Yes, in most cases. Giving advice and holding an asset are separate regulatory acts, and the custody rule attaches to possession or the authority to obtain possession, so knowing a wallet address does not create custody. My view is that the harder constraint sits in the duty of care, because the firm still has to build a defensible basis for advice on a position it cannot independently confirm.
The short version
- Custody means holding client funds or securities, or having any authority to obtain possession of them (17 CFR 275.206(4)-2(d)(2)). Advice moves nothing.
- Viewing does not create custody; the ability to move does. The staff answer on credentials turns on whether the access permits a withdrawal.
- The duty of care reaches past where the custody rule stops: the rule speaks to funds or securities, section 206 has no such limit.
- Reasonable investigation attaches to the investment, reasonable inquiry to the client. After that inquiry, a firm can generally rely on the client’s account of their own finances.
- What the firm touches sets the regime: seed phrases, signing devices, credentials, a key in a signing quorum, a capacity such as trustee.
Where the line between advising and holding sits
The rule defines its own trigger, and it runs to control rather than knowledge:
“Custody means holding, directly or indirectly, client funds or securities, or having any authority to obtain possession of them.”
Nothing there is tripped by looking. Reading a public address or importing an extended public key teaches the firm something and moves nothing. Staff drew the same line about login credentials: an adviser holding a client’s ID and password “has custody if password access provides the adviser with the ability to withdraw funds or securities or transfer them to an account not in the client’s name at a qualified custodian” (Staff Responses to Questions About the Custody Rule, Question II.6). Those closing words carry weight here, because a self-custodied position may involve no qualified custodian account on either end.
The rule’s words are “client funds or securities,” and whether a given token sits inside either has never been settled. The Division put that question to advisers in a March 2019 letter that also tells them to safeguard client assets under the policies required by 17 CFR 275.206(4)-7. The rule remains operative, its 2023 replacement withdrawn on 17 June 2025. Watch subparagraph (iii), which reaches any capacity giving access to client assets and names managing member of an LLC and trustee of a trust: managing the entity that holds the wallet, or serving a trustee in that capacity, changes the firm’s status.
Building a reasonable basis when you cannot see the position
The Commission’s 2019 interpretation governs the advice itself, and on the investment side it is explicit:
“A reasonable belief that investment advice is in the best interest of a client also requires that an adviser conduct a reasonable investigation into the investment sufficient not to base its advice on materially inaccurate or incomplete information.”
SEC Release IA-5248, Commission Interpretation Regarding Standard of Conduct for Investment Advisers
On the client side the release is gentler than most assume. After a reasonable inquiry into the client’s investment profile, it “generally would be reasonable for an adviser to rely on information provided by the client” about their financial circumstances, even where the client later misled the firm.
That split is the practical answer. A holding’s size is information about the client’s circumstances, so the client’s account of it, after inquiry, has support. The asset is the investment, and recommending anything about it demands real work.
Evidence of the position, strongest first: a message signed by the address, a client-initiated transfer of a trivial amount to an address the firm names in advance, a venue statement, then an image of a screen. None shows encumbrance, since a position pledged against a loan or behind a co-signer looks identical on chain to one that is free. Ask in words and keep the answer, which 17 CFR 275.204-2 already requires.
Key handling, and the point where advice turns into access
A firm can give a great deal of useful key-management advice without touching key material: quorum design and who holds which share, separation of backups, whether a passphrase exists and who else knows it, and whether recovery has been rehearsed against a real transaction. For a published reference, work from NIST Special Publication 800-57, which treats key management as a lifecycle from generation to destruction.
The lines I would write into the compliance manual: no seed phrase in any form, including a photograph, a password manager entry, or a note taken in a meeting; no possession of a hardware device, including while a client travels, a problem a trustee meets under a different rulebook; no wallet or exchange credentials, and no API key with withdrawal permission, which gets widened to fix a problem and stays widened; no key in a signing quorum that can move funds; no standing transfer authorization. The relief for inadvertent receipt runs to funds or securities returned within three business days, thin cover when the item is a phrase nobody can un-see.
Valuation, billing, and what the client is told
Two numbers come out of a self-custodied position and each needs a stated method. Form ADV counts toward regulatory assets under management “the securities portfolios for which you provide continuous and regular supervisory or management services,” and excludes advice given “on an intermittent or periodic basis” (Form ADV instructions, Part 1A Instruction 5.b). A wallet the firm cannot trade, looked at when the client raises it, sits badly against that test, and the honest reading keeps it out of the regulatory figure. Wherever it is counted, value it by the method used to report account values and calculate fees.
What the client sees is a separate exercise, and Part 2A Item 4.B requires a firm whose advice is limited to particular investments to say so (Form ADV Part 2). My position on billing is narrow: charge against a client-reported balance only where the brochure says so and the client’s written statement of value enters the file.
