CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

UK FCA Raids Illegal P2P Crypto Sites: What Firms Must Do Now

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING UK FCA Raids Illegal P2P Crypto Sites:What Firms Must Do Now

The UK's Financial Conduct Authority has moved from issuing warnings to physically disrupting unregistered peer-to-peer crypto operations, conducting coordinated enforcement actions at three London locations alongside HMRC and the Metropolitan Police. The agency confirmed that no peer-to-peer cryptocurrency businesses are currently registered in the UK, a statement that effectively puts every operator in that space in breach of the registration regime right now. For accounting firms, auditors, and CFOs advising clients with any exposure to unregistered crypto channels, the enforcement signal is unambiguous: the light-touch era is over, and criminal liability is now a live risk for any business trading digital assets by way of business without proper FCA registration.

UK FCA Raids Illegal P2P Crypto Sites: What Firms Must Do Now

What the FCA Actually Did

The action was the second coordinated enforcement operation of this kind in six months, according to Caroline Black, a consultant at Gherson Solicitors LLP. Rather than issuing further public guidance or warning letters, the FCA issued cease-and-desist notices directly at three London premises, requiring traders to halt their activities immediately. The joint nature of the operation matters: HMRC's involvement points to tax compliance failures running alongside the AML breaches, while the Metropolitan Police's presence signals that criminal prosecution rather than civil penalty is the intended escalation path.

Why P2P Trading Triggers Registration Requirements

Peer-to-peer crypto trading, where individuals buy and sell digital assets directly with each other rather than through a centralized exchange, is not inherently illegal in the UK. What makes it illegal is conducting that activity "by way of business" without registering with the FCA. The registration requirement exists because unregistered operators sit entirely outside the anti-money laundering controls that registered firms must maintain, including customer due diligence, transaction monitoring, suspicious activity reporting, and record-keeping obligations. The FCA's own statement drives this home: by operating outside the registration regime, these traders avoid precisely the controls designed to detect and prevent money laundering.

Criminal Liability Is Now Explicit

Black's characterization of criminal liability as "a live risk" is not hyperbole. Under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, carrying on a relevant financial business without registration is a criminal offence. The FCA's decision to involve the Metropolitan Police in a physical enforcement sweep rather than relying solely on civil powers confirms that prosecutors are prepared to use that provision. Accounting firms advising clients who operate or invest in P2P crypto platforms should document their own client risk assessments and, where warranted, file Suspicious Activity Reports with the National Crime Agency.

The Regulatory Timeline Every Firm Needs on Its Calendar

The enforcement action did not happen in isolation. It coincides with the FCA having recently published detailed regulatory perimeter guidance for the incoming UK cryptoasset regime. Aditya Mittal of Capco noted that following that guidance, firms should treat understanding their in-scope activities as a priority rather than a future exercise. The key dates are now fixed:

Authorization Window and Go-Live Date

The FCA will accept applications for crypto firm authorization from 30 September 2026 through 28 February 2027. The full UK crypto regulatory framework then takes effect on 25 October 2027. That window is short relative to the complexity of a full authorization application, which requires documented governance structures, financial crime policies, capital adequacy evidence, and systems and controls attestations. Firms that miss the window or submit incomplete applications will face the same position as today's unregistered P2P operators: operating outside the regime with no regulatory cover.

Activities Captured by the Incoming Regime

The FCA's perimeter guidance identifies the following activities as requiring authorization under the new framework:

  • Issuing qualifying stablecoins
  • Operating a crypto asset exchange or trading venue
  • Dealing in crypto assets as principal or agent
  • Arranging deals in crypto assets
  • Safeguarding and administering digital assets
  • Staking services offered to retail or professional clients

Each of these maps to specific systems and controls requirements. Any client whose business touches more than one category, say an exchange that also offers staking, will need to assess whether they require separate permissions or whether a single authorization covers the full scope of their activities.

Accounting and Audit Implications for Firms

The raids create several immediate obligations for accounting firms and CFOs, both in terms of client advisory work and their own AML duties as regulated professionals.

Client Risk Assessment Updates

Any client operating in the UK crypto market should be reviewed against the FCA's updated perimeter guidance. Firms that are conducting P2P activity, acting as intermediaries on unregistered platforms, or facilitating transactions through channels that fall outside the registration regime must be escalated to high-risk status on your firm's client risk register. This is not a discretionary exercise: the UK's MLR 2017 requires accounting firms themselves to maintain risk-based procedures, and accepting or retaining a client operating an unregistered regulated activity creates direct exposure for the firm.

Transaction Monitoring and the HMRC Angle

HMRC's participation in the raids underlines that tax non-compliance and AML risk are being treated as linked, not separate, problems in this enforcement cycle. Unregistered P2P operators typically lack the transaction records required to calculate capital gains accurately, report income from trading activity, or evidence the cost basis of disposed assets. For any accounting practice preparing tax returns or financial statements for clients in this space, the absence of proper records is itself a red flag requiring enhanced due diligence before accepting the engagement.

What Robust Crypto Accounting Software Must Now Evidence

The enforcement action sharpens the case for firms to audit the quality of their digital asset accounting software stack. Effective crypto accounting software used in a professional services context should now be capable of producing a complete transaction-level audit trail that can be handed to a regulator or law enforcement on request. That means wallet-level attribution, timestamped exchange records, counterparty identification where available, and reconciliation to on-chain data. Software that only aggregates gains and losses without preserving the underlying transaction history will not satisfy the evidential standards that the FCA and HMRC are now clearly prepared to enforce.

