Firms should assess whether they are carrying on crypto asset activity by way of business, whether they benefit from it directly or indirectly, how material the activity is to the wider business, and whether it is conducted from a UK office or UK-facing presence. If the firm markets crypto services to UK consumers, FCA registration is required.
How the FCA decision test works in practice
For crypto firms, the registration question is not just “do we touch crypto?”. The practical test is whether the activity is carried on by way of business, whether the firm benefits from it directly or indirectly, how material it is to the wider business, and whether the activity is conducted from a UK office or a UK-facing presence. If the service is marketed to UK consumers, the regulatory trigger is much harder to avoid.
The key judgment is to separate incidental technical involvement from a real business activity. A firm that merely supports another party’s service may sit outside the perimeter, but once it is operating the service, deriving value from it, or presenting itself to UK users, the FCA analysis becomes substantially more likely to require registration.
That perimeter-style assessment is similar to other regulatory gating questions where the operational reality matters more than the product label. Firms should document who controls the service, who receives the benefit, where the business is actually directed, and whether the UK is a meaningful part of the go-to-market model.
Business model, UK nexus, and marketing are the decisive facts
The strongest indicator is not the technology stack, but the business model. If the crypto activity is part of the firm’s commercial proposition, revenue model, or customer acquisition strategy, it is more likely to be regulated than a purely internal or incidental use of crypto-related tooling.
UK nexus also matters. A UK office, UK-facing website, UK distribution channel, or active promotion to UK consumers can all create the practical connection the FCA cares about. Firms should assume that “we are offshore” is not a safe answer if the service is clearly aimed at the UK market.
When a firm’s role sits in the supply chain, the question becomes whether it is only enabling another regulated service or whether it is itself carrying on a crypto asset activity. That distinction often determines whether the firm needs to register, and it should be tested against actual customer flows, control of assets, and the firm’s own representations to users.
Risk and Threat Considerations
The main risk is underestimating perimeter exposure and treating registration as a branding or legal formality rather than a conduct and supervision issue. Firms that misclassify their activity can create enforcement risk, consumer harm risk, and operational disruption if they have to unwind a UK-facing service after launch.
Failure mechanism: The failure usually comes from a narrow reading of the activity, where a firm focuses on where the technology sits instead of where the business benefit, customer targeting, and UK-facing delivery actually occur. That can leave a firm trading for months before discovering it has been operating inside the FCA perimeter.
Impact: The result can be delayed remediation, forced re-papering of the business model, paused marketing, and supervisory scrutiny. In the worst case, the firm may need to stop serving UK consumers until the registration position is resolved.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM — Risk Management Strategy | UK perimeter decisions need documented risk and governance judgement. |
| GV.OC — Organizational Context | The FCA test depends on business model, UK nexus, and customer targeting. | |
| Recommendation — Record the FCA perimeter decision in governance risk reviews and revisit it when the business model changes. Define whether the crypto activity, UK presence, and consumer targeting place the firm inside FCA scope. | ||
| CIS Controls v8 | 17.1 — Establish and Maintain a Security Awareness Program | Firms should retain evidence and staff awareness around regulated UK-facing activity. |
| Recommendation — Train commercial and product teams to escalate any UK-facing crypto offering before launch. | ||
| NIST SP 800-63 | IAL1 — Identity Proofing Requirements | Consumer-facing crypto services often depend on verified onboarding and jurisdiction checks. |
| Recommendation — Verify customer location and onboarding controls before concluding a service is not UK-facing. | ||
Practitioner Guidance
What to verify: Build a perimeter memo that answers four questions in writing: what crypto asset activity is being performed, who benefits from it, how central it is to the business, and whether any UK office, UK staff, UK domain, or UK marketing activity makes the firm UK-facing. If any one of those facts is unclear, treat the answer as provisional rather than assumed.
Decision rule: If the firm actively markets to UK consumers, or if the crypto activity is a material revenue-generating part of the business, assume FCA registration analysis is required and escalate before launch or expansion. If the activity is incidental and genuinely not UK-facing, keep evidence of that conclusion and review it whenever the operating model changes.
Practitioner takeaway: The safest approach is to judge the regulated activity from the actual commercial and customer-facing facts, not from entity structure or technical architecture alone.
Related resources from NHI Mgmt Group
- How should teams decide whether attestation is required for an API?
- How do organisations decide whether MCP-layer controls are required for AI agents?
- How should compliance teams decide whether the Travel Rule applies to a crypto platform?
- Who should be accountable for keeping POS merchants compliant with registration requirements?