FCA Crypto Enforcement: What the UK's AML Crackdown Means for Compliance Teams
Some links in this article are affiliate links. See our disclosure policy. This content is for informational purposes only and does not constitute legal advice.
FCA crypto enforcement has moved from the margins to the centre of the UK's financial crime agenda. The Financial Conduct Authority has signalled, through a series of coordinated actions and public statements, that unregistered cryptoasset activity — particularly peer-to-peer trading, crypto ATMs, and informal exchange services — sits squarely in its enforcement crosshairs. For compliance teams, the message is straightforward: UK crypto AML compliance is no longer a niche concern for a handful of registered firms. It is a perimeter question that touches banks, payment institutions, and any business with crypto exposure.
This article examines the enforcement context, the AML obligations that flow from the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), how the UK approach compares with the US, and what firms should do now. Where specific enforcement actions or dates are referenced, organisations should verify the latest position directly with the FCA and the National Crime Agency (NCA), as supervisory activity evolves quickly.
Enforcement Context: A Coordinated Perimeter Strategy
The FCA's crypto enforcement strategy rests on a simple premise: if you conduct cryptoasset activity by way of business in the UK, you must be registered with the FCA under the MLR 2017. That registration requirement applies to cryptoasset exchange providers and custodian wallet providers. Peer-to-peer crypto trading conducted by way of business, crypto ATM operation, and informal OTC brokerage all fall within scope.
What has changed is the coordination. The FCA has been working alongside HM Revenue & Customs (HMRC) and the Metropolitan Police Service on operations targeting suspected unregistered crypto businesses, including raids on premises and the issuance of cease and desist letters. These are not isolated actions. The FCA has publicly signalled that evidence gathered in such operations feeds into broader criminal investigations, and it has previously prosecuted operators of unlawful crypto ATM networks. Organisations should verify the current status of specific operations with the FCA's published enforcement notices.
The Registration Gap and Why It Matters
The UK's cryptoasset registration regime is deliberately narrow. Firms that fail to register, or that operate outside the registered perimeter, bypass the customer due diligence, transaction monitoring, and reporting controls that the MLR 2017 requires. That is precisely the risk the FCA is targeting: unregistered traders can move illicit funds with fewer friction points, undermining the controls that registered firms must maintain.
For traditional financial institutions, the implication is direct. If a bank or payment institution provides services to an unregistered crypto business — or fails to identify that a customer is conducting unregistered cryptoactivity — it may be facilitating the very activity the FCA is trying to disrupt. This is where the FCA's supervisory expectations around customer risk assessment and ongoing monitoring become critical.
The EES Investigation: An FCA AML Investigation to Watch
The FCA has opened an FCA AML investigation into Euro Exchange Securities UK Ltd (EES) for potential offences under the MLR 2017. The alleged failures span risk assessment, customer due diligence, ongoing monitoring, internal governance, resourcing, record-keeping, and escalation. The investigation followed earlier supervisory action, including a requirement to cease regulated electronic money and payment services, the appointment of interim managers, and a High Court appointment of special administrators under the Payment and Electronic Money Institution Insolvency Regulations 2021. A First Supervisory Notice imposed an assets requirement and ringfencing of relevant funds.
Two points matter for compliance teams. First, the FCA has not reached conclusions — organisations should verify the latest position. Second, the EES case illustrates that the FCA's AML enforcement is not confined to crypto-native firms. It reaches payment and e-money institutions whose control frameworks are found wanting. The same MLR 2017 obligations — risk assessment, CDD, ongoing monitoring, governance — apply across the regulated perimeter.
Key AML Compliance Takeaways
The FCA's approach reflects a philosophy articulated by Steve Smart, the FCA's executive director of enforcement and market oversight, who has used the metaphor of a beehive — "protecting the hive" — to describe how collective defence, signal-reading, and rapid coordinated action can combat financial crime. The practical translation for compliance teams is that no single firm has the full picture, and the FCA expects firms to share information, act quickly on red flags, and maintain controls that withstand scrutiny.
1. Registration Is the Baseline
Any firm conducting cryptoasset activity by way of business in the UK must be registered with the FCA under the MLR 2017. The UK is also moving toward a fuller cryptoasset regime under the Financial Services and Markets Act (FSMA) framework, which will expand the FCA's remit. For now, registration under the MLR 2017 is the threshold requirement. Operating without it is not a technical breach — it is the core offence the FCA is pursuing.
2. KYC/CDD Expectations Are Non-Negotiable
The MLR 2017 requires firms to identify and verify customers, identify beneficial owners, and understand the purpose and intended nature of the business relationship. For crypto firms, this means source of funds and source of wealth checks that are proportionate to risk. The EES investigation underscores what happens when these controls are assessed as inadequate: supervisory intervention, management displacement, and potential enforcement.
3. Transaction Monitoring Must Be Risk-Based and Documented
Ongoing monitoring is an explicit MLR 2017 obligation. For crypto businesses, that means monitoring on-chain and off-chain activity for patterns consistent with money laundering or terrorist financing, and documenting the rationale for the monitoring rules applied. The FCA expects firms to be able to explain not just what they monitor, but why.
4. SAR Filing Goes to the NCA — Not FinCEN
This is a point of persistent confusion. UK suspicious activity reports (SARs) are filed with the National Crime Agency (NCA), which hosts the UK Financial Intelligence Unit (UKFIU). The legal basis is the Proceeds of Crime Act 2002 (POCA) and the MLR 2017, not the US Bank Secrecy Act. Firms must submit SARs using the NCA's reporting system, and they must observe the tipping-off provisions in POCA. If you are evaluating tooling that advertises "FinCEN-format" SAR generation, recognise that this is a US capability; the equivalent UK workflow requires NCA-compatible reporting. Some platforms support both, but the distinction matters for compliance accuracy.
