCA expects firms to be able to demonstrate that risks were appropriately assessed and mitigated.
Fitness and Propriety
[4] New regime for cryptoassets regulation – Introduction to the Senior Managers and Certification Regime (SM&CR) webinar.
The Conduct Rules establish minimum standards of behaviour for individuals working within regulated firms and are intended to support a culture of accountability and responsible conduct across the organisation. The rules require individuals to act with integrity, exercise due skill, care and diligence, deal openly and cooperatively with regulators and observe proper standards of market conduct. Senior managers are subject to additional obligations requiring them to take reasonable steps to ensure that the business areas for which they are responsible are effectively controlled and comply with regulatory requirements. Where the FCA considers that reasonable steps were not taken, SMFs could face enforcement action, including fines, public censure, restrictions on performing regulated functions or prohibition from working in regulated financial services roles. For cryptoasset firms, the Conduct Rules are likely to form an increasingly important part of the FCA’s supervisory focus, particularly as the regulator continues to emphasise governance, culture and consumer outcomes. Firms should therefore ensure that Conduct Rules training, internal reporting processes and disciplinary frameworks are appropriately embedded across the business.
Individual Conduct Rules and Firm Culture
In preparation for authorisation under the UK’s future cryptoasset regime and the application of SM&CR, firms should begin taking proactive steps now to assess whether their governance, oversight and accountability frameworks are capable of supporting a fully authorised FSMA-regulated business. Key focus areas should include: reviewing governance structures, board composition and reporting lines to ensure clear oversight and accountability; identifying likely SMFs and mapping responsibilities across the business; preparing SoRs and documenting governance and decision-making processes; assessing whether Compliance, Risk and MLRO functions are sufficiently resourced and appropriately located; reviewing fitness and propriety frameworks, including recruitment, due diligence and ongoing monitoring processes; identifying individuals likely to fall within the Certification Regime and developing annual certification processes; enhancing Conduct Rules training and embedding accountability and escalation procedures across the organisation; reviewing systems and controls around conflicts of interest, operational resilience and customer protection; assessing whether existing compliance frameworks designed for MLR registration are sufficient for full FSMA authorisation; and conducting gap analyses against SM&CR, Consumer Duty and wider FCA governance expectations. Contact any member of the Dentons Regulatory & Investigations team if you would like to discuss further how your firm can prepare for the future UK cryptoasset regime.
What is changing for cryptoasset firms under the future UK regime?The future UK cryptoasset regime is expected to come into force from 25 October 2027 and will move crypto firms from the current MLR registration framework to a broader FSMA-style regulatory model focused on governance, accountability and conduct standards. Will cryptoasset firms be subject to SM&CR?Yes. The FCA has confirmed it will apply the Senior Managers and Certification Regime (SM&CR) to cryptoasset firms, including Senior Management Functions (SMFs), Certification Functions, Prescribed Responsibilities and Conduct Rules. Why is SM&CR important for crypto firms?SM&CR is designed to increase individual accountability, strengthen governance and improve oversight within regulated firms. For many crypto firms, this will represent a significant increase in regulatory expectations. What concerns has the FCA identified in the crypto sector?The FCA has highlighted concerns around founder-led governance structures, unclear allocation of responsibilities, weak oversight, unmanaged conflicts of interest and insufficient independent challenge. The collapse of cryptoasset exchange FTX has been referenced as an example of governance failures the FCA wants to avoid. What will boards and senior managers be expected cero demonstrate?Boards and senior management (who will be SMFs under the SM&CR regime) will be expected to demonstrate effective governance in practice, including clear oversight of key risks, escalation procedures, decision-making frameworks and appropriate management information and controls. What could SMFs be personally liable for under the new regime?Under SM&CR, SMFs may face regulatory scrutiny where failures occur in the business areas for which they are responsible. Senior managers are required to take “reasonable steps” to ensure that the areas of the business for which they are accountable are effectively controlled and comply with regulatory