Skip to main content
FCA Crypto Authorization Checklist: October 2027 Readiness TemplateInternational Bodies & Standards
6 min readFor AML Compliance Officers

FCA Crypto Authorization Checklist: October 2027 Readiness Template

The FCA authorisation gateway opens on 30 September 2026 for cryptoasset firms gearing up for the regulatory regime effective 25 October 2027. You'll need a structured readiness assessment to determine if you're in scope and to build the evidence package your application will require.

This checklist template provides a framework to evaluate your regulatory position, document your controls, and identify gaps before the gateway opens. It's designed for compliance officers at firms that may issue qualifying stablecoins, operate trading platforms, deal in cryptoassets, safeguard customer holdings, or arrange staking services.

Purpose of This Template

Use this checklist to:

  • Determine scope: Assess whether each of your business activities requires FCA authorisation under the new regime.
  • Document controls: Map your existing AML/CFT controls, governance structures, and operational safeguards to FCA expectations.
  • Identify gaps: Highlight areas where your current setup doesn't meet authorisation thresholds.
  • Build your evidence file: Create a structured record that supports your application narrative.

This isn't a compliance program; it's a diagnostic tool. You're building a clear view of where you stand before committing resources to an application.

Prerequisites

Before using this template, confirm:

  1. You've read the FCA's guidance: The regulator published detailed perimeter guidance explaining which activities fall within scope. Don't guess, read the source material.
  2. You have access to operational documentation: You'll need business model descriptions, customer onboarding procedures, transaction monitoring rules, and governance records.
  3. You know your current regulatory status: If you're already registered for Money Laundering Regulations compliance, document what that covers and what it doesn't.
  4. You can convene cross-functional input: This assessment requires input from legal, operations, technology, and finance, not just compliance.

The Readiness Assessment Template

Copy this template into a spreadsheet or project management tool. Assign owners to each section and set a completion deadline at least six months before the 30 September 2026 gateway opens.

Section 1: Activity Scope Assessment

Objective: Determine which of your activities require authorisation.

Activity In Scope? Evidence Gap Analysis Owner
Issue qualifying stablecoins Y/N/Unclear Describe the stablecoin, reserve mechanism, redemption rights If yes: Do you meet reserve requirements? Audit trail?
Operate cryptoasset trading platform Y/N/Unclear Platform description, order matching mechanism, custody model If yes: Do you have market abuse controls?
Deal in cryptoassets (principal) Y/N/Unclear Proprietary trading activity, market making arrangements If yes: Are you excluded as a technology provider?
Arrange deals in cryptoassets Y/N/Unclear Brokerage, intermediation, referral services If yes: Do you take custody or just facilitate?
Safeguard cryptoassets Y/N/Unclear Custody arrangements, wallet control, client asset segregation If yes: Do you use a central securities depositary?
Arrange cryptoasset staking Y/N/Unclear Staking services offered, validator operation, reward distribution If yes: Is this incidental to custody or a separate service?

Customization note: Add rows for any hybrid or novel activities your firm offers. The FCA's October 2026 consultation will address decentralised protocols and certain technology providers; flag these for monitoring if they apply to you.

Section 2: AML/CFT Control Inventory

Objective: Document your existing financial crime controls and map them to FCA expectations.

Control Area Current State Evidence Location Meets FCA Standard? Remediation Required
Customer Due Diligence Describe your CDD process, risk-based approach, enhanced due diligence triggers Link to CDD policy, sample customer files Y/N/Partial If no: What's missing?
Beneficial Owner Identification UBO verification thresholds, data sources, refresh cycles Link to UBO procedures, verification records Y/N/Partial If no: What's missing?
Transaction Monitoring Rules Scenarios deployed, thresholds, tuning methodology Link to TM rule library, tuning log Y/N/Partial If no: What's missing?
Name Screening Sanctions lists covered, screening frequency, match resolution process Link to screening policy, vendor contract Y/N/Partial If no: What's missing?
Suspicious Activity Reporting SAR decision framework, escalation to MLRO process, SAR Confidentiality controls Link to SAR policy, escalation log Y/N/Partial If no: What's missing?
Travel Rule Compliance VASP counterparty verification, originator/beneficiary data transmission Link to Travel Rule procedures, technical implementation Y/N/Partial If no: What's missing?
Record Retention Data retention periods, retrieval capability, audit trail integrity Link to retention schedule, data map Y/N/Partial If no: What's missing?

