PRA Cryptoasset Exposures: The 100% Capital Expectation for UK Banks

On 18 May 2026, the Prudential Regulation Authority published a Dear CEO letter addressed to the chief executives of all banks and designated investment firms, signed by David Bailey, Charlotte Gerken and Rebecca Jackson. The PRA continues to expect a 100 per cent own-funds requirement under the market-risk framework for unbacked cryptoassets. Separately, where a direct holding is classified as an intangible asset under the applicable accounting framework, it is deducted from CET1 under Articles 36(1)(b) and 37 of the Own Funds (CRR) Part of the PRA Rulebook.

The letter replaces the interim expectations the PRA published in 2022, when the market was smaller and the international standard was still being drafted. It arrived on a busy day for UK digital-asset policy. The same date carried a companion PRA Dear CEO letter on innovations in the use of deposits, e-money and stablecoins, and a joint FCA and Bank of England Call for Input setting out a shared vision for tokenisation in UK wholesale markets. Read together, they mark the point at which UK supervisors stopped treating bank crypto exposure as a fringe question.

What follows is a practitioner walkthrough of the letter: the 100 per cent capital expectation, the same-risk treatment of tokenised traditional assets, where the Basel standard sits, and why the real work for the next two years lands in the ICAAP.

Related reading: Bank of England systemic stablecoin rules for UK issuers

Key dates for the PRA cryptoasset letter

  • 2022: PRA sets interim expectations on cryptoasset exposures. This is the guidance the new letter supersedes.
  • 1 January 2026: the Basel Committee’s cryptoasset standard (SCO60) takes effect within the Basel Framework as the agreed international minimum.
  • 18 May 2026: the PRA publishes the Dear CEO letter on the prudential treatment of tokenised assets, stablecoins and other cryptoasset exposures, alongside a companion letter on deposits, e-money and stablecoins.
  • 2028 at the earliest: the PRA expects to consult on a proposed prudential framework after the Basel Committee completes its targeted review of the cryptoasset standard.

What the 18 May 2026 letter changes

The publication is a Dear CEO letter setting interim supervisory expectations; it does not amend the PRA Rulebook. No new template, no new reporting field, and no new rule instrument sits behind it. That distinction matters, because a reporting officer scanning for a filing deadline will not find one. The change is in the standard the PRA will hold firms to when it reviews capital adequacy and challenges an ICAAP.

The letter is addressed to the chief executives of all banks and designated investment firms. It does not address payment institutions, e-money institutions or standalone cryptoasset firms in those capacities. Firms should determine the applicable requirements from their PRA authorisation and the prudential framework applicable to the particular entity and exposure.

The letter clarifies that firms should continue to apply the full existing prudential framework to cryptoasset exposures, including the Fundamental Rules, Pillar 1, the ICAAP, Pillar 2 and operational-risk requirements. Firms should assess risks from first principles where existing methodologies do not adequately capture the features of cryptoasset markets.

How the PRA’s 100% cryptoasset capital expectation works

The PRA’s 100 per cent figure is an own-funds requirement under the market-risk framework, not a complete statement of the prudential treatment of every direct holding. A holding may also be classified as an intangible asset and deducted from CET1. Capital teams must therefore determine the accounting classification, the applicable Pillar 1 treatment and any Pillar 2 implications for the specific exposure.

The PRA expresses its current expectation as a 100 per cent own-funds requirement under the UK market-risk framework. This should not be presented as a UK 1250 per cent risk weight. Under SCO60, a 1250 per cent risk weight applies to Group 2b cryptoassets and is intended to produce Basel minimum risk-based capital at least equal to the relevant exposure measure; SCO60 has not been implemented in the PRA Rulebook.

The PRA frames this treatment as conservative for a reason it states plainly: unbacked cryptoassets are volatile, data on their behaviour is thin, and the modelling assumptions that support lighter treatment for traditional assets do not hold. The letter reaffirms that this conservative treatment remains appropriate for most cryptoassets.