requirements. Where the FCA believes reasonable steps were not taken, senior managers may face enforcement action, including fines, public censure, restrictions on performing regulated functions or prohibition from working in regulated financial services roles. What categories of firms exist under SM&CR?There are three categories: Limited Scope, Core, Enhanced. The FCA currently expects most cryptoasset firms to fall within the “Core” category, although larger or more complex firms may face "Enhanced" firm requirements. What are the requirements for Senior Management Functions (SMFs)?Individuals performing SMFs must: obtain FCA approval before carrying out their role; have clearly documented Statements of Responsibilities; and remain fit and proper on an ongoing basis. Will the FCA expect key individuals to be based in the UK?Yes. The FCA has indicated a preference for key control functions, including Compliance (SMF16) and MLRO (SMF17), to be based in the UK to ensure effective oversight and accountability. What is the Certification Regime?The Certification Regime applies to individuals who are not SMFs, but whose roles could pose a risk of significant harm to the firm or its customers. Firms must assess and certify these individuals as fit and proper at least annually. The FCA has also confirmed that, pending wider reforms to the SM&CR, it intends to use a "modification by consent" approach during the authorisation gateway in relation to certain aspects of the Certification Regime. What does the FCA expect regarding fitness and propriety?Firms will need to assess honesty, integrity, competence, capability and financial soundness on appointment and on an ongoing basis. The FCA is also increasingly focused on non-financial misconduct considerations. What evidence should firms maintain for fitness and propriety assessments?Firms should maintain robust documentation, including: regulatory and employment references; criminal and financial checks where appropriate; competency assessments; interview records; and documented rationale for appointment decisions. What are the Conduct Rules?The Conduct Rules establish minimum behavioural standards for staff in regulated firms, including acting with integrity, exercising due skill and care, dealing openly with regulators and observing proper standards of market conduct. Why are Conduct Rules important for crypto firms?The FCA increasingly views governance, culture and accountability as central to good consumer outcomes. Conduct Rules are therefore likely to become an important supervisory focus for crypto firms. What should crypto firms be doing now?Firms should begin preparing now by: reviewing governance structures and reporting lines; identifying likely SMFs and mapping responsibilities; preparing Statements of Responsibilities; reviewing fitness and propriety frameworks; implementing Certification Regime processes; embedding Conduct Rules training and accountability frameworks; reviewing conflicts management and operational resilience arrangements; and conducting regulatory gap analyses against SM&CR and wider FCA expectations. How can Dentons help?Dentons advises cryptoasset firms on SM&CR implementation, governance reviews, FCA authorisations, Statements of Responsibilities, fitness and propriety assessments, Conduct Rules frameworks and broader regulatory readiness planning for the future UK cryptoasset regime.
Cryptoassets before the English courts
August , 2026
Cryptoassets before the English courts: key cases and emerging principles
As the UK prepares to introduce a comprehensive regulatory regime for cryptoassets, a substantial body of case law has developed in parallel. This note summarises key cases in the UK courts that firms looking to carry on cryptoasset business in the UK should be aware of. The English courts and tribunals have considered issues ranging from the status of cryptoassets as property to fraud, asset recovery, jurisdiction, consumer protection and the FCA’s expectations of cryptoasset businesses. In doing so, they have applied established legal principles to novel technologies, complex ownership structures and transactions that frequently cross jurisdictional borders. The cases summarised below illustrate both the flexibility of English law and the areas in which important questions remain unresolved.
The starting point for many cryptoasset disputes is whether the relevant asset is capable of attracting personal property rights. The courts have now firmly accepted that cryptoassets can constitute property, although questions remain as to the precise nature of those rights and the causes of action available to protect them.
Property status of digital assets
Having recognised cryptoassets as property, the UK courts have developed an increasingly sophisticated toolkit for responding to fraud. This includes proprietary injunctions, worldwide freezing orders, disclosure orders against exchanges and, in appropriate cases, mandatory orders requiring technology providers to assist with recovery.
