Document

Adviser and Regulated Fund Custody Rules; Crypto Custody Rules

The Securities and Exchange Commission (the "Commission" or the "SEC") is proposing new custody rules under the Investment Company Act of 1940 (the "Investment Company Act") and...

Securities and Exchange Commission
  1. 17 CFR Parts 270, 274, 275, and 279
  2. [Release Nos. IA-7023; IC-36353; File No. S7-2026-35]
  3. RIN 3235-AN46
( printed page 63870)

AGENCY:

Securities and Exchange Commission.

ACTION:

Proposed rule.

SUMMARY:

The Securities and Exchange Commission (the “Commission” or the “SEC”) is proposing new custody rules under the Investment Company Act of 1940 (the “Investment Company Act”) and amendments to related reporting and recordkeeping requirements to address how regulated investment companies may custody crypto securities and similar investments, and amendments to the custody rule and related reporting and recordkeeping rules under the Investment Advisers Act of 1940 (the “Advisers Act”) to address how registered investment advisers may custody client crypto funds and securities. We are also proposing to amend the current custody rules to modernize their requirements, to better address current industry practices and feedback, and to implement certain conforming amendments. We are also proposing amendments to the recordkeeping rules under the Investment Company Act and Advisers Act related to these proposed modernization amendments to the custody rules. Additionally, we are proposing to redesignate the custody rule under the Advisers Act and to make corresponding amendments to Form ADV and Form ADV-E for registered investment advisers to reflect the Advisers Act custody rule redesignation. We are also proposing amendments to Form ADV for registered investment advisers and Form N-CEN for regulated investment companies and to improve the quality of public disclosures made on these forms. We are also proposing to add new questions to Form ADV and Form N-CEN related to tokenized private funds and regulated investment company shares, respectively.

DATES:

This release was published in the Federal Register on October 6, 2026. Comments should be received on or before December 7, 2026.

ADDRESSES:

Comments may be submitted by any of the following methods:

Electronic Comments

Paper Comments

  • Send paper comments to Vanessa A. Countryman, Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090.

All submissions should refer to File Number S7-2026-35. This file number should be included on the subject line if email is used. To help the Commission process and review your comments more efficiently, please use only one method of submission. The Commission will post all comments on the Commission's website ( www.sec.gov/​rules-regulations/​public-comments/​s7-2026-35). Do not include personally identifiable information in submissions; you should submit only information that you wish to make available publicly. The Commission may redact in part or withhold entirely from publication submitted material that is obscene or subject to copyright protection.

Studies, memoranda, or other substantive items may be added by the Commission or staff to the comment file during this rulemaking. A notification of the inclusion in the comment file of any such materials will be made available on the Commission's website. To ensure direct electronic receipt of such notifications, sign up through the “Stay Connected” option at www.sec.gov to receive notifications by email.

A summary of the proposal of not more than 100 words is posted on the Commission's website ( www.sec.gov/​rules-regulations/​2006/​10/​s7-2026-35).

FOR FURTHER INFORMATION CONTACT:

Janet Jun and Jill Pritzker, Senior Counsels; Samuel Thomas, Branch Chief; Robert Holowka, Assistant Director, Investment Adviser Regulation Office; Andrew Deglin, Alexis Hassell, and Gregory Scopino, Senior Counsels; Zeena Abdul-Rahman, Branch Chief; Amanda Hollander Wagner, Senior Special Counsel; and Brian M. Johnson, Assistant Director, Investment Company Regulation Office; Meghan Ryan, Assistant Chief Accountant, Chief Accountant's Office, Division of Investment Management, at (202) 551-6787, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-8549.

SUPPLEMENTARY INFORMATION:

The Commission is proposing for public comment: amendments to 17 CFR 270.17f-1 (“rule 17f-1”), 17 CFR 270.17f-2 (“rule 17f-2”), 17 CFR 270.17f-4 (“rule 17f-4”), 17 CFR 270.17f-5 (“rule 17f-5”), 17 CFR 270.17f-6 (“rule 17f-6”), 17 CFR 270.17f-7 (“rule 17f-7”), 17 CFR 270.31a-1 (“rule 31a-1”), 17 CFR 270.31a-2 (“rule 31a-2”), and 17 CFR 274.101 (“Form N-CEN”) under the Investment Company Act; [1] 17 CFR 270.17f-8 (“proposed rule 17f-8”) and 17 CFR 270.17f-9 (“proposed rule 17f-9”) under the Investment Company Act; to rescind 17 CFR 270.17f-3 (“rule 17f-3”) and 17 CFR 274.219 (“Form N-17f-1”) under the Investment Company Act; and amendments to 17 CFR 275.206(4)-2 under the Advisers Act [2] (“rule 206(4)-2”) and to redesignate it as 17 CFR 275.223-1 under the Advisers Act (“proposed rule 223-1”), 17 CFR 275.204-2 (“rule 204-2”), 17 CFR 275.279.1 (“Form ADV”), and 17 CFR 275.279.8 (“Form ADV-E”), under the Advisers Act.

( printed page 63871)

Table of Contents

I. Introduction

A. Custody of Crypto Assets

1. Development and Growth of Crypto Asset Market

2. Challenges of Custodial Compliance for Crypto Assets

B. Overview of the Proposal

II. Discussion

A. Adviser Self-Custody

1. Adviser Self-Custody Rule Overview

2. Qualified Custodian Determination

3. Safeguarding Expertise and Systems

4. Cybersecurity

5. Annual Review

6. Internal Control Report

7. Self-Custody Account Statements to Clients

8. Financial Asset Election

B. Self-Custody of Regulated Fund Crypto Assets

C. Custody of Crypto Assets by State Trust Companies

1. Overview and Scope

2. Initial and Annual Determinations

3. Financial Statement Audit

4. Internal Control Report

5. Segregation of Assets

6. Request for Comment on Other State Trust Company Issues

D. Decentralized Finance

E. Crypto Asset Trading

F. Investment Company Custody Rule Modernization

1. Business Development Companies

2. Broker-Dealer Custody

3. Free Cash Accounts

4. Other Amendments to Regulated Fund Custody Rules

5. Request for Comment on Other Regulated Fund Custody Issues

G. Investment Adviser Custody Rule Modernization

1. Redesignation to Section 223

2. Discretionary Trading Authority

3. PCAOB-Registered Accountant Requirement

4. Audit Provision

5. Standing Letters of Authorization

6. Treatment of Business Development Companies

7. Account Number in Notice to Clients

8. Notice to the Commission of Material Discrepancies

9. Inadvertent Custody

10. Segregation

11. Accommodation Reporting Guidance

H. Recordkeeping Requirements

1. Adviser Recordkeeping

2. Regulated Fund Recordkeeping

3. Records Related to Crypto Assets from a Crypto Network

I. Guidance for Accountants Updates

1. Revisions for Independent Verification

2. Revisions for Internal Control Report ( printed page 63872)

3. Other Revisions

J. Disclosure and Reporting Requirements

1. Amendments to Form ADV

2. Amendments to Custody Reporting on Form N-CEN

3. Adviser and Regulated Fund Risk Disclosure Requirements

4. Conforming Amendments to Form ADV-E

K. Existing Staff No-Action Letters and Other Staff Statements

L. Compliance Date

III. General Request for Comment

IV. Economic Analysis

A. Introduction

B. Economic Baseline

1. Crypto Assets and Market Overview

2. Regulatory Baseline

3. Affected Parties and Industry Statistics

4. Market Practice

C. Benefits and Costs

1. General Economic Considerations

2. Adviser Self-Custody

3. Regulated Fund Self-Custody of Crypto Assets

4. Custody of Crypto Assets by State Trust Companies

5. Investment Company Custody Rule Modernizations

6. Investment Adviser Custody Rule Modernization

7. Recordkeeping Requirements

8. Guidance for Accountants Updates

9. Disclosure and Reporting Requirements

10. Aggregate Monetized Benefits and Costs

D. Effects on Efficiency, Competition, and Capital Formation

1. Efficiency

2. Competition

3. Capital Formation

E. Reasonable Alternatives

1. Alternative Qualified Custodian Determination Criteria in Adviser Self-Custody

2. Alternative Protective Measures in Adviser Self-Custody

3. Alternative Board Oversight Measure in Regulated Fund Self-Custody

4. State Trust Companies as Permitted Custodians

5. Alternative Conditions Attached to the Use of State Trust Companies as Custodians for Crypto Assets

6. Crypto Asset Trading

7. Other Alternatives for Investment Company Custody Rule Modernization

8. Alternative to the Independent Verification Requirement

9. Adviser Account Statements

10. Sharing Key Materials

F. Request for Comments

V. Paperwork Reduction Act Analysis

A. Introduction

B. Advisers Act Custody Rule 223-1

C. Investment Company Act

1. Proposed Rule 17f-9

2. Proposed Rule 17f-8

3. Proposed Rule 17f-1

4. Inclusion of BDCs in Investment Company Act Custody and Recordkeeping Rules

D. Recordkeeping Rules

1. Rule 204-2

2. Rule 31a-2

E. Disclosure

1. Form ADV

2. Form N-CEN

3. Rescission of Form N-17F-1

F. Request for Comments

VI. Initial Regulatory Flexibility Analysis

A. Reason for and Objectives of the Proposed Action

B. Legal Basis

C. Small Entities Subject to the Rule and Rule Amendments

D. Projected Reporting, Recordkeeping and Other Compliance Requirements

E. Duplicative, Overlapping, or Conflicting Federal Rules

F. Significant Alternatives

G. Solicitation of Comments

VII. Congressional Review Act

VIII. Other Matters

Incorporation by Reference

Statutory Authority

I. Introduction

A. Custody of Crypto Assets

Section 17(f) of the Investment Company Act and the rules thereunder (collectively, the “Investment Company Act custody rules”) govern the custody of securities and similar investments of registered management investment companies and business development companies (“BDCs,” and together with registered management investment companies, “regulated funds”).[3] The Investment Company Act custody rules require that a regulated fund maintains fund securities and similar investments with certain specified custodians (“Investment Company Act custodians”) and subject to conditions designed to assure the safety of the regulated fund's assets.[4] Additionally, regulated funds are required to maintain a bond for officers and employees that singly, or jointly with others, have access to securities or funds.[5] The purpose of this bond is to protect shareholders against larceny and embezzlement by these officers or employees. This rule and any related bonding apply to crypto assets that are securities or similar investments.

Rule 206(4)-2 under the Advisers Act (the “Advisers Act custody rule” and, collectively with the Investment Company Act custody rules, the “custody rules”) regulates the custodial practices of registered investment advisers (“advisers”).[6] The Advisers Act custody rule is designed to safeguard client funds and securities from loss, theft, misuse, misappropriation, and the adviser's financial reverses, including insolvency.[7]

Among other things, the Advisers Act custody rule requires that an adviser that has custody of client funds or securities maintain such funds or securities with a qualified custodian (collectively with Investment Company Act custodians, “permitted custodians”), subject to specified exceptions.[8] An adviser has custody if it holds, directly or indirectly, client funds or securities or has any authority to obtain possession of them.[9] Under the Advisers Act custody rule, qualified custodians are limited to banks or savings associations, registered broker-dealers, registered futures commission merchants, and certain foreign financial ( printed page 63873) institutions.[10] The Commission has historically taken the view that maintaining client assets with only certain types of entities helps to guard against the risk that the adviser or its related person loses, misuses, or misappropriates client assets, or subjects them to an adviser's financial reverses or insolvency. When the custodian is a third party, there is a clear distinction between the roles of the adviser (advising the client on the buying and selling of assets and implementing the client's investment strategy) and of the custodian (safekeeping the assets). To effectuate a trade, the adviser must contact the custodian for the assets to be moved. An adviser is less likely to engage in unauthorized trading in a client's account when the adviser knows that the client will be receiving from the custodian an account statement detailing any trading activity. When the adviser and the custodian are the same party, the adviser can directly move the assets.

Shortly before the adoption of the Advisers Act custody rule in 1962, the Commission asked Congress for rulemaking and inspection authority under the Advisers Act's anti-fraud provisions because it was concerned about the custodial practices of advisers and the safety of client assets. Congress amended the Advisers Act to give the Commission rulemaking and inspection authority under the Advisers Act's antifraud provisions. The Advisers Act custody rule, when it was first adopted, required all advisers with custody of client funds and securities to deposit client funds into a bank account that was maintained in the adviser's name as agent or trustee and contained only client funds and to segregate client securities and hold them in safekeeping.[11] Similarly, the requirements of section 17(f) indicate that Congress intended fund investments to be kept by financially secure entities that have sufficient safeguards against misappropriation.[12]

The current custody rules were designed to address the custody and safekeeping of traditional assets. Since the Commission last amended the custody rules, there has been significant growth in the crypto asset market, with investors increasingly seeking investment exposure to crypto assets.[13] Crypto assets have unique attributes that present challenges under the current custodial frameworks, and advisers and regulated funds have encountered obstacles in attempting to comply with the current custody rules for crypto assets.[14]

In January 2025, the Commission's Acting Chairman, Mark T. Uyeda, established the Crypto Task Force to focus on developing a comprehensive and clear regulatory framework for crypto assets.[15] As a part of its public engagement, the Crypto Task Force solicited feedback and hosted a series of roundtables on a variety of compliance topics related to crypto assets, including issues related to adviser and regulated fund custody of crypto assets.[16] Among other topics, roundtable participants and commenters provided feedback on the current custody rules and the obstacles to compliance for crypto assets.[17]

Further, in January 2025, President Donald J. Trump issued an executive order titled “Strengthening American Leadership in Digital Financial Technology.” [18] Executive Order 14178, among other things, established the President's Working Group on Digital Asset Markets (the “Digital Assets PWG”), which comprises the Chairman of the Commission and the heads of several other Federal financial regulators.[19] It furthermore directed the Digital Assets PWG to issue a report that recommends regulatory actions to advance the policy goals established in the Executive Order.[20] Pursuant to Executive Order 14178, the Digital Assets PWG issued a report (the “Digital Assets PWG Report”) containing several regulatory recommendations related to crypto assets.[21] Among other recommendations, the Digital Assets PWG Report recommended that the Commission consider using its regulatory and exemptive authority under the Advisers Act and Investment Company Act to “[p]rovide clarity on the custody of digital assets that are securities” for advisers and regulated funds.[22] Following the publication of the Digital Assets PWG Report, Chairman Paul S. Atkins announced the launch of the Project Crypto initiative to, among other things, modernize the securities rules and regulations and develop rule proposals to implement the Digital Assets PWG Report's recommendations, including to modernize the Commission's crypto asset custody requirements.[23]

To address the evolution and growth of the crypto asset market and the Digital Assets PWG Report's recommendations to the Commission, the Commission is proposing new custody rules under the Investment Company Act and amendments to the Advisers Act custody rule to provide a tailored framework for crypto asset custody. We also considered feedback received by the Commission's Crypto Task Force. We are also proposing amendments to the recordkeeping and ( printed page 63874) disclosure requirements related to the proposed custody rules.

The proposed custody rules and related recordkeeping and disclosure amendments consider the unique aspects of crypto assets and are designed to maintain fair, orderly, and efficient crypto asset markets, facilitate investment in crypto assets, and protect crypto asset investors. In addition, we are also proposing several amendments to the Advisers Act and Investment Company Act custody rules to modernize the custody rules, better address current industry practices and feedback, and implement certain conforming amendments. These proposed amendments are designed to facilitate compliance, enhance investor protection, and help support the Commission's regulatory oversight function.

1. Development and Growth of Crypto Asset Market

A crypto asset is any digital representation of value that is recorded on a cryptographically secured distributed ledger.[24] The Commission's proposed definition of “crypto asset” is generally consistent with the definition of “Digital Asset” in section 2(6) of the GENIUS Act.[25] The term distributed ledger generally refers to technology in which data is shared across a network that creates a digital ledger of verified transactions or information among network participants, and in which cryptography is used to link the data to maintain the integrity of the ledger and execute other functions.[26]

Crypto assets are generated, issued, and transferred using a blockchain or similar distributed ledger technology network (a “crypto network”). Ownership of a crypto asset is recorded on a crypto network, and access to the asset is controlled by a private cryptographic key (a “private key”) that, when paired with the asset's public cryptographic key, allows the holder to transfer the asset, or participate in certain associated rights of many crypto assets, such as staking, yield farming, and exercising governance rights.[27] Private keys can be divided into distinct pieces, or “shards,” to disperse control of the crypto asset to more than one party. Transactions or data that are processed and recorded directly on a crypto network, or “onchain,” are immutable and verifiable by other market participants, and assets transferred onchain generally cannot be restored or recovered once transferred.[28] Some crypto assets (referred to as privacy tokens or privacy coins) are designed to preserve anonymity and mask identifying features of the holders or the transaction. Such transactions on the blockchain are only verifiable by the transacting parties.[29] In addition to digitally native crypto assets, traditional assets can also be formatted as or represented by crypto assets, or “tokenized,” where the record of ownership is maintained in whole or in part on or through one or more crypto networks.[30]

Since the advent of Bitcoin in 2008,[31] the crypto asset markets have grown significantly to reach a global market capitalization of approximately $2.7 trillion in May 2026, up from $800 billion at the beginning of 2021.[32] As the crypto asset market continues to grow and evolve, investors are demanding access to crypto assets as a part of their investment portfolios, although the extent of that ownership is subject to some uncertainty. According to a 2026 report by the Office of Investor Research within the Commission's Office of the Investor Advocate, approximately 9.2% of U.S. adults hold crypto assets.[33] This level of crypto asset ownership has remained relatively stable in recent years.[34] According to another survey in 2025, approximately 22% of U.S. surveyed respondents owned crypto assets, up from 14% in 2021.[35]

2. Challenges of Custodial Compliance for Crypto Assets

Advisers and regulated funds face challenges in complying with the current custody rules, which were designed to address safekeeping of traditional assets. These rules generally limit the types of financial institutions that are eligible to serve as custodians:

While the current custody rules rely on permitted custodians to provide custodial services, in practice, few such traditional custodians have offered robust custodial services for a substantial range of crypto assets in part due to prior Commission action and staff statements, as well as other applicable regulatory guidance.[38]

For example, with respect to broker-dealers, in July 2019, the staff of our Division of Trading and Markets (“TM”) and the Financial Industry Regulatory Authority (“FINRA”) issued a joint statement that reminded broker-dealers of their responsibilities under the securities laws, including under rule 15c3-3 (the “customer protection rule”) under the Securities Exchange Act of 1934 (the “Exchange Act”), when maintaining custody of digital asset securities and provided examples of broker-dealer activities involving digital asset securities that would not involve the broker-dealer engaging in custody functions.[39] In December 2020, the Commission issued a statement regarding custody of digital asset securities by broker-dealers, which created a time-limited special-purpose broker-dealer (“SPBD”) safe harbor for broker-dealers seeking to custody digital asset securities in the circumstances where such SPBDs did not provide custody of traditional securities or any non-security digital assets.[40] According to some commenters, market participants interpreted this framework as restricting traditional broker-dealers from providing custodial services for crypto assets, and few broker-dealers offered crypto asset custodial services under the SPBD framework, due in part to limitations of the framework.[41]

For banks, applicable regulatory guidance historically oscillated between permitting banks to engage in certain crypto asset activities and dissuading banks from offering crypto asset custody services.[42] Although prior guidance from the OCC permitted national banks to engage in crypto asset custodial services,[43] subsequent guidance was interpreted by market participants to restrict the ability of banks to offer crypto asset custodial services, due to the conditions with which a bank would have to comply.[44] Further, in March 2022, Commission staff issued Staff Accounting Bulletin No. 121, which provided that, in the staff's view, it would be appropriate for entities with an obligation to safeguard crypto assets to record a safeguarding liability and corresponding asset on its balance sheet measured at the fair value of the crypto asset.[45] Some commenters stated that this guidance, along with guidance from the banking regulators, acted as an impediment to bank crypto asset custodians and dissuaded these custodians from offering crypto custodial services.[46] In January 2025, Commission staff rescinded SAB 121.[47]

During this period, certain alternative custodians emerged, most prominently among them State-chartered limited purpose trust companies (“State trust companies”). State trust companies, as creations of State law, are subject to State law and regulatory oversight, which varies depending on the applicable jurisdiction. Some State law frameworks specifically regulate these entities for crypto asset custodial services.[48] However, whether a State trust company is a permitted custodian under the Commission's custody rules requires additional legal and factual analysis from advisers and regulated funds, and as described below, the outcome of such analysis may not be clear.

Because State trust companies are not an enumerated category of permitted custodian under the current custody rules, regulated funds and advisers typically must first conclude that a State trust company is a bank for purposes of the custody rules and therefore eligible to be a custodian under the current applicable custody rule. However, determining whether an entity is a bank for purposes of the custody rules is a ( printed page 63876) fact-specific inquiry that requires analysis of applicable State and Federal banking laws. For example, a State trust company is a “bank,” and thus a permitted custodian for an adviser or regulated fund if, among other conditions, a substantial portion of the business of the State trust company consists of receiving deposits or exercising fiduciary powers similar to those permitted to national banks under the authority of the OCC. Legal counsel to State trust companies have historically identified challenges in determining whether crypto asset custodial activities, including crypto custodial activities characterized as fiduciary in nature under applicable State law, could satisfy this standard.[49] Given the historic uncertainty in determining whether a particular State trust company is a bank for purposes of the custody rules, regulated funds and advisers may have been reluctant to engage State trust companies as crypto asset custodians.

In recognition of the emergence of State trust companies as crypto asset custodians, Division of Investment Management (“IM”) staff issued a no-action letter on September 30, 2025, regarding the use of State trust companies as crypto asset custodians for purposes of the custody rules.[50] Specifically, the 2025 State Trust Company NAL stated that IM staff would not recommend enforcement action to the Commission against advisers or regulated funds if they elect to treat a State trust company as a bank for purposes of the custody rules for the placement and maintenance of advisory or regulated fund crypto assets and related cash and/or cash equivalents under certain circumstances.[51] Although the 2025 State Trust Company NAL sets forth the staff's position on enforcement actions against advisers or regulated funds treating State trust companies as banks for purposes of the custody rules, the 2025 State Trust Company NAL, like all staff statements, has no legal force or effect and does not alter or amend applicable law.

Custodians, including State trust company custodians, that do offer custodial services for crypto assets are not able to support all crypto assets given the large and continuously growing number of crypto assets in the market. Although there has been an increase in the number of permitted custodians offering custodial services for crypto assets, and this trend may continue, there may be few or no permitted custodians for certain crypto assets.[52] For example, as nascent or novel crypto assets are created, custodians must determine which crypto assets they will support and update their technology and other systems accordingly. Custodians may not yet offer custodial services for nascent or novel assets due to market demand and/or high upfront costs to set up the necessary custodial infrastructure.[53]

The continued development of the crypto asset market may further strain the availability of crypto asset custodial services. However, an adviser may determine, consistent with its fiduciary duties, that investing in a particular nascent or novel crypto asset is in the best interest of its client.[54] The lack of available custodial services for a particular crypto asset may constrain an adviser's ability to advise clients to invest in such crypto assets because, for example, existing crypto asset custodians have not yet developed or started offering custodial services for such assets.[55] The continued growth and development of the crypto asset market may continue to increase the demand for crypto asset custodial services, which could outpace the availability of custodians that are both permitted custodians under the current custody rules and willing and able to provide these highly technical and specialized custodial services for any given crypto asset. Additionally, a limited pool of custodians—that are both technically capable of offering competent crypto asset custodial services and eligible under the custody rules to act as a custodian—may create concentration risk and ultimately increase risks and costs to investors. In the context of regulated funds, rule 17f-2 under the Investment Company Act permits holding fund assets in the custody of the regulated fund itself, rather than a permitted custodian.

However, even for regulated funds, this rule does not address the challenges posed by the limited pool of permitted custodians for crypto assets because its conditions do not contemplate crypto assets.[56] For example, regulated fund assets maintained in the custody of the fund under the rule must be deposited in the safekeeping of, or in a vault or other depository maintained by, a bank or other company whose functions and physical facilities are supervised by Federal or State authority.[57] This and other conditions in rule 17f-2 are designed for stock certificates but do not address crypto assets. While rule 17f-2's conditions are not designed for crypto assets,[58] the rule does provide a framework designed to protect regulated fund assets from the risk of misappropriation, which can be applied to crypto assets, such as implementing access restrictions, requiring multiple authorized persons to act jointly in effecting transactions, maintaining certain specified records of all transactions in such assets, and requiring independent public accountants to verify assets held in self-custody.

Further, crypto assets may be subject to unique custodial risks due to their nature. Crypto assets are transferred via crypto networks that may vary in security or other access vulnerabilities. Many crypto asset transactions are immutable once executed and may be difficult or impossible to reverse. Further, crypto assets may be subject to cybersecurity risks that differ from those applicable to traditional assets. These challenges can increase the risk of loss, theft, misuse, and misappropriation of custodied crypto assets and may limit the pool of capable and permitted custodians.

B. Overview of the Proposal

In light of the challenges discussed above, and based on our experience and public feedback, we are proposing ( printed page 63877) amendments to the Advisers Act custody rule and new custody rules under the Investment Company Act to help facilitate crypto asset custody. These proposed amendments and new custody rules would help to enhance investor protection by imposing protective conditions, and to promote investor choice and ability to invest by tailoring the custody rules to address the existing limitations of the custody rules as applied to crypto assets.[59] Without a workable regulatory framework that would expand the universe of permitted custodians, advisory clients (including regulated funds) would be limited in their ability to invest in certain crypto assets. Advisers would be unable to invest client assets in crypto assets for which permitted custodians are not available, which would limit investor choice and prevent investors from obtaining exposure to crypto assets with the investor protections provided by the involvement of an adviser or from obtaining that exposure through an investment in a regulated fund.[60]

Although a crypto asset may or may not meet the definition of a “security” under the Federal securities laws, the proposed Advisers Act custody rule amendments would only apply with respect to crypto assets that are funds or securities (or, with respect to the account of a regulated fund, a security or similar investment), and the proposed Investment Company Act custody rules would only apply with respect to crypto assets that are securities or similar investments.[61]

Self-Custody: We are proposing to amend the Advisers Act custody rule to add a new provision that would permit advisers to hold advisory clients', including regulated funds', crypto assets for which they provide investment advice in self-custody (the “adviser self-custody rule”) and to add a new Investment Company Act custody rule to permit a regulated fund to maintain its crypto assets in custody through the regulated fund's adviser if the adviser complies with the adviser self-custody rule, and if the regulated fund's board of directors engages in oversight of the custody arrangement (the “fund self-custody rule,” and together with the adviser self-custody rule, the “proposed self-custody rules”).[62] For purposes of this proposal, self-custody means the adviser holding a client's crypto asset through possession of any portion of the private keys that is necessary to access and effectuate transactions in the crypto asset, or a regulated fund holding the crypto asset through an adviser that complies with the adviser self-custody rule, in each case without maintaining the crypto asset at a permitted custodian.[63] This is consistent with the way the term “self-custody” often is used in the asset management industry, although we recognize that the term self-custody also is often used to refer to circumstances where the owner of a crypto asset holds the asset directly.[64]

The proposed self-custody rules' conditions, which are designed to address the inherent conflicts of interest associated with self-custody and the risks of maintaining custody of crypto assets, include the following:

The proposed self-custody rules are intended as generally applicable requirements informed by the Commission's current understanding of crypto assets and custodial practices involving crypto assets, including the typical transactional and structural features of crypto assets and crypto networks and the typical characteristics of custodial arrangements for crypto assets. However, the Commission recognizes that crypto asset features and custodial practices for crypto assets continue to evolve and that certain crypto assets as well as novel arrangements and transactions involving crypto assets may present circumstances not addressed in this proposal and the framework for the proposed self-custody rules. To help inform the Commission's ongoing consideration of these issues, we encourage members of the public to contact the Commission with any such unique or novel arrangements involving crypto assets that raise questions about custody and safeguarding of crypto assets in compliance with the Commission's custody rules.

State Trust Company Custody: We are also proposing to amend the custody rules to permit custody of client and regulated fund crypto assets by State trust companies (together, the “proposed State trust company rules”),[77] subject to the following proposed conditions.

Similar to the proposed self-custody rules, the proposed protective conditions are intended to address the risks inherent to the custody of crypto assets and help ensure that the State trust company custodian can provide secure and effective crypto asset custodial services.

Regulated Fund Custody Modernization and Adviser Custody Modernization: We are proposing several amendments to the Investment Company Act and Advisers Act custody rules to modernize the custody rules, better address current industry practices and address feedback from industry participants, and implement certain conforming amendments.[85]

For the Investment Company Act custody rules:

We are proposing to amend the Advisers Act custody rule in several respects. First, pursuant to the authority that Congress has given us under the Dodd-Frank Wall Street Reform and Consumer Protection Act (the “Dodd-Frank Act”) specifically to prescribe investment adviser custody rules, we are proposing to redesignate the Advisers Act custody rule to new rule 223-1 and make certain conforming amendments to reflect the proposed redesignation.[86] Second, we are also proposing several amendments to modernize the Advisers Act custody rule, along with conforming amendments to update outdated references. In certain cases, such amendments are consistent with previously issued interpretive releases, staff FAQs, and staff no-action letters. These additional proposed amendments would facilitate compliance with the Advisers Act custody rule, better address industry practices, and reduce burdens. Third, we are also providing our views on several topics related to the application of the Advisers Act custody rule to improve advisers' compliance with the Advisers Act custody rule and therefore enhance investor protection. Our proposed amendments to the Advisers Act custody rule and related views include:

Recordkeeping: We are proposing amendments to the recordkeeping rules under the Advisers Act and Investment Company Act to provide that records required to be maintained and preserved under the applicable recordkeeping rules may be maintained and preserved on a crypto network, provided that the adviser or regulated fund [88] can provide, promptly upon request by the Commission (including its examiners and other representatives), such records to the Commission in a human-readable and reasonably usable electronic format. We are also proposing amendments to the recordkeeping rules under the Investment Company Act to specify the applicability of these rules to BDCs.

Accounting Guidance: We discuss revisions we expect to make to the 2009 Commission Guidance Regarding Independent Public Accountant Engagements.[89]

Form Amendments: Finally, we are proposing amendments to certain Commission forms. We are proposing amendments to Form ADV to: (1) implement the proposed rule amendments related to adviser crypto asset self-custody; (2) improve the readability of Item 9; (3) add new questions to Schedule D of Form ADV ( printed page 63880) regarding tokenized private funds; [90] and (4) make certain conforming amendments, including to implement the proposed redesignation of the Advisers Act custody rule as rule 223-1.[91] These proposed amendments to Form ADV would support accurate and complete disclosure on Form ADV.

For regulated funds other than BDCs, we are proposing amendments to Form N-CEN to require reporting of the use of crypto asset self-custody or of a State trust company to custody crypto assets, as well as to require reporting of whether a registered investment company, other than a FACC, (or Series or Class thereof) is a tokenized fund.[92] In addition, we are providing our views on disclosures related to the proposed self-custody rules and the proposed State trust company rules (together, the “proposed crypto custody rules”) for Part 2 of Form ADV for advisers and Forms N-1A and N-2 for regulated funds to help improve the quality of disclosure made to the Commission and the public on these forms related to any material facts and risks associated with crypto asset self-custody and custody of crypto assets by State trust company custodians.

II. Discussion

A. Adviser Self-Custody

1. Adviser Self-Custody Rule Overview

(a) Summary and Scope of the Proposed Adviser Self-Custody Rule

The Advisers Act custody rule generally requires advisers to maintain client assets at a qualified custodian (the “qualified custodian requirement”).[93] However, as demand for crypto asset custodial services grows with the continued growth of the crypto asset market, the range of crypto assets that can be supported by qualified custodians that are both technically capable of offering custodial services and eligible under the Commission's custody rules to act as a custodian is limited.[94] Third-party custodians may not be capable of providing custodial services initially or quickly after launch of a particular crypto asset.[95] The timing delay in the offering of custodial services for a particular crypto asset may impair investors' ability to realize the available investment value for that crypto asset.[96]

In these instances, adviser self-custody may be a viable option to address this gap of custodial services for crypto assets. In particular, an adviser that conducts extensive due diligence of a crypto asset beginning in its early stage development as a novel or nascent crypto asset may have expertise on the functioning and operation of the crypto network, potentially allowing them to be well-positioned to securely self-custody the crypto asset. Advisers may be able to provide secure custodial services on a timelier basis than a third-party permitted custodian that may have less knowledge of the crypto asset and the operations of the crypto network.

We are also cognizant that an adviser's self-custody is subject to higher custodial risks such as the risk of loss, theft, misuse, misappropriation as well as the adviser's financial condition, as compared to maintaining a client's funds or securities at a qualified custodian, because advisers are not customarily engaged in the business of custody and therefore, many of them may lack the relevant experience, expertise and/or necessary controls to effectively safeguard an asset. In addition, there may be heightened custodial risk when the adviser and the custodian are the same party so that the adviser can move client assets without contacting an unaffiliated custodian. When there is a clear distinction between the roles of the adviser (advising the client on the buying and selling of assets and implementing the client's investment strategy), an adviser is less likely to engage in unauthorized trading in a client's account. Because an adviser self-custodial role goes beyond the services customarily associated with advisory businesses and presents heightened concerns on conflicts of interest, the proposed requirements under the adviser self-custody rule are necessary to ensure that the adviser has the qualifications and experience necessary to adequately safeguard client assets.

We are thus proposing an adviser self-custody rule under the Advisers Act that would permit an adviser to hold client crypto assets for which it provides investment advice without maintaining them at a qualified custodian; provided that the adviser complies with conditions designed to safeguard the self-custodied crypto assets from loss, theft, misuse and misappropriation as well as the adviser's financial condition.[97] As discussed further below, an adviser that possesses any portion of the key materials to a client's crypto asset would have “self-custody” of the client's crypto asset, and would thus be required to comply with the proposed adviser self-custody rule with respect to that crypto asset.[98]

The application of the adviser self-custody rule's heightened safeguards to the protection of key materials is critical to the safekeeping of a client's crypto asset because, unlike mechanisms used to transact in more traditional assets, access to crypto assets generally requires the use of public and private cryptographic key pairings, and the loss or theft of key materials can result in the irreversible loss of crypto assets.[99] Whereas processes and protocols exist to reverse erroneous or fraudulent transactions with respect to traditional ( printed page 63881) assets, crypto networks, by design, generally make it difficult or impossible to reverse erroneous or fraudulent crypto asset transactions. Custodial risks associated with the immutability of records on crypto networks may be heightened in the context of permissionless crypto networks where anyone can participate in the network without permission, as opposed to permissioned crypto networks where participants must be approved in order to access the crypto network.[100] These specific characteristics of crypto assets put clients at risk of permanently losing their crypto assets or being unable to reverse erroneous or fraudulent transactions when key materials are lost or stolen. Because of these features and the highly interconnected nature of crypto networks, crypto assets are subject to heightened risks, such as the risk of loss and theft from cybersecurity attacks, as compared to the risks associated with traditional assets, thus necessitating highly specialized technical knowledge and capabilities as well as proficiency in cybersecurity practices, to adequately safekeep crypto assets and their associated key materials.

Although accounts of regulated funds are excepted from the application of the Advisers Act custody rule, the term “client,” for purposes of the proposed adviser self-custody rule would include regulated funds.[101] The current exception in the Advisers Act custody rule recognizes that the custody of regulated funds' assets is addressed by section 17(f) of the Investment Company Act and the rules thereunder.[102] The Investment Company Act and the rules thereunder, however, currently do not address self-custody of crypto assets by regulated funds. The heightened risk of loss and custodial challenges associated with crypto assets arise to the same extent across all advisory clients including regulated funds. Therefore, the safeguards in the proposed adviser self-custody rule are designed to protect crypto assets in the self-custody of registered advisers, regardless of the type of advisory client.

Rather than duplicating protections provided under the proposed fund self-custody rule under the Investment Company Act, the proposed adviser self-custody rule under the Advisers Act would apply to accounts of regulated funds as well. An adviser that has self-custody of crypto assets for accounts of regulated funds would thus be required to comply with the requirements of the proposed adviser self-custody rule under the Advisers Act with respect to those assets, although the adviser will continue to be excepted from the rest of the Advisers Act custody rule with respect to accounts of regulated funds.[103]

Consistent with the current scope of assets subject to the Investment Company Act and its custody rules for regulated funds, which apply to a regulated fund's securities and similar investments, when an adviser complies with the proposed adviser self-custody rule with respect to regulated funds, the scope of the rule would apply with respect to crypto assets that are “securities and similar investments,” to be consistent with the scope of the Investment Company Act custody rules. In order to effect this change, we are proposing to revise the lead-in language of the Advisers Act custody rule, which currently says, “If you are an investment adviser registered or required to be registered under section 203 of the Act (15 U.S.C. 80b-3), it is a fraudulent, deceptive, or manipulative act, practice or course of business within the meaning of section 206(4) of the Act (15 U.S.C. 80b-6(4)) for you to have custody of client funds or securities unless . . .” This proposal would amend the lead-in of the Advisers Act custody rule to state as follows: “If you are an investment adviser registered or required to be registered under section 203 of the Act (15 U.S.C. 80b-3), you must take the following steps to safeguard client funds and securities of which you have custody; provided that, where this section (17 CFR 275.223-1) applies to the account of a registered investment company or a business development company, references to funds and securities shall be understood to refer to the securities and similar investments held for such account.” [104] The scope of the Advisers Act custody rule will continue to apply to funds and securities with respect to advisory clients that are not regulated funds.

