Eight reasons FCA cryptoasset applications get sent back
There is a document on the FCA website titled Cryptoassets: what we expect to see in your application for registration, last updated on 30 June 2026. It is the regulator setting out, in its own words, why applications fail. It was written for the money laundering registration regime rather than the FSMA gateway, and firms preparing for the gateway are mostly ignoring it. That is a mistake, because the FCA's diagnosis is about application quality, not about crypto.
The scale of the problem it describes
Across the MLR registration regime the FCA received 359 applications from January 2020 and had registered 44 firms by the time of its 2023/24 annual report. In the year to 31 March 2024, 35 applications produced 4 approvals — over 87 per cent were rejected, withdrawn or refused. Approval rates have since improved sharply, to roughly 45 per cent from April 2025, with average processing time just over five months against seventeen months two years earlier. The bar did not move. The files got better.
The eight failure modes
- Generic, off-the-shelf documentation. The FCA's own phrase is material "not appropriately tailored to your business model … generic, off-the-shelf or high level." A supervisor can tell within a page whether a policy was written for your firm or bought.
- Incomplete submission. Missing supporting documents produce rejection without assessment. Note the distinction the FCA draws: rejection means you fell below the minimum information bar; refusal means you failed the standard, triggers a Warning Notice, and goes on the record.
- A business-wide risk assessment disconnected from the customer risk assessment. Generic or irrelevant risks listed, no line drawn through to how customers are risk-rated, and no stated methodology for judging whether a control works.
- Tools left on vendor defaults. "Out of the box" configuration of customer due diligence, PEP screening and transaction monitoring, with no documented rationale for choosing the tool and no evidence of testing or calibration against your own inherent risks.
- Transaction monitoring rules not documented. Rules and thresholds not written down, not fitted to the business model, and not covering both fiat and crypto flows.
- Policies and procedures that contradict each other. The policy says one thing and the operating procedure says another. This is found by reading, not by investigation.
- Training and staff expectations left vague. Generic training material not tailored to the business model.
- Already-authorised firms assuming their framework carries over. Failure to show understanding of the new and unique crypto risks layered on top of an existing framework. Holding another permission is not a head start.
The individual dimension
A disproportionate share of failures attach to people rather than documents. The FCA has said the money laundering reporting officer must be heavily involved in preparing the application, not handed it at the end. It names specific red flags: an MLRO located outside the UK without evidence of adequate oversight; a history of resigning shortly after a successful application; capacity problems from holding multiple concurrent roles; and conflicts of interest, such as an MLRO who is also head of sales. Changing the MLRO mid-process may cause significant delays. Non-disclosure of convictions or regulatory history seriously prejudices an application, and an unspent relevant offence under Schedule 3 is an automatic rejection.
What a good file looks like, in the FCA's words
All key documents present at submission, in final versions with governance sign-off rather than drafts. A risk assessment that identifies "all the specific and unique risks inherent in your business," assessed per product and service. Tools "configured so they cover the inherent risks within your firm's business." A clear line running from business-wide risk assessment, through customer risk assessment, to controls.
The same standard applies to the pre-application service. The FCA has said it will reject requests for pre-application meetings that are not accompanied by meaningful supporting information, and that firms arriving with generic commitments to provide detail later are not prepared. The free meeting is only useful if you bring a drafted position to be tested.
The checklist behind this article
Everything above is drawn from the same working document I use when I read a file: an 11-page readiness checklist for the FCA cryptoasset gateway, with the rule, article number or published FCA statement cited behind every item, and the open questions marked as open rather than guessed at. It covers the seven activity heads with their RAO article numbers, the permanent minimum requirement by activity, the application pack and its attachments, SM&CR, and the eight failure modes the FCA has published. It is USD 149, and buyers get the updated edition free when the September 2026 fee notice and the autumn perimeter guidance land.
If your situation is straightforward, the checklist is genuinely enough and you will not need to speak to me. If it is not, the 48-hour gap check reads what you have and returns a written list of what is missing, in the order it should be fixed.