Crypto Compliance Checklist for RIAs

Build the list rule by rule. 17 CFR 275.206(4)-7 requires the written policies, the annual review, and a chief compliance officer, and custody, books and records, marketing, and the code of ethics each add their own lines. My view is that an item nobody can trace to a rule gets dropped first.

RIA crypto compliance: the short version

  • The list exists because of 17 CFR 275.206(4)-7, which names no asset class and requires policies reasonably designed against the Act and the rules under it.
  • Custody turns on control. 17 CFR 275.206(4)-2(d)(2) reaches any authority to obtain possession, and a staff no-action position of 30 September 2025 adds five conditions for state-chartered trust companies.
  • Paid promoter arrangements carry three conditions under 17 CFR 275.206(4)-1(b): disclosure at dissemination, oversight plus a written agreement, and a disqualification check.
  • A token the firm has concluded is not a security falls outside the reportable security definition in 17 CFR 275.204A-1(e)(10), leaving your code of ethics blind to it.
  • Four proposals were withdrawn in June 2025 and the adviser AML rule moved to 2028, so a 2024 checklist carries dead lines.
The adviser rulebook changed in 2025: four proposals including safeguarding were withdrawn on 17 June 2025, the adviser AML rule moved from 1 January 2026 to 2028, SAB 121 was rescinded by SAB 122, and the custody rule 275.206(4)-2 still stands.
The adviser rulebook changed in 2025.

Which rule puts each line on the list

The compliance rule is where a checklist gets its authority:

“unless you: (a) Policies and procedures. Adopt and implement written policies and procedures reasonably designed to prevent violation, by you and your supervised persons, of the Act and the rules that the Commission has adopted under the Act”

17 CFR 275.206(4)-7

Read it as an instruction for generating the list: walk the rules the firm already lives under, ask what a digital asset changes about each, and the items arrive with a cite attached. The rule adds two obligations of its own, a review no less frequently than annually under paragraph (b) and a designated supervised person under paragraph (c).

The record of that review lives elsewhere. 17 CFR 275.204-2(a)(17) wants the policies in effect over the past five years and, separately, records documenting the review, so a review that leaves no artifact fails the second rule.

The four rules crypto changes, and what it changes about each

Custody, 17 CFR 275.206(4)-2. The definition is broader than firms assume:

“Custody means holding, directly or indirectly, client funds or securities, or having any authority to obtain possession of them.”

17 CFR 275.206(4)-2(d)(2)

So ask which keys the firm can reach: a seed phrase held for emergencies, a co-signer key in a multi-signature arrangement, an exchange API key with withdrawal rights. The staff’s no-action response of 30 September 2025 then treats certain state-chartered trust companies as banks here, on five conditions: initial and annual assessment of the custodian, audited financials and a controls report, client disclosure of the material risks, a best-interest determination, and segregation terms. Qualified custody and self-custodied positions turn on where they land.

Books and records, 17 CFR 275.204-2. Paragraph (a)(11) covers advertisements, (a)(12)(i) the code of ethics, (a)(16) whatever supports a performance presentation, and (a)(17) the policies and the review. Retention runs five years, the first two in an appropriate office of the adviser. A block explorer is public infrastructure and a venue may close, so neither is your book. Held-away positions are the hard case: the record you owe sits at a firm you have no agreement with.

Marketing, 17 CFR 275.206(4)-1. Paragraph (a) requires fair and balanced treatment of material risks and limitations, and a reasonable basis for believing a material statement of fact can be substantiated on demand, which is where crypto copy fails most.

Paragraph (b) governs paid promoter arrangements, the largest single change the 2021 marketing rule made and the one crypto firms touch most:

“(b) Testimonials and endorsements. An advertisement may not include any testimonial or endorsement, and an adviser may not provide compensation, directly or indirectly, for a testimonial or endorsement, unless the investment adviser complies with the conditions in paragraphs (b)(1) through (3) of this section, subject to the exemptions in paragraph (b)(4) of this section.”

17 CFR 275.206(4)-1(b)

Three conditions, three lines. (b)(1) requires the disclosure clearly and prominently at the time the statement is disseminated, so a post pointing at a disclosures page misses, and (b)(1)(i)(B) reaches non-cash compensation, which covers token grants and waived fees. (b)(2) adds a reasonable basis for believing the statement complies, plus a written agreement describing scope and terms of compensation. (b)(3) bars compensating anyone the adviser knows or should know is an ineligible person at that moment, so promoter background work recurs. The (b)(4)(i) exemption drops the written agreement and the disqualification check where compensation is absent or de minimis, and leaves the disclosure standing.

Code of ethics, 17 CFR 275.204A-1. Access persons report holdings and file quarterly transaction reports on reportable securities, and paragraph (e)(10) defines that term by reference to section 202(a)(18) of the Act. Copy the term across and the regime inherits the firm’s own securities conclusion. Where the firm publishes model allocations, the conflict is identical either way, so define the reportable asset by description.

Lines to strike, and one that arrived

Compliance calendars accumulate items that outlive the proposals behind them. Strike those by name and date so nobody restores them from an old deck.

