FCA TIGHTENS UP ON CRYPTOASSETS REGULATION IN CONSULTION PAPER
By FF Newsroom · 19 February 2019

In January 2019, the Financial Conduct Authority ("FCA") published a Consultation Paper which sets out draft Guidance on how cryptoassets can be subject to FCA regulation ("the Guidance"). The draft Guidance is relevant to any firm issuing, creating, buying, selling, holding or storing cryptoassets, as well as firms marketing cryptoasset products and services, and their advisers.
Ian Mason and Sushil Kuner from Gowling WLG summarise the FCA's expectations and explore the key considerations for firms.
Overview
The draft Guidance seeks to clarify where different categories of cryptoasset tokens fall in relation to the FCA's regulatory perimeter, i.e. the boundary that separates regulated and unregulated financial services activities. Activities which fall within the regulatory perimeter are regulated and require authorisation from the FCA, and in limited circumstances the Prudential Regulation Authority (PRA), before they can be carried out. Carrying out regulated activities without the relevant authorisations may constitute a criminal offence.
The FCA has categorised cryptoassets into three types of tokens, and has provided guidance on whether these tokens are regulated or unregulated. In categorising cryptoassets as below, the FCA has made it clear that the categories of token are not mutually exclusive, nor are they exhaustive of the types of cryptoassets that can exist. Whether a cryptoasset falls within the regulatory perimeter should always be considered on a case-by-case basis with regard to a number of different factors.
Security Tokens
Security tokens include specific characteristics which bring them within the definition of a 'Specified Investment', such as a share or a debt instrument, which mean they fall within the regulatory perimeter. The FCA considers a security to refer broadly to an instrument which indicates an ownership position in an entity, a creditor relationship with an entity, or other rights to ownership or profit. Security tokens are securities because they grant certain rights associated with traditional securities.
If you carry on a regulated activity involving a Security Token, you will need to make sure that you are appropriately authorised or exempt. Issuers of such tokens may themselves not need to be authorised, however certain requirements related to the issuance of the tokens may still apply, for example prospectus and transparency requirements.
What to consider when determining if a token is a Security Token
Given the complexity of many tokens, the FCA has recognised that it is not always easy to determine whether a token is a Specified Investment. The FCA has, therefore, set out a non-exhaustive list of factors that it considers are indicative of a security to assist firms in determining whether or not they are undertaking regulated activities:
- the contractual rights and obligations the token-holder has by virtue of holding or owning that cryptoasset;
- any contractual entitlement to profit-share (e.g. dividends), revenues, or other payment or benefit of any kind;
- any contractual entitlement to ownership in, or control of, the token issuer or other relevant person (e.g. voting rights);
- the language used in relevant documentation (e.g. Whitepapers) . However, the FCA has made clear that if a Whitepaper declares a token to be a utility token, but the characteristics of the token indicate it is a Specified Investment, the FCA would treat it as a Security Token;
- whether the token is transferable and tradeable on cryptoasset exchanges or any other type of exchange or market;
- whether there is a flow of payment from the issuer or other relevant party to token holders; and
- whether any flow of payment is a contractual entitlement – the FCA has made clear that it would consider this to be a strong indication that a token is a security.
- issued on receipt of funds for the purpose of making payment transactions;
- accepted by a person other than the electronic money issuer; and
- not excluded by the E Money Regulations.
-
- the application of financial promotion rules, including ensuring communications are marketed in a way which is clear, fair and not misleading;
- the application of the Prospectus Directive;
- the application of relevant financial crime controls; and
- operational resilience and cyber security issues – cryptoassets are now regarded as high-value targets for theft and service providers (e.g. custodians/wallet providers) are increasingly being targeted by cyber-criminals to obtain the private keys which enable consumers to access and transfer their cryptoassets.