Qualified Custody for RIAs Managing Digital Assets

The custody rule, 17 CFR 275.206(4)-2, applies to a registered adviser that holds client funds or securities or has any authority to obtain possession of them. It then requires a qualified custodian, written notice, quarterly custodian statements, and, in most cases, an annual surprise examination. My view: most firms diligence the custodian carefully and never run the same test on themselves.

Qualified custody for an RIA: the short version

  • The trigger sits inside your own firm. Custody reaches any capacity giving the adviser or a supervised person access to client assets, and access to a digital asset means key material or a signing seat.
  • Eligibility is a charter question. The rule names four kinds of institution, so technology, insurance, and audit history sit outside the definition.
  • The surprise examination is unannounced by design. The accountant picks the date, files Form ADV-E within 120 days, and notifies the Commission within one business day of a material discrepancy.
  • Staff relief dated 30 September 2025 lets an adviser treat certain state trust companies as banks for crypto custody, on conditions the firm re-satisfies annually.
  • The rule’s words are funds or securities, so how a client’s holdings classify decides how much of the position it reaches.
Qualified custody for RIAs managing digital assets: the trigger sits inside the firm, because custody reaches any capacity giving the adviser or a supervised person access to client assets; eligibility is a charter question and the rule names four kinds of institution, so technology, insurance and audit history sit outside the definition; the surprise examination is unannounced by design, with the accountant picking the date and filing Form ADV-E within 120 days; and staff relief dated 30 September 2025 lets an adviser treat certain state trust companies as banks for crypto custody, on conditions the firm re-satisfies.
The trigger sits inside your own firm.

What counts as custody when the asset is a private key

Start with the definition:

“Custody means holding, directly or indirectly, client funds or securities, or having any authority to obtain possession of them. … Custody includes … (iii) Any capacity … that gives you or your supervised person legal ownership of or access to client funds or securities.”

17 CFR 275.206(4)-2(d)(2)

Commission staff compressed it into one sentence: “Custody includes authority and access to client securities and funds, not just physical possession” (Engaging on Non-DVP Custodial Practices and Digital Assets, 12 March 2019). In digital assets that means key material. An exchange credential carrying withdrawal permission is authority. A recovery phrase in the office safe is access. One signature in a two-of-three quorum is access. So is managing the entity that owns the wallet.

Trading authority alone has not been treated as custody, and the Commission’s reason was settlement mechanics: a custodian moves assets out “only upon corresponding transfer of securities (or funds) into the account.” An on-chain transfer settles by itself, with no matching delivery holding the other side honest, so that comfort rests on a mechanism the asset lacks.

Then there is scope. The rule governs funds or securities, and in March 2026 the Commission interpreted how the securities laws apply to crypto assets: “Digital commodities, digital collectibles, and digital tools … are not themselves securities” (91 FR 13714, effective 23 March 2026). One client account can straddle the rule’s language, and the 2023 proposal that would have covered client assets generally was withdrawn on 17 June 2025, the Commission stating it “does not intend to issue final rules with respect to these proposals” (90 FR 25531). Reading that gap as permission misreads the risk: the antifraud provisions and Item 9 of Form ADV ask the same question in plainer language.

What the firm arranges, and what the client arranges

Paragraph (a)(1) allows two shapes: a separate account per client in that client’s name, or accounts holding only client assets in the adviser’s name as agent or trustee. Neither is satisfied by a dashboard showing a balance.

Notice under (a)(2) is owed where the firm opens the account on the client’s behalf, covering the custodian’s name and address, how the assets are held, and any later change. A firm that sends its own statements must also urge the client to compare the two. Delivery under (a)(3) is the paragraph I see misread most, because it is written as a diligence duty: the firm needs “a reasonable basis, after due inquiry, for believing that the qualified custodian sends an account statement, at least quarterly,” showing each holding at period end and every transaction in the period. A downloadable history becomes that document only when somebody confirms the custodian sends it, to the client, on that cadence.

Where the client holds a position the firm never touches, the analysis changes shape rather than disappearing: held-away positions and assets outside the firm each have their own answer, and advising on self-custodied holdings turns on whether the firm accepted any credential.

The surprise examination and the internal control report

Independent verification under (a)(4) is annual, and the timing belongs to the accountant, “at a time that is chosen by the accountant without prior notice or announcement to you and that is irregular from year to year.” The agreement requires a certificate on Form ADV-E within 120 days and notice to the Commission within one business day of any material discrepancy. Fee-deduction-only custody is excepted, as is custody arising solely through an operationally independent related person.

Read (a)(6) before designing anything clever, because it governs an adviser or related person acting as its own qualified custodian. It requires an annual internal control report opining that custodial controls were suitably designed and operating effectively, plus this: “The independent public accountant must verify that the funds and securities are reconciled to a custodian other than you or your related person.” An arrangement whose entire design is that only the firm can move the asset leaves no outside record to reconcile against. Max Avery’s account of a custodian that could not open its own wallets shows what that reconciliation catches, and custody remains a core review area in the Division of Examinations’ fiscal year 2026 priorities.

