Bank Crypto Safekeeping: Custody Risks and Controls
Summary
The document outlines how US banking regulators frame crypto-asset safekeeping under existing fiduciary and non-fiduciary rules. It distinguishes safekeeping from the broader idea of custody, then describes operational controls banks may need, including secure key management, offline storage, transaction approvals, cybersecurity, asset reviews, anti-money-laundering compliance, and oversight of sub-custodians. These points are relevant to institutions assessing the risks around holding digital assets for clients.
The article gives recommendations rather than measured evidence: it reports no audit findings, incident data, or comparative assessment of control effectiveness. It also briefly mentions SEC disclosure guidance for crypto exchange-traded products and MITRE’s AADAPT framework, but supplies few details on either topic. Several sections, including audit procedures and consumer scams, are left undeveloped. Treat the piece as a high-level checklist, not legal advice or a complete account of regulatory requirements; firms would need to consult applicable rules and guidance directly.
Key ideas
- Banks should assess crypto safekeeping against existing fiduciary and non-fiduciary obligations.
- Secure key controls, cybersecurity, and asset due diligence are central operational safeguards.
- Banks using sub-custodians should evaluate providers and define responsibilities in contracts.
- The document recommends AML compliance and regular operational oversight but gives few implementation details.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.