Cryptoasset Authorisation: Getting the Regulatory Business Plan Right First Time
From 25 October 2027, a much broader range of cryptoasset activities will fall within the Financial Conduct Authority's (FCA) regulatory perimeter under the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026. Firms undertaking regulated activities will require FCA authorisation, rather than simply registration under the Money Laundering Regulations. Existing registrations will not automatically convert into authorisation.
More immediately, the expedited application window opens on 30 September 2026 and closes on 28 February 2027. Firms which want to benefit from the saving provisions and continue operating while their application is being determined need to apply during this period. The FCA has also been explicit that firms should apply as early as possible. Poor quality or incomplete applications can result in delay, rejection or ultimately refusal.
For crypto and blockchain businesses that have historically operated outside the full Financial Services and Markets Act 2000 (FSMA) regime, this represents a significant change. The challenge is not simply completing an FCA application form. Firms need to be able to demonstrate that the business they are seeking permission to operate is viable, appropriately governed, adequately capitalised and supported by a control environment capable of meeting FCA standards from day one.
At the centre of that is the Regulatory Business Plan.
Start with the regulatory perimeter
Before drafting the Regulatory Business Plan, firms need to be clear about exactly what they are seeking permission to do.
The new regime covers activities including operating cryptoasset trading platforms, safeguarding cryptoassets, dealing as principal or agent, arranging deals, staking and certain stablecoin activities. The FCA's final perimeter guidance was published on 16 September 2026 and firms are expected to assess their activities against it.
This can be particularly difficult for innovative business models. A single proposition can combine technology, custody, execution, payments, staking, lending or other services, potentially bringing different parts of the operating model within different regulatory requirements.
The practical challenge is therefore to move from describing what the technology does to describing, precisely, what the legal entities do, which regulated activities arise and which permissions are required.
Getting the perimeter wrong at the start can create problems throughout the application. The permissions requested, financial forecasts, governance structure, capital requirements, customer journey and control framework all need to tell the same story.
The Regulatory Business Plan is much more than a business plan
The FCA's application materials specifically require firms to upload a Regulatory Business Plan and state that it must be tailored to the firm's business model. A generic document will not be accepted.
That distinction matters.
A commercial business plan is generally written to explain why a business will succeed. A regulatory business plan needs to explain how it will succeed within the regulatory framework, what risks the business creates and how those risks will be controlled.
It should effectively provide the narrative that connects the different parts of the application.
The FCA's application framework includes the Regulatory Business Plan alongside permissions, senior managers, controllers, organisational structure, financial forecasts, IT controls, financial crime arrangements, compliance monitoring and complaints handling. There are then substantial additional requirements depending on whether the firm is issuing stablecoins, safeguarding assets, providing staking or lending services, acting as an intermediary or operating a Cryptoasset Trading Platform (CATP).
A good Regulatory Business Plan therefore needs to be capable of standing behind all of these components.
What should a robust Regulatory Business Plan contain?
There is no benefit in producing a long document for its own sake. The objective should be a clear, internally consistent description of the regulated business and how it will operate.
For most firms, this should include:
- Business model and strategy, including the proposition, products and services, target customers, jurisdictions, distribution model, revenue model, growth assumptions and the regulated activities being undertaken.
- Regulatory perimeter and permissions, mapping the activities of each relevant legal entity to the permissions being requested and explaining any important perimeter judgments, exclusions or dependencies.
- Governance and accountability, covering the Board, executive structure, Senior Managers and Certification Regime (SM&CR), decision-making, reporting lines, risk ownership and the resources and capability required to run the regulated business.
- Risk and control framework, including compliance, financial crime, conflicts, market conduct, customer protection, complaints, record keeping, safeguarding and any activity-specific controls.
- Financial resources, demonstrating how the business will be funded, its expected revenues and costs, its capital and liquidity requirements, stress scenarios and how it can remain adequately resourced as the business grows.
- Operating model and technology, covering the end-to-end customer and transaction lifecycle, key systems, blockchain infrastructure, cybersecurity, outsourcing and third parties, data, IT controls, operational resilience and business continuity.
- Implementation and ongoing compliance, explaining what is already in place, what still needs to be built, who owns the actions and when the firm will be ready to operate within the new regime.
