CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

FCA Raids Three London Sites Over Unregistered P2P Crypto Trading

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING FCA Raids Three London Sites OverUnregistered P2P Crypto Trading

The Financial Conduct Authority has moved against three additional London locations suspected of running peer-to-peer crypto trading operations without registration, continuing a pattern of targeted physical enforcement that carries serious implications for any firm handling digital assets in the UK. For accounting firms, auditors, and CFOs advising clients in the space, this action is a concrete reminder that the regulator is not limiting its scrutiny to online platforms: it is physically attending unregistered premises and, where necessary, making arrests.

FCA Raids Three London Sites Over Unregistered P2P Crypto Trading

What the FCA Action Involves

The FCA's latest operation targeted three sites in London where individuals were allegedly facilitating crypto-to-cash and crypto-to-crypto exchanges on a peer-to-peer basis, outside of the regulatory perimeter. Peer-to-peer trading venues that act as intermediaries, match buyers and sellers, or hold funds in the course of exchange are required to register with the FCA under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, commonly known as the MLRs. Operating without that registration is a criminal offence.

This is not the FCA's first physical intervention of this kind. The regulator has been progressively expanding enforcement against unregistered crypto venues across London, treating in-person, cash-adjacent operations as a particularly high-risk segment of the market. The September 2026 action adds three further locations to an already growing list.

Why P2P Cash-Adjacent Trading Draws Regulatory Attention

Unregistered P2P operations are structurally difficult for the financial system to monitor. When trades are settled in cash or via informal transfers, there is no regulated counterparty producing transaction records, no Travel Rule data being shared, and no Customer Due Diligence being applied systematically. For the FCA, that combination represents a near-ideal environment for layering illicit funds. The physical nature of some of these venues, operating out of retail or commercial premises rather than licensed exchange infrastructure, makes the oversight gap even more pronounced.

The FCA's position, consistent with its broader approach to crypto enforcement, is that the size or apparent informality of an operation does not reduce its regulatory obligations. A small P2P matching service sitting outside the perimeter carries the same legal exposure as a larger unregistered platform.

The UK Regulatory Framework These Sites Are Accused of Breaching

Registration under the MLRs is the baseline requirement for any UK business carrying on cryptoasset exchange activity. That registration obliges firms to implement AML controls, conduct Customer Due Diligence and Enhanced Due Diligence where appropriate, file Suspicious Activity Reports with the National Crime Agency, comply with the Travel Rule for qualifying transfers, and keep records adequate for audit. Firms that are registered are also subject to FCA supervisory visits, transaction monitoring expectations, and ongoing reporting obligations.

The Distinction Between Registration and Full Authorisation

It is worth being precise here because the two terms are often conflated. MLR registration is a compliance gateway: it confirms that a firm meets AML and counter-terrorist financing standards. Full FCA authorisation under the Financial Services and Markets Act, which is now required for crypto firms wishing to offer a wider range of regulated activities under the incoming regime, is a separate and more demanding process. The sites targeted in this action had not cleared even the lower MLR registration bar. That matters because it means there was, in effect, no AML oversight of the transactions they facilitated.

For context on what full FCA authorisation now requires from crypto businesses, the UK FCA crypto authorisation guidance and the September window sets out the specific steps firms must take before applications are submitted.

Accounting and Audit Implications for Firms and CFOs

The enforcement action has several direct implications for accounting professionals and finance leaders who work with UK crypto businesses or whose clients transact through informal channels.

Client Exposure to Unregistered Counterparties

If a client has used an unregistered P2P venue, any transactions routed through that venue are potentially tainted. From an accounting perspective, the records produced by these operations are unlikely to meet the standard required for tax or audit purposes. There is no regulated audit trail, no formal transaction confirmations, and no verified counterparty identity attached to the flow of funds. Firms auditing entities that used such venues will need to assess whether those transactions can be substantiated at all, and whether the lack of documentation gives rise to a qualified opinion or a reportable matter.

For CFOs, the question is whether the business has adequate policies preventing staff or treasury teams from using unregistered venues for over-the-counter or liquidity management purposes. In the current enforcement climate, that is not a theoretical risk.

The Role of Crypto Accounting Software in Producing a Compliant Audit Trail

One of the structural problems with unregistered P2P trading is that it leaves no usable data for proper crypto accounting software workflows. Registered and authorised exchanges produce transaction exports that can be ingested, reconciled, and mapped to cost bases. Unregistered venues do not. Where a client's books contain gaps corresponding to P2P activity conducted outside the regulatory perimeter, those gaps need to be flagged, investigated, and, where possible, reconstructed from available evidence such as wallet records, bank statements, and any counterparty communications.

Robust digital asset accounting software gives firms the capability to identify those gaps during reconciliation, particularly when on-chain data is available to cross-reference against what the client has reported. The absence of matching records from an exchange or custodian is itself a signal that warrants further inquiry.

AML Obligations for Accountants Under the MLRs

Accounting firms that are themselves subject to the MLRs, which applies to many practices providing accountancy or tax services, carry their own Suspicious Activity Report obligations. If information comes to light during an engagement that suggests a client has been using unregistered crypto venues to move funds, the firm's Money Laundering Reporting Officer needs to assess whether a SAR is required. The FCA's enforcement pattern makes this a live issue rather than an abstract compliance consideration.