Moreover, in addition to the safeguards required of registered advisers with self-custody of crypto assets under the proposed adviser self-custody rule, a regulated fund's board of directors would need to engage in the oversight of the self-custody arrangement as required under the proposed fund self-custody rule under the Investment Company Act. This would allow regulated funds to place and maintain crypto assets with an adviser to the regulated fund, subject both to the protections in the proposed adviser self-custody rule and the regulated fund's board of director's oversight of the arrangement under the proposed fund self-custody rule.[105]

An adviser that has self-custody of crypto assets would be required to comply with the proposed adviser self-custody rule's requirements. As discussed in more detail in subsequent sections below, as an initial matter and no less than quarterly, the adviser would need to determine, and record in writing, that a qualified custodian is not available to maintain the crypto asset.[106] In order to help ensure that only those advisers who are well-suited and have the capabilities to safeguard crypto assets have self-custody of client crypto assets, the proposed adviser self-custody rule would also require the adviser to have expertise regarding the safeguarding of each crypto asset; to document in writing the basis of such determination; and to adopt, implement, and maintain the systems necessary to safeguard each crypto asset against loss, theft, misuse, and misappropriation.[107]

Although the proposed adviser self-custody rule would not prescribe specific technical requirements for the adviser's safeguarding systems, the adviser's safeguarding systems would need to address, at a minimum, the following core elements designed to safeguard the crypto assets:

Other required safeguards under the proposed adviser self-custody rule include implementing cybersecurity controls [109] and obtaining an annual internal control report prepared by an independent public accountant.[110] The proposed adviser self-custody rule would also require an adviser to annually review, and to document its review in writing, the adviser's safeguarding systems and cybersecurity controls implemented pursuant to the adviser self-custody rule and the effectiveness of their implementation.[111] In addition, the proposed adviser self-custody rule would require an adviser to send quarterly account statements, or alternatively, to transmit or arrange for the transmission of information required in account statements at least quarterly in a human-readable and reasonably usable electronic format, to advisory clients for which they self-custody crypto assets.[112] Finally, the proposed adviser self-custody rule would require an adviser and its client to agree in writing to treat each crypto asset in the adviser's self-custody as a financial asset and that the adviser holding the client's crypto asset in self-custody is a securities intermediary pursuant to applicable State law that governs the written agreement between the adviser and the client.[113]

Structurally, the proposed adviser self-custody rule would be an exception from certain requirements of the Advisers Act custody rule, including the qualified custodian requirement.[114] The proposed adviser self-custody rule would also be an exception from the requirement to notify the client in writing of certain information if the adviser opens an account with a qualified custodian on the client's behalf and to have a reasonable basis, after due inquiry, for believing that the qualified custodian sends quarterly account statements to clients.[115] Advisers would remain subject to the other applicable portions of the Advisers Act custody rule unless eligible for a specific exception. For example, advisers subject to the Advisers Act custody rule must obtain a surprise examination at least once each calendar year verifying client funds and securities of which the adviser has custody, unless, for instance, the adviser manages a pooled investment vehicle subject to an annual financial statement audit by an independent public accountant.[116] Advisers with self-custody of crypto assets on behalf of an account of a regulated fund would only need to comply with the proposed adviser self-custody rule with respect to such crypto assets, and would remain excepted from the other parts of the Advisers Act custody rule with respect to the account of a regulated fund.[117]

In connection with the proposed adviser self-custody rule, we are proposing amendments to the Form ADV, Part 1A, to add new questions that would require the adviser to disclose certain information regarding its crypto asset self-custody practices.[118] We also discuss below disclosures regarding the material risks and conflicts of interest associated with self-custody of client crypto assets that advisers may need to provide in their brochures as well as separately to their clients pursuant to their fiduciary duty.[119]

Although the proposed adviser self-custody rule is designed to be generally flexible and principles-based in order to adapt to developments over time, we remind advisers to also consider, as fiduciaries, their fiduciary obligations when they have self-custody of client crypto assets. An adviser's fiduciary duty, which comprises a duty of loyalty and a duty of care, requires the investment adviser to act in the best interests of its client at all times and to not subordinate its client's interest to its own.[120] Under its duty of loyalty, an investment adviser must eliminate or make full and fair disclosure of all conflicts of interest which might incline an investment adviser—consciously or unconsciously—to render advice which is not disinterested such that a client can provide informed consent to the conflict. This fiduciary duty extends to client funds and securities, and securities and similar investments with respect to advisory clients that are regulated funds, in the adviser's custody.[121] Therefore, an adviser that fails to take reasonable steps to safeguard self-custodied crypto assets or that misappropriates or misuses those assets would be acting in a manner inconsistent with the client's best interests and the adviser's fiduciary duty. Loss of client crypto assets in the adviser's self-custody resulting from the adviser's failure to take such reasonable steps may be a violation of its duty of care, while an adviser that misappropriates client crypto assets in self-custody would be breaching its duty of loyalty. An adviser's failure to make full and fair disclosure of the conflicts of interest arising from the self-custodial arrangement in order to allow the client to provide informed consent to such conflicts would be a breach of the adviser's duty of loyalty. Although the specific obligations that flow from the adviser's fiduciary duty depend on what functions the adviser has agreed to assume for the client, the relationship in all cases remains that of a fiduciary to the client and may not be waived.[122] We request comment on the proposed adviser self-custody rule under the Advisers Act:

1. Pursuant to the proposed adviser self-custody rule, an adviser would be permitted to have self-custody of a client's crypto asset without maintaining it at a qualified custodian, ( printed page 63883) provided that the adviser complies with the requirements of the proposed adviser self-custody rule. Should an adviser be permitted to have self-custody of client crypto assets, including crypto assets of a regulated fund, as proposed? Why or why not?

2. Do commenters agree that qualified custodian availability is a particularly acute problem for certain kinds of crypto assets, such as nascent or novel crypto assets? If so, what types of crypto assets raise heightened challenges to finding available qualified custodians to maintain them? To what extent would the proposed rule permitting crypto asset custody at State trust companies discussed below (see section II.C) alleviate these challenges? [123]

3. The Advisers Act custody rule excepts securities that meet the description of privately offered securities from the qualified custodian requirement on the basis that they are hard to steal.[124] Privately offered securities are securities that are: (i) acquired from the issuer in a transaction or chain of transactions not involving any public offering; (ii) uncertificated, and ownership thereof is recorded only on the books of the issuer or its transfer agent in the name of the client; and (iii) transferable only with prior consent of the issuer or holders of the outstanding securities of the issuer. Crypto assets would not be able to meet this exception if, for example, records of their ownership are not recorded only on the books of the issuer or its transfer agent in the name of the client, or if they can be transferred without the prior consent of the issuer. Are there crypto assets that could qualify as privately offered securities? If so, what characteristics of such crypto assets and/or their crypto networks satisfy the conditions of the privately offered securities exception? If there are crypto assets that could qualify as privately offered securities, should the privately offered securities exception be amended to except the adviser from the conditions of the proposed adviser self-custody rule with respect to any such crypto assets in the adviser's self-custody? Why or why not? If yes, how should the privately offered securities exception be amended, if at all, to accommodate characteristics unique to securities that are crypto assets and what conditions should apply to such crypto assets under the exception to ensure that the privately offered securities exception continues to exempt only those crypto assets that have features similar to privately offered securities that provide external safeguards against the kinds of abuse the custody rule seeks to prevent?

4. Is our understanding correct that some advisers engage in extensive due diligence of a crypto asset beginning in its early stage development, and that such advisers may acquire expertise on the functioning and operation of the associated crypto network, potentially allowing them to be well-positioned to securely self-custody the crypto asset? If not, why not? How does the adviser's due diligence of the crypto asset position the adviser to be better situated than a traditional custodian to custody the crypto asset? Does the adviser's involvement via the due diligence of the crypto asset create or enhance any conflicts of interest that the proposed custody rule amendments should uniquely address?

5. In a Commission interpretation addressing the application of certain Federal securities laws to certain types of crypto assets and certain transactions involving crypto assets, the Commission stated that non-security crypto assets may be offered and sold subject to an investment contract, which is a security.[125] Is any guidance or additional changes to the Commission's custody rules needed to address non-security crypto assets that are subject to an investment contract?

6. Would the proposed safeguards under the adviser self-custody rule raise any particular challenges for smaller advisers or regulated funds with smaller advisers? If so, what could we do to help mitigate those challenges?

7. Are there any services or business practices engaged in by advisers that could cause an adviser to become subject to regulation or become regulated entities under other regulatory frameworks outside of the Commission's rules (for example, regulations governing banks and money transmitters) if advisers were permitted to hold crypto assets in self-custody pursuant to the adviser self-custody rule?

(b) Adviser Self-Custody Rule Terms and Definitions

We propose to amend the Advisers Act custody rule to add the following terms in connection with the proposed adviser self-custody rule: “crypto network,” “crypto asset,” “crypto asset address,” “key materials,” “self-custody,” “distributed crypto asset,” and “management persons.” As a relatively novel and highly technological asset class, it is important that terms related to crypto assets be defined appropriately so that they can be understood by all market participants, regardless of their technological sophistication. Given the rapid pace of innovation in the crypto asset markets, it also is important that the terms be both accurate with respect to the current state of the technology and sufficiently flexible to cover potential developments in the market to avoid a need to continually revisit and update the definitions. The definitions proposed herein are intended to be consistent with the definitions of applicable terms used in a prior Commission interpretation and staff statements.[126]

The proposed amendments to the Advisers Act custody rule would thus set forth the following definitions that would apply to crypto assets pursuant to the proposed adviser self-custody rule:

“Crypto asset” would mean any digital representation of value that is recorded on a cryptographically secured distributed ledger.[127] Consistent with the current scope of assets subject to the custody rule for advisers under the Advisers Act (which only applies to custody of client funds or securities) and the Investment Company Act and its custody rules for regulated funds (which apply to a regulated fund's securities and similar investments), crypto assets subject to the Advisers Act custody rule would only include crypto assets that are digital representations of funds ( e.g., cash, bank accounts, payment stablecoins issued by stablecoin issuers that are permitted payment stablecoin issuers under the GENIUS Act or foreign payment ( printed page 63884) stablecoin issuers registered pursuant to section 18 of the GENIUS Act,[128] tokenized deposits) or securities, or with respect to crypto assets self-custodied for the accounts of regulated funds, that are securities or similar investments.[129] For purposes of the Advisers Act custody rule, crypto assets would include, but are not limited to, crypto assets that are native to a particular crypto network.[130] Crypto assets native to a crypto network include native digital commodities ( e.g., Bitcoin (BTC), Ether (ETH), Solana (SOL)) that, although they are generally not subject to the Advisers Act custody rule with respect to advisory clients that are not regulated funds because they are not funds or securities,[131] would qualify as “securities and similar investments” subject to the proposed Advisers Act custody rule to the extent an adviser holds them in self-custody pursuant to the proposed adviser self-custody rule for the account of a regulated fund.[132] Crypto assets would also include digital securities (commonly known as “tokenized” securities), which are financial instruments enumerated in the definition of “security” under the Federal securities laws that are formatted as or represented by a crypto asset, where the record of ownership is maintained in whole or in part on or through one or more crypto networks.[133]

“Crypto asset address” would mean the unique identifier on the crypto network that designates the destination for sending, receiving, and storing a crypto asset on the crypto network.[134] This term is used in the proposed segregation and self-custody account statement requirements under the proposed adviser self-custody rule.[135]

“Crypto network” would mean a blockchain or similar distributed ledger technology network.[136]

“Key materials” would mean the cryptographic private keys or any part thereof that is necessary to access and effectuate transactions in the corresponding crypto asset.[137] Because private keys control access to and movements of crypto assets, it is appropriate in our view to define key materials to refer specifically to private keys. The term “key materials” appears in the proposed definition of self-custody.[138] The term also appears in the proposed adviser self-custody rule's provision requiring advisers to adopt, implement and maintain systems that manage and protect key materials.[139] It is appropriate to include, in the definition for key materials, “any part” of the private key necessary to access and effectuate transactions in a crypto asset, because the loss of any portion of the private key could result in the inability to access the crypto asset, and the safekeeping of any and all parts of the private key held with an adviser in accordance with the proposed adviser self-custody rule's conditions is essential to the safeguarding of the crypto asset.

“Self-custody” would mean, with respect to crypto assets, possession of any portion of a client crypto asset's key materials.[140] Self-custody of crypto assets, however, would not include possession of key materials by the adviser or its related person solely in its capacity as a qualified custodian maintaining the crypto asset under proposed rule 223-1(a)(6) (the “related person QC rule”), as discussed further below in section II.A.1(c)(2). Relatedly, we also propose to amend the first prong of the definition of “custody” in the Advisers Act custody rule that addresses custody by way of possession of client funds or securities, to include possession of client crypto assets via self-custody.[141] This is because self-custody of the key materials to a client's crypto asset effectuates possession of the crypto asset. Moreover, registered investment advisers are subject to the Advisers Act custody rule only if they have custody of client funds or securities (or, under the proposed custody rule, custody of securities and similar investments with respect to advisory clients that are regulated funds) as “custody” is defined in the Advisers Act custody rule, and, by characterizing self-custody as a type of possession in the first prong of the custody definition, the proposed amendment is intended to help ensure that the crypto assets in the adviser's self-custody are afforded the protections under the proposed adviser self-custody rule.

“Distributed crypto asset” would mean a crypto asset received as a distribution for no or nominal consideration in connection, or as a result of activity associated, with a client's crypto asset in an adviser's custody.[142] This term, which is intended to be synonymous and used interchangeably with airdropped crypto assets in this proposal, is used in the proposed provision for distributed crypto assets that would allow advisers a grace period to come into compliance with the Advisers Act custody rule with respect to distributed crypto assets received unexpectedly.[143]

Finally, “management persons” would have the same meaning as set forth in Form ADV, Glossary of Terms.[144] This term is used in the proposed joint authorization requirement under the adviser self- ( printed page 63885) custody rule, which would require that at least one of the persons jointly authorizing a crypto asset transfer be a management person.[145]

We request comment on the proposed terms and definitions in connection with the adviser self-custody rule:

8. Are the terms and definitions proposed in connection with the proposed adviser self-custody rule (“crypto network,” “crypto asset,” “crypto asset address,” “key materials,” “self-custody” and “distributed crypto asset”) clear? Why or why not? Do they accurately reflect the current technology for crypto assets and are they flexible enough to accommodate technological developments in the future? Are there other definitions of these terms we should use? For example, given how fundamental the term “crypto asset” is to this proposal, is there a more specific definition we should consider? Is the definition too limiting or too encompassing? Does the definition for “crypto asset” scope in the appropriate range of assets as applied to registered advisers and regulated funds? Is the term “self-custody,” as used in this proposal, appropriate to describe an adviser holding a client's crypto asset, or a regulated fund holding through an adviser a crypto asset, without maintaining it with a permitted custodian? Instead of “self-custody,” is there a more apt term to describe such custodial arrangements for crypto assets?

9. Are there any defined terms that we either should not adopt or that we should change in the final rule? If so, please identify those defined terms along with any recommended changes to the definitions.

10. Are there additional terms used in the proposed adviser self-custody rule that we should define?

11. As noted above, the proposed Advisers Act custody rule would continue to apply to client assets that are funds or securities (and would be amended to apply to securities and similar investments held for the accounts of regulated funds that are subject to the proposed adviser self-custody rule), and we express our view that tokenized deposits and payment stablecoins issued by stablecoin issuers that are permitted payment stablecoin issuers under the GENIUS Act and foreign payment stablecoin issuers registered pursuant to section 18 of the GENIUS Act are crypto assets that are digital representations of funds subject to the Advisers Act custody rule. Are there other types of crypto assets, if any, that need clarification as to whether they are digital representations of “funds” subject to the Advisers Act custody rule, and why?

12. As noted above, “crypto asset” for purposes of this proposal would include digital securities, commonly known as “tokenized” securities. There are a variety of models used to tokenize securities, which may vary in terms of structure and the rights afforded to holders.[146] What guidance or adjustments to the Commission's custody rules, if any, are needed to address the custody of tokenized securities? Are there any circumstances in which maintaining the associated crypto asset at a permitted custodian, or in self-custody by an adviser pursuant to the proposed adviser self-custody rule, would not be sufficient to effectively hold the tokenized security in custody under the Commission's custody rules?

(c) Scope of Activity Subject to the Proposed Adviser Self-Custody Rule

Under this proposal, an adviser that has self-custody of client crypto assets would be required to comply with the proposed adviser self-custody rule with respect to those crypto assets. An adviser would have self-custody of a crypto asset if the adviser possesses any portion of a client crypto asset's key materials. As mentioned above, the proposal would add a new term “self-custody” to mean, with respect to a client's crypto asset, possession of any portion of the crypto asset's key materials.[147]

The proposed self-custody definition is intended to confer self-custody of a client's crypto asset and the attendant obligations under the proposed adviser self-custody rule on an adviser if the adviser possesses any portion of the key materials to the crypto asset. For purposes of the proposed adviser self-custody rule, an adviser would have self-custody of a crypto asset and would need to comply with the adviser self-custody rule's requirements with respect to such crypto asset only if the adviser actually possesses (rather than merely having the authority to obtain possession of) the key materials to the crypto asset.[148]

The proposed crypto self-custody definition reflects a longstanding principle of the definition of custody, under which the Advisers Act custody rule applies when an adviser has the ability to change a client's ownership and possession of its assets, since an adviser with this ability can subject a client's assets to the risks of loss, misuse, misappropriation, theft, or financial reverses of the adviser. For example, an adviser that physically holds a check drawn by the advisory client and made payable to a third party is not subject to the rule solely as a result of holding the check, since the adviser cannot use the check to change ownership of the client's underlying cash holdings.[149] An adviser with the full set of key materials over a crypto asset would have unilateral ability to change a client's ownership and possession of the crypto asset.

However, an adviser's possession of even a non-controlling portion of the key materials would subject its client's crypto assets to custody risks because loss of or unauthorized access to even a portion of the key materials could potentially result in the permanent loss of ownership and possession of the crypto asset, and consequently, harm to clients. Moreover, an adviser holding a crypto asset's key materials, regardless of whether they constitute a non-controlling share of the crypto asset's private keys, raises misappropriation risks because an adviser could coordinate with one or more other private key holders to conduct unauthorized actions with the crypto asset.

Guarding against potential loss and fraud is particularly important in the context of crypto assets due to the immutability of most crypto asset transactions and the bearer nature of many crypto assets and their associated key materials, which create a heightened risk that any loss of the crypto assets would be irreversible. Moreover, crypto assets held with an adviser are subject to higher custodial risks such as the risk of loss, theft, misuse, misappropriation as well as the adviser's financial reverses, as compared to maintaining them at a qualified custodian, because advisers are not customarily engaged in the business of custody and therefore, many of them may lack the relevant experience, expertise and/or necessary controls to effectively safeguard a crypto asset. The application of the proposed adviser self-custody rule's heightened safeguarding requirements to an adviser with self-custody of client crypto assets is intended to ensure that an adviser that holds any key materials to the ( printed page 63886) crypto assets takes affirmative steps to safeguard them against the custodial risks that the Advisers Act custody rule is designed to protect against. Moreover, an adviser may self-custody crypto assets only in the limited circumstances when a qualified custodian is not available and when the adviser has the appropriate expertise and custodial infrastructure to mitigate against such risks.

(1) Use of Service Providers

The proposed adviser self-custody rule is not intended to preclude an adviser from engaging third parties (including related persons) as service providers to support its crypto asset self-custody and to help administer the required safeguards under the proposed adviser self-custody rule, provided the adviser exercises appropriate oversight and continues to comply with the substantive requirements of the adviser self-custody rule. For example, an adviser may engage the services and personnel of a third party or a related person with cybersecurity expertise in order to implement cybersecurity controls required under the proposed adviser self-custody rule.[150] In these instances, however, the adviser would ultimately remain responsible for its compliance with the requirements of the proposed adviser self-custody rule, and violations of the adviser self-custody rule resulting from the adviser's use of third parties or related persons engaged to administer the adviser's self-custody program would not waive nor reduce the adviser's obligation to comply with the custody rule or to meet its fiduciary duty.

An adviser may also engage a service provider to license the provider's cryptographic wallet technology and/or software platform to manage the key materials rather than build its own technology in-house, provided that the service provider of the wallet technology does not have access to the crypto asset's key materials nor otherwise have the ability to unilaterally move a client's crypto asset. For purposes of this release, a cryptographic wallet (also referred to as “wallet” or “crypto wallet” herein) is software or hardware that is used to store a crypto asset's private key.[151] For example, providers may provide the wallet technology to generate and/or maintain the key materials as well as backup recovery services to reset a crypto asset's key materials when they are lost or damaged.[152] In some instances, the crypto wallet provider may also be the provider of the user interface, provided by a website, browser extension, or other software application ( e.g., mobile application), that may be embedded in a wallet or separately available for download, designed to assist users engaging in user-initiated crypto asset transactions on blockchain protocols (or blockchain-based smart contracts) utilizing the user's wallet (“covered user interface”).[153] A crypto wallet is self-custodial if neither the provider of the wallet nor the wallet's associated covered user interface has custody of, or access to, the wallet user's encrypted or decrypted private key.[154]

An adviser could not satisfy the proposed adviser self-custody rule if it places a client's crypto asset in a wallet technology or other key management platform that is not self-custodial, or if such service provider otherwise is able to access and/or unilaterally move a client's crypto asset through its services. For example, the adviser would not be able to satisfy the rule requirement to limit access to key materials to only designated persons that are supervised persons of the adviser, if a third party has access to a client's crypto asset.[155] Therefore, in order to ensure their compliance with the proposed adviser self-custody rule, it is our view that advisers would need to determine as part of their due diligence of these service providers prior to engaging them whether or not the service providers' capabilities give them access to the key materials and/or other means to unilaterally move a client's crypto asset.

(2) Crypto Asset Custody Not Subject to Adviser Self-Custody Rule

An adviser that does not have self-custody of a client's crypto assets ( i.e., because the adviser does not possess any portion of the crypto asset's key materials) would not be required to comply with the proposed adviser self-custody rule, although it would be required to comply with other applicable provisions of the Advisers Act custody rule with respect to client crypto assets of which the adviser has custody for other reasons besides self-custody.

The Advisers Act custody rule defines “custody” as holding, directly or indirectly, client funds or securities, or having any authority to obtain possession of them.[156] An adviser also has custody if a related person holds, directly or indirectly, client funds or securities, or has any authority to obtain possession of them, in connection with advisory services the adviser provides to clients.[157] Proposed rule 223-1(d)(6) would retain the three prongs provided in the current definition of custody where custody of client funds or securities is conferred on an adviser in the following arrangements: (i) Possession of client funds or securities (including, pursuant to this proposal, possession of client crypto assets via self-custody) (but not of checks drawn by clients and made payable to third parties) unless the adviser receives them inadvertently and returns them to the sender promptly but in any case within three business days of receiving them; (ii) any arrangement (including a general power of attorney) under which the adviser is authorized or permitted to withdraw client funds or securities maintained with a custodian upon the adviser's instruction to the custodian; and (iii) any capacity (such as general partner of a limited partnership, managing member of a limited liability company or a comparable position for another type of pooled investment vehicle, or trustee of a trust) that gives the adviser or its supervised person legal ownership of or access to client funds or securities.[158]

Custody could arise pursuant to paragraph (ii) or paragraph (iii) under the definition of “custody” in the Advisers Act custody rule. For instance, mere authority to obtain possession of ( printed page 63887) the key materials to a client's crypto asset, without actually possessing the key materials, would not impute self-custody of the crypto asset to an adviser. However, such authority would nevertheless confer on the adviser custody of the crypto asset, because the adviser effectively has the authority to obtain possession of the crypto asset.[159] An adviser with custody, but not self-custody, of the crypto asset, would not need to comply with the proposed adviser self-custody rule. The adviser would, however, be subject to other applicable portions of the custody rule, for instance, the qualified custodian requirement and the annual surprise examination requirement, unless an exception applies.

An adviser would also, under paragraphs (ii) and (iii) of the definition of custody, have custody of crypto assets in which a private fund client is invested if the adviser or its related person has power of attorney with respect to the private fund's crypto assets and/or is a general partner of the private fund; however, the adviser would not have self-custody of those crypto assets, and would not be required to comply with the proposed adviser self-custody rule with respect to those assets, if the private fund's crypto assets and their associated key materials are maintained at a qualified custodian. To avoid having self-custody and being subject to the attendant requirements, an adviser intending to place and maintain a client's crypto asset at a qualified custodian would not be able to hold any portion of the crypto asset's private key materials. In such a case, the adviser would not be able to satisfy the self-custody requirement, because an adviser can only hold a crypto asset in self-custody if no permitted custodian is available.[160]

The proposed adviser self-custody rule would not apply to crypto assets that are maintained by an adviser or its related person, in each case acting in its capacity as a qualified custodian. The proposed self-custody definition would state that an adviser does not have self-custody of a crypto asset if the adviser or a related person possesses key materials associated with that crypto asset solely in its capacity as a qualified custodian maintaining the crypto asset under the related person QC rule. Likewise, although custody would be imputed to an adviser if its related person maintains client crypto assets as a qualified custodian in connection with advisory services provided by the adviser, the adviser would not have self-custody of the crypto assets if all of their associated key materials are held by the related person acting as a qualified custodian. In both instances, where the adviser itself or its related person acts as a qualified custodian to hold client crypto assets and their key materials, the related person QC rule, rather than the proposed adviser self-custody rule, would apply.

Advisers relying on the related person QC rule in these custodial arrangements would remain obligated to comply with the other applicable provisions under the Advisers Act custody rule such as the notice and account statement delivery requirements, unless an exception applies (for instance, the audit provision).[161] The application of the related person QC rule, as opposed to the proposed adviser self-custody rule and the heightened safeguards thereunder, is appropriate in these arrangements, because crypto assets in those instances would be maintained by a traditional custodian entity that is customarily engaged in the business of custody and is subject to other extensive regulatory requirements that govern traditional custodians.

We request comment on the proposed scope of activities that would be subject to the adviser self-custody rule and the related proposed definition of self-custody:

13. Is the proposed definition for self-custody appropriate in imputing self-custody to an adviser that possesses any portion (including a non-controlling share) of the key materials associated with its client's crypto asset? If not, what portion of a crypto asset's key materials in an adviser's possession should confer self-custody on the adviser and trigger the application of the self-custody requirements to the adviser? For example, should self-custody be conferred on an adviser only when the adviser holds all or a controlling share of the key materials? How should a “controlling” private key share be defined for this purpose? If the custody rule did not confer self-custody on an adviser that holds a non-controlling portion of the key materials, what protections, if any, should instead apply to ensure that the key materials held with the adviser are appropriately safeguarded and how, if at all, should such protections differ from the conditions in the proposed adviser self-custody rule?

14. Currently, under what circumstances, if any, is the private key to a client's crypto asset shared among the adviser and third parties? Which parties in those circumstances would hold the shares of a private key, and for what purpose? For example, do wallet solution providers ever need to retain a portion of the user's key materials? Is doing so necessary to enhance the security of key materials?

15. Under this proposal, a qualified custodian maintaining a client's crypto asset would not be able to share the key materials to the crypto asset with an adviser because, if the adviser held any portion of the key materials, the adviser would be required to comply with the self-custody requirements, which are limited to circumstances where no qualified custodian is available. Are there circumstances today in which a qualified custodian ( e.g., a bank) would maintain a client's crypto asset and some portion of its key materials while the adviser retains a non-controlling portion of the key materials, such that the adviser does not have the unilateral ability to access and/or move the crypto asset? If so, what would be the purpose of these arrangements? Are custodial risks, such as the risk of misappropriation by the adviser or the loss of the crypto asset resulting from the loss of any private key held with the adviser, mitigated in these arrangements, so that only some of the proposed adviser self-custody rule's requirements (or none at all) should apply to the adviser? If yes, which of the proposed adviser self-custody rule's requirements should apply to the adviser in these arrangements? In such arrangements, should the adviser self-custody rule apply only to the portion of the key materials held with the adviser, and should other applicable requirements under the Advisers Act custody rule ( e.g., the qualified custodian requirement, the notice requirement, and the account statement delivery requirement) apply to the portion of the key materials held with a qualified custodian? Would it be possible, in practice, to apply the Advisers Act custody rule to different shares of key materials distributed between a qualified custodian and an adviser?

16. Alternatively, are there circumstances in which a qualified custodian would share the key materials to a client's crypto asset with the adviser, such that neither the adviser nor the qualified custodian would have exclusive control over the crypto asset? If so, what would be the purpose of these arrangements? If yes, would the qualified custodian and the adviser share control over the crypto asset, or would each independently have control ( printed page 63888) over the crypto asset, in that each party independently would have the unilateral ability to access and move the crypto asset? Is the loss of the crypto asset resulting from the loss of any private key share mitigated or increased in these arrangements where neither the adviser nor the qualified custodian has exclusive control over the crypto asset?

17. Under this proposal, the proposed related person QC rule, as opposed to the adviser self-custody rule, would apply to custodial arrangements where the adviser, or its related person, holds all of the key materials to a client's crypto asset, in each case in its capacity as a qualified custodian. Should the proposed adviser self-custody rule apply instead of the related person QC rule to these arrangements? Why or why not? Would the proposed related person QC rule and the internal control report requirement thereunder, as proposed, sufficiently address risks of adviser fraud and misappropriation through the adviser and its related persons that are qualified custodians maintaining client crypto assets? [162]

18. Are there circumstances today in which an adviser's related person that is a qualified custodian would share a client crypto asset's key materials with a qualified custodian that is not the related person of an adviser? How should the requirements of the related person QC rule apply to those arrangements?

19. The Advisers Act custody rule sets forth conditions that must be met in order to overcome the presumption that a related person of the adviser is not operationally independent of the adviser.[163] Are there circumstances today in which an adviser's use of a related person that is operationally independent of the adviser would raise issues related to the proposed adviser self-custody rule? For example, do advisers today utilize related persons that are operationally independent of the adviser to hold client crypto assets outside of a traditional custodian, and if so, what functions do such related persons serve for purposes of self-custody, and how do advisers oversee the practices of such related persons in light of their operational independence from the adviser?

20. In what circumstances, if any, would multiple qualified custodians need to hold copies of the key materials to a crypto asset or share portions of the key materials to a crypto asset? Should the Advisers Act custody rule prohibit the sharing of access to a client crypto asset's key materials by multiple qualified custodians? Why or why not?

21. Is our view provided under section II.A.1c)(1) (“Use of Service Providers”) regarding the use of service providers and related persons sufficiently clear? Should we provide any additional clarification regarding an adviser's use of service providers and related persons for purposes of the proposed adviser self-custody rule? If so, what clarifications are needed? What, if any, additional protections are needed in self-custody arrangements for crypto assets that involve the use of service providers and related persons? What arrangements involving the use of service providers and/or related persons for purposes of crypto asset custody that are commonly in place today would be prohibited by limiting access to crypto asset key materials to qualified custodians and registered investment advisers complying with the adviser self-custody rule?

22. Are there any instances today where a service provider (including a related person that is not a registered adviser) could have possession and control of a crypto asset even without access to the key materials to such crypto asset? If so, for what services are those providers used, and what protections are in place to prevent such service providers from unilaterally and impermissibly moving a crypto asset for unauthorized purposes?

23. In what circumstances, if any, does a service provider have access to a portion, but not all, of a crypto asset's key materials? Do service providers in those instances have possession and control of the crypto asset, or otherwise the ability to unilaterally move a crypto asset? Notwithstanding whether a service provider in those instances has the unilateral ability to move a crypto asset, does a service provider having access to a portion of the key materials still raise custodial risks such as the risk of loss resulting from the loss of the key share? If not, should the adviser be permitted to engage such service provider, and if so, what protections should apply to those arrangements where a service provider has access to a portion of the key materials, to ensure that such access does not result in the loss or theft of the crypto asset?

24. Are commenters aware of any examples of advisers using related persons that are not qualified custodians to safeguard crypto assets including their key materials? If so, what type of entities are such related persons that provide custodial services for client crypto assets in an adviser's custody? Are these examples necessary and helpful to investor protection? Why or why not?

25. Do advisers anticipate that they would enter into separate custodial agreements with clients for whom they hold crypto assets in self-custody, or would advisers specify the terms and conditions of self-custody services within the client's overall investment advisory agreement? Whether reflected in a separate agreement with the client or otherwise, an adviser holding a client's crypto asset in self-custody—and not any third party assisting the adviser in these efforts—would be responsible for the safekeeping of the crypto asset and compliance with the proposed adviser self-custody rule. Should the adviser be required to acknowledge and clearly delineate this responsibility in an agreement with the client?

26. Is our understanding correct that some third-party service providers offer key backup and recovery services? From a technical standpoint, what steps are involved in the key recovery process and which parties ( e.g., the adviser, the client, the service provider) are required to be involved when the service provider recovers key materials? Could the key materials ever be recovered or reset in a way that would grant the service provider access to and control of the key materials, or deny the adviser exclusive access to and control over the key materials? If yes, under what circumstances could this occur? If not, what technology prevents this from happening? Could an adviser's non-payment for the provider's services ever result in the service provider gaining control of the adviser's key materials or the service provider preventing the adviser from accessing the key materials? What technology prevents the service provider from doing this?

27. In what circumstances, if any, would an adviser have the authority to obtain possession of a client's crypto asset's key materials, but not actually possess the key materials? In what circumstances, if any, would an adviser have the authority to obtain possession ( printed page 63889) of, but not actually possess, only a portion of the key materials to a client's crypto asset? Is it more difficult for an adviser to misappropriate or lose a crypto asset when it has the authority to obtain possession of only a portion of a crypto asset's key materials? Why or why not? If yes, should the custody rule's protections apply to such crypto asset differently, and if so, how?

(d) Airdropped Crypto Assets

The proposed Advisers Act custody rule would include a provision that would deem the receipt of distributed crypto assets ( i.e., airdropped crypto assets) to not be in violation of the Advisers Act custody rule, provided that, as soon as reasonably practicable, the adviser either (i) comes into compliance with the requirements of the adviser self-custody rule with respect to such distributed crypto asset; or (ii) places and maintains the distributed crypto asset at a permitted custodian (“adviser airdrop provision”).[164]

For clients that are regulated funds, we are also proposing a parallel provision under the Investment Company Act that, consistent with the proposed amendments to the Advisers Act custody rule, would deem the receipt of distributed crypto assets to not be in violation of section 17(f) of the Investment Company Act and the rules thereunder, provided that, as soon as reasonably practicable, the regulated fund places and maintains the distributed crypto asset with (i) an investment adviser to the regulated fund in compliance with proposed rule 17f-9(b); or (ii) a permitted custodian in compliance with section 17(f) of the Investment Company Act or the rules thereunder (“fund airdrop provision,” and together with “adviser airdrop provision,” “airdrop provisions”).[165] The proposed fund airdrop provision, part of the fund self-custody rule, would apply to all regulated funds and would provide that a “distributed crypto asset” has the same meaning as in the proposed adviser airdrop provision.[166]

In some circumstances, a crypto asset may be broadly distributed, or “airdropped,” to a large number of crypto wallet addresses in exchange for no or nominal consideration.[167] For example, an issuer of a crypto asset may, usually in the early stages of development of a crypto system, effectuate an airdrop by transferring its crypto asset to specific cryptographic wallets or other addresses.[168] An issuer of a crypto asset may airdrop crypto assets to recipients that it chooses for a variety of reasons. For example, crypto assets may be airdropped to cryptographic wallets holding another specified crypto asset, with or without minimum ownership thresholds of that other crypto asset, or to selected users of a crypto system for meeting specific criteria, such as holding a minimum amount of the crypto asset or based on their prior or current level of activity with the associated crypto system.[169] An adviser that has self-custody of a crypto asset could receive a separate, new crypto asset in an airdrop by virtue of holding the first crypto asset on behalf of a client. Advisers may also receive new crypto assets through an airdrop as reward distributions on the crypto network in connection with staking or trading a client's crypto asset on that network.[170] Airdrops may facilitate the implementation of a client's investment objectives because the airdropped crypto asset may allow an adviser to generate returns for the client, for example by selling the airdropped crypto asset to generate returns for a profit.

An adviser holding a client's crypto asset at a qualified custodian or in self-custody under the proposed adviser self-custody rule may receive a new crypto asset through an airdrop with little or no advance notice. Likewise, a regulated fund holding a crypto asset in self-custody through its investment adviser, may also unexpectedly receive a new crypto asset through an airdrop. In some cases, a permitted custodian may not immediately offer custodial services for the airdropped crypto asset, and immediate compliance with the proposed adviser and fund self-custody rules' requirements with respect to an airdropped crypto asset received with little or no advance notice would not be possible. For example, an adviser may receive a new crypto asset through an airdrop in connection with a crypto asset held in self-custody before the adviser has had an opportunity to assess whether an appropriate qualified custodian is available to maintain the airdropped crypto asset and to determine whether holding such crypto asset in self-custody would be compliant with the adviser self-custody rule.[171] A crypto asset may also be airdropped into a wallet held for a regulated fund with no advance notice and before the regulated fund's board makes the requisite determinations under the proposed fund self-custody rule regarding the availability of a permitted custodian to hold the airdropped crypto asset and the adviser's self-custody arrangement for the asset.[172]

As the proposed adviser self-custody rule requires an adviser to have the relevant expertise and safeguarding systems particularized to each crypto asset in self-custody, an adviser may also need time to evaluate whether its existing expertise and systems in place are appropriate to self-custody the airdropped crypto asset, and if necessary, time to develop and onboard the relevant expertise and systems to safeguard the airdropped crypto asset.[173]

Accordingly, in these circumstances, the proposed adviser airdrop provision on distributed crypto assets would provide that the receipt of a distributed crypto asset would not be in violation of the Advisers Act custody rule provided that, as soon as reasonably practicable, the adviser complies fully with the requirements of the proposed self-custody rule with respect to such distributed crypto asset, or, alternatively, places and maintains the distributed crypto asset with a qualified custodian, if available. We are also proposing the fund airdrop provision for regulated funds for the same reasons discussed above. A regulated fund, like any other client of an adviser, may receive a new crypto asset through an airdrop with little or no advance notice and face the same custodial challenges discussed above.

The proposed airdrop provisions are intended to provide an adviser and a regulated fund a grace period to comply ( printed page 63890) with the Advisers Act and the Investment Company Act custody rules, as applicable, upon an unexpected receipt of an airdropped crypto asset with little or no advance notice. Both airdrop provisions do not specify the time period by which the adviser or the regulated fund must come into compliance with the applicable custody rules, because the amount of time needed depends on the facts and circumstances. Accordingly, under the proposed airdrop provisions, the adviser or a regulated fund, as applicable, must, as soon as reasonably practicable, either comply with the applicable self-custody rules if the adviser will hold the crypto asset in self-custody, or otherwise place and maintain the distributed crypto asset with a permitted custodian.

An adviser that seeks to self-custody a distributed crypto asset in reliance on the proposed adviser airdrop provision would need to build or adapt as necessary and as quickly as its systems and resources practicably allow its safeguarding systems and self-custody controls to accommodate the airdropped crypto asset. Consequently, we expect that an adviser that self-custodies the distributed crypto asset in reliance on the proposed adviser airdrop provision would be able to satisfy, and should come into compliance with, certain provisions of the proposed adviser self-custody rule more quickly than others, for instance, the self-custody account statement and the financial asset election requirements discussed later in this proposal.[174]

We request comment on all aspects of the proposed airdrop provisions:

28. Are there any circumstances where an adviser would receive distributed crypto assets in connection with its advisory services but of a different kind from the crypto assets already in the adviser's self-custody or maintained at a qualified custodian? How much advance notice, if any, would an adviser typically have of an upcoming airdrop? If the adviser receives an airdrop in connection with a crypto asset held in custody for a client, whether in the adviser's self-custody or maintained at a qualified custodian, to what extent would the custodial infrastructure developed in connection with the client's initial crypto asset be expected to apply to the airdropped crypto asset? To what extent would a qualified custodian be able to accommodate, or an adviser be able to adapt its self-custody infrastructure in order to hold, an airdropped crypto asset in full compliance with the Advisers Act custody rule upon receipt of the airdropped crypto asset?

29. Do advisers enter into written agreements with clients that include provisions relating to the custody treatment of distributed crypto assets? What do custodial agreements typically provide for with respect to the custody treatment of distributed crypto assets?

30. Should the airdrop provisions impose an outer limit of the time period within which an adviser and a regulated fund must come into full compliance with the Advisers Act and Investment Company Act custody rules, as applicable, with respect to an airdropped crypto asset, and if so, what should that time period be ( e.g., no later than 30 business days, 60 days, or 90 days, after receipt of the airdrop), and why? In the case of airdropped crypto assets received for the account of a regulated fund, should the time period within which the regulated fund's board must make the requisite determination pursuant to rule 17f-9 be more specific (for example, within 2 months of receiving the airdropped crypto asset or by the next regularly scheduled board meeting)?

31. When an adviser receives a distributed crypto asset in connection with its advisory services relating to crypto assets in its self-custody, how does the adviser ensure that the distributed crypto asset is correctly allocated to the relevant client? Does the adviser receive the distributed crypto asset in the wallet that holds the key materials to the crypto asset self-custodied for the corresponding client? Are there any circumstances where the distributed crypto asset is distributed into an adviser's proprietary wallet, or the wallet of another client? Would the proposed segregation requirement under the adviser self-custody rule as discussed later in this proposal help ensure that distributed crypto assets are correctly allocated to the relevant parties? Are there any circumstances where an adviser treats a distributed crypto asset received in connection with its advisory services as belonging to the adviser, as opposed to the client, and if so, what are those circumstances? Should any amendments to the Advisers Act custody rule address the allocation of distributed crypto assets received in connection with the adviser's custody of client crypto assets?

