The FCA authorisation gateway opens on 30 September 2026 for cryptoasset firms gearing up for the regulatory regime effective 25 October 2027. You'll need a structured readiness assessment to determine if you're in scope and to build the evidence package your application will require.
This checklist template provides a framework to evaluate your regulatory position, document your controls, and identify gaps before the gateway opens. It's designed for compliance officers at firms that may issue qualifying stablecoins, operate trading platforms, deal in cryptoassets, safeguard customer holdings, or arrange staking services.
Purpose of This Template
Use this checklist to:
- Determine scope: Assess whether each of your business activities requires FCA authorisation under the new regime.
- Document controls: Map your existing AML/CFT controls, governance structures, and operational safeguards to FCA expectations.
- Identify gaps: Highlight areas where your current setup doesn't meet authorisation thresholds.
- Build your evidence file: Create a structured record that supports your application narrative.
This isn't a compliance program; it's a diagnostic tool. You're building a clear view of where you stand before committing resources to an application.
Prerequisites
Before using this template, confirm:
- You've read the FCA's guidance: The regulator published detailed perimeter guidance explaining which activities fall within scope. Don't guess, read the source material.
- You have access to operational documentation: You'll need business model descriptions, customer onboarding procedures, transaction monitoring rules, and governance records.
- You know your current regulatory status: If you're already registered for Money Laundering Regulations compliance, document what that covers and what it doesn't.
- You can convene cross-functional input: This assessment requires input from legal, operations, technology, and finance, not just compliance.
The Readiness Assessment Template
Copy this template into a spreadsheet or project management tool. Assign owners to each section and set a completion deadline at least six months before the 30 September 2026 gateway opens.
Section 1: Activity Scope Assessment
Objective: Determine which of your activities require authorisation.
| Activity | In Scope? | Evidence | Gap Analysis | Owner |
|---|---|---|---|---|
| Issue qualifying stablecoins | Y/N/Unclear | Describe the stablecoin, reserve mechanism, redemption rights | If yes: Do you meet reserve requirements? Audit trail? | |
| Operate cryptoasset trading platform | Y/N/Unclear | Platform description, order matching mechanism, custody model | If yes: Do you have market abuse controls? | |
| Deal in cryptoassets (principal) | Y/N/Unclear | Proprietary trading activity, market making arrangements | If yes: Are you excluded as a technology provider? | |
| Arrange deals in cryptoassets | Y/N/Unclear | Brokerage, intermediation, referral services | If yes: Do you take custody or just facilitate? | |
| Safeguard cryptoassets | Y/N/Unclear | Custody arrangements, wallet control, client asset segregation | If yes: Do you use a central securities depositary? | |
| Arrange cryptoasset staking | Y/N/Unclear | Staking services offered, validator operation, reward distribution | If yes: Is this incidental to custody or a separate service? |
Customization note: Add rows for any hybrid or novel activities your firm offers. The FCA's October 2026 consultation will address decentralised protocols and certain technology providers; flag these for monitoring if they apply to you.
Section 2: AML/CFT Control Inventory
Objective: Document your existing financial crime controls and map them to FCA expectations.
| Control Area | Current State | Evidence Location | Meets FCA Standard? | Remediation Required |
|---|---|---|---|---|
| Customer Due Diligence | Describe your CDD process, risk-based approach, enhanced due diligence triggers | Link to CDD policy, sample customer files | Y/N/Partial | If no: What's missing? |
| Beneficial Owner Identification | UBO verification thresholds, data sources, refresh cycles | Link to UBO procedures, verification records | Y/N/Partial | If no: What's missing? |
| Transaction Monitoring Rules | Scenarios deployed, thresholds, tuning methodology | Link to TM rule library, tuning log | Y/N/Partial | If no: What's missing? |
| Name Screening | Sanctions lists covered, screening frequency, match resolution process | Link to screening policy, vendor contract | Y/N/Partial | If no: What's missing? |
| Suspicious Activity Reporting | SAR decision framework, escalation to MLRO process, SAR Confidentiality controls | Link to SAR policy, escalation log | Y/N/Partial | If no: What's missing? |
| Travel Rule Compliance | VASP counterparty verification, originator/beneficiary data transmission | Link to Travel Rule procedures, technical implementation | Y/N/Partial | If no: What's missing? |
| Record Retention | Data retention periods, retrieval capability, audit trail integrity | Link to retention schedule, data map | Y/N/Partial | If no: What's missing? |
Customization note: The FCA expects risk-based controls calibrated to your business model. If you operate a stablecoin, your reserve audit and redemption monitoring belong here. If you run a trading platform, add market abuse surveillance and wash trading detection.
