Feature Regulatory Compliance
SEC Crypto Custody Proposal: The Self-Custody Control Test Advisers Need to Run Now
The SEC crypto custody proposal would permit adviser self-custody—with quarterly availability tests, dual authorization, audits, and board oversight.
Table of Contents
TL;DR
- The SEC crypto custody proposal would let investment advisers self-custody covered crypto assets only when no permitted custodian is available—and that conclusion would need to be revisited quarterly.
- The proposed control stack is specific: documented safeguarding expertise, private-key controls, authorization by at least two people, client-level address segregation, annual cyber review, independent control reporting, and quarterly client statements.
- State trust companies could become permitted crypto custodians, but advisers and funds would inherit a documented initial-and-annual due-diligence obligation.
- This is a proposal, not an effective rule. Build the inventory and evidence map now; do not report a proposal-readiness gap as a current legal violation.
The SEC’s new crypto custody proposal does not create a casual “not your keys, not your coins” exception for investment advisers. It creates a tightly conditioned operating model—and the hardest condition may be the one that sounds simplest: proving, asset by asset and every quarter, that no permitted custodian is available.
On October 1, 2026, the SEC issued Release Nos. IA-7023 and IC-36353, a proposed package covering registered investment advisers, registered investment companies, and business development companies. The proposal would allow adviser self-custody in limited circumstances, admit qualifying state trust companies as permitted crypto custodians, and modernize parts of the broader custody regime.
Nothing is effective yet. The SEC press release says comments will be due 60 days after Federal Register publication. But the proposal is concrete enough to expose exactly where custody programs will break: incomplete asset inventories, undocumented custodian searches, concentrated key access, weak wallet segregation, stale vendor reviews, and assurance reports that nobody in Compliance has actually read.
What the SEC crypto custody proposal would change
The proposal has three distinct workstreams. Treating them as one “crypto policy update” will miss most of the implementation burden.
| Workstream | Proposed change | Primary owner | Evidence to build |
|---|---|---|---|
| Adviser self-custody | Permit self-custody of covered client crypto assets when no permitted custodian is available and conditions are met | CCO, COO, CISO, Digital Asset Operations | Asset determination, wallet map, key-control evidence, quarterly review |
| State trust company custody | Permit covered crypto custody with eligible state trust companies subject to due diligence and segregation | Vendor Risk, Legal, CCO | Charter analysis, control report review, audited financials, segregation confirmation |
| General custody modernization | Update discretionary-authority, standing-letter, inadvertent-custody, audit, account-notice, broker-dealer, recordkeeping, and form provisions | CCO, Fund Counsel, Finance, Operations | Obligations matrix, revised procedures, filing data lineage, exception analysis |
The scope needs careful handling. Commissioner Hester Peirce’s October 1 statement notes that the proposed Advisers Act provisions apply to crypto assets that are funds or securities; for a regulated fund, the Investment Company Act provisions apply to crypto assets that are securities or similar investments. “Crypto asset” is not itself the legal scope test.
That means Legal must classify the asset before Operations selects the custody path. A broad inventory label such as “digital asset—high risk” is not enough. The decision record should identify the asset, the client or fund account, the legal classification used for custody-rule analysis, the current custodian or wallet, and the specific proposed-rule provision the firm is evaluating.
This proposal also sits beside, rather than replaces, the SEC’s Regulation Crypto Assets offering proposal. One governs how certain crypto securities could be offered; this one addresses how covered assets would be safeguarded after acquisition. Teams using a single “SEC crypto” workstream should split those obligations now.
Self-custody starts with a quarterly market-availability test
Under the SEC’s four-page fact sheet, an adviser could self-custody a covered client crypto asset only after determining that a permitted custodian is unavailable. The adviser would repeat that determination quarterly.
That is not a one-time legal memo. It is a recurring control.
A defensible quarterly file should answer:
- Which custodians were evaluated? Maintain the population, not just the selected vendor list.
- Can they custody this specific asset? Support must be asset-level; “Custodian X supports crypto” proves very little.
- Can they serve this account and strategy? Document jurisdiction, client type, liquidity, staking, settlement, transfer, and contractual constraints.
