U.S. Banks: Pass Crypto Custody Exams After Rescission

Bank examiner observing secure custody controls

Banks in the United States may custody crypto-assets for customers, and federal supervisors have said so directly: the OCC, the Federal Reserve, and the FDIC now treat custody as a permissible banking activity, provided it’s conducted safely and soundly and in full compliance with existing law. The SEC and the New York Department of Financial Services shape the edges of that permission, particularly around adviser custody obligations and customer-asset segregation. The real test isn’t whether custody is legal. It’s whether a bank’s controls, BSA/AML program, and third-party oversight can survive an examiner’s scrutiny.


TL;DR:

  • Banks can custody crypto-assets without pre-approval if activities are managed safely, with supervision shifting from pre-launch filings to exam reviews.
  • Regulators emphasize strong controls over key management, including verifiable on-chain control records and robust incident response plans.
  • Sub-custodians are permitted but banks retain ultimate accountability, requiring deep due diligence, strict contracts, and ongoing oversight.
  • Proper custody agreements must clearly specify ownership and avoid creating debtor-creditor relationships to protect customer assets in insolvency.
  • A governance-first approach, supported by continuous documentation and oversight, is critical for exam readiness, not just choosing the right technology.

Wush
Build Stronger Custody Governance
DARE helps digital asset teams develop governance, assessment, and compliance capabilities for secure, responsible custody operations.
Explore DARE certification

Table of Contents

What Changed in Bank Crypto Custody Regulation Since 2026

The regulatory readout for 2025 and 2026 is less about new permissions and more about regulators stepping back from friction they’d created themselves. For years, banks exploring crypto custody faced a de facto pre-clearance regime: notify your primary regulator, wait, sometimes wait months, before launching anything. That regime is largely gone.

The FDIC moved first. Between March and April 2025, the agency rescinded prior letters requiring advance notification before a bank could engage in crypto-related activities. The replacement standard is simpler to state and harder to satisfy in practice: banks may proceed as long as the activity is managed in a safe and sound manner, with risk management appropriate to the specific exposure. No filing, no waiting period, no regulator sign-off before launch, though banks must manage the activity in a safe and sound manner. That sounds like deregulation. It’s actually a shift in when scrutiny happens, from a paperwork gate before launch to a supervisory exam after launch.

The OCC followed with its own clarification in May 2025, confirming that national banks and federal savings associations may provide crypto-asset custody and execution services directly, so long as the activity meets the same safe-and-sound bar and complies with applicable law. The OCC has since built out the specifics through interpretive letters. Interpretive Letters 1184 and 1186, along with Corporate Decision 1366, spell out what banks can actually do under that umbrella: hold cryptographic keys on behalf of customers, outsource custody functions to qualified sub-custodians, and offer specific ancillary services like staking in a fiduciary capacity.

Outsourcing matters here because most banks entering this space aren’t building custody infrastructure from scratch. The OCC’s position is that a bank can rely on a third-party sub-custodian, but the bank never outsources its regulatory responsibility. That distinction shows up repeatedly across every piece of guidance issued in the past year.

The Federal Reserve and FDIC added the interagency layer in July 2025 with a joint statement on crypto-asset safekeeping, co-issued with the OCC. This document does real conceptual work: it defines “safekeeping” for crypto-assets and draws a clear line between fiduciary and non-fiduciary custody arrangements. Critically, the statement insists that offering crypto safekeeping doesn’t create a new category of supervisory expectation. Existing safekeeping law and safety-and-soundness principles apply. What’s new is the asset class, not the legal framework.

A few points from that interagency statement carry outsized weight for compliance teams building programs right now:

  • Banks must demonstrate board and senior management understanding of the specific risks tied to cryptographic key management, not just crypto markets generally.
  • Contingency planning for key loss, compromise, or vendor failure is treated as a core safekeeping control, not an optional add-on.
  • Examiners will look at whether safekeeping arrangements are documented clearly enough to determine, in an insolvency scenario, what belongs to the customer and what belongs to the bank.

