A crypto custody playbook is a written set of procedures defining how digital assets are held, who may move them, how transfers are approved, and how custody providers are reviewed. It documents your choice between self-custody and qualified custody, your approval controls, and your annual review cadence, so custody is governed deliberately rather than by default.
What Crypto Custody Means
Custody is the practice of holding and controlling the private keys that authorize movement of digital assets. It is both a security decision (how keys are generated, stored, and signed with) and a governance decision (who approves transfers and how that is documented). For an SEC-registered adviser with custody of client crypto, the Advisers Act custody rule generally requires using a Cryptocurrency qualified custodians have emerged to serve institutional requirements. Qualified custody may be required for register">qualified custodian; whether a given crypto arrangement satisfies that rule depends on the facts and should be reviewed with qualified counsel. For a fuller overview, see what a qualified crypto custodian is and how custody fits into crypto wealth management.
Custody Steps
Work through these in order. Each step produces a document or control you can later show an examiner or trustee.
- Confirm legal ownership. Establish which person or entity (individual, Wyoming digital asset LLC, or trust) legally owns the assets and holds title to the keys.
- Identify regulatory or advisory requirements. Note whether an adviser has custody under the rule, whether a qualified custodian is required, and what Form ADV disclosures apply.
- Compare custody models. Weigh self-custody, qualified custody, and hybrid arrangements against your risk tolerance and operational capacity (see the table below and qualified custody vs self-custody).
- Select approved custodians or wallets. Run diligence on each candidate. SOC 1 / SOC 2 reports, insurance scope, key-management design, and regulatory status, using a custody due diligence checklist.
- Define transfer approval rules. Set signing thresholds (for example, multi-sig or M-of-N approval), dollar limits, and who must approve which transfers.
- Create address verification procedures. Require independent confirmation of destination addresses (test sends, allowlists, second-person checks) before any material transfer.
- Document signer succession. Record who holds keys or shards, where backups live, and how authority passes if a signer is lost. See private key succession planning.
- Reconcile statements and wallet activity. Compare custodian statements to on-chain wallet activity on a fixed schedule and investigate discrepancies.
- Review custodians annually. Re-run diligence at least yearly and after any material change at the provider.
Custody Models Compared
No model removes every risk. Self-custody concentrates operational and key-loss risk on you; qualified custody shifts key handling to a third party but adds counterparty and concentration risk. Choose by matching control to the capacity you actually have to govern it.
| Factor | Self-custody | Qualified custody |
|---|---|---|
| Who holds keys | You / your entity | Third-party qualified custodian |
| Custody rule fit (adviser) | Often does not satisfy the rule; facts-dependent | Generally designed to meet the rule |
| Key control burden | Falls entirely on you | Outsourced, with vendor oversight needed |
| Typical safeguards | Cold storage, multi-sig, hardware | SOC 1 / SOC 2 reports, segregation, stated insurance |
| Main residual risks | Key loss, signer error, succession gaps | Counterparty failure, concentration, access delays |
Insurance and any protection a custodian advertises cover only what their policy states; crypto held at a custodian is generally not covered by FDIC or SIPC insurance, and no arrangement removes market, custody, or tax risk.
Key Documents
- Custody policy.
- Transfer approval policy.
- Address verification policy.
- Custodian due diligence checklist.
- Incident response plan.
- Signer succession policy.
Related Questions
Does an RIA have to use a qualified custodian for client crypto?
Generally, when an adviser has custody of client assets, the Advisers Act custody rule requires holding them with a qualified custodian. Whether a particular crypto custodian or arrangement qualifies depends on the specific facts and remains an evolving area, so confirm the analysis with qualified counsel before relying on it.
Is self-custody allowed for high-net-worth crypto holders?
Individuals can generally self-custody their own crypto, and many do using cold storage and multi-sig. The trade-off is that key loss, signer error, and succession gaps fall entirely on the holder. Advisers with custody face additional rules. See how to choose a crypto custodian to weigh the options.
How often should custody arrangements be reviewed?
A common practice is at least an annual re-review of each custodian, plus an off-cycle review after any material change, a SOC report finding, ownership change, security incident, or shift in regulatory status. Reconciliation between custodian statements and on-chain activity should happen far more frequently.
Does using a registered custodian guarantee my crypto is safe?
No. Registration or licensing signals that a provider meets certain baseline requirements, but registration alone does not guarantee skill, solvency, or that assets are protected from every risk. Diligence on key management, audits, and insurance scope still matters.
Sources
- SEC: Custody rule compliance guide
- SEC: Custody rule FAQs
- SEC: Investor Bulletin, Custody of Your Investment Assets
Compliance Note
This playbook is educational and does not provide legal, tax, investment, fiduciary, compliance, or custody advice. Custody decisions should be reviewed with qualified professionals. Registration does not imply a certain level of skill or training.