The FCA actively supervises virtual asset firms, and rejects most registration applications it receives. KYCifi designs and documents the AML programme the FCA expects to see, enhanced by LÆdar AI, so what you submit reflects how you will actually operate.
Under the Money Laundering Regulations 2017 (as amended), any business offering cryptoasset exchange or custodian wallet services in the UK must register with the FCA as a cryptoasset business, and operating unregistered is a criminal offence. The scope is broader than many firms realise.
Centralised exchanges and peer-to-peer trading platforms.
Firms holding private keys on behalf of customers.
Crypto over-the-counter desks and brokerage businesses.
Operators of cryptoasset cash machines.
Crypto payment processors facilitating merchant transactions.
Currently a grey area, but the UK has signalled wider scope; building now beats retrofitting under pressure.
The FCA requires a complete, functioning AML framework, not a policy document assembled from templates. The common reason for rejection is not the business model; it is the compliance documentation.
A business-wide risk assessment specific to your products and customers, an AML/CFT policy, an MLRO with real authority and board reporting, and an annual MLRO report.
CDD covering identity and beneficial ownership, a customer risk-rating framework calibrated to crypto risk, enhanced due diligence for higher-risk customers, and ongoing review.
Documented monitoring rules and thresholds, an alert-triage process with escalation to the MLRO, SAR procedures and record-keeping, and blockchain analytics integration.
FATF Travel Rule procedures above the £1,000 threshold, unhosted-wallet due diligence, sanctions screening, and a staff AML training programme with records.
The FATF Travel Rule requires originator and beneficiary information to travel with virtual asset transfers above the £1,000 threshold. Your firm must exchange customer data with the counterparty VASP on every qualifying transaction, and document what happens when the counterparty cannot or will not provide it.
Most firms understand they need a technical solution. Far fewer have documented the procedures around it, what happens at onboarding, how non-compliant counterparties are handled, and how transfers to unhosted wallets are treated. Those gaps are exactly what the FCA examines.
From our work supporting crypto businesses through FCA registration and supervisory review, these are the failures we see most often, and the ones that cause the most damage.
A BWRA that reads like a template rather than the specific risks of the business. This is usually easy for a reviewer to spot.
Applying the same CDD to all customers. A privacy-coin trader and a small retail buyer are not the same risk profile.
A technical solution but no documented procedure, especially for unhosted wallets and non-compliant counterparties.
Analytics tools that generate alerts, but no documented process for reviewing, closing or escalating them.
Policies that exist on paper but have never been communicated to the people responsible for implementing them.
An MLRO in name only, with no annual report, no management information and no documented escalation decisions.
KYCifi is, first, a specialist AML and KYC practice. Our crypto programmes are designed and documented by financial crime specialists who have taken firms through FCA registration and supervisory review, not generated from a template.
Our practitioners lead every engagement. LÆdar AI, our intelligence platform, does the legwork behind them, screening, monitoring and evidence, so judgement stays with the people and the programme is built as they work.
An end-to-end AML framework built from scratch around your business model, with all fees fixed and agreed in writing before work begins.
Tailored to your products, customers and jurisdiction.
A full suite of operating procedures, not a single document.
Calibrated to crypto-specific risk factors.
Monitoring rules and a documented triage procedure.
Including unhosted wallets and non-compliant counterparties.
Application support and a pre-submission review.
Training materials and delivery, with records.
All fees fixed and agreed in writing before work begins.
Book a free 15-minute consultation. We’ll assess your current compliance position and give you a clear action plan, and what it will cost to build it.
15 minutes. No cost. No commitment. Contact contact@kycifi.com