Meanwhile, the SEC has been running its own parallel track. Registered investment advisers have long operated under Rule 206(4)-2, the custody rule, which requires client assets to sit with a “qualified custodian.” The SEC’s custody-rule modernization framework proposes a reasonableness standard that could let advisers use nonqualified custodial arrangements if those arrangements achieve equivalent security outcomes. For banks marketing custody services to advisers and fund managers, this matters directly: it could widen or narrow the pool of clients who need a bank-grade qualified custodian versus a lighter-weight alternative. Banks and their compliance teams tracking SEC crypto custody obligations for adviser clients should watch this rulemaking closely, since it will reshape demand for bank custodial services regardless of how it lands.

Building a Compliant BSA/AML Program for Crypto Custody

Custody permission from the OCC doesn’t mean much if the compliance program underneath it can’t hold up. Regulators have been consistent on this point: crypto custody doesn’t get a lighter BSA/AML standard because the assets are digital. If anything, examiners apply more scrutiny, because the tools banks have used for decades to identify counterparties don’t map cleanly onto blockchain transactions.

Know-your-customer and enhanced due diligence for crypto custody clients need to go further than standard account opening. A bank has to understand not just who the customer is, but where their crypto came from and whether the addresses feeding into custody accounts show mixing, layering, or ties to sanctioned wallets. On-chain identity is pseudonymous by design, which creates real friction: a wallet address doesn’t come with a name attached. Banks solve this by combining blockchain analytics tools with traditional KYC files, cross-referencing wallet clusters against sanctions lists and known illicit-activity databases before assets ever move into custody.

Transaction monitoring for on-chain activity looks different from monitoring wire transfers. Instead of dollar thresholds and geographic risk flags, custody teams need systems that can trace fund flows across multiple hops, flag interactions with mixing services or privacy coins, and identify when a customer’s deposit address has touched a sanctioned entity three transactions upstream. OCC Bulletin 2025-17 makes clear that regulators expect this level of granularity, especially when a bank is relying on a sub-custodian’s monitoring tools rather than its own.

OFAC and sanctions screening carries its own wrinkle. Traditional sanctions screening checks names and account numbers against the Specially Designated Nationals list. On-chain screening has to check wallet addresses, and the list of sanctioned addresses changes frequently as OFAC adds new designations tied to ransomware operators, sanctioned states, and darknet markets. A custody program needs:

  • Real-time or near-real-time screening of deposit and withdrawal addresses against current OFAC sanctioned-address lists.
  • A documented blocking procedure when a match occurs, including how frozen assets are held and reported.
  • Clear escalation paths so sanctions hits don’t sit in a queue while a customer’s assets remain accessible.

Recordkeeping for crypto custody needs to satisfy two audiences at once: bank examiners and tax authorities. Custody records should tie every wallet address to a customer identity, every transaction to a monitoring decision, and every SAR filing to the underlying evidence that triggered it. Tax-reporting obligations add another layer, since custodial banks may have information-reporting duties tied to customer holdings and transfers.

Pro Tip: Build your exam evidence file as you go, not after the examiner asks for it. Every sanctions screening hit, every SAR decision, every wallet-attribution judgment call should land in a searchable log the day it happens. Reconstructing that trail six months later, under exam pressure, is where compliance teams lose credibility fast.

Compliance teams looking to adapt an existing BSA/AML framework for on-chain flows can start from a structured digital asset AML compliance checklist rather than reinventing the monitoring logic from scratch.

How Do Banks Prove Control Over Crypto Assets in Custody?

Control is the concept examiners keep coming back to, because crypto custody doesn’t work like custody of a stock certificate or a bond. There’s no central registrar confirming ownership. Control means possessing, or provably directing, the cryptographic keys that authorize movement of assets on a blockchain. The interagency safekeeping statement treats key management as the central operational risk in the entire custody relationship, underscoring the need to meet regulatory requirements for mobile messaging security to prevent phishing and maintain operational controls.

Proving initial control starts at the moment assets transfer into custody. A bank needs a verifiable, timestamped ledger record showing the assets moved into wallets or key-management systems it controls, not merely wallets it has visibility into. Ongoing control means the bank can demonstrate, at any point, that it retains sole or shared authorization rights over those keys, and that no unauthorized party could move the assets without triggering a control alert.

