The Senior Hires a Crypto Firm Needs Before Applying for FCA Authorisation or a MiCA Licence

The FCA crypto gateway is open and MiCA grandfathering has ended. Which senior roles to hire, in what order and where, before you apply.

Sam Wellalage, Founder
October 6, 2026
9 min read

Before you apply for FCA authorisation or a MiCA CASP licence, you need named, credible people in four seats: a chief executive who runs the regulated entity, a compliance oversight lead, a money laundering reporting officer (MLRO), and a board with the collective knowledge to challenge them. In the UK those people become approved senior managers under SM&CR. In the EU they form a management body that must be of sufficiently good repute and genuinely located in the Union. Hire them before you write the application, not after.

This guide is for founders and CEOs of exchanges, custodians, brokers and stablecoin issuers.

What are the key dates for the UK cryptoasset regime and MiCA?

The UK window is open now. The FCA opened its authorisation gateway on 30 September 2026. The application period closes on 28 February 2027, and the new regime comes into force on 25 October 2027. From that date, carrying on a regulated cryptoasset activity in the UK without authorisation is unlawful.

Three points matter for planning:

  • MLR registration does not convert. The FCA is clear that firms registered under the Money Laundering Regulations will not be automatically converted and must secure authorisation under FSMA.
  • Applying in the window protects existing business. Under the saving provision, a firm that applies during the application period can keep providing cryptoasset services until its application is finally determined, even if that runs past 25 October 2027.
  • Applying late is costly. Firms that apply after the window but are not authorised by go-live fall into a transitional provision where they can only do what is necessary to perform pre-existing contracts.

In the EU, the grandfathering period has already ended. Article 143(3) of MiCA allowed CASPs operating under national law before 30 December 2024 to continue until 1 July 2026 at the latest, and member states could shorten or remove that window. As of today, any firm serving EU clients without MiCA authorisation (or a valid Article 60 notification as an existing financial entity) has no transitional cover.

Which SM&CR roles apply to FCA-authorised crypto firms?

The FCA confirmed in PS26/13, published on 30 June 2026, that it will apply SM&CR in full to authorised cryptoasset firms: senior management functions (SMFs), certification functions, prescribed responsibilities and the conduct rules.

Most crypto firms will be Core firms. The FCA's guide for solo-regulated firms lists the Core SMFs:

  • SMF1 Chief Executive
  • SMF3 Executive Director
  • SMF9 Chair: the only approved role a non-executive can hold.
  • SMF16 Compliance Oversight: responsible for the compliance function and reporting to the board.
  • SMF17 Money Laundering Reporting Officer: oversees compliance with the FCA's anti-money laundering systems and controls rules.

Core firms must also allocate prescribed responsibilities to those senior managers, including responsibility for financial crime policies and, where relevant, compliance with CASS. PS26/13 confirms custodians must give that CASS responsibility (PRz) to an individual SMF, covering both traditional and crypto safe custody.

Enhanced status will be rare at launch. The FCA set the threshold at £100bn in client cryptoassets and safe custody assets for custodians, and £20bn in backing assets (three-year rolling average) for UK qualifying stablecoin issuers. It does not expect many, if any, crypto-only firms to hit Enhanced when the regime starts.

On certification, the FCA will use a "modification by consent" waiver during the gateway, deferring assessment of Certification Regime compliance while the wider SM&CR review runs. In April 2026 the FCA and PRA noted the Government's proposal to remove the Certification Regime from legislation. Staff in significant roles still need to be fit and proper; just do not over-engineer a process that may be dismantled.

What does MiCA require of a CASP's management body?

MiCA sets the standard in Article 68. Members of the management body must be of sufficiently good repute and have the appropriate knowledge, skills and experience, individually and collectively. They must not have convictions for money laundering, terrorist financing or other offences affecting good repute, and must show they can commit sufficient time. The CASP must also employ personnel with the expertise its services require.

The suitability test is set out in the joint EBA and ESMA guidelines on management body members and qualifying holders under MiCA. The sharper practical guidance is in ESMA's supervisory briefing on CASP authorisation (January 2025), which tells national authorities what to look for. Its people expectations include:

  • At least one executive board member resident in the member state granting authorisation (small member states have limited flexibility).
  • The CEO devoting, as a rule, 100% of their time to the CASP, and other executive board members at least half their time.
  • An independent chair of the executive board, with limited dual-hatting with the parent group.
  • At least one dedicated head of compliance or compliance officer. Combining compliance with risk is accepted only in rare, proportionate cases.
  • Board members with a good understanding of how crypto-assets and the services offered actually work. Less management experience can be offset by colleagues with regulated-finance management experience.
  • Compliance with the EBA guidelines on the AML/CFT compliance officer.