Fraud tracing and recovery
AA v Persons Unknown [2019] EWHC 3556 (Comm)
This case was one of the earliest significant English decisions addressing the proprietary status of cryptoassets. The claimant was an insurer whose customer had suffered a cyberattack. Hackers encrypted the customer’s computer systems and demanded a ransom in Bitcoin in exchange for a decryption tool. The insurer paid approximately US$950,000 in Bitcoin, following which the systems were decrypted. The insurer subsequently brought claims in restitution and constructive trust, and sought a proprietary injunction over the Bitcoin paid to the hackers. The High Court accepted that Bitcoin was property under English law and could therefore be the subject of a proprietary injunction. The decision gave early judicial support to the UK Jurisdiction Taskforce’s conclusion that cryptoassets should not be denied proprietary status merely because they do not fit neatly within the traditional categories of choses in possession or choses in action. The case established the practical foundation on which many subsequent cryptoasset recovery claims have been brought.
Mr D’Aloia, an Italian engineer and founder of gaming business Microgame, alleged that he had been defrauded of substantial amounts of cryptocurrency through sophisticated fraudulent online trading platforms. The assets included the stablecoins Tether (or USDT) and USD Coin (or USDC). Farnhill J concluded that USDT was neither a chose in action nor a chose in possession (historically the two sole categories of property in English law), but a distinct form of property whose existence did not depend on an underlying legal right enforceable against another person. The decision confirms that cryptoassets can attract property rights and proprietary remedies, although its analysis remains a first-instance authority. As such, it remains subject to scrutiny from higher courts if such a case arises.
D’Aloia v Persons Unknown and Others [2024] EWHC 2342 (Ch)
The claimant brought claims in conversion and trespass to goods against his estranged wife and her sister seeking the recovery of his Bitcoin. The defendants applied to strike out both claims and the claimant applied to add further claims including unjust enrichment, proprietary restitution and causing loss by unlawful means. While the High Court recognised that part of the purpose of the Property (Digital Assets etc.) Act 2025, which came into force in the UK last December, included allowing the common law to develop a framework of personal property rights for digital assets, it found that it was bound to strike out the claimant’s conversion claim given the House of Lords decision in OBG Ltd v Allan [2007] UKHL 21 that only tangible property could be converted. The court had expressed some scepticism as to the claim in trespass to goods, which traditionally requires direct physical interference with tangible assets, but granted the claimant an opportunity to amend his pleading to clarify whether the claim alleged physical interference with the cryptocurrency wallet. The court therefore gave the claimant seven days to apply to amend the Particulars of Claim to specify the alleged physical interference. In the absence of such an application, the trespass to goods claim was to be automatically struck out.
Ping Fai Yuen v Fun Yung Li & Another [2026] EWHC 532 (KB)
The claimant alleged that he had been induced by fraudsters to transfer 32.45 Bitcoin, worth approximately €2.58 million, to fraudulent wallets. Blockchain investigators traced the Bitcoin through 49 transactions to infrastructure associated with a cryptoasset exchange. The High Court continued a proprietary injunction and worldwide freezing order, finding a good arguable case that property rights attached to Bitcoin. It also accepted that “following”, as distinct from tracing, may remain available where the identity of a cryptoasset is preserved despite its being mixed with other assets. A Bankers Trust disclosure order was continued against Huobi, requiring information capable of identifying the relevant account holder controlling the wallet into which the claimant’s Bitcoin had been transferred, and thereby assisting the claimant to locate and preserve the assets. The decision illustrates the willingness of the English courts to compel cryptoasset exchanges to provide customer information where that may assist victims in identifying wrongdoers and recovering misappropriated cryptoassets.
Wilden v Person Unknown [2026] EWHC 1355 (KB)
The proceedings arose from the theft of substantial quantities of cryptocurrency during the 2022 attack on the Wormhole blockchain bridge. Some of the stolen assets were deposited into vaults operated through the Oasis decentralised finance application. The High Court required Oazo Apps to use its technical control over the application to modify the relevant smart contract and recover the assets through what was described as an “ethical hack” or counter-exploit. It is understood that there was a vulnerability in the code of the specific token bridge where it was possible to reverse the hack in this manner. The order demonstrates that the court may grant mandatory relief requiring a technology provider to deploy its technical capabilities to assist with asset recovery. It also highlights the practical importance of identifying entities that retain administrative or technical control over supposedly decentralised protocols.
