Operational resilience is becoming the foundation for the growth of digital assets in the UK

Insight — 27th August 2026
Thistle crypto webinar insights hero
Share article

As the UK’s new cryptoasset regime approaches, digital asset firms face a clear message: authorisation will depend on more than ambition. Firms will need to show that they can operate safely, protect customers, manage disruption and sustain growth within a more mature regulatory framework. 

That was the central theme of a recent webinar exploring the UK’s incoming cryptoasset regulatory regime, operational resilience and the role of regulated banking and payments infrastructure. Hosted by our partners, Thistle Initiatives and advisory firm TORI Global, the discussion covered important topics across regulatory, technology and infrastructure perspectives. 

You can watch the full on-demand webinar here. 

Together, we examined what firms should be preparing for now and why resilience should be treated as a growth lever, rather than purely a compliance exercise. Below are highlights from that conversation. 

If your firm is preparing for the UK's new cryptoasset regime and would like to discuss how ClearBank's banking infrastructure can help.

A new regime raising the bar

The UK’s cryptoasset regime will come into force on 25 October 2027, introducing a comprehensive authorisation and supervisory framework for firms undertaking regulated cryptoasset activities and issuance of stablecoins. The FCA has also confirmed that the authorisation gateway will open in September 2026, creating a defined window for firms to prepare, apply and demonstrate that they can meet the standards expected under Part 4A of the Financial Services and Markets Act (FSMA). 

For many digital assets firms, this will mark a shift from the current regime, which has been in place since 2021, and was limited to AML/CTF and Financial Promotions-related rules. In their application, firms will need to demonstrate robust governance, clear accountability, appropriate conduct standards, prudential risk management, complaint handling, Consumer Duty considerations, operational resilience arrangements and, where relevant, controls over trading, custody, settlement, and stablecoin-related activity. 

In practical terms, the authorisation process is an assessment of whether a firm’s understanding of its operating model is mature enough to withstand scrutiny and resilient enough to withstand disruption. 

Operational resilience should be viewed from the customer’s perspective

The FCA’s regime requires firms to identify the services whose disruption could cause intolerable harm to customers or pose a risk to market integrity. From there, they should then map the people, processes, technology, data, facilities and third parties that support them. 

That mapping must be specific enough to reveal vulnerabilities. It should show who owns each service, who is accountable for it, which systems and suppliers it depends on, where failure could occur and how quickly the firm could respond. Impact tolerances then define the maximum disruption the firm can tolerate before harm becomes unacceptable. Scenario testing should prove whether the firm can remain within those tolerances – or highlight where further investment is needed. 

The point is not simply to document a framework. Regulators will expect evidence of testing, lessons learned, remediation plans, board visibility and continual improvement to be maintained. Operational resilience is increasingly a live management discipline, not a static policy document.

Technology supports, but doesn’t deliver, resilience

Our discussion also challenged a common misconception: that technology creates governance. Technology can support resilient outcomes, but only when it works alongside effective processes, clear accountability and human decision-making. Operational resilience often breaks down when those layers become disconnected. 

For digital asset firms, this matters because critical functions may be distributed across multiple parties and systems. Custody, wallet infrastructure, cloud hosting, reconciliation tools and payments connectivity are likely to be delivered through partners. Senior managers and boards must understand how those dependencies work, how they affect customer outcomes and what happens if a critical component fails. 

Simple questions raised by the panel can reveal whether a firm truly understands its model: who can move assets? Can it identify depositors and the assets they hold? How are records reconciled? What happens if a supplier fails? These questions are particularly relevant in digital assets, where controls such as multi-signature approvals, key generation, cold storage, geographic distribution and ledger reconciliation can have direct implications for both security and service continuity.

Third-party dependencies are becoming a board-level issue

Another major theme was the growing regulatory focus on third-party arrangements. New rules coming into force in March 2027 (PS26/2) will expand reporting expectations beyond traditional outsourcing to include material non-outsourcing arrangements. That means firms must look beyond obvious suppliers and identify the wider chain of dependencies that could affect its business services. 

This could include cloud providers, cybersecurity vendors, SaaS platforms, data providers, payments partners and other technology services that sit beneath a customer journey. The challenge is that some of the most important dependencies may be hidden several layers down.  

This will require firms to maintain accurate registers, refresh their mapping when products or vendors change and learn from incidents elsewhere in the market. They also need to know who owns the data, the platform, the supplier relationship and the oversight. Without that clarity, disruption quickly becomes harder to manage, escalate, and remediate. 

Regulated infrastructure links resilience to customer outcomes

The discussion also highlighted the role of regulated banking and payments infrastructure in helping digital asset firms demonstrate operational readiness. Customers do not experience governance papers, risk assessments or testing plans. They experience whether they can access services, move money, complete transactions and see where their funds are held.  

Infrastructure choices are strategic operating model decisions. Banking and payments partners underpin core customer journeys, including GBP wallets, fiat movement through on- and off-ramps, settlement, account services and connectivity to the wider financial system. Their resilience, scalability, service standards, escalation channels and contractual commitments all affect whether a firm can maintain its critical business services during any disruption. 

Joint testing, clear communication protocols and aligned recovery expectations can help firms show that resilience works in practice. As digital assets become more connected to traditional finance, this matters for individual firms and for confidence in the wider ecosystem.

Resilience and growth should be complementary

Perhaps the strongest commercial message from the webinar was that resilience and growth should not be treated as competing priorities. Firms that build resilient foundations early will be better placed to scale, innovate and maintain trust as the market matures. Authorisation may feel like the finish line, but in reality, it is the starting point for maintaining sustainable growth in a more demanding supervisory environment. 

That means selecting partners that can meet short-term requirements and longer-term needs as they scale. Firms should ask whether their operating model can support new products, higher volumes, changing customer needs and more complex integrations. Digital assets firms should also consider at what point their infrastructure may no longer keep up and test those assumptions before disruption exposes the weakness. 

The winners in the UK’s next chapter of digital assets are likely to be the firms that combine strong governance with resilient, regulated infrastructure. Operational resilience is not just about satisfying the regulator. It is about protecting customers, preserving reputation and building the confidence needed for long-term growth.

Further reading

CTA 2

Ready to collaborate?

Experience the ClearBank difference and begin your journey today.

Begin

Let’s stay in touch

You're subscribed!

Subscribe for our insights, news and exclusive events – straight to your inbox

Thanks for connecting with us.