This also needs to reflect the firm's particular activity. A custody business, for example, will need to demonstrate robust records, reconciliation, safeguarding arrangements and security around customers' means of access. A CATP will need to address areas such as access, admissions, execution, conflicts, market abuse, algorithmic trading and market-making controls. Stablecoin issuers face additional requirements around backing assets, redemption and disclosures.
Capital, liquidity and the operating model cannot be an afterthought
One of the more significant changes for many crypto firms will be the move into a full prudential and systems and controls environment.
The FCA's new framework applies prudential requirements alongside wider Handbook obligations including the Consumer Duty, Conduct of Business Sourcebook (COBS), SM&CR, operational resilience and financial crime requirements.
This means the financial model needs to align directly to the business described in the Regulatory Business Plan.
Growth assumptions drive staffing and technology requirements. Transaction volumes affect operational capacity. New products create new risks and control requirements. Outsourcing may reduce internal headcount but introduces third-party dependencies. Capital and liquidity need to be considered against these risks, including stressed circumstances and an orderly wind-down.
Similarly, an organisation chart is not an operating model. Firms need to be able to show who actually performs each important activity, where accountability sits, how first and second line controls operate and how senior management receives sufficient information to oversee the business.
The Regulatory Business Plan should bring these components together.
Getting it right first time matters
Regulatory applications for new and innovative businesses are rarely completely straightforward.
NLC have developed regulatory business plans for novel businesses where the regulatory perimeter was complex and the proposition did not fit neatly within a single established model. In our experience, the quality of the initial Regulatory Business Plan makes a material difference to the application process.
A well constructed application enables the regulator to understand the business quickly. More importantly, it reduces inconsistencies between the business model, requested permissions, financial projections and control framework.
Where those elements do not align, the result is usually further questions, revised submissions and additional rounds of regulatory engagement. Each round of to-and-fro extends the approval process, often by months.
The question firms should ultimately be able to answer is simple:
Does the application describe a business that the FCA can understand, supervise and reasonably conclude is ready to be regulated?
How can New Link Consulting help?
New Link Consulting supports firms across the full new business launch process, including regulatory permission application support, business planning incorporating capital and liquidity, and operating model design.
For cryptoasset firms approaching the new authorisation window, we can take ownership of the Regulatory Business Plan itself, working with management, legal advisers, compliance, finance and technology teams to develop a single coherent regulatory narrative.
That includes translating the commercial proposition into the regulatory business model, testing the perimeter and proposed permissions, developing the capital and liquidity narrative, documenting the target operating model and control environment, identifying gaps against FCA expectations and ensuring that the wider application is consistent with the Regulatory Business Plan.
The objective is not simply to produce a document that can be uploaded with an application. It is to produce a regulatory business plan that accurately represents how the firm intends to operate and gives the regulator the information it needs to assess the application efficiently.
With the application window opening on 30 September, firms that have not yet begun this process should now be moving quickly.
For further information on how New Link Consulting can support your cryptoasset authorisation, please contact Tom Masters, Mark Adams or Corinne Lidlow.
Tom Masters
Partner
- Tom has been a partner since 2014, specialising in organisational structure and strategy, risk and control, banking regulation and financial crime.
- Delivered complex regulatory change programmes globally alongside occupying senior interim COO and KYC/AML roles where clients require.
- Prior to NLC, spent five years at RBS leading large-scale, front-to-back transformation and regulatory implementation.
Mark Adams
Director
- Mark has nearly 40 years of experience across Retail, Corporate, Investment and Custody Banking. He has worked with New Link Consulting since 2017, and as a Director since 2021.
- Has been retained by clients on successive long-term engagements, keen to leverage his broad experience and trusted ability to successfully deliver across a wide range of regulatory and strategic change projects in both the First and Second Lines of Defence.
- Fully proficient in the performance of impact assessments and gap analysis, facilitating delivery of remedial actions, undertaking risk assessments and design of appropriate mitigating controls, Target Operating Model design and robust project governance execution.
Corinne Lidlow
Director
- Corinne has over 35 years of Financial Services experience, primarily within Investment Banking, combining deep expertise in Risk, Operations, COO functions and business transformation.
- She has led high-profile regulatory, risk and control programmes, including enterprise-wide risk framework implementations, governance transformations and operating model redesigns for global financial institutions.
- Corinne partners effectively with senior stakeholders to deliver practical, sustainable solutions that enhance governance, mitigate risk, improve operational effectiveness and support strategic business objectives.

