US federal banking regulators have once again clarified their position on crypto custody. In a joint statement, the Federal Reserve, the OCC, and the FDIC said that banking organizations may engage in bitcoin and crypto-asset safekeeping and related activities, provided they follow existing law and maintain strong risk controls. The statement is important not because it opens a brand-new regulatory pathway, but because it makes clear that crypto custody is not automatically off-limits to banks. Instead, it sits within the current legal and supervisory framework, with the same expectations for governance, compliance, and operational discipline that apply to other banking activities.
For banks exploring digital asset services, the message is straightforward: participation is possible, but only if the institution can demonstrate that it understands the technology, the legal obligations, and the risks involved. The regulators are not offering a blanket endorsement of crypto activity. They are signaling that banks must treat bitcoin and other crypto-assets as an area requiring careful controls, experienced personnel, and a risk management structure capable of handling the realities of on-chain assets.
What the joint statement actually says
The agencies state that banking organizations may provide safekeeping for crypto-assets in either a fiduciary or nonfiduciary capacity. That distinction matters because the legal obligations of the bank depend on the role it plays for the customer. The statement expressly notes that a banking organization providing crypto-asset safekeeping in a fiduciary capacity must comply with 12 CFR 9 or 150, as applicable, along with relevant state laws and regulations and any other legal provisions tied to the instrument that created the fiduciary relationship.
Just as important, the regulators stress that the document does not introduce new rules. It serves as a reminder of banks’ existing obligations when handling bitcoin and other crypto-assets on behalf of customers. In practice, that means banks cannot assume digital assets fall into a loosely governed category simply because the underlying technology is different. If a bank wants to custody bitcoin, it must do so within the same broad supervisory expectations that govern fiduciary activities, customer asset protection, recordkeeping, and internal controls in traditional finance.
Crypto custody centers on control of cryptographic keys
The statement makes clear that safekeeping crypto-assets is fundamentally tied to control over customers’ cryptographic keys. In the digital asset world, key control often determines effective control over the assets themselves. That is why the agencies emphasize the need for strong cybersecurity, operational expertise, and full legal compliance. A bank offering custody cannot treat crypto storage as a simple extension of conventional asset safekeeping. It must build systems specifically designed to secure key generation, storage, authorization, recovery, and transfer procedures.
The regulators identify several concrete risks that banks must be prepared to address, including key loss, cyberattacks, and unauthorized asset transfers. These risks can have immediate and severe consequences in crypto markets, where transactions may be irreversible and asset recovery can be extremely difficult. As a result, banks need controls that go beyond ordinary IT security. They may need segmented access models, secure signing environments, documented approval workflows, continuous monitoring, and tested incident response procedures tailored to digital asset operations.
The agencies also note that bitcoin and other crypto safekeeping activities may require specialized personnel, secure infrastructure, and ongoing monitoring of rapidly changing technologies. Not all crypto-assets work the same way, and not all chains or wallet architectures present the same operational profile. A bank entering the market must therefore ensure that it has people who understand the technical and procedural dimensions of digital asset custody, rather than relying solely on legacy custody expertise developed for conventional securities or cash-based systems.
AML, CFT, and OFAC obligations still fully apply
Another major point in the statement is that crypto custody does not sit outside the normal compliance perimeter of the banking system. The agencies explicitly say that, like all other banking activities, crypto-asset safekeeping relationships remain subject to applicable BSA/AML, CFT, and OFAC requirements. This means banks must continue to apply anti-money laundering controls, counter-terrorist financing measures, and sanctions screening when handling customer crypto-assets.
That requirement has practical implications. A bank cannot characterize itself as merely a technical storage provider and avoid responsibility for the broader compliance context of the assets it holds. Customer due diligence, suspicious activity monitoring, sanctions checks, and transaction review remain essential. In the crypto setting, that may also require institutions to integrate blockchain analysis capabilities and address screening tools into their compliance programs. The statement underscores that being involved in digital assets does not weaken a bank’s existing legal responsibilities.
Comprehensive risk assessment is required before launch
The regulators further warn that banking organizations should conduct a full risk assessment before engaging in bitcoin and other crypto safekeeping. This assessment should not be superficial or purely commercial. It must consider the nature of the crypto-assets involved, the technologies used, and the legal obligations attached to the service. In other words, the bank must understand what it is planning to custody, how the relevant systems function, and what liabilities or legal duties may arise from the custody structure.
This is a significant point because different crypto-assets may present different legal and operational considerations. Bitcoin may not raise the same issues as other crypto-assets with distinct technical features or governance mechanisms. The agencies therefore expect banks to evaluate those differences rather than apply a one-size-fits-all framework. Thorough front-end analysis is part of safe and sound banking practice, especially in a sector where technological design and legal treatment can vary considerably from one asset to another.
Responsibility remains with the bank, even when using a sub-custodian
The statement also addresses the use of sub-custodians, which is common in financial markets and increasingly relevant in digital asset infrastructure. The agencies say that, subject to the terms and conditions in the customer agreement, a banking organization is responsible for the activities performed by the sub-custodian. That means outsourcing part of the safekeeping function does not eliminate the bank’s accountability. The institution remains responsible for managing the relationship and ensuring that the outsourced activity meets appropriate standards.
Because of that, the regulators stress the importance of due diligence before selecting a sub-custodian. This includes evaluating the effectiveness of the sub-custodian’s cryptographic key-management solution, including its policies, processes, and internal controls, as well as its adherence to standard safekeeping risk management practices. In practical terms, a bank should examine how a sub-custodian generates, stores, protects, and authorizes the use of keys, how it records activity, how it separates duties, and how it responds to incidents or control failures.
Overall, the joint statement gives the market a clearer view of how US regulators currently frame bank involvement in bitcoin and crypto custody. It is not a broad deregulation signal, and it is not a green light for casual entry. Rather, it confirms that banks may participate under existing law if they can meet the standards expected of regulated financial institutions. For the industry, that means future competition in bank-based crypto custody is likely to center on security architecture, compliance depth, operational maturity, and the ability to manage third-party custody relationships responsibly.

