"Bank-grade" is the most overused phrase in digital asset custody marketing. Every vendor with a security page claims it. Very few can point to the thing that actually makes custody bank-grade: a banking regulator that examines the business, a capital requirement that backs it, and an operating discipline that survives an audit.

This guide explains what the label means when it is real. We cover the licences that create bank-grade obligations, the key-management architecture banks actually run, the governance layer that matters more than the vault, and the Basel rules that quietly shape what any bank can touch. By the end you should be able to tell a chartered custodian from a startup with a nice security page in about ten minutes of checking.

One framing note before we start. Bank-grade custody is a subset of institutional crypto custody, not a synonym for it. Plenty of excellent institutional custodians are trust companies, not banks. The question this article answers is narrower: what changes when the entity holding your keys is a bank, supervised like a bank, with a bank's obligations?

Image: Taurus SA

What separates a bank from a custody startup

Three things, and none of them are technology.

Supervision. A bank is examined by a prudential regulator on a recurring cycle. In the United States that is the Office of the Comptroller of the Currency for national banks, or a state banking department. In Switzerland it is FINMA. Examiners show up, pull records, test controls, and can compel changes. A startup's SOC 2 report is a snapshot taken by an auditor the company hired. An examination is a recurring event run by someone the company cannot fire.

Capital. Banks must hold regulatory capital against their operations. If a custody operation loses money, absorbs a fraud, or faces a lawsuit, the capital cushion exists so clients are not the ones absorbing the hit. Custody startups carry insurance instead. Insurance is useful, but it is a contract with exclusions, not a balance sheet requirement a regulator enforces quarterly.

Resolution. When a bank fails, a legal regime decides what happens next, and custodied assets held in a fiduciary capacity sit outside the bank's estate. This is the same principle that matters for any qualified custodian: segregation is only as good as the law that enforces it in bankruptcy. Bank resolution law is old, tested, and specific. The bankruptcy treatment of assets at a failed tech-company custodian was, until recently, an open question that Celsius and FTX answered in the worst possible way.

If a vendor says "bank-grade" and cannot point to a banking supervisor, capital requirement, and resolution regime, the phrase means "we bought good hardware." That is not nothing. It is also not a bank.

The label attaches to a small set of licences, and it is worth knowing them by name.

OCC national bank and trust charters. The OCC confirmed in Interpretive Letter 1170 (July 2020) that national banks may provide crypto custody. Anchorage Digital converted to a national trust bank in January 2021 — the first crypto-native firm inside the federal banking perimeter. A national charter means OCC examination, capital planning, and the full weight of federal banking law.

FINMA banking licences. Switzerland granted banking and securities dealer licences to Sygnum and SEBA (now AMINA) in August 2019. A Swiss banking licence brings capital rules, audit obligations, and depositor protections, and Swiss law treats custodied crypto as segregated from the bank's estate in insolvency.

NYDFS trust charters. New York limited-purpose trust companies — Coinbase Custody Trust, Gemini Trust, Paxos Trust — sit under the New York Department of Financial Services. NYDFS is a banking regulator in every sense that matters: it examines, it fines, and its January 2023 custody guidance spelled out segregation, sub-custody, and disclosure expectations in detail.

European banking licences. Germany's BaFin has licensed crypto custody since 2020, and MiCA now provides an EU-wide framework. Several large banks — BNY, Société Générale through Forge, Deutsche Bank through its pending applications and partnerships — run digital asset custody inside existing banking groups.

Thomas Brunner, Sygnum's Head of Custody and Staking, seated in the bank's Zurich office

Image: Sygnum Bank — Thomas Brunner, Head of Custody & Staking

The names matter because the label travels with the licence, not the company. "Our custody partner is a bank" is checkable in a public register. Every claim in this category takes five minutes to verify, and we give you the exact steps in the checklist below.

Strip away the marketing and bank-grade key management is a short list of design decisions, applied without exceptions.

Cold storage as the default. Private keys are generated and stored in hardware security modules or air-gapped signing devices that never touch the internet. Warm and hot tiers exist only for operational float, sized as a small percentage of assets, with automatic sweep rules back to cold. When a bank platform creates a wallet, cold is the default path, not the premium tier.

Wallet creation form in Taurus-PROTECT with blockchain, wallet name "Cold storage", single-owner toggle, and client ID fields

Image: Taurus SA — Taurus-PROTECT wallet creation

Hardware-enforced policy. The signing device itself enforces the rules — which addresses can receive, which amounts need extra approvals, which operators can even propose a transaction. Software policy can be changed by whoever administers the software. Hardware-enforced policy requires physical ceremonies to change, which is the point.