- What does “unavailable” mean? Legal should define when pricing, onboarding delay, technical incompatibility, or unwillingness becomes unavailability rather than inconvenience.
- Who challenged the conclusion? The business team that prefers self-custody should not be the sole approver of the custodian-availability analysis.
The practical trap is obvious. A product team may find adviser custody operationally faster and then reverse-engineer a conclusion that no custodian is “available.” Compliance needs a repeatable search protocol, documented sources, and independent approval. If a permitted custodian begins supporting the asset next quarter, the firm needs a decision process for migration—not a stale memo explaining last quarter’s market.
For regulated funds, the board would have an additional role. The proposal would require the board to review the adviser’s written no-custodian-available report initially and quarterly, and to determine initially and annually that the fund asset would receive reasonable care under the adviser’s self-custody arrangement.
A board packet should therefore show the search evidence, changes since the prior quarter, incidents or control exceptions, and management’s recommendation. A checkbox saying “no qualified custodian available” is not meaningful oversight.
The proposed self-custody control stack is operational, not theoretical
The SEC’s proposed conditions read like an examination request list. Each condition needs a control owner and an artifact.
| Proposed condition | Control activity | Evidence an examiner could test |
|---|---|---|
| Safeguarding expertise | Approve asset-specific competency criteria and name qualified personnel | Skills matrix, training records, technical assessment, approval memo |
| Private-key management | Document generation, storage, backup, rotation, recovery, revocation, and destruction | Key ceremony records, access logs, recovery test, architecture diagram |
| Joint authorization | Require at least two people to authorize each crypto transaction | Workflow configuration, signer roster, sampled transaction approvals |
| Client-level segregation | Use one or more addresses that store only the applicable client’s assets | Address inventory, on-chain reconciliation, client-to-address mapping |
| Cybersecurity mitigation | Review crypto custody cyber controls at least annually | Risk assessment, test results, penetration findings, remediation log |
| Independent control report | Obtain a report from an independent public accountant within six months and annually thereafter | Engagement letter, report, exceptions, management response |
| Client reporting | Send account statements at least quarterly | Statement sample, delivery evidence, holdings reconciliation |
| Financial-asset treatment | Obtain a written agreement with the client | Executed agreement and legal review |
Joint authorization deserves more attention than adding a second name to a wallet workflow. The control should prevent one person from initiating, approving, and changing the signer configuration. Privileged administrators should not be able to replace both signers and then authorize a transfer without an independent alert and escalation.
A realistic control test would sample transactions, signer changes, failed approvals, emergency access, and wallet recovery events. It would also reconcile the on-chain transaction to the order-management record, client authorization where required, accounting entry, and client statement. “The multisig worked” is only one link in that chain.
The client-level address condition also changes the data model. Firms using pooled omnibus wallets need to determine whether their architecture can create and maintain addresses that store only a particular client’s assets. Operations should map wallet addresses to client books and records, and Compliance Testing should sample that map in both directions: client to address and address to client.
The SEC’s chairman’s statement frames the proposal as a compliant path where legacy rules did not fit newer assets. That framing does not reduce the control burden. It moves more responsibility into the adviser’s own systems, people, and evidence.
State trust companies would require ongoing custody due diligence
The second path is custody with a state trust company. The proposal would require an adviser or regulated fund, before engagement and annually thereafter, to have a reasonable basis after due inquiry for believing that the company:
- is authorized by the relevant state banking authority to provide crypto custody; and
- maintains and implements written safeguarding policies and procedures.
The firm would also obtain and review the custodian’s latest audited financial statements and internal control report. Client and fund crypto assets would need to be segregated from the trust company’s proprietary assets.
This is more than a procurement questionnaire. The annual review should produce a signed decision memorandum covering charter authority, regulatory status, financial condition, control-report scope and exceptions, subcustodians, key-management architecture, incident history, insurance claims relevant to custody, asset segregation, and unresolved remediation.
Vendor Risk may collect the documents, but the CCO cannot outsource the legal conclusion, and the CISO cannot outsource the technical review. Where a control report excludes a material wallet platform or subcustodian, the gap should be explicit. A clean opinion over the wrong system is not comfort.