Banks generally choose among a handful of architectures, each with different supervisory trade-offs:

  1. Hardware security modules (HSMs) offer strong, well-understood physical protection for private keys, but require rigorous physical security and disaster-recovery planning for the hardware itself.
  2. Multi-party computation (MPC) splits key material across multiple parties so no single point of compromise exposes the full key, which examiners tend to view favorably for reducing single-person insider risk.
  3. Multi-signature wallets require multiple independent approvals to authorize a transaction, giving clear audit trails but adding operational complexity to routine transfers.
  4. Cold storage keeps keys entirely offline, which minimizes hacking exposure but slows down transaction processing and requires careful procedures for the rare occasions keys need to come online.

Most banks entering custody end up running a hybrid: cold storage for the bulk of client assets, with a smaller hot or warm allocation using MPC or multi-sig for day-to-day liquidity needs. A closer look at how these custody architectures compare shows why hybrid setups dominate. Pure cold storage is safest but operationally rigid; pure hot-wallet setups are fast but carry unacceptable exposure for institutional-scale holdings.

Beyond the architecture itself, examiners expect a documented control environment: access controls that limit who can initiate key ceremonies, separation of duties so no single employee can both generate and deploy keys, formal change-control procedures for any modification to custody infrastructure, and an incident-response plan specific to key compromise scenarios, not a generic cybersecurity playbook repurposed for crypto.

Audit and reconciliation work sits on top of all this. Banks need on-chain reconciliation processes that match internal ledger records against actual blockchain state, daily at minimum for active accounts. Proof-of-control documentation, cryptographic attestations showing the bank can move assets on demand, and detailed system logs covering every key access event round out what an examiner will ask to see. The Federal Reserve’s July 2025 interagency statement names cryptographic key management as one of the two or three risk areas examiners will focus on most heavily during safekeeping reviews.

Managing Sub-Custodian and Third-Party Custody Risk

Very few banks build custody infrastructure entirely in-house. Most rely on a sub-custodian, a specialized crypto custody technology provider, for key management, wallet infrastructure, or blockchain connectivity. The OCC has confirmed this is permissible, but it comes with a hard rule: outsourcing the function never outsources the accountability. If the sub-custodian fails, the bank answers for it.

Due diligence on a sub-custodian needs to go deeper than a vendor questionnaire. Banks should require independent audits of the sub-custodian’s key-management controls, ideally SOC-type attestations or an equivalent, and should understand exactly which jurisdiction regulates that sub-custodian and how robust that oversight actually is. A sub-custodian regulated in a jurisdiction with weak enforcement creates a supervisory gap the bank inherits by proxy.

Contract terms matter as much as the diligence that precedes them. Effective sub-custodian agreements typically include:

  • For the benefit of (F/B/O) account titling that clearly identifies customer assets as distinct from the sub-custodian’s own balance sheet.
  • Explicit segregation requirements, both on-chain wallet segregation and internal ledger segregation.
  • Audit rights letting the bank inspect the sub-custodian’s controls on demand, not just annually.
  • Insolvency clauses specifying that customer assets are bankruptcy-remote from the sub-custodian’s estate.

Ongoing oversight can’t stop once the contract is signed. Service-level agreements need measurable uptime and response-time standards, periodic control testing beyond the initial audit, and, for higher-risk relationships, on-site review of the sub-custodian’s operations. Every one of these activities should generate documentation, since OCC Bulletin 2025-17 makes third-party oversight evidence a specific examiner focus area, not a general good-practice suggestion.

Cross-border sub-custody adds jurisdictional complexity that domestic arrangements don’t carry. A sub-custodian operating under a different country’s insolvency regime may not honor the same segregation protections a U.S. bank’s contract assumes, and conflict-of-law questions can leave customer assets exposed in ways that only surface during an actual failure.

Fiduciary Custody vs. Safekeeping: Why the Distinction Matters

Whether a bank’s custody arrangement counts as fiduciary or merely safekeeping determines which set of duties, and which set of legal exposures, applies. Fiduciary custody under 12 CFR 9 for national banks (or 12 CFR 150 for federal savings associations) triggers heightened duties: loyalty to the customer, prudent management, and specific recordkeeping obligations that go beyond simple asset-holding. Non-fiduciary safekeeping, by contrast, is closer to a safe-deposit-box relationship: the bank holds the asset but doesn’t exercise discretion over it.