The state trust company route and its conditions

Most crypto custodians reach the definition through the bank category, where the fit of a state-chartered trust company was unsettled for years. On 30 September 2025 the staff addressed it:

“the Division of Investment Management … would not recommend enforcement action … against a Registered Adviser or Regulated Fund for treating a State Trust Company as a ‘bank’ with respect to the placement and maintenance of Crypto Assets … provided that …”

SEC Division of Investment Management, response to Simpson Thacher & Bartlett LLP, 30 September 2025

The conditions are the work. Before engaging the custodian and every year after, the firm needs a reasonable basis after due inquiry that the state banking authority authorized that entity for crypto custody and that it keeps written policies on private key management and cybersecurity, resting on audited GAAP financial statements and a current internal control report covering safeguarding. The custodial agreement must bar lending, pledging, hypothecation, and rehypothecation without prior written consent, and require segregation from the custodian’s own assets. Material risks of using the arrangement get disclosed to clients, with a recorded best-interest determination. The staff closed two doors on the way out: “all requirements of the respective Custody Provisions continue to apply,” and the letter “is not a rule, regulation, or statement of the Commission.” National banks are a separate route (OCC Interpretive Letter 1183, 7 March 2025).

What I actually see with qualified custody for an RIA

The analysis gets run on the custodian and never on the firm. Somebody builds an excellent provider file while a withdrawal-enabled API key, a seed phrase taken during onboarding, and a signing seat in a client multisig sit unexamined three floors away.

The account statement gets assumed. A portal, a balance, and a CSV export stand in for the (a)(3) inquiry, and nobody confirmed the custodian sends a statement to the client quarterly. It surfaces during an examination, the worst moment to learn the answer.

Form ADV drifts from operations. Item 9 was answered honestly in year one, then the firm took key access to solve a client problem in an afternoon, and the filing now describes a firm that no longer exists. Read your record at Investment Adviser Public Disclosure before a regulator does.

The check I would run. One page, one row per path by which anyone at the firm could move a client’s digital asset without the client acting: exchange credentials with withdrawal permission, whitelisted addresses somebody can edit, recovery material on the premises, a signing key in a client quorum, any entity the firm manages that owns a wallet. Write the named individual, the credential, and the control that stops one person acting alone. Then read Item 9 of your Form ADV against the page. In my experience the page runs longer than the filing implies, and the gap is one convenience nobody wrote down.

Where qualified custody for an RIA goes wrong

Firms fail this by answering the custodian question thoroughly and the authority question never.

The specific failures: an API key issued with withdrawal permission because trading permission alone was harder to configure; a signing seat taken in a multisig to protect a client from themselves, converting a service into custody in one meeting; an omnibus wallet with no per-client record, so the (a)(1) shapes describe nothing real; a surprise examination scheduled cooperatively with the accountant, which defeats the only feature the paragraph has; and a sub-advisory chain where each firm assumed the other held custody and nobody documented the split.

The decision rule for qualified custody for an RIA

  1. Map every path to movement first, person by person and credential by credential, before evaluating any provider.
  2. Classify the holdings against the rule’s own words, funds or securities, and record the reasoning and its date.
  3. Name the custodian’s exact legal entity and confirm its charter with the state banking authority or the OCC rather than with the provider.
  4. Work the 30 September 2025 conditions as a checklist, and calendar the annual repeat the day you finish.
  5. Read the custodial agreement on lending, pledging, rehypothecation, and segregation, and have counsel resolve anything ambiguous.
  6. Confirm statement delivery in writing: quarterly, to the client, holdings at period end, transactions for the period.
  7. Engage the accountant early and settle how a key-controlled asset gets tested before signing the engagement letter.
  8. Reconcile Item 9, the brochure, and the manual to what operations does, then re-run this list after any change in access.

Where qualified custody for an RIA fits

Start with the custody hub for the arrangements, then the compliance checklist for the program around them and the due diligence checklist for the provider file. Documenting recommendations is the evidence layer that makes any of this demonstrable a year later.

These questions cross professional boundaries, and the crossing is where they fail. The attorney drafts the custodial agreement, the accountant runs the surprise examination, the custodian runs key management, and the compliance officer answers Form ADV. Each works from a document the others never see, so the contradictions live in the gaps: a pledge the agreement permits and the manual forbids, an access change nobody filed, a charter held by an entity other than the one on the signature page. Before the next examination, name the person who reads all four together, because that seat is usually empty.

Sources

Related

Last updated: 3 August 2026.

This article is general education, not legal, tax, or investment advice. It describes regulatory requirements that apply to registered investment advisers and does not evaluate or recommend any custodian, and compliance with the custody rule can reduce certain risks but does not eliminate them. Talk to a qualified attorney and your compliance counsel about your own situation.

Sources

    Jake Claver

    Written by

    Jake Claver

    Family office professional working on how substantial holdings are held, structured and passed on. Qualified Family Office Professional. Finance degree, University of North Texas. Board member, Arkansas Blockchain Council. Author of Wealth in Numbers and Infinite Banking for Crypto Investors.