Same Risk, Same Regulation — Except Where It Isn't
- James Ross

- Aug 6
- 5 min read
What PS26/13 actually did to UK cryptoasset firms, and the Parity Premium nobody is pricing.
The phrase everyone will quote from PS26/13 is "same risk, same regulation". It appears in the FCA's cost-benefit analysis, it is a reasonable summary of the policy intent, and it will anchor most of the commentary written about the June package.
It is also not quite what the rules do.
In at least three places, the FCA has held cryptoasset firms to a standard higher than the one it applies to their traditional-finance equivalents. Not different — higher. These are not incidental drafting choices; each was consulted on, challenged by respondents, and confirmed anyway. Taken together, they constitute a cost that sits above parity, and firms modelling their authorisation budgets against a TradFi baseline are going to under-provision.
We call it the "Parity Premium". It is worth naming, because what is not named does not get budgeted.

Where the premium sits
Client money, first. CASS 7 contains a professional-client opt-out. Institutional businesses in traditional finance use it routinely — sophisticated counterparties can agree that money need not be segregated. For qualifying cryptoasset activities, it is disapplied. An institutional-only crypto business must fully segregate, whatever its clients would prefer. The FCA's stated reasoning is the sector's vertical integration and market concentration, and it has said it will keep the position under review. That is a review, not a promise.
Settlement, second. The delivery-versus-payment exemption is disapplied where the delivery obligation relates to client cryptoassets. The logic is clean enough — the exemption assumes a recognised commercial settlement system, and the FCA does not consider that any exists for crypto. The consequence is not clean at all. Money received ahead of delivery is client money for the entire settlement period. Any firm running a pre-funded model has just discovered that a balance it treated as its own is a segregated client balance, with the reconciliation, the auditor's opinion, and the capital consequences that follow. Firms structuring genuine atomic settlement, where they never hold client money at any point, are unaffected. Very few are.
Reporting, third. Cryptoasset safeguarding firms file a monthly return. The traditional-finance analogue, the CMAR, is tiered by firm size. This one is not — a small custodian reports as often as a large one. The FCA justifies this on the volatility of crypto holdings and the speed at which composition changes, and points to the equivalent monthly return for payments firms. Complaints reporting follows the same pattern: quarterly for crypto, against a six-monthly cycle in traditional finance.
None of these is unreasonable in isolation. That is precisely why they will be absorbed without argument, and precisely why the aggregate is being missed.
The Redress Asymmetry
There is a second structural feature that deserves a name of its own.
The Financial Ombudsman's compulsory jurisdiction extends to the new activities. The Financial Services Compensation Scheme does not — and the FCA has declined to extend it, judging it too early to conclude that the benefits outweigh the risks, and wary of signalling a safety that does not exist.
The two decisions are individually defensible and jointly awkward. Firms carry uncapped ombudsman exposure with no compensation-scheme backstop beneath it. A consumer who loses money to a firm's act or omission has a route to redress; a consumer who loses money because the firm failed does not. Meanwhile the firm's standardised risk summaries must state the FSCS absence in terms, which is a marketing constraint layered on top of a liability one.
The detail that has attracted least attention is the one we would flag hardest: this extends to the safeguarding of tokenised traditional investments. Under the Cryptoassets Regulations 2026, safeguarding of relevant specified investment cryptoassets moved to Article 9N of the Regulated Activities Order — and out of FSCS scope with it. A tokenised share is not covered. The underlying share is. The FCA has left open a future exception, which is an acknowledgement that the outcome is odd rather than a plan to fix it.
For anyone building tokenisation infrastructure on the premise that the wrapper does not change the substance, that is a material problem. The wrapper changed the substance.
Where the FCA did give ground
It would be a poor reading of the package to present it as uniformly restrictive, and we do not.
The most significant concession went to dual-regulated firms. The FCA will generally expect solo-regulated international firms to operate through a UK legal entity rather than a branch. Following pushback from international banks — several of whom run substantial UK business from branches already — dual-regulated firms may carry on cryptoasset activities from a branch, subject to the PRA as lead regulator and to threshold conditions assessed case by case. For global institutions that is the difference between a variation of permission and a new entity with its own capital, board and infrastructure.
UK-issued qualifying stablecoins have been removed from the Restricted Mass Market Investment category, which strips out the cooling-off and appropriateness friction at onboarding. Permissionless DLT will not be treated as outsourcing under SYSC 8, which 98% of respondents supported and which spares firms an unworkable contractual analysis with parties they cannot contract with. Backing-asset management will not require proprietary-trading certification. No separate prescribed responsibility was created for crypto custody.
Where the FCA was shown a concrete operational impossibility, it moved. Where it was shown a cost, it generally did not.
The equivalence gap
One line in Chapter 2 deserves more attention than it will get. The FCA cannot commit to a timeframe for international equivalence or recognition arrangements, noting that these take time, involve multiple parties, and usually require legislation that is outside its powers.
Read plainly, that means a firm serving the UK and other major jurisdictions should plan to satisfy each regime on its own terms, indefinitely. Duplicate structures, duplicate governance, duplicate safeguarding arrangements. Not as a transitional inefficiency pending mutual recognition — as the operating model.
We would urge firms to build their authorisation business case on that assumption rather than on the hope of a recognition regime arriving to rationalise it later.
What follows from this
The gateway application period closes on 28 February 2027. The regime goes live on 25 October 2027. A firm that misses the gateway risks being unable to carry on regulated cryptoasset activities in the UK lawfully at go-live.
Between here and there sit the things that take longest: fixing the legal structure question, re-papering settlement and pre-funding arrangements now that two CASS 7 protections have gone, moving compliance and money-laundering leadership to a UK principal place of business, rebuilding onboarding around a hardened appropriateness rule, and specifying the data pipelines for monthly and quarterly returns. None of these is a document exercise. All of them are procurement, hiring, or systems work with lead times measured in quarters.
The UK has done something more ambitious than most commentary has registered. It has not built a parallel regime for crypto; it has admitted crypto to the existing one, and then, in a handful of places, asked more of it than it asks of anyone else. That is a coherent position and arguably the right one.
It is simply not parity. Firms should price it accordingly.
denouement advises cryptoasset and digital-asset firms on UK regulatory strategy, authorisation and implementation. This article summarises FCA Policy Statement PS26/13 (June 2026) for general information and is not legal advice.



Comments