Cryptoasset custody will become a fully regulated FCA activity under the UK’s new cryptoasset regime. Firms that safeguard qualifying cryptoassets or relevant specified investment cryptoassets for clients will require the appropriate FCA permission and must comply with detailed requirements covering client asset protection, trust arrangements, private key security, reconciliations, third-party custodians, governance and prudential resources.
The FCA published its final custody rules in June 2026. These rules will apply to firms authorised to carry on regulated cryptoasset activities when the new regime commences on 25 October 2027. The FCA authorisation gateway opens on 30 September 2026, with the main application period closing on 28 February 2027.
For existing crypto custodians, exchanges, wallet providers and platforms, the change is substantial. Current MLR registration focuses primarily on anti-money laundering controls, whereas full FCA authorisation requires a broader regulatory framework and a specific CASS 17 client-asset regime designed to protect ownership of customer cryptoassets if a custodian fails.
FCA crypto custody requirements at a glance
| Requirement | FCA position |
|---|---|
| Regulated activity | Safeguarding qualifying cryptoassets and relevant specified investment cryptoassets |
| FCA authorisation | Required under the new FSMA cryptoasset regime |
| Main application window | 30 September 2026 to 28 February 2027 |
| New regime commences | Expected 25 October 2027 |
| Client asset rules | CASS 17 |
| Client asset ownership | Client cryptoassets generally safeguarded on trust |
| Minimum capital | £150,000 permanent minimum requirement |
| Activity-based capital | K-RCS equal to 0.04% of average relevant cryptoassets safeguarded |
| Reconciliations | Required at least once each business day |
| Private keys | Detailed means-of-access, security and control requirements |
| Third-party custodians | Subject to regulatory, due diligence, contractual and governance requirements |
The £150,000 figure is only the permanent minimum requirement. A custodian’s actual own funds requirement may be higher once the fixed overheads requirement, K-factors and overall risk assessment are taken into account. The full prudential framework is set out in our FCA crypto prudential requirements guide.
What counts as regulated cryptoasset custody?
The regulated activity applies where a firm safeguards qualifying cryptoassets or relevant specified investment cryptoassets for another person and has the necessary degree of control over those assets or the means of access to them.
In practical terms, this can include a firm holding private keys, controlling wallets, operating custodial arrangements or otherwise having the ability to bring about a transfer of the client’s cryptoassets. The legal analysis is not limited to whether the firm describes itself as a custodian or wallet provider.
The position can also become more complex where control is distributed. Multi-party computation, sharded private keys, back-up keys and arrangements involving several custodians can still create regulated custody where one or more firms have the degree of control specified by the legislation.
By contrast, a genuinely non-custodial wallet where the customer alone controls the private keys and the provider has no means of transferring the assets may fall outside the custody activity. The exact technical architecture must therefore be analysed rather than relying on the commercial description of the product.
Exchanges and trading platforms may also need custody permission
Cryptoasset custody is rarely a standalone issue.
An exchange or trading platform may hold customer cryptoassets while facilitating transactions, meaning it can require both the relevant trading or intermediary permission and the safeguarding permission. A staking provider may safeguard the assets being staked, and issuers of qualifying stablecoins face separate backing and redemption requirements, while a lending or borrowing platform may hold cryptoassets as collateral.
The FCA’s CASS 17 framework is designed to apply where custody sits alongside these other regulated services. Firms should therefore map every point in the customer journey where they control or safeguard cryptoassets and determine whether custody permission arises in addition to the firm’s other activities.
A platform that outsources the technical holding of assets to another custodian should not assume that it is automatically outside the custody perimeter. The contractual relationship, control structure and responsibility owed to the customer all remain relevant.
The complete permission analysis should therefore be carried out before the authorisation application is prepared.
CASS 17 introduces a dedicated cryptoasset safeguarding regime
CASS 17 is the FCA’s new client-asset framework for safeguarding cryptoassets.
The rules are intended to protect clients’ ownership rights and reduce the risk that customer assets become mixed with the custodian’s own property or are unavailable if the firm fails. This represents a significant move towards a formal client-assets regime for regulated cryptoasset custody.
Firms will need to maintain detailed records showing which cryptoassets belong to which clients, how they are held and which trust arrangements apply. They must also maintain appropriate controls over wallet structures, means of access and any third parties involved in safeguarding.
