"Qualified custodian" is the most load-bearing phrase in institutional crypto — and one of the most misused. Marketing pages apply it to everything from chartered trust companies to software wallets, but the term has a specific regulatory meaning under the SEC's custody rule, and whether your custodian genuinely meets it determines whether a registered investment adviser can legally hold client crypto with them at all.
This guide explains what qualified custodian status means for digital assets in practice: which charters and licenses actually confer it, how the SEC's proposed safeguarding rule would tighten the definition, and how to verify a provider's claims instead of taking the label on faith. It is written for RIAs, fund managers, and corporate treasurers who need the regulatory reality, not the brochure version.
Fidelity Digital Assets custody and trading interface. Image: Fidelity Digital Assets.
Where the term comes from: the custody rule
The phrase originates in Rule 206(4)-2 under the Investment Advisers Act of 1940 — the "custody rule." When a registered investment adviser has custody of client funds or securities, the rule requires those assets to be maintained with a qualified custodian: a bank, a savings association, a registered broker-dealer, a futures commission merchant, or certain foreign financial institutions.
The rule was written decades before digital assets existed, and that mismatch is the source of most of the confusion. Bitcoin held in a hardware wallet in an adviser's office is plainly not with a qualified custodian. But what about a state-chartered trust company running institutional cold storage? A broker-dealer subsidiary? The answer depends on the entity's charter, not on the quality of its security engineering.
Three entity types dominate qualified custody claims in digital assets today:
National trust banks. The Office of the Comptroller of the Currency confirmed in Interpretive Letter 1170 that national banks may provide cryptocurrency custody services. A federally chartered trust bank — Anchorage Digital Bank is the most prominent example — is a "bank" for custody-rule purposes, which is the cleanest path to qualified custodian status currently available.
State-chartered trust companies. New York limited-purpose trust companies (Coinbase Custody Trust Company, Gemini Trust Company, BitGo New York Trust Company) and South Dakota trust companies (BitGo Trust Company, Fidelity Digital Asset Services) hold state banking charters and are supervised by state banking regulators. Most advisers and their counsel treat these as banks under the custody rule, and they custody the large spot bitcoin ETFs — but the SEC has never issued a blanket confirmation, which is why diligence memos still hedge.
Broker-dealers. A registered broker-dealer is a qualified custodian by statute, but crypto-native broker-dealer custody remains narrow in practice, largely confined to digital asset securities under the SEC's special-purpose broker-dealer framework rather than bitcoin and ether themselves.
The entity that signs your custody agreement matters as much as the category. Large providers operate families of legal entities — a broker-dealer, a state trust company, sometimes a federal bank — and only some of them are qualified custodians. Ask which entity holds the assets, under which charter, and get it in the agreement.

Gemini Custody's institutional dashboard. Image: Gemini Trust Company.
It is tempting to treat qualified custodian status as a compliance checkbox, but the charter carries substantive protections that unregulated custody does not.
Fiduciary duty. A trust company holds assets as a fiduciary. Client assets sit in segregated custodial accounts that are not property of the custodian's estate — the core protection that failed catastrophically at exchanges that commingled client funds. If a chartered trust company fails, custodied assets are not supposed to be available to its creditors.
Regulatory examination. Chartered custodians are examined by their supervisor — the OCC for national trust banks, the New York State Department of Financial Services or the South Dakota Division of Banking for state trust companies. Examiners review capital adequacy, key management, transaction controls, and business continuity. NYDFS went further in January 2023, issuing custody-specific guidance requiring segregation of customer virtual currency, limiting use of omnibus accounts, and restricting the custodian's ability to use customer assets.
Capital and insurance requirements. Charters impose minimum capital, and supervisors expect insurance programs sized to the business. This is why chartered custodians publish specie or crime insurance figures while unregulated wallets generally cannot.
None of this makes a charter a guarantee. It makes custody supervised, which is the property the custody rule was designed to secure. The security architecture underneath — cold storage, HSMs, or multi-party computation custody — is a separate axis: a qualified custodian can run any of these models, and the charter says nothing about which one protects your keys.

Staking from custody at Anchorage Digital, a federally chartered crypto bank. Image: Anchorage Digital.
The SEC's proposed safeguarding rule
On February 15, 2023, the SEC proposed replacing the custody rule with a new Rule 223-1 — the "safeguarding rule" — and the proposal would materially raise the bar for digital assets.
Three changes matter most for crypto:
Scope expands from "funds and securities" to all client assets. Under the current rule, advisers have argued that many crypto tokens are neither funds nor securities and thus sit outside the custody rule entirely. The proposal closes that argument: any client asset an adviser has custody of, including crypto, would need a qualified custodian.
Possession or control becomes an explicit standard. The proposed rule would require the qualified custodian to have "possession or control" of the assets — participating in any change of beneficial ownership. For digital assets, that maps directly onto key management: a custodian that does not control the private keys arguably does not have possession or control.
Written agreements and minimum protections. The proposal would require a written agreement between the adviser and custodian, reasonable assurances on segregation, and indemnification for negligence — terms that today vary widely between custody agreements.
The proposal has not been adopted, and its final shape remains contested. But it is already the diligence template: allocators increasingly evaluate custodians against the proposed standard, because a custodian that cannot meet it may not remain usable if the rule lands. When you shortlist providers, ask how they would satisfy possession-or-control and the written-agreement terms — the answers separate custodians built for regulated flows from those retrofitting compliance onto an exchange wallet.

