Nadia Suleiman
London, England
Oct 4, 2026

For a cryptoasset business, the first authorisation question is not how to complete an FCA application. It is which activities require permission—and which legal entity is carrying them on.

That distinction matters. A token’s marketing label does not determine its regulatory treatment, and a business described as a technology platform may perform several legally distinct functions. A useful perimeter assessment connects the rights attached to an asset with the substance of the services provided around it.

Source and timing caveat: The supplied account refers to FCA Policy Statement PS26/18, publication on 16 September 2026 and commencement of a wider regime on 25 October 2027. Those details, and the claimed final wording of PERG 18, could not be independently verified for this article. They should not be treated as confirmed implementation dates or final rules without checking the FCA publication and the enacted legislation.

1. Establish what the token represents

The starting point is the asset, not the product name. “Utility token”, “stablecoin” and “digital collectible” are descriptions, not conclusive legal classifications.

Firms should examine the token’s terms, associated contracts and operation in practice. Does the holder have a claim against an issuer? Rights to repayment, income or an underlying asset? An interest in a pooled investment arrangement? Or access to a service without financial rights?

This assessment also needs to consider existing regulation. Some tokenised instruments can already fall within established investment categories; tokenisation does not remove them from the financial-services perimeter. The FCA’s cryptoassets information is a starting point, alongside the relevant legislation and Handbook provisions.

Where a framework distinguishes qualifying cryptoassets from specified investment cryptoassets, firms must apply the statutory definitions and any overlap provisions. A broad commercial description is not enough.

2. Separate the underlying right from its digital record

Tokenised traditional assets raise a further question: does the token merely record a right that exists independently, or is holding or transferring the token integral to that right?

Consider a token associated with a conventional security. If the legally effective ownership record sits elsewhere, the token may have a different role from one whose transfer itself changes ownership or entitlement. Firms need to establish which records and contractual provisions have legal effect, including what happens when on-chain and off-chain records disagree.

The supplied account describes a “solely a record” test. Its precise scope must be checked against the final legal text and guidance. Firms should not infer that every tokenised traditional asset is excluded from a cryptoasset regime—or that every digital representation belongs within it.

3. Map activities, not just products

A single customer journey can contain issuance, exchange, transaction arrangement, custody and staking. Each function needs its own assessment.

A practical activity map should identify:

  • which entity contracts with the customer;
  • who receives and transmits instructions;
  • who brings about or executes transactions;
  • who controls assets or the means of accessing them;
  • who exercises discretion; and
  • which functions are delegated to group companies or external providers.

These questions help expose gaps between a product description and its operation. Outsourcing a function does not, by itself, establish that the customer-facing firm has no regulatory responsibility. Equally, supplying infrastructure does not necessarily mean a provider performs every activity that infrastructure supports.

For staking, firms should distinguish the validation process from the customer service. Asset control, transaction permissions, reward allocation and contractual obligations may each affect the analysis.

4. Apply the business and territorial tests separately

Asset classification alone does not establish an authorisation requirement. Firms must also examine the relevant activity’s business and territorial conditions, together with applicable exclusions or exemptions.

Incorporation, server location and website accessibility are not reliable substitutes for that analysis. An overseas firm should not assume that having no UK office resolves its position; a UK group should not assume that every affiliate performs the same regulated activity.

The territorial rules may differ between activities and regulatory regimes. Firms should document the applicable legal test rather than rely on a general concept of being “UK-facing”.

5. Do not mistake technology provision for an automatic exemption

The supplied account identifies software development, transmission networks and non-discretionary interfaces as activities that do not, by themselves, constitute regulated intermediation.

That distinction is important for proportionate regulation. A developer should not be treated as a financial intermediary simply because its software supports financial transactions. But “software provider” is not a safe harbour: operating the service, exercising discretion or performing an in-scope transaction function may change the assessment.

Clear boundaries can protect customers without unnecessarily forcing infrastructure developers into an authorisation process designed for financial-service providers.

Keep existing obligations separate

A future authorisation regime would not make current requirements irrelevant. FCA registration under the money-laundering regulations is distinct from Part 4A authorisation. The UK cryptoasset financial promotions regime is another separate assessment, including for overseas businesses marketing to UK consumers.

Under section 19 of the Financial Services and Markets Act 2000, the general prohibition restricts carrying on regulated activities in the UK unless authorised or exempt. The applicable legislation establishes that obligation; perimeter guidance helps interpret it.

The useful output is therefore not a one-line conclusion that a business is “in scope”. It is a documented, entity-by-entity assessment of assets, activities, territorial connections and permissions, with clear assumptions and triggers for review. Changes to token rights, custody arrangements or the customer journey should prompt reassessment.

That work should precede an application. It helps firms seek the right permissions—and gives smaller technology businesses a firmer basis for explaining when their services do not require them.