Crypto safeguarding rules finalised: what has changed and what should firms do next?
When the FCA published its final rules for stablecoin backing assets and cryptoasset safeguarding, much of the commentary focused on what the regulator introduced.
For firms preparing for authorisation under the new regime, it is just as important to understand what changed between the consultation proposals and the final rules.
The move from CP25/14 to the final CASS 16 and CASS 17 rules shows a regulator that has listened to industry concerns around operational practicality while remaining firm on safeguarding, governance and consumer protection.
At a glance: where firms have greater flexibility and where expectations remain firm
Where the FCA shifted its ground
A more pragmatic approach to liquidity
One of the clearest changes relates to how stablecoin issuers assess liquidity. Under the consultation proposals, firms would have needed to estimate future redemption activity when determining the composition of their backing asset pool. Industry respondents argued that predicting redemption behaviour could be difficult and subjective.
The final rules take a more practical approach. The FCA has removed the requirement to estimate redemption forecasts and instead focuses on maintaining an appropriately liquid pool of backing assets capable of meeting redemption requests as they fall due.
For firms, this reduces modelling complexity while retaining the FCA’s core objective of ensuring customers can redeem stablecoins when required.
The FCA also removed its proposed unallocated backing funds regime following industry feedback. For firms designing treasury, reserve and reconciliation processes, this removes a layer of operational complexity that many considered difficult to implement in practice.
A more workable approach to intragroup arrangements
Many crypto firms operate within wider international groups and depend on shared infrastructure and custody arrangements.
The final rules stop short of prohibiting intragroup custody. Instead, such arrangements remain permissible, subject to concentration limits, governance requirements and appropriate oversight.
For firms operating within global groups, this provides welcome flexibility and avoids the need for significant structural changes. However, firms will still need to demonstrate that intragroup arrangements do not compromise the protection of customer assets.
A framework that better reflects how crypto markets operate
The final safeguarding framework also recognises practical issues around settlement arrangements, operational wallets and key management that are specific to digital asset businesses.
The FCA has introduced greater flexibility in several areas, but firms using those flexibilities will need to demonstrate that customer assets remain adequately protected and that their control environment remains effective.
What did not change may be more important than what did
For all the adjustments made during consultation, the most striking feature of the final rules is how much remained unchanged.
Segregation of assets, statutory trust protections, reconciliations, governance frameworks and oversight of third parties remain central pillars of the regime. The FCA listened to arguments about operational practicality. It was far less receptive to arguments that would dilute safeguarding standards or reduce accountability.
The consultation changes should not be interpreted as a relaxation of standards. Instead, they suggest a regulator that is prepared to be pragmatic about implementation while remaining firm on customer protection and accountability.
For many firms, the challenge is no longer understanding what the rules require. The challenge is demonstrating that their governance, controls and safeguarding arrangements can meet those requirements in practice.
The focus has shifted from interpretation to implementation
The FCA’s application gateway opens on 30 September 2026 and closes on 28 February 2027, ahead of the new regime taking effect on 25 October 2027. Firms are also being encouraged to engage early through its Pre-Application Support Service (PASS).
Attention is now shifting from regulatory interpretation to implementation.
Many firms are focusing on:
- safeguarding and custody operating models;
- private key management and wallet controls;
- governance arrangements and Senior Managers and Certification Regime (SMCR) accountability;
- reconciliation processes;
- third-party and intragroup dependencies;
- operational resilience;
- prudential and liquidity requirements; and
- authorisation planning.
The firms most likely to navigate authorisation successfully are those that can clearly evidence that their governance, controls and operating arrangements meet the FCA’s final expectations.
Is your business ready?
The consultation process demonstrates that the FCA is willing to listen and adapt where there is a strong case for operational practicality. However, firms should not mistake that flexibility for a lower regulatory bar.
The final rules are more detailed, more workable and more closely aligned with the realities of operating a digital asset business than many firms anticipated when CP25/14 was first published.
The FCA has not changed the destination: a regulated cryptoasset market built on robust safeguarding, effective governance and customer protection. What has changed is the route firms can take to get there.
With the authorisation window opening in September, firms should be testing whether their safeguarding arrangements, governance frameworks, operational controls and authorisation plans are aligned with the final CASS 16 and CASS 17 requirements.
If you would like to discuss your readiness for authorisations under the new regime, please contact our financial services team to explore your implementation roadmap.