Customization note: The FCA expects risk-based controls calibrated to your business model. If you operate a stablecoin, your reserve audit and redemption monitoring belong here. If you run a trading platform, add market abuse surveillance and wash trading detection.

Section 3: Governance and Accountability

Objective: Confirm you have the governance structures the FCA expects.

Requirement Current State Evidence Gap Owner
Board-level AML/CFT oversight Describe board committee structure, reporting frequency Board minutes, committee charter If no committee: Establish one
Designated MLRO Name, qualifications, reporting line, authority MLRO appointment letter, org chart If MLRO reports to commercial: Fix reporting line
Independent compliance function Compliance team size, budget, independence from business Compliance charter, budget allocation If under-resourced: Build business case
Internal audit of AML controls Audit frequency, scope, remediation tracking Last audit report, remediation log If no recent audit: Schedule one
Training program Training content, delivery frequency, completion tracking Training records, completion rates If ad hoc: Formalise program

Customization note: The FCA will scrutinise your governance during authorisation. If your MLRO reports to your Head of Growth, document the plan to fix that before you apply.

Section 4: Technology and Data Controls

Objective: Validate that your systems can meet regulatory expectations.

Control Current Capability Evidence Gap Owner
Customer data accuracy Data validation at onboarding, Periodic Review process Data quality metrics, refresh schedule If no refresh: Implement Periodic Review
Transaction data completeness Originator/beneficiary data capture, counterparty identification Transaction schema, data completeness report If missing fields: Update data model
Audit trail integrity Immutable logs, timestamp accuracy, retrieval capability Audit log sample, retrieval test results If logs are mutable: Implement controls
Regulatory reporting capability Ability to produce reports on demand, data extraction process Sample regulatory report, extraction procedure If manual: Automate extraction
System resilience Backup procedures, disaster recovery, business continuity DR test results, RTO/RPO metrics If untested: Schedule DR test

Customization note: If you safeguard cryptoassets, add wallet security controls, key management procedures, and segregation mechanisms. If you operate a trading platform, add order book integrity and market data accuracy.

Section 5: Financial Promotions Compliance

Objective: Assess your marketing materials and customer communications.

Promotion Type Current Approach FCA Compliance? Gap Owner
Website content Risk warnings, balanced presentation, clarity Link to website, compliance review If promotional: Add warnings
Social media Approval process, risk disclosure, influencer agreements Sample posts, approval log If unapproved: Implement process
Email campaigns Segmentation, suitability, opt-out mechanism Sample emails, segmentation rules If untargeted: Refine targeting
Referral programs Incentive structure, disclosure of conflicts, suitability Referral T&Cs, conflict disclosure If undisclosed: Add disclosure

Customization note: The FCA's October 2026 consultation will address financial promotions perimeter issues. Monitor that consultation and update this section based on final guidance.

How to Customize It

Tailor to your business model: If you only deal in cryptoassets, delete the stablecoin and staking rows. If you're a pure custody provider, focus on safeguarding and client asset segregation.

Add firm-specific risks: If you serve high-risk jurisdictions, add a geolocation control assessment. If you offer margin trading, add leverage risk controls. If you use third-party service providers, add vendor due diligence.

Set realistic deadlines: Work backwards from 30 September 2026. If a gap requires vendor selection, budget approval, and implementation, you need at least 12 months. Flag those items now.

Assign clear ownership: Every line needs an owner and a deadline. "Compliance team" isn't specific enough, name the person responsible for delivering the evidence.

Validation Steps

Before you consider this assessment complete:

  1. Cross-check against FCA guidance: Re-read the regulator's perimeter guidance and confirm you haven't missed an in-scope activity.
  2. Conduct a peer review: Have a colleague outside compliance review your gap analysis. Fresh eyes catch blind spots.
  3. Quantify remediation costs: For each gap, estimate the cost and time to close it. This becomes your business case for pre-authorisation investment.
  4. Monitor the October 2026 consultation: The FCA will consult on perimeter updates, decentralised protocols, and technology provider exclusions. Update this template when final guidance publishes.
  5. Schedule quarterly reviews: Don't treat this as a one-time exercise. Review and update quarterly as your business evolves and the FCA clarifies expectations.

The firms that get authorised won't be the ones with perfect controls on day one. They'll be the ones who identified their gaps early, built credible remediation plans, and executed them before the gateway opened. This template gives you the structure to be one of them.

You Might Also Like