US Regulators Say Banks May Custody Bitcoin and Crypto Under Existing Rules

US Regulators Say Banks May Custody Bitcoin and Crypto Under Existing Rules

N
News Editor 01
2026-07-03 19:30:14
The Federal Reserve, the Office of the Comptroller of the Currency, and the Federal Deposit Insurance Corporation issued a joint statement clarifying that US banks may provide custody and safekeeping services for bitcoin and other crypto-assets as long as they comply with existing laws and maintain strong risk controls. The statement does not create new rules. Instead, it reminds banking organizations that crypto custody must fit within established legal, operational, and compliance frameworks. Banks may offer safekeeping services in either a fiduciary or nonfiduciary capacity, and fiduciary arrangements must comply with 12 CFR 9 or 12 CFR 150, applicable state laws, regulations, and the governing legal instruments. The agencies also stress that crypto custody is fundamentally tied to control over customers’ cryptographic keys, which creates heightened requirements around cybersecurity, operational resilience, technical expertise, and legal compliance. Risks such as key loss, cyberattacks, and unauthorized transfers must be actively managed. In addition, banks remain subject to BSA/AML, CFT, and OFAC obligations when handling crypto-assets. Before launching such services, banks are expected to conduct full risk assessments covering the nature of the assets, the technology involved, and the legal obligations attached. If a bank uses a sub-custodian, it is still responsible for the activities performed under the customer agreement and must perform robust due diligence on that provider’s key-management systems, policies, processes, internal controls, and adherence to standard safekeeping practices.
Bitcoin custodyUS regulationBank complianceCrypto assetsKey managementAMLOCCFDIC

US banking regulators clarified that crypto custody is permitted under current law

The Federal Reserve, the Office of the Comptroller of the Currency (OCC), and the Federal Deposit Insurance Corporation (FDIC) released a joint statement saying that banking organizations may engage in bitcoin and crypto-asset-related custody and other activities as long as they follow existing laws and maintain strong risk controls. The agencies did not unveil a new rulebook or a special crypto banking regime. Instead, they reiterated that when banks handle bitcoin or other crypto-assets on behalf of customers, they remain fully bound by the same supervisory expectations that apply to other regulated banking activities.

This is an important distinction. The statement does not represent a broad deregulation of digital asset services, nor does it create a regulatory safe harbor. Rather, it confirms that banks are not categorically barred from offering crypto custody. They may participate, but only if they can do so within established legal, compliance, and operational frameworks. In practical terms, that means a bank’s ability to enter the crypto custody market depends less on market demand and more on whether it can demonstrate robust governance, controls, staffing, and technological readiness.

Custody can be offered in fiduciary or nonfiduciary form

The document states that banking organizations may provide safekeeping for crypto-assets in either a fiduciary or a nonfiduciary capacity. Where the bank provides safekeeping in a fiduciary capacity, it must comply with 12 CFR 9 or 12 CFR 150, as applicable, as well as relevant state laws and regulations and any other applicable legal provisions, including the legal instrument that created the fiduciary relationship.

That distinction matters because the bank’s legal duties, decision-making authority, and standards of care can differ significantly depending on the type of customer relationship. A fiduciary structure can impose heightened obligations compared with a more limited nonfiduciary custody arrangement. By explicitly referencing both paths, the agencies are signaling that crypto-assets are not outside conventional banking law. They must be slotted into recognizable legal categories, with the bank’s role clearly defined before services are offered.

Control of cryptographic keys is the center of the risk framework

The regulators emphasized that safekeeping bitcoin and other crypto-assets often means controlling customers’ cryptographic keys. That single point has major consequences. Unlike many traditional financial assets, possession or control of the relevant keys can effectively determine control over the assets themselves. If keys are lost, compromised, or misused, recovery may be difficult or impossible. Because of that, the agencies said that crypto custody requires strong cybersecurity, operational expertise, and full legal compliance.