Key sharding and dual control. No single person can ever move assets. Keys are split — through Shamir secret sharing, multi-signature schemes, or multi-party computation custody — so that signing requires a quorum of people, devices, and often locations. Dual control is a banking concept older than computers; crypto custody just gives it new hardware.

Deterministic recovery. Backups of key material exist in geographically separated vaults, sealed, with documented recovery ceremonies that are actually rehearsed. Examiners ask for evidence of the rehearsal, not the policy document.

None of this is exotic anymore. The differentiator is discipline: banks run these controls under an examiner's eye, with consequences for drift.

Governance: the signature policy is the product

Here is the part most buyers under-weight. The vault is a solved problem. The governance layer — who can move what, with whose approval, under which conditions — is where custody actually succeeds or fails, and it is where bank-grade platforms visibly differ from retail tools.

A bank-grade platform expresses governance as explicit, auditable rules. Four-eyes approval on every transaction. Separate teams for initiation and release. Velocity limits per wallet, per day, per counterparty. Allowlisted withdrawal addresses with time-locked additions. Role separation between administrators who configure the system and operators who use it.

Signature requirements screen in Taurus-PROTECT showing a manual rule requiring one signature from Team 1, with policy

Image: Taurus SA — signature policy configuration

When you evaluate a platform, ask to see the policy editor, not the vault photos. You are looking for three things. First, rules that bind administrators too — a platform where an admin can quietly bypass the quorum is a platform with one key. Second, an immutable audit trail: every proposal, approval, rejection, and configuration change logged where nobody can edit the log. Third, policy expressiveness that matches your operations — if your fund requires compliance sign-off on transfers above a threshold, the platform should encode that, not your team's memory.

Business hours and validation settings in Taurus-PROTECT restricting transaction time windows by day of week with a two-day

Image: Taurus SA — transaction time-window policy

The uncomfortable truth: most crypto losses at institutions are not vault failures. They are governance failures — a compromised laptop with too much authority, a process that existed on paper but not in the software, an approval flow that one busy person could satisfy alone. Banks are not immune to bad process, but examiners are very good at finding approval flows with one human in them.

More in Guides

The Basel rules that shape what banks can hold

If you want to predict how a bank will behave as a custodian, read its capital rules. The Basel Committee's cryptoasset standard, finalized in December 2022, divides crypto into two groups. Group 1 covers tokenized traditional assets and qualifying stablecoins, treated close to their underlying exposures. Group 2 covers everything else — including bitcoin and ether — with punitive capital treatment up to a 1,250% risk weight and a hard cap: Group 2 exposures may not exceed 2% of a bank's Tier 1 capital.

Here is why that matters less than the headline suggests: custody, done properly, is not an exposure. Assets held in a fiduciary capacity for clients sit off the bank's balance sheet, so the punitive weights largely do not apply to pure custody. That is precisely why custody has become the beachhead product for banks entering digital assets. They can custody bitcoin without holding capital against its price; they mostly cannot warehouse it on their own books.

For a client, two practical consequences follow. First, banks have a structural reason to keep custody clean, segregated, and off-balance-sheet — their capital treatment depends on it, which aligns their incentives with yours. Second, if a "bank-grade" provider is commingling client assets in a way that would put them on the balance sheet, it is not just sloppy; it is expensive under Basel, which is a strong signal that no examiner has looked closely. Segregation you can verify beats any adjective in a sales deck.

Most banks do not build custody technology from scratch. They license the key-management and governance layer from a specialist and wrap it in their own regulated operations. The clearest public example: Deutsche Bank announced in September 2023 that it would build its digital asset custody service on Taurus, the Swiss provider whose $65 million Series B it had co-led earlier that year. Sygnum runs its own stack and also licenses banking-grade custody software to other institutions. BNY's digital asset platform combines its own infrastructure with specialist components.

Taurus 360 client view listing bitcoin, dogecoin, ethereum, and solana balances with total value and allocation percentages

Image: Taurus SA — 360 client view

This layering matters when you diligence a provider. "Bank-grade technology" can mean the software a bank licenses — a true statement about Taurus or similar platforms — while the entity actually holding your assets is not a bank at all. Always separate the two questions. Who wrote the software? And who is the legal custodian with the licence, the capital, and the examiner? The second question is the one that protects you in a failure.

A verification checklist

You can verify a bank-grade claim in one sitting. Work through these steps in order.