Tai Mo Shan Limited v Oazo Apps Limited (6 March 2023, unreported1)
1Although unreported, the facts of the case were published in the New York Supreme Court SEC judgment: https://iapps.courts.state.ny.us/nyscef/CaseDetails?docketId=PE6l_PLUS_YSqugbfDL9/PNYAxQ==
The pseudonymous and cross-border nature of cryptoasset transactions creates difficult questions concerning jurisdiction, applicable law, service and the identification of defendants.
Identifying defendants
The claimant (Tulip) alleged that it had lost access to Bitcoin following a hack in which the private keys controlling the relevant assets were deleted. It brought proceedings against the developers and controllers of several Bitcoin networks, seeking orders requiring them to implement a software patch that would enable it to regain control of the Bitcoin, on the basis that they owed it fiduciary and/or tortious duties. The Court of Appeal held that there was a serious issue to be tried as to whether blockchain developers could, in certain circumstances, owe fiduciary duties to users of the relevant networks. Consequently, Tulip was granted permission to serve proceedings out of the jurisdiction. The Court of Appeal commented on the academic discourse surrounding the nature of decentralised governance of cryptoassets and how decisions requiring code to be amended may be a threat to the immutability of the blockchain, recognising that this requires further exploration. Tulip was controlled by Dr Craig Wright, who claimed to be Satoshi Nakamoto, the inventor of Bitcoin. These proceedings were ultimately discontinued following a ruling in COPA against Dr Craig Wright, whereby his assertions that he was Satoshi Nakamoto had been discredited. Nevertheless, the implications of the court’s decision remain important for the duties owed by software developers.
Tulip Trading Ltd v van der Laan [2023] EWCA Civ 83
In D’Aloia, the High Court granted an interim freezing injunction and permitted service of proceedings by alternative means under CPR 6.15 via the transfer of an NFT to the relevant wallets.
D’Aloia v Persons Unknown [2022] EWHC 1723 (Ch)
The claimant brought proceedings after approximately £1.1 million of Bitcoin was transferred from his wallet without authority. On a summary judgment application, the court declined to follow the approach in Boonyaem, holding that the judge in that case misinterpreted earlier authority and that there was no requirement that defendants be identifiable, and valid service of the proceedings gave the court jurisdiction to grant final relief. The differing approaches in Boonyaem and Mooij leave unresolved whether a final money judgment may be entered against defendants who remain genuinely unidentified.
Mooij v Persons Unknown [2024] EWHC 814 (Comm)
The claimant alleged that she had been induced to transfer more than 425,000 USDT through a fraudulent investment scheme. The High Court granted summary judgment against one set of defendants who were unknown but identifiable persons who controlled the relevant wallet addresses containing the claimant’s USDT, but refused to grant summary judgment against a second set of defendants – the alleged fraudsters – on the basis that judgment could not be entered against persons who were wholly unidentifiable.
Boonyaem v Persons Unknown [2023] EWHC 3180 (Comm)
The financial promotions regime represents a further route through which UK regulators can address cryptoasset activity, including promotions communicated by overseas firms to UK consumers.
Financial promotions
The FCA commenced civil proceedings in the High Court against Huobi Global S.A. (HTX Exchange) and persons unknown (alleged related entities) on 21 October 2025, alleging the unlawful promotion of cryptoasset services to UK consumers in breach of section 21 of the FSMA. The FCA is seeking injunctive relief (including under section 380 of the FSMA) to restrain the defendants from communicating financial promotions in breach of section 21. This is the FCA’s first enforcement action against a crypto business for illegal marketing to UK consumers.
FCA v Huobi Global S.A. (FS-2025-000015)2
The Upper Tribunal has also considered the standards expected of cryptoasset businesses seeking registration under the UK’s anti-money laundering regime. These decisions demonstrate that registration requires effective operational controls. These cases are likely to be particularly important for firms seeking authorisation in the UK under the new regulatory regime as they demonstrate the standards the FCA expects of firms entering the perimeter.