The substance requirement

Article 59(2) requires a registered office in a member state where the CASP provides services, a place of effective management in the Union, and at least one director resident in the Union. ESMA's briefing goes further: the EU entity must be able to take decisions autonomously, meet its regulator without a group representative in the room, and keep key roles predominantly in the home jurisdiction. Outsourcing that turns the entity into a letter-box is grounds for rejection.

Stablecoin issuers face a separate route. Issuers of e-money tokens must be authorised as a credit institution or electronic money institution under Article 48, while asset-referenced token issuers face the same good repute and competence test for their management body under Article 34.

How do UK and EU people requirements compare?

  • Key deadline: UK (FCA cryptoasset regime): Apply 30 Sep 2026 to 28 Feb 2027; regime live 25 Oct 2027. EU (MiCA CASP): Grandfathering ended 1 Jul 2026 at the latest.
  • Accountability framework: UK (FCA cryptoasset regime): SM&CR applied in full; Core tier for most firms. EU (MiCA CASP): Management body suitability under Article 68 and EBA/ESMA guidelines.
  • Individual approval: UK (FCA cryptoasset regime): Each SMF approved by the FCA. EU (MiCA CASP): Management body members assessed as part of authorisation.
  • Compliance lead: UK (FCA cryptoasset regime): SMF16 Compliance Oversight. EU (MiCA CASP): Dedicated head of compliance expected.
  • AML lead: UK (FCA cryptoasset regime): SMF17 MLRO. EU (MiCA CASP): AML/CFT compliance officer under national AML law and EBA guidelines.
  • Location: UK (FCA cryptoasset regime): "Mind and management" in the UK; SMF16 and SMF17 expected at the UK principal place of business. EU (MiCA CASP): Effective management in the EU; at least one resident director; key roles mainly in the home state.
  • CEO time: UK (FCA cryptoasset regime): Assessed through fit and proper test and Statement of Responsibilities. EU (MiCA CASP): ESMA expects 100% as a rule.
  • Decision clock: UK (FCA cryptoasset regime): SMF decisions within 3 months of application (clock can stop). EU (MiCA CASP): 25 working days completeness check, then 40 working days assessment.

In what order should a crypto firm hire for a licence application?

Hire in the order the regulator will test you. A sensible sequence:

  1. Chief executive of the regulated entity. If the founder will not be the SMF1 or the EU-resident CEO, appoint the person who will. They own the business plan the regulator will interrogate.
  2. Head of compliance (SMF16) and MLRO (SMF17). These are the roles regulators look at most closely and the hardest to fill. In smaller UK firms one person can hold both, and the FCA's guide confirms an individual can hold more than one SMF if they apply for each. Only combine them where the capacity is real.
  3. Chair and independent non-executives. Collective suitability is assessed on the board as a whole, so use the chair to fill gaps: regulated-markets experience if the founders are crypto-native, crypto technical depth if they are not.
  4. Finance and risk. A CFO or head of finance who can own prudential requirements and capital reporting, and a risk lead. ESMA expects risk and compliance to be separate unless that would be disproportionate.
  5. Custody, safeguarding and technology. For custodians, the senior manager who will take the CASS prescribed responsibility. For all firms, someone senior enough to own operational resilience and key management.
  6. Market surveillance for trading platforms, since both regimes bring market abuse rules for cryptoassets.

For trading-venue operating roles, see our exchanges and venues practice.

Can senior managers be remote or based overseas?

Partly, but the key control functions should not be. In PS26/13 the FCA says it may approve overseas-based SMFs, for example a group executive responsible for UK strategy. Its general expectation, though, is that "mind and management" sits in the UK. It particularly considers physical location for SMF16 and SMF17 and expects those holders to work from the firm's UK principal place of business. Firms that are part of a global group should also read the FCA's guidance on its approach to international cryptoasset firms.

MiCA is stricter on paper. ESMA's briefing says staff outside the country of authorisation are acceptable in supporting roles such as non-management IT and HR, but key roles should be predominantly in the home jurisdiction and management must remain accessible to the national authority.

Should you hire interim or permanent senior managers?

Use interim where it buys you time, not where it signals a gap. Interim compliance professionals can build the policy suite and draft the application, but the people named in your application are the people the regulator assesses. If your SMF16 or MLRO is an interim who leaves after authorisation, you are back to finding, onboarding and seeking approval for a replacement while live.

A practical model: interim to build, permanent to apply. Bring in interim support early to prepare the documentation, and run the permanent search in parallel so the permanent holder is in place, and ideally has reviewed the application, before it goes in.