32. Are there any limited exigent circumstances where an adviser or a regulated fund could unexpectedly receive a crypto asset, other than an airdropped crypto asset, in connection with the adviser's advisory services provided to a client including a regulated fund? If so, what are those circumstances? For example, if the permitted custodian holding a client's crypto asset suddenly becomes unavailable to hold the crypto asset, should the adviser be required to comply immediately with the proposed self-custody rules or otherwise cease to hold the crypto asset? Should the airdrop provisions be expanded to more generally cover such crypto assets received in these or other limited exigent circumstances?

33. The proposed fund airdrop provision would largely mirror the conditions set forth in the proposed adviser airdrop provision. We request comment on all of the matters discussed in the above requests for comment as applied to the proposed fund airdrop provision for regulated funds. Is there a reason to address the receipt of distributed crypto assets differently for regulated funds as compared to other kinds of advisory clients?

34. Is the scope of the proposed fund airdrop provision under the Investment Company Act for regulated funds, i.e., registered management investment companies and business development companies, appropriate? Do UITs, which hold an unmanaged portfolio, receive airdrops such that the fund airdrop provision under the Investment Company Act should include UITs in addition to registered management investment companies?

2. Qualified Custodian Determination

The proposed adviser self-custody rule would require an adviser to make a determination in writing, prior to taking self-custody of each crypto asset and no less frequently than quarterly thereafter, that the adviser has a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset (a “QC determination”).[175] This QC determination would be a prerequisite to an adviser taking self-custody of a client's crypto asset. For accounts of regulated funds, advisers would be required to make this determination as to the availability of custodians authorized to serve as a custodian for the regulated fund under the Investment Company Act and applicable rules thereunder.[176] This is because an ( printed page 63891) adviser assessing the availability of, and services provided by, custodians for a regulated fund would have to assess the types of custodians permitted to serve as the regulated fund's custodian. If the adviser determines that a qualified custodian has become available to maintain the client's crypto asset, the adviser must place such crypto asset with the qualified custodian as soon as reasonably practicable.

The proposed QC determination requirement is meant to mitigate custodial compliance challenges for certain crypto assets that advisers may face today.[177] While maintaining client crypto assets at a qualified custodian would decrease the risk of misappropriation of those assets by the adviser as compared to holding crypto assets in the adviser's self-custody, there may be limited availability of traditional custodians offering custodial services for certain types of crypto assets of interest to investors.[178] For example, an adviser may struggle to find a qualified custodian for a particular type of crypto asset, such as a nascent crypto asset, because no qualified custodian has yet developed the requisite technological sophistication or procedural safeguards to hold that crypto asset while an adviser, for example, that had conducted extensive due diligence of the nascent crypto asset and its associated crypto network in its early-stage development, may have already developed the expertise to well-position itself as a potential custodian of that crypto asset.[179] The QC determination requirement is thus designed to allow adviser self-custody of client crypto assets only when, as a threshold matter, there is a need for an alternative to a qualified custodian. This approach is also consistent with the approach suggested in many of the Crypto Task Force comment letters that advocated for a crypto self-custody solution.[180]

The proposed adviser self-custody rule would require an adviser to make the QC determination, in writing, prior to taking self-custody of each crypto asset.[181] This means that an adviser would need to make a QC determination individualized to each crypto asset; an adviser would not be allowed to make a blanket QC determination covering all types of crypto assets. This is because the custodial capabilities and availability of qualified custodians may differ depending on the particular crypto asset in question, and the individualized determination would enable advisers to conduct the requisite due inquiry to form its reasonable basis for believing that an appropriate qualified custodian is not available with respect to each crypto asset.

We do not intend for the proposed adviser self-custody rule to require an adviser to conduct boundless analysis or the identification of every possible custodian to confirm no qualified custodian exists to hold the crypto asset. Rather, the proposed adviser self-custody rule would require an adviser to form a reasonable basis, upon due inquiry, for believing that no qualified custodian will maintain a crypto asset. We anticipate that the adviser's reasonable basis for its QC determination would be formed by due inquiry of material facts concerning, among other things, each individual crypto asset and its characteristics; the custodial marketplace for the crypto asset; and whether custodians generally known in the custodial marketplace provide custodial services for a crypto asset in question. For example, an adviser could form its QC determination if reasonable due diligence of generally known custodians in the crypto custody market reveal that those custodians have not developed the infrastructure to support custody of a particular crypto asset. The proposed adviser self-custody rule would not permit the adviser to make the QC determination based on the costs associated with engaging a qualified custodian. The cost of utilizing a custodian is not relevant to whether a custodian has the appropriate capabilities to custody and safeguard client assets against loss, theft, misuse and misappropriation, and therefore does not serve the custody rule's policy objective of protecting investors and their assets from harm.

The proposed adviser self-custody rule would also require an adviser to reassess the QC determination, in writing, no less frequently than quarterly after taking self-custody of each crypto asset.[182] This quarterly reassessment is designed to permit an adviser to continue holding clients' crypto assets in self-custody only if the adviser has a reasonable basis to believe, after due inquiry, that no qualified custodian will maintain the crypto asset. As the custodial market for crypto assets continues to evolve with an increasing number of sophisticated entrants, including traditional asset custodians potentially developing the technology to effectively custody crypto assets, and custodians expanding the types of crypto assets they custody, the quarterly reassessment of the QC determination would enable advisers to consider whether more suitable custodial options have emerged following their prior QC determination and to timely place client crypto assets with a qualified custodian that has become available. For example, whereas an adviser may have initially faced challenges finding a qualified custodian to maintain a crypto asset ( e.g., a nascent crypto asset), with time, qualified custodians in many cases will emerge. In those circumstances, placing the crypto assets with a third-party qualified custodian that is customarily engaged in the business of custody would reduce the risk of advisers misplacing or misappropriating client crypto assets.[183]

The proposed adviser self-custody rule would require the adviser to conduct this quarterly reassessment of its QC determinations only with respect to the crypto assets still held in the adviser's self-custody at the time of the ( printed page 63892) reassessment.[184] Moreover, in the event an adviser has taken self-custody of different crypto assets at different points in time over the course of the quarter, it is our view that an adviser would be permitted to conduct this quarterly reassessment for all the different crypto assets in its self-custody at the same time, as long as the adviser conducts the review for each crypto asset no more than a quarter after the adviser has taken self-custody of it.

Under the proposed requirement, an adviser that determines a qualified custodian has become available to maintain a client's crypto asset would be required to place such crypto asset with the qualified custodian as soon as reasonably practicable. This obligation would arise when an adviser discovers a newly available qualified custodian from its quarterly reassessment of its QC determination as well as when the adviser becomes aware of an available qualified custodian between quarterly reassessments. The proposed requirement is designed to provide an adviser a grace period to move the crypto asset from its self-custody to an available qualified custodian and does not specify the time period by which the crypto asset must be moved in order to provide an adviser flexibility to transfer the crypto asset as quickly as its systems and resources practicably allow.

We request comment on the proposed QC determination requirement:

35. Is the QC determination requirement, as proposed, appropriate and necessary to protect investors and to further the policy goals of the custody rule with respect to crypto assets? Why or why not? Alternatively, should the adviser be able to self-custody crypto assets without making the QC determination, as long as the adviser determines that holding the client's crypto asset in self-custody is consistent with its fiduciary duty? Why or why not?

36. The proposed adviser self-custody rule would require the adviser to determine in writing that it has a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset. Are there concerns that the “reasonable basis” standard in the proposed QC determination requirement would enable advisers to avoid using a qualified custodian, even where qualified custodians are generally available to custody a particular crypto asset? Should the Commission instead apply a different standard to the adviser's QC determination? If so, what alternative approaches to the QC determination would be necessary and appropriate to protect clients and to further the policy goals of the custody rule?

37. As an alternative, or in addition, to the proposed QC determination requirement, should an adviser that seeks to self-custody crypto assets be required to provide custodial services at the same level of quality as those typically provided by a qualified custodian for crypto assets or, alternatively, as those provided by a similarly situated qualified custodian? What should be the criteria or standard to determine which qualified custodian is appropriate as a benchmark for the quality of an adviser's self-custody services? Alternatively, should the adviser self-custody rule require an adviser to provide custodial services in accordance with reasonable commercial standards? Why or why not?

38. As an alternative, or in addition, to the proposed QC determination requirement, should an adviser that seeks to self-custody crypto assets be permitted to hold a crypto asset in self-custody, even where a qualified custodian is available, if the adviser determines that using the available qualified custodian(s) would prevent the adviser from implementing its investment advice in the best interests of the client, based on the client's investment objective? Why or why not? If so, under what circumstances could an adviser reasonably make this determination? Under what circumstances would it be in the best interests of the client for an adviser to self-custody a crypto asset when no available qualified custodian is able or willing to support or accommodate the activities associated with the adviser's investment advice regarding the crypto asset? If an adviser placing and maintaining a crypto asset at an available qualified custodian would prevent the adviser from implementing its investment advice in the best interests of the client due to the nature of the qualified custodian's services, such as limited capacity to stake the associated crypto asset or to support a level of trading activity, or due to the adviser's view that the available custodial services are inadequate to the extent they do not meet due care compared to the adviser's own custodial services, how should the adviser be required to analyze these issues and document its conclusions? Is there a way for the adviser self-custody rule to identify objective criteria, rather than the adviser's subjective determination, under this alternative approach? Should an adviser be able to make such a best interest determination based on, for example, the cost of the qualified custodian, the quality of service provided by the qualified custodian, and the level of the qualified custodian's technological sophistication? What parameters, if any, should guide the adviser's best interest determination? What should the adviser use as a benchmark to compare such qualities of the qualified custodian in making such best interest determination? If the benchmark is the adviser's own custodial services, how should such a best interest determination be made in light of the adviser's conflict of interest in finding that its own custodial services are in the client's best interest?

39. Under the proposed adviser self-custody rule, the QC determination would be required with respect to each crypto asset that the adviser holds in self-custody. Is the requirement that the adviser makes the QC determination individualized to each crypto asset necessary and appropriate to protect investors and to further the policy goals of the custody rule? In what circumstances, if any, would a blanket determination for multiple crypto assets be appropriate without undermining the policy goals of the custody rule?

40. In some instances, a crypto network may require users to pay transaction (or “gas”) fees in crypto assets native to the crypto network, typically used as an incentive mechanism to reward participation in and use of the crypto network.[185] Are there any circumstances where an adviser would need to self-custody crypto assets for which qualified custodians are generally available in limited amounts necessary to pay gas fees associated with executing a transaction or operation on the crypto network involving other types of crypto assets in the adviser's self-custody? What are the custodial compliance challenges, if any, that an adviser would face in maintaining at a qualified custodian those crypto assets used for paying gas fees even though a qualified custodian is generally available to hold them? Should the adviser self-custody rule provide an exception from the proposed QC determination requirement for such crypto assets held for gas fees, notwithstanding the availability of a qualified custodian to maintain them? If so, should such an exception be available only for crypto assets that are held in amounts necessary to effect, and ( printed page 63893) for the sole purpose of effecting, a transaction or operation on the crypto network involving another type of crypto asset in the adviser's self-custody? Why or why not? Would such an exception be appropriate for protecting investors and furthering the policy goals of the Advisers Act custody rule? Why or why not?

41. Should the QC determination requirement specify certain elements that must be considered by the adviser to reach its determination? If so, what factors should be considered by the adviser in reaching its determination?

42. Is the proposed guidance provided on the factors relevant to an adviser's reasonable basis for its QC determination useful? For example, is it appropriate for an adviser to consider, as part of its due inquiry to make its QC determination, each individual crypto asset and its characteristics; the custodial marketplace for the crypto asset; and whether custodians generally known in the custodial marketplace provide custodial services for a crypto asset in question? If not, what adjustments or clarifications are needed to the guidance to alleviate compliance and interpretive challenges with respect to the proposed QC determination requirement?

43. What are best practices that commenters have developed or are aware of with respect to assessing the availability of custodians to hold crypto assets? Conversely, are there any factors and considerations that commenters have found to be ineffective or relatively less effective?

44. Should the adviser self-custody rule require the adviser to reassess its QC determination with respect to the crypto assets held in self-custody on a quarterly basis, as proposed? Why or why not? Should the requirement impose a different review period ( e.g., monthly, every six months, annually, no less frequently than once every two years), and if so, why?

45. The proposed adviser self-custody rule requires an adviser to move a client's crypto asset from the adviser's self-custody to the qualified custodian as soon as reasonably practicable if the adviser determines that a qualified custodian has become available to maintain the crypto asset. Should the rule require an outer limit to the time period by which the crypto asset must be moved ( e.g., no later than by the end of the next quarter)? If so, what time period should that be, and why? How long does it typically take in practice to transfer a crypto asset from one custodian to another?

3. Safeguarding Expertise and Systems

The proposed adviser self-custody rule under the Advisers Act would require an adviser to have expertise regarding the safeguarding of each crypto asset and to document in writing the basis for its determination that it has such expertise.[186] The proposed adviser self-custody rule would also require an adviser to adopt, implement, and maintain the systems, including the appropriate technology, software, hardware, and other associated systems and processes around their use, necessary to safeguard each crypto asset against loss, theft, misuse and misappropriation (collectively, “safeguarding systems”).[187] Because crypto asset self-custody arrangements would involve the adviser holding clients' crypto assets without an independent qualified custodian, the proposed safeguarding expertise and systems requirement is a critical protection to ensure that only advisers that have the technical capabilities to safeguard crypto assets on their clients' behalf are permitted to hold these assets in self-custody.

(a) Safeguarding Expertise

Under the Advisers Act custody rule, advisers have generally maintained client assets with qualified custodians, such as banks or registered broker-dealers, with expertise regarding custodial services.[188] However, an adviser holding clients' crypto assets in self-custody under the proposed adviser self-custody rule would be serving as a custodian of those assets in lieu of a qualified custodian. Because this custodial role goes beyond the services customarily associated with advisory businesses and presents heightened concerns on conflicts of interest, this proposed requirement is necessary to ensure that the adviser has the qualifications and experience necessary to adequately safeguard client assets. Moreover, given the highly technological nature of crypto assets and the potential complex and unique risks they carry, only advisers who are well-positioned to manage these risks associated with crypto assets should self-custody clients' crypto assets.

The proposed requirement does not enumerate specific criteria for the expertise that would satisfy the rule. Different advisers may utilize different types of expertise regarding the safeguarding of crypto assets depending on the type of crypto asset. Rather than the rule taking a prescriptive approach in identifying a specific level or type of expertise that the adviser must have, the proposed requirement is designed to provide flexibility such that advisers taking self-custody of client crypto assets have the expertise that is relevant and tailored to the unique risks and characteristics specific to the crypto asset in the adviser's self-custody.

However, advisers should have, at a minimum, the expertise sufficient to establish, implement and oversee the appropriate systems and controls necessary to safeguard each crypto asset as required under the proposed adviser self-custody rule. An assessment of the adviser's expertise in this regard should entail due diligence of the different technological components of the adviser's safeguarding systems that would be used to self-custody crypto assets (including, for example, the cryptographic wallet in which the crypto assets' key materials are maintained and stored). This assessment would help ensure the adviser has the relevant expertise necessary to efficiently operate its systems and to address any vulnerabilities or weaknesses therein that could raise the risk of theft or inadvertent loss of clients' crypto assets.

The proposed adviser self-custody rule would require the adviser to have expertise regarding the safeguarding of “each” crypto asset.[189] This is intended to ensure that in assessing whether they have the expertise for purpose of the rule, advisers consider the characteristics and specific custodial risks of each crypto asset considered for self-custody. Because different kinds of crypto assets may carry different custodial risks and vulnerabilities, an assessment of each crypto asset and its specific technology would be necessary for the adviser to determine the appropriate expertise needed to reduce the client's exposure to these risks. [190] ( printed page 63894) Key factors for this analysis may include an evaluation of each crypto asset's crypto network, such as its extensibility ( i.e., whether the crypto network can have new functionality added, and continue processing transactions, without data loss or corruption) and governance (including how protocol updates and changes are determined and implemented).[191] An assessment of the crypto network would enable an adviser to identify significant weaknesses and operational issues with the network that could impact the adviser's access to the crypto asset and determine whether it has the systems and the expertise to implement and operate the systems relevant to effectively safeguard client crypto assets from related risks.

Moreover, as discussed above, although the proposed adviser self-custody rule would not preclude an adviser from obtaining assistance from third parties in connection with the adviser's self-custody services, an adviser should have the expertise sufficient to oversee any functions performed and services provided by third parties. The adviser would remain responsible for its obligations under the adviser self-custody rule, and it should therefore have the expertise to ensure that it is complying with the adviser self-custody rule on an ongoing basis notwithstanding its use of services provided by third parties. In other words, an adviser cannot just “set it and forget it” when using the services of third parties to administer its self-custody program.

We request comment on the proposed safeguarding expertise requirement:

46. What requirements other than safeguarding expertise and systems, as proposed, should we consider to help ensure that an adviser, which is not typically engaged in the custodial business, is able to adequately safeguard clients' crypto assets from loss, theft, misuse and misappropriation?

47. Is the proposed requirement that the adviser has “expertise regarding the safeguarding of each crypto asset” sufficiently clear? Would this raise questions about what expertise would suffice for purposes of the rule?

48. Should the rule identify specific qualifications, training, or experience an adviser must have that would suffice as “expertise” for purposes of the rule? Why or why not? If so, what should they be and why? Could any such qualifications, training, or experience be identified in a way that was not unique to a particular crypto asset but rather could apply to any crypto asset the adviser self-custodies?

49. Should we provide any additional clarification regarding the proposed safeguarding expertise requirement? If so, what changes should we make?

50. Are there best practices and/or considerations, in addition to those discussed above, that commenters have developed or are aware of with respect to the types of qualifications and amount of experience that should be relevant to the determination of whether an adviser has expertise regarding the safeguarding of crypto assets? For example, what other aspects of a crypto asset besides the characteristics of its associated crypto network should be relevant to an adviser's assessment of its safeguarding expertise?

51. The proposed adviser self-custody rule would require an adviser to identify the specific characteristics and risks of each crypto asset including its associated crypto network in order to assess whether the adviser has the relevant expertise to safeguard that crypto asset. To what extent do advisers currently have such, or similar, processes in place? Do commenters agree with our characterization of key factors that may be relevant to an evaluation of each crypto asset for purposes of determining whether the adviser has the expertise to safeguard the crypto asset? Are there other factors, risks, or potential harms to clients that our analysis has not identified, and if so, what are those considerations that an adviser should include in its evaluation of each crypto asset for purposes of the proposed safeguarding expertise requirement?

52. Would the proposed safeguarding expertise requirement raise any particular challenges for smaller advisers or regulated funds with smaller advisers? If so, what could we do to help mitigate these challenges?

53. To what extent do advisers already consider the level of their expertise regarding the safeguarding of crypto assets when providing advisory services with respect to crypto assets?

(b) Safeguarding Systems

The proposed adviser self-custody rule also would require the adviser to adopt, implement, and maintain the systems, including the appropriate technology, software, hardware, and associated systems and processes around their use, necessary to safeguard each crypto asset against loss, theft, misuse and misappropriation.[192] The safeguarding systems subject to the rule would capture at a minimum the hardware and/or software system ( e.g., a cryptographic wallet) in which the crypto asset's key materials are stored and maintained. Safeguarding systems may also include, depending on the adviser's and the client's circumstances, any other software platforms, hardware devices, physical and/or technical safeguards that advisers may utilize to implement and administer their self-custody program.

Like the safeguarding expertise requirement discussed above, the safeguarding systems requirement would not prescribe specific technological measures. Rather, under the proposed adviser self-custody rule, the adviser's safeguarding systems, at a minimum, must address the following three elements discussed further below: (1) key management; (2) joint authorization of crypto asset transactions; and (3) segregation of each client's crypto assets from the assets of others, including those of the adviser and the adviser's related persons.[193] These requisite elements are essential to mitigate the unique risks associated with the specific characteristics of crypto assets and the fact that an independent custodian is not involved to deter and thwart misconduct by the adviser in self-custody arrangements.

Although the proposed adviser self-custody rule does not require additional explicit written policies and procedures related to the safeguarding systems, if the proposed adviser self-custody rule were adopted, advisers would be required under existing rule 206(4)-7 of the Advisers Act (“Advisers Act compliance rule”) to have policies and procedures reasonably designed to prevent violations of the Advisers Act and rules under the Act, and this requirement would apply to the proposed adviser self-custody rule.[194] In order to be reasonably designed to ( printed page 63895) prevent violations of the proposed adviser self-custody rule, an adviser's policies and procedures adopted under the Advisers Act compliance rule would need to specifically address each element of the adviser self-custody rule, including the QC determination, processes to determine whether an adviser has the expertise necessary to safeguard a given crypto asset and the adviser's safeguarding systems including the key management, joint authorization, and segregation elements of the adviser's safeguarding systems as well as cybersecurity measures implemented pursuant to the proposed adviser self-custody rule.[195]

Similar to the safeguarding expertise requirement, the adviser would need to have the systems necessary to safeguard “each” crypto asset. As discussed above, each crypto asset may carry different risks and vulnerabilities, and the adviser would need to ensure that its safeguarding systems are appropriately tailored to address and mitigate the particularized risks associated with each crypto asset held with the adviser and such crypto asset's associated crypto network.[196] For example, certain types of crypto assets may be more prone to targeted attacks from malicious actors and require elevated levels of protections against theft. Moreover, in developing the appropriate safeguarding systems, advisers may also need to consider the nature of their advisory services provided with respect to each crypto asset and what specific custodial protections are needed to mitigate the risks associated with those services. For example, an adviser that intends to frequently trade a client's crypto assets using primarily “hot” (online) (as opposed to “cold” (offline)) wallets connected to the network would need to consider whether any additional safeguards are needed to mitigate the risks typically associated with hot wallets such as the risk of malware and cyberattacks.[197]

To comply with the proposed safeguarding systems requirement, advisers would be able to employ different self-custody frameworks and practices rather than a “one-size-fits-all” approach. As discussed above, in developing their self-custody practices, advisers would need to consider the specific characteristics and risks of the crypto assets held in adviser self-custody and the services provided with respect to those crypto assets. An understanding of these elements would enable advisers to develop safeguarding systems that are tailored to their practices and would help mitigate the risks specific to their circumstances and particular operations. Advisers could look to industry best practices to develop appropriate safeguarding systems and processes around their use. Based on the staff's outreach with the industry and comments received through the Crypto Task Force, effective safeguarding systems, among other things, would protect crypto assets against inside threats ( e.g., the threat of employees stealing crypto assets) and outside threats ( e.g., cyber attacks) [198] as well as mitigate the risk of inside error [199] ( e.g., accidental loss or use of private keys resulting in the inability to access the crypto assets; erroneous crypto asset transactions). Effective safeguarding systems should also generally address business continuity and disaster recovery practices to ensure continued access to and integrity of the crypto assets in the wake of disruptive events.[200] These elements are consistent with the core policy objectives of the Advisers Act custody rule which is to safeguard client assets from the risk of loss, theft, misuse and misappropriation.

We request comment on the safeguarding systems requirement of the proposed adviser self-custody rule:

54. Is it appropriate to require, as proposed, the adviser to have the expertise and to adopt, implement, and maintain the safeguarding systems necessary to safeguard each crypto asset against loss, theft, misuse and misappropriation? Why or why not?

55. Is the proposed requirement that the adviser adopt, implement, and maintain “the systems, including the appropriate technology, software, hardware, and other associated systems and processes around their use, necessary to safeguard each crypto assets against loss, theft, misuse and misappropriation” sufficiently clear? Would any changes to the proposed requirement be useful?

56. Would this proposed requirement (which does not prescribe specific practices or technology that should be incorporated into the adviser's safeguarding systems) provide appropriate flexibility for advisers including smaller advisers? Would this raise questions about what safeguarding systems would suffice for purposes of the rule? Should the rule identify specific practices (in addition to the three minimum requirements of key management, joint authorization and segregation discussed further below) or specific technological components that the adviser must establish and implement as part of its safeguarding systems? Why or why not? If so, what should they be and why?

57. Are there best practices that commenters have developed or are aware of with respect to the types of measures that should be implemented as part of the proposed safeguarding ( printed page 63896) systems requirement or, alternatively, are there any measures that commenters have found to be ineffective or relatively less effective?

58. Does the proposed requirement create any operational challenges for related persons of advisers that may be engaged for self-custody purposes? For example, are there any aspects of the proposed safeguarding expertise and systems requirement that would make it operationally difficult to engage the services of a related person that is operationally independent of the adviser to help administer its self-custody program? If so, what are those challenges and what changes to the proposed adviser self-custody rule would be necessary to mitigate those challenges?

59. The proposed adviser self-custody rule would require an adviser to identify the specific characteristics and risks of each crypto asset including its associated crypto network, as well as the services to be provided with respect to that crypto asset, in order to tailor the appropriate safeguarding systems. To what extent do advisers currently have such, or similar, processes in place? Do commenters agree with our characterization of risks relevant to the development of adequate safeguarding systems? Are there other risks or potential harms to clients that our analysis has not identified? Should an adviser, for instance, consider the threat of quantum computing to the security of a crypto asset and its associated crypto network in assessing the adequacy of its safeguarding systems and other related measures required under this proposal such as cybersecurity measures? [201]

60. To what extent do advisers already take the steps that would be required by the proposed adviser self-custody rule's safeguarding systems requirement to hold clients' crypto assets in self-custody?

(1) Key Management

Because access to the crypto asset is controlled by its pairing to a private key, proper management of key materials to protect against their loss or misappropriation is critical to the safeguarding of crypto assets.[202] The proposed adviser self-custody rule would thus require an adviser that has self-custody of client crypto assets to adopt, implement, and maintain safeguarding systems that manage and protect key materials against loss and unauthorized access, including by limiting access to key materials to only supervised persons designated by the adviser.[203] With respect to crypto assets held for an account of a regulated fund, the regulated fund's board of directors would need to designate such persons from the adviser's supervised persons by resolution of the board.[204]

The proposed key management requirement does not prescribe specific technical safeguards and is intended to provide advisers the flexibility to tailor their measures in the context of their business practices and the specific advisory services that they provide with respect to the clients' crypto assets. The requirement is also designed to adapt to developments over time as cryptographic key management practices continue to evolve to reflect changes in technology. Input received from commenters as well as our staff's experience indicate that the industry has developed best practices with respect to key management, including secure key generation and storage methods as well as vigorous authentication measures, to protect key materials against unauthorized access and use. For example, to enhance the security of key generation processes and to protect against access by unauthorized persons during the key generation process and thereafter, advisers could consider encrypting all levels of key generation and having designated authenticators be physically present at a secure and monitored location.[205] Advisers would also need to consider secure storage methods to back up and protect private keys against unauthorized and accidental use. These methods could include “airgapping” key materials to ensure that they are disconnected from any network, and/or holding key materials in tamper-resistant devices known as hardware security modules.[206]

Although the proposed adviser self-custody rule would not mandate a particular type of key storage method between cold and hot storage, effective safeguarding of client assets may necessitate, in many cases, that key materials be held in a cold wallet to protect against the risks typically associated with hot wallets; however, depending on the facts and circumstances, such as when the adviser seeks to trade the client's crypto assets frequently,[207] an adviser may need to use hot or warm wallets [208] in combination with other risk mitigation measures such as the use of encryption to store key materials (as opposed to storing them in plain text),[209] multi-signature wallets,[210] “whitelisting” recipients of crypto asset transfers, [211] ( printed page 63897) and time-delayed withdrawals.[212] Additional risk mitigation measures could include physically separating copies of key materials across different geographic locations and individuals, prohibiting the concentration of personnel with key materials at a particular location at any given time ( e.g., prohibiting personnel with private key access from travelling together), and other physical security protections and protocols to secure any facilities and hardware storing key materials against intruders and to enhance the physical safety of personnel with access to key materials.[213]

Effective safeguarding of key materials would likely also need exit procedures to ensure that departing firm personnel that had access to key materials do not leave their employment at the firm with continued access to the key materials. Advisers could consider adopting measures to mitigate the risks associated with any particular set of key materials, for example, by periodically changing the crypto asset's key materials and crypto asset addresses, establishing limits on sizes of cryptographic wallets, and avoiding the use of key materials for more than one purpose.[214]

Advisers would also consider whether their private key storage methods are adequately designed to protect key materials from being corrupted, lost or destroyed. Moreover, advisers should consider putting in place plans to ensure the continued safekeeping of the crypto assets in the wake of events that could disrupt access to the crypto assets including, but not limited to, a disruption or destruction of the facility, software, hardware system, or other format or system on which the key materials are stored and/or used. Advisers should also consider the legal and jurisdictional risks of placing crypto assets in hardware wallets in jurisdictions that lack robust regulatory frameworks or meaningful recourse protective of wallet owners in the event the wallet is compromised.

Advisers could draw from industry developed practices to tailor their safeguarding systems in accordance with their circumstances and the specific advisory services that they provide with respect to the clients' crypto assets. As crypto assets and distributed ledger technology continue to evolve, so do key management practices, and advisers should periodically reevaluate industry developed practices for key management and update and tailor their own key management practices as appropriate.

The proposed key management requirement would require the adviser to limit access to key materials to only designated persons that are supervised persons of the adviser and, with respect to crypto assets held in an account of a regulated fund, the regulated fund's board of directors must designate such persons from the supervised persons of the adviser (collectively, “designated persons”).[215] This requirement is similar to the requirement under current rule 17f-2 under the Investment Company Act that requires the board of the investment company to designate persons with access to the assets in the self-custody of the investment company.[216] Limiting access to key materials is important because of the risk inherent in the bearer nature of crypto asset keys and the heightened challenges of recovering many types of crypto assets when lost or stolen. Limiting access to key materials to designated persons would reduce the risk of misappropriation or accidental loss of crypto assets by limiting the universe of persons who could access them to those that are subject to the adviser's ongoing supervision and control. Limiting the universe of designated persons with private key access to supervised persons of the adviser is important to ensuring that the adviser is able to enforce the various protective requirements of the proposed adviser self-custody rule for such persons and oversee their compliance with those requirements.[217]

It is our view that in order to comply with the proposed key management requirement, an adviser must have exclusive possession of the key materials to the crypto asset, as sharing key materials with anyone outside of the adviser would be a violation of the requirement that private key access be limited to supervised persons of the adviser. This also means advisers would not be permitted to share key materials with the client, which is necessary to limit the parameters of access to the private keys and to reduce the risk of inadvertent loss or theft of the key materials.

An adviser would be permitted to rely on the proposed adviser self-custody rule only with respect to crypto assets for which it provides investment advice.[218] For instance, an adviser would not be permitted under this proposal to place the key materials to an advisory client's crypto assets with an affiliate adviser (including a foreign affiliate adviser) that is not designated as the investment adviser to that client in the advisory agreement, since that affiliate would not be the entity providing investment advice to the client with respect to those crypto assets. It is necessary in our view to limit adviser self-custody to crypto assets for which an adviser provides investment advice in order to reduce instances of advisers placing key materials to client crypto assets with affiliates that may be operationally difficult to supervise and control for compliance with the required safeguards of the rule. This limitation is also necessary to address the possibility that advisory affiliates could serve primarily as custodians for client crypto assets rather than as providers of investment advice. Such advisers may not be subject to fiduciary and other obligations under the Advisers Act associated with providing investment advice.

We request comment on the proposed key management requirement:

61. Is the proposed requirement that the adviser's safeguarding systems must “manage and protect key materials against loss and unauthorized access” sufficiently clear? Would this raise questions about what key management practices would suffice for purposes of the rule? Should we provide any additional clarification regarding the proposed key management requirement? If so, what changes should we make? ( printed page 63898) Would any changes to the proposed adviser self-custody rule be useful?

62. Conversely, would this proposed requirement (which does not prescribe specific practices or technology enabling key management) provide appropriate flexibility necessary to tailor safeguarding systems to the unique aspects of a crypto asset held in the adviser's self-custody? Should the rule identify specific key management practices or technology that the adviser must establish and implement for purposes of the rule? Why or why not? If so, what should they be and why?

63. What are best practices that commenters have developed or are aware of with respect to the types of measures that should be implemented as part of the proposed key management requirement or, alternatively, are there any measures that commenters have found to be ineffective or relatively less effective?

64. Would the proposed requirement that access to key materials be limited to supervised persons designated by the adviser (and in the case of crypto assets held in an account of a regulated fund, supervised persons designated by the board of the regulated fund) create any particular challenges for advisers, such as smaller advisers? Would the board designation requirement create any particular challenges for any regulated funds or their advisers? If so, what modifications to the proposed adviser self-custody rule would be necessary to mitigate these challenges?

65. Do advisers to regulated funds anticipate a need to change designated persons frequently such that compliance with the proposed board designation requirement would be challenging? If so, why would frequent changes in designated persons be necessary and how should a regulated fund's board oversee this process?

66. Are supervised persons the appropriate persons to have access to the key materials? Should the requirement be a higher standard, for example, that only the adviser's management persons have access to the key materials?

67. To the extent advisers engage third parties such as software providers to support their management of key materials, are there concerns that those third parties would have access to the adviser's key materials (for example, when generating new private keys), therefore violating the requirement that only the adviser's supervised persons have access to the key materials? Are there any instances when access to key materials by third parties would be necessary and helpful to investor protection? If so, what are those examples?

68. Are commenters aware of any examples of advisers sharing key materials with the client? In what circumstances, if any, would this arrangement be necessary? Would sharing key materials with the client enhance investor protection? Why or why not? Do advisers anticipate that sharing key materials with clients would be necessary as an additional cybersecurity resilience measure to ensure that no single party is able to instruct the movement of a given crypto asset without the client also agreeing to the movement? Or does sharing key materials with clients exacerbate custodial risks because it exposes key materials to additional parties that are not subject to the adviser's supervision and control? If the adviser self-custody rule permitted the sharing of key materials with clients, under what conditions should this be allowed? For example, should the adviser self-custody rule allow the client to have only a non-controlling share of the key materials ( i.e., a private key share that is necessary to effectuate a crypto asset transaction but not sufficient for the client to unilaterally move the crypto asset), and only if such private key share is recoverable? Should the adviser self-custody rule require an adviser in such arrangement to obtain explicit client authorization for each transfer of the client's crypto asset? [219]

69. Are the security and control of key materials impacted by the geographic location of the systems in which they are stored, relative to the adviser? Could an adviser maintain the security and control of key materials stored in a system located outside of the adviser's jurisdiction as effectively as an adviser could maintain the security and control of key materials stored in a system located in the adviser's jurisdiction? What jurisdictional barriers, if any, could undermine an adviser's ability to maintain its control and security of key materials that are stored outside of the jurisdiction of the adviser? Should the proposed adviser self-custody rule require advisers to maintain a client's key materials in the United States? Given the virtual nature of key materials, would it be operationally possible to limit the location of key materials to the United States?

(2) Joint Authorization

Under the proposed adviser self-custody rule, an adviser holding client crypto assets in self-custody would be required to adopt, implement, and maintain safeguarding systems that prevent unauthorized transfers of crypto assets.[220] At a minimum, such systems must require joint authorization of crypto asset transfers by two or more designated persons, at least one of which must be a management person and, in the case of crypto assets held for an account of a regulated fund, such management person must be an officer of that regulated fund. Crypto assets carry a heightened risk of irreversible loss because of the bearer nature of private keys and the irreversibility of most crypto asset transactions on crypto networks. Controls and processes governing how a client's crypto assets are transferred are thus a critical element of safekeeping crypto assets.[221]

Under the proposed adviser self-custody rule, advisers would have to establish systems that require joint authorization of crypto asset transfers by two or more designated persons.[222] This is to ensure that multiple persons subject to the adviser's ongoing supervision and control are independently involved to oversee and gatekeep access to the clients' crypto assets, which would help to reduce the ability of any single bad actor to misappropriate clients' crypto assets. Although we recognize that the proposed requirement would preclude an adviser with only one employee from relying on the adviser self-custody rule, the proposed requirement is appropriate because a single person at an adviser having the authority to unilaterally transfer a client's crypto assets heightens the risk of misappropriation and misuse of the crypto asset by the adviser.

This requirement parallels a provision in rule 17f-2 under the Investment Company Act that requires two or more (but not more than five) designated persons to act jointly in accessing assets in the investment company's own ( printed page 63899) custody.[223] In our view, similar protections should apply when the adviser has self-custody of clients' crypto assets without the involvement of an independent custodian to deter potential misconduct. Although like the key management requirement, this joint authorization requirement is intended to be technologically neutral, advisers should implement protections that effectively allow them to safeguard clients' crypto assets against unauthorized access and use of the private keys.

Advisers could establish different security measures to satisfy the proposed requirement that multiple designated persons jointly authorize any transactions in the crypto assets. Several commenters recommended different technology solutions that enable joint authorization requirements gating crypto asset transfers. Advisers may consider, for example, MPC, which prevents any one person from unilaterally transferring crypto assets by distributing among independent users private key shares that are privately maintained from each other and requiring the input of some or all of the key share holders in order to effectuate a crypto asset transaction.[224] Alternatively, depending on their circumstances, advisers could also consider multi-signature wallets, which involve multiple independent private keys to approve transactions.[225] Advisers would also generally want to consider establishing protocols to verify the identity of the designated persons, such as multi-factor authentication that implements layers of security and identity verifications in order to ensure that the persons seeking authorization to move the crypto assets are, in fact, who they claim to be.[226] Advisers should also consider using other protective measures to prevent crypto assets from falling into the hands of unauthorized actors or being moved for unauthorized purposes, such as measures to prevent blind signing by authorized signatories [227] and address verification technology that restricts recipients of crypto asset transfers to authorized and vetted persons ( e.g., whitelisting).[228]

At least one of the persons authorizing crypto asset transfers would have to be a management person, and in the case of crypto assets held for an account of a regulated fund, such management person must be an officer of the regulated fund.[229] Proposed rule 223-1(d)(11) defines “management persons” as having the same meaning as that term in the Form ADV, Glossary of Terms, which currently defines “Management Persons” as anyone with the power to exercise, directly or indirectly, a controlling influence over the adviser's management or policies, or to determine the general investment advice given to the clients of the adviser.[230] Generally, all of the following are management persons:

(1) The adviser's principal executive officers, such as the adviser's chief executive officer, chief financial officer, chief operations officer, chief legal officer, and chief compliance officer; the adviser's directors, general partners, or trustees; and other individuals with similar status or performing similar functions;

(2) The members of the adviser's investment committee or group that determines general investment advice to be given to clients; and

(3) If the adviser does not have an investment committee or group, the individuals who determine general investment advice provided to clients.

