Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Crypto Custody Rule Readiness TemplateRegulatory Compliance
5 min readFor GRC Leaders

Crypto Custody Rule Readiness Template

The SEC has submitted a revised custody rule to the Office of Information and Regulatory Affairs for review, signaling a regulatory pivot on how investment advisers can hold crypto assets for clients. This marks a significant shift from the 2023 Safeguarding Advisory Client Assets proposal, which made compliance nearly impossible for most alternative assets, including crypto.

If you're an investment adviser or fund manager handling digital assets, you need a structured readiness assessment now. Waiting for the final rule text puts you behind. This template helps you inventory your current custody arrangements, identify gaps against likely modernized requirements, and prepare documentation that works regardless of how permissive or restrictive the final rule becomes.

Purpose of the Template

This readiness assessment template serves three purposes:

Gap identification. It maps your current custody infrastructure against probable requirements in the modernized rule, including qualified custodian relationships, asset segregation protocols, and verification procedures specific to crypto assets.

Stakeholder alignment. It creates a shared record between your compliance function, operations team, and external custodians about who holds what, under which terms, and with what verification cadence.

Documentation foundation. It establishes the baseline for your custody control narrative when auditors or examiners ask how you've adapted to the new rule. You'll have dated evidence of your readiness work, not a scramble after publication.

Prerequisites

Before you complete this template, gather:

  • Current custodial agreements for all client assets, including any third-party arrangements for crypto
  • Your firm's most recent Form ADV Part 2A, specifically Item 15 (Custody)
  • Documentation of any surprise examination or internal control reports under the current custody rule
  • A list of all digital asset types you hold or plan to hold (Bitcoin, Ethereum, tokenized securities, stablecoins, etc.)
  • Contact information for your current qualified custodian(s) and any specialized crypto custodians you're evaluating

You'll also need input from whoever manages your firm's wallet infrastructure, whether that's in-house IT, a third-party administrator, or a hybrid model.

The Template

Copy this into your working document and complete each section:


CRYPTO CUSTODY RULE READINESS ASSESSMENT
Prepared by: [Name, Title]
Date: [Date]
Review frequency: Quarterly until rule finalization, then annually

SECTION 1: CURRENT CUSTODY ARRANGEMENTS

For each asset type, document:

Asset Type Custodian Name Qualified Custodian? (Y/N) Custody Agreement Date Segregation Method Verification Frequency
[e.g., Bitcoin]
[e.g., Ethereum]
[e.g., Tokenized equity]

SECTION 2: INFRASTRUCTURE COMPATIBILITY

Answer for your current setup:

  • Do your custodians support independent verification of crypto holdings by a public accounting firm? [Y/N/Partial]
  • Can you demonstrate continuous chain-of-custody from client deposit through current holding? [Y/N]
  • Do you maintain offline records (beyond blockchain) proving client ownership? [Y/N]
  • If you use self-custody or proprietary wallets, do you have SOC 2 Type II reports covering key management? [Y/N/N/A]

SECTION 3: COMPLIANCE CONTROL GAPS

Based on the 2023 proposed rule (worst-case scenario) and likely modernization elements, rate each control:

Control Requirement Current State (Compliant / Partial / Missing) Gap Description Remediation Owner Target Date
Qualified custodian maintains possession
Written custody agreement in place
Surprise examination or SOC 1 Type II report obtained
Independent verification of crypto holdings
Client notification of custody arrangement
Segregation of client assets from firm assets

SECTION 4: VENDOR READINESS

For each custodian or service provider involved in crypto custody:

Custodian/Provider: [Name]
Last contacted about rule changes: [Date]
Their stated readiness for modernized rule: [Summary]
Outstanding questions for them:

Backup custodian identified? [Y/N]
If yes, name: [Name]

SECTION 5: CLIENT COMMUNICATION PLAN

  • How many client accounts currently hold crypto assets? [Number]
  • How many clients have requested crypto custody but you've declined under current rule? [Number]
  • Draft disclosure language for Form ADV Item 15 update: [Text]
  • Client notification timeline if custody arrangements must change: [Date/trigger]

SECTION 6: DECISION LOG

Document key decisions as you learn more:

Date Decision Rationale Approver

Customization Options

If you don't currently hold crypto: Focus on Section 2 (Infrastructure Compatibility) and Section 4 (Vendor Readiness). Treat this as a build plan rather than a gap assessment. Your "current state" column becomes "required state" and your target dates reflect when you'd need each component operational to accept crypto assets post-rule.

If you're a fund manager rather than an RIA: Expand Section 1 to include fund-level custody arrangements and add a row for each fund's specific custodian. Your Form ADV reference changes to the fund's custody documentation under the Investment Company Act.

If you use multiple custody models: Create separate assessment sheets for each model (e.g., one for qualified custodian relationships, one for self-custody under exemption). This prevents confusion when different asset types have different control requirements.

If you're evaluating new custodians: Add a scoring matrix in Section 4 that weights factors like regulatory examination history, insurance coverage for digital assets, disaster recovery testing results, and fee structure. Make the scoring criteria explicit so you can defend your selection to your Chief Compliance Officer or board.

Validation Steps

Complete these checks before you consider the assessment finished:

Cross-reference with your compliance calendar. Does your surprise examination schedule (if applicable) align with the custody verification frequency you've documented? If you're planning to rely on SOC reports instead, when do those reports expire?

Test your vendor contact list. Email each custodian contact in Section 4 with a specific question about the pending rule. If you don't get a response within five business days, you've identified a communication risk that needs a backup contact.

Review with your external auditor. If you're subject to annual financial statement audits, walk your auditor through Section 2 (Infrastructure Compatibility). They'll spot verification gaps you might miss, particularly around existence assertions for crypto holdings.

Validate your decision log with legal counsel. Any decision to change custody models, add new asset types, or modify client agreements should get a legal review before you execute. Use Section 6 as your running record of what counsel has blessed.

Schedule your next update. Put a recurring quarterly review on your calendar until the rule finalizes. After finalization, shift to annual reviews unless you add new digital asset types or custodians.

The difference between reactive compliance and strategic readiness is documentation. When the final rule publishes, you'll have a structured record of your preparation, not a blank page and a deadline.

Application Security Isn’t Optional Anymore.

You Might Also Like