A crypto custody review process is a recurring examination of whether a digital asset custody arrangement still fits the owner's legal, operational, tax, and governance needs. It confirms who legally owns the assets, which custody model holds them, how transfers are approved, and whether access and signer succession are current. Family offices, RIAs, and trustees run it on a set cadence.
What a Crypto Custody Review Covers
The review tests the full custody arrangement rather than the price of the assets. It examines the legal owner, the custody model (Cryptocurrency qualified custodians have emerged to serve institutional requirements. Qualified custody may be required for register">qualified custodian, self-custody, or a hybrid), account titling, transfer and address controls, statements and tax exports, insurance disclosures, and signer succession. This process sits inside broader crypto custody for family offices and is one of the core operational disciplines run on schedule rather than only after something breaks.
A qualified custodian is generally a bank, trust company, or broker-dealer that holds client assets under the SEC custody rule. Whether a given crypto arrangement meets that standard is fact-specific and should be confirmed with qualified counsel. For the threshold definition, see what is a qualified crypto custodian.
Review Steps
- Confirm the legal owner. Match assets to the individual, trust, LLC, or other entity that should hold them. Verify titling reflects current estate and entity documents.
- Identify the custody model. Record whether each holding sits with a qualified custodian, in self-custody (cold storage, multi-sig, hardware wallet), or a hybrid. Document where keys and backups physically reside.
- Review account title and authorized users. Confirm the account name matches the legal owner and that the list of parties with view, initiation, or approval rights is current.
- Review transfer approval controls. Check withdrawal limits, multi-person approval requirements, and whether large or new-destination transfers require a second approver. See crypto transfer approval policy.
- Review address verification controls. Confirm allowlisting of known addresses and a defined procedure for verifying any new destination before funds move. See crypto address verification policy.
- Review statements and tax exports. Confirm complete transaction history and cost-basis data are accessible for reporting, including records relevant to Form 1099-DA.
- Review insurance and SOC reports. Request current SOC 1 and SOC 2 reports and read what custody insurance covers and excludes. Crypto custody coverage is not FDIC or SIPC deposit protection. See crypto custody SOC 1 and SOC 2 reports.
- Review signer succession. Confirm a documented, tested path for an authorized party to access assets if a key holder is unavailable. See crypto signer succession policy.
- Document issues and next steps. Log each gap with an assigned owner and a target resolution date. Schedule the next review.
For a line-item vendor evaluation version of steps 4 through 8, see the crypto custody due diligence checklist.
When to Review
Run the review on a fixed cadence. Trigger an out-of-cycle review after: new account openings, trustee or signer changes, family office policy changes, token unlocks, large transfers, custodian service or ownership changes, or a security incident at the custodian.
Annual Custodian Review Checklist
The annual review is the recurring counterpart to initial onboarding diligence. A custodian that fit at account opening can drift: regulatory registration, asset support, audit posture, fees, and ownership all change over time. This checklist re-examines those facts on current evidence rather than the version signed at onboarding.
Work through each item, document what changed since last year, and flag anything requiring follow-up before the file is signed off.
- Legal entity and regulatory status, confirm the operating entity, its charter (for example, a state trust company), and that any registration remains current. Registration alone does not guarantee skill, safety, or favorable outcomes.
- Qualified custodian analysis, where the SEC custody rule applies, reconfirm whether the custodian still meets the qualified custodian definition for the assets held. See what is a qualified crypto custodian.
- Asset support, verify the specific tokens and networks you custody are still supported and that none have been delisted or restricted.
- Account types supported, confirm continued support for your trust, LLC, and family office entity structures, consistent with your crypto account opening checklist for trusts and LLCs.
- Transfer approval controls, re-test withdrawal address allowlisting, multi-approver release, and the key model (multi-sig or MPC) against your transfer approval policy.
- SOC reports, obtain current SOC 1 and SOC 2 reports, read the auditor's opinion, and review any noted exceptions and your responsibility as a user entity.
- Insurance disclosures, review what custody insurance actually covers, its limits, and its exclusions. Crypto custody coverage is not FDIC or SIPC protection. See crypto insurance and custody.
- Fees, compare current fee schedules against last year and against your engagement terms.
- Statements and tax exports, confirm statements reconcile and that exports support your tax records, including readiness for evolving reporting requirements.
- Incident history, ask about security incidents, outages, and any operational changes since last review.
- Service quality, assess responsiveness, operational reliability, and support for governance requests.
- Changes in terms, review amendments to the custody agreement, sub-custody arrangements, and ownership structure.
Family Office Supplemental Questions
- Does the custodian still support all relevant trusts and LLCs?
- Are reports sufficient for tax and governance, or do gaps need to be raised?
- Are signer changes documented and reflected in current access rights?
- Is exposure too concentrated with one provider? See should a family office use more than one crypto custodian.
Related Questions
How often should a crypto custody review be done?
No single mandated frequency applies. Many family offices and advisers conduct a full review annually and additionally whenever a triggering event occurs, a trustee change, a security incident, a large transfer, or a custodian ownership change. The appropriate interval depends on the size and complexity of the holdings.
What documents should I request for an annual custodian review?
Typically: current SOC 1 and SOC 2 reports, proof of regulatory or charter status, insurance summaries, the current fee schedule, and any amendments to the custody agreement since last review. What constitutes a sufficient package depends on your circumstances; review it with qualified counsel and compliance.
Does using a qualified custodian remove all custody risk?
No. A qualified custodian can reduce certain operational and safekeeping risks, but no arrangement eliminates market, custody, tax, or key-management risk. Registration or qualified status alone does not guarantee performance or safety, and custodian insurance is generally not equivalent to FDIC or SIPC deposit coverage.
Who should perform the review?
Reviews are generally run by the asset owner's adviser, family office staff, or trustee, with qualified legal and tax professionals involved where titling, fiduciary duties, or reporting are in question. For evaluating custody model choices, see qualified custody vs self-custody for crypto wealth.
What triggers an out-of-cycle review?
Material triggers include: new account openings or entity changes, trustee or key-person turnover, significant transfers or token unlock events, custodian ownership changes or security incidents, and regulatory actions affecting the custodian.
Sources
- SEC: Custody Rule Compliance Guide
- SEC: Custody Rule FAQs
- SEC: Investor Bulletin, Custody of Your Investment Assets
Compliance Note
This page is educational and does not provide legal, tax, investment, fiduciary, compliance, or custody advice. Custody arrangements and custodian selection involve facts specific to each client and entity structure. Reviews should be conducted with qualified legal, tax, and compliance professionals. Registration does not imply a certain level of skill or training.