For applicants, CASS 17 cannot be treated as a policy-writing exercise. The regulatory framework must be reflected in the technology, wallet architecture, legal terms, operational procedures and governance of the custody service.
A firm whose current custody arrangements were designed solely around operational efficiency may need material changes before they satisfy the FCA’s client-asset requirements.
Client cryptoassets must generally be held on trust
The FCA’s final rules require firms subject to the cryptoasset safeguarding activity to safeguard client cryptoassets on trust, subject to specified exceptions.
This is a non-statutory trust arrangement rather than the statutory trust used for UK qualifying stablecoin backing assets. The objective is nevertheless similar: client ownership should be protected and customer cryptoassets should remain separately identifiable from assets belonging to the firm.
The FCA permits flexibility in how firms implement the trust across wallet structures. A firm can operate separate trusts through different virtual addresses or combine client cryptoassets held at several addresses within the same trust, provided the arrangements satisfy the CASS 17 requirements.
The same virtual address cannot simply be allocated across different trusts where this would undermine the required separation. Firms also need clear records showing which clients are beneficiaries and which cryptoasset classes are held under each trust.
The legal trust documentation and technical wallet architecture therefore need to work together. A trust described correctly in legal documents is of little value if the firm’s operational systems cannot identify the corresponding client assets accurately.
Omnibus wallets can still be used
The FCA has not required every customer to have an individually segregated blockchain address.
Omnibus structures can continue to be used where the firm can maintain the necessary trust, ownership and record-keeping protections. The critical requirement is that client cryptoassets remain identifiable and are not improperly co-mingled with the custodian’s own assets or assets held under incompatible arrangements.
This provides firms with some operational flexibility, particularly where blockchain transaction costs or technical architecture make individual addresses inefficient. However, the internal ledger and reconciliation framework must be strong enough to establish each client’s entitlement accurately.
Where a firm uses omnibus wallets, its records become especially important. The blockchain may show only the aggregate assets held at an address, while the custodian’s internal systems must identify the individual client ownership positions behind that total.
The FCA therefore requires firms to maintain detailed internal records and perform regular reconciliations rather than relying solely on blockchain data.
Daily cryptoasset reconciliations
CASS 17 requires firms to calculate and reconcile safeguarded client cryptoassets at least once each business day.
The firm must calculate the relevant cryptoasset requirement using its own internal records of client instructions, transactions and services. It must then establish the cryptoasset resource available within the relevant trust and compare the two positions.
This distinction is important because the firm cannot simply use an external blockchain balance as both the starting point and the confirmation of what it should hold. The internal entitlement records must independently establish what clients are owed.
Where a reconciliation identifies a discrepancy, the firm must investigate the reason and take appropriate action. Shortfalls and excesses are subject to specific CASS 17 rules, and the firm must maintain records showing when the reconciliation was completed, what discrepancies were identified and how they were addressed.
For an applicant, the reconciliation methodology should therefore be fully designed and testable before authorisation. A spreadsheet or systems process that cannot reliably map internal customer entitlements to on-chain or third-party custody positions will create a material regulatory weakness.
Private key and means-of-access security
The custody regime places significant emphasis on how firms control the means of accessing client cryptoassets.
Traditional custody risk often centres on physical possession or account control. Crypto custody introduces additional technical risks around private keys, key shards, multi-signature arrangements, multi-party computation, recovery processes and cyber security.
Firms need robust policies and controls covering the creation, storage, use, recovery and destruction of means of access. Access rights should be restricted appropriately, and the firm must be able to demonstrate how control operates where private keys or shards are distributed between several people or organisations.
The FCA also requires appropriate records explaining the means by which the firm exercises control. These records need to remain accurate and, where applicable, be reviewed at least once each business day.
For custody applicants, technical security will therefore be examined as part of the regulatory operating model rather than treated as an IT matter sitting outside compliance.
What happens if a custodian uses a third party?
A regulated custodian may appoint another person to safeguard client cryptoassets, but the FCA imposes detailed conditions on these arrangements.
The third party must operate in a jurisdiction with appropriate mandatory regulation and supervision of cryptoasset safeguarding. The appointing firm must undertake due diligence and conclude that the arrangement will not increase the risk of loss or diminution of client cryptoassets.