5. The Travel Rule Applies
The UK's implementation of the Financial Action Task Force (FATF) travel rule requires cryptoasset businesses to obtain, hold, and transmit originator and beneficiary information for transfers. This is an operational and data-governance challenge, and it is a core expectation for registered firms.
How the US Approach Compares
The UK and US are on divergent trajectories. In the US, crypto enforcement has been driven primarily by FinCEN (under the Bank Secrecy Act), the Office of Foreign Assets Control (OFAC) for sanctions, and the SEC and CFTC for securities and commodities questions. The US has no comprehensive federal market structure legislation for digital assets; the Digital Asset Market Clarity Act advanced through the House in 2025, but its Senate path remains unresolved. Organisations should verify the current legislative status before relying on any specific outcome.
The practical consequence is that US crypto firms operate under agency rules that can shift with each administration, while the EU has moved to a more durable framework under the Markets in Crypto-Assets Regulation (MiCA), which applied fully to crypto-asset service providers from 30 December 2024. The UK sits between these poles: it has a registration regime under the MLR 2017 and is building a fuller FSMA-based regime. For compliance teams, the divergence means that a single global AML programme must account for different registration triggers, different SAR destinations (FinCEN vs NCA), and different sanctions lists (OFAC vs OFSI — the UK's Office of Financial Sanctions Implementation).
Practical Compliance Checklist
For crypto firms and traditional financial institutions with crypto exposure, the following actions are a reasonable starting point. This is not legal advice, and firms should verify current requirements with the FCA and qualified counsel.
- Confirm your registration status. If you conduct cryptoasset activity by way of business in the UK, verify that you are registered with the FCA under the MLR 2017. If you are not, seek advice immediately.
- Refresh your business-wide risk assessment. The MLR 2017 requires a documented assessment of money laundering and terrorist financing risk across customers, geographies, products, transactions, and delivery channels. Update it and evidence the review.
- Strengthen CDD and EDD. Ensure customer identification, beneficial ownership, and source of funds/wealth checks are proportionate to risk and documented.
- Review transaction monitoring. Confirm that monitoring rules cover crypto-specific typologies and that alerts are investigated and documented.
- Validate your SAR workflow. Confirm that SARs are filed with the NCA (UKFIU) and that tipping-off obligations are understood. If you operate in the US, maintain a separate FinCEN workflow.
- Implement travel rule compliance. Ensure originator and beneficiary information is collected and transmitted for covered transfers.
- Screen against the right lists. UK firms should screen against OFSI and UN sanctions lists, alongside OFAC where US exposure exists.
- Conduct vendor due diligence. For any third-party AML or monitoring tool, verify data sources, list coverage, and jurisdictional fit. Ask vendors to evidence their claims.
For firms dealing with high false-positive rates in transaction monitoring, AI-driven platforms such as RisksRadarAI are designed to correlate signals across HR, finance, and security systems to reduce noise — a capability that can help compliance teams focus on genuine risk. When evaluating such tools, confirm that SAR outputs map to the NCA's reporting requirements for UK operations, and to FinCEN for US operations.
Sidebar: The FCA's Principles-Based Approach to AI in AML
The FCA has taken a principles-based approach to AI in financial services, rather than prescribing specific technologies. Its expectations — set out in its AI and machine learning guidance for financial services — emphasise that firms remain accountable for outcomes, that models are explainable and governed, and that consumer outcomes are fair. For compliance teams using AI in AML, this means:
- Accountability sits with the firm, not the model. Senior managers remain responsible for AML outcomes.
- Explainability matters. Firms should be able to explain how AI-driven monitoring and screening decisions are reached, particularly when they lead to SARs or account exits.
- Governance is expected. Model risk management, validation, and ongoing monitoring apply to AML AI just as they do to other models.
- Data quality is foundational. AI is only as good as the data feeding it; firms should evidence data lineage and quality controls.
This is distinct from the EU's approach under the AI Act, which classifies certain AI systems by risk level and imposes specific obligations. UK firms operating in both jurisdictions should map their AI AML tools against both regimes. For teams assessing risk classification, tools like AIGovHub's AI Act Risk Classifier can help determine where a system falls under the EU framework.
Key Takeaways
- FCA crypto enforcement is targeting unregistered cryptoasset activity, including peer-to-peer trading and crypto ATMs, through coordinated operations with HMRC and the Metropolitan Police.
- UK crypto AML compliance starts with registration under the MLR 2017; operating by way of business without it is the core offence.
- The FCA AML investigation into EES shows that enforcement reaches payment and e-money institutions, not just crypto-native firms.
- UK SARs go to the NCA (UKFIU) under POCA and the MLR 2017 — not to FinCEN. Maintain separate workflows for US operations.
- The US and UK are on divergent paths; MiCA provides a more durable EU framework, while the UK builds a fuller FSMA-based regime.
- AI in AML is governed by principles in the UK and by risk classification in the EU; firms operating in both must map to both.
What to Do Next
If your firm has crypto exposure — directly or through customers — the time to review your AML controls is now. Start with a documented risk assessment, validate your registration status, and test your SAR workflow against the NCA's requirements. For teams looking to strengthen monitoring and sanctions screening, AIGovHub's SENTINEL module provides geopolitical intelligence and sanctions screening across multiple lists, while RisksRadarAI offers AI-driven transaction monitoring and SAR workflow support. Both should be evaluated against your specific jurisdictional obligations. Organisations should verify the latest regulatory timelines and enforcement positions directly with the FCA and NCA.
This content is for informational purposes only and does not constitute legal advice.