Getting this characterization wrong in a customer agreement creates the single most damaging outcome a custody program can produce: a debtor-creditor relationship instead of a preserved ownership interest. If a bank’s contract language implies the customer’s crypto becomes a general liability owed by the bank rather than a specific asset held for the customer’s benefit, that crypto could get swept into the bank’s estate in an insolvency proceeding. The customer becomes an unsecured creditor standing in line with everyone else, instead of someone whose specific asset was segregated and protected.

NYDFS guidance updated in September 2025 draws this line sharply for New York-chartered and New York-serving institutions, requiring clear on-chain and ledger segregation and explicit disclosure of any sub-custody arrangements to preserve the customer’s equitable and beneficial interest in the asset.

A solid contract drafting checklist to avoid debtor-creditor characterization includes:

  • Explicit bailment or trust language stating the bank holds the asset on the customer’s behalf, not as bank property.
  • Clear F/B/O titling on any account or wallet holding customer crypto.
  • Disclosure of exactly which entity, bank or sub-custodian, holds the private keys at any given time.
  • Language specifying that customer assets are not available to satisfy the bank’s general creditors.

Pro Tip: Read your own custody agreement as if you were a bankruptcy judge looking for ambiguity. If a single clause could be read to mean the bank “owes” the customer crypto rather than “holds” it, rewrite that clause before you launch, not after a regulator or a litigator finds it first.

What Crypto Activities Can Banks Actually Offer Customers?

OCC interpretive letters and Corporate Decision 1366 have drawn a fairly specific map of what’s permitted alongside pure custody, and what still sits outside the guardrails.

On the permitted side, banks can offer staking-as-a-service when acting in a fiduciary capacity, meaning the bank stakes customer assets on their behalf under a documented fiduciary mandate rather than at its own discretion. Banks can also exercise governance and voting rights tied to customer holdings, again under fiduciary authority and with customer instruction where applicable. And banks may hold a limited principal amount of crypto-assets for genuinely operational purposes: covering network gas fees, running internal testing, or facilitating transaction processing, not building a trading position.

That last point draws the clearest line regulators have set. Holding crypto to keep the lights on operationally is fine. Holding crypto as a proprietary trading position funded by customer assets is not. The distinction the OCC keeps drawing is between operational necessity and speculative exposure using funds that belong to someone else.

Offering these ancillary services comes with its own disclosure burden:

  • Customers need clear documentation of exactly what staking or governance activity the bank will perform on their behalf.
  • Fee structures for staking rewards or governance participation need to be transparent, not buried in fine print.
  • Banks need internal controls distinguishing operational principal holdings from any activity that could be read as proprietary trading.

What Do Examiners Actually Look for in a Custody Exam?

With advance-notification requirements gone, the exam itself has become the primary checkpoint. That’s a meaningful shift in how banks should think about readiness: instead of clearing a hurdle once before launch, they need continuous documentation that would survive an examiner walking in unannounced.

Examiners typically request a specific set of artifacts:

  1. Board minutes showing formal approval of the custody program and evidence that directors understood the specific risks involved, not just a general endorsement of “entering crypto.”
  2. Written policies covering key management, third-party oversight, incident response, and customer disclosures.
  3. Independent audit reports, both internal audit findings and any third-party attestations of sub-custodian controls.
  4. Reconciliation logs showing on-chain asset positions matched against internal ledgers on a documented schedule.
  5. Incident history, including any key-management near-misses, sanctions screening hits, or vendor performance failures, along with how each was resolved.

Governance expectations run alongside the paperwork. Regulators want to see a designated custodial officer or equivalent function, staff with documented crypto-specific training, and a board that can articulate why the bank’s risk appetite supports this activity, not just that it approved a budget line.

Common exam deficiencies tend to cluster around a few recurring gaps: incomplete documentation of key-ceremony procedures, sub-custodian oversight evidence that’s thinner than the contract implies, and reconciliation processes that run less frequently than the bank’s own policy promises. Remediation usually means tightening the documentation cadence and closing the gap between what the policy says and what the operations team actually does day to day.

The practical implication of rescinded advance-notification is straightforward: readiness can’t be a one-time project completed before launch. It has to be a standing state the bank maintains, because the exam could happen at any point, without the lead time a filing requirement used to provide. Teams tracking regulatory change management practices for crypto programs are essentially building the muscle this new supervisory model demands.