The due diligence should consider the third party’s regulatory permissions, custody arrangements, financial resources, creditworthiness, capacity, expertise, market reputation, security standards and the legal framework of the jurisdiction in which it operates. The FCA requires periodic review at least annually.
The appointment must also be governed by an appropriate written agreement. This includes requirements around the services provided, treatment of client assets, further delegation, liability and recognition of the trust structure.
Outsourcing therefore does not outsource accountability. The FCA-authorised firm remains responsible for ensuring that its client cryptoassets are protected throughout the custody chain.
Sub-custody and custody chains
Crypto custody frequently involves several providers.
A UK platform may appoint a specialist institutional custodian, which may itself use another entity for certain assets, jurisdictions or key-management functions. The FCA permits these structures subject to conditions, but each link in the chain increases the importance of regulatory due diligence and oversight.
Further appointments generally require consent and must provide equivalent protections. The authorised firm remains responsible for satisfying itself that the broader chain does not increase the risk of loss or weaken client ownership rights.
This is particularly important where overseas providers are used. Insolvency law, trust recognition and custody regulation differ between jurisdictions, and the UK firm cannot assume that a foreign provider offers equivalent protection simply because it is a well-known crypto institution.
International custody structures should therefore be mapped in detail as part of the application.
FCA capital requirement for crypto custody
The permanent minimum capital requirement for a firm with permission to safeguard cryptoassets is £150,000.
However, this is only one component of the wider prudential framework. The firm must calculate its overall own funds requirement under COREPRU and CRYPTOPRU, taking into account the permanent minimum requirement, the fixed overheads requirement and applicable K-factor requirements.
For custody businesses, the K-RCS requirement is particularly important. It is calculated at 0.04% of the average relevant cryptoassets safeguarded, so capital can increase as the value of assets under custody grows.
A custodian therefore cannot assume that £150,000 will remain sufficient once it scales. The prudential model must reflect forecast assets under custody, operating expenditure and the wider risks of the business.
The FCA also requires an overall risk assessment that considers whether additional own funds and liquid assets are needed beyond the formulaic minimums. The application should therefore model financial resources through the forecast period rather than focusing only on the minimum capital required on day one.
Custody firms need sufficient liquidity and wind-down resources
Capital and liquidity serve different purposes.
Own funds provide loss-absorbing capacity, while liquidity ensures that the firm has resources available to meet obligations and manage stress or wind-down. Under the new framework, cryptoasset firms must maintain appropriate liquid assets and assess the resources needed to operate and, if necessary, exit the market without causing material harm.
For custodians, wind-down planning is especially important because customer assets must remain identifiable and capable of being returned even if the business itself is no longer viable.
The wind-down plan should consider technology access, key personnel, third-party custodians, blockchain fees, insolvency arrangements, client communications and the cost of transferring or returning assets.
A custody firm should therefore be able to demonstrate not only that client assets are protected legally, but that the business could actually return those assets operationally during a failure scenario.
Governance and Senior Managers responsibilities
Crypto custody is a high-trust activity and the FCA expects clear senior management accountability.
The Senior Managers and Certification Regime will apply to authorised cryptoasset firms. Responsibility for CASS, client assets, private key security, operational resilience and related controls should therefore be allocated clearly within the governance framework.
The board should receive meaningful information about safeguarded assets, reconciliation discrepancies, shortfalls, security incidents, third-party custody arrangements and material operational risks.
Technical custody expertise is also important. A board that relies entirely on external technology providers without sufficient internal understanding may struggle to demonstrate effective oversight.
The FCA application should therefore explain how regulatory, operational and technical expertise come together within the management structure.
Consumer Duty and customer disclosures
Custody firms serving retail clients must consider Consumer Duty alongside the detailed CASS 17 requirements.
Customers need to understand how their assets are held, whether third-party custodians are used, what happens in insolvency and whether any circumstances can cause assets to fall outside normal trust protections.
Where the firm uses omnibus arrangements, offshore custodians or other complex structures, disclosures should be clear enough for customers to understand the material consequences without requiring technical or legal expertise.
The firm should also consider how customers access and withdraw their assets. Unreasonable friction, unexplained delays or inadequate support can create poor outcomes even where the underlying assets remain safely held.
Consumer Duty therefore sits alongside custody security rather than being replaced by it.