The broader pattern of crypto being used to route funds through channels that avoid regulated oversight, covered in detail in our analysis of how USDT and encrypted messaging apps are being used to fund illicit activity, underlines why regulators treat unregistered P2P venues as a priority target.

What This Means for the FCA's Enforcement Trajectory

This action is the latest in a sequence of physical interventions. Read together, the FCA's moves against unregistered sites suggest a deliberate strategy: register or face enforcement, and enforcement now includes attending your premises. The regulator has the power to require information, obtain warrants, and refer matters for criminal prosecution. Individuals running unregistered crypto operations face the prospect of prosecution under the MLRs, which carries a maximum two-year custodial sentence, as well as potential proceeds of crime recovery action.

Implications for the Broader Registration Landscape

For firms that are legitimately in the process of seeking FCA registration or authorisation, this enforcement wave has a secondary effect. It signals that the FCA is actively monitoring the perimeter and is aware that some operators are attempting to avoid registration by characterising their activities as informal or small-scale. Firms in the application pipeline should ensure their documentation is precise about the nature of their activities and that no part of their current operations sits outside the scope of their pending registration.

It also reinforces the case for maintaining comprehensive transaction records from day one of operations. When the FCA conducts a supervisory visit or an enforcement inquiry, it will expect to see records that meet MLR standards. Gaps in those records, especially where they correspond to periods before registration was sought, will attract scrutiny. Digital asset accounting software that produces a continuous, time-stamped audit trail is a practical safeguard against that kind of inquiry, not just a back-office convenience.

Practical Steps for Accounting Firms and CFOs

Given the enforcement direction the FCA is taking, there are several concrete steps that advisers and finance leaders should consider now.

Review Client Transaction Sources

Any client who has traded crypto through informal or cash-adjacent channels should be asked to provide documentation of those transactions. If documentation cannot be produced, the firm needs to assess the materiality of the gap and its implications for the financial statements and tax position. Where the sums are significant, specialist forensic analysis of on-chain data may be required.

Update Onboarding Questionnaires

Accounting firms taking on new crypto clients should include specific questions about whether the client has used, or continues to use, unregistered P2P trading venues. This is not just a compliance formality: the answer affects the risk assessment that determines the level of due diligence the firm needs to apply under its own MLR obligations.

Confirm That Crypto Bookkeeping Software Covers All Transaction Sources

CFOs and finance teams should confirm that their crypto bookkeeping software is configured to flag transactions that cannot be matched to a regulated counterparty. Unmatched inflows or outflows that correspond to P2P activity should trigger a manual review process, not simply pass through the system unexamined.

Engage with FCA Guidance Proactively

The FCA has published detailed expectations for cryptoasset businesses at every stage of the registration and authorisation process. Firms that engage with that guidance early, and that can demonstrate a good-faith effort to understand and meet their obligations, are in a materially better position if they later come under supervisory review.

FCA Raids Three London Sites Over Unregistered P2P Crypto Trading

Frequently Asked Questions

Does an informal P2P trading arrangement require FCA registration?

Yes, if the arrangement involves facilitating exchanges between buyers and sellers of cryptoassets, holding funds in the course of that activity, or matching counterparties on a commercial basis, it falls within the scope of the MLRs and requires FCA registration as a cryptoasset business. The informal or cash-based nature of the activity does not create an exemption.

What records should a crypto business keep to satisfy FCA expectations?

Registered firms are expected to maintain Customer Due Diligence records, transaction records including counterparty details and amounts, risk assessments, and evidence of ongoing monitoring. These records must generally be retained for at least five years. Digital asset accounting software that produces time-stamped, auditable transaction logs supports compliance with this requirement.

What are the accounting risks when a client has used an unregistered P2P venue?

Transactions through unregistered venues typically lack the documentation needed to establish cost basis, confirm counterparty identity, or produce a compliant audit trail. This can result in an inability to substantiate reported figures, which may require a qualified audit opinion. Tax positions tied to those transactions may also be unsupportable without reconstruction from alternative evidence.

When must an accounting firm file a Suspicious Activity Report related to a crypto client?

A SAR must be filed with the National Crime Agency when a firm knows, suspects, or has reasonable grounds to suspect that a person is engaged in money laundering or the proceeds of criminal conduct. Discovery that a client has been using unregistered crypto venues to transact significant sums is likely to meet that threshold and should be assessed by the firm's Money Laundering Reporting Officer without tipping off the client.

How does the Travel Rule interact with P2P trading at unregistered venues?

The Travel Rule, which applies to regulated cryptoasset transfers in the UK, requires that originator and beneficiary information travels with the transaction. Unregistered venues do not apply the Travel Rule, meaning transfers through them create gaps in the information chain. For regulated firms receiving funds that originated from an unregistered P2P venue, those incoming transfers may need to be treated as higher risk and subjected to enhanced due diligence.

Source: Decrypt

UKGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
UK FCA Raids Illegal P2P Crypto Sites: What Firms Must Do Now
AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $8.4B Illicit Marketplace Means for Crypto Accounting
AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $36B Scam Marketplace Means for Crypto Accounting
AML/KYC & Licensing
NCA Warns of Innovative Crypto Laundering Tactics: What UK Firms Must Do Now