This requirement parallels the requirement under rule 17f-2 under the Investment Company Act that at least one of the persons acting jointly to access a registered investment company's self-custodied assets be an officer. The requirement is intended to ensure that at least one of the persons authorizing crypto asset transactions has the authority sufficient to oversee self-custodied crypto asset activities across the firm and to monitor transactions conducted by authorized personnel, which would help mitigate the risk of a bad actor conducting unauthorized activities with the crypto asset. A management person, and an officer in the case of a regulated fund, would be more likely to have the seniority compared to a non-management employee to effectively oversee and monitor crypto asset activities across the firm. As the definition of “management persons” includes anyone with “the power to exercise, directly or indirectly, a controlling influence over the adviser's management or policies,” the proposed requirement would not limit authorized signatories for this purpose to only senior investment professionals.[231] For example, an adviser's cybersecurity director or a chief information security officer could be designated as an authorized signatory for this purpose. We request comment on the joint authorization element of the proposed safeguarding systems requirement:

70. Is the proposed requirement that the adviser's safeguarding systems “prevent unauthorized transfers of crypto assets” including by requiring joint authorization of crypto asset transfers by two or more designated persons (at least one of which must be a management person, and in the case of crypto assets held for an account of a regulated fund, such management person must be an officer of the regulated fund) sufficiently clear? Would this raise questions about what joint authorization measures would suffice for purposes of the rule? Should we provide any additional clarification or changes regarding the proposed joint authorization requirement? If so, what changes should we make? ( printed page 63900)

71. Conversely, would this proposed requirement (which does not prescribe specific practices or technology enabling joint authorization of crypto asset transactions) provide appropriate flexibility for advisers including smaller advisers and regulated funds with smaller advisers? Or would this raise questions about what joint authorization practices would suffice for purposes of the rule? Should the rule identify specific practices or technology that the adviser must utilize for purposes of the rule? Should the rule specifically require, for example, that the adviser use MPC or multi-signature wallets to authorize transactions of crypto assets? Why or why not? If so, what should these practices and/or technology be, and why?

72. What are best practices that commenters have developed or are aware of with respect to the types of measures that should be implemented as part of the proposed joint authorization requirement or, alternatively, are there any measures that commenters have found to be ineffective or relatively less effective?

73. Would the proposed requirement that two or more designated persons jointly authorize any crypto asset transactions raise any particular challenges for advisers, including smaller advisers and, if so, what could we do to help mitigate these challenges? For example, should we modify the proposed adviser self-custody rule to permit advisers to authorize the use of third parties not employed by the adviser to authorize transactions and, if so, under what conditions? Why or why not?

74. Are management persons of the adviser and an officer of the regulated fund the appropriate persons to authorize crypto asset transactions, as proposed? Why or why not? Would the proposed requirement that at least one of the persons authorizing crypto asset transactions be a management person of the adviser and, in the case of a regulated fund, also an officer of the regulated fund, be overly burdensome for advisers and regulated funds? Are there any persons at the adviser or the regulated fund other than management persons and officers that should be required to authorize crypto asset transactions? For example, should the rule instead require an adviser or regulated fund's chief compliance officer or their designee(s) to participate in the authorization of a crypto asset transaction given their involvement in compliance functions? Alternatively, should the adviser self-custody rule instead require that at least one of the persons authorizing crypto asset transactions have authority sufficient to oversee self-custodied crypto asset activities across the firm and monitor transactions conducted by authorized personnel?

75. Instead of requiring at least one of the designated persons to be a “management person” and, in the case of a regulated fund, also an “officer,” as proposed, should the rule instead permit advisers and regulated funds to designate persons with authorization privileges based on a principles-based facts and circumstances approach? If so, which facts and circumstances should inform the adviser's designation of persons with authorization privileges? Would the proposed requirement that at least one of the designated persons be a management person or an officer of the regulated fund raise the risk of targeted attacks by malicious actors acting upon their knowledge of who holds these titles?

76. Is “two or more” the appropriate number of persons to provide joint authorization of crypto asset transactions? Why or why not? Should this requirement be revised with a higher minimum number of persons that must jointly authorize crypto asset transactions? Should the rule, like rule 17f-2(d), apply a limit to the number of persons to provide joint authorization of crypto asset transactions?

77. Are commenters aware of any examples of advisers and custodians utilizing non-human, software-based agents as signatories of crypto asset transactions, such as automated smart contracts and artificial intelligence? Should the proposed joint authorization requirement expressly permit or prohibit the use of software-based agents as signatories of crypto asset transactions? Does the use of software-based agents as signatories enhance or undermine the safeguarding of a crypto asset?

(3) Segregation

The proposed adviser self-custody rule would require an adviser that has self-custody of client crypto assets to adopt, implement, and maintain safeguarding systems that maintain each client's crypto assets in one or more crypto asset addresses on the crypto network storing only such client's crypto assets.[232] This aspect of the proposed adviser self-custody rule is designed to segregate each client's crypto assets in the adviser's self-custody from the crypto assets of others, including other clients, the adviser and its related persons. Segregation of client assets continues to be a foundational element of safeguarding client assets and is particularly essential in light of the unique custodial risks inherent in crypto assets.[233]

The proposed requirement that a client's crypto assets be maintained in crypto asset addresses storing only such client's crypto assets on the crypto network is intended to ensure that the client's crypto assets are clearly identifiable as belonging to the appropriate client. Ownership and transfers of crypto assets today are recorded on the crypto network and are controlled by pairings of the crypto asset's private key materials to its corresponding crypto asset address, a bespoke and public identifier on the crypto network that functions as a destination or “wallet address” for storing, receiving and sending crypto assets.[234] The crypto asset address can be used to view the corresponding crypto asset's balances and transactions on the crypto network on which the crypto asset's transfers and ownership are recorded. Maintaining client crypto assets in a segregated manner under crypto asset addresses that store only the relevant client's assets, rather than commingling them with the crypto assets of others, would help isolate each client's crypto assets and allow a client to monitor activity at the wallet address holding the client's crypto assets.

The proposed segregation requirement is necessary in the context of adviser self-custody to prevent circumstances that could result in the misuse or misappropriation of the client's crypto assets by the adviser.[235] Segregation of ( printed page 63901) client crypto assets under separate crypto asset addresses would serve as an important check on potential misconduct by the adviser by helping ensure the client's continued ownership and authorized use of its crypto assets. When client crypto assets are isolated from the assets of others under separate crypto asset addresses, records of crypto asset ownership and transactions viewable under the relevant addresses onchain would provide transparency as to the adviser's uses of the client's crypto assets and consequently reduce the likelihood that advisers or their related persons use client crypto assets for their own purposes in a manner not authorized by the client. Commenters have also stated that segregation of client crypto assets and clear identification of those assets as belonging to the client may also help protect client crypto assets from claims by a third party looking to secure or satisfy an obligation of the adviser including in cases of insolvency or bankruptcy of the adviser, or its related persons.[236]

Moreover, to the extent the adviser primarily relies on onchain records of crypto asset ownership and transactions to track and notify clients of the crypto asset's activities, segregation of clients' crypto assets by address would be critical to preserve the benefits of onchain transparency.[237] This is because the crypto network shows transactions in the relevant crypto asset, allowing a client to monitor the client's own account by monitoring the activity associated with crypto asset addresses holding only the client's crypto assets. This monitoring would not be possible if the client's assets were commingled with other client assets in an omnibus crypto asset address. In that case, client transactions would not always be visible on the crypto network because, while they could be effected on the books and records of the adviser, any transactions visible on the crypto network could not be used to monitor activity affecting any particular client's account.[238]

We recognize that even with segregated crypto asset addresses, an adviser may need to supplement onchain records with records of transactions or data that are processed and recorded outside of a crypto network (“offchain”), such as offchain logs identifying owners of each crypto asset address by name, since a crypto asset address comprises a pseudonymous combination of letters and numbers.[239] Segregating crypto assets by address, however, would allow clients with their address information to easily identify and monitor their crypto asset balances and transactions on the crypto network rather than having to rely on the adviser to parse out which crypto asset activity under a commingled address relates to a client's account. Segregation of crypto assets by address is therefore an essential component of furthering transparency through the use of cryptography's protective onchain features and reducing the risk of adviser misconduct.

We request comment on the proposed segregation requirement:

78. Is this proposed segregation requirement sufficiently clear? Should we provide any additional clarification regarding the proposed segregation requirement? If so, what changes should we make?

79. Conversely, would this proposed segregation requirement provide appropriate flexibility for advisers including smaller advisers? Or would this raise questions about what segregation practices would suffice for purposes of the rule? Should the rule identify specific practices or technology that the adviser must establish and implement for purposes of the rule?

80. What are best practices that commenters have developed or are aware of with respect to the types of measures that should be implemented to effectively segregate crypto assets or, alternatively, are there any measures that commenters have found to be ineffective or relatively less effective?

81. Should we modify the rule to permit advisers to use omnibus wallets to hold all clients' crypto assets and, if so, under what conditions, if any? Why or why not?

82. Would the proposed segregation requirement increase the likelihood that client crypto assets would be available to be returned to clients if the adviser experiences financial events such as insolvency or bankruptcy? For example, do commenters believe the requirements would help ensure that client crypto assets are more readily identifiable as client property? Would the proposed segregation requirement offer substantial protections in the event of a bankruptcy or financial losses involving the adviser?

4. Cybersecurity

Under the proposed adviser self-custody rule, an adviser that has self-custody of clients' crypto assets must mitigate any cybersecurity risks to the safeguarding of each such crypto asset.[240] The proposed adviser self-custody rule provides certain general core elements that advisers would need to address when implementing their cybersecurity measures: (1) periodic but no less than annual written assessments of cybersecurity risks to crypto assets in the adviser's self-custody and cybersecurity risks associated with the adviser's safeguarding systems; (2) measures reasonably designed to detect, mitigate and remediate any cybersecurity threats and vulnerabilities with respect to the adviser's safeguarding systems; and (3) measures reasonably designed to detect, respond to, and recover from a cybersecurity incident relating to the adviser's safeguarding systems.

Crypto assets are a highly technological asset class that operate virtually on interconnected networks composed of crypto systems.[241] As a result, crypto assets are subject to heightened cybersecurity risks, and cybersecurity breaches could result in the theft of crypto assets and significant financial losses.[242] For example, cyber ( printed page 63902) threat actors could take advantage of potential vulnerabilities associated with an adviser's custodial infrastructure, including aspects of that infrastructure that are owned or operated by third parties, to conduct malicious activities, including unauthorized access to cryptographic wallets holding clients' key materials. Crypto systems may also be vulnerable to cyber attacks that exploit vulnerabilities in the underlying code of the crypto applications running on those systems, resulting in the theft of crypto assets deposited therein.[243] Timely cybersecurity risk assessments and robust cybersecurity protocols are therefore critical to the proper safekeeping of crypto assets.[244] Advisers may have already implemented cybersecurity programs under the existing regulatory framework that implicates cybersecurity considerations. For example, under 17 CFR 248.1 through 248.31 ( i.e., Regulation S-P), every investment adviser registered with the Commission and regulated fund is required to, among other things, adopt written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information, i.e., any record containing nonpublic personal information about an adviser's customer, which, under Regulation S-P, is an individual advisory client.[245] These policies and procedures must be reasonably designed to (i) ensure the security and confidentiality of customer information, (ii) protect against any anticipated threats or hazards to the security or integrity of customer information, and (iii) protect against unauthorized access to or use of customer information that could result in substantial harm or inconvenience to any customer as well as include a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. Accordingly, registered investment advisers with self-custody already must have programs under Regulation S-P that they could enhance or build upon, to the extent necessary or appropriate, to satisfy the cybersecurity requirement under the proposed adviser self-custody rule.

Advisers and funds subject to 17 CFR 248.201 through 202 (“Regulation S-ID”) must also develop and implement a written identity theft program that includes policies and procedures to identify relevant types of identity theft red flags, detect the occurrence of those red flags, and respond appropriately to the detected red flags.[246] Advisers holding crypto assets in self-custody would be required to comply with Regulation S-ID and establish a red flags program to the extent that they are financial institutions or creditors that offer or maintain covered accounts under Regulation S-ID.[247]

Furthermore, funds and advisers may have put in place measures to prevent, detect, and respond to cyber attacks as necessary to address their compliance obligations under other provisions of the Federal securities laws. Advisers are encouraged to leverage and/or enhance their existing cybersecurity programs to comply with the proposed cybersecurity requirement under the adviser self-custody rule.

The proposed cybersecurity requirement otherwise gives advisers the flexibility to address the three general elements based on the particular cybersecurity risks posed by each adviser's safeguarding systems as well as the particular characteristics of the self-custodied crypto assets and the crypto networks on which they operate. Given the number and varying characteristics ( e.g., size, business, and sophistication) of advisers, this flexibility is necessary to allow advisers the ability to tailor their cybersecurity protocols based on their individual facts and circumstances. Cybersecurity threats are also constantly evolving, and as measures to address those threats continue to advance, this approach would allow advisers' cybersecurity measures to evolve accordingly as firms reassess the cybersecurity risks to their self-custody practices.

(a) Risk Assessment

The first core element of the proposed cybersecurity requirement would require periodic but no less than annual written assessments of cybersecurity risks to crypto assets in the adviser's self-custody and cybersecurity risks associated with the adviser's safeguarding systems used to self-custody crypto assets.[248] This assessment is necessary for an adviser to design effective cybersecurity protocols and controls tailored to the firm's particular operations and the specific characteristics and vulnerabilities associated with each crypto asset in the adviser's self-custody. Advisers may be subject to different cybersecurity risks that necessitate different cybersecurity measures depending on, for example, whether a crypto system associated with a particular crypto asset in the adviser's self-custody is vulnerable to, or has been subject to, a cybersecurity breach; an adviser's investment and trading activities involving the self-custodied crypto assets; [249] whether an adviser utilizes hot wallets versus cold wallets to store private keys; [250] whether designated private key holders work remotely or travel internationally; an adviser's degree of vulnerability to inside and/or outside threats; and/or whether an adviser utilizes a cryptographic wallet provider that has previously experienced a cybersecurity breach. Given that this assessment is necessary to implement effective cybersecurity measures and adequate safeguarding systems for a particular crypto asset based on its particularized risks, advisers would consequently need to conduct the first risk assessment before the adviser takes self-custody of a crypto asset, which would help ensure that those risks are mitigated before a cybersecurity incident happens.

This assessment would need to include an evaluation of the particular characteristics and specific vulnerabilities associated with each crypto asset and its associated crypto network on which it operates. An understanding of the crypto asset's specific technology including its associated crypto system is necessary for the adviser to develop appropriate ( printed page 63903) cybersecurity protocols to mitigate risks that could affect the adviser's continued ability to access the crypto asset.[251] Such assessments would allow the adviser to identify significant weaknesses or other potential operational issues associated with a crypto asset and its associated crypto system, or other risks posed to the adviser's business by the crypto asset, and to take appropriate action to identify and reduce its exposure to such risks by establishing cybersecurity measures tailored to mitigate those risks.

Due to the ongoing and emerging nature of cybersecurity threats to crypto assets, advisers would be required to conduct these risk assessments periodically but no less than annually. An adviser that holds a crypto asset in self-custody for less than a year would not be expected to conduct an annual risk assessment with respect to such crypto asset when it is no longer in the adviser's self-custody by the time the annual assessment is due. However, although the proposed requirement specifies an outer limit for the frequency of this assessment ( i.e., annual), it is our view that an adviser would not be able to satisfy the proposed adviser self-custody rule unless it conducts this risk assessment as material cybersecurity risks arise and to reflect internal changes ( e.g., changes to the firm's business practices, new crypto assets taken under the adviser's self-custody, and the scope and nature of the adviser's services with respect to the crypto assets) as well as external changes ( e.g., changes in technology, the crypto asset market, and the emergence of new cybersecurity threats). For instance, a cybersecurity breach at a crypto wallet provider that occurs two months after the adviser had placed a self-custodied crypto asset in the wallet licensed from that provider may warrant a risk assessment to determine whether the breach poses any risks to the adviser's ability to safeguard the crypto asset utilizing such wallet. Timely assessment of cybersecurity risks as they arise to the crypto assets in the adviser's self-custody and to its safeguarding systems is critical to taking steps to mitigate those risks and to safeguard client crypto assets before they are lost.

(b) Threat and Vulnerability Management

The second core element of the proposed cybersecurity requirement would require the adviser to take measures reasonably designed to detect, mitigate and remediate any cybersecurity threats and vulnerabilities with respect to the adviser's safeguarding systems. Cybersecurity vulnerabilities may present weaknesses in the adviser's custodial environment for self-custodied crypto assets that attackers may exploit to obtain unauthorized access to the client's crypto assets and key materials, which could lead to adverse consequences and substantial harm to an advisory client. Effective management of cybersecurity threats and vulnerabilities is therefore critical to the safekeeping of crypto assets.

Detecting, mitigating, and remediating cybersecurity threats and vulnerabilities is essential to preventing cyber incidents before they occur. Advisers could seek to detect cybersecurity threats and vulnerabilities through ongoing monitoring, which could include, for example, conducting regular security audits and penetration testing by independent parties.[252] We also would encourage advisers to monitor industry and government sources for new threat and vulnerability information that may assist them in detecting cybersecurity threats and vulnerabilities to their custodial infrastructure.[253]

Once a threat or vulnerability is detected, advisers would need to mitigate and remediate such threat or vulnerability in their safeguarding systems. Advisers would generally be advised to do so with a view toward minimizing the window of opportunity for attackers to exploit the vulnerability. Cybersecurity measures could also include processes for establishing accountability for handling vulnerability reports, and processes for intake, assignment, escalation, remediation, and remediation testing. Advisers could also consider cybersecurity threat, vulnerability and response training, especially for persons designated by the adviser to have access to private keys. For example, trainings could include phishing and social engineering awareness training for employees and executives. Proactively identifying and addressing threats and vulnerabilities reduces the likelihood that the firm's self-custody environment, and therefore the crypto assets held therein, will be compromised.

(c) Cybersecurity Incident Response and Recovery

The third core element of the proposed cybersecurity requirement would require the adviser to implement measures reasonably designed to detect, respond to, and recover from a cybersecurity incident relating to the adviser's safeguarding systems. Cybersecurity incidents can lead to significant disruptions, including unauthorized access to cryptographic wallets holding private keys, which could result in the permanent loss of crypto assets. Having controls designed to respond to cybersecurity incidents can help mitigate risks of substantial harm to advisory clients resulting from unauthorized access to self-custodied crypto assets or a compromise in the adviser's safeguarding systems. A clear incident response plan reasonably designed to ensure continued operational capability and to facilitate recovery even if there is a breach in the adviser's systems would be necessary to mitigate the effects of a cybersecurity incident on the adviser's ability to safeguard client crypto assets. Advisers, therefore, may wish to consider maintaining physical copies of their incident response plans—and other cybersecurity controls and processes—to help ensure they can be accessed and implemented during the times they may be needed most.

An effective incident response plan may need to designate adviser personnel to perform specific roles in the case of a cybersecurity incident. This could entail identifying personnel or third parties who have the requisite cybersecurity and recovery expertise (or are able to coordinate effectively with outside experts if necessary) as well as identifying personnel who should be kept informed throughout the response and recovery process. In addition, an incident response plan may generally need a clear escalation protocol to ensure that an adviser's senior officers, including appropriate legal and compliance personnel, and a regulated fund's board (as applicable) receive necessary information regarding cybersecurity incidents on a timely basis.

We request comment on the proposed cybersecurity requirement:

83. Are the proposed elements of the cybersecurity requirement appropriate? Should we modify or remove any of the proposed elements? Why or why not? Should we require that each element ( printed page 63904) include more specific measures, and if so, what should they be?

84. What are cybersecurity best practices as they relate to the safekeeping of crypto assets that commenters have developed or are aware of with respect to the types of measures that should be implemented as part of the proposed cybersecurity requirement or, alternatively, are there any measures that commenters have found to be ineffective or relatively less effective?

85. Would advisers expect to use sub-advisers or other third parties and service providers to administer their cybersecurity programs? If so, to what extent and in what manner? Should there be additional or specific requirements for advisers that delegate cybersecurity management responsibilities to a sub-adviser or third party, such as a service provider? If so, what requirements and why?

86. Should we include any other cybersecurity requirements as they relate to the safeguarding of crypto assets? If so, what? For example, should we include a requirement for training staff responsible for day-to-day management of the adviser's cybersecurity program? If we require such training, should that involve setting minimum qualifications for staff responsible for carrying out the requirements of the program? Why or why not? If so, what minimum qualifications should we require?

87. Should we require that advisers respond to cybersecurity incidents within a specific timeframe? If so, what would be an appropriate timeframe?

88. As stated above, advisers must have already implemented cybersecurity programs under the existing regulatory framework that implicates cybersecurity considerations, such as Regulation S-P and Regulation S-ID, as applicable, and advisers are encouraged to leverage and/or enhance their existing cybersecurity programs to comply with the proposed cybersecurity requirement. Would the proposed cybersecurity requirement under the adviser self-custody rule raise any interpretive or compliance challenges as advisers also try to comply with existing regulatory requirements under Regulation S-ID and Regulation S-P? If so, what clarifications or guidance is needed to facilitate advisers' compliance with the proposed cybersecurity requirement alongside their existing obligations under Regulation S-ID and Regulation S-P? Would there be any overlaps in the way advisers comply with and implement their cybersecurity pursuant to Regulation S-ID, Regulation S-P and the proposed adviser self-custody rule's cybersecurity requirement, in that the proposed cybersecurity requirement under the adviser self-custody rule or certain aspects of it are duplicative and unnecessary? If so, what are those overlapping areas?

89. Should the adviser self-custody rule require an adviser to obtain an independent attestation report ( e.g., System and Organization Controls for Cybersecurity report) that assesses an adviser's compliance with the proposed cybersecurity requirement? Why or why not?

5. Annual Review

The proposed adviser self-custody rule would require advisers that have self-custody of client crypto assets to review, within a year of taking self-custody of each crypto asset and no less frequently than annually thereafter, the following including the effectiveness of their implementation: (i) the adviser's safeguarding systems, and (ii) the cybersecurity controls implemented pursuant to the proposed cybersecurity requirement.[254] Advisers must document their review in writing.[255] The proposed annual review requirement is intended to ensure that advisers evaluate periodically, but no less than annually, whether the safeguarding systems and cybersecurity controls that they have in place to self-custody clients' crypto assets continue to work as designed and whether changes are necessary to assure their continued effectiveness.

The annual review of the adviser's safeguarding systems should consider any compliance matters that arose during the previous year. This would include consideration of compliance matters that arose in the previous year with respect to crypto assets no longer held in the adviser's self-custody by the time of the annual review. Custodial and compliance matters as to such crypto assets could raise risk of recurrence for other crypto assets currently in the adviser's self-custody, for instance, if a governance protocol for a previously held crypto asset is similar to that of a crypto asset currently in the adviser's self-custody. The annual review should also consider any changes in the business activities of the adviser or its affiliates, and any changes or technological developments and custodial service best practices with respect to crypto assets that might suggest a need to revise or update the adviser's safeguarding systems. An adviser would not be expected to conduct this annual review, however, to the extent the adviser does not hold any client crypto assets in self-custody by the time an annual review is due. For instance, an adviser that held a crypto asset in self-custody for less than a year and does not hold any other client crypto assets in self-custody would not be required to conduct this annual review, because that adviser would no longer be subject to the adviser self-custody rule.

An adviser's annual review of its cybersecurity controls generally should include, among other things, testing of its incident response plan to assess its efficacy and to determine whether any changes to the incident response plan are necessary. These tests would help to assess the design and effectiveness of the adviser's incident response plan and whether any amendments are necessary to correct any identified weaknesses in the plan's design or effectiveness. Such periodic testing of the incident response plan is critical in light of the continuing emergence of novel cybersecurity threats to crypto assets and to ensure that an adviser is adequately prepared to address and mitigate the impact of a cybersecurity incident on the adviser's safeguarding systems.

In the event an adviser has taken on self-custody of different types of crypto assets at different points in time over the course of the review period, an adviser would be permitted to conduct this annual review for all the different types of crypto assets in its self-custody at the same time, as long as the adviser conducts the review for each type of crypto asset no more than a year after the adviser has taken self-custody of it.

Advisers may need to periodically reevaluate their safeguarding systems and cybersecurity practices to determine that they still meet the conditions in the proposed adviser self-custody rule in light of any changes in industry developed practices with respect to crypto asset custody or to account for any novel cybersecurity threats to crypto assets as they emerge.

We request comment on the annual review requirement of the proposed adviser self-custody rule:

90. Should we require advisers to document the annual review of their safeguarding systems and cybersecurity measures in writing, as proposed? If not, why?

91. Should we specify certain elements that must be included in the ( printed page 63905) adviser's written documentation of the annual review? If so, what should those elements be?

92. Should the proposed adviser self-custody rule require the review of the adviser's safeguarding systems and cybersecurity measures to occur no less frequently than annually, as proposed? Should the rule instead require the review to occur over longer ( e.g., every two years) or shorter ( e.g., every quarter, every six months) review periods? If so, what time period, and why?

93. Should there be specific requirements for designating responsible persons to oversee and implement an adviser's safeguarding systems and cybersecurity program for purposes of the adviser self-custody rule? [256] For example, should we require an adviser to specify an individual, such as a chief information security officer and/or a chief compliance officer, or group of individuals, as responsible for overseeing and implementing the adviser's safeguarding systems and cybersecurity program or parts thereof as well as functions performed and services provided by third parties in connection with the adviser's self-custody program? Why or why not? If so, should the adviser self-custody rule require the adviser to establish, maintain, and enforce reasonably designed written policies and procedures that include the criteria for identifying such individual(s) and the designation and documentation of responsible individual(s)? Should such an individual or group of individuals be required to have certain qualifications or experience related to crypto asset custody and cybersecurity, and if so, what type of qualifications or experience should be required?

6. Internal Control Report

The proposed adviser self-custody rule would require an adviser that takes self-custody of client crypto assets to obtain an internal control report prepared by an independent public accountant.[257] As discussed further below, the internal control report must include an opinion of an independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of crypto assets held by the adviser on behalf of the adviser's advisory clients.[258]

Relatedly, we recognize that certain aspects of the 2009 Guidance for Accountants may benefit from updating to address attestation standards for crypto assets and other industry developments since its publication.[259] The modified guidance is intended to provide accountants with the overall objectives and scope of the internal control examination as it relates to clients' crypto assets in the adviser's self-custody.

We are proposing this internal control report requirement to address the heightened custodial risks associated with self-custody arrangements and to provide additional safeguards to protect advisory clients' crypto assets from these risks. Arrangements where an adviser acts as the custodian of client assets can present higher risks to advisory clients than maintaining assets with an independent custodian. Where the adviser holds client assets without an independent custodian to act as a check on potential misconduct, there is a greater risk that the adviser may engage in fraud by compromising custodial records. In supporting the internal control report requirement under the related person QC rule, the Commission noted several enforcement actions alleging misappropriation or other misuse of client assets involving advisers or related persons that maintained client assets.[260] Self-custody arrangements involving crypto assets may heighten these risks due to the fact that fraudulent crypto asset transactions are generally difficult or impossible to reverse. Requiring advisers to obtain an internal control report would provide an important check on the safeguards relating to client crypto assets held by the adviser.

This proposed internal control report requirement is consistent with the current Advisers Act custody rule that requires an annual internal control report when the adviser or its related person acts as a qualified custodian of client assets, as well as our understanding of best practices regarding control assessments of crypto asset custody. Based on our experience with the Advisers Act custody rule, the benefits and protections provided by the internal control report in custody arrangements involving the adviser or its related person as a qualified custodian should be expanded to adviser self-custody of crypto assets. Several commenters writing to the Crypto Task Force highlighted the importance of independent assessments of the adviser's self-custody practices to ensure their efficacy and suitability.[261]

The first internal control report would need to be obtained within six months of the adviser taking self-custody of a client crypto asset, and thereafter no less frequently than once each calendar year as long as the adviser has any client crypto asset in self-custody. A six-month requirement for the first internal control report would help ensure that deficiencies in the adviser's self-custody controls that could enable fraudulent activities are discovered early and rectified, therefore reducing the risk of client losses. The calendar year requirement, which is consistent with the calendar year cadence for the internal control report requirement under the current related person QC rule,[262] is intended to ensure that advisers periodically engage independent assessments of their safeguarding practices and controls, which would increase the likelihood that significant control issues are detected and addressed. The periodic checks on the adviser's safeguarding controls may also act as a deterrent to advisers that may consider misappropriating client crypto assets.

Under the proposed rule, advisers would need to obtain the first internal control report only once within six months of taking self-custody of a client's crypto asset. For example, if the adviser takes self-custody of one type of crypto asset (“Crypto Asset A”), and within the six month period obtains self-custody of another type of crypto asset (“Crypto Asset B”), the first ( printed page 63906) internal control report may cover both controls for Crypto Asset A and Crypto Asset B, as long as the first internal control report is obtained within six months of taking self-custody of Crypto Asset A. If the adviser takes self-custody of Crypto Asset B after the first six months of taking self-custody of Crypto Asset A but before the next internal control report is due, the adviser would not be required to get a separate internal control report related to Crypto Asset B, but rather would obtain the next internal control report covering controls for both Crypto Asset A and Crypto Asset B (and any other crypto assets held in self-custody at that time) no less than one calendar year after the first internal control report is obtained.

We recognize that some advisers may need to move crypto assets from their self-custody to qualified custodians that become available to maintain the crypto assets or cease their self-custody operations, and that this could happen in less than the applicable time periods that an internal control report would cover. An adviser would not be expected to obtain an internal control report if it does not hold any client crypto assets in self-custody by the time an internal control report would otherwise be due. For instance, an adviser that held a client crypto asset in self-custody for less than six months and does not hold any other client crypto assets in self-custody would not be required to obtain an internal control report. An adviser that holds a crypto asset in self-custody for more than six months but less than a year would need to obtain the first internal control report but would not be required to obtain the annual internal control report to the extent the adviser does not hold any other crypto asset in self-custody.

The proposed adviser self-custody rule would require the internal control report to be prepared by an “independent public accountant” with reference to that term's definition in the Advisers Act custody rule, meaning a public accountant that meets the standards of independence described in rule 2-01(b) and (c) of Regulation S-X.[263] The Commission has long recognized that an audit by an objective, impartial, and skilled professional contributes to both investor protection and investor confidence.[264] We continue to adhere to this bedrock principle, which is critical in the context of the internal control report, because requiring the accountant to be independent in fact and in appearance would contribute to investor protection and investor confidence in connection with the relationship between an accountant and the adviser.[265]

Under the proposed adviser self-custody rule, for the internal control report to satisfy the rule's requirements, the accountant preparing the report must verify that the client's crypto assets are reconciled to the crypto network. This requirement parallels the current custody rule's provision whereby accountants preparing the internal control report for advisers and related persons acting as qualified custodians must verify that the client's funds and securities are reconciled to a custodian,[266] for example, the Depository Trust Corporation, unaffiliated with the adviser or its related person.[267] Because transactions in and ownership of crypto assets are recorded on their crypto networks, at this time, the crypto asset's associated crypto network serves as the most appropriate and analogous location unaffiliated with the adviser to verify the adviser's reconciliations. Verification with the crypto network serves as a critical check on potential fraud when the adviser self-custodies the crypto assets. The accountant preparing the internal control report is in the best position to perform this check because the accountant will have access to the information necessary to verify crypto assets when testing controls over the adviser's reconciliation processes. Reconciliation of an adviser's custodial records to the crypto network is a key control objective of the internal control report, which will report on, among other things, tests of controls designed to meet this specific objective. Internal control reports regarding custody, such as SOC 1 Type 2 reports, however, may not necessarily include specific procedures performed by the accountant that are designed to verify the reconciliation of crypto assets. For this reason, we are requiring this verification to be performed in connection with, and reported in, the internal control report.[268]

As long as the control objectives are addressed, the proposed requirement is intended to provide advisers the flexibility to leverage existing attestation work to satisfy regulatory requirements, or work currently performed as part of internal control reports prepared to meet client demand. For example, a report that provides a description of controls and whether the controls were suitably designed and implemented and operating effectively throughout the period, commonly referred to as a “SOC 1 Type 2 Report,” would satisfy the requirements of the internal control report. A report that simply provides a description of controls and whether the controls were suitably designed and implemented as of a specified date, commonly referred to as a “SOC 1 Type 1 Report,” would not satisfy the requirements of the internal control report because it does not test operating effectiveness of the controls.

Although this proposal would not require an adviser to file with the Commission the internal control report received from an independent public accountant, advisers would be required to disclose in Form ADV, Part 1, consistent with current practice, whether reports prepared by an independent public accountant that examined the adviser's internal controls contained unmodified opinions.[269] If an adviser checks “Report Not Yet Received” in response to this question, the adviser must promptly file an amendment to its Form ADV to update its response when the accountant's report becomes available. This information, together with the proposed amendments to Item 9 of Form ADV, Part 1, where advisers would need to report whether they self-custody crypto assets, would be crucial to the Commission staff's ability to identify areas in need of further outreach and examination regarding controls at advisers that self-custody crypto assets.[270]

We request comment on the proposed internal control report requirement:

94. Do commenters agree that an adviser that has self-custody of client crypto assets presents risks to client assets that are not present when an independent qualified custodian that is neither the adviser nor a related person ( printed page 63907) of the adviser maintains client assets including crypto assets? Do commenters agree that the proposed internal control report requirement would help to reduce those risks? Would the requirement enhance the safeguarding of client assets not maintained with a qualified custodian and reduce the risk of loss or misappropriation?

95. Would the proposed internal control report requirement result in significant operational burdens or costs for advisers including smaller advisers and regulated funds with smaller advisers? Would the proposed internal control report requirement result in additional costs or operational burdens on advisory clients? For example, would the requirement cause advisory clients to lose access to services or other efficiencies they currently receive? Would the requirement result in higher costs for advisory clients? Would obtaining an internal control report present additional issues if the adviser providing self-custody of client crypto assets is located outside of the United States?

96. Would requiring the internal control report to be prepared by an independent public accountant raise any particular challenges for advisers? Would using independent public accountants increase the costs of obtaining these reports or make it too difficult to obtain a qualified accounting firm to provide an internal control report? Should there be a different independence standard for accountants performing the engagement for purposes of the internal control report requirement under the proposed adviser self-custody rule? Does an independent public accountant have the expertise and technical skills with crypto assets, crypto networks, and crypto systems necessary to prepare an internal control report? If not, who else is better situated to prepare an internal control report that would further the objectives of the Advisers Act custody rule? Should the rule permit advisers to obtain the internal control report from other categories of persons, other than independent public accountants, if those persons have experience and expertise in assessing custody-related controls for crypto assets? If so, what standards (including independence standards) should apply to these persons and internal control reports prepared by such persons?

97. The current and proposed Advisers Act custody rule define an independent public accountant as a public accountant that meets the standards of independence described in rule 2-01(b) and (c) of Regulation S-X (17 CFR 210.2-01(b) and (c)).[271] Do advisers that voluntarily obtain internal control reports, for example, due to investor demand or risk management purposes, obtain them from independent public accountants that are independent according to this standard? If not, do they have another standard for determining independence? For example, do advisers require independent public accountants to meet the independence standard set by the American Institute of Certified Public Accountants? Do advisers require an independent public accountant to be unaffiliated from the custodian?

98. Under the current and proposed definition of “independent public accountant” in the Advisers Act custody rule, accountants performing surprise examinations, preparing internal control reports, or conducting financial statement audits are required to meet the standards of independence described in rule 2-01(b) and (c) of Regulation S-X (17 CFR 210.2-01(b) and (c)). Should the definition of “independent public accountant” be amended so that it is defined as a public accountant that meets the standards of independence described in rule 2-01 of Regulation S-X, under which all the independence provisions, definitional provisions, and other related provisions in rule 2-01 of Regulation S-X, in addition to existing restrictions on the financial, employment, and business relationships between an accountant and an audit client and restrictions on an accountant providing certain non-audit services to an audit client, would apply to accountants performing engagements under the Advisers Act custody rule? Why or why not?

99. Should the adviser self-custody rule prescribe particular steps an adviser should take to review internal control reports for control exceptions? For example, should we expressly require an annual review of these reports by the adviser's Chief Compliance Officer and the adviser's personnel with the technical skill set to review such reports (for example, the adviser's cybersecurity personnel and accountants)? Should we require the adviser to provide disclosure to its investors regarding material control exceptions?

100. We state our view above that a SOC 1 Type 2 report, which examines internal controls over financial reporting, would satisfy the requirements of the internal control report under the proposed adviser self-custody rule. Should the rule, however, require the adviser to obtain certain other type(s) of internal control report(s), given the highly technological nature of crypto assets? If so, what type(s) of internal control report(s) should we require and why? For example, should the adviser self-custody rule require the adviser to obtain an internal control report that addresses its controls relevant to security, availability, processing integrity, confidentiality, and/or privacy ( e.g., System and Organization Controls 2 (“SOC 2”) report)? What concerns, if any, do commenters have about an adviser obtaining a SOC 1 Type 2 report regarding crypto assets in its self-custody, but not a SOC 2 Type 2 report? Are there different attestation reports that should be considered or required to satisfy the requirements of the internal control report under the proposed self-custody rule?

101. Should an internal control report for advisers having self-custody of crypto assets have similar control objectives to the internal control report we would require of qualified custodians that are related persons of advisers? Or should those control objectives be different from those required of qualified custodians that are related persons of advisers? If so, what should those control objectives be? Should an internal control report relating to the safeguarding of crypto assets have similar control objectives to the internal control report we would require of custodial services for traditional assets? Or should those control objectives be different due to the different nature of the assets? If so, what should those control objectives be?

102. When preparing an internal control report for purposes of the proposed adviser self-custody rule, should an accountant verify that client crypto assets are reconciled to the crypto network, as proposed? Should this verification occur at a location other than the crypto network? Why or why not? Is any guidance needed on this verification requirement?

103. Under the proposed adviser self-custody rule, for the internal control report to satisfy the rule's requirements, the accountant preparing the report must verify that the client's crypto assets are reconciled to the crypto network. Could there be instances where an adviser is affiliated with a crypto network that stores the crypto assets in the adviser's self-custody? If so, what would be the nature of that affiliation between the adviser and the crypto network, and does that affiliation create or enhance conflicts of interest that the proposed custody rule ( printed page 63908) amendments should uniquely address? [272] What additional or different requirements in those instances should apply to the internal control report to verify the adviser's reconciliations, to preserve the integrity of the internal control report, and to promote investor protection under the custody rule?

104. What challenges, if any, do accountants face or foresee bespoke to the testing of controls relating to custodial services for crypto assets, such as challenges associated with the inherent features of a crypto network that make it difficult to test in a traditional manner?

105. Should we require a different time period in which an adviser would be required to obtain the internal control report? For example, should we require the adviser to obtain its first internal control report within one year after taking self-custody of client crypto assets, as opposed to the proposed six months? Should we require the adviser to obtain an internal control report at least annually thereafter? Alternatively, should the internal control report be obtained more or less frequently?

106. Does the proposed internal control report requirement create any particular challenges for advisers including smaller advisers and regulated funds with smaller advisers? If so, what changes should be made to the rule to mitigate those challenges?

107. Do service providers of crypto wallet technology and software platforms provide internal control reports? If not, could the use of service providers by an adviser to administer its self-custody program create any challenges with respect to testing controls for purpose of obtaining an internal control report required under the proposed self-custody rule? [273]

108. If advisers are subject to both the proposed adviser self-custody rule and the related person QC rule with respect to different client assets, would it be possible for an adviser to use the same accountant to perform both examinations under a single internal control report to satisfy both rules? Why or why not? Does an accountant need specialized knowledge with respect to crypto assets to prepare the internal control report pursuant to the proposed adviser self-custody rule, such that it would be difficult to use the same accountant to satisfy the internal control report requirement under both the adviser self-custody rule and the related person QC rule?

