Insights

Crypto Custody Rules Put Vendor Evidence Back in View

The SEC's new crypto custody proposal gives financial advisers and professional-services firms a practical reason to review custody roles, vendor evidence, and who is accountable when digital assets enter the conversation.

Editorial image of SEC crypto custody controls, digital asset keys, and vendor evidence documents on a financial services desk.

The Securities and Exchange Commission proposed new crypto custody rules on October 1, 2026, for registered investment advisers and regulated funds. The proposal is not a final rule, but it puts a very practical question in front of financial firms and the business owners who advise them: who actually controls the assets, and what evidence proves it?

The SEC said the proposal would create a tailored framework for the custody of crypto assets under the federal securities laws. It also described possible paths for self-custody in certain circumstances, the use of state trust companies as custodians, financial statement audit considerations, and broker-dealer custodial services for regulated funds.

That may sound like a securities-law story, but it quickly becomes a technology and vendor-accountability story. Crypto custody depends on systems, keys, permissions, transaction controls, audit trails, service terms, and incident response. For a New Jersey financial adviser, family office, accounting firm, law firm, or business owner evaluating crypto-related services, the technology setup is not a side detail. It is part of the risk.

The proposal changes the review conversation

Many firms hear the word custody and think first about a custodian name on a contract. That is only the start. If a vendor, platform, wallet provider, trust company, broker-dealer, or internal team touches the custody workflow, the firm should understand what each party is responsible for and where the evidence lives.

The useful owner question is not whether a provider sounds confident. The useful question is whether the firm can document the custody model well enough to explain it to leadership, counsel, auditors, examiners, insurers, and clients.

That means leaders should treat the SEC crypto custody proposal as a prompt to review current and planned arrangements before buying a tool, expanding an advisory service, or accepting a vendor's standard answer. Proposed rules can change, but vendor risk tends to show up early and stay for the whole relationship.

What owners and firm leaders should ask

Before approving a crypto custody vendor review, a regulated firm should ask direct questions that connect legal obligations to operational reality.

  • Who has control? Identify whether assets are held by a qualified custodian, a state trust company, a broker-dealer, the adviser, a fund, or another party.
  • What evidence is available? Request control reports, audit materials, transaction logs, access-control records, and written custody procedures where appropriate.
  • How are keys and permissions managed? Document who can approve movement of assets, how approvals are separated, and how emergency access is handled.
  • What happens during an incident? Review breach notification terms, service interruption procedures, asset-freeze options, and escalation contacts.
  • How will rule changes be tracked? Assign ownership for monitoring the final SEC rule, comment-period developments, contract updates, and operational changes.

Those questions are not anti-crypto. They are pro-evidence. If digital assets are going to sit inside a regulated business process, the firm needs records that survive more than a sales call.

The IT provider role is documentation, not guesswork

An MSP or internal IT team should not be expected to interpret securities law. That belongs with qualified legal and compliance advisers. But technology teams can help firm leadership understand systems, access, logging, backup dependencies, identity controls, vendor integrations, and incident-response gaps.

For example, an IT review can identify whether administrative access relies on shared accounts, whether multi-factor authentication is enforced, whether approval workflows are documented, whether logs are retained long enough to support an investigation, and whether vendor support access is limited and tracked.

That evidence can help leadership have a better conversation with counsel, compliance, auditors, and vendors. It also keeps the technology conversation grounded. The goal is not to chase every crypto headline. The goal is to avoid approving a custody model that no one can explain when the questions get specific.

A practical next step

Firms do not need to overhaul every system today because the SEC issued a proposal. They do need a current inventory of any crypto-related custody, wallet, staking, advisory, accounting, reporting, or client-service workflow that touches the business.

Start with a simple review: list the services in use, identify the parties with control or access, gather the available evidence, and flag contracts or systems where custody responsibilities are unclear. Then decide what should pause, what should proceed, and what needs a documented vendor response before the firm expands the service.

The SEC crypto custody proposal may still evolve. The need for clear custody controls, vendor evidence, and leadership ownership will not.

Sources and further reading

  1. SEC Proposal Would Address How Investment Advisers and Funds Can Custody Crypto Assets Under the Federal Securities Laws
  2. Statement on Proposal to Address the Custody of Crypto Assets Under the Investment Advisers Act and the Investment Company Act
  3. SEC's Division of Examinations Announces New Exam Handbook
Was this article useful?
0 net
Follow Tekmyster insights: RSS

Ready for better technical decisions?

Get senior technical judgment before the next move.

Use Tekmyster when you need senior technical judgment before making a larger IT decision, granting vendor access, replacing infrastructure, buying security tools, or continuing with temporary fixes.