Give the client the limits in writing. The firm cannot confirm the holding exists, execute or halt anything, recover the position if access is lost, or reconcile against a third party’s statement, so the operational risk stays with the client. Scope can be agreed, since the duty applies in a manner reflecting the agreed scope of the relationship, while a provision purporting to waive it is inconsistent with the Act.
What I actually see
The manual says one thing and the meeting says another. A firm excludes digital assets on paper, then the adviser answers a question about the client’s wallet across the table, because staying silent feels absurd. Advice was given, nothing was recorded, and the only document on the subject says the firm does not do this.
Access widens by accident. A read-only key is issued so balances flow into the reporting system, a transfer needs doing during a busy onboarding, permissions get broadened, and nobody re-reads the scope. I have watched the same shape with a hardware device left in a firm’s safe after a meeting and forgotten.
The number nobody sourced. A wallet balance enters the plan from a screenshot, gets billed against, and appears in four quarterly reports, while nobody wrote down which venue, at which price, at what time, or whether the coins were pledged. When it matters, at a death or an examination, the firm finds its reports were repeating the client back to himself.
The check I would run. Take every self-custodied position in a client file and give each one four lines: the identifier the firm uses; the evidence of control it holds and its date, whether a signed message, a test transfer, a venue statement, or nothing; the price source and time used to value it; and what the firm can do about it, in verbs. Any position whose second line is empty gets labeled client-reported everywhere it appears, the fee calculation included. That takes an afternoon for a whole book and usually changes one billing arrangement.
Where this goes wrong
Firms fail here by answering a question about advice with a policy about custody.
The specific failures: a blanket prohibition that stops nothing, since the conversation happens anyway and now happens off the record. Advice given inside a scope the engagement letter excludes, so the firm carries the duty without the fee and without a file. A read-only integration widened during an operational fix and never narrowed. A valuation carried for years from a source nobody can name. Key-management help that drifted into holding a device, a passphrase on a meeting pad, or a signing seat accepted to be useful. A capacity taken on as manager or trustee of whatever holds the wallet. Basis records left to the client, then leaned on in a tax conversation where the usual record failures surface. And the opposite error, a capable firm that refers every wallet away instead of deciding when a specialist is warranted.
The decision rule
- Settle the scope in the agreement first, naming the self-custodied positions and whether advice on them is inside the engagement.
- Write the access rule before the first meeting: what may be viewed, what may never be held, who approves an exception.
- Ask the control questions in words: who signs, at what quorum, who else knows the passphrase, what is pledged.
- Obtain one piece of independent evidence per position, a signed message or a client-initiated test transfer, and date it.
- Fix the valuation method in writing: the venue, the time of day, the fallback when it is unavailable.
- Decide the billing treatment, and disclose it whenever a fee touches a client-reported balance.
- Give the client the limits as a list: verification, execution, recovery, the absence of a third-party statement.
- Re-verify on a calendar, annually and whenever the client reports a move, a new device, or a loan against it.
Where this sits
This is the advice question inside a cluster that splits three ways: what the rule demands once a firm crosses the line, the operating policy for held-away coins, and the file that survives an examination. Start with the compliance checklist and the custody hub.
Four professionals touch one wallet, and the seams between them are where this fails. The attorney drafts the entity or trust, the CPA reconciles basis and lots, the client holds the keys, the adviser advises, and none of them reads the others’ working papers. The gaps are predictable: an engagement letter excluding the largest holding the plan depends on, a trust instrument handing the adviser a capacity nobody flagged as custody, a billing valuation the tax return contradicts, a signing arrangement changed between reviews. Name the person whose job is to read all four in one sitting, because that role is normally unassigned.
Sources
- 17 CFR 275.206(4)-2, Custody of funds or securities of clients by investment advisers (Cornell Legal Information Institute)
- SEC Release No. IA-5248, Commission Interpretation Regarding Standard of Conduct for Investment Advisers (GovInfo, Federal Register, 12 July 2019)
- SEC, Staff Responses to Questions About the Custody Rule
- SEC Division of Investment Management, Engaging on Non-DVP Custodial Practices and Digital Assets (12 March 2019)
- Withdrawal of Certain Proposed Rules, 90 FR 25531 (GovInfo, Federal Register, 17 June 2025)
- SEC, Form ADV General Instructions and Part 1A Instructions
- SEC, Form ADV Part 2, brochure requirements
Related
- Qualified custody for RIAs managing digital assets
- Crypto held away from advisor: what should RIAs do?
- How should RIAs document crypto recommendations?
- Crypto compliance checklist for RIAs
- Digital asset custody
- Crypto for advisers and RIAs
Last updated: 3 August 2026.
This article is general education, not legal, tax, or investment advice. Whether a particular digital asset counts as client funds or securities is a fact-specific question, and nothing here recommends any asset, allocation, or provider. Talk to a qualified securities attorney and your compliance counsel about your own firm.
