Modernising Safeguards for Direct Safekeeping
Under the newly proposed framework, advisers taking direct custody of digital holdings would face rigorous operational requirements. Eligibility for direct safekeeping mandates quarterly reassessments, while underlying security systems must undergo reviews at least annually. To mitigate internal risk, token transfers would require authorization from at least two individuals, and each customer’s holdings must occupy distinct, segregated blockchain addresses.
Furthermore, investors would receive regular quarterly statements and sign agreements legally classifying the tokens as financial assets under applicable state law. Advisers opting for direct custody must also obtain an independent accountant’s internal control report within six months of implementation and annually thereafter, ensuring rigorous oversight of blockchain transactions and tokenized fund shares.
State Trust Companies and Regulatory Division
Beyond direct self-custody, the regulatory package allows state trust companies—institutions chartered by state banking regulators—to act as external custodians for advisory and fund holdings. These entities would remain subject to initial and ongoing annual checks of their authorisation and security policies, alongside reviews of audited financial statements.
The initiative reflects ongoing evolution in federal oversight. State supervision already addresses asset separation, such as New York’s Department of Financial Services guidance issued on Sept. 30, 2025, which enforces separate accounting for licensed virtual currency businesses. However, digital asset protections have previously triggered sharp divisions among SEC commissioners. While Commissioner Hester M. Peirce supported regulatory flexibility, Commissioner Caroline A. Crenshaw criticized aspects of the legal basis and investor safeguards.
Next Steps and Public Engagement
The proposed rule changes—which fall under the Investment Advisers Act of 1940 and the Investment Company Act of 1940—underwent White House review by the Office of Information and Regulatory Affairs in August ahead of the formal proposal. Public comments will remain open for 60 days following publication in the Federal Register, setting the stage for extensive industry debate over the future of digital asset safekeeping.