7. Self-Custody Account Statements to Clients

The proposed adviser self-custody rule would require account statements to be sent at least quarterly to each of the adviser's clients whose crypto assets the adviser has in self-custody. The statement would identify the crypto asset address on the crypto network that stores the client's crypto assets and the crypto network on which such crypto asset address operates and the amounts of crypto assets stored in the client's crypto asset address at the end of the period, and set forth all transactions from that crypto asset address during that period. The statement also would urge the client to compare the account statements from the adviser with the crypto asset balances and transaction information indicated under the client's crypto asset address (“self-custody account statement requirement”).[274] Advisers may satisfy this self-custody account statement requirement if, at least quarterly in lieu of an account statement, they transmit, or arrange for the transmission, to clients, the information required to be provided in the account statement in a human-readable and reasonably usable electronic format, provided that a notice is sent to the client identifying the crypto asset address that stores the client's crypto assets and the crypto network on which such crypto asset address operates.[275] The proposed self-custody account statement requirement is intended to provide clients with transparency into their crypto assets in the adviser's self-custody and to help deter fraudulent conduct by the adviser. We also propose corresponding amendments to the Advisers Act recordkeeping rule to require advisers to maintain copies of these account statements, records of transmissions and notices sent to clients.[276]

For purposes of the self-custody rule, “account” would mean the crypto asset address under which the client's crypto assets are stored. As discussed above, the crypto asset address functions as a unique identifier on the crypto network that is used to send and receive crypto assets and to identify the corresponding crypto asset's balances and transactions on the crypto network, similar to a bank account number.[277] Moreover, under the proposed segregation requirement, advisers would be required to maintain each client's crypto assets under crypto asset addresses that store only such client's crypto assets.[278] As such, the account statements sent to clients pursuant to the proposed adviser self-custody rule should in effect reflect crypto asset amounts and transactions identified under the corresponding crypto asset address that stores the client's crypto assets on the crypto network.

Account statements would provide investors with transparency as to holdings of and transactions in their crypto assets, thereby increasing the likelihood that a loss would be detected sooner, and misconduct would be deterred. The Advisers Act custody rule currently requires the adviser to have a reasonable basis, after due inquiry, for believing that the qualified custodian sends an account statement, at least quarterly, to each client for which the qualified custodian maintains funds or securities.[279] If the adviser or a related person is a general partner of a limited partnership or holds a comparable position with another type of pooled investment vehicle, the account statement under rule 206(4)-2(a) must be provided to the limited partners or other beneficial owners in the pooled investment vehicle.[280] Because there would be no qualified custodian involved in self-custody arrangements, the proposed adviser self-custody rule would require quarterly account statements to be sent to the client when the adviser has self-custody of client crypto assets. This requirement would enhance investor protection by allowing clients to review their account statements to evaluate the legitimacy of any movement of their crypto assets, for example, by comparing the activity purported in the account statements to the actual activity under the relevant crypto asset addresses on the associated crypto network. Furthermore, an adviser would be less likely to engage in unauthorized trading with clients' crypto assets when account statements are delivered to clients showing trading and account activity.[281]

( printed page 63909)

The proposed adviser self-custody rule would require the account statement to identify the crypto asset address on the crypto network that stores the client's crypto assets and the crypto network on which such crypto asset address operates as well as a statement urging the client to compare the account statements from the adviser with crypto asset balances and transaction information indicated under the client's crypto asset address on the crypto network. This requirement draws from the current notice requirement in the Advisers Act custody rule, which requires an adviser to promptly notify the client in writing of identifying information about any accounts that an adviser opens on behalf of a client.[282] As discussed earlier in this proposal, the proposed adviser self-custody rule would require advisers to maintain client crypto assets segregated by crypto asset addresses that store only the client's crypto assets and not the crypto assets of others.[283] This and the self-custody account statement requirement would allow clients to identify and monitor their crypto asset holdings and transactions by their bespoke crypto asset addresses on the crypto network.

We continue to believe that the notice requirement provides important client protections and that similar information should be provided to clients pursuant to the proposed adviser self-custody rule to enhance the transparency of the adviser's use of client crypto assets held in self-custody. Clients would be able to monitor their crypto asset balances and transactions directly on the crypto network, and potentially reduce the likelihood that an adviser would misappropriate crypto assets in their self-custody, provided that clients know where their crypto assets are stored on the crypto network. Moreover, the required legend included in the account statement urging clients to compare the adviser's account statements with information indicated under the client's crypto asset address would serve to effectively remind clients to proactively take steps to protect their crypto assets by regularly reviewing their crypto asset balances and transactions on the crypto network. This would help to reduce the likelihood that any loss or unauthorized use of a client's crypto assets would go undetected for an extensive time.

The proposed adviser self-custody rule is designed to remain principles-based and adapt to developments over time in order to allow advisers the flexibility to utilize the inherent functionalities of crypto assets and their crypto networks and the available technology to provide clients with access to their account activity, and it would not require the adviser to be the one to deliver the required information for purposes of the proposed self-custody rule. Several commenters writing to the Crypto Task Force stated that onchain records of crypto asset ownership and transactions are reliable and independently verifiable.[284] Software tools such as blockchain explorers may provide clients with a user-friendly interface to review crypto asset transactions and balances directly on the crypto network in an easily readable format. These tools may also enable real-time alerts of crypto asset transactions to clients through various communication channels such as email, SMS or in-app notifications, thus enhancing transparency and reducing the risk of fraud by keeping clients informed about their crypto assets and facilitating prompt detection of suspicious activities. These tools, by providing clients with timely and accurate information about their crypto assets and allowing them to verify the legitimacy of each crypto asset transaction directly on the crypto network, may reduce the likelihood that advisers engage in fraud.

Given the potentially protective elements of the technology discussed above, the proposed adviser self-custody rule would not preclude advisers from utilizing these tools to satisfy the proposed self-custody account statement requirement. As noted above, the proposed adviser self-custody rule would permit advisers to satisfy the self-custody account statement requirement by transmitting, or arranging for the transmission, to clients the information required to be provided in an account statement, i.e., the amount of crypto assets stored in the client's crypto asset address at the end of the period and all transactions in the crypto assets that occurred under the client's crypto asset address during that period, at least quarterly in a human-readable and reasonably usable electronic format, in lieu of delivering a consolidated account statement prepared offchain. The specific technology, systems or files that comprise the required information as well as the method of delivery to satisfy this requirement would generally be within the adviser's discretion.

In order to further the proposed self-custody account statement requirement's intended benefits of transparency for advisory clients, however, the information transmitted to clients must be accurate in a human-readable and reasonably usable electronic format, and comply with the requirements of the proposed adviser self-custody rule discussed above. A human-readable format is a format that can be naturally read by a human, and a reasonably usable electronic format is a format that is common and compatible with commonly used systems for accessing and reading electronic records.[285] An adviser may, for example, satisfy the proposed requirement by utilizing a software application ( e.g., a wallet alert) that sends notifications to clients, at least quarterly, alerting them of transactions under their crypto asset addresses, so that clients can review their crypto asset transactions and balances under those addresses on the crypto network or through a blockchain explorer. In some instances, transaction and ownership data with respect to some crypto assets may be obscured and untraceable on the crypto network, as in the case of privacy tokens which are designed to preserve the anonymity of crypto asset users and their transactions on the network.[286] To satisfy the proposed self-custody account statement requirement, an adviser that has self-custody of privacy tokens would need to additionally provide clients with access to view the required crypto asset balances and transactions information in a human-readable and reasonably usable electronic format.

Rule 206(4)-2 currently requires an adviser that acts as general partner of a pooled investment vehicle to send account statements to each limited partner (or member or other beneficial owner) in the pooled vehicle.[287] Under the proposed adviser self-custody rule, an adviser that holds client crypto assets in self-custody on behalf of a pooled ( printed page 63910) investment vehicle must do the same with respect to any account statements, transmissions or notices sent pursuant to proposed rule 223-1(b)(7)(vi) if the adviser or its related person is a general partner (or managing member or holds a comparable position for another type of pooled investment vehicle) of such pooled vehicle.[288] This is required because delivery of account statements to the adviser itself but not to the limited partners would not afford investors the intended benefit of transparency from the account statement nor deter the adviser's misuse of client crypto assets.[289] This delivery requirement would also apply to any transmissions and notices sent pursuant to the proposed adviser self-custody rule, which would help to provide investors in pooled vehicles transparency into pooled vehicles' crypto asset activities on the crypto network.[290] An adviser that seeks to satisfy the self-custody account statement requirement by transmitting, or arranging for the transmission of, the required information as discussed above would need to transmit, or arrange for the transmission of, the required information, along with the required notice identifying the crypto asset address on the crypto network where the crypto assets are stored and the crypto network on which such crypto asset address operates, to each limited partner (or member or other beneficial owner) in the pooled vehicle.

The proposed adviser self-custody rule would allow for two circumstances under which an adviser would not be required to comply with the proposed self-custody account statement requirement.[291] First is with respect to an account of a limited partnership (or limited liability company, or another type of pooled investment vehicle) that undergoes a financial statement audit at least annually and upon liquidation in accordance with paragraphs (i) through (ii) of the audit provision.[292] This largely mirrors the audit provision under the current Advisers Act custody rule that permits pooled investment vehicles to deliver audited financial statements in lieu of having a reasonable belief that a qualified custodian delivers account statements to investors.[293] Moreover, this proposal would not preclude an adviser from relying on the audit provision to be excepted from the annual surprise examination requirement with respect to pooled investment vehicles that invest in self-custodied crypto assets.

We are permitting pooled investment vehicles that invest in self-custodied crypto assets to rely on the audit provision because the benefits of a financial statement audit are not less protective in the context of self-custodied crypto assets compared to other custody arrangements for pooled vehicles pursuant to the Advisers Act custody rule. A financial statement audit regularly involves an accountant confirming account balances and securities holdings as of a point in time and includes the testing of transactions that have occurred throughout the year. We believe that the common types of audit evidence procedures typically performed by accountants during a financial statement audit, e.g., physical examination or inspection, confirmation, documentation, inquiry, recalculation, re-performance, observation, and analytical procedures, serve as important checks on adviser behavior with respect to transactions and withdrawals.

Secondly , under the proposed adviser self-custody rule, an adviser that holds crypto assets in self-custody with respect to an account of a regulated fund need not send account statements to those regulated funds.[294] Like pooled investment vehicle clients of advisers relying on the audit provision, regulated funds also undergo financial statements audits.[295] Investors are able to review the regulated fund's audited annual financial statements each year via required annual reports. Open-end regulated funds, including exchange-traded funds, are required to transmit to their investors annual and semi-annual shareholder reports that highlight key information for investors. These shareholder reports include a website address where the regulated fund's annual and semi-annual financial statements are available, and the regulated fund is also required to file its financial statements (which, in the case of annual financial statements, must be audited) on Form N-CSR.[296] Closed-end management investment companies include audited financial statements in their annual shareholder reports, which are required to be filed on Form N-CSR.[297] BDCs are required to file Form 10-K annually, which includes audited financial statements.[298] The proposed account statement delivery requirement is not necessary for regulated funds for the same reasons it is not necessary for other pooled investment vehicles that provide audited financial statements to their investors.

The current Advisers Act custody rule allows advisers to send any required account statements and notices to an independent representative designated by the client.[299] We are amending this provision to allow advisers to do the same for account statements, transmissions and notices sent on any crypto assets in their self-custody.[300] We understand that some clients may not wish to receive account statements and would prefer to have an independent representative receive account statements on their behalf. As long as the designated recipient of the account statements meets the definition of “independent representative,” [301] we believe advisers should be able to deliver account statements, transmissions, and notices regarding self-custodied crypto assets in accordance with the clients' preferred method of receipt regardless of the asset class.

We request comment on the proposed self-custody account statement requirement:

109. Should the proposed adviser self-custody rule include the requirement ( printed page 63911) that account statements are sent at least quarterly to clients? Why or why not? Would the proposed requirement have a significant cost impact on advisers and would those costs be passed on to advisory clients? Are there alternatives to the proposed self-custody account statement requirement to ensure that clients are given auditable records to monitor their crypto asset balances and transactions?

110. Is the proposed self-custody account statement requirement sufficiently clear? Should we provide any additional clarification regarding the proposed requirement? If so, what changes should we make?

111. Should we prescribe particular steps an adviser should take to ensure that account statements are sent to clients? For example, should the rule affirmatively require the adviser to deliver account statements to clients (as opposed to a requirement that account statements “must be provided,” as proposed)? Should the rule instead require an adviser to deliver account statements to clients and additionally to provide clients with access to the crypto network against which they could verify their crypto asset balances and transactions indicated on the adviser's account statements? Should the rule expressly require the adviser to set up notifications to go out to clients at least every quarter alerting them to review their crypto asset activities on the crypto network? How would this or other alternatives impact costs to advisers and advisory clients?

112. Is our understanding correct that there are tools that allow crypto asset owners to monitor activities and balances under their crypto asset addresses (including their crypto asset balances and transactions) on the crypto network in a human-readable and reasonably usable electronic format and that provide real-time alerts regarding crypto asset transactions? Can the frequency of these alerts be configured so that, for example, alerts go out at the end of every quarter as opposed to at every transaction?

113. Would providing advisory clients the ability to monitor their crypto assets directly on the crypto network reduce the risk of fraud? Why or why not? Could onchain records regarding crypto asset transactions and ownership, whether by themselves or translated into human-readable and reasonably usable electronic formats, satisfy the substantive requirements of the proposed self-custody account statement requirement ( i.e., that account statements provide the amounts of crypto assets in the account at the end of the quarterly period and set forth all transactions in the crypto assets in the account during that period)? Do traditional account statements provide other information that is not available onchain but necessary to protect clients and reduce the risk of fraud (for example, notices regarding any changes in the client's crypto asset address, which would not be reflected onchain), in that delivery of account statements should be required by the adviser self-custody rule?

114. Is information viewable directly on the crypto network, or through a blockchain explorer, sufficient to convey to advisory clients in a human-readable and reasonably usable electronic format the information otherwise required in an account statement ( i.e., the crypto asset address on the crypto network that stores the client's crypto assets and the crypto network on which such crypto asset address operates, the amounts of crypto assets stored in the client's crypto asset address at the end of the period and all transactions from that crypto asset address during that period)? What modifications, if any, should be made to the self-custody account statement requirement to ensure that advisory clients are able to obtain the information they need to verify their crypto asset balances and transactions directly onchain in lieu of receiving an account statement?

115. What are best practices with respect to the types of formats, files or systems used as account statements or similar equivalents to provide clients with information regarding their crypto asset balances and transactions? Or, alternatively, are there any measures that commenters have found to be ineffective or relatively less effective?

116. Many advisers or their related persons serve as advisers to pooled investment vehicles or to other similar entities ( e.g., general partner of a limited partnership). The proposed adviser self-custody rule would except these advisers from the requirement to have account statements sent with respect to pooled investment vehicles that are audited annually and distribute their audited financial statements to the investors in the pool. Should we except these advisers from the proposed self-custody account statement requirement? Should we except advisers from this requirement with respect to crypto assets held in self-custody for a regulated fund for the same reasons, as proposed? Would the investors in those pools or regulated funds find the account statement useful to monitor the pooled vehicle's or regulated fund's account activity? Are there other persons that we should except from the proposed self-custody account statement requirement?

117. For what purpose are privacy tokens used? Does one need a privacy token's private keys to access information on the crypto network regarding the privacy token's balance and associated transactions? If so, what compliance challenges would advisers face with respect to satisfying the proposed self-custody account statement requirement for privacy tokens in their self-custody?

8. Financial Asset Election

The proposed adviser self-custody rule would require an adviser and the client to agree, in writing, to treat each crypto asset held in the adviser's self-custody for such client as a financial asset, and that the adviser holding the client's crypto asset in self-custody is a securities intermediary, pursuant to applicable State law that governs the written agreement between the adviser and the client (a “financial asset election”).[302] Under this proposal, an adviser would be required to retain copies of these financial asset elections.[303]

State law governs the written contractual treatment of an asset as a financial asset and a party to the written agreement as a securities intermediary pursuant to the applicable State's enacted version of Article 8 of the UCC. Article 8 of the UCC governs how financial assets are held by a “securities intermediary” that maintains “securities accounts” for others ( e.g., a clearing corporation, broker-dealer or a bank). While “financial asset” has a specific definition in Article 8 that includes a security, it is also defined as any property that is held by a securities intermediary for another person in a securities account if the securities intermediary has expressly agreed with the other person that the property is to be treated as a financial asset under Article 8 of the UCC.[304] Article 8 of the UCC defines a “securities intermediary” to include a person, including a bank or broker, that in the ordinary course of its business maintains securities accounts for others and is acting in that capacity.[305] “Securities account” means an account to which a financial asset is or may be credited in accordance with an agreement under which the person maintaining the account undertakes to treat the person for whom the account is maintained as entitled to exercise the ( printed page 63912) rights that comprise the financial asset.[306] Although Article 8 mentions broker-dealers, banks, and clearing corporations as examples of securities intermediaries, Article 8's broad definitions for securities intermediary and securities account do not preclude their application to investment advisers and accounts managed for advisory clients.[307]

A financial asset election allows parties to an agreement to opt into treating certain assets held at a securities intermediary in a securities account as financial assets under Article 8 of the UCC even if they may not otherwise qualify as a financial asset.[308] A financial asset election, accompanied by crediting of the financial asset to a person's securities account by the securities intermediary in its records, allows a person to acquire a security entitlement ( i.e., rights and property interest), and to become an entitlement holder, with respect to the financial asset in that securities account.[309] The proposed requirement would not impose additional recordkeeping requirements to perfect a financial asset election because an adviser's current recordkeeping obligations under Advisers Act rule 204-2 already require an adviser to maintain, among other things, a record for each security in which each client has a position and showing the name of each such client having an interest in such security.[310] Under this proposal, this provision would apply to any records that the adviser makes and keeps pursuant to the proposed adviser self-custody rule, including with respect to regulated funds, provided that references to securities under rule 204-2(b) would also be understood to include any crypto assets of a regulated fund that the adviser self-custodies.[311]

A financial asset election, in turn, subjects the securities intermediary to the rules and duties owed to the entitlement holder as set forth in Article 8 and provides certain protections and priorities to entitlement holders. For example, a securities intermediary is required to maintain a financial asset in sufficient quantities corresponding to all security entitlements with respect to that financial asset.[312] Article 8 also provides that the financial asset is not the property of the securities intermediary and is generally not subject to claims of creditors of the securities intermediary,[313] and that entitlement holders have priority of claims to the financial asset over the claims of other creditors.[314]

The UCC is a model commercial code and does not have the effect of law unless a State enacts it. Therefore, the proposed financial asset election requirement provides that the adviser must make the financial asset election pursuant to applicable State law that governs the written agreement between the adviser and the client. Currently, all fifty States have enacted Article 8, although the specific version adopted may vary from State to State.[315] The proposed requirement is intended to allow the adviser and the client to invoke the financial asset election and the attendant obligations as provided for in the applicable State's enacted version of Article 8 that governs the written agreement between the adviser and the client.

The proposed financial asset election requirement is critical to the protection of advisory clients in light of uncertainty that often exists with respect to the proprietary status of customer assets held at financial intermediaries in the event of their bankruptcy or insolvency.[316] In many cases, whether customer assets are the property of the customer as opposed to the intermediary depends on written agreements between the customer and the intermediary.[317] The proposed requirement is thus intended to help ensure that a client's crypto asset in an adviser's self-custody is clearly maintained as the client's property and protected from adverse claims by a third party looking to secure or satisfy an obligation of the adviser in cases of the adviser's insolvency or bankruptcy. A financial asset election provides important protections in the context of self-custodied crypto assets given that advisers are not otherwise governed by other protections typical of other custody arrangements ( e.g., FDIC protections for banks or Securities Investor Protection Corporation (“SIPC”) protections for broker-dealers). This requirement, in combination with the proposed segregation requirement that would help to attribute client crypto assets as clearly belonging to the appropriate client, would directly and comprehensively achieve a longstanding policy goal of the Advisers Act custody rule which includes protecting client assets from the adviser's financial condition.

We request comment on the proposed financial asset election requirement under the Advisers Act self-custody rule:

118. Should the proposed self-custody rule include the financial asset election requirement? Is the proposed requirement sufficiently clear? If not, why not? Would it be more efficient for practitioners if we set forth the definitions of “financial asset,” “securities intermediary,” and other terms used in Article 8 of the UCC relevant to a financial asset election ( e.g., “securities account”) in the text of the Advisers Act custody rule itself? Alternatively, should the Advisers Act custody rule incorporate by reference the terms “financial asset” and “securities intermediary” by defining ( printed page 63913) such terms as having the same meanings as are attributed to those terms in Article 8 of the UCC, and if so, from which specific edition ( e.g., the 2025-2026 edition) or version ( e.g., 2022 amended) of the UCC should the Advisers Act custody rule incorporate these terms by reference, and why? Would parties to an agreement making the financial asset election be able to effectuate a financial asset election and invoke its attendant obligations under relevant State law if that State has not adopted the specific edition or version of the UCC from which the Advisers Act custody rule has incorporated these terms by reference?

119. Would the financial asset election requirement as proposed allow parties to invoke the financial asset election and the attendant obligations under the applicable State's laws that govern the written agreement between the adviser and the client? Why or why not? Would this approach help ensure that the financial asset election requirement remains evergreen in the Advisers Act custody rule? Why or why not?

120. Would the proposed financial asset election requirement offer substantial protections for advisory clients in the event of an adviser's bankruptcy or insolvency? If not, why not? Would the proposed financial asset election requirement help ensure that a client's crypto asset in an adviser's self-custody is clearly maintained as the client's property? If not, why not?

121. In order for a financial asset election to be effectuated under Article 8 of the UCC, the securities intermediary must credit in its records the financial asset to a person's securities account, which then allows a person to acquire a security entitlement ( i.e., rights and property interest), and to become an entitlement holder, with respect to the financial asset in that securities account. The proposed financial asset election requirement would not impose additional recordkeeping obligations beyond an adviser's current obligations under Advisers Act rule 204-2. Are any additional records beyond those already required by Advisers Act rule 204-2 necessary to ensure that a client acquires a security entitlement and becomes an entitlement holder with respect to the financial asset?

122. To make the proposed financial asset election, the adviser would be a “securities intermediary” as such term is defined in Article 8 of the UCC. A “securities intermediary” includes a person that in the ordinary course of its business maintains securities accounts for others and is acting in that capacity. “Securities account” means an account to which a financial asset is or may be credited, and is not limited to accounts holding securities as defined in the Federal securities laws or in Article 8. An adviser holding client assets in self-custody could come within that definition because the adviser, like banks and brokers traditionally viewed as security intermediaries, would be maintaining assets on behalf of clients rather than solely providing investment advice about assets maintained at a qualified custodian. Are there any reasons as to why an investment adviser could not be a securities intermediary under Article 8 of the UCC? Should the adviser self-custody rule include, as proposed, that the adviser and client agree that the adviser holding the client's crypto assets in self-custody is a securities intermediary? Why or why not?

123. Are there any crypto assets within the scope of the proposed adviser self-custody rule that cannot be subject to a financial asset election under Article 8 of the UCC? If so, which crypto assets are they, and why? Are there any other steps necessary to effectuate a financial asset election, or any ramifications that would stem from a financial asset election, that the proposed adviser self-custody rule should address?

124. Are there any ramifications of requiring a financial asset election, under State law or otherwise, that we should consider? For example, what negative ramifications or consequences, if any, arise from an investment adviser acting as a securities intermediary under Article 8 of the UCC?

B. Self-Custody of Regulated Fund Crypto Assets

As described in more detail below, the proposal would permit an investment adviser to custody a regulated fund client's crypto assets if the adviser complies with the adviser self-custody rule described above, and if the regulated fund's board of directors engages in oversight of the custody arrangement as required under proposed rule 17f-9, the fund self-custody rule.[318]

The custodial challenges associated with crypto assets discussed above in section I.A.2 apply to regulated funds just as they do to other types of advisory clients. Permitting a regulated fund's adviser to maintain the regulated fund's crypto assets pursuant to the proposed adviser self-custody rule would allow the regulated fund, like other clients of the adviser, to invest in crypto assets where a qualified custodian is unavailable and the adviser maintains the assets in self-custody subject to conditions designed to safeguard the regulated fund's crypto assets from loss, theft, misuse and misappropriation.

The proposed fund self-custody rule would require, prior to the investment adviser maintaining a regulated fund's crypto asset and quarterly thereafter, that the fund's board of directors, including a majority of directors who are not interested persons of the fund, reviews the investment adviser's written report documenting the basis for the adviser's determination for believing that no qualified custodian will maintain the crypto asset.[319]

In addition, the proposed rule would require, prior to the investment adviser maintaining the regulated fund's crypto asset and annually thereafter, that the board of directors, including a majority of directors who are not interested persons of the fund, determines that the crypto asset will be subject to reasonable care, if maintained with the regulated fund's adviser, after considering the factors relevant to the safekeeping of the crypto asset.[320] To facilitate the board's determination, the proposed rule would require the regulated fund's adviser to furnish and the regulated fund's board to evaluate, such information as may reasonably be necessary for the board to evaluate the fund's custody arrangement of the crypto asset.[321]

This information must include at a minimum, the following:

The board oversight requirements in the proposed fund self-custody rule for crypto assets reflect that board oversight is appropriate where there are heightened risks of misappropriation of fund assets by the regulated fund's investment adviser. These proposed requirements also reflect a similar approach in the current fund self-custody rule for traditional assets, which likewise requires board involvement in a regulated fund's self-custody arrangements.[325] Rule 17f-2 requires a regulated fund's board to approve the personnel that have access to self-custodied fund assets and the fund personnel that receive the related transaction records.

The proposed board review of the investment adviser's written determination that no qualified custodian is available to maintain the regulated fund's crypto asset is designed to allow the board to provide oversight of the adviser's QC determination.[326] The board's review of the QC determination will allow the board to evaluate the necessity of self-custody by, for example, asking questions regarding the material facts upon which the QC determination is based and the adviser's process for making its QC determination.

The written report we propose to require the adviser to furnish, containing information regarding the adviser's safeguarding expertise and systems under the proposed adviser self-custody rule, would include information that is fundamental to the adviser's justification for self-custodying a fund's crypto asset.[327] The written report would help the board evaluate the adviser's capability to take on the role of custodian and put in place effective safeguards to address the risk of loss, theft, misuse, or misappropriation.

The annual review of safeguarding systems and cybersecurity controls, including the effectiveness of their implementation, would help the board evaluate the adviser's safeguarding systems and cybersecurity controls.[328] This requirement is designed to ensure that the board is evaluating the safeguards and cybersecurity controls used for self-custody and considering, at least on an annual basis, whether the safeguarding systems and cybersecurity controls continue to reflect that the adviser is capable of self-custodying the regulated fund's assets. Since self-custody poses a risk of misappropriation by the investment adviser, the board's evaluation of the safeguarding systems would help to ensure the adviser remains capable of safeguarding regulated fund crypto assets and continues to implement robust safeguards when self-custodying fund crypto assets. As the self-custody of crypto assets involves cybersecurity risks, the annual review requirement would also facilitate board oversight of the effectiveness of the adviser's cybersecurity controls. The board's oversight of whether the adviser's cybersecurity controls remain up to date is critical in light of the continuous emergence of novel cybersecurity threats to crypto assets and to ensure that the controls adequately address and mitigate the risk of cybersecurity incidents.

Similarly, requiring advisers to provide the internal control reports they have obtained would provide an important check on risks relating to regulated fund crypto assets held by the adviser. In this regard, these internal control reports, as described above, must include an opinion of an independent public accountant as to whether the adviser's controls associated with its holding client crypto assets in self-custody were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services.[329] These reports therefore would supplement the adviser's own determination that a crypto asset is subject to appropriate safeguarding systems and would represent an independent source of information that the board would review and rely on in making its reasonable care determination.

The written report documenting the basis for the investment adviser's QC determination would be reviewed by the board initially before the adviser were to hold a regulated fund's crypto asset in self-custody and thereafter on an quarterly basis.[330] Receiving the report initially would allow the regulated fund's board, prior to the adviser taking self-custody of a fund's crypto asset, to evaluate the adviser's QC determination that there is a need for self-custody. This timing would also allow the board to prevent the adviser's self-custody of the regulated fund's crypto asset if the board determines that the QC determination is not based on adequate due inquiry, is not supported by the facts in the written report, or is inconsistent with the regulated fund's best interests. The board may also choose to request further information from the adviser regarding the availability of qualified custodians to help it evaluate the need for self-custody. Receiving the required written report quarterly would allow the board to provide oversight of the adviser's ongoing quarterly QC determinations and evaluate each quarter whether self-custody of a fund's crypto asset continues to be necessary and justified by the most recent quarterly report.

The proposed fund self-custody rule would require certain other information to be provided to the board initially before the adviser were to hold a regulated fund's crypto asset in self-custody and thereafter on an annual basis. For example, the written report documenting the adviser's safeguarding expertise and systems would be provided on this schedule.[331] Receiving the required information initially would ( printed page 63915) allow the regulated fund's board to evaluate the custodial arrangement for a crypto asset before the adviser takes the crypto asset into self-custody. This timing would allow the board to probe the self-custody arrangement and request changes, if any, to the arrangement consistent with the regulated fund's best interests. The timing would also allow the board to prevent the adviser's self-custody of the regulated fund's crypto asset if the board determines that self-custody is inconsistent with the regulated fund's best interests. Receiving the required written report annually would help the board stay up to date on the adviser's safeguarding expertise and systems that may impact the board's reasonable care determination.

The proposed rule would also require the adviser to furnish, and the board to evaluate, the most recent written annual review of the adviser's safeguarding systems and cybersecurity controls prior to the investment adviser self-custodying the crypto asset, if available, and annually thereafter.[332] If the most recent written annual review is not available prior to the investment adviser self-custodying the fund's crypto asset, such information must be furnished by the adviser to the board for its evaluation by the next regularly scheduled board meeting.[333] A written annual review of the adviser's safeguarding systems may not be available at the time of the board's initial determination if the investment adviser had not been holding crypto assets in self-custody for the regulated fund or other clients for at least one year at the time of the board's determination. This timing is intended to ensure that the board is informed about the current state of the safeguarding systems used to protect the regulated fund's crypto asset so that the board can evaluate whether the safeguarding systems work prior to the adviser self-custodying the regulated fund's crypto asset and on a continuing basis. The proposed rule would also require the adviser to furnish, and the board to evaluate, the adviser's most recent internal control report prior to the adviser's initial custody of the crypto asset, if available, and then annually thereafter.[334] If the most recent written internal control report is not available prior to the adviser self-custodying the fund's crypto asset,[335] such information must be furnished by the adviser to the board for its evaluation by the next regularly scheduled board meeting after the information becomes available to the adviser. If the adviser has not been holding a crypto asset in self-custody for any client for at least six months at the time of the next regularly scheduled board meeting, then the information must be furnished by the first regularly scheduled board meeting following expiration of the six-month time period.[336] The board's ongoing oversight aided by the receipt of the internal control reports may act as an incentive for an adviser to ensure its safeguarding systems and processes continue to be sufficiently robust to prevent potential misappropriation of crypto assets.

Serious safeguarding issues must be brought to the board's attention promptly and cannot be delayed until the next board meeting. In addition, individual safeguarding matters that, taken in isolation, may not be material may collectively suggest a serious safeguarding issue. The adviser must promptly notify the board if any of the regulated fund's crypto assets maintained by the adviser are lost, stolen, misused, or misappropriated. Other examples of serious matters that would need to be brought to the board's attention promptly include significant cybersecurity events that materially raise the risk of harm to the regulated fund or an internal control report where the auditor will not issue an unmodified opinion. Alerting the board to such serious matters is consistent with the adviser's fiduciary duty and necessary to lower the risk of loss, theft, misuse, and misappropriation.

As discussed above, under the proposed fund self-custody rule, advisers would be required to provide, such information as may reasonably be necessary for the board to evaluate the regulated fund's custody arrangement. Such information may include further information beyond that explicitly required by the proposed rule that may be relevant to the board's determination. This could include, for example (and if not already provided in the required written report), additional information or assessments by an independent third party, relating to the adviser's safeguarding expertise and systems. Other factors the board may wish to consider in making its determination that the regulated fund's crypto asset will be subject to reasonable care could include, for example, the availability of insurance or other arrangements put in place by the adviser to reimburse the regulated fund in the event of loss of the regulated fund's crypto asset and the terms of such arrangements and how the adviser intends to use third-party service providers (if at all) in self-custodying the crypto asset and what steps the adviser takes to manage risk from such arrangements.

We request comment on the proposed board oversight requirements:

125. Pursuant to the proposed fund self-custody custody rule, a regulated fund would be permitted to maintain its crypto asset with the regulated fund's adviser without the involvement of a qualified custodian provided that the adviser complies with the adviser self-custody rule described above (and the regulated fund complies with certain board oversight requirements). Should a regulated fund be permitted to maintain its crypto asset with the fund's adviser? Why or why not? Is it appropriate to permit a regulated fund to maintain its crypto asset with the fund's adviser only where the adviser complies with the proposed adviser self-custody rule? Why or why not?

126. The proposed fund self-custody rule can only be relied on by registered investment management companies and BDCs. Should the rule permit other types of entities to rely on it? For example, should UITs or FACCs be able to rely on the rule? If so, how should the rule be modified, if at all, to accommodate these entities? For example, could the trustee or sponsor of a UIT, instead of a regulated fund board, comply with the rule's board oversight requirements?

127. The proposed fund self-custody rule would require board oversight of the custody arrangement between the regulated fund and its adviser. Is board oversight of the custody arrangement appropriate and necessary to protect against misappropriation by the adviser? Why or why not?

128. As part of the board oversight of the custody arrangement between the regulated fund and its adviser, the proposed fund self-custody rule would require the board to determine that the regulated fund's crypto asset will be subject to reasonable care, if maintained with the regulated fund's adviser, after considering the factors relevant to the safekeeping of the crypto asset. Is the board's reasonable care determination the appropriate standard to facilitate board oversight of the custody arrangement? Why or why not? Should the proposed rule provide additional detail about the reasonable care standard, for example, by requiring the ( printed page 63916) reasonable care standard to be based on standards applicable to safekeeping the crypto asset?

129. The proposed fund self-custody rule would require the board to review the written report documenting the basis for the investment adviser's determination that no qualified custodian will maintain a regulated fund's crypto asset before the investment adviser maintains the crypto asset and quarterly thereafter. Is it appropriate to require the regulated fund's board to review and evaluate, this specific information? Why or why not? Is such information necessary for the board to evaluate the adviser's justification for self-custodying a regulated fund's crypto asset? Should the fund self-custody rule provide specific matters that must be addressed in the report? Should the regulated fund's board be required to review and evaluate such information at an in-person board meeting, as proposed, or would it be appropriate for the board to evaluate such information by written consent in lieu of an in-person board meeting?

130. The proposed fund self-custody rule would require the investment adviser to furnish, and the regulated fund's board of directors to evaluate, a written report documenting the basis for the investment adviser's determination under the adviser self-custody rule that the adviser has expertise regarding the safeguarding of the regulated fund's crypto asset and the systems necessary to safeguard such crypto asset against loss, theft, misuse and misappropriation. Is it appropriate to require the adviser to furnish, and the regulated fund's board to evaluate, this specific information? Why or why not? Is such information necessary for the board to evaluate whether the regulated fund's crypto asset will be subject to reasonable care if maintained at the adviser? Should any other information be required to be in the written report or otherwise provided to the board in addition to the basis for the adviser's determination it has the expertise and systems necessary to safeguard the fund's crypto asset?

131. Should the proposed fund self-custody rule require a regulated fund's board to make a determination that a fund's crypto asset maintained with the regulated fund's investment adviser will be subject to reasonable care prior to the adviser maintaining the regulated fund's crypto asset? Why or why not? Should the rule require a regulated fund's board to, at least annually, determine that a regulated fund crypto asset maintained with the regulated fund's investment adviser continues to be subject to reasonable care?

132. The proposed adviser self-custody rule would require the investment adviser to make its QC determination at least quarterly and, if it determines that a qualified custodian has become available to maintain the regulated fund's crypto asset, the adviser must place such crypto asset with the qualified custodian as soon as reasonably practicable.[337] If the adviser places the regulated fund's crypto asset with a qualified custodian under such circumstances, should the fund self-custody rule require that the board be notified? If so, how soon should the board be notified after the placement at the qualified custodian, for example, at the next quarterly board meeting or “as soon as reasonably practicable”? Should the board instead be notified as soon as the adviser determines that a qualified custodian has become available? If so, how soon should the board be notified after the determination, for example, at the next quarterly board meeting or “as soon as reasonably practicable”?

133. Should the proposed fund self-custody rule require the regulated fund's investment adviser to furnish, and the regulated fund's board of directors to evaluate, the most recent internal control report obtained by the adviser pursuant to the adviser self-custody rule? Would this requirement help the regulated fund's board in making its determination that a crypto asset maintained by the regulated fund's investment adviser will be subject to reasonable care? Would this requirement potentially incentivize the adviser to ensure its processes for maintaining the regulated fund's crypto asset are robust? Would the requirement act as a deterrent against the adviser's potential misappropriation of the regulated fund's crypto asset? Is there any other information an adviser should be required to provide the regulated fund's board to help evaluate the internal control report? Should the proposed fund self-custody rule require the adviser to furnish, and the board to evaluate, the most recent internal control report prior to the adviser's initial custody of the crypto asset if available, and annually thereafter? Why or why not? If not, what initial and ongoing cadence should be required instead and why? If such information is not available prior to the investment adviser self-custodying the crypto asset, should the fund self-custody rule require, as proposed, the most recent written internal control report to be furnished by the adviser to the board for its evaluation by the next regularly scheduled board meeting after the information becomes available to the adviser, but in no case later than the next regularly scheduled board meeting following six months from the date the adviser takes self-custody of the crypto asset? Why or why not? If not, what timing standard would be more appropriate than “by the next regularly scheduled board meeting”?

134. Should the proposed fund self-custody rule require the regulated fund's investment adviser to furnish, and the board of directors to evaluate, any other documents or reports to assist the board in its reasonable care determination, for example, reports related to the adviser's financial asset election discussed above? [338]

135. Should the proposed fund self-custody rule require the adviser to furnish, and the board to evaluate, the most recent written annual review of the adviser's safeguarding systems and cybersecurity controls prior to the investment adviser self-custodying the crypto asset, if available, and annually thereafter? Why or why not? If not, what cadence should be required instead and why? If such information is not available prior to the investment adviser self-custodying the crypto asset, should the fund self-custody rule, as proposed, require the most recent written annual review to be furnished by the adviser to the board for its evaluation by the next regularly scheduled board meeting after the information becomes available? Why or why not? If not, what timing standard would be more appropriate?

C. Custody of Crypto Assets by State Trust Companies

1. Overview and Scope

The custody rules generally require that advisory clients' and regulated funds' assets be maintained with certain permitted custodians. For the reasons discussed above in section I.A.2, the Commission is proposing amendments to the Advisers Act custody rule and a new custody rule under the Investment Company Act (together, the “proposed State trust company rules”) to add State trust companies as an additional category of permitted custodian for crypto assets, subject to certain conditions designed to safeguard client crypto assets from loss, theft, misuse, and misappropriation.[339] The proposed ( printed page 63917) conditions are designed to address common custodial risks that bank regulations generally address, as well as to address the custodial risks that are unique to the custody of crypto assets. Because State trust companies are subject to State regulations that can vary from State to State, the proposed conditions are designed to provide that the adviser or regulated fund has made a determination that the State trust company is authorized and regulated by an applicable State authority and that certain protective conditions apply that are designed to help ensure that the State trust company is an appropriate custodian for crypto assets.

Under the proposed State trust company rules, prior to engaging a State trust company as a custodian for crypto assets, and on an annual basis thereafter, the adviser or regulated fund must determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company:

(1) is authorized by the relevant State banking authority to provide custody services for crypto assets and related cash and/or cash equivalents and

(2) maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation.

