TK Global OS — Regulatory notesCryptoasset licensing: United Kingdom, Kenya, Brazil

Eight reasons FCA cryptoasset applications get sent back

UK Published 2026-08-12

There is a document on the FCA website titled Cryptoassets: what we expect to see in your application for registration, last updated on 30 June 2026. It is the regulator setting out, in its own words, why applications fail. It was written for the money laundering registration regime rather than the FSMA gateway, and firms preparing for the gateway are mostly ignoring it. That is a mistake, because the FCA's diagnosis is about application quality, not about crypto.

The scale of the problem it describes

Across the MLR registration regime the FCA received 359 applications from January 2020 and had registered 44 firms by the time of its 2023/24 annual report. In the year to 31 March 2024, 35 applications produced 4 approvals — over 87 per cent were rejected, withdrawn or refused. Approval rates have since improved sharply, to roughly 45 per cent from April 2025, with average processing time just over five months against seventeen months two years earlier. The bar did not move. The files got better.

The eight failure modes

The individual dimension

A disproportionate share of failures attach to people rather than documents. The FCA has said the money laundering reporting officer must be heavily involved in preparing the application, not handed it at the end. It names specific red flags: an MLRO located outside the UK without evidence of adequate oversight; a history of resigning shortly after a successful application; capacity problems from holding multiple concurrent roles; and conflicts of interest, such as an MLRO who is also head of sales. Changing the MLRO mid-process may cause significant delays. Non-disclosure of convictions or regulatory history seriously prejudices an application, and an unspent relevant offence under Schedule 3 is an automatic rejection.

What a good file looks like, in the FCA's words

All key documents present at submission, in final versions with governance sign-off rather than drafts. A risk assessment that identifies "all the specific and unique risks inherent in your business," assessed per product and service. Tools "configured so they cover the inherent risks within your firm's business." A clear line running from business-wide risk assessment, through customer risk assessment, to controls.

The same standard applies to the pre-application service. The FCA has said it will reject requests for pre-application meetings that are not accompanied by meaningful supporting information, and that firms arriving with generic commitments to provide detail later are not prepared. The free meeting is only useful if you bring a drafted position to be tested.

The checklist behind this article

Everything above is drawn from the same working document I use when I read a file: an 11-page readiness checklist for the FCA cryptoasset gateway, with the rule, article number or published FCA statement cited behind every item, and the open questions marked as open rather than guessed at. It covers the seven activity heads with their RAO article numbers, the permanent minimum requirement by activity, the application pack and its attachments, SM&CR, and the eight failure modes the FCA has published. It is USD 149, and buyers get the updated edition free when the September 2026 fee notice and the autumn perimeter guidance land.

If your situation is straightforward, the checklist is genuinely enough and you will not need to speak to me. If it is not, the 48-hour gap check reads what you have and returns a written list of what is missing, in the order it should be fixed.

Get the note when something actually changes

The UK gateway, Kenya's VASP Act and Brazil's BCB regime. Only when a rule, date or figure moves — and primary sources are always marked separately from press reporting.

More on UK