FCA Puts Own Funds At The Heart Of Its Crypto Prudential Guidance
The FCA’s crypto rulebook has spent the past year answering a scope question: which firms and which activities fall inside the perimeter created by the Cryptoassets Regulations. Two guidance consultations that close on 30 July move the debate onto harder ground. GC26/4 and GC26/5 set out how the regulator expects cryptoasset firms to think about capital, financial resources and the overall risk assessment that sits behind them, and they land just weeks before the authorisation gateway opens in September.
Both are non-Handbook guidance. GC26/4 accompanies Chapter 7 of COREPRU, the core prudential sourcebook, and GC26/5 accompanies Chapter 7 of CRYPTOPRU, the sector-specific sourcebook for firms carrying on regulated cryptoasset activities. Neither creates new binding rules. Instead, each explains what the FCA expects the overall risk assessment to achieve once the finalised prudential regime, confirmed in policy statement PS26/12, takes effect. For firms preparing applications, that distinction matters less than it sounds: guidance on how the FCA reads its own rules is, in practice, the supervisory yardstick.
Own funds, front and centre
The finalised regime in PS26/12 sets the definition and composition of regulatory capital, or own funds, for CRYPTOPRU firms. The design leans on higher-quality “going concern” capital, the kind that absorbs losses while a firm keeps operating, and permits only a limited amount of “gone concern” capital, which counts mainly in wind-down. That mirrors the logic of the banking and investment-firm regimes: a firm that wants permission to hold client cryptoassets or run a trading venue needs a capital base that survives stress, not a balance sheet padded with instruments that thin out when they are most needed.
The overall risk assessment is the mechanism that ties that capital base to a firm’s real risk profile. Under both sourcebooks, Chapter 7 asks firms to run a continuous, forward-looking assessment of whether they hold adequate financial resources, capital and liquidity alike, against the risks they actually run. The FCA’s guidance is deliberately about purpose rather than a checklist. It wants management teams to own the judgement about how much is enough, documented and defensible, rather than treat a regulatory minimum as a ceiling. Concentration, liquidity and an orderly wind-down are the recurring themes.
Why two sourcebooks
The split design is doing real work. COREPRU sets a common prudential floor that is intended to reach across FCA-regulated sectors over time; for now it bites on firms doing regulated crypto activity. CRYPTOPRU layers the crypto-specific requirements on top. Dividing the guidance across GC26/4 (COREPRU 7) and GC26/5 (CRYPTOPRU 7) means a firm has to reconcile both: the general expectation of an overall risk assessment, and the version tuned to crypto business models, where asset volatility, custody and operational risk dominate the picture.
A short runway into September
The timetable is tight. Responses to both consultations are due by 30 July. The FCA plans to open its gateway for cryptoasset permission applications in September. A firm that waits for final guidance before modelling its own funds and drafting its overall risk assessment will be building the two most load-bearing parts of its application in the few weeks between the consultation close and the gateway opening. The prudential lens, not the scope question, is now what decides who can realistically clear the gate.
The reach extends past crypto-native firms. Banks, e-money firms and payment institutions with crypto exposure, or plans to offer crypto services, will have to map how the new prudential expectations interact with the regimes they already sit under. For a dual-regulated bank, the question is less a fresh capital charge than one of consistency: supervisors will expect the crypto arm’s risk assessment to speak the same language as the group’s wider capital-adequacy work.
What firms should do before 30 July
For compliance and finance teams the practical asks are coming into focus. Model own funds against the going-concern and gone-concern split now, rather than assuming existing capital qualifies. Stand up an overall risk assessment that is genuinely continuous and board-owned, with concentration, liquidity and wind-down scenarios evidenced. And respond to GC26/4 and GC26/5 before the close, because guidance the FCA adopts after this window is the text supervisors will hold applicants to from September.
The FCA could still publish a feedback statement or adjust the guidance once the consultation closes, and firms should watch for either. But the direction is set. The UK crypto regime has moved from asking who sits inside the perimeter to asking whether they are capitalised, and self-aware, enough to stay there.
Sources: FCA GC26/4 (Non-Handbook Guidance on COREPRU 7: Overall risk assessment); FCA GC26/5 (Non-Handbook Guidance on CRYPTOPRU 7: Overall risk assessment for CRYPTOPRU firms); FCA PS26/12 (A prudential regime for cryptoasset firms); FSMA Cryptoassets Regulations 2026; FCA crypto regime timeline (authorisation gateway, September 2026).
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.