Initiating a transfer from segregated custody accounts at Gemini. Image: Gemini Trust Company.
The practical landscape sorts into three tiers, and the differences show up in diligence, not in day-to-day operations.
Federal charter (OCC). Anchorage Digital Bank remains the only crypto-native custodian with a national trust bank charter. The federal charter preempts state-by-state licensing and is the least ambiguous qualified custodian claim available. The trade-off is concentration: one charter, one supervisor, and OCC posture toward crypto banking has shifted with administrations.
New York trust charter (NYDFS). New York's limited-purpose trust companies operate under the strictest state regime. NYDFS's January 2023 guidance imposed custody-specific requirements — segregation, disclosure of sub-custody arrangements, limits on use of customer assets — that function as a de facto national standard because the largest custodians (Coinbase Custody, Gemini, BitGo NY, Fidelity's New York entity) hold New York charters. If your counterparties or LPs are conservative, a NYDFS-supervised custodian is the easiest diligence conversation.
South Dakota trust charter. South Dakota chartered several major digital asset trust companies (BitGo Trust, Fidelity Digital Asset Services' original entity) with lighter-touch supervision than New York. These are still chartered, examined trust companies — but expect sophisticated LPs to ask why South Dakota rather than New York, and to read the examination cadence more closely.
Public-market validation has become its own diligence signal. BitGo's 2025 listing on the New York Stock Exchange put audited financials of a pure-play custodian into the public record for the first time — balance-sheet transparency that private custodians cannot match and that diligence teams now cite alongside SOC reports.

BitGo listed on the NYSE in 2025, adding public-company reporting to its charter obligations. Image: BitGo.
More in Guides
Verifying a qualified custodian claim
Because the label is unregulated as a marketing term, verification is on you. A practical checklist:
1. Identify the exact legal entity. Get the full entity name from the draft custody agreement — not the brand. "Coinbase" is not a custodian; Coinbase Custody Trust Company, LLC is.
2. Confirm the charter with the regulator, not the website. NYDFS publishes its list of virtual currency licensees and chartered trust companies. The OCC publishes national bank and trust charters. South Dakota's Division of Banking lists its trust companies. A claim you cannot find on the supervisor's own list is a red flag, full stop.
3. Read the examination and audit posture. Ask for the most recent SOC 1 Type II and SOC 2 Type II reports, and ask when the regulator last examined the entity. A chartered custodian that cannot produce current SOC reports is behind its peers.
4. Trace where keys actually live. Qualified custodian status attaches to the entity, but protection depends on that entity controlling the keys. Sub-custody and omnibus arrangements — common when a smaller platform white-labels a larger custodian — mean your agreement may be with an entity that never touches a key. NYDFS guidance requires disclosure of these arrangements; use it.
5. Match the account structure to your regulatory need. An RIA satisfying the custody rule needs client assets in accounts under each client's name or a properly structured omnibus with sub-accounting. A fund needs the fund entity named. Getting the account titling wrong can undermine the qualified custody you paid for.
6. Check insurance scope, not headline size. A $300 million policy that covers only cold storage theft by employees is narrower than it sounds. Ask what perils are covered, whether the policy is shared across all clients, and how claims are subordinated.
This is the same verification spine covered in our broader guide to institutional crypto custody, applied specifically to the regulatory claim.

