Key Takeaways
The US Securities and Exchange Commission (SEC) wants to change how investment advisers and regulated funds safeguard crypto assets, potentially opening additional routes for investors to obtain professionally managed exposure.
Announced on Oct. 1, the proposal would permit certain adviser custody arrangements, recognize eligible state trust companies as crypto custodians, and modernize existing requirements. It covers registered investment advisers, registered investment companies, and business development companies.
However, its use of “self-custody” needs careful reading. Here, the term principally refers to an adviser holding clients’ assets itself, rather than individual investors controlling their own wallets.
And the framework remains a proposal, rather than an effective rule.
+68
Custody determines who controls access to assets and how those holdings are protected against theft, loss or misuse.
For cryptocurrencies, that responsibility centers on private keys and the systems used to authorize transactions.
Traditional custody rules were largely developed for financial infrastructure that predates blockchain, creating practical difficulties when advisers want exposure to assets that established custodians cannot support.
SEC Chairman Paul Atkins said custodial capabilities can lag the introduction of new crypto assets by months. His argument is that investors seeking professional advice should have a workable framework rather than rules poorly suited to the technology.
The proposal would amend requirements under the Investment Advisers Act of 1940 and the Investment Company Act of 1940. Alongside crypto provisions, it addresses financial statement audits, broker-dealer custody services, and other existing practices.
Its scope is also narrower than a universal rulebook for cryptocurrency ownership. The release ties relevant requirements to assets covered by the respective statutes, including funds, securities and, for regulated funds, securities or similar investments.
Commissioner Hester Peirce explicitly highlighted the terminology problem. An adviser who controls a client’s crypto assets is different from an investor who holds assets without an intermediary.
Under the proposal, an adviser would first need to determine that no permitted custodian is available for the particular crypto asset. That assessment would be repeated quarterly.
The exception, therefore, would not grant advisers unrestricted permission to bypass custodians simply because it is cheaper or more convenient.
Proposed safeguards include relevant custody expertise, cybersecurity protections, annual reviews, internal control reporting, and client disclosures. Commissioner Mark Uyeda also emphasized that the adviser’s fiduciary obligations would continue to apply.
More specifically, the release calls for transaction authorization by at least two people and addresses containing only the relevant client’s crypto assets. Clients would receive quarterly statements or equivalent usable electronic information, while regulated fund boards would oversee arrangements involving their advisers.
For an investor, the practical distinction is control: the adviser remains responsible for access and safekeeping. Calling the arrangement self-custody does not place the private keys in the client’s hands.
The proposal’s other major route would allow eligible state-chartered trust companies to safeguard client and fund crypto assets, subject to conditions.
These companies already participate in digital asset custody, but their eligibility under federal investment rules has required legal analysis that can discourage advisers from using them.
The proposed framework would require advisers and funds to examine a trust company’s state authorization and safeguarding procedures before engaging it, then repeat those checks annually.
They would also review annual audited financial statements and internal control reports. Client assets would need to be separated from the trust company’s own holdings.
Additional eligible providers could improve competition and reduce dependence on a small group of custodians. That is a potential consequence, rather than a guaranteed reduction in costs.
State authorization also would not make every provider equally capable. Technical controls, operational resilience, and the assets supported would remain relevant when selecting a custodian.
For an individual already using a personal wallet, the proposal does not directly require switching to an adviser or custody company.
Retail self-custody means managing access to private keys and recovery credentials. It provides direct control, alongside responsibility for protecting that access.
Third-party custody delegates key management but introduces dependence on the provider’s security and continued operation.
The SEC’s investor guidance identifies risks in both models, including compromised wallets, lost credentials and custodians that fail or become insolvent.
For clients using an adviser, the meaningful questions would include who authorizes transfers, how holdings are separated, what reporting is available, and what happens if the provider fails.
The SEC will accept comments for 60 days following publication of the proposed release in the Federal Register. Adoption and implementation would require further action.
If finalized, the framework could broaden access to managed crypto. Its central promise is more custody options with defined responsibilities, not an automatic guarantee that any particular arrangement is safe.