Firms reviewing their crypto bookkeeping software or digital asset accounting software should also confirm that the tool can flag transactions routed through unhosted wallets or high-risk jurisdictions, since those are precisely the channels that unregistered P2P operations tend to use. See our analysis of FCA crypto authorization guidance and the September application window for the specific disclosure and systems requirements attached to the incoming regime.

AML Red Flags Specific to P2P Channels

For compliance officers and auditors, the FCA's confirmation that zero registered P2P businesses exist in the UK is itself a screening criterion. Any transaction flow your client can trace back to a UK-based P2P counterparty is, by definition, a transaction involving an unregistered entity. That does not automatically mean the funds are criminal, but it does mean that enhanced due diligence is mandatory, and any subsequent SAR decision must be documented with reference to this regulatory fact.

Common Transaction Patterns to Escalate

Unregistered P2P platforms tend to produce recognizable on-chain patterns: high-frequency small transactions from multiple wallet addresses converging on a single consolidation wallet, transactions that avoid round numbers, activity concentrated in cash-equivalent stablecoins, and counterparties with no verifiable KYC trail. Crypto accounting software with blockchain analytics integration should be configured to flag these patterns for manual review. The broader landscape of how state and non-state actors exploit unmonitored crypto channels is covered in our piece on AML red flags in unregistered crypto channels.

Practical Steps for Accounting Firms Before October 2027

The authorization window opening on 30 September 2026 is closer than it looks. Firms advising clients in the crypto sector, and practices that themselves offer crypto-related financial services, should move on the following actions now rather than waiting for the application window to open.

Scoping, Gap Analysis, and Authorization Preparation

First, map every client activity against the FCA's perimeter guidance to determine which permissions are required. Second, conduct a gap analysis between current AML policies, systems, and controls and the standards the FCA will require for authorization. Third, prepare or update the governance documentation that will form the backbone of any authorization application: board-level ownership of financial crime policy, documented risk appetite, and a named Money Laundering Reporting Officer with clear escalation procedures.

For clients who are already operating and cannot pause their business during the authorization process, the critical question is whether any transitional provisions apply. The FCA has not yet published a formal transitional relief framework equivalent to the one used for the original AML registration regime, so firms should not assume that operating during the application window carries automatic protection. Legal advice specific to each client's activities is essential.

Internal Practice Compliance

Accounting firms regulated by a professional body under the MLR 2017 must also review their own AML policies in light of this enforcement signal. The fact that the FCA is now conducting physical enforcement sweeps rather than relying solely on guidance changes the risk calculus for any practice that has crypto-sector clients. Documented evidence of enhanced due diligence, client risk ratings, and SAR decisions will be the first things a regulator or professional body inspection team asks for if a client later turns out to be connected to an unregistered operation.

UK FCA Raids Illegal P2P Crypto Sites: What Firms Must Do Now

Frequently Asked Questions

Is all peer-to-peer crypto trading illegal in the UK?

No. Private individuals who occasionally buy or sell crypto for their own account are not conducting a regulated activity. The registration requirement applies when the activity is carried on "by way of business," meaning with regularity, commercial intent, and for profit. Operating a platform that matches buyers and sellers, or acting as an intermediary on a consistent basis, almost certainly crosses that threshold.

What does "no registered P2P crypto businesses" mean for due diligence?

It means that any counterparty your client identifies as a UK-based P2P operator is, by the FCA's own confirmation, unregistered. That is a mandatory trigger for enhanced due diligence under MLR 2017 and should be documented as such in your client file. It does not automatically require a SAR, but the decision either way must be recorded.

Can a firm apply for FCA authorization after 28 February 2027?

The FCA has set the application window at 30 September 2026 to 28 February 2027. Operating a captured activity after 25 October 2027 without authorization will be a breach of the incoming regime. Firms that miss the window will need to cease in-scope activities until they obtain authorization, which creates significant operational and commercial risk.

How does HMRC's involvement affect tax filings for crypto clients?

HMRC's participation signals that tax compliance is being reviewed alongside AML compliance in these operations. Clients who have transacted through unregistered P2P channels may have unreported capital gains or income. Accounting firms preparing returns for such clients should consider whether they have adequate records to support the figures disclosed, and whether prior year returns may need amendment.

What should accounting firms do if a client refuses to provide transaction records from a P2P platform?

A client's refusal to produce transaction records is itself a red flag under MLR 2017. Firms should consider whether they can continue acting, document their decision-making, and assess whether a SAR to the National Crime Agency is appropriate. Continuing to act without adequate records exposes the firm to its own regulatory and criminal liability.

Source: CoinDesk Policy

UKGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
FCA Raids Three London Sites Over Unregistered P2P Crypto Trading
AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $8.4B Illicit Marketplace Means for Crypto Accounting
AML/KYC & Licensing
OFAC Sanctions Xinbi Guarantee: What the $36B Scam Marketplace Means for Crypto Accounting
AML/KYC & Licensing
NCA Warns of Innovative Crypto Laundering Tactics: What UK Firms Must Do Now