

Registered investment advisers generally must maintain client funds and securities subject to custody requirements with a qualified custodian. However, the SEC’s October 1, 2026 crypto custody proposal would create a limited exception allowing advisers to self-custody certain client crypto assets when no qualified custodian is available to maintain the particular asset. The framework is proposed and is not yet a final rule.
The SEC proposal would permit investment advisers to self-custody covered crypto assets only when they determine that no qualified custodian is available for the specific asset.
Advisers relying on the proposed exception would need to document the determination and reassess qualified-custodian availability at least quarterly.
Proposed safeguards include private-key controls, transaction authorization procedures, cybersecurity protections, client account statements, annual reviews and independent oversight.
State-chartered trust companies may serve a custody role under certain conditions, including existing SEC staff no-action relief and the separate framework proposed in October 2026.
Self-custody would not remove an investment adviser’s fiduciary duties or obligation to protect client assets against theft, loss, misuse and misappropriation.
The Securities and Exchange Commission’s Adviser and Regulated Fund Custody Rules; Crypto Custody Rules proposal was issued on October 1, 2026. It addresses registered investment advisers under the Investment Advisers Act of 1940 as well as regulated funds, including registered investment companies and business development companies.
The proposal would modernize existing crypto custody rules while establishing specific pathways for self-custody and permitted third-party custody. Under current adviser custody requirements, client funds and securities generally must be maintained with a qualified custodian when the rule applies.
The proposed crypto custody exception would not replace qualified custody as the default. Instead, it would provide a narrowly defined alternative when an adviser cannot find a qualified custodian willing or able to maintain a particular client crypto asset.
Under the proposed rule, an investment adviser could self-custody a client crypto asset when it has a reasonable basis, after appropriate inquiry, for determining that no qualified custodian is available to maintain that specific asset.
The determination must be asset-specific. An adviser could not simply conclude that qualified custody is unavailable for crypto assets generally. The adviser would need to document the basis for relying on the exception before obtaining possession or control of the client crypto assets.
The SEC proposal would also require the adviser to review qualified custodian availability at least quarterly. If an appropriate qualified custodian later becomes available, the adviser would generally need to transfer the asset to qualified custody as soon as reasonably practicable.
Cost alone would not necessarily establish that qualified custody is unavailable. The proposed exception focuses on whether an eligible custodian can actually provide custodial services for the particular crypto asset.
Self-custody would come with stricter operational and oversight requirements because the investment adviser would perform both advisory and custodial functions.
| Proposed safeguard | Requirement |
|---|---|
| Qualified-custodian determination | Document why no qualified custodian is available for the particular crypto asset |
| Quarterly review | Reassess custodian availability at least every quarter |
| Private key controls | Protect private keys and other authentication material from loss or unauthorized access |
| Transaction authorization | Maintain controls over who can approve and execute transactions |
| Cybersecurity | Maintain protections intended to reduce theft, compromise and operational loss |
| Annual reviews | Review safeguarding systems and related controls |
| Independent oversight | Obtain required independent public accountant involvement where applicable |
| Client communications | Provide account information covering client crypto holdings and transactions |
| Recordkeeping | Maintain documentation supporting custody decisions and compliance |
The proposed requirements recognize that controlling private keys can provide the ability to transfer digital assets. Advisers would therefore need internal controls designed to restrict unauthorized transactions and protect client assets.
Effective cybersecurity protections would also be essential. Private-key compromise, malicious authorization or operational failures could result in irreversible losses because blockchain transactions typically cannot be reversed through a traditional financial intermediary.
The proposed self-custody framework would require investment advisers to provide detailed account information for applicable client crypto assets.
Client statements would generally need to identify holdings and relevant transactions in a format that allows clients to verify their assets. The proposed framework contemplates reporting at least quarterly for assets covered by the self-custody arrangement.
Independent oversight would provide another layer of investor protection. The SEC’s proposed custody framework includes requirements involving independent public accountants, internal control reporting and verification procedures intended to reduce the risk of misappropriation or inaccurate asset records.
These controls matter because an adviser that controls client private keys may otherwise have the technical ability to move client assets without an unrelated custodian approving the transaction.
Qualified custody remains the preferred structure when an eligible custodian can maintain the relevant assets.
Depending on the applicable rule and institutional status, qualified custodians can include banks, savings associations and registered broker-dealers. Certain foreign financial institutions may also qualify when they meet the applicable conditions.
State-chartered trust companies have become particularly relevant for digital asset custody. In September 2025, the SEC Division of Investment Management issued conditional no-action relief concerning certain State Trust Companies, allowing registered investment advisers and regulated funds to treat qualifying entities as banks for specified crypto custody arrangements when the stated conditions are satisfied.
The October 2026 proposal would establish a more formal framework for state trust companies serving as permitted crypto custodians. Requirements would address authorization, safeguarding policies, cybersecurity, private-key management, financial condition and internal controls.
Federally chartered banks and other permitted custodians would remain important because the proposed self-custody exception is intended for situations in which suitable qualified custody is genuinely unavailable.
Adviser self-custody can increase operational and conflict-of-interest risks because the investment adviser may simultaneously select investments, manage client accounts and control the assets.
The SEC has emphasized that safeguarding client assets is intended to protect against misuse, misappropriation and loss. Commissioner Mark Uyeda’s October 2026 statement on the proposed custody amendments noted that an adviser’s fiduciary duty continues to apply when it directly holds client crypto assets.
Unlike an individual managing assets in a personal self-custody wallet, a registered investment adviser must consider fiduciary obligations, client authorization, recordkeeping, independent verification and regulatory compliance.
The proposed exception therefore does not treat possession of private keys as sufficient protection. Advisers would need controls governing access, segregation, transactions, cybersecurity and oversight.
The distinction between custodial and self-custodial arrangements can also be seen in ordinary crypto asset management. A non-custodial environment such as Gate Web3 allows users to interact with blockchain assets while maintaining direct wallet control, whereas custodial services involve a third party holding or administering assets on the user’s behalf.
For registered investment advisers, however, using a consumer self-custody wallet does not by itself satisfy SEC custody requirements. Advisers must evaluate whether their custody arrangements meet applicable federal securities laws, fiduciary duties, internal-control requirements and investor-protection standards.
The proposed crypto custody exception would allow advisers to self-custody certain client crypto assets only when qualified custody is genuinely unavailable and specific conditions are met. Those conditions include documented custodian searches, quarterly reviews, private-key safeguards, cybersecurity controls, client statements and independent oversight.
The key distinction is that the October 1, 2026 framework remains an SEC proposal rather than a final rule. Investment advisers and fund managers therefore need to distinguish proposed self-custody conditions from custody requirements and SEC staff positions that are already effective.
No. The proposed exception would not provide unrestricted authority to self-custody client crypto assets. It would apply only under specific conditions, principally when no qualified custodian is available for the particular asset.
Under the SEC proposal, the adviser would need a reasonable basis after due inquiry for determining that no qualified custodian will maintain the relevant crypto asset. The adviser would also need to document that determination.
The proposed rule would require advisers relying on the self-custody exception to reassess the availability of qualified custodians at least quarterly.
Some state-chartered trust companies may be used under specific conditions. The SEC issued conditional no-action relief in September 2025 for certain arrangements, while the October 2026 proposal would establish additional rules governing state trust companies acting as permitted crypto custodians.
Yes. The proposed framework would require safeguards designed to protect private keys, transaction authorization systems and client crypto assets against unauthorized access, theft, loss and misuse.











