On August 25, 2026, the SEC submitted rewritten crypto custody rules to the White House for review, placing a new framework for investment advisers and investment companies under scrutiny by the Office of Information and Regulatory Affairs. The submission followed the agency's withdrawal of a separate 2023 safeguarding proposal, making this the second attempt to establish federal custody standards for digital assets held on behalf of clients.
The procedural milestone matters because custody rules determine who can legally hold crypto assets for institutional clients and under what conditions. Yet the more important question is not whether the rule clears review, but what happens to compliance risk once it does. The SEC's framework makes institutional crypto custody explainable on paper by requiring advisers to use and monitor qualified custodians. What it does not resolve is who bears the cost when those custodians fail.
This is a structural rearrangement, not a risk elimination. The rule redistributes operational and legal exposure from the regulatory void onto investment advisers themselves.
The 2023 safeguarding proposal's withdrawal left advisers operating without explicit federal custody standards for digital assets. The current rewrite entered White House review after the agency withdrew that 2023 proposal, according to The Defiant. The SEC is resurrecting a custody rule the previous administration failed to land, CoinDesk reported.
The proposal could clarify how investment advisers and funds hold digital assets for clients, CoinTelegraph noted. The conditional framing is appropriate: OIRA review introduces procedural uncertainty, and the text itself remains unpublished. What advisers know is the obligation structure; what they do not know is the full specification of standards they will be held accountable for enforcing.
The qualified custodian designation functions as a gatekeeping mechanism. Custodians must meet criteria the SEC sets; advisers must verify and maintain that compliance. This creates a two-layer monitoring obligation. Advisers become responsible not only for their own due diligence at onboarding, but for continuous verification that custodians remain qualified. The framework assumes this monitoring is feasible and that failure modes are detectable before client assets are affected.
That assumption is testable only in failure.
The core tension in the SEC's approach is between delegated custody and retained liability. Advisers must outsource asset holding to regulated custodians, yet retain regulatory responsibility for that choice. If a qualified custodian fails through operational error, security breach, or insolvency, the adviser faces questions about whether its monitoring was sufficient. The rule provides the form of protection (use a qualified custodian) without clarifying the substance of recourse (what happens when qualification proves insufficient).
This is characteristic of regulatory frameworks that make complex activities explainable to oversight bodies. The structure satisfies procedural demands: there is a designated responsible party, a documented chain of custody, and a nominally regulated intermediary. What the structure does not guarantee is that the party now holding risk, the adviser, has tools to mitigate it.
Cross-border custody arrangements compound this asymmetry. U.S. advisers using custodians in jurisdictions with different licensing frameworks face additional verification challenges. The SEC's qualified custodian standard may not map cleanly onto non-U.S. regulatory categories, leaving advisers to interpret equivalence without definitive guidance. The rule's silence on cross-border recognition is not accidental omission; it reflects unresolved tension between national custody standards and globally distributed asset infrastructure.
White House review through OIRA is a procedural checkpoint, not a policy endorsement. The office examines whether regulatory submissions meet administrative requirements, including cost-benefit analysis and consistency with executive priorities. OIRA can return rules for revision, extend review indefinitely, or clear them for publication.
The timeline is inherently unpredictable. The August 25 submission begins a review period with no fixed endpoint. Advisers cannot assume the rule will emerge unchanged, or emerge at all. This uncertainty itself generates compliance risk: firms must prepare for implementation without knowing the final requirements, the effective date, or whether the 2023 proposal's fate, withdrawal after prolonged contestation, will repeat.
If the rule clears review and takes effect, institutional crypto custody becomes a regulated utility in form. Advisers must use designated providers, maintain audit trails, and document compliance. Whether it becomes a reliable utility in function depends on whether the SEC's qualified custodian standards are stringent enough to prevent failures, and whether advisers have meaningful recourse when standards are met but assets are lost.
The framework's silence on this second condition is the critical gap. Redistribution of risk is not reduction of risk. Someone must carry the exposure the previous regulatory vacuum left undefined. The SEC's rewrite names that someone: the investment adviser who chooses, monitors, and remains accountable for the qualified custodian. What the rule does not specify is how heavy that burden will prove, or whether advisers can bear it without custody standards that extend beyond U.S. borders to the global infrastructure on which institutional crypto custody actually depends.
The views and opinions expressed in this article are solely those of the author and do not constitute professional financial advice.
The Cronos network halted after a $75 million exploit of Tectonic, replaying the 2022 Mango Markets pattern.
$75M Cronos Exploit Exposes Collateral Liquidity Blind Spot
Robinhood Chain's record DEX volume shows tokenized equities work when on-chain infrastructure defers to securities compliance rather than outpacing it.
Tokenized Stocks Hit $29.5B: Why Rules, Not Chains, Set the Pace
Cosmos Labs admitted it wrongly cleared a bug reported through its bounty program in April, allowing a $5.7 million exploit four months later across six chains.
When Bug Bounties Fail: Cosmos Labs' $5.7M Misclassification
SBI Holdings paid $270 million for a 20% stake in Indonesian brokerage Ajaib to expand its yen stablecoin in Southeast Asia.
Yen Stablecoin Meets 3 Million Accounts: SBI's Indonesia Play
The SEC's revived crypto custody rule shifts compliance burden to investment advisers who must vet qualified custodians, without clear protection when those custodians fail.
SEC custody rewrite enters White House review after 2023 withdrawal
Judge Katherine Polk Failla adjourned Roman Storm's Tornado Cash retrial to April 2027 with his motion for acquittal still pending, signaling judicial uncertainty about whether publishing open-source code...
Storm Retrial Delayed to 2027 as Judge Weighs Acquittal Motion