Skip to content
Explainers & Guides

Why FCA authorisation won't guarantee crypto firms a bank account

The FCA's crypto authorisation gateway is open, but a licence will not force a bank to offer an account. Here is why registration, authorisation and a bank's own risk decision are three separate things.

By

Published
A paper certificate rests on a doormat outside a bank branch whose security shutter is down and whose door has no handle.

The Financial Conduct Authority's new cryptoasset authorisation gateway opened on 30 September 2026 and closes on 28 February 2027, with the full regime expected to commence on 25 October 2027. For the first time, UK cryptoasset exchanges and custodian wallet providers can apply for a genuine FSMA permission, rather than only the anti-money-laundering registration that currently applies to in-scope businesses. Many in the sector hope this will unlock business banking. It is worth being precise about what authorisation can and cannot do.

The change matters to every UK cryptoasset exchange provider and custodian wallet provider currently registered under the Money Laundering Regulations 2017, to firms already authorised for other activities who now need a variation of permission, and to the major banks that decide whether to offer them a current account. It also matters to anyone assuming a licence alone will solve the UK's crypto banking-access problem.

On 11 August 2026, co-chairs of the Crypto and Digital Assets All-Party Parliamentary Group (APPG) wrote to chief executives of major UK banks asking whether the incoming FCA regime would change their approach to crypto customers. The Government, answering a written question on 28 September 2026, acknowledged that crypto firms face banking-access challenges — two days before the gateway opened. Authorisation and banking access are being discussed in the same breath, but they are not the same decision.

Three different statuses, often used loosely

Industry conversation uses "FCA authorised" as a catch-all. As at 5 October 2026, it is not one thing.

StatusWhat it coversCurrent position
MLR registrationLegal requirement for in-scope UK cryptoasset exchange and custodian wallet businesses, since 10 January 2020Remains the main regime most firms hold; not an FCA endorsement
FSMA authorisation (new regime)Seven new regulated cryptoasset activities created by the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026Application window open 30 September 2026 to 28 February 2027; full commencement expected 25 October 2027
Variation of permissionRequired where a firm already holds FSMA authorisation for another activity and needs the new cryptoasset permission addedApplies case by case; not automatic

An existing MLR registration does not convert automatically into authorisation under the new regime. Registered firms must apply through the new gateway, and firms already authorised under FSMA for another activity must seek the relevant variation of permission. None of this happens by default.

What the APPG actually asked

The Crypto and Digital Assets APPG is a cross-party group of parliamentarians with an interest in the sector. It is not a House of Commons select committee, and its inquiry is not a formal parliamentary committee inquiry in the way the Treasury Committee's work is. The distinction matters for how much weight to put on its findings once published.

The APPG's call for evidence ran for six weeks, from 21 July to 31 August 2026. On 11 August, its co-chairs wrote to chief executives of major banks and banking service providers with six broad questions: what their policies towards crypto businesses are, whether they provide accounts or other services, what transaction restrictions they apply, what regulatory, legal, compliance, commercial and risk factors drive those decisions, whether the incoming FCA authorisation regime will change their approach, and what Government or regulators could do. As at 5 October 2026, no verified final report or complete set of bank responses was located. The questions sketch a useful framework: they separate what the FCA decides, what the bank's own compliance function decides, and what its commercial risk appetite decides.

Decision one: what the FCA authorises

FCA authorisation assesses an applicant against regulatory threshold conditions and activity-specific rules. It tests governance, systems and controls, and fitness to carry on the regulated activity applied for. What it does not do is perform a bank's customer due diligence, trace the firm's future transactions, or accept financial-crime exposure on a bank's behalf. A licence is evidence a bank can use in its own assessment. It is not a substitute for that assessment.

Decision two: the bank's own anti-money-laundering duty

Banks are themselves "relevant persons" under the Money Laundering Regulations 2017, which transposed the EU's Fourth Anti-Money Laundering Directive and align with Financial Action Task Force standards, and which remain UK law, as amended, after EU exit. Under regulation 18, a bank must assess the money-laundering and terrorist-financing risk to its own business, considering the customer, the countries involved, the products and the delivery channels. Under regulations 27 and 28, it must carry out customer due diligence before establishing a business relationship — identifying the customer and any beneficial owner, understanding the purpose of the relationship, and monitoring it on an ongoing basis.

If a bank cannot complete that due diligence, regulation 31 generally requires it not to transact and to end an existing relationship, subject to the regulation's detailed provisions. This duty sits with the bank. An FCA permission held by the customer does not discharge it.