The letter does not prohibit cryptoasset activity, but it also does not endorse a firm’s business plan or make the 100 per cent market-risk expectation the sole condition for proceeding. Firms must apply the full prudential framework, including governance, risk management, any CET1 deduction, Pillar 1, ICAAP, Pillar 2 and supervisory engagement. Nor does the charge fall on every digital token in the same way. Tokenised traditional assets are treated differently, which is the part of the letter most likely to be misread.

Tokenised traditional assets and the same-risk principle

The letter states that tokenised traditional assets would generally receive the same prudential treatment as their non-tokenised equivalents where the legal rights conferred are identical and the underlying risks are comparable, applying the PRA’s “same risk, same regulatory outcome” approach. A tokenised gilt that carries the same claim, the same issuer and the same cash flows as a conventional gilt should not attract a different capital charge simply because ownership is recorded on a distributed ledger.

The load-bearing words are “where legal rights conferred are identical and the underlying risks are comparable.” Tokenisation can change the risk profile even when the economic claim looks identical. Settlement finality on a ledger, the enforceability of the token holder’s legal claim, custody arrangements, and the operational and ICT dependencies of the platform can all introduce risks that the non-tokenised instrument never carried. Same economic exposure does not automatically mean same risk, and the firm has to evidence the comparison.

This is where a common shortcut fails. A treasury team that books a tokenised money-market instrument at the risk weight of its conventional twin, without testing whether the legal claim survives issuer insolvency or a platform failure, has assumed the conclusion the PRA expects it to prove. The same-risk outcome is available, and the firm earns it through analysis of the specific structure. The label “tokenised” does not grant it. For the wider tokenisation debate that sits behind this, our note on how tokenised securities fall inside the MiFID perimeter shows the same legal-substance test playing out in the EU.

Where the Basel cryptoasset standard fits

The letter references the Basel Committee’s international standard as a useful reference point, and it is worth understanding what that standard says, because the PRA’s own future rules are expected to be built from it. The Basel cryptoasset standard, catalogued as SCO60 in the consolidated Basel Framework, took effect on 1 January 2026 as the agreed global minimum.

The standard splits cryptoassets into Group 1 and Group 2. Group 1a covers tokenised traditional assets that meet the classification conditions, while Group 1b covers cryptoassets with effective stabilisation mechanisms that meet those conditions. Cryptoassets that fail the Group 1 conditions fall into Group 2: Group 2a permits limited hedging recognition and is capitalised under modified market-risk approaches, while Group 2b permits no hedging recognition and is subject to a 1250 per cent risk weight applied to the greater of the absolute aggregate long and short positions in each cryptoasset.

The standard also sets an exposure limit that has no direct equivalent in the traditional framework. A bank’s total Group 2 cryptoasset exposure should generally remain below 1 per cent of Tier 1 capital and must not exceed 2 per cent. Amounts above the 1 per cent threshold fall into the more punitive Group 2b treatment, and a breach of the 2 per cent ceiling pushes the bank’s entire Group 2 exposure into Group 2b.

Here the onshoring trap needs flagging. The Basel standard is an international minimum, and it is not UK law. The PRA has not transposed SCO60 into the PRA Rulebook, and it does not expect to consult on a UK prudential framework for cryptoassets before 2028 at the earliest, after a targeted review and once the Basel Committee’s own review of the standard concludes. A UK firm that lifts the 1250 per cent risk weight, the Group 1 and Group 2 split, or the 1 per cent and 2 per cent limits straight into a UK regulatory return as if they were binding CRR rules would be citing a standard the UK has not enacted. For now these remain the reference points the PRA is steering towards. Our explainer on the PRA’s Basel 3.1 market risk implementation shows how the PRA adapts, and does not simply copy, Basel text when it does legislate.

Governance, ICAAP and Pillar 2 carry the gap

Because binding rules are years away, the letter puts the weight on governance and the firm’s own capital assessment. It expects strong governance and risk management, and it expects boards and senior management to assess whether the characteristics of cryptoassets and tokenised instruments are adequately captured within the firm’s existing frameworks. The Fundamental Rules on prudent conduct of business, effective risk management and open dealing with the regulator are the backstop where a specific rule is silent.

