SECTOR

Regulatory Licencing and Compliance Advisory for Cryptoasset and Digital Asset Firms

No jurisdiction issues a single crypto licence that covers every digital asset activity. Exchange, custody, transfer, brokerage, stablecoin issuance and staking are regulated differently, and often under separate authorisations, within the same regime.

Regulatory classification of tokens, services and business models

UK cryptoasset registration and the transition to the future UK regime

EU MiCA crypto-asset service provider authorisation

Canada, Australia, Singapore and Hong Kong digital asset requirements

Financial crime frameworks including the travel rule and blockchain analytics

Ongoing compliance, reporting and regulator engagement for digital asset firms

Speak to an Expert
OVERVIEW

How we advise cryptoassets & digital assets

Regulatory Counsel advises cryptoasset and digital asset firms on classification first and applications second: what the activity is in regulatory terms, which regime captures it in each market served, and what the resulting compliance obligations look like in practice.

We work across the UK cryptoasset framework and its transition to full regulation, the EU markets in crypto-assets regime, Canadian, Australian, Singaporean and Hong Kong requirements, and the payments and e-money regimes that stablecoin and tokenised money models frequently engage.

Is there a single crypto licence?

No. Regulation attaches to activities, not to the word crypto. A firm running an exchange, holding customer assets in custody, arranging transactions for others and issuing a stablecoin may require different permissions for each of those activities, and different permissions again in each jurisdiction it serves.

This is why classification work comes before application work. Firms that begin with an application form frequently discover midway through that part of the business is outside the regime they applied under, or that a second permission is required before launch.

How are cryptoasset firms regulated in each priority market?

The regimes differ substantially in scope and maturity. The table sets out the primary supervisor and route in each of our priority markets.

JurisdictionRegulatorPrimary route
United KingdomFCARegistration under the Money Laundering Regulations for cryptoasset businesses, with the regime moving toward full authorisation of cryptoasset activities under FSMA
European UnionNational competent authorities under MiCACrypto-asset service provider authorisation, with separate requirements for asset-referenced and e-money tokens
CanadaFINTRAC, with provincial securities regulatorsRegistration as a money services business dealing in virtual currency, plus securities registration or undertakings where platforms trade crypto contracts
AustraliaAUSTRAC, with ASIC for financial productsDigital currency exchange registration, and financial services licencing where the product is a regulated financial product
SingaporeMASPayment Services Act licence covering digital payment token services
Hong KongSFC, with other regulators by activityVirtual asset trading platform licencing, and separate treatment for stablecoin issuance
Cryptoasset regulatory regimes by market

What is changing in the UK cryptoasset regime?

The UK is moving from an anti-money laundering registration regime for cryptoasset businesses to full regulation of cryptoasset activities under the Financial Services and Markets Act framework. Firms currently registered for money laundering purposes should plan for authorisation standards rather than registration standards.

The practical implication is that governance, prudential resources, custody arrangements, conduct standards and disclosure will be assessed in a way that AML registration never required. Firms that built only to registration standard will find the gap material, and the gap is best closed before an application window rather than during it.

What does MiCA require of crypto-asset service providers?

MiCA introduced a harmonised EU authorisation for crypto-asset service providers, covering activities including custody, operation of a trading platform, exchange, execution, placing, reception and transmission of orders, advice, portfolio management and transfer services, together with distinct regimes for asset-referenced tokens and e-money tokens.

Authorisation is granted by a national competent authority and, once obtained, supports cross-border provision within the EU. Firms should not assume that an existing national registration converts automatically; the substantive requirements around governance, custody segregation, prudential safeguards, complaints handling and disclosure are more demanding.

What financial crime controls do digital asset firms need?

Digital asset firms need the standard elements of a financial crime framework, calibrated to on-chain risk: an enterprise-wide risk assessment, customer due diligence, sanctions screening, transaction monitoring using blockchain analytics, travel rule compliance for transfers, and suspicious activity reporting.

  • -Risk assessment covering asset types, chains, counterparties and geography
  • -Blockchain analytics deployment, alert calibration and typology coverage
  • -Travel rule solutions and counterparty due diligence for transfers
  • -Sanctions screening covering wallet addresses as well as names
  • -Governance and management information that shows the controls are working

How does Regulatory Counsel support digital asset firms?

We start with a regulatory classification of the business model, then build the licencing and compliance roadmap that follows from it: which permission in which market, in what sequence, with what control build required before submission.

01

Classify

Determine what each activity and token is in regulatory terms across the markets served.

02

Sequence

Prioritise the permissions that unlock revenue and identify those that can follow later.

03

Build

Governance, custody, financial crime and operational resilience controls to authorisation standard.

04

Apply

Prepare and manage the application and the regulator question process.

05

Operate

Ongoing compliance, reporting, monitoring and regulator engagement after approval.

WHAT WE SEE IN PRACTICE

Practitioner observations from cryptoassets & digital assets engagements

Classification errors are the expensive ones

The costly mistakes we see are not failed applications. They are firms that launched under one regime, grew, and then discovered that a feature added along the way brought the business inside another regime entirely.

Stablecoin models touch payments regulation

Tokenised money and stablecoin products frequently engage e-money or payments frameworks alongside cryptoasset rules. The analysis has to cover both, particularly where redemption at par is promised.

Custody is where supervisors concentrate

Segregation of client assets, key management, wallet architecture and what happens on insolvency attract detailed scrutiny in every maturing regime. Firms should expect to evidence these arrangements rather than describe them.

Classify your digital asset activities before you apply

Tell us your business model, the markets you serve and the permissions you hold. We will tell you what is actually in scope and what the credible route looks like.

Get Expert Advice

Free initial consultation. No obligation.

Frequently asked questions

No. UK registration has no EU effect. Providing crypto-asset services to customers in the European Union generally requires MiCA authorisation from a national competent authority in an EU member state.

Registration under the Money Laundering Regulations assesses whether a firm has adequate financial crime controls and fit and proper individuals. Authorisation assesses the whole business: governance, prudential resources, custody, conduct and operational resilience. The evidential burden is considerably higher.

It needs to assess every market where it has customers or actively markets. Some jurisdictions regulate on the basis of establishment, others on the basis of services directed at local persons. Passive access is not always a defence.

It depends on the token and the jurisdiction. In the EU, e-money tokens and asset-referenced tokens have distinct treatment under MiCA. In the UK, the analysis can engage the e-money and payments framework alongside the cryptoasset regime. Firms should classify the token before designing the product.

It can. Depending on how a staking service is structured, it may be treated as a distinct regulated service, may raise questions about custody of client assets, or may engage collective investment or financial product rules. The structure of the arrangement drives the answer.

The travel rule requires originating and beneficiary information to accompany cryptoasset transfers, with obligations on both sending and receiving firms. Implementation involves solution selection, counterparty due diligence, handling transfers to unhosted wallets and a documented approach to non-compliant counterparties.

By closing the gap between registration standard and authorisation standard: governance and senior management accountability, prudential resources, custody and client asset arrangements, conduct and disclosure, operational resilience, and evidence that controls operate rather than merely exist.

Primary regulatory sources

This page summarises regulatory requirements for orientation. It is not legal advice. The primary sources below govern.