Prevention of financial crime and FCA registration
The FCA refused Moneybrain’s application for registration as a cryptoasset exchange provider and custodian wallet provider. It concluded that statements describing the firm’s BiPS token as “backed” by assets and “stabilised” were misleading and had been made deliberately or recklessly. The Upper Tribunal refused to suspend the decision. The case demonstrates that the FCA’s registration assessment is not limited to the technical adequacy of anti-money laundering controls. Firms should note that it may also encompass the firm’s conduct towards customers, the accuracy of its public statements and whether its management has acted with honesty and probity.
Moneybrain Ltd v FCA [2022] UKUT 00257 (TCC)
The FCA identified weaknesses in Vladimir Consulting’s customer due diligence, identity verification, adverse-media screening and procedures for identifying politically exposed persons. It also concluded that the firm’s sole director lacked the necessary skills and experience. The Upper Tribunal refused to suspend the FCA’s decision, holding that general assurances, newly prepared policies and intended improvements were insufficient where material deficiencies remained. It also rejected the firm’s proposed reliance on checks undertaken by other regulated businesses, emphasising that each regulated entity is an individual gatekeeper and must satisfy its own obligations unless the specific requirements for reliance under the MLRs are met.
Vladimir Consulting Ltd v FCA [2022] UKUT 00168 (TCC)
The FCA refused Gidiplus’s application for registration as a cryptoasset exchange provider after identifying deficiencies in its customer risk assessments, due diligence and transaction-monitoring arrangements. Gidiplus sought suspension of the FCA’s decision so that it could continue trading pending determination of its reference. The Upper Tribunal refused the application. The burden was on Gidiplus to show that continued trading would not prejudice the interests protected by the MLRs, including the public, potential victims of financial crime and the integrity of the UK financial system. Proposed remediation and potential commercial harm were insufficient. The case confirms that firms must demonstrate that effective controls are operational during the relevant period.
Gidiplus Ltd v FCA [2022] UKUT 00043 (TCC)
2 You can access the FCA press release here: https://www.fca.org.uk/news/statements/htx-huobi-legal-proceedings
Cryptoasset businesses dealing with UK retail customers must also consider the application of general consumer and financial services protections. Contractual choices of foreign law, jurisdiction or arbitration will not necessarily displace mandatory UK rights.
Consumer protection
Mr Chechetkin, a UK-based lawyer, lost more than £600,000 trading through the Kraken cryptoasset exchange. Kraken’s terms required disputes to be resolved by arbitration seated in California, in which Payward obtained an award declaring that it was not liable. The Commercial Court refused to enforce that award in England. It held that Mr Chechetkin was a consumer for the purposes of the Consumer Rights Act 2015, notwithstanding his professional background and trading experience. Enforcement would be contrary to public policy because the arbitrator had applied Californian law without considering protections available under the CRA and FSMA. The court also found the arbitration clause unfair under the CRA. The decision confirms that foreign law and arbitration provisions will not necessarily displace mandatory UK consumer protections where a contract has a close connection with the UK.
Payward Inc. and Others v Chechetkin [2023] EWHC 1780 (Comm)
Cryptoasset firms carrying on business in the UK should be prepared for the English court’s ability to flex and adapt the common law to address issues posed by digital assets. The English courts have taken the view that these assets are a form of property under English law. In addition, the courts are addressing consumer protection and regulatory issues. Firms should be prepared for and consider: • how digital assets can be traced and recovered. If you are a wallet provider or involved in trading or safeguarding services, the tracing of digital assets may have direct impacts on your business; • the application of consumer protection standards to contracts involving digital assets, including fairness of communications and contractual terms. A novel technology does not protect from claims on standard consumer protection grounds; and • the regulatory regime including the ability of the FCA to enforce this in the Upper Tribunal and the standards expected under the regime. This will become particularly important once the regime enters into force and customers gain additional rights to directly bring action based on FCA rules and/or take cases to the Financial Ombudsman. Several issues nevertheless remain open. These include the availability of personal remedies against unidentified defendants, the application of traditional torts to intangible assets and the circumstances in which developers or other participants in decentralised systems may owe duties to users. It is likely that future cases in the UK courts will address some or all of these issues.
Conclusion