← Back to ResourcesCrypto
Who may hold client cryptoassets under the FCA's custody rules and what must you evidence?
Karthigeyan R J#FCA#Crypto Custody#CASS 17
From 25 October 2027, safeguarding qualifying cryptoassets for UK clients is a regulated activity: only firms authorised as cryptoasset custodians may hold and transfer them. The FCA's PS26/11 (30 June 2026) sets the CASS 17 rules: client assets held on trust, daily reconciliations, immediate shortfall notification and a settlement float capped at 2% per client per cryptoasset.
Three things this article will leave you able to do
Say whether your firm's holding of client cryptoassets needs authorisation.
List the CASS 17 obligations and the artefact that evidences each.
Ask the key-management questions the rules deliberately do not answer for you.
Custody is where crypto's failures actually happened. Exchange collapses were rarely trading losses; they were client asset losses, discovered when the withdrawal queue formed. So it is no accident that custody carries some of the most concrete rules in the FCA's new regime or that it gets its own sourcebook.
The rules land in CASS 17, finalised in PS26/11 on 30 June 2026. They read like CASS 7 rewritten by someone who has watched a bridge hack. That is roughly what they are.
Who may hold client cryptoassets
From 25 October 2027, safeguarding qualifying cryptoassets in or into the UK is a regulated activity. The right to hold and transfer client cryptoassets belongs to firms authorised for it, applying in the window that opens 30 September 2026 and closes 28 February 2027. The application of the rules is control-based: what matters is who controls the means of access (in practice, the private keys), not what a terms-of-service document says. A platform that "just holds keys for convenience" is a custodian in the FCA's eyes or an unauthorised one.
Two boundary cases matter. Custody of tokenised traditional securities (relevant specified investment cryptoassets) sits under CASS 6 with authorisation as a cryptoasset custodian, not under CASS 17; the FCA has said it will consult further on tokenised asset custody. And DeFi arrangements are in scope where an identifiable controlling entity exists.
What CASS 17 requires
Trust protections. Client cryptoassets are held on trust for clients, with targeted exceptions the FCA added in the final rules. The pool belongs to clients, not to the firm's balance sheet or its creditors.
Segregation and identification. Client holdings are separated from the firm's own and identifiable per client in the firm's books.
Daily reconciliation. Internal records reconciled against on-chain and third-party positions every business day.
Shortfall treatment. Discrepancies made good and clients notified immediately when a shortfall affects them.
The 2% settlement float. Firms operating a float for settlement efficiency hold own funds supporting it, capped at 2% of safeguarded cryptoassets per client per asset.
Key management, technology-agnostic. The FCA deliberately does not prescribe cold-wallet percentages or HSM brands. It requires arrangements that protect the means of access, with the firm accountable for the design.
Third parties. Sub-custodians used only with due diligence, ongoing review and clarity about the client protections that survive the arrangement.
What you must evidence
The pattern from safeguarding applies here too: every artefact is produced by the control operating, dated, retrievable inside a working day.
The questions the rules leave with you
The technology-agnostic stance on key management is a transfer of homework, not a relief. Your firm decides the hot-to-cold split, the signing quorum, the recovery procedure and the response to a compromised key, then stands behind those decisions with evidence. Useful test questions: who can move client assets alone (the answer should be nobody); how long does recovery take if the primary signer is unavailable on a Sunday; what happens to the trust analysis if your sub-custodian enters administration in another jurisdiction? A custodian that can answer in writing, with dated artefacts, is most of the way to its authorisation case.
How firms handle this
Incumbent crypto platforms are retrofitting CASS discipline onto architectures built for speed, which is harder than building it in. Traditional custodians entering the market have the CASS muscle memory but need the key-management engineering. Both need the same register: the CASS 17 obligations, each mapped to a control and an artefact. Our Gap Analyser ships those rows against the PS26/11 rule text, which is one way to start the file before the window opens. Either way, the FCA's question in 2027 will be the one clients asked in every collapse since 2014: where, exactly, are the assets?
Primary sources
FCA, PS26/11: Regulated cryptoasset activities. Published 30 June 2026. CASS 17 final rules.
FCA, cryptoasset regime overview. Application window 30 September 2026 to 28 February 2027; regime commences 25 October 2027.
FCA, CP25/14 (the custody consultation preceding the final rules).
Volatile. Re-verify before each republish: the promised consultation on tokenised asset custody and CASS amendments · the separate consultation on crypto custodian resolution · the final scope of trust exceptions · float and own-funds percentages.
#FCA#Crypto Custody#CASS 17