The statement highlights several concrete risks that banks must be prepared to manage: key loss, cyberattacks, and unauthorized asset transfers. These are not merely technical inconveniences. For a regulated bank, they can become customer protection failures, legal liabilities, supervisory issues, and reputational events. That is why the agencies frame crypto safekeeping as a high-control activity that demands mature systems rather than a simple extension of ordinary digital account services.

The document also notes that providing custody for bitcoin and other crypto-assets may require specialized personnel, secure infrastructure, and continuous monitoring of evolving technologies. Wallet design, signing architecture, custody software, blockchain-specific risks, and settlement processes can all change over time. A bank entering the sector therefore needs more than a general compliance program. It needs dedicated technical and operational capabilities tailored to digital asset custody.

AML, CFT, and OFAC obligations still fully apply

The agencies were equally clear that crypto custody relationships remain subject to BSA/AML, CFT, and OFAC requirements. In other words, the fact that an asset is bitcoin or another crypto-asset does not remove a bank’s obligations under anti-money laundering rules, counter-terrorist financing controls, sanctions screening, customer due diligence, and suspicious activity monitoring. Crypto services must be integrated into the same compliance architecture that governs other banking operations.

This reinforces a long-running US regulatory theme: innovation may be permitted, but it is not exempt from financial crime controls. A bank that supports deposits, withdrawals, transfers, or safekeeping for digital assets must still maintain screening and monitoring processes capable of addressing the risks that come with blockchain-based movement of value. The joint statement makes clear that crypto custody is not being treated as a compliance exception.

Banks must complete full risk assessments before offering crypto safekeeping

Beyond broad principles, the statement warns that banking organizations should conduct a full risk assessment before engaging in bitcoin and other crypto-asset safekeeping. That assessment should include the nature of the specific crypto-assets involved, the technology being used, and the legal obligations attached to the service. Not all digital assets, custody structures, or blockchain systems present the same operational or legal profile, so banks are expected to assess these issues in detail rather than apply a generic approach.

This expectation suggests that regulators want banks to understand the differences among assets and systems before they onboard customers or hold keys. A custody model appropriate for one token or network may not be appropriate for another. The legal rights associated with different crypto-assets can also vary, and the bank is expected to map those differences into its controls, disclosures, and operating procedures.

Using a sub-custodian does not remove the bank’s responsibility

The statement also addresses the use of a sub-custodian. According to the agencies, subject to the terms and conditions in the customer agreement, a banking organization is responsible for the activities performed by the sub-custodian. That means outsourcing some part of the custody chain does not automatically transfer accountability away from the bank. If the customer relationship sits with the bank, regulators expect the bank to understand and manage the associated third-party risk.

The agencies specifically say that conducting due diligence before selecting a sub-custodian is an important part of sound risk management. That review should include an evaluation of the effectiveness of the sub-custodian’s cryptographic key-management solution, including its policies, processes, and internal controls, as well as its adherence to standard safekeeping risk management practices. This language makes clear that regulators expect meaningful review, not a box-ticking exercise.

In practice, that means banks considering third-party custody support must examine how keys are generated, stored, accessed, backed up, and protected; what governance and approval structures exist; how incidents are handled; and whether the provider follows recognized custody risk standards. The message is straightforward: delegation may be operationally useful, but supervisory responsibility remains.

What the statement means for the market

Overall, the joint statement provides a clearer path for regulated banks that want to offer bitcoin and crypto custody in the United States. It confirms that the activity is permissible under current rules, but only when supported by strong legal, technical, and compliance foundations. It also shows that regulators view digital asset custody not as a lightweight add-on, but as a service with significant operational and control demands.

For the crypto market, this may help reduce uncertainty around whether banks can participate in safekeeping services. For banks, however, the message is not simply permissive. It is conditional. Entry into crypto custody depends on governance, cybersecurity, key management, compliance infrastructure, and careful oversight of any third-party provider. The agencies have effectively said: banks may custody bitcoin and crypto-assets, but they must do it the hard way—through disciplined risk management under existing law.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.