Skip to content
RiskTemplates · The Daily Brief Friday, October 2, 2026
Wire SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake SEP 30

Feature Regulatory Compliance

SEC Crypto Custody Proposal: The Self-Custody Control Test Advisers Need to Run Now

The SEC crypto custody proposal would permit adviser self-custody—with quarterly availability tests, dual authorization, audits, and board oversight.

By Rebecca Leung · October 2, 2026 ·
Table of Contents

TL;DR

  • The SEC crypto custody proposal would let investment advisers self-custody covered crypto assets only when no permitted custodian is available—and that conclusion would need to be revisited quarterly.
  • The proposed control stack is specific: documented safeguarding expertise, private-key controls, authorization by at least two people, client-level address segregation, annual cyber review, independent control reporting, and quarterly client statements.
  • State trust companies could become permitted crypto custodians, but advisers and funds would inherit a documented initial-and-annual due-diligence obligation.
  • This is a proposal, not an effective rule. Build the inventory and evidence map now; do not report a proposal-readiness gap as a current legal violation.

The SEC’s new crypto custody proposal does not create a casual “not your keys, not your coins” exception for investment advisers. It creates a tightly conditioned operating model—and the hardest condition may be the one that sounds simplest: proving, asset by asset and every quarter, that no permitted custodian is available.

On October 1, 2026, the SEC issued Release Nos. IA-7023 and IC-36353, a proposed package covering registered investment advisers, registered investment companies, and business development companies. The proposal would allow adviser self-custody in limited circumstances, admit qualifying state trust companies as permitted crypto custodians, and modernize parts of the broader custody regime.

Nothing is effective yet. The SEC press release says comments will be due 60 days after Federal Register publication. But the proposal is concrete enough to expose exactly where custody programs will break: incomplete asset inventories, undocumented custodian searches, concentrated key access, weak wallet segregation, stale vendor reviews, and assurance reports that nobody in Compliance has actually read.

What the SEC crypto custody proposal would change

The proposal has three distinct workstreams. Treating them as one “crypto policy update” will miss most of the implementation burden.

WorkstreamProposed changePrimary ownerEvidence to build
Adviser self-custodyPermit self-custody of covered client crypto assets when no permitted custodian is available and conditions are metCCO, COO, CISO, Digital Asset OperationsAsset determination, wallet map, key-control evidence, quarterly review
State trust company custodyPermit covered crypto custody with eligible state trust companies subject to due diligence and segregationVendor Risk, Legal, CCOCharter analysis, control report review, audited financials, segregation confirmation
General custody modernizationUpdate discretionary-authority, standing-letter, inadvertent-custody, audit, account-notice, broker-dealer, recordkeeping, and form provisionsCCO, Fund Counsel, Finance, OperationsObligations matrix, revised procedures, filing data lineage, exception analysis

The scope needs careful handling. Commissioner Hester Peirce’s October 1 statement notes that the proposed Advisers Act provisions apply to crypto assets that are funds or securities; for a regulated fund, the Investment Company Act provisions apply to crypto assets that are securities or similar investments. “Crypto asset” is not itself the legal scope test.

That means Legal must classify the asset before Operations selects the custody path. A broad inventory label such as “digital asset—high risk” is not enough. The decision record should identify the asset, the client or fund account, the legal classification used for custody-rule analysis, the current custodian or wallet, and the specific proposed-rule provision the firm is evaluating.

This proposal also sits beside, rather than replaces, the SEC’s Regulation Crypto Assets offering proposal. One governs how certain crypto securities could be offered; this one addresses how covered assets would be safeguarded after acquisition. Teams using a single “SEC crypto” workstream should split those obligations now.

Self-custody starts with a quarterly market-availability test

Under the SEC’s four-page fact sheet, an adviser could self-custody a covered client crypto asset only after determining that a permitted custodian is unavailable. The adviser would repeat that determination quarterly.

That is not a one-time legal memo. It is a recurring control.

A defensible quarterly file should answer:

  1. Which custodians were evaluated? Maintain the population, not just the selected vendor list.
  2. Can they custody this specific asset? Support must be asset-level; “Custodian X supports crypto” proves very little.
  3. Can they serve this account and strategy? Document jurisdiction, client type, liquidity, staking, settlement, transfer, and contractual constraints.
  4. What does “unavailable” mean? Legal should define when pricing, onboarding delay, technical incompatibility, or unwillingness becomes unavailability rather than inconvenience.
  5. Who challenged the conclusion? The business team that prefers self-custody should not be the sole approver of the custodian-availability analysis.