These policies and procedures would be required, at a minimum, to address private key management and cybersecurity.

In addition, the adviser or regulated fund would be required to receive and review the State trust company's audited annual financial statements and most recent internal control report prior to engaging the State trust company as a custodian and on an annual basis thereafter.

Further, under the proposed State trust company rules, all client crypto assets must be held in segregated accounts.[340] For regulated funds, the regulated fund must enter into a custodial services agreement with the State trust company that provides that all crypto assets and related cash and/or cash equivalents held in custody for the fund will be held in accounts segregated from the State trust company's proprietary assets.[341]

In the event an advisory client engages the State trust company custodian directly, the adviser would be required to satisfy the proposed conditions prior to the adviser having custody of those client crypto assets that are maintained at the State trust company as custodian. If the adviser did not satisfy the proposed conditions, the adviser would nonetheless not be limited in its ability to provide nondiscretionary investment advice to its client regarding the client's crypto asset investment that is maintained at a State trust company where the client makes the investment on its own and not through the adviser and the adviser does not have custody of the client's assets maintained at the State trust company.

In connection with the proposed State trust company rule, we are also proposing to amend Form ADV to require an adviser to disclose whether a State trust company maintains client funds or securities pursuant to the proposed rule.[342] We describe all these requirements in more detail below.

For other types of permitted custodians, we rely on the existing regulatory framework to ensure that the custodian has appropriate internal controls. For example, under Federal banking laws, banks are subject to certain regulatory requirements related to internal controls.[343] In the absence of a uniform set of regulatory controls for State trust companies, which may vary by State, requiring the adviser or regulated fund to receive and review a State trust company's internal control reports would help ensure that the State trust company has adequate internal controls in place and is implementing such controls. In addition to the proposed requirements, an adviser would continue to be required to exercise its fiduciary duty of care to act in the best interests of its clients.[344] An adviser's fiduciary duty applies to the selection and monitoring of a custodian and would therefore also apply to the selection of a State trust company as a permitted custodian for client crypto assets under the proposed State trust company rules.[345]

Under the proposed State trust company rules, the adviser or regulated fund would be limited to maintaining only crypto assets and related cash and/or cash equivalents at the State trust company custodian. The proposed rules are intended to facilitate crypto asset custody by State trust companies and enhance investor protection by requiring certain protective conditions. As discussed further above in section I.A.2, we have observed that funds and advisers have historically experienced challenges in obtaining crypto asset custodial services with traditional custodians and that State trust companies have emerged as a custodial solution for crypto assets specifically. We are not aware of similar challenges with respect to other asset classes nor a significant need or demand for custodial services from State trust companies for other asset classes at this time, but we request comment on whether the proposed State trust company rules should be expanded to include any other asset classes.

For the rules applicable to both advisers and regulated funds, we propose to define a State trust company as “a legal entity organized under State law that is supervised and examined by a State authority having supervision over banks and permitted to exercise fiduciary powers under applicable State law.” [346] The requirement in the proposed definition for the State trust company to be “supervised and examined by a State authority having supervision over banks” is designed to ensure that a State banking authority regulates the custodial activities of the State trust company and that the State trust company is subject to State examination and supervision, similar to that of a State bank.

Although under the proposed State trust company rules, a State trust company would be a separate category of permitted custodian, a regulated fund or adviser would not need to rely on the proposed rules with respect to a State trust company if the State trust company meets the definition of “bank” under the Investment Company Act or Advisers Act, as applicable.[347] The proposed State trust company rules are designed to permit a regulated fund or adviser to use a State trust company as a custodian for crypto assets without having to determine the entity's status as a “bank” under the relevant statutes. The proposed rules, however, would not ( printed page 63918) preclude a regulated fund or adviser from performing this analysis.[348]

We request comment on all aspects of the scope of the proposed State trust company rules and the proposed definitions of State trust company, including the following:

136. Pursuant to the proposed State trust company rules, a State trust company (that is not otherwise a bank as defined for purposes of the applicable custody rule) would be a permitted custodian for client or regulated fund crypto assets and related cash and/or cash equivalents only. Alternatively, should a State trust company custodian be permitted to act as custodian for any other types of assets? If so, which asset classes and why? Are regulated funds and advisers experiencing custodial challenges for other types of assets for which State trust companies provide custodial services? Are State trust company custodians generally engaged for custodial services for asset classes other than crypto assets and related cash and/or cash equivalents?

137. As proposed, should the rules scope the definition of State trust company to include only those State trust companies that are organized under State law and are supervised and examined by a State authority having supervision over banks? Is it necessary to limit the scope of State-registered entities in this way? Why or why not? If not, how should we define the State regulation requirements? Alternatively, should the proposed definition be expanded to include all State-regulated trust companies, including those that are not supervised and examined by a State authority having supervision over banks?

138. Is it clear what it means for a State trust company to be “supervised and examined” by a State authority? If not, how should we modify the definition to make it clear? Should the proposed definition instead refer to the State trust company being subject to examination by a State authority on a particular frequency, such as on an annual basis?

139. Should we, as proposed, limit the definition of State trust company to State trust companies that are permitted to exercise fiduciary powers under applicable State law? Why or why not? Would this aspect of the proposed definition appropriately limit the entities that would satisfy the definition? Alternatively, should the definition be modified to include any State-registered entity that is authorized to provide custodial services for crypto assets? Why or why not?

140. Should the proposed definition require that the applicable State regulatory framework include any particular considerations? For example, for the purposes of the proposed rules, should the State trust company definition be limited to those State trust companies that are subject to State regulations that require ongoing supervision and periodic examination by State authorities, minimum capital requirements for State trust companies, restrictions on activities and balance sheet investments, periodic financial condition and/or business operation reporting requirements, recordkeeping requirements, and/or supervision by State banking authorities having authority to bring enforcement proceedings for non-compliance? Alternatively, should the proposed State trust company definition be limited to those State trust companies that are subject to State supervision and examination with standards substantially similar to those in equivalent Federal regulatory frameworks?

141. Should the proposed State trust company definition instead require that the State trust company be licensed under applicable State law and be subject to certain minimum eligibility requirements for licensing under applicable State law?

142. Should the scope of the proposed rules be modified to include other non-trust entities, for example an entity that operates pursuant to a New York BitLicense (which is explicitly not authorized to exercise fiduciary powers under New York law) or any other State-regulated entity that would not otherwise meet the proposed definition of a “State trust company”? How are these entities regulated and how does the regulatory treatment of such non-trust entities differ from State trust companies that are supervised and examined by a State authority having supervision over banks?

143. Is the meaning of the term “related cash and cash equivalents” in this context clear? Would it be burdensome to determine whether certain cash and cash equivalents constitute “related” cash and cash equivalents?

144. The proposed rule 17f-8 can only be relied on by registered investment management companies and BDCs. Should the rule permit other types of entities to rely on it? For example, should UITs or FACCs be able to rely on the rule? Could the trustee or sponsor of a UIT comply with the rule's requirements to make a reasonable basis determination?

2. Initial and Annual Determinations

As described in more detail below, the proposed rules would require that an adviser or regulated fund make certain reasonable basis determinations, after due inquiry, regarding the State trust company, prior to engaging the State trust company as a custodian for crypto assets and on an annual basis thereafter.[349] The proposed reasonable basis determinations are intended to require the adviser or regulated fund to perform sufficient due diligence to determine that the State trust company is an appropriate and capable custodian for crypto assets.

To demonstrate a reasonable basis for its determinations under the proposed State trust company rules, an adviser or regulated fund would need to conduct reasonable due diligence of the State trust company. The due diligence would not require identification of every custodial risk associated with using a State trust company as a custodian for crypto assets or boundless analysis of the State trust company. The proposed rule is intended to be flexible and allow advisers and regulated funds to tailor their due diligence practices, while ensuring that the due diligence performed covers certain key areas that are relevant to the use of a State trust company as a custodian for crypto assets. We are also proposing corresponding amendments to the recordkeeping rules to require advisers and regulated funds to maintain records related to these reasonable basis determinations.[350]

(a) Authorization to Custody Crypto Assets

Under the proposed State trust company rules, the adviser or regulated fund would be required, prior to engaging the State trust company custodian and on an annual basis, to determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company is authorized by the relevant State banking authority to provide custody services for crypto assets and related cash and/or cash equivalents. In forming its reasonable basis, an adviser or regulated fund should conduct due inquiry into ( printed page 63919) the State trust company and the governing State laws and regulations that apply to the State trust company to determine whether the State trust company is authorized to provide crypto asset custodial services.[351] An adviser or regulated fund may consider obtaining a legal opinion of counsel and/or a certification from the State trust company regarding the State trust company's authorization to custody crypto assets under applicable State law, in conjunction with other due diligence, to support its reasonable basis determination.

In addition to the proposed definitions of State trust company discussed above, this proposed condition is designed to provide that the adviser or regulated fund diligences whether the State trust company is permitted under applicable State law to provide custodial services for crypto assets and is subject to applicable custodial regulation. This proposed condition is intended to help ensure that the adviser or regulated fund has a reasonable basis for believing that the State trust company is qualified, able, and authorized to properly safeguard crypto assets and is subject to appropriate regulatory oversight for its custodial activities. The annual requirement is designed to ensure that the adviser or regulated fund periodically reassesses whether there have been any applicable State law or regulatory changes that may impact whether the State trust company continues to be authorized under State law to provide crypto asset custodial services.

We request comment on all aspects of the proposed State authorization requirement, including the following items:

145. Should any guidance be provided on how an adviser or regulated fund can satisfy the proposed reasonable basis requirement or what due diligence would be required to support a reasonable basis determination?

146. The proposed State trust company rules require that the adviser or regulated fund has a reasonable basis for believing that the State trust company is authorized by the State to provide custodial services for crypto assets. Is this requirement clear? Do commenters anticipate any challenges associated with satisfying this requirement?

147. Alternatively, should the proposed rules require that the adviser or regulated fund determine that the State trust company is in “good standing” (or an equivalent status) in the applicable State?

(b) Policies and Procedures

The proposed State trust company rules would require that, prior to engaging a State trust company as a permitted custodian for client crypto assets and on an annual basis thereafter, the adviser or regulated fund must determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation, with such policies and procedures, at a minimum, addressing private key management and cybersecurity. In forming this reasonable basis, the adviser or regulated fund should review the State trust company's policies and procedures to determine whether the policies and procedures address private key management and cybersecurity, as well as assess the adequacy and effectiveness of the policies and procedures on these topics, and whether the State trust company's policies and procedures as a whole are reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation. As a part of the reasonable basis determination, the adviser or regulated fund should also conduct a reasonable investigation to determine whether the State trust company adequately implements its policies and procedures. An adviser or regulated fund may consider obtaining a certification from the State trust company or an assessment by counsel or other third party regarding the adequacy and implementation of the State trust company's policies and procedures to support its reasonable basis determination.

As discussed above in sections II.A.3.b)(1) and II.A.4, secure private key management and cybersecurity are essential to the ability to safeguard crypto assets. Similar to the proposed requirements for adviser or regulated fund self-custody, the proposed condition for required adviser or regulated fund due diligence of the State trust company policies and procedures is designed not to be prescriptive as to specific policies and procedures and to be flexible and adaptable to changes that may occur over time. This would permit advisers or regulated funds to rely on the State trust company custodians tailoring and evolving their policies and procedures for their custodial practices to adapt to evolutions in technology and best practices in crypto asset safeguarding. The proposed requirement for advisers or regulated funds to review the policies and procedures on an annual basis allows the adviser or regulated fund to regularly reassess whether the State trust company's policies and procedures continue to appropriately safeguard crypto private key material and address cybersecurity risks, which are central to crypto asset safeguarding and may evolve over time.

The proposed requirement for the adviser or regulated fund to diligence the State trust company's policies and procedures to determine if they address private key management reflects that proper private key management is a critical aspect of safeguarding crypto assets.[352] In order for the State trust company's policies and procedures to address private key management, the adviser or regulated fund would need to consider whether the State trust company's private key management policies and procedures cover the essential elements related to private key management, such as private key generation, managing access to key materials, and location and means of key material storage. For example, the adviser or regulated fund may consider whether the State trust company's policies and procedures limit the number and/or geographic dispersal of persons with access to private key material, address the number of persons required to authorize transactions, and adequately govern the use of cold, warm, and hot storage for maintaining crypto assets.

While the proposed State trust company rules would not require that the adviser's or regulated fund's diligence confirm that any specific key management policies and procedures are in place, the adviser or regulated fund must determine whether the State trust company's policies and procedures, including those related to key management, are reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation. Due to the rapid evolution of technology and development of best practices in the crypto asset market, an adviser's or regulated fund's reasonable basis determination may change over time; as such, the adviser or regulated fund would need to consider any relevant industry and market changes to be able to continue to have a reasonable basis ( printed page 63920) for believing that the State trust company's policies and procedures are designed to adequately safeguard custodied crypto assets.

The proposed requirement for the adviser or regulated fund to determine that it has a reasonable basis for believing that the State trust company's policies and procedures address cybersecurity similarly reflects the Commission's view that cybersecurity is an important component of secure custody of crypto assets given the heightened vulnerability of crypto assets to adverse cyber events. Similar to the inquiry related to private key management, the adviser would need to make a due inquiry into the State trust company's policies and procedures related to cybersecurity in forming its reasonable basis. While the proposed rules would not require that the adviser confirm whether any particular cybersecurity-related policies and procedures are in place, the adviser may consider whether and to what extent the State trust company's policies and procedures address such relevant cybersecurity topics as cyber-attack prevention, cyber-attack event detection, cybersecurity incident response and escalation, and external reporting of cybersecurity incidents. The adviser may also consider the State trust company's policies and procedures related to system access privileges and management, systems and network security and monitoring, cybersecurity training, and data management and disposal.[353] Given the constant evolution of cybersecurity vulnerabilities and threats, the adviser should consider, as a part of its annual determination, whether the State trust company's policies and procedures can continue to adequately address evolving cybersecurity risks to the crypto assets that it custodies. For example, the adviser may consider whether the State trust company's policies and procedures provide for periodic review of the adequacy of its cybersecurity controls and practices to ensure the security of its systems and/or mandate regular ongoing cybersecurity trainings that are routinely updated to reflect relevant risks.

Finally, other aspects of the State trust company's policies and procedures may be relevant in determining whether the policies and procedures are reasonably designed to safeguard crypto assets and related cash and/or cash equivalents. For example, other relevant considerations may include whether the State trust company's policies and procedures cover such topics as, minimum required insurance related to the loss or theft of client crypto assets, minimum levels of reserves, physical security protections, and privacy protections for customers.[354]

We request comment on all aspects of this proposed rule, including the following:

148. Is the proposed requirement for the adviser or regulated fund to determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents appropriate? Why or why not?

149. Would it be burdensome for advisers or regulated funds to be required to review the State trust company's policies and procedures? Alternatively, should the rule permit advisers or funds to review a summary of the State trust company's policies and procedures and/or a certification that verifies that the State trust company's policies and procedures are reasonably designed to safeguard crypto assets and related cash and/or cash equivalents and include private key management and cybersecurity policies and procedures?

150. The proposed State trust company rules would require the adviser or regulated fund to determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents with such policies and procedures addressing, at a minimum, private key management and cybersecurity. Should the proposed State trust company rules refer to any specific key management and/or cybersecurity policies and procedures? If so, what key management and/or cybersecurity policies and procedures? For example, should the adviser or regulated fund be required to have a reasonable basis, after due inquiry, for believing that the State trust company's policies and procedures require the State trust company to maintain client crypto assets in cold storage at all times or limit the amount of crypto assets and/or time that crypto assets can be held outside of cold storage or for believing that the State trust company custodian's key management-related policies and procedures mandate joint authorization of transactions?

151. Should the State trust company custodian's cybersecurity-related policies and procedures be required to address certain topics? For example, should the rule require that the adviser or regulated fund has a reasonable basis, after due inquiry, for believing that the State trust company's policies and procedures address particular topics, such as minimum required technical expertise and/or systems?

3. Financial Statement Audit

Under the proposed State trust company rules, the adviser or regulated fund would be required to receive and review the State trust company's most recent annual financial statements both prior to engaging the State trust company as a custodian and on an annual basis. The adviser or regulated fund would also be required to receive and review the financial statements to confirm they were prepared in accordance with U.S. GAAP and subject to an audit performed by an independent public accountant.[355] In the event the State trust company's financial statements are presented on a consolidated basis with its parent or other affiliates that have substantive activities, an adviser or regulated fund may be able to satisfy this proposed requirement by receiving and reviewing copies of the parent's or affiliate's audited financial statements, provided that the adviser or regulated fund is able to make the confirmations required under the proposed rule by reviewing such consolidated financial statements. We are also proposing corresponding amendments to the recordkeeping rules to require advisers and regulated funds to maintain copies of these audited financial statements.[356]

The proposed audited financial statements requirement would provide advisers and regulated funds with important information about the State trust company's financial position. Receipt and review of the State trust company's audited financial statements can provide the adviser and regulated fund with important information about the ongoing financial stability of the State trust company, which is a relevant ( printed page 63921) consideration for its ability to safeguard client crypto assets effectively.

We request comment on all aspects of the proposed audited financial statements requirement, including the following items:

152. Would requiring that advisers and regulated funds receive and review audited financial statements from the State trust company custodian provide important information about the State trust company's financial position?

153. Should the rule instead require that the audited financial statements that the adviser or regulated fund is required to receive and review also include an evaluation of the State trust company's internal controls over financial reporting?

154. In the event that the State trust company's financial statements are presented on a consolidated basis with its parent and/or other affiliates that have substantive activities and the adviser or regulated fund is not able to make the determination required under the proposed rule, should the audited financial statements requirement be met if the adviser or regulated fund obtains a written certification or representation from the State trust company that the most recent annual financial statements of its parent have been subject to an audit by an independent public accountant and have been prepared in accordance with U.S. GAAP? Would such a certification or representation provide comparable information about the State trust company's financial position? Would there be any risks associated with permitting the adviser or regulated fund to satisfy the audited financial statement requirement by obtaining a certification or representation from the State trust company custodian? If so, how could these risks be mitigated?

4. Internal Control Report

Further, the adviser or regulated fund would be required to receive and review the State trust company's most recent written internal control report prepared by an independent public accountant during the current or prior calendar year both prior to engaging the State trust company as a custodian and on an annual basis. The adviser or regulated fund would have to confirm that such internal control report contains an opinion of an independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of crypto assets and related cash and/or cash equivalents. We are also proposing corresponding amendments to the recordkeeping rules to require advisers and regulated funds to maintain copies of these internal control reports.[357]

As discussed above, the design and implementation of internal controls is particularly important for crypto assets, many of which are bearer instruments and are vulnerable to unique risks of loss compared to other asset classes, such as from cybersecurity incidents.[358] Requiring the adviser or regulated fund to receive and review a written internal control report for the State trust company would provide important information on the design and effectiveness of internal control measures in place to protect client crypto assets from risk of loss. We request comment on all aspects of the proposed internal control report requirement, including the following items:

155. Would requiring that the adviser or regulated fund review an internal control report from the State trust company custodian provide the adviser or regulated fund with adequate information to manage the risks associated with providing custodial services for crypto assets?

156. Should the proposed State trust company rules permit an adviser or regulated fund to receive and review an internal control report prepared by persons other than an independent public accountant, if those persons have experience and expertise in assessing custody-related controls for crypto assets? If so, what standards (including independence standards) should apply to these persons and internal control reports prepared by such persons and who would set those standards?

157. Are there best practices and/or considerations regarding the control objectives and associated controls that the proposed State trust company rules should require the adviser or regulated fund to review in connection with its receipt and review of the State trust company's internal control report? If so, what are they?

5. Segregation of Assets

The proposed State trust company rules would require that all assets held in custody at a State trust company be held in accounts that are segregated from the State trust company's assets.[359] For regulated funds, the custodial services agreement with the State trust company would have to provide for the segregation required by the proposed rule.[360] Segregation of client assets from a custodian's proprietary assets is a long-established principle of custody and critical to safeguarding assets held in custody for the adviser's client or regulated fund, particularly in the case of insolvency of the custodian.[361] In the event of a State trust company custodian's insolvency or bankruptcy, client assets maintained at the State trust company custodian, without proper segregation, could be subject to the claims of the State trust company's other creditors and/or property of the State trust company's estate and subject to the automatic stay in a bankruptcy proceeding.[362]

We request comment on the following:

158. Are there any State or Federal regulations that would prevent a State trust company from segregating assets held in custody for the adviser's client or regulated fund? Are there any State or Federal regulations that would otherwise impact the segregation of assets being held in custody?

159. Should we require that, for regulated funds or advisers to custody assets with a State trust company, the assets must be segregated from other client assets of the State trust company, as well as from the State trust company's own assets? Are there certain circumstances under which omnibus accounting should be permitted and other circumstances where it should not? If so, what are these circumstances? Should we require segregation of client assets according to some other principles?

160. Rehypothecation of client assets by registered broker-dealers is primarily used to finance lending to clients and reduce the costs of the financing. Fiduciary custodians, such as many ( printed page 63922) State trust companies in many jurisdictions, have regulatory restrictions on lending to clients and rehypothecating client assets.[363] Do any State regulatory regimes permit rehypothecation of client assets by State trust companies? If so, what restrictions do these states impose on trust rehypothecation? To what extent and under what conditions do State trust company regulations permit lending by trusts to their custodial clients? Do any State trust company regulatory regimes permit margin accounts or similar arrangements?

161. Are there State trust companies that currently rehypothecate client assets? If so, please provide examples and describe any relevant practices, contract terms and client protections of this rehypothecation. Are affiliates, control affiliates, or entities with significant financial ties to a State trust company receiving rehypothecated assets of the State trust company's clients? If so, please describe these arrangements and what protections are in place for the client's assets.

162. Do any State trust companies hold assets for clients in a non-fiduciary capacity? If so, do practices differ in these arrangements relative to fiduciary custodial arrangements with respect to rehypothecation?

163. To the extent that a State trust company rehypothecates client assets or has authority under State law and the terms of the custodial agreement to rehypothecate client assets, what is the business purpose of such rehypothecation? Does the State trust company profit or otherwise receive economic value? Does the client receive a benefit, and if so, what is it? Do any other clients of the State trust company receive a benefit? Are there any contexts outside of lending to clients in which a State trust company would rehypothecate client assets?

164. To the extent that any State trust companies are rehypothecating client assets pursuant to their applicable regulatory regime, should we permit regulated funds or investment advisory clients engaging these State trust companies as custodians to consent to have their assets rehypothecated? If so, under what conditions?

6. Request for Comment on Other State Trust Company Issues

In addition to the requests for comment about the individual conditions relating to custody of crypto assets by State trust companies above, we also request comment about these proposed conditions generally, including the following items:

165. Should any of the conditions included in the proposed adviser or regulated fund self-custody rules also apply for custody by a State trust company? If so, which conditions or limitations should apply and why? For example, should the proposed safeguarding expertise and systems requirements for crypto self-custody also apply for custody of crypto assets at a State trust company? Should the State trust company rules require that the adviser has a reasonable basis, after due inquiry, for believing that the State trust company elects to treat each crypto asset in its custody as a “financial asset” and the State trust company as a “securities intermediary” pursuant to applicable State law that governs the custodial agreement (similar to the proposed financial asset election requirement under the proposed adviser self-custody rule)?

166. Should the proposed State trust company rules include any additional conditions? For example, should the proposed rules require that the adviser or regulated fund confirms or has a reasonable basis for believing that the State trust company maintains certain minimum capital reserves, has obtained certain minimum insurance coverage, and/or that the State trust company has posted minimum sufficient collateral to the adviser or regulated fund?

167. Should an adviser or regulated fund be required to make an initial and annual determination regarding the suitability of a particular State trust company custodian for custody of crypto assets generally or on a crypto asset-by-asset basis?

168. Should the regulated fund's board of directors be required to review and approve of the reasonable basis determination and/or the engagement of the State trust company?

169. Should any different requirements apply if a client has entered into a custodial arrangement prior to the adviser having custody of the client's crypto asset? If so, what requirements should apply in that circumstance?

170. Should the required ongoing determination be on a different basis than annually? If so, how frequently should an adviser or regulated fund be required to make an ongoing determination with respect to the State trust company? Should an ongoing determination only be required to be made if client crypto assets are maintained at the State trust company custodian for the duration of the annual (or other applicable) period?

D. Decentralized Finance

The Commission's custody rules require an advisory client's funds and securities, and securities and similar investments in the accounts of regulated funds, to be maintained at a permitted custodian, and the proposed adviser self-custody rule would allow an adviser to have self-custody of client crypto assets. An adviser or a permitted custodian, however, may seek to deposit an advisory client's assets in a smart contract in connection with decentralized finance (“DeFi”) protocols and applications (collectively, “DeFi activities”). DeFi activities may be useful for a variety of purposes integral to the functioning of a crypto asset, including for purposes of effectuating crypto asset transactions and earning value on crypto assets. For example, crypto assets may be deposited to a smart contract, which are self-executing software programs that can define how and when crypto assets may be purchased, sold, and transferred, as well as automate dividend and interest payments or other distributions.[364] Smart contracts can be used to effectuate staking arrangements that allow owners of crypto assets to earn rewards ( e.g., newly minted crypto assets or a percentage of transaction fees) if they commit or “stake” their crypto assets to the relevant network for a period of time.[365]

Participating in DeFi protocols also poses certain risks.[366] This includes the ( printed page 63923) risk that a malicious actor could exploit vulnerabilities in the code for a smart contract or the infrastructure of a crypto system to which the crypto assets are deposited, which could result in theft of crypto assets and significant harm to investors with no meaningful recourse to recover those assets. Hacks of DeFi protocols have been on the rise and have resulted in substantial losses of crypto assets.[367] Among other risks, a third party associated with the smart contract might be able to control the deposited crypto assets—and thus to steal them—due to administrative privileges that can be used to change the code governing the smart contract's operation or to otherwise effect unauthorized transactions in the deposited crypto assets.

A regulated fund or adviser participating in DeFi activities must do so in compliance with the custody rules, which require that a regulated fund's assets and advisory client assets over which an adviser has custody be maintained by a permitted custodian, subject to certain exceptions. An adviser maintaining an advisory client's crypto assets in self-custody under the proposed adviser self-custody rule—or any other permitted custodian maintaining a regulated fund's or advisory client's assets under the custody rules—therefore would only deposit a regulated fund or advisory client's crypto assets in a smart contract in connection with DeFi activities if the asset continues to be maintained by the adviser subject to the proposed adviser self-custody rule or other permitted custodian or an exception to the requirement to maintain the crypto assets with a permitted custodian is available.

Commenters writing to the Crypto Task Force offered views on the compatibility of DeFi arrangements with regulated funds' and advisers' obligations under the custody rules. One commenter raised concern that depositing advisory client assets into a staking contract, liquid staking protocol, or DeFi smart contract could be viewed as violating the Advisers Act custody rule because the crypto assets in those arrangements are no longer held in the adviser's or the qualified custodian's wallet when they are “locked” in a third-party smart contract.[368] The commenter urged that the custody rules not prohibit these activities, as long as, for example, advisers are able to maintain and demonstrate effective control over the crypto assets.[369] Several commenters stated that qualities generally inherent in DeFi activities can provide important protections, such as the decentralized, automated, immutable and self-executable nature of DeFi activities where no one party in the network is able to unilaterally and impermissibly wrest possession and control of crypto assets.[370]

To inform whether Commission guidance or modifications to the custody rules would be necessary or appropriate to address DeFi activities, we request comment on the application of the custody rules to regulated funds and advisers' participation in DeFi activities. Specifically, we request comment on the circumstances in which crypto assets deployed in DeFi activities would continue to be maintained by the adviser in self-custody or a permitted custodian under the applicable custody rules, and whether we should permit (and if so, under what conditions) DeFi activities that result in the crypto assets not being maintained at a permitted custodian or the adviser holding the crypto assets in self-custody. Additionally, we request comment on whether custody rules should permit certain DeFi arrangements with certain protections, for example, where the owner of the crypto asset deposited in a smart contract receives a claim or receipt token that entitles the owner of the crypto asset to the return of the deposited crypto asset. We also request comment on how existing Commission guidance and/or modifications to existing custody rules can address crypto asset lending or other DeFi protocols. Additionally, we request comment on how we can best address crypto asset lending or other DeFi protocols, or whether these arrangements should be considered by our staff or via the exemptive application process on a case-by-case basis. Finally, we request comment on the steps advisers currently take to address custodial risks associated with DeFi activities including how advisers analyze vulnerabilities and risks associated with smart contracts and what they consider in their due diligence on a smart contract:

171. In what circumstances can crypto assets be deployed in DeFi activities ( e.g., crypto assets deposited into a smart contract for purposes of staking) while still being maintained by the adviser in self-custody or by a permitted custodian under the applicable custody rules? For example, Commission staff has addressed certain protocol staking arrangements, stating that when a crypto asset owner engages in self (or solo) staking, or engages in self-custodial staking directly with a third party, the crypto asset owner maintains ownership and control of its crypto asset and cryptographic private keys at all times.[371] Commission staff also stated that, in so-called “custodial” staking, the deposited crypto assets remain in the control of the custodian and the crypto asset owner is intended to retain ownership of the crypto assets held by the custodian. In these protocol staking arrangements, as described in more detail in the Protocol Staking Statement, should staked crypto assets be viewed as being maintained by the adviser holding the asset in self-custody or a permitted custodian engaged in custodial staking, because control and ownership of the staked crypto asset do not change? Is it sufficiently clear how regulated funds and advisers would apply this analysis to staking arrangements? What guidance, if any, should we provide on these or other staking arrangements?

172. In other DeFi contexts in addition to protocol staking, when analyzing whether a crypto asset deposited in a smart contract continues to be maintained by a permitted custodian or adviser holding the asset in self-custody, should the analysis turn on whether there has been a change in ownership and control, and if so, how should regulated funds and advisers make this assessment? Would it be ( printed page 63924) reasonable to conclude that ownership and control are maintained if the crypto network makes it possible to reverse or correct unauthorized transfers of the deposited crypto asset? Alternatively, should the analysis turn on the extent of the associated protocol's decentralization, on the basis that a more decentralized protocol would reduce the likelihood that a single or small group of actors could abuse administrative privileges associated with a smart contract to come into control of crypto assets deposited in the smart contract? How should advisers and regulated funds analyze decentralization in this context? Is it feasible for advisers and regulated funds reliably to conclude whether a protocol is sufficiently decentralized to reduce the risk of the abuse of any administrative privileges in the smart contract? Should the analysis more generally turn on the adviser's or a regulated fund's assessment of whether and the extent to which a third party would have control of the crypto assets (that is, not be focused on or limited to analysis of decentralization)? Where an adviser or a regulated fund concludes that a smart contract as currently constituted would not involve a change in ownership and control of the deposited crypto assets, how should the adviser or a regulated fund consider the associated governance process, the possibility of any upgrades to the smart contract's code introducing vulnerabilities to smart contract exploits, and any bonding periods or other mechanism during which deposited crypto assets cannot be withdrawn? How do advisers, regulated funds, and others analyze all of these issues currently?

173. If depositing a crypto asset in a smart contract resulted in that crypto asset no longer being maintained by a permitted custodian or the adviser holding the crypto asset in self-custody, it would not be permitted because, in that case, an advisory client's or regulated fund's crypto assets would not be held by a permitted custodian. Should we permit these activities subject to conditions to address the related risks? For example, should an adviser be permitted to deposit a client's crypto assets in such a smart contract only where clients will be protected against the possibility of their crypto assets being lost or stolen due to insurance arrangements; the adviser's commitment to indemnify the client against lost assets; collateral posted to the adviser; or other arrangements put in place by the adviser or the associated DeFi protocol?

174. How should the analysis apply when the owner of a crypto asset deposited in the smart contract receives a claim or receipt token that entitles the owner of the crypto asset to the return of the deposited crypto asset? Should the custody rules permit these arrangements if the (i) claim or receipt token, rather than the deposited crypto asset, is held in a wallet exclusively controlled by the permitted custodian or adviser holding the asset in self-custody and (ii) there are no or limited restrictions on the ability to use the claim or receipt token to recover the deposited crypto asset and any restrictions that do exist are enforced by the smart contract's code and not subject to the discretion of any person or group of persons? If so, what types of restrictions on the recoverability of the deposited crypto asset would be appropriate? For example, should the smart contract's mechanisms include liquidity arrangements (for example, reserve of liquid crypto assets that allow for timely withdrawals) that mitigate the risk of the adviser being unable to withdraw the client's crypto assets without significant delays? What liquidity and insurance arrangements would help to mitigate the risk of a client being unable to recover its crypto assets from the smart contract? How do market participants currently analyze receipt or claims tokens in these circumstances? How, if at all, would the analysis differ for other kinds of crypto assets received in connection with DeFi activities, like vault tokens that entitle the holder to a share of assets held in a smart contract as opposed to the specific asset the holder deposited?

175. Regulated funds currently engage in securities lending, which implicates the Investment Company Act custody rules, consistent with staff no-action letters.[372] Are these current practices an effective way to address lending or other DeFi protocols? What guidance would be needed on how these current practices could be conducted involving crypto assets or using DeFi protocols?

176. If appropriate conditions when an advisory client's or regulated fund's crypto assets are no longer being maintained by a permitted custodian or the adviser holding the asset in self-custody would depend on the associated DeFi protocol, is it possible to address the range of associated protocols by Commission guidance or modifications to the custody rules, or should these arrangements be considered by our staff or via the exemptive application process on a case-by-case basis?

177. What steps do advisers currently take to address custodial risks associated with DeFi activities? Absent arrangements in place to mitigate the loss of client crypto assets deployed in DeFi activities, if an adviser deposits a client's crypto assets in a smart contract that results in the loss of those crypto assets because, for example, a third party abuses the administrative privileges associated with that smart contract or a third party exploits a vulnerability in the smart contract's code, what recourse should the client have against the adviser?

178. Although smart contracts are intended to be transparent, automated and immutable, their security can be compromised by a bug in the code or a malicious actor manipulating or exploiting the contract's programming.[373] Moreover, some smart contracts have designated addresses with administrative privileges to perform critical operations such as upgrading and modifying the contract's logic and parameters and to pause the contract's operations.[374] These privileges could be abused to further unauthorized actions, and faulty access controls could expose a smart contract to manipulation and hacks.[375] Vulnerabilities in smart contracts have resulted in significant financial losses. Should the presence of these risks preclude depositing the crypto assets of a regulated fund or advisory clients in smart contracts even if control and ( printed page 63925) ownership are maintained? How do advisers currently analyze vulnerabilities and risks associated with DeFi activities that may implicate the Commission's custody rules? To the extent advisers deposit client crypto assets in smart contracts, what do advisers consider in conducting due diligence on the smart contract?

179. Hacks of DeFi protocols have been on the rise, resulting in substantial losses of crypto assets.[376] What changes, if any, to the Commission's custody rules should the Commission consider to address and mitigate the custodial risks associated with DeFi protocols?

180. Are there circumstances where a smart contract should be treated like a wallet, such that an adviser holding a client's assets in self-custody pursuant to the proposed adviser self-custody rule should be permitted to maintain the crypto assets in a smart contract, or use a smart contract in connection with the execution of the client's strategy, rather than using more conventional wallet technology to initiate and sign each transaction? What functionality should such a smart contract have and what steps should the adviser be required to take to ensure the smart contract does not have functionality that would allow any other person access to the deposited crypto assets?

E. Crypto Asset Trading

The Commission explored and rejected the possibility of proposing a new, stand-alone rule to permit advisers and regulated funds to maintain assets on trading platforms that are not permitted custodians (sometimes referred to as the practice of custodying assets “on exchange”) under certain conditions. Based on our understanding of current practice, and taking into account outreach with market participants, we do not have evidence indicating there is need for such a rule at this time. Expanding the scope of permitted custodians to trading platforms—which can take a variety of forms and operate in jurisdictions around the world—could potentially increase the risk of loss, theft, misuse, or misappropriation unless such a rule included conditions designed to match the purposes of using such trading platforms as custodians with their capabilities and risks. Without evidence of any need for such a rule, we are unable to craft and propose an appropriate scope, circumstances, or conditions for any such rule.

In the course of developing this proposal, Commission staff met with crypto asset market participants to determine the extent to which the Commission's regulations should be modified to accommodate trading on platforms that do not meet the existing criteria for permitted custodians for advisers or funds. More specifically, Commission staff explored whether the trading platforms in question were—or could readily become—permitted custodians. Commission staff also examined whether crypto assets maintained by custodians need to be temporarily transferred out of custody to trade or exercise crypto-associated rights. That is, staff's outreach and research aimed to determine whether crypto asset trading generally necessitates prefunding trades in way that requires assets to leave the control of permitted custodians and be transferred to third parties or protocols that do not meet the requirements of the current and proposed custody rules.

Commission staff further sought to ascertain if certain crypto asset investment strategies require that some amount of crypto assets be maintained at trading platforms on an ongoing basis. Additionally, Commission staff examined if the custody rules present obstacles to a regulated fund's or adviser's ability to trade crypto assets or pursue particular investment strategies. In particular, staff communicated with market participants to determine if, for advisers, the limitations of the custody rules could conflict with advisers' fiduciary obligations to serve their clients' best interests.[377] These determinations were important to whether the Commission needed to develop a new, separate trading platform custody rule—or amend existing custody rules.

Outreach by Commission staff has generally shown that it is possible for advisers and funds to structure crypto asset trades without the need to maintain funds or prefund trades on platforms in ways that would violate the custody rules. For example, several crypto asset market participants indicated that it would be a risky practice (one they would not use) to keep assets on a trading platform in hot wallets, or to use similar practices to facilitate trading by leaving crypto assets on a trading platform. These participants suggested that these practices could increase the risk of loss, theft, misuse, or misappropriation. Further, one trading platform told Commission staff that its approach is generally to ensure that the majority of crypto assets are kept in cold storage with broker-dealers—and thus not held on the trading platform itself. Rather, the platform would perform a bookkeeping function after trade completion by documenting when assets changed ownership among the investor accounts with broker-dealers. Likewise, representatives of a crypto asset custodian stated that their firm keeps crypto assets in cold storage during trading, with assets moving out of cold storage later when the trades are settled. In short, all of these market participants described to Commission staff practices consistent with the existing custody rules (and which also would be consistent with the proposed rules).

In addition, Commission staff heard in outreach that some exchanges with affiliated custodians permit trading out of an omnibus wallet held at the affiliated custodian to eliminate the need to move assets in and out of custody and that market practices are generally moving in this direction. Advisers can trade client assets via smart contracts or other non-custodial trading mechanisms and thus avoid potential custodial issues that could arise from the need to prefund trades. Further, in circumstances where trades must be prefunded, some trading platforms have arranged for the assets needed for trading to be placed with a separate counterparty that is a permitted custodian under existing rules, such as a broker-dealer or futures commission merchant, which may help to address custody rule problems. Overall, staff outreach appears to indicate that industry practices are developing in ways that either limit the need to move advisory client or regulated fund crypto assets from the custody of a permitted custodian for trading or that allow the assets that must be moved for trading to be transferred to a permitted custodian in compliance with the custody rules.

For the reasons described above, the Commission is not proposing a separate, crypto asset trading platform custody rule. Notwithstanding this fact, the Commission welcomes comment on all aspects of the issue, including the following:

181. Do commenters agree that a separate, stand-alone trading platform custody rule for advisers and funds is unnecessary? How do factors such as current market practices, the current custody rules, and the proposed changes to the custody rules affect this assessment?

