A crypto custody policy template is a fill-in governance document a family office completes to record how its digital assets are held: which custodians and custody models are approved, who can access keys, who approves transfers, and how activity is reported. This page is the working skeleton. It is an educational outline, not legal advice; customize it with qualified counsel.
What a Crypto Custody Policy Is
A crypto custody policy is the internal governing document that states, in writing, how a family office secures and controls its digital assets. It names the people, accounts, custodians, and approval rules that apply to every wallet the office touches. Where a crypto family office holds assets directly rather than only through funds, this policy is what makes custody auditable instead of dependent on one person's memory.
A custody policy focuses narrowly on safekeeping and access, not on what to buy. It typically pairs with an investment policy statement and an allocation policy. It also sits inside a broader governance framework; see Crypto Governance for Family Offices and Digital Asset Governance Policy.
Why This Document Matters
Custody is the control layer of crypto wealth. If a family office cannot identify who can move assets, approve transactions, recover access, and document activity, it has an operational risk problem even when the investment thesis is sound. A policy does not remove market, custody, or technology risk; it makes the points of control explicit so they can be supervised, tested, and improved.
Questions to Settle Before Drafting
Resolve these before filling in custodian names, because they determine the rest of the structure.
- Will assets sit with a Cryptocurrency qualified custodians have emerged to serve institutional requirements. Qualified custody may be required for register">qualified custodian, an institutional platform, a self-custody setup, or a documented mix? A qualified custodian is the model SEC rules generally point advisers toward; self-custody shifts key-management risk onto the family.
- Are trust and LLC accounts separated from personal accounts? Separation can support charging-order protection and cleaner directed-trust administration, depending on the structure.
- For self-custody, is the design single-signature or multi-sig, and is the cold-storage backup geographically separate?
- Who can initiate transfers, and who must approve them?
- How are wallet addresses verified before funds move?
- How are statements and transaction records stored for tax and audit purposes? Form 1099-DA reporting and the IRS treatment of digital assets as property both make clean records matter.
How to Complete This Template
Work through the sections below in order. Each carries placeholder fields in brackets that the family office, its counsel, and its custody providers fill in.
- Purpose and scope,
[entities and accounts covered],[effective date],[policy owner]. - Covered assets and accounts, list each token, chain, and account in scope.
- Approved custody models, qualified custodian, institutional platform, self-custody, or a documented mix. State the rationale for each.
- Approved custodians and wallets,
[custodian name],[SOC 1 / SOC 2 report on file? Y/N],[wallet labels and addresses]. - Authorized users and signers,
[name / role]for each signer, plus multi-sig or MPC quorum (e.g.,[2 of 3]). - Transfer approval thresholds, dollar or asset limits that trigger additional sign-off; who initiates, who approves.
- Address verification process, test transfers, allowlists, and a second-person check.
- Staking and delegation authority, who may stake, with which validators, and within what limits.
- Account titling and entity ownership rules, how wallets map to LLCs, trusts, or other entities.
- Recordkeeping requirements, where statements, on-chain records, and approvals are stored, and for how long.
- Incident response process,
[who is notified],[escalation path],[key-compromise steps]. - Trustee, family member, and adviser permissions, read vs. approve vs. initiate.
- Trustee or successor access procedures, how a trustee or successor reaches keys if a signer is unavailable.
- Review schedule,
[review frequency]and[next review date].
The signer authority and allocation sections feed the Family Office Crypto Allocation Policy, so keep names and limits consistent across both documents.
Custodial vs. Self-Custody: How They Differ
| Dimension | Qualified custodian | Supervised self-custody |
|---|---|---|
| Key control | Held by the custodian | Held by the family office |
| Typical safeguards | SOC reports, insurance terms, segregation | Multi-sig / MPC, cold storage, documented backups |
| Recovery | Custodian process | Internal succession and backup procedures |
| Oversight burden | Vendor due diligence and monitoring | Ongoing internal controls and testing |
| Best suited to | Families wanting institutional process | Families able to supervise their own signing |
Many family offices use both models. The policy should state the rationale for each. Coverage terms (where any exist) are set by the custodian's own agreements; crypto custody is not covered by FDIC or SIPC insurance, and no arrangement removes the risk of loss.
Approved Custodian Checklist
Before a custodian or platform goes on the approved list, confirm each item. This mirrors the deeper review in Crypto Due Diligence for Family Offices.
- Qualified-custodian status and regulatory standing documented
- Current SOC 1 and/or SOC 2 report obtained and reviewed
- Custody model (segregated, omnibus, on-chain multi-sig) understood
- Insurance scope confirmed in writing, note that crypto custody insurance is limited and is not FDIC or SIPC coverage
- Key-management and disaster-recovery design reviewed
- Statement, API, and audit-trail access confirmed for recordkeeping
Evaluate each provider against the same checklist rather than assuming any one platform is inherently safer.
Sample Transfer Approval Tiers
The thresholds below are illustrative placeholders, not recommendations. Set your own with counsel and custody professionals.
| Transfer size | Initiation | Approval required | Address check |
|---|---|---|---|
Up to [threshold A] |
[role] |
One authorized person | Allowlisted address |
[threshold A] – [threshold B] |
[role] |
Two authorized persons | Allowlist + test transfer |
Above [threshold B] |
[role] |
[2 of 3] signers + written destination confirmation |
Allowlist + test transfer + second-person verify |
A sample clause: all outbound transfers above a stated threshold may require approval from two authorized persons and written confirmation of the destination address. This is a hypothetical example; customize it with counsel and custody professionals.
When a Policy May Not Be Enough
A policy is only useful if followed. Pair it with custody agreements, written operating procedures, technical controls, training, and periodic testing. Common gaps to avoid are covered in Common Crypto Custody Mistakes for Family Offices. For the broader custody review workflow, see Crypto Custody Review Process.
Related Questions
Is a crypto custody policy template the same as legal advice?
No. A template is an educational starting outline. The clauses, thresholds, and signer rules generally need to be drafted or reviewed by qualified legal and custody professionals before they apply to a real family office.
Does using a qualified custodian remove all custody risk?
No. A qualified custodian can address aspects of the SEC custody rule and provide SOC-audited controls, but no custody arrangement removes market, operational, or key-management risk entirely. Registration or audit status alone does not guarantee the elimination of loss.
How often should a family office review its crypto custody policy?
Many offices set a fixed review cadence and also revisit the policy after adding a custodian, changing signers, or experiencing a security incident. Record the next review date in the policy itself.
Should trust and personal crypto accounts share one custody policy?
They can share one policy, but the document should separate trust and LLC accounts from personal ones. Clean separation supports directed-trust administration and entity-level protections, depending on how the structures are drafted.
Should the policy allow self-custody?
Generally only if the family office can supervise it. Self-custody needs documented signing rules, backups, access controls, and succession procedures. The answer depends on the family's operational capacity and risk tolerance.
Should a family office use one custodian or multiple?
Some families diversify custody relationships to reduce single-vendor dependence; others prefer operational simplicity. The policy should state the rationale either way. See Should a Family Office Use More Than One Crypto Custodian? for the tradeoffs.
Should trustees be included in the policy?
Yes, where trusts own or may inherit digital assets. Trustee authority and custody procedures should match so that titling and signing rights stay consistent.
Sources
- SEC: Custody rule compliance guide
- SEC: Custody rule FAQs
- SEC: Investor Bulletin. Custody of Your Investment Assets
Compliance Note
This article is for general educational purposes and does not provide legal, tax, fiduciary, compliance, cybersecurity, or custody advice. Custody policies should be drafted and reviewed by qualified professionals before use.