The practical trap is obvious. A product team may find adviser custody operationally faster and then reverse-engineer a conclusion that no custodian is “available.” Compliance needs a repeatable search protocol, documented sources, and independent approval. If a permitted custodian begins supporting the asset next quarter, the firm needs a decision process for migration—not a stale memo explaining last quarter’s market.

For regulated funds, the board would have an additional role. The proposal would require the board to review the adviser’s written no-custodian-available report initially and quarterly, and to determine initially and annually that the fund asset would receive reasonable care under the adviser’s self-custody arrangement.

A board packet should therefore show the search evidence, changes since the prior quarter, incidents or control exceptions, and management’s recommendation. A checkbox saying “no qualified custodian available” is not meaningful oversight.

The proposed self-custody control stack is operational, not theoretical

The SEC’s proposed conditions read like an examination request list. Each condition needs a control owner and an artifact.

Proposed conditionControl activityEvidence an examiner could test
Safeguarding expertiseApprove asset-specific competency criteria and name qualified personnelSkills matrix, training records, technical assessment, approval memo
Private-key managementDocument generation, storage, backup, rotation, recovery, revocation, and destructionKey ceremony records, access logs, recovery test, architecture diagram
Joint authorizationRequire at least two people to authorize each crypto transactionWorkflow configuration, signer roster, sampled transaction approvals
Client-level segregationUse one or more addresses that store only the applicable client’s assetsAddress inventory, on-chain reconciliation, client-to-address mapping
Cybersecurity mitigationReview crypto custody cyber controls at least annuallyRisk assessment, test results, penetration findings, remediation log
Independent control reportObtain a report from an independent public accountant within six months and annually thereafterEngagement letter, report, exceptions, management response
Client reportingSend account statements at least quarterlyStatement sample, delivery evidence, holdings reconciliation
Financial-asset treatmentObtain a written agreement with the clientExecuted agreement and legal review

Joint authorization deserves more attention than adding a second name to a wallet workflow. The control should prevent one person from initiating, approving, and changing the signer configuration. Privileged administrators should not be able to replace both signers and then authorize a transfer without an independent alert and escalation.

A realistic control test would sample transactions, signer changes, failed approvals, emergency access, and wallet recovery events. It would also reconcile the on-chain transaction to the order-management record, client authorization where required, accounting entry, and client statement. “The multisig worked” is only one link in that chain.

The client-level address condition also changes the data model. Firms using pooled omnibus wallets need to determine whether their architecture can create and maintain addresses that store only a particular client’s assets. Operations should map wallet addresses to client books and records, and Compliance Testing should sample that map in both directions: client to address and address to client.

The SEC’s chairman’s statement frames the proposal as a compliant path where legacy rules did not fit newer assets. That framing does not reduce the control burden. It moves more responsibility into the adviser’s own systems, people, and evidence.

State trust companies would require ongoing custody due diligence

The second path is custody with a state trust company. The proposal would require an adviser or regulated fund, before engagement and annually thereafter, to have a reasonable basis after due inquiry for believing that the company:

  • is authorized by the relevant state banking authority to provide crypto custody; and
  • maintains and implements written safeguarding policies and procedures.

The firm would also obtain and review the custodian’s latest audited financial statements and internal control report. Client and fund crypto assets would need to be segregated from the trust company’s proprietary assets.

This is more than a procurement questionnaire. The annual review should produce a signed decision memorandum covering charter authority, regulatory status, financial condition, control-report scope and exceptions, subcustodians, key-management architecture, incident history, insurance claims relevant to custody, asset segregation, and unresolved remediation.

Vendor Risk may collect the documents, but the CCO cannot outsource the legal conclusion, and the CISO cannot outsource the technical review. Where a control report excludes a material wallet platform or subcustodian, the gap should be explicit. A clean opinion over the wrong system is not comfort.

This same principle appears in the site’s guide to SEC transfer-agent risk, recordkeeping, and blockchain controls: a modern ledger does not eliminate ordinary control evidence. Custody teams still need access governance, reconciliation, incident handling, change control, and recoverability.