182. Should the Commission permit an investment adviser to place a client's ( printed page 63926) crypto assets, including the crypto assets of a regulated fund, at a crypto trading platform for the purpose of trading, under certain conditions? If so, what conditions should the Commission consider? For example, would any or all of the following conditions help address risks associated with this practice?: (A) The crypto asset trading platform is subject to the jurisdiction of a Federal or State regulatory authority with the power to examine or audit the platform; (B) The investment adviser reasonably determines that placing and maintaining crypto assets at the crypto trading platform presents minimal risk of loss, theft, or misuse of those assets, and the adviser complies with the requirements of the applicable provisions of the proposed adviser self-custody rule; (C) In the case of a client that is a regulated fund, the fund's board determines that it is reasonable to rely on the fund's adviser to evaluate the crypto trading platform and otherwise perform the responsibilities required under the applicable provisions of the proposed adviser self-custody rule; (D) The assets are not maintained on the crypto asset trading platform for periods longer than 24 hours; (E) The adviser receives and reviews the crypto trading platform's policies and procedures regarding the safeguarding of crypto assets before placing client assets on a trading platform; and (F) The adviser regularly obtains and reviews internal control reports of crypto asset trading platforms and provides copies of those reports to clients. Are there other appropriate conditions for allowing advisers to maintain a client's crypto assets at a crypto trading platform for the purpose of trading?

F. Investment Company Custody Rule Modernization

We are proposing to amend the Investment Company Act custody rules to modernize the rules and correct certain errors or inconsistencies. These amendments would: (1) add BDCs to the Investment Company Act custody rules; [378] (2) remove the condition in current rule 17f-1 and make it permissible for regulated funds to custody their securities or similar investments with all broker-dealers registered under section 15(b)(1) of the Exchange Act where the broker-dealer's custody of the securities or other investments is subject to the requirements of rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections; [379] (3) rescind rule 17f-3; (4) update the address to access the Uniform Commercial Code in rule 17f-4; [380] and (5) clarify the definition of a “Eligible Securities Depository” in rule 17f-7.[381] We are also requesting comment on updates to self-custody by regulated funds in rule 17f-2 and the other Investment Company Act custody rules.

1. Business Development Companies

The Commission is proposing to add references to BDCs to certain Investment Company Act rules. Various provisions of the Investment Company Act, including section 17(f) governing custody of securities are incorporated by statute to apply to BDCs to the same extent as if the BDC was a registered closed-end investment company.[382] Under section 17(f), BDCs must place and maintain their securities and similar investments in the custody of a permitted custodian.[383] None of the Investment Company Act custody rules mention BDCs, however, and in many cases were adopted before Congress adopted the amendments to the Investment Company Act that created BDCs. We understand that industry practice has been to interpret the Investment Company Act's application of section 17(f) to BDCs to allow BDCs to rely on the Investment Company Act custody rules to the same extent as registered closed-end investment companies. Consistent with this industry practice, although BDCs may be less likely to rely on certain of these rules due to the nature of their investments, we see no reason to restrict the Investment Company Act custody rules to permit a registered closed-end fund, but not a BDC, to rely on them. The rules' conditions do not turn on the distinction of whether a fund is registered under the Investment Company Act or regulated under the Act in the case of a BDC. We therefore are proposing to add appropriate references to BDCs in the Investment Company Act custody rules to make clear that BDCs may rely on them.[384]

We request comment on the following:

183. Do BDCs currently use the Investment Company Act custody rules to comply with their custodial obligations? If not, how do they comply with section 17(f)?

184. Are there any Investment Company Act custody rules that should not be available to BDCs? Are there any situations, or any specific Investment Company Act custody rules, for which BDCs would operate differently or otherwise not be able to comply fully to the extent that regulated funds would?

2. Broker-Dealer Custody

We are proposing to amend rule 17f-1 to update and modernize the circumstances in which regulated funds may use broker-dealers as custodians. As discussed further below, due to the comprehensive modern broker-dealer regulatory regime, including the financial responsibility rules such as the customer protection rule, which the Commission adopted after the adoption of rule 17f-1 in 1940, the risks to clients that use broker-dealers for custodial services are very different than in 1940. The proposal would amend rule 17f-1 to permit regulated funds to custody securities and similar investments at a broker or dealer registered under section 15(b)(1) of the Exchange Act where the broker-dealer's custody of the securities or similar investments is subject to the requirements of rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections without requiring specific enumerated conditions.[385] For the reasons discussed below, permitting a fund to place and maintain its securities or similar investments with a registered broker-dealer, and not just a member of securities exchange, is necessary or appropriate in the public interest and consistent with the protection of investors and the purposes fairly intended by the policy and provisions of the Investment Company Act.[386] If the Commission were to develop and adopt a rule that provides similar customer protections to rule 15c3-3 under the Exchange Act, proposed rule 17f-1 would permit regulated funds to custody its securities or similar investments with a broker-dealer subject to the requirements of that protective rule without the need to amend rule 17f-1.

Current Rule 17f-1

Rule 17f-1 permits regulated funds to custody their securities or similar investments with a broker-dealer that is a member of a national securities exchange, subject to certain ( printed page 63927) conditions.[387] This rule was adopted in 1940 to correspond to the provision in section 17(f) of the Investment Company Act permitting funds to custody their securities and similar investments with a broker-dealer that is a member of a national securities exchange and has not been substantively amended since.[388] The current rule imposes a number of protective conditions on the custody of a regulated fund's securities and similar investments with a broker-dealer that is a member of a national securities exchange and requires that these conditions be in a written contract with the custodian that is ratified by a majority of the board of directors of the investment company. The conditions this contract must require are:

National Securities Exchange Membership

When Congress passed section 17(f) of the Investment Company Act it defined the permissible custodians under that section to include members of a national securities exchange as defined in the Exchange Act.[390] At the time, members of national securities exchanges and broker-dealers making or creating markets for the purchase and sale of securities other than on a national securities exchange (over-the-counter markets or “OTC markets”) served different functions and were subject different rules and enforcement mechanisms.

Under the Exchange Act, as adopted in 1934, regulation of the OTC market was the Commission's responsibility as there was no self-regulatory organization (“SRO”) for the OTC market.[391] At that time, section 15 of the Exchange Act provided authority for the Commission to prescribe rules for broker-dealers that make or create a market otherwise than on a national securities exchange (called over-the-counter markets (“OTC markets”)), including rules that could provide for such broker-dealers to register with the Commission.[392]

However, under the Exchange Act as adopted in 1934, the direct regulation of broker-dealer activities on national securities exchanges was to be conducted by the exchanges themselves. Brokers or dealers that solely effected securities transactions as members of a national securities exchange were subject to the rules and enforcement mechanisms established by the national securities exchanges.[393] The national securities exchanges provided significantly more oversight for exchange members, both because of the exchanges' experience, and because unlike those that effect transactions in OTC markets, members needed to maintain good standing with an exchange to conduct business through it.[394] The national securities exchanges were themselves subject to Commission registration and oversight, and had by this time existed for decades.[395] Membership with the exchange and adherence to its rules was mandatory for exchange members to transact business on the exchange.[396] The Commission could directly take action such as withdrawing the registration of an exchange, suspending trading on an exchange, or directly suspending any member of a national securities exchange.[397]

The Maloney Act of 1938 provided for the creation of national securities associations of broker-dealers, which are self- regulatory organizations (“SROs”) to govern the OTC markets, and the National Association of Securities Dealers (“NASD”) was registered as an SRO in 1939.[398] At that time, ( printed page 63928) membership in NASD was voluntary for those participating on OTC markets.[399]

In the decades since 1940, the registration and regulatory regime for broker-dealers has expanded considerably. Exchange Act section 15(a) generally requires brokers or dealers that effect securities transactions, or that induce or attempt to induce the purchase or sale of securities, to register with the Commission, absent an exception or exemption.[400] In addition, broker-dealers are required to become members of at least one SRO ( i.e., a national securities association, such as FINRA, or a national securities exchange).[401] Generally, all registered broker-dealers must become members of FINRA (which is the sole national securities association), unless they effect transactions in securities solely on an exchange of which they are a member.[402] In addition to the Commission's comprehensive rules governing all registered broker-dealers, the SROs, including FINRA, have rules that apply to their members and provide additional protections for customers of broker-dealers. In light of the changes in the regulatory landscape for registered broker-dealers since the adoption of rule 17f-1, we are proposing to amend rule 17f-1 to permit regulated funds to custody securities and similar investments at a broker or dealer registered under section 15(b)(1) of the Exchange Act (without requiring specific enumerated conditions) where the broker-dealer's custody of the securities or similar investments is subject to the requirements of rule 15c3-3 under the Exchange Act.

Broker-Dealer Financial Responsibility Rules

The Commission's current rules governing broker-dealer financial responsibility were largely adopted in response to Congressional authorizations that were not granted to the Commission until the 1970s.[403] In the decades since, the Commission has considerably expanded the rules governing broker-dealer capital, margin, segregation, recordkeeping, reporting, notification, securities count and hypothecation requirements, which are part of the broker-dealer financial responsibility rules.[404] The broker-dealer financial responsibility rules establish a comprehensive regulatory program designed to, among other things, protect customer funds and securities, ensure that broker-dealers can promptly satisfy customer claims, and maintain sufficient liquid resources to promote the prudent operation of broker-dealers.[405] In addition, generally, all registered broker-dealers that deal with the public must become members of FINRA, a registered national securities association.[406] These broker-dealers include broker-dealers that hold customer funds and securities (“carrying broker-dealers”). FINRA members must comply with FINRA rules, and submit to compliance examinations by FINRA in addition to those examinations conducted by the Commission or another SRO.[407]

The broker-dealer financial responsibility rules “have existed for many years and have facilitated the prudent operation of broker-dealers.” [408] For example, the Commission adopted rule 15c3-1, the uniform net capital rule that applies to all broker-dealers, in 1975.[409] Rule 15c3-1 imposes a net liquid assets test that is designed to promote liquidity within broker-dealers.[410] Rule 15c3-1 permits a broker-dealer to engage in activities that are part of conducting a securities business ( e.g., taking securities positions) but in a manner that leaves the firm holding at all times more than one dollar of highly liquid assets for each dollar of unsubordinated liabilities ( e.g., money owed to customers, counterparties, and creditors).[411] The objective of rule 15c3-1 is to require a broker-dealer to maintain sufficient liquid assets to meet all liabilities, including obligations to customers, counterparties, and other creditors and to have adequate additional resources to wind-down its business in an orderly manner without the need for a formal proceeding if the firm fails financially.[412] Rule 15c3-1's emphasis on liquidity helps to ensure that the liquidation of a firm will not result in excessive delay in repayment of the firm's obligations to customers, broker-dealers, and other creditors, and therefore assures the continued liquidity of the securities markets.[413]

In addition, the Commission adopted rule 15c3-3—the customer protection rule—in 1972 under section 15(c)(3)(A) of the Exchange Act.[414] Rule 15c3-3 is designed to give specific protection to customer funds and securities, in effect forbidding broker-dealers from using customer assets to finance any part of their businesses unrelated to servicing securities customers.[415] To meet this objective, rule 15c3-3 requires a carrying broker-dealer to take two primary steps to safeguard these assets.[416] The steps are designed to protect customers by segregating their securities and cash from the carrying broker-dealer's proprietary business activities.[417] If the carrying broker- ( printed page 63929) dealer fails financially, the customer securities and cash should be readily available to be returned to the customers.[418] In addition, if the failed carrying broker-dealer is liquidated under SIPA, the customer securities and cash should be isolated and readily identifiable as customer property [419] and, consequently, available to be distributed to customers ahead of other creditors.[420] At a high level, in such a liquidation, SIPA would provide for the appointment of a trustee who is required to return customer name securities to customers of the debtor, distribute the fund of “customer property” ratably to customers, and obtain cash advances from the SIPC from the fund administered by SIPC (“SIPC Fund”) to satisfy remaining customer net equity claims, to the extent provided by SIPA.[421]

The first step required by rule 15c3-3 is that a carrying broker-dealer must maintain physical possession or control over customers' fully paid and excess margin securities.[422] The term “fully paid securities” means all securities carried for the account of a customer in a cash account as defined in Regulation T promulgated by the Federal Reserve Board (“Regulation T”),[423] as well as securities carried for the account of a customer in a margin account or any special account under Regulation T that have no loan value for margin purposes, and all margin equity securities in such accounts if they are fully paid: provided, however, that the term fully paid securities does not apply to any securities purchased in transactions for which the customer has not made full payment.[424] The term “margin securities” means those securities carried for the account of a customer in a margin account as defined in section 4 of Regulation T,[425] as well as securities carried in any other account (such accounts referred to as “margin accounts”) other than the securities referred to in paragraph (a)(3) of rule 15c3-3 ( i.e., fully paid securities).[426] The term “excess margin securities” means those securities referred to in paragraph (a)(4) of rule 15c3-3 ( i.e., margin securities) carried for the account of a customer having a market value in excess of 140% of the total of the debit balances in the customer's account or accounts encompassed by paragraph (a)(4) of rule 15c3-3, which the broker-dealer identifies as not constituting margin securities.[427] Control means the carrying broker-dealer must hold these securities in one of several locations specified in rule 15c3-3 and free of liens or any other interest that could be exercised by a third-party to secure an obligation of the carrying broker-dealer.[428] Permissible locations include a clearing corporation and a “bank,” as defined in section 3(a)(6) of the Exchange Act. A carrying broker-dealer does not treat customer securities as its own assets. Rather, the carrying broker-dealer holds them in a custodial capacity, and the possession and control requirement is designed to ensure that the carrying broker-dealer treats them in a manner that allows for their prompt return.

The second step is that a carrying broker-dealer must maintain a reserve of funds or qualified securities in an account at a bank that is at least equal in value to the net cash owed to customers.[429] The account must be titled “Special Reserve Bank Account for the Exclusive Benefit of Customers” (“customer reserve bank account”).[430] The amount of net cash owed to customers is computed weekly or daily as of the close of the last business day of the week pursuant to a formula set forth in Exchange Act rule 15c3-3a (“customer reserve computation”).[431] Under the customer reserve computation, the carrying broker-dealer adds up customer credit items and then subtracts from that the amount of customer debit items.[432] The credit items include credit balances in customer accounts ( i.e., cash owed to customers) and funds obtained through the use of customer securities ( e.g., a loan from a bank collateralized with customer margin securities).[433] The debit items include money owed by customers ( e.g., from margin lending), securities borrowed by the carrying broker-dealer to effectuate customer short sales, and margin required and on deposit with certain clearing agencies as a consequence of customer securities transactions.[434] If credit items exceed debit items, the net amount must be on deposit in the customer reserve bank account in the form of cash and/or qualified securities.[435] The customer reserve computation permits the carrying broker-dealer to offset customer credit items only with customer debit items.[436] This means the carrying broker-dealer can use customer cash to facilitate customer transactions such as financing customer margin loans and borrowing securities to make deliveries of securities that customers have sold short.

The broker-dealer margin rules require securities customers to maintain a minimum level of equity in their securities accounts ( i.e., the customer's ownership interest in the account, computed by adding the current market value of long securities and the amount of any credit balance and subtracting the current market value of all short securities and the amount of any debit balance).[437] In other words, the cash and the market value of the customer's securities in the account must be sufficiently larger than the sum of the cash borrowed by the customer and market value of the securities sold short by the customer.[438] In addition to protecting the carrying broker-dealer from the consequences of a customer default, this equity serves to over-collateralize customers' obligations to the broker-dealer. This buffer protects the customers whose cash was used to facilitate the carrying broker-dealer's ( printed page 63930) financing of securities transactions of other customers ( i.e., margin loans and short sales).[439] For example, if the carrying broker-dealer fails, the customer debits—because they generally are over-collateralized—should be attractive assets for another broker-dealer to purchase or, if not purchased by another broker-dealer, they should be able to be liquidated to a net positive equity.[440]

Broker-dealers are also subject to extensive recordkeeping, reporting, notification, and securities count requirements under the broker-dealer financial responsibility rules.[441] For example, Exchange Act rules 17a-3 and 17a-4 require broker-dealers to create, and preserve in an accessible manner, a comprehensive record of each securities transaction they effect and of their securities business in general.[442] The broker-dealer financial reporting requirements are codified in Exchange Act rule 17a-5, and contains two main elements: (1) a requirement that broker-dealers file periodic unaudited reports containing information about their financial and operational condition on a Financial and Operational Combined Uniform Single Report or “FOCUS Report”; and (2) a requirement that broker-dealers annually file financial statements and certain reports and a report covering the financial statements and reports prepared by an independent public accountant registered with the PCAOB (if registration is required by the Sarbanes-Oxley Act of 2002) in accordance with PCAOB standards.

The reporting program established under Exchange Act rule 17a-5 is designed, among other things, to promote compliance with rules 15c3-1 and 15c3-3 and to assist the Commission, SROs, and state securities regulators in conducting effective examinations of broker-dealers.[443] As the Commission has stated, the reporting requirements, “together with the Commission's inspection powers, [are] an integral element in the arsenal for protection of customers against the risks involved in leaving securities with their broker-dealer.” [444] The broker-dealer reporting requirements promote transparency of the financial and operational condition of the broker-dealer to the Commission, the firm's designated examining authority (“DEA”), and, in the case of a portion of the annual reports, to the public. In the release adopting rule 17a-5, the Commission stated its intention to periodically review the reporting requirements “in order to continue modifying and updating the financial and operational reporting systems to keep pace with the changing securities industry”.[445] Under Exchange Act rule 17a-11, broker-dealers that are experiencing financial or operational difficulties must provide notice to the Commission, the broker-dealer's DEA, and the CFTC if the broker-dealer is registered with the CFTC as a futures commission merchant, including when, among other things, their net capital falls below 120% of the minimum required amount or below the minimum required amount, or when the firm fails to make and keep current the books and records required by Commission rules.[446] Meanwhile, Exchange Act rule 17a-13 requires that, at least once in each calendar quarter, a broker-dealer must physically count, verify, and account for securities held in its physical possession or otherwise within its control or direction.[447]

Finally, Exchange Act rules 8c-1 and 15c2-1, commonly called the “Hypothecation Rules,” generally prohibit a broker-dealer from using its customers' securities as collateral to finance its own trading, speculating, or underwriting transactions.[448] More specifically, the rules state three main principles: first, that a broker-dealer is prohibited from commingling the securities of different customers as collateral for a loan without the consent of each customer; second, that a broker-dealer cannot commingle its customers' securities with its own under the same pledge; and third, that a broker-dealer can only pledge its customers' securities up to the value of monies owed to the broker-dealer by its customers.[449]

Proposed Changes to Rule 17f-1 Conditions

We are proposing to remove the conditions of the current rule 17f-1 in conjunction with permitting regulated funds to custody their securities or similar investments at a registered brokers-dealer that carries customer securities accounts, where custody of such assets by the broker-dealer is subject to the requirements of rule 15c3-3 or such other rule that the Commission determines provides similar customer protections. Under the proposed rules, the securities or similar investments of a regulated fund would receive the same level of protections as other customers of the broker-dealer, while eliminating antiquated and duplicative regulatory burdens.

For example, the current rule 17f-1 segregation condition is antiquated due to the requirement to physically segregate securities and similar investments, for example by placing them in “separate containers,” which is inconsistent with the uncertificated nature of most current assets.[450] The lien condition also is duplicative because, as discussed above, the “possession or control” requirement of rule 15c3-3 already requires a broker-dealer to hold fully-paid or excess margin securities free of liens.[451] Broker-dealers are also required to make and keep current (as of the end of each business day) ledger accounts itemizing separately each cash and margin account of every customer of the broker-dealer under rule 17a-3.[452]

( printed page 63931)

As discussed above, margin securities are those securities carried for a customer in a margin account, with market value equal to (or less than) 140% of the account's debit balance, which includes the customer margin loan balance. While carrying broker-dealers are permitted to use customer margin securities to, for example, obtain bank loans to finance the funds used to lend to customers to purchase securities, the customer protection rule generally requires broker-dealers to include a credit in the customer reserve formula for funds obtained through the use of these securities.

Removing the segregation condition in rule 17f-1 generally would not affect clients' ability to recover their securities and funds held at a broker-dealer for multiple reasons. First, the customer protection rule is designed to give specific protection to customer funds and securities, in effect forbidding broker-dealers from using customer assets to finance any part of their businesses unrelated to servicing securities customers.[453] Second, the customer protection rule works in conjunction with the net capital rule to ensure not only that the broker-dealer properly segregates customer assets from the firm's proprietary assets, but also that it maintains sufficient liquid assets to meet all liabilities to its creditors, including its obligations to customers. By requiring the broker-dealer to properly segregate customer assets and maintain sufficient liquid assets to meet all liabilities to its creditors, the rule is designed to ensure that the broker-dealer has adequate additional resources to wind-down its business in an orderly manner without the need for a formal proceeding under SIPA, helping to ensure that the liquidation of a firm will not result in excessive delay in repayment of the firm's obligations to customers. Third, SIPA affords certain protections against loss of customer securities and related customer funds resulting from a broker-dealer failure, including the right to share pro rata with other customers under SIPA (“SIPA customer”) in the customer property held by the carrying broker-dealer by way of a priority claim on the customer property compared to general unsecured creditors of the carrying broker-dealer.[454] If a customer has a margin loan with a broker-dealer, this amount would be deducted in calculating the customer's net equity in the SIPA liquidation. During SIPC's fifty-five year history (as of Dec. 31, 2025), cash and securities distributed for accounts of customers totaled approximately $143 billion. Of that amount, approximately $142 billion (99.3%) came from debtors' estates and $909 million came from the SIPC Fund.[455] SIPA protections also include the ability for a SIPA customer to generally receive an advance from the SIPC Fund of up to $500,000 (of which $250,000 can be used to cover cash claims), if the amount of customer property is insufficient to satisfy the customer's claim for securities and/or cash.[456]

Similarly, where the current rule 17f-1 rehypothecation condition forbids the broker-dealer from rehypothecating any client assets except pursuant to client directions,[457] the customer protection rule requires a broker-dealer to hold fully paid and excess margin securities in its possession or control (while explicitly allowing rehypothecation of margin securities up to the 140% threshold).[458] Further, while the customer protection rule may lower financing costs for broker-dealers by allowing them to rehypothecate margin securities, it requires broker-dealers to include a credit in the customer reserve formula for funds obtained through the use of customer securities (which may increase a broker-dealer's deposit requirement into its special reserve bank account).[459] Additionally, as discussed above, the broker-dealer hypothecation rules create further restrictions on the broker-dealer's use of customers' securities.[460] In addition, as discussed above, SIPA, Regulation T, and the other broker-dealer financial responsibility rules also serve to mitigate the risk of loss to customers. The approach under the customer protection rule, while different, is comparable to the current rule 17f-1 condition, as the customer protection rule requirements discussed above provide protection for rehypothecated margin securities that did not exist when this condition of rule 17f-1 was adopted.

The current rule 17f-1 lien condition provides a general prohibition on a lien or charge of any kind in favor of the custodian.[461] The customer protection rule provides similar protections, requiring broker-dealers to maintain physical possession or control over customers' fully paid and excess margin securities.[462] If the customer chooses to purchase securities on margin, to secure that loan, a broker-dealer may have a lien on, and the possession or control requirement may not apply to, the customer's margin securities.[463] Permitting regulated funds to custody their securities with broker-dealers that may have liens on their securities in these limited circumstances, which would be only when a fund chooses to buy securities on margin, as proposed balances the risks associated with the liens in favor of custodians against the potential benefits to regulated funds to be able to obtain financing on more favorable terms.[464]

The current rule 17f-1 examination condition does not have a singular direct analog in the Exchange Act requirements for broker-dealers. However, its general purpose is collectively addressed by several different requirements found within the broker-dealer financial responsibility rules discussed above.[465] For example, rule 17a-13 under the Exchange Act requires broker-dealers quarterly to conduct examinations of securities held, account for and verify securities in transfer and record any unresolved differences on their books and records.[466] Rule 17a-5 under the Exchange Act requires broker-dealers to file periodic and annual financial reports, including FOCUS Reports and annual audited financial statements.[467] In addition to financial statements, a carrying broker-dealer is required to state in its audited annual reports, among other things, whether it has ( printed page 63932) established and maintained “internal control over compliance” with a series of financial responsibility rules, including rule 17a-13, and whether the internal control over compliance of the broker-dealer was effective during the most recent fiscal year and as of the end of the most recent fiscal year.[468] These requirements, coupled with the modern regulatory regime governing broker-dealer segregation and insolvency discussed above, provide significant protections to client assets which make the rule 17f-1 requirement to conduct examinations three times a year unnecessary and unduly burdensome.

Section 17(a) of the Exchange Act requires registered broker-dealers to make and keep records required by Commission rules and to furnish copies of the records to the Commission.[469] Further, section 17(b) of the Exchange Act authorizes representatives of the Commission to conduct “reasonable, periodic, special or other examinations” of all records of a broker-dealer. These examinations may be conducted at any time or from time to time as the Commission “deems necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the [Exchange Act.]” Dedicated Commission staff conduct ongoing reviews of the market, credit, leverage, liquidity, legal, and operational risk management controls within broker-dealers approved to compute their net capital using risk-based models and other dedicated Commission staff engage in programs that monitor certain large broker-dealers.[470] In addition to Commission examinations, broker-dealers are subject to examinations by the SROs of which they are members, such as FINRA. These SROs are also subject to Commission oversight and examination. Similarly, the current rule 17f-1 inspection condition also has an analog in rule 17a-4 under the Exchange Act, which requires that a broker-dealer must promptly furnish records of the broker-dealer that are required to be preserved or any records of the broker-dealer subject to examination at the request of the Commission.[471]

Finally, the circumstances contemplated by the current rule 17f-1 possession condition, which provides protections for securities or similar investments during the transaction process, are no longer present.[472] Broker-dealers carrying customer securities accounts must now comply with the customer protection rule, which did not exist at the time rule 17f-1 was adopted by the Commission, including the requirement to promptly obtain and thereafter maintain the physical possession or control of all fully-paid and excess margin securities.[473] The customer protection rule also requires, among other things, certain buy-ins of short security differences, steps to take when required securities are not in possession or control, and required items in the customer reserve formula for items that are failed to receive or deliver that all provide additional protection for assets not in possession of the broker-dealer.[474]

We are also proposing to remove the requirement in rule 17f-1 to maintain a written custodial contract that is approved by the board of directors of the regulated fund, because we are proposing to remove the conditions in rule 17f-1 that are required to be effectuated pursuant to a written contract.[475] Similarly, we are also proposing to remove the requirements for the custodial contract to be transmitted to the Commission and be ratified by the board of directors of the regulated fund at least annually.[476] Nevertheless, we anticipate that as part of standard business practices, regulated funds will continue to maintain written custodial contracts with any custodian they engage, including broker-dealers engaged under rule 17f-1, based on the staff's experience that regulated funds enter into written custodial contracts with their permitted custodians.

Finally, because we are proposing to rescind the examination condition under rule 17f-1, we are also proposing to rescind Form N-17f-1.[477]

We request comment on the following:

185. To what extent do regulated funds currently custody securities or similar investments pursuant to rule 17f-1? Do regulated funds find this rule to be generally useful or functional as written? In what circumstances do regulated funds use rule 17f-1? What challenges or difficulties have regulated funds that do use rule 17f-1 observed with complying with the requirements of this rule?

186. Should we define which brokers or dealers may custody a regulated fund's securities or similar investments by reference to section 15(b)(1) as proposed or in some other way? In order to carry customer accounts, a broker-dealer must generally meet certain criteria, such as being a FINRA member, being subject to rule 15c3-3, and meeting minimum net capital requirements under rule 15c3-1. Should rule 17f-1 include any such criteria for which broker-dealers may custody a regulated fund's securities or similar investments? Is there some other standard (such as membership with a particular SRO) which should be required for brokers or dealers that may custody securities or similar investments for regulated funds?

187. Are any of the protective conditions in current rule 17f-1 still necessary or beneficial? If so, which ones? Please explain how the concerns underlying these conditions are not addressed by the existing broker-dealer regulatory regime, including the broker-dealer financial responsibility rules. If any of these conditions should be retained, to what extent, if any, should they be amended? If so, how and why? Are there any conditions not currently required by rule 17f-1 which should be added? Please explain the risks that such conditions would be intended to protect against. Should we retain the requirement that a regulated fund maintain a written custodial contract regardless of whether the conditions under rule 17f-1 are retained? Why or why not? Do you agree that it is standard business practice for regulated funds to enter into written custodial contracts with their custodians?

188. Are securities and similar investments for which the broker-dealer's custody is subject to rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections the proper scope for securities or similar investments eligible to be custodied by broker-dealers on behalf of regulated funds?

189. Under the proposal, due to the protections that rule 15c3-3 provides, a regulated fund would only be permitted to place or maintain securities or similar investments with a registered broker-dealer where the custody of the ( printed page 63933) securities and similar investments is subject to rule 15c3-3 or such other rule that the Commission determines provides similar customer protections. Should we permit a regulated fund to place and maintain any securities or similar investments at a broker-dealer where the broker-dealer's custody of those securities or similar investments are not subject to rule 15c3-3 or such other rule that the Commission determines provides similar customer protections? If so, describe the securities or similar investments for which this should be permitted and what additional conditions would be appropriate? For example, should rule 17f-1 require a regulated fund and the broker-dealer custodian to agree in writing to treat each crypto asset in the broker-dealer's custody as a financial asset pursuant to applicable State law that governs the written agreement between the regulated fund and the broker-dealer?

3. Free Cash Accounts

We are proposing to rescind rule 17f-3, which provides for free cash accounts for investment companies with bank custodians. Specifically, the rule provides that, if a regulated fund has a bank custodian, the fund may maintain a free cash account only upon a resolution of the fund's board of directors in an amount not to exceed $500, and provided further that the petty cash account is operated under the “imprest system” (a system to maintain a fixed amount of money for small, routine expenses that is replenished following withdrawals) and maintained subject to adequate controls approved by the board of directors over disbursements and reimbursements including, but not limited to, fidelity bond coverage of persons having access to funds in the account. We understand that regulated funds are no longer using this rule and have not received any feedback from the industry that amendments to modernize this rule would be beneficial. Due to technological advances in banking and payment processing, we also do not perceive a need in modern markets for regulated funds to maintain free cash accounts ( i.e., petty cash).

We request comments on the following related questions:

190. Are there any regulated funds that currently rely on rule 17f-3 or anticipate they might rely on it? If so, for what purpose?

191. If regulated funds perceive a need to maintain free cash accounts, what amount would be appropriate and why?

192. If we maintain a free cash account rule, what, if any, protective conditions should apply? If we maintain rule 17f-3, are the current controls effective? Should we modify them in any way?

4. Other Amendments to Regulated Fund Custody Rules

We are proposing amendments to rule 17f-4 and rule 17f-7 to correct an outdated mailing address and a definitional cross-reference, respectively. Rule 17f-4 contains a reference to the UCC and provides that members of the public may inspect a copy at the Commission Library or at a website of the National Archives and Records Administration (“NARA”).[478] The Commission no longer has a publicly accessible library or a public reference room and the NARA website no longer is functioning. We are proposing to instead reference the website for the Uniform Law Commission, which produces the UCC and makes it available on its site, in rule 17f-4.[479]

Rule 17f-7 states that the term “Eligible Securities Depository” means a system for the central handling of securities as defined in rule 17f-4. When the Commission first adopted rule 17f-4 in 1978 the rule stated that a “securities depository” is a “system for the central handling of securities where all securities of any particular class or series of any issuer deposited within the system are treated as fungible and may be transferred or pledged by bookkeeping entry without physical delivery of the securities.” [480] In 2000 the Commission adopted rule 17f-7 and the current definition of an “Eligible Securities Depository” by reference to the definition of a “system for the central handling of securities” in rule 17f-4.[481] The Commission proposed amendments to rule 17f-4 in 2001 which would have maintained the original language defining “system for the central handling of securities.” [482] A commenter suggested that the same objective as that language could be achieved by defining a securities depository by reference to a “clearing corporation” under Article 8 and a “clearing agency” under the Securities Exchange Act and the Commission adopted this recommendation.[483] There was no discussion of the impact of this change on rule 17f-7 in that release or any indication that the Commission intended to break this cross-reference or to modify the substance of rule 17f-7 in any way. Commission staff has taken a similar view that this term should continue to be interpreted to have the same meaning as was defined in the prior version of rule 17f-4.[484] Therefore, we are proposing to amend rule 17f-7 to define the phrase “system for the central handling of securities” included in the defined term “Eligible Securities Depository” as written in the original rule 17f-4 adoption.[485]

We request comment on the following:

193. Is it necessary or beneficial for the Commission to provide where the UCC may be accessed? Is the website of the Uniform Law Commission an appropriate place to reference for such information? Is there a better source available? Should the Commission provide a location for physical review of the UCC, and if so, where?

194. Should we adopt the proposed definition of “Eligible Securities Depository”? Should we amend this definition in any way?

195. Are there other references or provisions in the Investment Company Act custody rules that would benefit from technical corrections? If so, describe what the corrections should be.

196. Investment Company Act rule 17f-5 permits a regulated fund to place and maintain its “foreign assets” in the care of certain foreign custodians, subject to conditions. The rule defines foreign assets to mean any investments (including foreign currencies) for which the primary market is outside the United States, and any cash and cash equivalents that are reasonably necessary to effect the fund's transactions in those investments. Crypto assets are generated, minted, or mined on a blockchain or similar distributed ledger technology and therefore would not seem to have a “primary market” that is “outside the United States.” Should we amend rule 17f-5 or provide guidance on the rule to address crypto assets? Under what ( printed page 63934) circumstances, if any, would it be appropriate for regulated funds to place and maintain crypto assets with eligible foreign custodians under rule 17f-5? Should the analysis differ for traditional assets that are formatted as or represented by crypto assets, or “tokenized,” where the record of ownership is maintained in whole or in part on or through one or more crypto networks? Is the current definition of “eligible foreign custodian” appropriate for entities that provide custodial services for crypto assets outside the United States?

197. Are there parts of the Investment Company Act custody rules that should be substantively updated or amended? If so, describe any issues with or possible improvements to the current rules and how these rules should be amended.

5. Request for Comment on Other Regulated Fund Custody Issues

We are requesting comment on the experience of regulated funds in custodying their securities and similar investments under the Investment Company Act custody rules.[486] We are requesting comment to assist the Commission in evaluating whether proposing further fund custody rules, or amendments to the current Investment Company Act custody rules, to accommodate modern custodial practices may be warranted in the future.

We understand that, generally, fund assets are able to be maintained by permitted custodians in custodial arrangements that do not raise any interpretive questions. However, we understand that is not universally the case, particularly for three types of fund assets: assets maintained at custodians that are affiliated with the fund's investment adviser in certain ways, certain types of uncertificated securities ( e.g., regulated fund shares, privately offered securities, and loans), and collateral for certain types of cleared swap contracts. In response, some regulated funds holding these types of fund assets have sought no-action letters from Commission staff relating to certain Investment Company Act custody rules, such as rule 17f-2 and rule 17f-4, for the regulated fund to follow alternative procedures designed to achieve the same goals as the relevant Investment Company Act custody rule, including the prevention of misappropriation. In addition, we understand that regulated funds that maintain even certificated securities in the fund's own custody may have difficulty complying with some of the requirements of rule 17f-2 due to changes in custodial practices since the rule was last substantively amended in 1947.[487]

(a) Affiliated Custodians and Custody of Non-Crypto Assets With the Regulated Fund Itself

Under rule 17f-2, fund assets are considered to be in the custody of a regulated fund if such fund assets are maintained with a bank or certain other permitted custodian under any arrangement where the regulated fund's directors, officers, employees or agents are authorized or permitted to withdraw such fund assets upon their “mere receipt.” Due to the heightened risk of misappropriation posed by circumstances where regulated fund personnel can withdraw fund assets upon mere receipt without depositing cash or other fund assets in exchange for the investments, rule 17f-2 imposes various conditions designed to guard against misappropriation. Specifically, fund assets must be deposited in the safekeeping of, or in a vault or other depository maintained by, a bank or other permitted custodian (the “vaulting requirement”) and physically segregated at all times from any other person's assets (the “physical segregation requirement”). A written notation also must be created for every transaction in self-custodied fund assets and signed by authorized persons (the “notation requirement”).

In addition, the rule requires board involvement in the approval of regulated fund personnel that can access fund assets from custody (“access requirement”). Further, the regulated fund's assets must be verified by actual examination by an independent public accountant at least three times annually, two of which must be by surprise (“exam requirement”).[488] This exam requirement is in addition to the annual audit that all regulated funds must obtain.[489]

Regulated funds sometimes choose to custody their fund assets with a bank or certain other permitted custodian that also serves as the fund's investment adviser or that is an affiliate of the regulated fund's investment adviser, instead of with an independent, unaffiliated bank or other permitted custodian. The Commission and its staff have taken the position that, where a regulated fund's investment adviser controls or is controlled by, or is under common control with, a regulated fund's custodian, sub-custodian, or depository (an “affiliated custodian”), such arrangements may be subject to rule 17f-2.[490] According to Commission staff, inherent in these arrangements is the risk that an employee of the investment adviser would have access to a regulated fund's assets in connection with the provision of custody services, and then could have the ability to take advantage of the fund by misappropriating fund assets.[491] Commission staff has therefore interpreted such affiliated custodian arrangements as being subject to rule 17f-2, recognizing that such arrangements raise misappropriation concerns and also present the risk that the fund's assets will not be maintained in a manner subject to adequate independent scrutiny.[492] For the avoidance of doubt, rule 17f-2, rather than the proposed fund self-custody rule (proposed rule 17f-9), applies to fund crypto assets maintained at an affiliated custodian of the investment adviser. Proposed rule 17f-9 provides that a crypto asset placed and maintained with an investment adviser itself is subject to that rule in lieu of rule 17f-2.[493]

Subsequent to the adoption of rule 17f-2, the Commission transitioned to a different approach under the Advisers Act custody rule to address the risks of misappropriation present where a qualified custodian maintaining advisory clients' assets is a related person of the investment adviser—that is, a qualified custodian that is directly or indirectly controlling or controlled by, or under common control with, the adviser. In these cases, the investment adviser or its related person maintaining client funds or securities must obtain an ( printed page 63935) internal control report from an independent public accountant to guard against the risk of misappropriation, in addition to the annual surprise examination (or audit in the case of a private fund client) to which all advisers with custody generally are subject under the Advisers Act custody rule.[494] Such internal control report must contain an opinion of an independent public accountant as to whether controls have been placed in operation as of a specific date, and are suitably designed and are operating effectively to meet control objectives relating to custodial services, including the safeguarding of client funds and securities held by the adviser during the year.[495] The accountant must also verify that the client's funds and securities are reconciled to a custodian unaffiliated with the adviser or its related person.[496]

The requirement to obtain the internal control report is designed to address the heightened misappropriation risks posed by custody arrangements where the adviser or a related person is the custodian of client assets instead of an independent custodian.[497] In support of its decision to adopt the internal control report requirement, the Commission noted that a number of enforcement actions involved misappropriation of client assets by advisers or related persons that maintained client assets.[498] The internal control report requirement provides important additional safeguards for client assets maintained with the adviser or a related person because the internal control report requires the investment adviser to demonstrate that it, or its related person, has established appropriate custodial controls.[499] Further, the internal control report can significantly strengthen the utility of the surprise examination when the investment adviser or a related person acts as qualified custodian for client assets because it provides a basis for the independent public accountant performing the surprise examination to obtain additional comfort that the confirmations received from the related custodian are reliable. The requirement to obtain an internal control report therefore serves both to inform the surprise examination process and may itself act as a deterrent to fraud by advisers that may consider misappropriating client assets directly or through a related person.[500]

We request comment on the following aspects of regulated fund custody:

198. Under what circumstances do regulated funds currently rely on rule 17f-2 to custody fund assets at an affiliated custodian?

