On July 8, the Financial Conduct Authority (FCA) published a preview of the application forms that firms will be required to complete when applying for authorization to conduct crypto asset business under the new crypto asset regime.
This preview provides valuable clarity on the questions firms will be expected to answer and the information they will need to supply. Given that the application gateway does not open until September 30, and that the final application forms will not be available until then, this advance guidance is particularly welcome. It represents the most detailed insight firms are likely to receive before the application process formally begins.
The guidance sets out not only the questions applicants will be required to answer, but also the supporting information and documentation they must submit. It distinguishes between documents that must be uploaded as part of the application and those that firms must simply attest are in place, while confirming that such documents can be provided to the FCA on request.
The forms and accompanying guidance will be relevant to two broad categories of firms. First, they will be essential reading for firms seeking authorisation for the first time under the new cryptoasset regime. This includes firms currently registered under the Money Laundering Regulations to conduct cryptoasset business, which will not be grandfathered into the new authorisation regime and will instead need to apply for and obtain full authorisation.
Second, the guidance will be highly relevant to FCA-authorised firms that will need to vary their existing permissions in order to provide cryptoasset services. This includes, for example, brokers wishing to deal in cryptoassets as principal or agent, firms arranging transactions in cryptoassets on behalf of clients, and discretionary investment managers seeking authority to transact in cryptoassets on behalf of managed portfolios. For these firms, the intermediary section of the application forms will be particularly important, as it outlines the cryptoasset–specific information that is likely to accompany a Variation of Permission application.
The Application Packs
The application packs are structured around a common set of core questions supplemented by activity-specific sections. Rather than requiring every applicant to navigate a single, generic application, the new framework consists of a common core section for all applicants, supplemented by activity-specific modules tailored to the particular regulated activities for which authorisation is sought.
The core information requirements will be familiar to firms that have undergone the FCA authorisation process in recent years. Each applicant will be required to provide, among other things:
- A regulatory business plan
- Details of senior managers, controllers and close links
- Information regarding IT systems and controls
- Financial forecasts and projected first-year income
- Information on financial promotions activity
- Compliance arrangements and compliance monitoring programs
- Financial crime prevention frameworks
- Complaints handling procedures
- Organizational responsibility and reporting structures identifying senior managers and key decision-makers, together with reporting lines and areas of responsibility
IT and Operational Controls
Each firm will be required to complete an IT controls questionnaire and, where relevant, provide detailed supporting documentation regarding its technology infrastructure and operational resilience arrangements.
Financial Crime Framework
The application places substantial emphasis on financial crime controls. Every firm must submit:
- A business-wide risk assessment
- A customer risk assessment
- Anti–money laundering (AML) policies
- Suspicious activity reporting procedures
- Sanctions controls
- Travel Rule compliance arrangements
- Transaction monitoring procedures
- Operational procedures demonstrating how onboarding, screening, monitoring and escalation processes function in practice
Firms must also explain how alerts will be generated, investigated and documented; how suspicious activity will be identified and reported; and how relevant employees will be trained on AML systems and processes.
Where third-party providers are used for functions such as identity verification, politically exposed person screening or transaction monitoring, the firm will need to explain:
- Services provided
- Data sources used
- Search parameters applied
- Testing methodologies
- Frequency of calibration and review of automated systems
Records Management
Each applicant must submit a cryptoasset records management policy demonstrating how records are stored, protected and retrieved, together with an explanation of the governance framework supporting records management.
Sector-Specific Forms
In addition to the core information requirements, applicants must complete activity-specific sections tailored to the cryptoasset services they intend to provide:
- Issuing qualifying stablecoins
- Safeguarding cryptoassets
- Staking qualifying cryptoassets
- Cryptoasset lending and borrowing
- Intermediaries
- Operating a cryptoasset trading platform (CATP)

