This policy statement sets out the FCA’s final rules and guidance on how key cross-cutting FCA Handbook obligations will apply to regulated cryptoasset activities.
Designated investment business
The FCA has made no changes to its definition of designated investment business.
Approach to International Cryptoasset Firms (AICF): non-handbook guidance
The FCA has made limited changes to its approach for international firms. The expectation that cryptoasset activities should be conducted through a UK legal entity, rather than a branch, will apply to solo-regulated FCA firms under the AICF. Dual-regulated firms may carry on cryptoasset activities from a branch, subject to PRA approval, satisfaction of the FCA’s threshold conditions at authorisation, and holding the relevant permission.
Consumer Duty:
The FCA is proceeding with the application of Principle 12 (A firm must act to deliver good outcomes for retail clients) and PRIN 2A to cryptoasset firms, supplemented by finalised non-Handbook guidance (FG26/5). The Duty will apply in full to cryptoasset firms, subject to limited exemptions for admissions and disclosures activities and trading between participants on a UK qualifying cryptoasset trading platform. The guidance is framed around retail market business and makes clear that a firm’s responsibilities will depend on its role and level of influence over retail customer outcomes in practice, rather than solely on contractual allocation.
The final guidance also provides additional colour on consumer understanding, fair value, territorial scope, consumer support and the respective responsibilities of manufacturers and distributors in the supply chain. The FCA has clarified that firms do not need to offer support across every possible channel, but the channels they do provide must meet customer needs, including for customers with non-standard issues or characteristics of vulnerability. It also signals that firms should avoid complex redemption mechanisms, such as multi-step stablecoin redemptions, while still carrying out required anti-money laundering checks.
See our analysis of the FCA’s proposals for consumer duty and cryptoasset firms here:
CASS
The final rules clarify how the client money and custody regimes apply across cryptoasset activities. CASS 7 will apply where firms receive or hold client money in connection with safeguarding client cryptoassets or undertaking execution, dealing or arranging activities involving qualifying cryptoassets or relevant specified investment cryptoassets (tokenised traditional financial instruments). The FCA has also disapplied the professional client opt-out in CASS 7 for money held in connection with qualifying cryptoasset activities.
For Stablecoin Issuers: The FCA has also clarified the boundary between CASS 7 and CASS 16 for qualifying stablecoin issuers. Firms carrying on the activity of issuing qualifying stablecoins will not be subject to CASS 7 in relation to money held as backing assets, or other money arising from stablecoin issuance, although they may still be subject to other CASS chapters for separate business lines. Stablecoin issuers must also keep backing assets separate from money held under other CASS regimes, while firms safeguarding relevant specified investment cryptoassets will remain subject to CASS 6 for the time being.
SYSC
No change - cryptoasset firms will generally be treated as “other firms” under SYSC unless they are otherwise common platform firms. This means that cryptoassets firms will be have the same general organisation and governance requirements as ‘traditional’ firms.
Senior Managers and Certification Regime (SM&CR)
The FCA is proceeding with applying the SM&CR in full to authorised cryptoasset firms, subject to minor amendments to the Annex of SYSC 23. Given the wider SM&CR is under review, the FCA will use a modification by consent approach to avoid imposing requirements that may soon change. Assessment of Certification Regime compliance will therefore be deferred during the gateway until the Phase 2 SM&CR review changes have been finalised.
The FCA has noted that it may approve Senior Management Function applications for individuals based overseas, for example where a group individual is responsible for implementing strategy in the UK entity. However, the regulators general expectation remains that the firm’s “mind and management” should be located in the UK, with particular attention to physical location for SMF16 (Compliance Oversight) and SMF17(Money Laundering Reporting function)applications.
The final position also removes the requirement for individuals involved in backing asset management for stablecoin issuance to be certified under the proprietary trader certification function.
See our article on SMCR for crypto firms here: UK Cryptoasset Regulatory Regime: Senior Managers & Certification Regime (SM&CR)
Operational resilience
The FCA is proceeding with applying SYSC 15A to cryptoasset firms without change and will not treat permissionless DLTs as outsourcing under SYSC 8.
The final non-Handbook guidance FG26/6 provides additional clarity on outsourcing expectations, setting impact tolerances, mapping exercises, scenario testing and communications, supported by examples of emerging and established good practice from industry. An additional illustrative example of a firm arranging deals in qualifying cryptoassets to show how operational resilience requirements could apply in practice has also been added to the guidance.
Later this year, the FCA intends to consult on non-Handbook guidance on operational resilience for DLT use, aimed at helping firms manage DLT-specific operational and technological risks across both permissionless and permissioned use cases.
See our detailed summary of the Operational Resilience rules here: Operational resilience for cryptoasset firms
Financial crime
No change – the FCA is proceeding with its proposal to apply the financial crime elements of SYSC 6, together with the Financial Crime Guide and Financial Crime Thematic Reviews, to cryptoasset firms.
COBS
The FCA has made some targeted refinements to the application of COBS which sets out the cored standards governing how firms interact with clients.
For CATPs: COBS will be disapplied for non-UK users of overseas-incorporated UK-authorised QCATPs operating via a branch, based on the user’s habitual residence or country of establishment.
Additional guidance has also been added under COBS 6 (Information about the firm) to support consumer understanding.
The FCA has provided further clarification on appropriateness under COBS 10 and plans to consult further on how strengthened appropriateness requirements should apply to existing clients. It is also disapplying COBS 16 client reporting requirements for staking activities, while otherwise proceeding with the remaining COBS proposals.
ESG
The FCA is proceeding with its proposal to apply the ESG Sourcebook requirements in ESG 4.1.1R and ESG 4.3.1R to all cryptoasset firms. These rules prevent cryptoasset firms from using sustainability labels and require cryptoasset firms to ensure that any sustainability references are clear, fair and not misleading, However, it will not extend ESG provisions that are designed for specific firm types, such as asset managers, asset owners and distributors, where those provisions are not relevant to cryptoasset firms.
Dispute resolution
The FCA is proceeding with applying DISP 1 complaint-handling requirements to all cryptoasset firms, subject to any relevant exemptions. It has adjusted the proposed wording for third-party complaint forwarding so that complaints must be forwarded “promptly” rather than “immediately”.
The final position also confirms that non-UK clients will not have access to the Financial Ombudsman Service and that FSCS protection will not be extended to cover cryptoassets.
Reporting
From go-live firms will be expected to submit all existing returns which are not specific to cryptoasset firms , baseline returns, the crypto-specific returns developed ahead of commencement in conjunction with firms, and the applicable prudential reporting.
A demonstration form is to be published by the regulator as an example after the application period closes but before gateway opens. Along with their returns firms may also submit additional supplementary questions. There will then be post implementation refinement after which the regulator will launch a consultation.