The adviser anti-money-laundering program is the expensive one. FinCEN moved the effective date of the rule published at 89 FR 72156 to 1 January 2028 (FinCEN), so a firm that budgeted a build for 1 January 2026 spent that money two years early. The safeguarding rule is the headline strike, withdrawn on 17 June 2025 in an action that also ended the outsourcing proposal at 87 FR 68816, the cybersecurity risk management proposal, and the predictive data analytics proposal, with the Commission stating it does not intend to issue final rules on any of them (SEC). Four readiness projects, closed by one notice.

What arrived instead is Regulation S-P. The amendments adopted 16 May 2024 require an incident response program, oversight of service providers, and notice to affected individuals not later than 30 days after the firm becomes aware of unauthorized access. Advisers with $1.5 billion or more in assets under management were designated larger entities and had eighteen months from publication, the rest twenty-four (SEC). Publication was 3 June 2024, so both dates have passed.

What I actually see with RIA crypto compliance

The pattern I run into most is a digital asset policy living outside the compliance manual. It gets drafted carefully, saved to its own folder, and the annual review never reaches it. The activity carrying the most operational risk sits in the one file the review does not test.

Next is a custody answer that was true about the account and wrong about the key. The firm confirmed a qualified custodian holds the assets, wrote no custody in the file, and never asked operations what else exists. Somebody is keeping a recovery phrase in a fire safe, which is authority to obtain possession on any reading of (d)(2).

Third is the referral relationship nobody papered. A platform or a newsletter sends clients and gets something back, sometimes tokens or waived fees rather than cash, with no written agreement, no disclosure carried alongside the post, and no record that anyone ran the (b)(3) check. Marketing built it, compliance saw the copy, and the three conditions were never assigned to a person.

Here is the exercise, and it takes an afternoon. Pull your most recent annual review memo and write a rule cite in the margin beside every finding and every open item. Some cite cleanly. Some trace to a firm policy choice, which is fine if you label it. The rest cite nothing, and that residue is two piles: obligations you cannot name, and items that stopped being obligations.

Where RIA crypto compliance goes wrong

The list gets assembled from headlines rather than from the rulebook, so items arrive with urgency attached and no cite behind them.

The failures are consistent: a crypto policy filed outside the manual the review covers; a thorough review with no record documenting it, which satisfies 275.206(4)-7(b) and fails 275.204-2(a)(17)(ii); a custody conclusion drawn from the statement while a supervised person holds keys; a code of ethics that borrows the reportable security definition and never asks about a token trade; a compensated referral with no written agreement and no disclosure at dissemination; a readiness workstream still open for a withdrawn proposal; and recommendation files that record the trade without the reasoning.

The decision rule for RIA crypto compliance

  1. Write the rule cite beside every line, and delete anything you cannot source to a rule or label as a firm policy choice.
  2. Test custody against control, listing every key, seed phrase, co-signer, withdrawal-capable credential, and fee-deduction authority the firm can reach.
  3. Fold the digital asset policy into the manual the review covers, and record the review as it happens, since 275.204-2(a)(17)(ii) asks for the documentation and not only the review.
  4. Define reportable assets by description in the code of ethics, since the rule’s term follows the securities analysis and your conflicts do not.
  5. Open the substantiation file before any claim goes out, and keep the copy with its support for five years.
  6. Paper every compensated promoter before the first referral, with the (b)(2) written agreement, the (b)(1) disclosure alongside the statement, and the (b)(3) check recorded.
  7. Date every strike, naming the withdrawal or delay that removed the item, so the next calendar inherits the reason.

Where RIA crypto compliance fits

This page sits above the answers that go rule by rule. Qualified custody for digital assets works the custodian question in detail, documenting recommendations covers the file your care obligation leaves behind, and asset-level diligence covers what you owe before recommending a position. Where the client holds the asset elsewhere, start with held-away crypto and clients who own crypto outside the firm. Sub-advisory and referral move the obligation without removing it, and the custody hub maps the rest.

These questions cross professional boundaries, and the crossing is where they break. The rule cite belongs to compliance counsel, the operational fact to whoever runs the accounts and the keys, and the person answering an examiner is the chief compliance officer, who too often meets that fact for the first time in the room. The client’s attorney and CPA hold facts that change your answer, starting with which entity owns the position. If you would rather have a checklist where every line names the rule that creates it than a binder assembled from last year’s alerts, adviser and RIA coordination is where my firm starts.

Sources

Related

Last updated: 3 August 2026.

This article is general education, not legal, tax, or investment advice. Compliance policies and custody arrangements can reduce certain risks but do not eliminate them, and the obligations that apply to your firm depend on your registration, your activities, and your client base. Talk to qualified compliance counsel about your own situation.

Sources

    Jake Claver

    Written by

    Jake Claver

    Family office professional working on how substantial holdings are held, structured and passed on. Qualified Family Office Professional. Finance degree, University of North Texas. Board member, Arkansas Blockchain Council. Author of Wealth in Numbers and Infinite Banking for Crypto Investors.