  1. Name the legal entity. Get the exact legal name of the entity that will hold your assets from the draft agreement — not the brand name on the website. Groups often have a dozen entities; only one signs your custody agreement.
  2. Find the licence. Search the regulator's public register: the OCC's charter records, FINMA's authorized institutions list, the NYDFS virtual currency licensing page, or BaFin's company database. The entity from step 1 must appear, with a licence type that includes custody or fiduciary powers.
  3. Confirm the examiner. Ask when the entity was last examined and by whom. A bank will answer the "who" without hesitation. If the answer is only "we have a SOC 2," you have left the banking perimeter.
  4. Read the segregation language. The custody agreement should state that assets are held in a fiduciary or custodial capacity, segregated from the custodian's own assets, and identifiable on-chain or in records as yours. Vague "we take security seriously" language is a red flag; estate-separation language is the green one.
  5. Test the governance claims. Ask for a demo of the policy engine. Set up a rule — a two-of-three approval with an allowlisted address — and try to break it with an admin account. Serious platforms let you try.
  6. Check the sub-custody chain. Some "bank" offerings sub-custody to a third party. That can be fine, but then the third party's licence is the one that matters, and steps 1 through 5 apply to it instead.

"We are a corporate treasury holding bitcoin, and our board requires a regulated counterparty." A chartered bank or trust custodian is the straightforward answer, and the board deck writes itself: named regulator, examination cycle, estate separation in law. Expect to pay more in fees than at a pure technology custodian and consider it the cost of the audit committee sleeping.

"We are a fund advised under the Advisers Act." Your constraint is the custody rule, not the bank label. You need a qualified custodian, and banks are one of the four categories that qualify — but so are certain trust companies. Read our full guide to qualified custodian status before assuming the bank label is required; what you must verify is the fiduciary capacity, not the word "bank."

"We are a fintech that needs custody infrastructure inside our own product." You are probably buying the technology layer, not the fiduciary. Platforms like the one Deutsche Bank licenses are sold to non-banks too. Be precise in your own marketing about which you bought — regulators have started reading fintech custody pages closely, and "bank-grade" claims without a bank behind them are becoming enforcement bait.

Treating the label as transitive. A fund does not become bank-grade by using a bank, and a wallet app does not become bank-grade by licensing bank software. The properties attach to the chartered entity and stop there.

Confusing insurance with capital. A $250 million crime policy shared across all clients of a custodian can be a fraction of one large client's holdings. Bank capital is not shared out of a fixed pool in the same way. Read the policy limits and the per-event exclusions before you count insurance as protection.

Ignoring the withdrawal path. Bank-grade security on deposits means little if withdrawal governance is weak. Most thefts exit through the front door — an approved-looking withdrawal to an attacker's address. Allowlists, time locks, and out-of-band confirmation on new addresses are the controls that stop them.

Assuming banks custody everything. Basel's Group 2 rules and internal risk appetite mean most bank custodians support a short asset list — often just bitcoin, ether, and tokenized traditional assets. If you hold long-tail tokens, the bank-grade universe shrinks fast, and you will be evaluating trust companies and specialists instead.

Frequently asked questions

Is a bank always safer than a trust company for crypto custody?

Not automatically. A well-run NYDFS trust with strong segregation can be safer in practice than a distracted bank running custody as a side project. The bank brings capital and prudential examination; the trust brings focus. Verify the controls of the actual entity rather than ranking licence types in the abstract.

Can a US national bank hold crypto for retail customers?

The OCC's interpretive letters permit national banks to provide crypto custody as a fiduciary service, and subsequent guidance requires banks to notify supervisors before starting. In practice, chartered custody today serves institutions and high-net-worth clients; retail crypto at scale still lives at exchanges and brokers.

What happens to custodied crypto if the bank fails?

Assets held in a fiduciary or custodial capacity are not property of the bank's estate. In a resolution, they are returned to clients or transferred to a successor custodian rather than being distributed to the bank's creditors. This is the sharpest legal difference from lending platforms, where courts treated deposited crypto as estate property.

Does "bank-grade encryption" mean a company is bank-grade?

No. Bank-grade encryption usually means AES-256 or similar — the same encryption in every modern phone. It describes an algorithm, not supervision, capital, or fiduciary duty. Treat the phrase as decoration unless a charter sits behind it.

Do bank custodians support staking or DeFi?

A few support staking on major proof-of-stake assets under conservative conditions, because regulators have pressed for clarity on slashing and rehypothecation risks. Direct DeFi interaction from bank custody remains rare; Basel treatment and operational risk keep most banks out. Specialists and trust companies go further down the risk curve.

Sources

  • Basel Committee on Banking Supervision, "Prudential treatment of cryptoasset exposures" — December 16, 2022.
  • New York Department of Financial Services, "Guidance on Custody and Disclosure Practices" — January 23, 2023.
  • Deutsche Bank press release, "Deutsche Bank partners with Taurus to launch digital asset custody" — September 14, 2023.