Section 3: Governance and Accountability
Objective: Confirm you have the governance structures the FCA expects.
| Requirement | Current State | Evidence | Gap | Owner |
|---|---|---|---|---|
| Board-level AML/CFT oversight | Describe board committee structure, reporting frequency | Board minutes, committee charter | If no committee: Establish one | |
| Designated MLRO | Name, qualifications, reporting line, authority | MLRO appointment letter, org chart | If MLRO reports to commercial: Fix reporting line | |
| Independent compliance function | Compliance team size, budget, independence from business | Compliance charter, budget allocation | If under-resourced: Build business case | |
| Internal audit of AML controls | Audit frequency, scope, remediation tracking | Last audit report, remediation log | If no recent audit: Schedule one | |
| Training program | Training content, delivery frequency, completion tracking | Training records, completion rates | If ad hoc: Formalise program |
Customization note: The FCA will scrutinise your governance during authorisation. If your MLRO reports to your Head of Growth, document the plan to fix that before you apply.
Section 4: Technology and Data Controls
Objective: Validate that your systems can meet regulatory expectations.
| Control | Current Capability | Evidence | Gap | Owner |
|---|---|---|---|---|
| Customer data accuracy | Data validation at onboarding, Periodic Review process | Data quality metrics, refresh schedule | If no refresh: Implement Periodic Review | |
| Transaction data completeness | Originator/beneficiary data capture, counterparty identification | Transaction schema, data completeness report | If missing fields: Update data model | |
| Audit trail integrity | Immutable logs, timestamp accuracy, retrieval capability | Audit log sample, retrieval test results | If logs are mutable: Implement controls | |
| Regulatory reporting capability | Ability to produce reports on demand, data extraction process | Sample regulatory report, extraction procedure | If manual: Automate extraction | |
| System resilience | Backup procedures, disaster recovery, business continuity | DR test results, RTO/RPO metrics | If untested: Schedule DR test |
Customization note: If you safeguard cryptoassets, add wallet security controls, key management procedures, and segregation mechanisms. If you operate a trading platform, add order book integrity and market data accuracy.
Section 5: Financial Promotions Compliance
Objective: Assess your marketing materials and customer communications.
| Promotion Type | Current Approach | FCA Compliance? | Gap | Owner |
|---|---|---|---|---|
| Website content | Risk warnings, balanced presentation, clarity | Link to website, compliance review | If promotional: Add warnings | |
| Social media | Approval process, risk disclosure, influencer agreements | Sample posts, approval log | If unapproved: Implement process | |
| Email campaigns | Segmentation, suitability, opt-out mechanism | Sample emails, segmentation rules | If untargeted: Refine targeting | |
| Referral programs | Incentive structure, disclosure of conflicts, suitability | Referral T&Cs, conflict disclosure | If undisclosed: Add disclosure |
Customization note: The FCA's October 2026 consultation will address financial promotions perimeter issues. Monitor that consultation and update this section based on final guidance.
How to Customize It
Tailor to your business model: If you only deal in cryptoassets, delete the stablecoin and staking rows. If you're a pure custody provider, focus on safeguarding and client asset segregation.
Add firm-specific risks: If you serve high-risk jurisdictions, add a geolocation control assessment. If you offer margin trading, add leverage risk controls. If you use third-party service providers, add vendor due diligence.
Set realistic deadlines: Work backwards from 30 September 2026. If a gap requires vendor selection, budget approval, and implementation, you need at least 12 months. Flag those items now.
Assign clear ownership: Every line needs an owner and a deadline. "Compliance team" isn't specific enough, name the person responsible for delivering the evidence.
Validation Steps
Before you consider this assessment complete:
- Cross-check against FCA guidance: Re-read the regulator's perimeter guidance and confirm you haven't missed an in-scope activity.
- Conduct a peer review: Have a colleague outside compliance review your gap analysis. Fresh eyes catch blind spots.
- Quantify remediation costs: For each gap, estimate the cost and time to close it. This becomes your business case for pre-authorisation investment.
- Monitor the October 2026 consultation: The FCA will consult on perimeter updates, decentralised protocols, and technology provider exclusions. Update this template when final guidance publishes.
- Schedule quarterly reviews: Don't treat this as a one-time exercise. Review and update quarterly as your business evolves and the FCA clarifies expectations.
The firms that get authorised won't be the ones with perfect controls on day one. They'll be the ones who identified their gaps early, built credible remediation plans, and executed them before the gateway opened. This template gives you the structure to be one of them.