In practice the ICAAP is the document that has to do this work. Where a cryptoasset exposure carries risks that Pillar 1 does not fully capture, the firm is expected to hold additional capital under Pillar 2 and to explain that judgment in its capital assessment. The PRA expects firms to discuss the proposed prudential treatment of cryptoasset exposures with their supervisors and to engage where appropriate, particularly where their application of the existing framework differs materially from the BCBS standard. The letter does not prescribe a notification form, a materiality threshold or a specific pre-booking deadline. Teams building this into their capital cycle can read it alongside our guide to how the ICAAP and ILAAP fit together.

The letter does not create a directly binding rule, but the PRA can challenge a firm’s ICAAP and use its existing Pillar 2 and supervisory powers where risks are not adequately captured. Waiting for the 2028 consultation carries its own capital consequence, because the firm will still have to defend its treatment at the next supervisory review.

How the letter fits the wider UK cryptoasset architecture

The PRA sets prudential expectations for banks and designated investment firms with cryptoasset exposures. In June 2026, the FCA published final rules for the future FSMA cryptoasset regime, including COREPRU and CRYPTOPRU; the full scope of regulated cryptoasset activities expands from 25 October 2027. Qualifying stablecoin issuers recognised as systemic by HM Treasury will be jointly regulated by the Bank of England and the FCA, rather than by the Bank alone.

So a single stablecoin can touch all three. Its issuer may need FCA authorisation, a systemic issuer may fall under Bank of England rules, and a bank that holds or facilitates it must capitalise that exposure under the PRA’s expectations. The 18 May letter addresses the prudential treatment and risk management of cryptoasset exposures for PRA-authorised banks and designated investment firms; it does not establish the issuer-authorisation or systemic-stablecoin rulebooks. For the conduct and authorisation side, our coverage of the FCA’s UK cryptoasset authorisation gateway sets out the parallel regime.

The Brexit divergence is worth stating for firms that also operate in the European Union. The UK approach is separate from the EU’s Markets in Crypto-Assets Regulation. MiCAR is an EU authorisation, issuance, conduct, governance and prudential framework for crypto-asset issuers and crypto-asset service providers; the PRA letter sets interim UK prudential expectations for PRA-authorised banks and designated investment firms. A group that maps its UK obligations onto its MiCAR analysis, or the reverse, will misread both. The instruments, the perimeters and the responsible authorities differ, even where the underlying token is the same.

Frequently Asked Questions

Does the PRA letter create a new reporting requirement or return?

No. The Dear CEO letter does not introduce a new return, template or reporting field. It also does not state that all cryptoasset exposures are reported through large-exposure returns. Firms must determine the applicable existing reporting treatment from the relevant accounting and prudential rules and confirm any uncertain mapping with the PRA. The letter’s principal operational effects concern capital treatment, ICAAP assessment and supervisory engagement.

Which firms are actually in scope?

The letter is addressed to the chief executives of all PRA-authorised banks and designated investment firms. It does not apply to payment institutions, e-money institutions or standalone cryptoasset firms, which fall to the FCA and, for systemic stablecoins, the Bank of England. Scope tracks the population that already applies the CRR and PRA Rulebook prudential framework.

Is the 100% capital requirement the same as a 1250% risk weight?

The PRA’s 100 per cent own-funds requirement and the Basel 1250 per cent risk weight are separate standards. The PRA expects a 100 per cent own-funds charge under the UK market-risk framework for unbacked cryptoassets. SCO60 applies a 1250 per cent risk weight to Group 2b cryptoassets under the Basel standard; that Basel treatment has not been implemented in the PRA Rulebook.

Do tokenised bonds or deposits attract the 100% charge?

Generally no. Tokenised traditional assets would generally receive the same prudential treatment as their non-tokenised equivalents where the legal rights conferred are identical and the underlying risks are comparable, under the “same risk, same regulatory outcome” approach. The firm has to evidence that comparability, including any settlement, legal-claim and custody risk introduced by the token, before applying the lighter treatment. Comparability is tested, not assumed.