BitGo's OCC national trust charter approval — federal charters are becoming a second path beyond state trusts. Image: BitGo.
The rule binds registered investment advisers, but the label matters to a wider set of situations:
You are an RIA with discretionary authority over client crypto. You are squarely inside the custody rule. Client digital assets need to sit with a qualified custodian, and given the proposed safeguarding rule, the conservative reading — treat all crypto as in scope now — is the one your compliance counsel will likely take.
You run a private fund. The custody rule reaches you through your adviser registration, and the audit exception many funds rely on still interacts with custody choices. Your auditor's willingness to verify digital asset holdings depends heavily on the custodian's controls, so a chartered custodian with strong SOC coverage shortens your audit, whatever the rule technically requires.
You are a corporate treasurer. No custody rule applies to you directly. But board approval, D&O comfort, and insurance underwriting all get easier when the custodian is a supervised trust company, which is why most corporate treasury programs specify qualified custody in policy even without a legal mandate.
You are a fintech embedding crypto. Your regulators (state money transmission, potentially the SEC or CFTC depending on product) will ask where customer assets sit. Sub-custody with a chartered qualified custodian is the standard answer, but remember the disclosure obligations that come with it.
The charter tells you who supervises the custodian; the agreement tells you what you actually get. Four clauses deserve more attention than they usually receive.
Standard of care. Agreements range from full fiduciary language to liability capped at fees paid in the prior twelve months. A trust charter implies fiduciary duty, but a cap in the contract can hollow it out in practice. Ask for negligence-based liability at minimum, and read how "losses" is defined — some drafts exclude the market value of assets and cover only direct out-of-pocket costs.
Segregation mechanics. "Segregated" can mean a dedicated on-chain wallet per client, a sub-account within an omnibus wallet, or merely book-entry separation in the custodian's ledger. Each has different insolvency behavior. The NYDFS guidance pushes toward genuine separation; your agreement should say which structure applies to your assets, not leave it to an operations FAQ.
Instruction and authorization flow. Who can move assets, with what quorum, and how the custodian authenticates instructions is where most real-world losses occur — through compromised authorized users, not broken cryptography. Look for contractual support for multi-user approval policies, callback verification on withdrawal-address changes, and the custodian's liability when it executes a forged but procedurally valid instruction.
Termination and asset delivery. Exiting a custodian is an operational project: on-chain transfers, address re-whitelisting at counterparties, and updated fund documents. Agreements that permit the custodian to delay delivery for extended "security reviews," or that charge exit fees on assets under custody, convert a service decision into a hostage negotiation. Cap delivery timelines in writing while the relationship is still friendly.
None of this replaces the regulatory analysis above — an excellent contract with an unchartered entity still fails the qualified custodian test. But the inverse also holds: the charter is necessary, not sufficient, and the agreement is where sufficiency is won or lost.
Common mistakes
Accepting the brand's claim for the entity you contract with. The most frequent failure: signing with a non-chartered affiliate of a group that also owns a trust company, on the assumption the charter covers the whole family. It does not.
Treating an exchange account as custody. Assets on an exchange trading venue are typically a claim against the exchange, not custodied property — even when the same group operates a genuine trust company. Move long-term holdings into the chartered entity's segregated custody accounts.
Assuming qualified custody means insured custody. The charter and the insurance program are independent. Verify both.
Ignoring the safeguarding proposal because it isn't final. Custody relationships are yearslong and migration is painful. Selecting a custodian that fails the proposed possession-or-control standard is a bet against the regulatory direction of travel.
Letting staking or trading features blur segregation. Value-added services often route assets through operational wallets. Ask which services move assets out of the segregated custody structure, and whether that movement changes their legal status.
FAQ
What exactly is a qualified custodian?
Under SEC Rule 206(4)-2, a qualified custodian is a bank, savings association, registered broker-dealer, futures commission merchant, or certain foreign financial institutions that maintains client funds and securities for a registered investment adviser. For digital assets, chartered trust companies and national trust banks are the entities most commonly relied on to meet the definition.
Is Coinbase a qualified custodian?
Coinbase Custody Trust Company, LLC — a New York limited-purpose trust company supervised by NYDFS — is the entity generally treated as a qualified custodian, and it custodies most US spot bitcoin ETFs. The Coinbase exchange itself is a different entity, and assets held on the trading platform are not in qualified custody.
Are state trust companies definitively qualified custodians under the SEC rule?
Most advisers and counsel treat state-chartered trust companies as "banks" under the custody rule, and the market operates on that basis. The SEC has not issued blanket confirmation, and the proposed safeguarding rule would add conditions rather than settle the question — which is why diligence still focuses on the specific charter and agreement terms.
Does a qualified custodian have to hold the private keys itself?
Under the current rule, not explicitly. Under the proposed safeguarding rule's possession-or-control standard, the custodian would need to participate in any change of beneficial ownership — which in practice means controlling key material. Custodians already built that way have the simpler compliance story.
Can a fund self-custody and still satisfy its adviser's obligations?
Generally no, for an SEC-registered adviser: self-custody structures rarely satisfy the custody rule, and the safeguarding proposal would narrow the space further. Some funds relying on the surprise-examination or audit provisions have argued for exceptions, but the mainstream institutional answer is a chartered third-party custodian.
Sources
- Office of the Comptroller of the Currency, Interpretive Letter 1170 — national banks may provide cryptocurrency custody services (July 22, 2020).
- U.S. Securities and Exchange Commission, Proposed Safeguarding Rule 223-1 — safeguarding advisory client assets, expanding the custody rule to all assets including crypto (February 15, 2023).
- New York State Department of Financial Services, Guidance on Custodial Structures for Customer Protection in the Event of Insolvency — segregation and sub-custody disclosure requirements for virtual currency custodians (January 23, 2023).