Will crypto custodians need independent audits?
The FCA has confirmed its policy intention that firms subject to the cryptoasset client-asset regime should be subject to appropriate audit requirements.
The detailed client cryptoasset audit requirements are being finalised through the FCA’s wider work on audit requirements for cryptoasset firms. Firms should therefore expect independent assurance over compliance with the custody and client-asset regime to form part of the mature regulatory framework.
Even before final audit mechanics are settled, applicants should design their systems so that custody records, reconciliations, wallet controls and trust arrangements can be independently tested.
A control that cannot be evidenced or reproduced will be difficult to audit effectively.
Audit readiness should therefore be built into the custody framework rather than added after authorisation.
What should a crypto custody application include?
The application must explain the complete custody model.
This includes which cryptoassets will be supported, who the customers are, how wallets are structured, how private keys or other means of access are controlled, which third parties are involved and how assets move into and out of custody.
The firm should provide a detailed CASS 17 framework covering trust arrangements, record keeping, reconciliations, discrepancies, shortfalls, private key security and third-party appointments.
The prudential submission should include capital calculations, financial forecasts, liquidity planning and an overall risk assessment aligned with forecast assets under custody.
The wider authorisation package should also cover governance, Senior Managers responsibilities, financial crime, Consumer Duty, operational resilience, outsourcing, complaints, regulatory reporting, business continuity and wind-down.
The FCA should be able to understand how the custody service works operationally and how client assets remain protected through both normal operations and a firm failure.
What should existing custodians do now?
Existing MLR-registered custodians should begin by comparing their current arrangements against CASS 17 and the wider FSMA framework.
The gap analysis should examine legal ownership arrangements, wallet structures, internal records, daily reconciliations, key management, third-party custodians, governance and prudential resources.
Firms should then identify where operational changes are required. Some existing custody models may need changes to legal terms, wallet architecture or third-party contracts rather than merely new policies.
The application period opens on 30 September 2026. Existing firms that want to continue regulated custody after the new regime commences should therefore complete the substantive design work well before submission.
The transition from MLR registration to FSMA authorisation is addressed in more detail in our guide, From MLR Registration to FCA Cryptoasset Authorisation: What Existing Crypto Firms Must Do.
How Regulatory Counsel can help
Regulatory Counsel supports crypto custodians, exchanges, wallet providers and other digital-asset businesses through FCA authorisation and the implementation of the new custody regime.
We assess whether the proposed model falls within the regulated safeguarding activity and identify any additional permissions required for trading, arranging, staking, lending or other services.
Our work can include the FCA application, regulatory business plan, CASS 17 framework, trust and custody operating model, prudential calculations, financial forecasts, governance, financial crime, Consumer Duty, operational resilience, outsourcing and wind-down planning.
For existing custodians, we can carry out a gap assessment between current MLR arrangements and the future FSMA and CASS 17 requirements, then support remediation before the application is submitted.
A custody application is strongest where the legal, technical, operational and regulatory architecture have been designed together. Regulatory Counsel can manage that regulatory workstream through application preparation, FCA questions and determination.
Contact Regulatory Counsel to discuss FCA crypto custody authorisation or readiness for CASS 17.
Frequently Asked Questions
Yes. Under the new regime, firms carrying on the regulated activity of safeguarding qualifying cryptoassets or relevant specified investment cryptoassets will require FCA authorisation. Existing MLR registration will not automatically convert into custody permission under FSMA.
The permanent minimum capital requirement is £150,000. The actual own funds requirement may be higher because firms must also consider the fixed overheads requirement, the K-RCS requirement and the outcome of their overall risk assessment.
K-RCS is the activity-based capital requirement linked to relevant cryptoassets safeguarded. It is calculated at 0.04% of the firm’s average relevant cryptoassets safeguarded, subject to the detailed CRYPTOPRU methodology.
Not necessarily. The FCA permits appropriate omnibus arrangements, provided client cryptoassets remain separately identifiable and the firm’s trust, record-keeping and reconciliation controls satisfy CASS 17.
Potentially, but detailed conditions apply. The UK firm must assess the regulatory jurisdiction, permissions, financial and operational resilience, security, client-asset protections and other relevant risks of the third party. The appointment remains subject to FCA requirements and ongoing oversight.