Has the UK adopted the Basel cryptoasset standard?

Not yet. The Basel standard (SCO60) took effect within the Basel Framework on 1 January 2026 as an international minimum, but the PRA has not written it into the PRA Rulebook. The PRA expects to consult on a proposed UK prudential framework in 2028 at the earliest, after completion of the BCBS targeted review. Until then, existing PRA rules remain the primary requirements. The BCBS classification conditions and methodologies may inform firms where PRA rules allow discretion, but SCO60’s group classifications, 1,250 per cent risk weight and 1 per cent and 2 per cent exposure limits are not binding UK requirements.

What supervisory engagement does the letter expect?

The letter reaffirms that firms should discuss the proposed prudential treatment of cryptoasset exposures with their supervisors. Firms should exercise judgement and engage where appropriate, particularly where their application of the existing PRA framework differs materially from the BCBS standard. The letter does not prescribe a materiality threshold or a specific pre-booking deadline.

How does this relate to the companion PRA letter published the same day?

The 18 May 2026 package included a separate Dear CEO letter on innovations in the use of deposits, e-money and stablecoins. That companion letter addresses how banks structure deposit-like and e-money products and their interaction with stablecoins; the cryptoasset letter addresses the capital treatment of cryptoasset and tokenised exposures. They are complementary, and a firm active in both areas should read them side by side.

Key Takeaways

  • The PRA’s 18 May 2026 Dear CEO letter replaces its 2022 expectations and is addressed to the chief executives of all banks and designated investment firms.
  • The PRA continues to expect a 100 per cent own-funds requirement under the market-risk framework for unbacked cryptoassets; some direct holdings may also be deducted from CET1 if classified as intangible assets.
  • Tokenised traditional assets would generally receive the treatment of their non-tokenised equivalents only where the legal rights conferred are identical and the underlying risks are comparable.
  • The letter is a supervisory expectation, and not a new rule or return; the work surfaces through the ICAAP, Pillar 2 and supervisory engagement.
  • The Basel cryptoasset standard (SCO60) took effect on 1 January 2026 as an international minimum, but the PRA has not enacted it and will not consult on UK rules before 2028 at the earliest.
  • Firms should discuss the proposed prudential treatment of cryptoasset exposures with supervisors and engage where appropriate, particularly where their application of the existing PRA framework differs materially from the BCBS standard.
  • The PRA, FCA and Bank of England each own a different slice of the UK cryptoasset map; the letter speaks only to bank prudential treatment, and UK rules are distinct from EU MiCAR.

Sources and References

  • Prudential Regulation Authority, Letter from David Bailey, Charlotte Gerken and Rebecca Jackson on the prudential treatment of tokenised assets, stablecoins, and other cryptoasset exposures, 18 May 2026: bankofengland.co.uk (letter PDF: PDF).
  • FCA and Bank of England, Call for Input: The future of tokenisation – a joint vision from the authorities for UK wholesale markets, 18 May 2026: bankofengland.co.uk.
  • Basel Committee on Banking Supervision, Basel Framework SCO60 – Cryptoasset exposures: bis.org.
  • Financial Conduct Authority, Cost Benefit Analysis – Cryptoasset Regime (PS26/9 to PS26/13), June 2026: fca.org.uk.
  • Financial Conduct Authority, Crypto Roadmap, November 2024: fca.org.uk.

What UK capital teams should do before 2028

Until the PRA consults on binding rules, firms should apply the existing PRA framework to each exposure: assess any CET1 deduction for intangible assets, apply the 100 per cent market-risk expectation to unbacked cryptoassets where relevant, test whether tokenised traditional assets confer identical legal rights and comparable underlying risks, document the treatment in the ICAAP where Pillar 1 may not fully capture the risks, and discuss the proposed prudential treatment with the supervisor where appropriate.

Last updated: July 2026

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts