For most of the last decade, a bank that wanted to hold digital assets for clients faced a wall of ambiguity: unclear legal permission, punitive accounting, and examiners with no playbook. That wall has been dismantled piece by piece. The Office of the Comptroller of the Currency confirmed in 2020 that national banks may provide crypto custody, the SEC's balance-sheet-crushing accounting guidance was rescinded in January 2025, and the OCC removed its extra approval hurdle in March 2025. The question for a bank board is no longer whether crypto custody is permitted. It is how to enter: build the capability, license the technology, or ride on a sub-custodian.

This guide walks through the regulatory sequence that opened the door, the three entry models and their trade-offs, the technology decisions that follow, and the mistakes banks make in their first year of digital asset custody.

Image: Zodia Custody — the bank-backed custodian's authorization app; Zodia was founded by Standard Chartered, one of the clearest examples of a global bank entering crypto custody through a dedicated subsidiary.

The regulatory sequence that opened the door

Three dates matter more than the rest.

July 2020 — permission. OCC Interpretive Letter 1170 concluded that providing cryptocurrency custody services is a modern form of a traditional banking activity, permissible for national banks and federal savings associations. State trust charters in New York, Wyoming, and South Dakota had reached similar conclusions earlier, which is why so many crypto custodians are structured as state trust companies — a landscape we map in our guide to qualified custodians for digital assets.

January 2025 — accounting. The SEC's Staff Accounting Bulletin 121, issued in 2022, had required entities safeguarding crypto to record the assets on their own balance sheets as both an asset and a liability. For a bank, that treatment triggered capital charges that made custody uneconomical at any realistic fee, and it was the single biggest practical blocker for the large trust banks. SAB 122, issued January 23, 2025, rescinded it. Custodied crypto returned to where custodied securities have always lived: off the custodian's balance sheet, with disclosure.

March 2025 — process. OCC Interpretive Letter 1183 reaffirmed that crypto custody and related activities are permissible and removed the requirement, introduced in 2021, that banks obtain supervisory non-objection before starting. Crypto custody became an ordinary product decision, subject to ordinary risk management and examination.

Layered on top is the Basel Committee's prudential standard on cryptoasset exposures, finalized in December 2022. It matters less than banks fear for custody specifically: assets held in properly segregated custody are the client's, not the bank's exposure. It bites when a bank holds crypto on its own balance sheet, where unbacked cryptoassets carry a 1,250% risk weight.

The practical consequence of the sequence: what was legally brave in 2021 is procedurally normal in 2026. The differentiator has shifted from regulatory access to operational competence.

Every bank entering digital asset custody chooses among the same three structures, whether it names them or not.

Build. The bank develops or assembles its own custody stack — key generation, storage, policy engine, client interface — and runs it under its existing charter. Maximum control, maximum time. Realistic programs take 18 to 36 months to production, and the scarce ingredient is not software but people who have operated digital asset key ceremonies under audit.

License the technology. The bank runs custody on a vendor platform — Taurus, Fireblocks, Metaco-style infrastructure — while keeping the client relationship, the regulatory obligation, and usually the keys. This is the dominant European pattern: the technology is bought, the accountability is not. Time to production drops to months.

Sub-custody. The bank contracts a specialist custodian — Zodia, BitGo, Coinbase Custody, Anchorage — to hold the assets, and offers the service to clients under its own brand. Fastest to market and thinnest margin, with the bank's role closer to distribution than custody. The client-facing bank remains responsible for due diligence on the sub-custodian, exactly as in traditional global custody networks.

Zodia Custody app showing pending, confirmation, and approval stages for custody instructions

Image: Zodia Custody — instruction states move through pending, confirmation, and approval; sub-custody gives a bank this operational machinery without building it.

Build vs license vs sub-custody, side by side

Because no single public comparison lays the three bank entry models side by side on the factors that decide board approvals, we compiled one from regulatory texts, vendor documentation, and the deployment patterns visible across announced bank programs.

FactorBuild in-houseLicense technologySub-custody
Time to production18–36 months4–12 months2–6 months
Key controlBank holds keysUsually bank holds keys on vendor stackSub-custodian holds keys
Regulatory postureFull custody obligationsFull custody obligationsOversight of a service provider
Margin retainedHighestHigh, minus platform feesLowest
Fixed cost and staffingHighest; ceremony-experienced staff requiredModerateLowest
Concentration riskInternal operational riskVendor dependencyCounterparty dependency
Typical adopterGlobal trust banksEuropean private and universal banksRegional banks, first offerings

The honest reading: sub-custody is how most banks should start, licensing is how most banks should scale, and building is justified only where custody is a strategic business line rather than a client-retention feature.

Whichever model a bank picks, the same technical architecture questions surface, because clients and examiners will ask them.

Key generation and storage. Institutional platforms today split between hardware security modules in certified facilities and multi-party computation, which splits key material into shares so no complete key ever exists in one place. The trade-offs are covered in depth in our guide to MPC custody; most bank deployments now use MPC for operational wallets and deep cold storage for reserves.

Policy and governance. The control examiners scrutinize hardest is not cryptography but authorization: who can instruct a withdrawal, under what quorum, with what velocity limits. Bank-grade platforms externalize this as configurable signature policy.

Taurus interface for configuring signature requirements with manual rules, policy templates, and team quorum settings

Image: Taurus — configuring signature requirements by team and quorum; Taurus supplies custody technology to several European banks under the licensing model.

Approval workflow. Day-to-day operation is a queue of transfer requests moving through maker-checker stages, each cryptographically signed by named individuals on registered devices. This is where digital asset custody most resembles existing payment operations, and where existing bank control culture transfers directly.

Fireblocks mobile app cards for approving or rejecting a transfer and a new admin user request

Image: Fireblocks — approve-or-reject cards for a transfer and an admin change; maker-checker on registered devices is the operational heart of bank crypto custody.

Segregation and proof. On-chain segregation — per-client wallets rather than omnibus pools — is increasingly the institutional default because it makes client-asset verification a matter of public record rather than attestation. Banks with omnibus models should expect the question in every RFP, and should have a written answer for how client-level records reconcile to pooled on-chain balances, who performs that reconciliation, at what frequency, and which independent party checks it. The custodians winning institutional mandates in 2026 publish their segregation model plainly instead of making prospects extract it in diligence, and banks entering the market should match that transparency standard from the first client conversation onward.

A bank entering this market is not competing on cryptography — the specialists are ahead and will stay ahead. It competes on three things clients cannot get from a startup.

First, balance-sheet and franchise durability: the belief that the institution will exist, regulated and capitalized, in twenty years. Second, integration: custody positions that appear in the same statements, portals, and reporting pipelines as the client's securities. Third, the perimeter: familiar onboarding, familiar legal agreements under bank regulation, one relationship manager. The standard the market expects from any provider claiming this tier — segregation, insurance, audited controls, regulated charter — is what we call bank-grade custody, and clients will hold an actual bank to it with zero tolerance.

Zodia Custody profile screen showing a user ID and the account's ECC public key with access logs

Image: Zodia Custody — each operator identity is bound to a public key with access logs; identity-bound signing is what lets a custodian attribute every instruction to a person.

More in Guides

Insurance, bankruptcy remoteness, and the failure question

Every serious client conversation eventually arrives at the same scenario: the custodian fails — what happens to my assets? A bank entering custody needs a crisper answer than the crypto-native average, because the bank's whole pitch is institutional durability.

The legal half of the answer is segregation. Assets held in properly documented custody for an identified client are the client's property, not part of the custodian's estate, and should pass outside a bankruptcy or resolution. The strength of that answer depends on documentation discipline: account agreements that create a custodial relationship rather than a debtor-creditor one, wallet structures that map to specific clients, and books that reconcile to the chain daily. The failures of 2022 taught the market that firms calling themselves custodians while operating commingled pools produced creditors, not owners. A bank should be able to show — not assert — that its structure produces owners.

The insurance half is narrower than marketing implies. Crime and specie policies in this market cover specific named perils, typically theft of key material from defined storage, up to sublimits that are usually a fraction of assets under custody. They do not cover market loss, protocol failure, or most client-side compromise. The right posture for a bank is to state coverage precisely — perils, limits, and whose benefit the policy runs to — and to treat controls, not insurance, as the primary safeguard. Sophisticated clients read vague "insured custody" claims as a signal that the provider hopes they will not ask follow-up questions.

There is also a supervisory half. Unlike a startup custodian, a failing bank is resolved by a regulator with statutory tools, and client custody books at failed banks have historically transferred to successor institutions rather than freezing. That resolution story — messy but bounded — is one of the strongest quiet arguments a bank custodian has, and almost none of them articulate it in client materials.