Decision three: commercial risk appetite

Even where a bank can meet its legal due-diligence obligations, it may still decide that a crypto customer sits outside its risk appetite. Factors can include ownership complexity, the source and destination of funds, customer geography, transaction volumes, blockchain-tracing capability, sanctions exposure, fraud history, operational cost, correspondent-banking requirements and expected commercial return. The precise weighting any individual bank gives these factors has not yet been established from published APPG responses. HM Treasury's position, in its 28 September 2026 answer, is that banking provision is "largely commercial."

No blanket exclusion, but no duty to take unmanageable risk either

The FCA's published guidance states that a risk-based approach should not turn into generic treatment of a whole customer category, and separately that a bank should not enter into or maintain a relationship whose money-laundering risk it cannot manage effectively. Together, wholesale exclusion of every crypto firm is discouraged, but a case-specific refusal or closure, where the risk genuinely cannot be managed, can be lawful or even required.

The Government's expectation, set out in the same 28 September 2026 answer, is that it would not expect a firm licensed under the new regime to be restricted simply because it operates in crypto. That is a policy expectation about fair, individual treatment. It is not a statutory guarantee of service, and the FCA is explicit that companies and organisations have no general legal right to a bank account, and that it cannot require a firm to offer one to a business customer.

A narrower protection: regulation 105

One statutory protection exists, but only for a specific category, not crypto firms generally. Regulation 105 of the Payment Services Regulations 2017 requires that specified authorised or registered payment service providers, and applicants for that status, get access to payment-account services on an objective, non-discriminatory and proportionate basis; refusals or withdrawals must be notified to the FCA with reasons. It helps firms that qualify as specified payment service providers. It is not a universal right to a conventional business current account for every cryptoasset company, and crypto status alone does not trigger it.

What authorisation might improve, and what it cannot guarantee

Authorisation under the new regime may give a bank stronger evidence about a firm's governance and compliance than MLR registration currently does, and it should remove uncertainty about whether the regulated activity itself is lawful to carry on. There is no quantitative evidence yet of how this will affect banks' account decisions, and the available primary sources contain no promise that authorisation will produce an account, prevent a future closure, or stop transaction restrictions.

In February 2023, retail-bank chief executives told the Treasury Committee about restrictions on retail customers' transfers to crypto platforms, citing fraud, volatility and platform stability. That concerned consumer payments, not whether the same banks will open an operating account for a regulated crypto business — the question the APPG's 2026 letter addresses directly.

What the evidence does not yet show

A Treasury Committee report from 26 January 2023 found that around 85% of firms that had applied for MLR registration by that date had failed to demonstrate the minimum standards required — but that figure relates to the earlier registration gateway, not the 2026–27 FSMA authorisation window, and it measures registration failure, not bank account refusal. The FCA's September 2023 payment-account review gathered information from 34 banks, building societies and payment firms across all sectors; it does not produce a reliable crypto-specific acceptance or refusal rate. No verified official percentage for UK crypto firms refused business accounts was located as at 5 October 2026.

Banking-access difficulties are a real commercial problem for the UK crypto sector, distinct from the consumer credit or investment risks this publication usually flags.

What to watch

First, whether the Crypto and Digital Assets APPG publishes its findings and any bank responses — none had surfaced publicly as at 5 October 2026. Second, how the FCA's authorisation gateway performs once applications close on 28 February 2027, and whether authorised firms report any practical change in how banks treat them. Third, whether the regime commences in full as expected on 25 October 2027, a date worth rechecking against the FCA's own gateway page nearer the time, since implementation timetables can move. In the meantime, a firm checking its own position, or a bank's, should consult the FCA's register and the exact wording of the permission granted, rather than relying on the label "FCA authorised" alone.

Sources

  1. Cryptoassets: How the gateway will operate (opens in a new tab)

    Financial Conduct Authority · Accessed

  2. Cryptoassets: AML / CTF regime (opens in a new tab)

    Financial Conduct Authority · · Accessed

  3. Money Laundering Regulations 2017 (opens in a new tab)

    HM Treasury · · Accessed

  4. De-risking: managing money-laundering risk (opens in a new tab)

    Financial Conduct Authority · Accessed

  5. FCA perimeter report (opens in a new tab)

    Financial Conduct Authority · Accessed

  6. The Payment Services Regulations 2017 (opens in a new tab)

    The National Archives · · Accessed

  7. Oral evidence: Retail Banks, HC 1117 (opens in a new tab)

    House of Commons Treasury Committee · · Accessed

  8. UK Payment Accounts: access and closures (opens in a new tab)

    Financial Conduct Authority · · Accessed