What happened
On 25 June 2026 the Financial Conduct Authority (FCA) censured CACEIS UK, an asset servicing bank, and confirmed that the firm will make a £31.7m voluntary payment to clients of WealthTek for failing to act on information that left those clients exposed to the risk of financial crime. With this action, the FCA says it has now secured over £57m in total for WealthTek clients in just over a year, following separate measures against Sapia Partners and Barclays Bank UK.
The factual chain is instructive. CACEIS UK became WealthTek’s sub-custodian in November 2020, making it responsible for keeping client assets safe. On three occasions it checked the Financial Services Register, which showed WealthTek was not authorised to hold certain client assets, but did not take sufficient action. The firm also failed to identify that WealthTek was not permitted to hold client money. Despite this, it opened client accounts for WealthTek and then failed to monitor those accounts properly — notably by not promptly reviewing and resolving alerts raised by its own systems.
Because CACEIS UK co-operated extensively and agreed to the voluntary payment, the FCA decided not to impose a fine; absent that co-operation, the regulator says it would have imposed a penalty of £23,091,000. The FCA also stressed it concluded the investigation in 13 months, citing improved pace.
What it means in practice
This case is not about crypto, but the supervisory expectations it reinforces apply directly to firms operating in digital assets. The FCA’s own words are blunt: “Strong financial crime controls keep clients’ assets safe.” For anyone seeking or holding a crypto / VASP registration in the UK, three themes stand out.
- Counterparty permissions are your problem too. CACEIS UK had the information — the Register itself flagged that WealthTek lacked the relevant permissions — yet did not act on it. Checking a counterparty’s authorisation status is necessary but not sufficient; you must act on what you find and document that action.
- Alerts must be worked, not just generated. The firm had monitoring systems that raised alerts. The failure was not the absence of technology but the failure to review and resolve those alerts promptly. For crypto firms relying on blockchain analytics and transaction-monitoring tools, an unreviewed alert backlog is a live regulatory risk.
- Custody carries heightened duties. Holding or safeguarding someone else’s assets — fiat or digital — invites the highest scrutiny. The £31.7m sits alongside criminal charges against WealthTek’s former principal partner for fraud and money laundering, with a trial scheduled for September 2027, underlining how custodial failings sit within wider financial-crime ecosystems.
Implications for licensees and applicants
The FCA is demonstrating that it will pursue gatekeepers and service providers, not only the failed firm at the centre of misconduct. Sub-custodians, banking partners and ManCos all faced consequences here. If your crypto business provides custody, payment rails, or onboarding for other regulated or unregulated entities, you should assume that the FCA will assess whether you acted on red flags — and whether your clients were protected when controls broke down.
The decision to forgo a fine in exchange for co-operation and redress is also a signal. Firms that self-correct, co-operate fully and make clients whole can materially change the regulatory outcome — but only after the damage is done. The cheaper path is robust controls from day one.
Concrete next steps
- Test your alert-handling discipline: measure how quickly alerts are reviewed, escalated and closed, and keep an evidenced audit trail.
- Verify and re-verify counterparty permissions against the Financial Services Register, and define what action is triggered when a mismatch appears.
- Reconcile and segregate client assets rigorously, with clear ownership of safeguarding obligations.
- Build financial-crime controls into your application, not as an afterthought. If you are preparing for a crypto / VASP license in United Kingdom, expect the FCA to probe exactly the weaknesses exposed in this case.
The MiCA regime now shapes expectations across Europe, but the UK’s framework continues to place financial-crime systems and controls at the centre of authorisation. This case is a timely reminder of where examiners will look first.