![]()
The FCA’s Money Laundering Regulations registration has one focus: whether a firm has adequate controls to prevent financial crime. It is a threshold test, not a comprehensive review.
Authorisation is different in kind, not just in degree. The FCA will assess five things it has never previously assessed for most crypto firms.
Business Model Viability
The FCA will want to understand what the firm does, how it makes money, and whether the model is sustainable. A firm that cannot articulate this clearly — in the FCA’s terms, not its own — will struggle early in the process. This is not about whether the business is profitable. It is about whether the FCA can see a coherent, credible case for how it operates within the regulatory perimeter.
Governance
Not whether a board exists or whether responsibilities are listed in an organisational chart. The FCA will want to know whether decision-making works the way the documentation says it does — whether the right people are involved in the right decisions, whether oversight is genuine, and whether the senior individuals responsible can demonstrate their competence in their specific roles.
Informal governance that works in practice does not pass a formal assessment. Firms that rely on well-functioning informality will need to formalise before they apply.
Compliance Framework
A compliance officer is not a compliance framework. The FCA expects a structured function — documented policies, monitoring procedures, a clear escalation path, and evidence that it operates independently of commercial pressure. Firms running lean compliance operations under the current regime will need to build before they apply.
The FCA will want to understand not just what the compliance function does, but how it relates to the rest of the business. A compliance officer who reports to the CEO without a clear escalation path to the board, or whose resource and authority depend on commercial performance, does not present the picture of an independent function.
Consumer Protection
Documented policies are the starting point, not the finish line. The FCA will want to see that consumer protection operates in practice — that outcomes are monitored, that consumer harm is identified and responded to, and that product design is reviewed against consumer outcomes. A document that has never been applied is not the same as a functioning consumer protection framework.
Operational Resilience
Can the firm continue to operate through disruption? Business continuity plans and operational resilience frameworks need to have been exercised, not just written. The FCA expects firms to demonstrate that controls work — that disruption scenarios have been considered and that the response has been tested. A statement of intent is not sufficient.
The Preparation Gap
None of these five areas are assessed at registration stage. All of them require preparation time. A firm beginning this work in August is not giving itself enough runway — particularly for governance documentation and compliance framework development, which cannot be built overnight.
The starting point is a clear-eyed assessment of where your firm stands against each area. Not an optimistic read, but an honest one. The gap between a firm’s current position and where it needs to be is almost always larger than it looks from the inside.
Worth asking:
Which of these five areas could your firm evidence to the FCA’s standard today — and which would require work before you could submit credibly?
Get in touch
We are currently running fixed-price readiness audits for crypto firms preparing to apply for FCA authorisation. If you would like to understand where your firm stands across the five areas covered in this article, contact our team directly.
Email: info@lhiconsult.com | Phone: +44 203 319 5147 | Web: lhiconsult.com
This article is for general information purposes only and does not constitute legal or regulatory advice. LHI Consulting is a trading style of LHI Holdings Ltd, registered in England and Wales, No. 11496647.
FAQs
What is the difference between FCA AML registration and FCA authorisation?
AML registration assesses whether a firm has adequate controls to prevent money laundering and terrorist financing. FCA authorisation is a substantially more comprehensive assessment covering business model viability, governance, compliance framework, consumer protection, and operational resilience. The two processes are separate — registration does not carry over into authorisation and does not reduce the assessment burden.
Do I need to reapply if I am already FCA registered?
Yes. Every firm must submit a full authorisation application regardless of its current registration status. There is no conversion process and no credit given for existing registration. The application window opens 30 September 2026 and closes 28 February 2027.
How long does it take to prepare a credible authorisation application?
For most firms, a minimum of twelve weeks of focused preparation work is required. This includes completing a gap analysis, remediating the issues identified, finalising governance documentation, evidencing the compliance framework, and ensuring consumer protection policies are demonstrably operational. Firms beginning this process in August are at the outer limit of the timeline for a September submission.
What happens if the FCA finds gaps during the application assessment?
The FCA may request further information, issue requirements, or decline the application. A declined application means the firm cannot reapply immediately and must resubmit — including paying the full application fee again. Early preparation reduces the risk of gaps being identified at assessment stage rather than during pre-submission review.
What is a readiness audit and how does it help?
A readiness audit is a structured assessment of your firm’s current position against the five areas the FCA will assess in an authorisation application. It identifies the gaps, prioritises them by risk, and provides a practical set of recommendations for closing them before submission. LHI Consulting offers a fixed-price, three-day readiness audit with written recommendations delivered within five working days of completion.