Put the three halves together and the bank's failure answer becomes concrete: segregated property that passes outside the estate, named-peril insurance stated honestly, and a resolution regime with a track record of transferring custody books intact. Boards should insist this answer exists in writing before launch, because it will be asked within the first month of client meetings — usually by the largest prospect in the pipeline, whose allocation depends on repeating it credibly to their own investment committee and auditors.

Common mistakes banks make

Piloting under SAB 121 assumptions. Programs scoped in 2023–2024 were often shaped around avoiding balance-sheet treatment — structures that no longer earn their complexity after SAB 122. Re-scope before launching a design that solved a repealed problem.

Treating the sub-custodian as a vendor rather than a counterparty. Under sub-custody the bank's clients are exposed to the sub-custodian's failure. Due diligence belongs at credit-risk depth — financials, key governance, insurance terms, bankruptcy treatment — not procurement depth.

Launching custody without a trading answer. Clients who custody assets eventually want to move or trade them. Banks that launch storage-only discover their assets leave for platforms that pair custody with execution. Decide the settlement and trading integration story before launch, even if the answer is a partner.

Underestimating the examiner conversation. Permissibility is settled; expectations are not standardized. The banks that move smoothly document key ceremonies, quorum policies, and incident runbooks to the standard of payment operations from day one, rather than treating the crypto stack as an innovation-lab artifact.

"We are a regional bank with wealth clients asking about bitcoin, and we cannot justify a build." Sub-custody under your brand is the fit. Your work is counterparty diligence on the sub-custodian and clean client disclosure of where assets actually sit — not technology.

"We are a private bank with significant digital asset demand and our own trust charter." The licensing model matches: run a vendor custody stack under your charter, keep the keys and the margin, and buy the operational tooling you would otherwise spend two years rebuilding.

"We are a global custodian evaluating whether digital assets threaten our core business." That is a build decision, and the honest framing is defensive: tokenized securities will eventually settle on the rails you are evaluating. The custody stack you build for crypto is the settlement infrastructure for whatever fraction of your existing book migrates on-chain.

BitGo branded graphic of a glowing glass key with the words Digital Asset Custody

Image: BitGo — the custodian, which received OCC approval to operate as a national trust bank in 2025, markets custody as the foundation product; specialists like BitGo are both competitors and sub-custody partners for banks entering the market.

Frequently asked questions

Are U.S. banks actually allowed to custody crypto?

Yes. OCC Interpretive Letter 1170 established permissibility for national banks in July 2020, and Interpretive Letter 1183 in March 2025 removed the supervisory non-objection step. State-chartered institutions follow their own regulators, with New York's trust framework the most developed. Permissibility is settled; execution quality is what examiners now test.

What did SAB 122 change in practice?

It rescinded SAB 121's requirement that custodians record safeguarded crypto on their own balance sheets. That single change restored the economics of custody for banks, because off-balance-sheet treatment means no capital charge against client assets. It is the main reason large trust banks re-activated digital asset programs in 2025.

Does the Basel framework make bank crypto custody uneconomical?

No. The Basel standard's punitive 1,250% risk weight applies to a bank's own exposures to unbacked cryptoassets, not to client assets held in segregated custody. A bank that custodies without taking principal exposure carries operational-risk capital, as with any custody business, not credit-risk capital against the coins.

Should a bank use MPC or HSM-based key storage?

Most new bank deployments use multi-party computation for operational wallets, because it distributes signing across parties and maps naturally onto maker-checker governance, with cold storage for long-term reserves. The deciding factors are auditability and vendor maturity rather than raw cryptography; both approaches pass examination when governed well.

How long does it take a bank to launch digital asset custody?

Sub-custody arrangements have gone live in two to six months. Licensed-technology deployments typically run four to twelve months including model validation and examiner engagement. Full builds run eighteen months and up, with staffing — people who have run audited key ceremonies — the usual bottleneck rather than software.

Sources

  • Office of the Comptroller of the Currency, Interpretive Letter 1183, "OCC Reaffirms Permissibility of Cryptocurrency Custody Activities," March 7, 2025.
  • U.S. Securities and Exchange Commission, Staff Accounting Bulletin No. 122 (rescinding SAB 121), January 23, 2025.
  • Basel Committee on Banking Supervision, "Prudential treatment of cryptoasset exposures," December 16, 2022.