Crypto safeguarding is not new – ask anyone who has worked with CASS

Crypto safeguarding (custody) often sounds technologically novel. Wallets, private keys, signing ceremonies, cold storage, MPC, smart contracts and blockchain records are specific to the sector. But the regulatory objective is familiar: customer assets must be protected.

Anyone who has worked with CASS, payment safeguarding or e-money safeguarding will recognise the FCA’s concerns.

Can the firm identify what belongs to customers? Are assets segregated? Are records accurate? Are reconciliations performed? Are shortfalls identified and resolved? Are third parties overseen? If the firm fails, can customer assets be returned promptly?

The technology may differ, but the principles underpinning cryptoasset regulation are familiar.

Crypto safeguarding requirements go beyond storage

A common misconception is that crypto safeguarding is mainly about secure storage. Security matters, but safeguarding is broader.

A regulated custodian needs to know which assets it holds, for whom, under what legal basis, in which wallets, subject to which controls, with which third parties, and what happens if something goes wrong. It needs records, reconciliations, governance, incident response, client disclosures, contractual clarity and operational resilience.

A cold wallet can be secure and still sit within a weak safeguarding framework if ownership records are poor, reconciliations are not performed, private key access is not governed, or third-party dependencies are not understood.

Lessons from CASS

The prospective CASS 17 rules in the FCA Handbook make the lessons from CASS particularly relevant to crypto firms under the new regulatory regime.

CASS history teaches several lessons that crypto firms should not ignore.

First, records matter. If a firm cannot distinguish one customer’s assets from another’s, or client assets from firm assets, a failure event becomes much harder to manage.

Second, reconciliations matter. They are not administrative housekeeping. They are a core control for identifying discrepancies before they cause customer harm.

Third, outsourcing does not remove responsibility. A firm may use a third-party custodian, wallet technology provider, cloud provider or group service company, but it remains responsible for its own regulatory obligations.

Fourth, resolution matters. Regulators care about what happens when a firm fails, not only what happens when it is operating normally.

Private key governance is board-level risk

Private key governance should not be left as a technical appendix. It should be part of the firm’s risk framework.

Senior management should understand how keys are generated, stored, accessed, backed up, rotated, revoked and recovered. They should understand who can initiate and approve transfers, how dual controls operate, what happens if a key person leaves, how emergency access works and how the firm prevents unauthorised movement of assets.

The board does not need to become a cryptography committee. But it does need assurance that the control environment is understood, documented, tested and monitored.

Third-party custody needs real oversight

Many firms will rely on third parties. That may be sensible, but it creates oversight obligations.

Due diligence should assess the provider’s regulatory status, financial soundness, security controls, insurance, key management, incident history, sub-outsourcing, geographic location, insolvency treatment, audit reports, contractual liability and exit arrangements. Ongoing monitoring should not end after onboarding.

The firm should also consider concentration risk. If one provider holds a large proportion of client assets, technology, or operational capabilities, what is the contingency plan?

Blockchain records are useful, but not enough

Blockchain records can enhance transparency and facilitate transaction tracing. They do not replace the firm’s own books and records.

The firm must maintain records that link on-chain assets to customer entitlements, legal ownership, account records and internal systems. It must also reconcile those records and ensure they can be understood by an administrator, auditor, regulator or third party in a stress event.

A public blockchain address is not a client asset record.

Practical safeguarding guidance for crypto firms

Crypto firms should build a safeguarding control map that covers:

  • client asset legal analysis;
  • wallet architecture;
  • key generation and access controls;
  • transaction approval workflow;
  • segregation model;
  • books and records;
  • reconciliations;
  • shortfall treatment;
  • third-party due diligence;
  • incident response;
  • wind-down and asset return; and
  • client disclosures.

That map should be tested against the applicable rules and guidance before authorisation. It should also be understandable to non-technical senior managers.

How C&G can help

C&G’s experience across regulated financial services, including client asset, safeguarding, governance and control frameworks, is directly relevant to crypto custody. The firms that prepare best for the new regime will not treat safeguarding as an IT control. They will treat it as a regulated operating model.

**Download our complimentary C&G Guide to FCA Cryptoasset Authorisation and Regulation** for a practical overview of safeguarding, custody and CASS read-across.