This same principle appears in the site’s guide to SEC transfer-agent risk, recordkeeping, and blockchain controls: a modern ledger does not eliminate ordinary control evidence. Custody teams still need access governance, reconciliation, incident handling, change control, and recoverability.
Five things to put on Monday’s worklist
1. Build the custody inventory. The CCO and Digital Asset Operations lead should list every covered account, asset, legal classification, custody arrangement, wallet, custodian, subcustodian, control report, and contract owner.
2. Separate current-law gaps from proposal readiness. Legal should mark each finding as an existing obligation, a proposed condition, or a good-practice enhancement. That distinction belongs in issue titles, committee reporting, and board materials.
3. Run one transaction evidence trace. Pick a completed crypto transfer and trace initiation, dual approval, on-chain settlement, accounting, reconciliation, and client reporting. The missing handoff is usually more useful than another policy review.
4. Test the custodian file. Vendor Risk should select one crypto custodian and confirm the file contains charter authority, audited financials, the complete control report, exception follow-up, segregation evidence, and named review approvals.
5. Create the quarterly availability protocol. Define search sources, minimum custodians contacted, asset-level questions, approval roles, retention standards, and the trigger for moving out of self-custody if a permitted custodian becomes available.
Teams should also review the broader 2026 crypto compliance roadmap so custody changes do not get isolated from licensing, offering, stablecoin, and market-structure obligations.
Proposal-readiness findings still need owners, dates, dependencies, and closure evidence. The Issues Management Tracker & Template gives compliance teams a clean way to separate current deficiencies from regulatory-change work without losing either in a spreadsheet.
FAQ
Is adviser “self-custody” the same as a client holding their own keys?
No. In this proposal, self-custody generally describes an investment adviser holding covered crypto assets for clients or a regulated fund. Commissioner Peirce specifically distinguished that model from an investor personally controlling assets without an intermediary.
Would two signatures satisfy the whole key-management requirement?
No. The proposal’s fact sheet identifies joint authorization by at least two people as one required feature. The adviser would also need documented safeguarding expertise, systems designed to prevent loss and misuse, annual review, cyber controls, independent reporting, segregated addresses, statements, and other conditions.
Should proposed-rule gaps be entered in the issues tracker now?
Material readiness gaps can be tracked now, but label them accurately. A gap against an existing custody or fiduciary obligation may be a current compliance issue. A capability required only by IA-7023 should remain a regulatory-change readiness item unless and until a final rule makes it effective.
What is the comment deadline?
The SEC states that comments are due 60 days after the proposal is published in the Federal Register. Confirm the publication and deadline on the SEC rulemaking page before filing rather than counting 60 days from the October 1 announcement.
What is the first artifact a board should request?
For a fund evaluating adviser self-custody, start with the written asset-specific determination that no permitted custodian is available, including the search population, evidence, challenge, changes since the prior quarter, and control exceptions. That document drives the proposed quarterly oversight obligation.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the SEC propose for crypto custody on October 1, 2026?
Does the SEC crypto custody proposal allow every crypto asset to be self-custodied?
Can a state trust company serve as a crypto custodian under the proposal?
Is the SEC crypto custody proposal effective now?
What should an investment adviser do first?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
The OCC's GENIUS Act Final Rules Are Eight Weeks Out. Here's What Payment Stablecoin Issuers Need to Lock In Before the Clock Runs Out.
The OCC is targeting November 2026 for final GENIUS Act rules, with the framework becoming effective in January 2027 or 120 days after primary regulators finalize. Reserve requirements, eligible assets, capital floors, operational backstops — here is what issuers must have documented before the rules land.
Oct 2, 2026
Regulatory Compliance
FinCEN's A7 Network Rule: A Rejection Control, Not Another Watchlist Refresh
FinCEN's A7 Network rule and Alert007 require payment rejection, sub-agent screening, notice evidence, and new sanctions-evasion monitoring.
Oct 1, 2026
Regulatory Compliance
SEC v. Meyer Global: The $46,020 Capital Call That Allegedly Wiped Out a Nearly $3 Million SpaceX Stake
SEC v. Meyer Global turns a missed SpaceX capital call into a control lesson for private fund advisers. Here is what compliance teams should test.
Oct 1, 2026