Five things to put on Monday’s worklist

1. Build the custody inventory. The CCO and Digital Asset Operations lead should list every covered account, asset, legal classification, custody arrangement, wallet, custodian, subcustodian, control report, and contract owner.

2. Separate current-law gaps from proposal readiness. Legal should mark each finding as an existing obligation, a proposed condition, or a good-practice enhancement. That distinction belongs in issue titles, committee reporting, and board materials.

3. Run one transaction evidence trace. Pick a completed crypto transfer and trace initiation, dual approval, on-chain settlement, accounting, reconciliation, and client reporting. The missing handoff is usually more useful than another policy review.

4. Test the custodian file. Vendor Risk should select one crypto custodian and confirm the file contains charter authority, audited financials, the complete control report, exception follow-up, segregation evidence, and named review approvals.

5. Create the quarterly availability protocol. Define search sources, minimum custodians contacted, asset-level questions, approval roles, retention standards, and the trigger for moving out of self-custody if a permitted custodian becomes available.

Teams should also review the broader 2026 crypto compliance roadmap so custody changes do not get isolated from licensing, offering, stablecoin, and market-structure obligations.

Proposal-readiness findings still need owners, dates, dependencies, and closure evidence. The Issues Management Tracker & Template gives compliance teams a clean way to separate current deficiencies from regulatory-change work without losing either in a spreadsheet.

FAQ

Is adviser “self-custody” the same as a client holding their own keys?

No. In this proposal, self-custody generally describes an investment adviser holding covered crypto assets for clients or a regulated fund. Commissioner Peirce specifically distinguished that model from an investor personally controlling assets without an intermediary.

Would two signatures satisfy the whole key-management requirement?

No. The proposal’s fact sheet identifies joint authorization by at least two people as one required feature. The adviser would also need documented safeguarding expertise, systems designed to prevent loss and misuse, annual review, cyber controls, independent reporting, segregated addresses, statements, and other conditions.

Should proposed-rule gaps be entered in the issues tracker now?

Material readiness gaps can be tracked now, but label them accurately. A gap against an existing custody or fiduciary obligation may be a current compliance issue. A capability required only by IA-7023 should remain a regulatory-change readiness item unless and until a final rule makes it effective.

What is the comment deadline?

The SEC states that comments are due 60 days after the proposal is published in the Federal Register. Confirm the publication and deadline on the SEC rulemaking page before filing rather than counting 60 days from the October 1 announcement.

What is the first artifact a board should request?

For a fund evaluating adviser self-custody, start with the written asset-specific determination that no permitted custodian is available, including the search population, evidence, challenge, changes since the prior quarter, and control exceptions. That document drives the proposed quarterly oversight obligation.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the SEC propose for crypto custody on October 1, 2026?
The SEC proposed new and amended custody rules for registered investment advisers, registered investment companies, and business development companies. The proposal would permit adviser self-custody of covered crypto assets when no permitted custodian is available, subject to quarterly availability determinations, documented safeguarding expertise, joint authorization, cybersecurity controls, independent control reports, client statements, and other conditions.
Does the SEC crypto custody proposal allow every crypto asset to be self-custodied?
No. The proposed Advisers Act amendments apply to client crypto assets that are funds or securities. The proposed Investment Company Act rules apply to crypto assets that are securities or similar investments. The proposal also requires an adviser to determine initially and quarterly that no permitted custodian is available for the specific asset before using the self-custody path.
Can a state trust company serve as a crypto custodian under the proposal?
Potentially. Before engagement and annually thereafter, the adviser or regulated fund would need a reasonable basis, after due inquiry, to believe the state trust company is authorized by its state banking authority and has appropriate safeguarding policies. The firm would also review the trust company's latest audited financial statements and internal control report, and covered client assets would have to be segregated from the trust company's proprietary assets.
Is the SEC crypto custody proposal effective now?
No. Release Nos. IA-7023 and IC-36353 are proposed rules issued October 1, 2026. The comment period will remain open for 60 days after Federal Register publication. Firms must continue to follow current requirements and should label any gap work as proposal readiness rather than current-rule remediation unless the gap also violates an existing obligation.
What should an investment adviser do first?
Build an asset-by-asset custody inventory showing legal classification, current custodian, wallet structure, contractual control, availability of permitted custodians, and applicable custody-rule pathway. Then test whether existing key management, transaction authorization, cyber review, client reporting, accountant assurance, and issue governance could support the proposed conditions.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.