Getting from “we have OCC authority” to “we’re live and exam-ready” involves work across legal, operations, and compliance simultaneously. A useful way to sequence it:

  1. Pre-launch legal review. Confirm the bank’s chartering authority covers the specific custody activities planned, secure board approval with documented risk discussion, build the full policy suite covering key management and customer disclosures, and complete due diligence on any sub-custodian before signing.
  2. Operational build-out. Select a key-management architecture appropriate to the bank’s expected volume and risk tolerance, run reconciliation processes in a test environment before going live, and finalize an incident-response plan specific to key compromise and vendor failure scenarios.
  3. Compliance program adaptation. Extend the existing BSA/AML program to cover on-chain transaction monitoring, stand up OFAC address screening with a documented blocking procedure, and prepare SAR templates specific to crypto typologies before the first suspicious activity arises, not after.
  4. Post-launch maintenance. Set an audit schedule, a monitoring cadence for both transaction activity and sub-custodian performance, and a governance update process so policies evolve as regulatory guidance does.

Pro Tip: Treat the pre-launch and post-launch phases as equally important. Banks that pour resources into launch readiness and let monitoring cadence slip six months in are exactly the ones examiners flag, because the exam tests today’s controls, not the day-one plan.

Teams building out reconciliation and financial-control processes for this launch sequence can work from a crypto financial controls checklist rather than drafting reconciliation cadence and documentation standards from a blank page.

Where DARE Fits Into Custody Governance Readiness

Every section above maps to a governance gap regulators are actively testing for: key management, third-party oversight, fiduciary characterization, and audit readiness. That’s the exact terrain the Digital Asset Readiness Evaluation (DARE) certification framework was built to cover.

DARE’s modular structure lines up with the control areas examiners request evidence for:

  • Governance and board oversight modules that mirror what the interagency safekeeping statement expects directors to understand.
  • Key-management and operational-control modules addressing the same custody architecture questions covered above.
  • Third-party and sub-custodian oversight modules that translate contractual due diligence into demonstrable, renewable credentials.
  • Audit-readiness modules designed to produce the documentation examiners actually ask for during a review.

For teams that want a deeper operational playbook beyond the certification itself, the institutional custody guide breaks down disclosure and control expectations from the customer side of the relationship.

A Compliance Leader’s Take on Custody Readiness

Most banks approach crypto custody as a technology decision: pick an architecture, sign a vendor, launch. That’s backward. Custody is a governance program first, and the technology choice is downstream of it.

The rescission of advance-notification requirements didn’t lower the bar. It removed the one moment where a regulator would tell you, in advance, whether your plan was good enough. Now the burden sits entirely on the bank to prove, continuously, that its controls hold up. Banks that treat this as a one-time compliance project rather than a standing operational discipline are the ones that will struggle when an examiner shows up unannounced.

Prioritize two things above everything else: key management architecture that survives a real incident, and contract language that survives a real insolvency. Everything else, from staking permissions to sanctions screening tooling, matters, but those two failures are the ones that end custody programs.

— Gregg

How DARE Helps Banks Turn Custody Controls Into Exam Evidence

Compared with building an internal audit framework from scratch, or hiring outside counsel to draft a bespoke governance program, DARE give bank legal, compliance, risk, and treasury teams a structured, renewable path to demonstrating readiness without starting from a blank page every time guidance changes.

Wush

The certification covers the same terrain examiners test: governance documentation, key-management controls, third-party oversight evidence, and audit-readiness modules, refreshed annually so the credential doesn’t go stale as OCC interpretive letters and interagency statements keep evolving. Teams get modular learning, structured assessments, and a verifiable credential that a bank can point to when an examiner asks who on staff actually understands the custody control environment. That’s a faster answer than assembling a policy binder under exam pressure.

If your team is preparing to launch or expand crypto custody services, review the DARE certification program details and see which modules align with your current governance gaps.

Sources

Get DARE certified

Validate your competency in enterprise digital asset governance with the DARE certification.

View certification
DARE - Digital Asset Readiness Evaluation logo

The global standard for evaluating and certifying enterprise digital asset readiness and governance.

PARTNERS

DARE is developed by Wush.co and co-issued with the Asia Blockchain Association


© 2026 DARE by Wush.co. All rights reserved.
Follow Us