How long does it take to hire and approve a crypto senior manager?

Work backwards from your filing date. Three clocks stack up:

  • The search. Candidates with prior FCA or EU authorisation experience in crypto are scarce, and many are already committed to firms in this same window.
  • The notice period. Senior compliance hires typically need to serve one before joining. Ask about it in the first conversation.
  • The regulator. The FCA says it must decide SMF applications within three months, but can stop the clock to request information or interview the candidate. Under MiCA, the national authority has 25 working days to check completeness and 40 working days to assess a complete application, with suspensions of up to 20 working days for further information.

With the UK window closing on 28 February 2027, a firm that has not yet started its SMF16 or MLRO search is already tight. Respondents to the FCA's consultation flagged the cost of recruiting UK-based SMF holders and questioned whether a 6 to 12 month implementation period was realistic, suggesting some requirements could take 12 to 18 months.

Why do crypto licence applications stall on people?

The people problems that hold applications back are predictable:

  • Founder-concentrated control. In CP25/25 the FCA observed that responsibilities at crypto firms are often over-concentrated in a few individuals who are not constructively challenged. A board that cannot challenge the founder is a weak application.
  • Nominal local presence. A resident director who only signs documents, with real decisions taken at group level, fails ESMA's autonomy test.
  • Stretched dual-hatting. One person covering compliance, AML and risk for several entities rarely survives the time-commitment test.
  • Prior supervisory history. ESMA tells authorities to investigate past transgressions of board members, such as operating without registration elsewhere, and to interview them.
  • Key person departures after approval. Authorisation is not the finish line.

The last point is not theoretical. Austria's FMA granted KuCoin EU Exchange GmbH MiCA authorisation on 27 November 2025, then banned it from new business from 19 February 2026 because key functions, including the AML officer and sanctions compliance officer, were not properly filled. The FMA lifted the new business ban on 18 May 2026 once those roles were filled, but said commencement of business remained prohibited pending governance requirements and additional senior management key functions. Succession planning for named control functions belongs in your application plan, not your post-licence to-do list.

Where to start

Start with a gap analysis of people, not policies: list every SMF or key function the regime requires, name who will hold it, where they will sit, and whether they would pass a fit and proper interview today. Then hire into the gaps in order of regulatory scrutiny.

Spearpoint Search runs retained searches for digital asset and crypto leadership, including compliance, MLRO and regulated-entity CEO roles, and will tell you plainly if your compensation or structure will not attract the people a regulator expects. For benchmarks, see our compensation guide. For Sam's deeper take on how licences are lost through people rather than capital, read Who killed the licence? in Talent Before Capital.

This article is general information, not legal or regulatory advice. Requirements vary by firm, activity and jurisdiction, and regulators update their rules and guidance. Take advice from qualified counsel before applying.

‍

Frequently asked questions

When is the deadline to apply for FCA crypto authorisation?

The FCA's application window runs from 30 September 2026 to 28 February 2027, and the new cryptoasset regime comes into force on 25 October 2027. Existing firms that apply within the window can keep operating while their application is determined. Firms that miss it and are not authorised by go-live can only perform pre-existing contracts. MLR registration does not convert automatically.

Does SM&CR apply to crypto firms in the UK?

Yes. In PS26/13 the FCA confirmed it will apply the Senior Managers and Certification Regime in full to authorised cryptoasset firms. Most will be Core firms needing an approved Chief Executive (SMF1), executive directors (SMF3), a Chair (SMF9), Compliance Oversight (SMF16) and an MLRO (SMF17). Enhanced status applies only above high custody or stablecoin backing-asset thresholds.

Can the MLRO and head of compliance be the same person?

In the UK, one person can hold both SMF16 and SMF17 if they are approved for each, and this is common in smaller firms. Only do it where the capacity is genuine. Under MiCA, ESMA expects at least one dedicated compliance lead, and the AML/CFT compliance officer must meet EBA guidelines, so check expectations with your national authority.

Do MiCA directors need to live in the EU?

Article 59 of MiCA requires a CASP's place of effective management to be in the Union and at least one director to be resident in the Union. ESMA's supervisory briefing goes further, expecting at least one executive board member resident in the member state granting authorisation, key roles mainly based there, and a CEO who, as a rule, works full time for the CASP.

Is the MiCA transitional period still open?

No. Article 143 allowed crypto-asset service providers operating under national law before 30 December 2024 to continue until 1 July 2026 at the latest, and some member states set shorter periods. That window has now closed, so a firm serving EU clients needs MiCA authorisation, or a valid notification if it is an existing regulated financial entity.

‍