What happened

On 1 October 2026 the SEC proposed new rules and amendments that would create a tailored regime for the custody of crypto assets by registered investment advisers and regulated funds, meaning registered investment companies and business development companies. The proposal sits under the Investment Advisers Act of 1940 and the Investment Company Act of 1940.

The commission's stated aim is to replace rules written for a different market. Chairman Paul S. Atkins said the existing rules "have not kept pace" with a crypto market that has grown into a multi trillion dollar asset class, and described the proposal as giving advisers and funds a compliant pathway where none existed before. The package would also allow regulated funds to offer clients access to a wider range of crypto related investment strategies, and would update several requirements, including financial statement audits for registered investment advisers and broker dealer custodial services for regulated funds.

Two changes stand out for operations. First, the proposal would permit crypto assets to be held in self custody under certain circumstances. Second, it would allow the use of state trust companies as custodians for client and regulated fund crypto assets. A fact sheet and the proposed rule text were published alongside the release. The public comment period runs for 60 days after the proposing release is published in the Federal Register.

Why this is a GRC story

Custody is one of the oldest control domains in asset management. Advisers already operate under qualified custodian requirements, surprise examinations and client statement delivery, because someone has to hold client property safely and prove it. Extending that architecture to crypto assets extends the evidence trail to keys, wallets, network selection and settlement finality, where an asset can be moved irreversibly by whoever controls the key.

Self custody moves risk rather than removing it. Allowing self custody under conditions puts key management, access control and recovery planning squarely inside the adviser's control environment. Those are the areas where crypto losses usually happen, and they are harder to evidence than a bank statement. Any adviser considering that route should expect questions about who holds the keys, how a transfer is authorised, what happens when staff leave, and how the firm would recover after a loss.

Audit duties and custodian eligibility reshape the compliance matrix. Updating audit expectations for advisers and adding state trust companies to the eligible custodian pool means new due diligence, new agreements and new monitoring. Each choice has to be justified on the file, which is the part that quietly consumes most of the operational effort.

What to watch

The definitions will decide how much work this creates. What counts as custody, and what "certain circumstances" for self custody actually means, are the questions practitioners will read first. Watch the comment file as well: custodian banks, state regulators and investor advocates will all push on whether the safeguards are strong enough for retail exposure.

A reasonable next step for an adviser with crypto exposure is to draft the safeguarding section the way a supervisor would read it. Where does client crypto sit, who can move it, what independent verification exists, and what would the firm disclose if a key were lost. If those answers are missing today, the 60 day comment window is a good moment to find out.

Attribution: Analysis based on the SEC's press release and the accompanying fact sheet. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News