199. Commission staff has stated that custody arrangements where a regulated fund's investment adviser controls or is controlled by, or is under common control with, the fund's custodian, sub-custodian, or depository raise the risk of misappropriation and have interpreted such arrangements as being subject to rule 17f-2. Do commenters view these particular affiliated relationships ( i.e., where the custodian is a related person of the adviser) as raising misappropriation concerns? Why or why not? Are there other types of affiliation that raise heightened risks of misappropriation justifying additional safeguards? Do affiliated relationships between a regulated fund and custodian, sub-custodian or depository raise misappropriation concerns? What about where a regulated fund or the fund's adviser shares common personnel with the regulated fund's custodian or where the custodian owns, controls, or holds with the power to vote, five percent or more of the outstanding voting securities of the adviser (or vice versa)?

200. What safeguards should apply to affiliated relationships that raise misappropriation concerns? Should the rule 17f-2 exam requirement apply to such relationships? If so, should it be modified in any way? For example, is it necessary to require actual examination of the investments at least three times each year, at least two of which are chosen by the independent public accountant? Alternatively, should the Advisers Act related person internal control report requirement apply? Should regulated funds be able to choose which requirement applies—the rule 17f-2 exam requirement or the Advisers Act internal control report requirement?

201. What, if any, of rule 17f-2's other safeguards ( e.g., the access requirement) should apply to affiliated custodial arrangements that raise misappropriation concerns?

202. Should we propose to amend rule 17f-2 to explicitly allow regulated funds that use affiliated custodians to comply with the rule? Why or why not?

203. Rule 17f-2 currently applies where a regulated fund's directors, officers, employees, or agents are permitted or authorized to withdraw fund assets upon mere receipt. Is “mere receipt” the appropriate standard at which rule 17f-2 should apply?

(b) Uncertificated Securities

A substantial portion of securities—privately and publicly held—are uncertificated. Regulated funds holding uncertificated securities must custody those securities, like certificated securities, at a permitted custodian under the Investment Company Act custody rules. Although most uncertificated securities are able to be held at a permitted custodian, we understand that regulated funds have difficulty custodying uncertificated securities that cannot be placed with a securities depository under rule 17f-4 ( e.g., shares of regulated funds, privately offered securities, and certain types of loans).

(1) Regulated Fund Shares Held at Transfer Agents

A regulated fund (an “acquiring fund”) that holds shares of another regulated fund (an “acquired fund”) may not be able to technically comply with the Investment Company Act custody rules to custody the shares where such fund shares are held at a registered transfer agent of the acquired fund and no certificate is issued for the shares. As described in more detail below, this scenario presents challenges in light of certain aspects of rule 17f-4, which addresses custody of fund assets with a securities depository, and rule 17f-2, which governs a regulated fund maintaining its own fund assets.

Rule 17f-4 permits regulated funds to place and maintain financial assets with a securities depository, subject to certain conditions. A securities depository is defined under the rule as a clearing corporation that is registered with the Commission as a clearing agency, or a Federal reserve bank or other person authorized to operate the Federal book-entry system for U.S. Treasury securities. A transfer agent is not a securities depository because it is not a registered clearing agency. ( printed page 63936)

A number of acquiring funds have sought and received assurance from Commission staff that they would not recommend enforcement action under rule 17f-4 where acquired fund shares are maintained at the transfer agents of those funds and where the acquiring funds represented that certain procedures designed to comply with then-current rule 17f-4 would be implemented.[501] Some of these procedures include: the acquiring fund maintains a system that is reasonably designed to prevent unauthorized instructions and that provides for the form, content and means of giving, recording, and reviewing instructions; the acquired fund shares are maintained directly with the transfer agents of those funds in a separate account in the custodian's name, as custodian for the acquiring fund; the acquiring fund's custodian sends to the acquiring fund copies of all confirmations received from the transfer agents of any transfers to or from the account of the acquiring fund; the custodian sends the acquiring fund reports on its system of internal accounting control as the acquiring fund may reasonably request from time to time; and the acquiring fund, by resolution of its board, approves the arrangement initially and annually thereafter.

Commission staff has also issued no-action letters in connection with rule 17f-2 where an acquiring fund is engaged in self-custody or where an acquiring fund's transfer agent is an affiliated person of that fund.[502] In these instances, the acquiring funds holding uncertificated securities were unable to technically comply with rule 17f-2's requirement that fund assets be kept in a vault or other depository maintained by a bank or regulated entity, the written notation requirement for each transaction, and the requirement that an independent public accountant physically verify such fund assets three times per year.[503] The Commission staff gave assurance that they would not recommend enforcement action under rule 17f-2 subject to the acquiring funds representing that certain procedures would be implemented, including: limitations on the number of persons authorized to transmit instructions to the transfer agent; use of passwords to ensure that only properly authorized persons could transmit instructions; transmission by the transfer agents of confirmation of each transaction to persons employed by the fund's administrative agent other than those who transmit the investment instructions; and the acquiring fund's independent accountant conducting three annual examinations by reconciling the acquiring fund's book records with the account records of the acquired funds, and also independently confirming the acquiring fund's book records with the transfer agents of the acquired funds.[504]

The Commission proposed amending rule 17f-4 in 2001 to permit regulated funds to maintain custody of shares in other regulated funds with registered transfer agents.[505] The amendments were proposed in response to the growth of acquiring funds and other arrangements in which a regulated investment company invests in shares of a regulated fund.[506] The amendments were not adopted due to comments raising issues with the proposal, including those contending that a regulated fund's maintenance of its fund assets with another regulated fund's transfer agent involves self-custody issues that should be addressed in conjunction with any future amendments to rule 17f-2.[507]

Accordingly, we request comment on the following aspects of custody of uncertificated regulated fund shares with a registered transfer agent:

204. Should we propose a rule that would specifically allow transfer agents to custody shares of regulated funds? If so, what conditions, if any, should apply to transfer agents that custody shares of regulated funds? Do the procedures described in the no-action letters provide appropriate protections, or are there additional or different conditions that should be incorporated in a rule addressing transfer agents' custody of regulated fund shares? Should different or more conditions apply when the transfer agent is an affiliated person of the acquiring fund? What conditions should apply and why? Alternatively, should we allow transfer agents to custody shares of regulated funds without any additional conditions? Should we propose a rule that would specifically allow transfer agents to custody other types of uncertificated securities (in addition to shares of regulated funds), for example, uncertificated digital securities held by the issuer's transfer agent?

205. Alternatively, should we propose amendments to rule 17f-4 to add transfer agents? Should all the conditions in 17f-4 also apply to transfer agents? If not, what subset of conditions (or alternative conditions) should apply to transfer agents? Are there circumstances from rule 17f-4 no-action letters that should apply to transfer agents? Should we propose amendments to rule 17f-2 to accommodate a regulated fund that custodies its uncertificated securities at a transfer agent? Why or why not? If so, how should we propose amendments to the rule 17f-2 requirements to accommodate uncertificated securities?

(2) Privately Offered Securities

The current and proposed Advisers Act custody rules permit an adviser to custody its advisory clients' holdings of privately offered securities outside of a qualified custodian.[508] To qualify for this privately offered securities exception, securities must meet the rule's definition of “privately offered securities.” [509] This definition includes securities that are: (1) acquired from the issuer in a transaction or chain of transactions not involving any public offering; (2) uncertificated, and ownership thereof is recorded only on the books of the issuer or its transfer agent in the name of the client; and (3) transferable only with prior consent of the issuer or holders of the outstanding securities of the issuer.[510] No similar ( printed page 63937) provision exists under the Investment Company Act or rules thereunder to permit regulated funds to custody the fund's holdings of privately offered securities outside of a permitted custodian.

The private offering exception was adopted in recognition that maintaining these assets in accounts with qualified custodians could pose difficulties, particularly given that ownership of such assets generally is recorded only on the books of the issuer.[511] This includes, for example, investments in limited partnerships where clients receive only a copy of the partnership agreement and subscription agreement as evidence of their investment or assignment agreements for debt or equity interests in a private company. In support of its decision to adopt the exception, the Commission stated that some of the impediments to transferability of such securities provide external safeguards against the kinds of abuse that the custody rules seek to prevent, that is, loss or theft by an external third-party.[512] These characteristics reduce the need for the safeguarding protections offered by a qualified custodian.

We request comment on all aspects of regulated fund custody of privately offered securities, including:

206. What types of privately offered securities, if any, cannot be maintained at a permitted custodian or present particular challenges in maintaining them at a permitted custodian and why? What specific custodial challenges do regulated funds face in trying to custody such securities with a bank or other permitted custodian and why?

207. Should an approach like the privately offered securities exception in the Advisers Act custody rule be made available to regulated funds? Why or why not? What additional or different safeguards, if any, should be required in order to mitigate the custodial risks of holding uncertificated, privately offered securities outside of a permitted custodian? What unique custodial risks, if any, would arise if regulated funds were permitted to hold privately offered securities ( e.g., restricted securities, private equity, or private debt) outside of a permitted custodian, provided the regulated fund is audited as currently required?

(3) Loans

We understand that certain types of loans may be difficult for a regulated fund to custody with a permitted custodian. In a no-action letter provided to K&L Gates, the Commission staff stated that it would not recommend enforcement action against regulated funds that did not comply with rule 17f-2 as to self-custodied loan interests and instead implemented alternative procedures designed to achieve the same goals as rule 17f-2.[513] The loans had no certificate or other tangible token of ownership that could be physically “vaulted” under rule 17f-2, and although some regulated funds place paper loan documents with a permitted custodian to satisfy the obligation to hold the loans at a permitted custodian, many permitted custodians do not provide safekeeping services for paper loan documents.

The facts described in the K&L Gates NAL demonstrated the challenges and unique considerations associated with custodying loans. Although the regulated funds had been providing loan documents to a permitted custodian for safekeeping, the loan documents (unlike a securities certificate) could not transfer any value in the loan interests to a transferee. The loan interests could only be transferred after completion of a multi-step settlement process involving the seller of the loan interests, the purchasing regulated fund, and an unaffiliated administrative agent for the loan interests. The loan interests were reflected on the records that were maintained by the administrative agent on behalf of the borrower, for the purpose of identifying the owners of all loan interests and the principal amount of the loan attributable to each.

Instead of complying with the vaulting, access, and notation requirements under rule 17f-2, the regulated funds represented that they would implement alternative procedures to achieve the same goals as rule 17f-2, including the prevention of misappropriation or misuse by persons affiliated with the regulated funds. The alternative procedures included: only a limited number of authorized regulated fund personnel could provide instructions to the custodian and administrative agents, and passwords would be used to ensure only these personnel could transmit such instructions; each regulated fund would reconcile settled loan interests to the records of the administrative agent at least monthly and interest payments would be periodically reviewed for accuracy; and loan interests would be titled or recorded at unaffiliated administrative agents in the name of each regulated fund, not the adviser.[514]

In lieu of the exam requirement, each regulated fund subjected itself to an annual audit, during which the fund's independent public accountant confirmed each regulated fund's investments in loan interests, and reconciled the loan interests to the regulated fund's account records. In addition, each regulated fund's independent auditor relied on controls testing as reported in the Service Organization Controls Report (SOC 1) on the adviser's fund accounting system and controls around trade authorization, trade confirmation, position reconciliation, cost roll-forward, and the systematic calculation of realized gains and losses.[515]

We request comment on regulated funds' custody of loans, including:

208. What challenges, if any, do regulated funds experience in custodying loans? What are the characteristics of these loans ( e.g., how are the loans transferred and recorded)?

209. Are banks and other permitted custodians able to custody loans under the Investment Company Act custody rules, and if not, why not?

210. Should a specific rule be proposed to address a regulated fund custodying its own holdings of uncertificated loan interests? If so, what alternative procedures should apply instead of the rule 17f-2 vaulting, access, notation, and exam requirements? For example, in lieu of the exam requirement should a regulated fund custodying its own loan interests be subject to an audit verifying the loans combined with an internal control report, similar to the approaches in the Advisers Act custody rule for related person custody and the K&L Gates NAL? What other conditions should apply ( e.g., the K&L Gates NAL procedures—limiting the number of authorized fund personnel that can provide instructions to the custodian and administrative agents; using passwords for transmitting instructions; periodically reconciling settled loan interests to the records of the administrative agent and periodically ( printed page 63938) reviewing interest payments for accuracy; and recording loan interests at unaffiliated administrative agents in the name of each regulated fund, not the adviser)?

(c) Certificated Securities

Many of rule 17f-2's provisions are premised on the assumption that fund assets are certificated securities that can be locked in a physical vault, and as discussed above, this can present particular challenges in the context of uncertificated securities.[516] While most securities are now uncertificated, physical, certificated investments still exist (for example, in legacy holdings). These could include physical stock certificates from older companies, private placement shares, and physical savings bonds. We request comment below on the extent to which funds invest in these or other kinds of certificated securities and whether rule 17f-2's conditions should be amended in any way as applied to these investments.

211. Are there certificated securities in which regulated funds invest that are maintained by the regulated fund itself pursuant to rule 17f-2? What kinds of securities? Are there any particular challenges that this rule poses in the context of custodying certificated securities ( e.g., the access, notation and exam requirements)? If so, what are these, and what alternative processes would be preferable?

(d) Cleared Swap Collateral

Rule 17f-6 permits regulated funds to maintain their fund assets with futures commission merchants (“FCMs”) that are registered under the Commodity Exchange Act (“CEA”) in order to effect the fund's transactions in exchange-traded futures contracts and commodity options.[517] The conditions in rule 17f-6 generally require the FCM to comply with certain segregation requirements under CFTC rules; allow the FCM to place and maintain the fund's assets to effect the fund's transactions with certain other parties ( e.g., a derivatives clearing organization) subject to CFTC rules and require an acknowledgment from the other party that the fund assets are held on behalf of the FCM's customers; and require the FCM promptly to furnish records or other information pertaining to the fund's assets to the Commission or its staff upon their request. Rule 17f-6 also provides that any gains on the regulated fund's transactions, other than de minimis amounts, may be maintained at the FCM only until the next business day following receipt. Finally, the rule requires the withdrawal of fund assets from the FCM as soon as reasonably practicable if the regulated fund's custodial agreement no longer meets the requirements of the rule.

In 2010 Congress passed the Dodd-Frank Act, which established segregation requirements and bankruptcy treatment for swaps cleared through a derivative clearing organization and directed the CFTC to establish rules regarding the central clearing of swap transactions.[518] In response, the CFTC adopted comprehensive rules governing the treatment of cleared swaps generally and the custody of related collateral by FCMs specifically.[519]

Commission staff has subsequently issued no-action letters stating that the staff would not recommend enforcement action if regulated funds placed and maintained fund assets with certain clearing organizations and their clearing member FCMs that comply with the CFTC cleared swap rules in connection with the regulated funds' transactions in specific cleared swaps, subject to conditions comparable to those required by rule 17f-6.[520] These no-action letters are limited to the specific derivatives clearing organizations and cleared swap transactions addressed in each letter. The letters generally provide that the staff would not recommend enforcement action under these circumstances, which are based on the requirements of rule 17f-6:

We request comment on FCM custody of regulated fund cleared-swap collateral, including:

212. Should we propose amendments to rule 17f-6 to allow a regulated fund to place and maintain fund assets with FCMs and the other parties specified in the rule in connection with the fund's transactions in cleared swaps, or alternatively a subset of cleared swaps (such as the cleared swap transactions for which the staff issued a no-action letter)? Should such a proposal be limited to cleared swaps as defined by rule 22.1 under the CEA? Are there types of cleared swaps that do not meet the CEA definition of cleared swaps that should be included in the amendments?

213. If we propose amendments to rule 17f-6, how should we propose to modify the rule's conditions to accommodate cleared swaps while addressing the associated custodial risks? Should we add a reference to the written acknowledgment requirement from derivatives clearing organizations to the provision of rule 17f-6 requiring written acknowledgment from depositories? How does the clearing structure for cleared swaps differ from the clearing structure for the transactions in exchange-traded futures contracts and commodity options covered by rule 17f-6, and how should these differences inform appropriate conditions?

G. Investment Adviser Custody Rule Modernization

Originally adopted in 1962 pursuant to Advisers Act section 206(4), the Advisers Act custody rule has been amended several times in response to industry developments and risks.[521] The Commission most recently amended the rule in 2009 in light of several well-publicized fraud cases against investment advisers for actions that ( printed page 63939) included misappropriation or other misuse of client funds and securities.[522] In 2010, Congress passed the Dodd-Frank Act, adding a new section 223 titled “Custody of Client Accounts” to the Advisers Act, which provides the Commission with additional rulemaking authority related to the safeguarding of client assets.[523] Over time, questions about the application of certain aspects of the Advisers Act custody rule have arisen, often in response to evolving technologies and market practices.

To address certain longstanding questions relating to the application of the Advisers Act custody rule, we are proposing a number of modernizing amendments to the rule and proposing to provide guidance on certain known custody issues. These proposed modernizations include rule amendments to: (a) redesignate the Advisers Act custody rule to new rule 223-1 to align with the specific statutory authority provided in the Dodd-Frank Act relating to custody of client assets, (b) except authorized discretionary trading from the Advisers Act custody rule subject to conditions that limit executions to designated client accounts and prohibit transfers to accounts controlled by the adviser or related persons, (c) eliminate the requirements for accountants engaged to perform audit and examination services under the Advisers Act custody rule to be registered with, and subject to regular inspection by, the PCAOB, (d) modernize the audit requirements for pooled investment vehicles, (e) except advisers with respect to accounts subject to standing letters of authorization from asset verification requirements, (f) explicitly except advisers with respect to accounts of BDCs from the Advisers Act custody rule since they are subject to Investment Company Act custody requirements, (g) require an account number be included in the notice sent to the client by an adviser upon opening an account with a qualified custodian and following changes to certain information, (h) modernize rule language related to the notice an accountant must provide to the Commission upon the finding of any material discrepancies during the course of an independent verification, and (i) except advisers from the rule with respect to inadvertent custody of client funds or securities. We also outline our views related to: (a) segregation requirements for assets held at qualified custodians and client cash held at banks; and (b) disclosure related to accommodation reporting.

1. Redesignation to Section 223

We propose to redesignate the Advisers Act custody rule as new rule 223-1 under the Advisers Act. We propose to make this redesignation in the light of the additional authority that Congress provided the Commission in 2010 under the Dodd-Frank Act to prescribe investment adviser custody rules in section 223 of the Advisers Act.[524] Section 223 grants the Commission authority to adopt rules requiring registered investment advisers to take steps to safeguard client assets over which they have custody, including, without limitation, verification of such assets by an independent public accountant.

Redesignation of the current Advisers Act custody rule to section 223 would better align the rule with specific statutory authority regarding registered investment adviser custody of client accounts. Proposed rule 223-1, which would effectively replace current rule 206(4)-2 through redesignation, states that an adviser registered or required to be registered under section 203 of the Act must take certain steps to safeguard the client funds and securities of which the adviser has custody. Consistent with this redesignation, the proposed rule would no longer reference section 206(4) in its opening preamble regarding whether custody practices would be a fraudulent, deceptive, or manipulative act, practice or course of business. More specifically, to align with the statutory language of section 223, the redesignated rule replaces the lead-in language that was in 206(4)-2(a) to instead state that the adviser “must take the following steps to safeguard client funds and securities” of which it has custody. Redesignating the rule with the statutory provision that specifically addresses the custody of client funds and securities aligns the rule more closely with congressional intent to strengthen safeguarding requirements, including verification standards by independent public accountants, after investment adviser frauds uncovered during the financial crisis.[525]

We request comment on the redesignation of the Advisers Act custody rule to section 223:

214. Are there any practical implications for investment advisers in redesignating this rule and revising its introductory language?

2. Discretionary Trading Authority

We are proposing to amend the Advisers Act custody rule to specifically except discretionary trading authority by an adviser from the requirement to comply with the Advisers Act custody rule provided certain conditions are met. Specifically, advisers would not be required to comply with the proposed rule with respect to funds and securities over which the adviser has custody due to its authority to trade at its discretion provided that: (1) the adviser executes (and only has authority to execute) such trades only from and into designated client accounts in the client's name or the transfer is recorded in the client's name by the issuer; (2) the adviser has no authority (under the discretionary trading arrangement or otherwise) to transfer client funds or securities from the designated client account to itself or an account the adviser or its related person controls, or to any account that is not the client's unless such transfer is directed by the client in connection with such trading, nor does the adviser have the authority to have the transfer recorded by the issuer in its own name or that of a related person; and (3) the adviser complies with the Advisers Act custody rule for any other activities, rights, or authorities that otherwise cause it to have custody of such funds or securities separate from such discretionary trading authority and with the requirements of any corresponding exceptions under the Advisers Act custody rule that the adviser may exercise pursuant to such custody.[526]

In 2003, the Commission stated that an adviser's authority to issue instructions to a broker-dealer or a ( printed page 63940) custodian to effect or to settle trades does not constitute custody.[527] The Commission went on to explain a client's custodian is generally under instruction to transfer funds (or securities) out of a client's account only upon corresponding transfer of securities (or funds) into the account.[528] The Commission further explained that such delivery versus payment (“DVP”) arrangements minimizes the risk that an investment adviser could withdraw or misappropriate funds and securities in a client's custodial account. While the discussion in the 2003 Adopting Release identifies authorized trading as outside of the Advisers Act custody rule, it only identifies its inapplicability in the context of DVP trading.

Over the years, Commission staff and members of industry have engaged in a dialogue around whether authorized trading on a non-DVP basis constitutes custody under the Advisers Act custody rule.[529] In 2017, Commission staff issued guidance regarding inadvertent custody that raised questions as to whether an adviser trading assets on a non-DVP basis would have custody.[530] Following that guidance, investment advisers and other market participants expressed concerns related to the regulatory status of investment adviser discretionary trading practices that are processed or settled on a non-DVP basis.[531] In a 2019 letter seeking further engagement on the issue, Commission staff identified certain risks related to arrangements that trade on a non-DVP basis, stating that where trading or settlement occurs through a non-DVP arrangement, there is a heightened risk that an investment adviser could misappropriate funds or securities in its client's custodial account and that the lack of a corresponding transfer of securities or client funds into the custodial account reduces the effectiveness of the custodian as an independent safeguard.[532] In response, industry groups stated that an expansion of the rule's application to such arrangements misinterprets the 2003 Adopting Release; unduly expands the application of the rule to assets that trade on a non-DVP basis including loans, derivatives, private funds, and foreign assets; ignores that many investment management agreements already prohibit advisers from having custody while also outlining guidelines for the specific assets they are authorized to trade, and overlooks that advisers typically maintain reasonably designed policies and procedures tailored to the particular circumstances of an asset's settlement system.[533]

In light of the concerns raised by industry members about the application of the Advisers Act custody rule to discretionary trading activities, we are proposing an exception related to the treatment of authorized discretionary trading under the custody rule, considering any custodial risks such activity may pose as well as potential mitigating protections. As an initial matter, when assessing the custodial risks posed by discretionary trading on both DVP and non-DVP bases, it is important to distinguish risks related to custody and risks related to the settlement of transactions executed pursuant to discretionary trading authority because the Advisers Act custody rule is not generally intended to address risks related to settlement failure. It is possible that an adviser is competent in safeguarding client funds and securities (including complying with the requirements of the Advisers Act custody rule) yet the funds or securities it trades or the entities through which it trades may be subject to settlement or related risks. For example, in a derivatives trade, an adviser's counterparty may fail to deliver variation margin, which could occur for a number of reasons including operational errors or the insolvency of a regulated entity like a broker-dealer. The prophylactic measures in the Advisers Act custody rule are not designed to mitigate settlement or investment risks highlighted in this example but are intended to prevent and discover potential misappropriation, misuse, or loss. Accordingly, if the proposed discretionary trading authority exception is adopted, we expect to rescind the discussion in the 2003 Adopting Release on trading authority.

We are proposing three conditions that, collectively, are designed to mitigate the custodial risks associated with an adviser's discretionary trading authority. Instead of focusing on the means of settlement (whether DVP or non-DVP), our proposed conditions focus on custody risks and the adviser's authority to direct client assets outside of its trading authority. Specifically, advisers would not be required to comply with the proposed Advisers Act custody rule with respect to funds and securities over which it has custody due to its authority to trade at its discretion provided that:

(1) the adviser executes (and only has authority to execute) trades only from and into designated client accounts in the client's name or the transfer is recorded in the client's name by the issuer;

(2) the adviser has no authority (under the discretionary trading arrangement or otherwise) to transfer client funds and securities from the designated client account to an account in its own name, to an account the adviser controls, to an account controlled by a related person of the adviser as defined in proposed rule 223-1(d)(15), or to any account that is not the client's unless such transfer is directed by the client in connection with such trading, nor does the adviser have the authority to have the transfer recorded by the issuer in the adviser's own name or that of a related person; and

(3) the adviser complies with the Advisers Act custody rule for any other activities, rights, or authorities that otherwise cause it to have custody separate from such discretionary trading authority and with the requirements of any corresponding exceptions under the Advisers Act custody rule that the adviser may exercise pursuant to such custody.[534]

As an initial matter, an adviser with authorized discretionary trading authority must execute (and only have authority to execute) trades only from and into a designated client account in the client's name or have the transfer recorded in the client's name by the issuer to qualify for this proposed exception from the Advisers Act custody rule.[535] The proposed rule ( printed page 63941) would require specific identification of the account in which trading can occur, which would restrict the locus of the funds and securities and limit advisers from withdrawing or accessing funds in another way that would present significant misappropriation risks.[536] The proposed rule would require only trades from and into designated accounts in the client's name to ensure the assets are clearly identifiable as those of the client. This designated client account requirement provides protections similar to some of those found in the existing Advisers Act custody rule, namely, to notify a client of the account's location and provide a means for the client to monitor the amount and transactions in their account.[537]

This proposed condition also provides that the transfer of a security may be recorded in the client's name by the issuer. We understand from engagement on this issue that certain privately offered securities and bank loans may record ownership in this manner.[538] Allowing the transfer of securities to be recorded in the client's name by the issuer would provide flexibility for these kinds of securities while still providing appropriate protections given that the issuer, its designated administrator, or custodian is generally required to perform verification procedures on the client and certain trade details.[539]

An adviser seeking to rely on this discretionary trading authority exception would not be permitted to have authority (under the discretionary trading arrangement or otherwise) to transfer client funds and securities from the designated client account to an account in its own name or an account the adviser or its related person controls, or to any account that is not the client's unless such transfer is directed by the client in connection with such trading, nor the authority to have the transfer recorded by the issuer in the adviser's name or that of a related person.[540] This proposed condition is necessary because an adviser with the authority to transfer client funds or securities to itself, its related person or to a third party absent client direction would present the misappropriation risk that the Advisers Act custody rule is designed to protect against.

To demonstrate compliance with this condition, advisers could consider amending their investment management agreements or other arrangements to expressly prohibit the adviser or its related persons from transferring client funds or securities to itself or a related person (which would allow the adviser authority to obtain actual possession of client funds or securities) or to any account that is not the client's unless such transfer is directed by the client. It is our understanding that some investment management agreements contain similar provisions expressly providing that the adviser does not have custody of client assets.[541]

The proposed condition that the adviser must not have authority to transfer client funds and securities to any account that is not the client's unless the transfer is directed by the client in connection with such trading is designed to prevent advisers from unauthorized transfers of client funds or securities from the designated client account to the account of a third party.[542] This provision would address circumstances of misappropriation where, for example, an advisory employee transfers funds or securities to a family member or other third party associated with the adviser. However, transfers where the client has directed or provided the adviser with authority to transfer assets to a counterparty in furtherance of a trade with such third party would not be prohibited under this condition of the exception. This is necessary so that advisers can complete trades with third parties consistent with the authority provided by the client.

Lastly, to qualify for this proposed exception from the Advisers Act custody rule, an adviser with custody of funds or securities arising from its discretionary trading authority must comply with the Advisers Act custody rule for any other activities, rights, or authorities that otherwise cause it to have custody of such funds or securities separate from such trading authority and with the requirements of any corresponding exceptions under the Advisers Act custody rule that such adviser may exercise pursuant to such custody.[543] Some advisers have custody for separate reasons such as fee deduction authority or broad powers of attorney and may therefore engage both in discretionary trading and have the ability to transfer funds or securities out of client accounts, for example, to pay third party administrative or operating expenses.[544] These advisers' authority to transfer funds or securities out of a client's account exposes such client funds or securities to custodial risks regardless of whether the adviser also has discretionary trading authority. For instance, an adviser with both authority to trade at its discretion, and to transfer funds out of a client account for other purposes, could use the latter authority alone to misappropriate client funds, necessitating the protections of the Advisers Act custody rule. In that case, ( printed page 63942) the proposed discretionary trading authority exception would not be available unless the adviser complies with the Advisers Act custody rule with respect to its authority to transfer funds because the adviser has custody of funds or securities through its authority to transfer funds out of the account for purposes separate from its discretionary trading authority. This provision is designed to ensure that the authority is truly limited to executing trades and not used broadly to except wire authority or other authorities that confer custody outside of the discretionary trading context.

Additionally, this provision is designed to address circumstances where other exceptions under the Advisers Act custody rule may apply to an adviser that has custody over funds or securities for a separate reason in addition to its discretionary trading authority. In such circumstances advisers would need to comply with and independently satisfy such exceptions if they intend to rely on both of them. For example, an adviser could have two separate bases for custody: discretionary trading authority and inadvertent custody. In this situation, the adviser should evidence its satisfaction of the conditions to the exception for inadvertent custody, such as disavowing unwanted authority, while separately satisfying the three individual conditions of the discretionary trading authority exception. Based on the foregoing, an adviser that seeks to rely on this proposed exception from the Advisers Act custody rule should carefully review and monitor whether it otherwise has or acquires custody over the funds or securities it is trading on a discretionary basis to avoid becoming subject to the Advisers Act custody rule.

In practice, we understand that some advisers would likely have both discretionary trading authority and fee deduction authority over a client account. An adviser that has custody solely because it has authority to withdraw its advisory fees directly from a client's account is excepted only from the surprise examination requirement, but all other requirements of the Advisers Act custody rule, including the obligations to maintain client assets with a qualified custodian, to provide notice to clients upon account opening, and to have a reasonable basis for believing the qualified custodian sends account statements directly to clients, would continue to apply. In such circumstances where the adviser would have two separate bases for custody, the adviser would not be able to rely solely on satisfaction of the conditions of the discretionary trading authority exception to obtain relief from compliance with the entirety of rule, because the adviser would need to comply with the Advisers Act custody rule with respect to the separate basis for custody e.g. its fee deduction authorities. Therefore, with respect to such funds or securities that are subject to fee deduction the proposed rule would only except them from the surprise examination, but they would still be required to comply with the remainder of the rule. This outcome under the proposed rule aligns with the protective objectives of the Advisers Act custody rule because an adviser with authority to withdraw fees from a client account may transfer or withdraw funds to itself.

In addition to the specific conditions of this proposed exception from the Advisers Act custody rule, an adviser would need express authority in writing from a client to trade such client's funds or securities on a discretionary basis. Investment management agreements and provisions authorizing discretionary trading typically have express discretionary authority in writing from the client to issue instructions to execute such trades. Agreements that specify the extent of an adviser's authority help ensure that the client has consented to the arrangement before the adviser begins trading on a discretionary basis. Such agreements also provide the client with an opportunity to scope the adviser's trading activities appropriately to the investment strategy and asset types they trade. For example, a client could only authorize an adviser to trade a particular type of asset on a discretionary basis following a particular process, or with certain counterparties. A client could also authorize an adviser to trade a wide set of assets on a discretionary basis, but with specific parameters or a particular investment objective. Taken together, the facts and circumstances of the arrangement and specific written agreements outlining the client's authorization of discretionary trading are important in mitigating custody risk related to providing advisers with such authority. Broadly written grants of authority may prevent an adviser from qualifying for the proposed discretionary trading authority exception as they may instead constitute a more general power of attorney or arrangement authorizing the withdrawal of client funds or securities that otherwise would be “custody” under proposed rule 223-1(d)(6). We thus encourage advisers to review their contractual grants of authority.

Rule 206(4)-7 under the Advisers Act requires registered investment advisers to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and its rules.[545] Accordingly, an adviser that is seeking to rely on the proposed rule's discretionary trading authority exception should adopt written policies and procedures that are reasonably designed to ensure that the adviser's discretionary trading practices meet the conditions required under the rule.[546] For example, the adviser should consider adopting policies and procedures to provide how the adviser: monitors whether it has custody of client funds or securities for reasons other than its discretionary trading authority; has authority to and executes trades only from and into a designated account in the client's name or the transfer is recorded in the client's name by the issuer; confirms that the adviser has no authority to transfer client funds and securities from the designated client account to an account in its own name or an account the adviser or its related person controls, or to any account that is not the client's unless such transfer is directed by the client in connection with such trading, nor the authority to have the transfer recorded by the issuer in the adviser's own name or its related person; and monitor transactions to detect whether any such transfer has occurred.[547]

We also understand that adviser compliance programs may currently set forth other procedures regarding trading activities including, but not limited to: requiring the authorization of more than one employee before the movement of assets within, and withdrawals or transfers from, a client's account, as well as before changes to account ownership information; limiting the number of employees who are permitted to interact with custodians and administrators with respect to client assets and rotating them on a periodic basis; and segregating the duties of its advisory and third party personnel to make it difficult for any one person to misuse client assets without being ( printed page 63943) detected. Advisers, therefore, should consider focusing on such controls in the adviser's compliance program including by developing procedures by which the chief compliance officer periodically tests the effectiveness of the firm's controls over the trading of funds and securities on a discretionary basis. We have provided the guidance set out above primarily in the form of examples rather than proposing a one-size-fits-all approach and expect that advisers would tailor their discretionary trading policies and procedures to fit the asset types and particular risks involved. The Commission requests comment on our proposed amendments to the Advisers Act custody rule to except discretionary trading authority from the definition of custody:

215. Should we amend the Advisers Act custody rule to provide the proposed exception for discretionary trading authority from the custody rule? Are there any significant issues related to discretionary trading authority that the proposed amendments have not addressed? Should we provide more specific rule text or guidance for certain settlement or asset types such as DVP, non-DVP, loans, collateralized loan obligations, derivatives, private fund interests, or any other assets? Should we also consider amendments to the privately offered securities exception to accommodate such assets? [548]

216. Should the proposed exception require the use of a qualified custodian or require a qualified custodian to perform any particular services for the adviser to avail itself of the exception? Should we require or not require a qualified custodian for certain asset types? Should the proposed exception be available to crypto assets?

217. Instead of providing an exception from the Advisers Act custody rule should we instead amend the definition of custody to exclude discretionary trading authority from the definition of custody? If we amended the definition of custody to exclude such trading activities, should we still require conditions comparable to those we provide in the proposed exception?

218. Should an adviser be able to utilize the exception if it has custody for reasons other than its discretionary trading authority? Under the exception should the adviser have to comply with the Advisers Act custody rule for any other activities, rights, or authorities that otherwise cause it to have custody of such funds or securities separate or in addition to such trading authority? For example, should advisers have to independently comply with other exceptions related to a separate basis of custody including exceptions for fee deduction, SLOAs, and inadvertent custody among others?

219. Should we exclude or include any different conditions for this proposed exception? Do advisers with discretionary authority over a client's funds or securities (regardless of settlement method) currently have safeguards in place that effectively limit the risks to clients of loss, misuse, theft, or misappropriation? Do these safeguards differ depending on whether the arrangement involves a qualified custodian or the asset type? Should we modify any of the conditions?

220. Should we define designated client account? If so, should it be sufficiently broad to accommodate certain types of trading practices? Should the proposed limitation on transfers from the designated client account to an account in the adviser's name or one it controls allow for certain exceptions? Should it not apply to cross or principal trades involving related parties if the adviser (i) seeks and obtains written approval by the client for the specific trade and (ii) effectuates the trade in compliance with the adviser's policies and procedures for such trades? Should the proposed exception specifically address custody imputed from signatory authority, related party accounts, or family accounts?

221. Should we prohibit transfers to any account that is not the client's unless such transfer is directed by the client? Does this provision address circumstances of misappropriation where an advisory employee transfers funds or securities to a family member or other third party associated with the adviser? Does the provision allowing transactions where the client has directed or provided the adviser with authority to transfer assets to such third party provide appropriate flexibility so that advisers can complete trades with third parties? Should we require that the authorization or direction for transfers to any account that is not the client's be in writing? Could this provision be abused in certain circumstances for unauthorized transfers?

222. Should we change the proposed designated client account requirement so that an adviser cannot open accounts in the client's name or change the beneficiary of those accounts without providing notice and/or receiving client consent to do so? Are there any fund structuring or account opening details that may conflict with the proposed designated client account condition and the condition limiting transfers from the designated client account to an account in the adviser's name an account it controls, or any account that is not the client's unless such transfer is directed by the client in connection with such trading? As a practical matter, would clients likely have knowledge of the specific designated client accounts in which the adviser's discretionary trading activity will occur? Are such accounts typically identified and agreed upon at account opening or during the course of the advisory relationship?

223. Would advisers to private funds or separately managed accounts be able to comply with the proposed conditions to the exception? Are there unique circumstances or trading practices that would make complying with such conditions difficult?

224. Should the rule provide a definition for discretionary trading authority? If so, what should it be? Or is this term reasonably understood and applicable to the investment strategies that advisers provide to their clients? Should we conform the definition of discretionary trading authority with the Form ADV definition of “Discretionary Authority” or “Discretionary Basis” (“your firm has discretionary authority or manages assets on a discretionary basis if it has the authority to decide which securities to purchase and sell for the client” and “[y]our firm also has discretionary authority if it has the authority to decide which investment advisers to retain on behalf of the client”). Should we distinguish discretionary trading authority in the exception from the Form ADV definition because the proposed exception does not include having the authority to decide which investment advisers to retain on behalf of a client? Should we require written policies and procedures specific to the proposed discretionary trading authority exception, or rely on existing compliance rule obligations under rule 206(4)-7? If we require specific policies and procedures or internal controls, what should those be? In addition to the rule should we provide guidance with regard to compliance programs for authorized discretionary trading activities?

225. Would the proposed amendments require clients, advisers, and custodians to reconsider relevant investment management agreements, custodial contracts, or other arrangements? Or are many of the proposed conditions already met in existing agreements? What would the relative costs or compliance burdens with the exception be? Would the ( printed page 63944) proposed rule cause advisers to re-consider providing discretionary trading services to clients?

226. In addition to existing recordkeeping obligations under the Advisers Act, should there be specific corresponding recordkeeping obligations related to use of the proposed discretionary trading authority exception? Do advisers already maintain evidence of an adviser's trading authority pursuant to the existing recordkeeping rule? [549]

3. PCAOB-Registered Accountant Requirement

We are proposing amendments to the Advisers Act custody rule to remove the requirements that accountants and auditors must be registered with, and subject to regular inspection by, the PCAOB. The auditor performing the audit of a pooled investment vehicle's annual financial statements pursuant to the rule's audit provision, as well as the accountant performing the surprise examination or preparing the internal control report would continue to be required to be an independent public accountant.[550] Additionally, we are proposing conforming amendments to the description of the internal control report under current rule 206(4)-2(a)(6) (proposed to be redesignated as rule 223-1(a)(6)) to align the description of the internal control report with updates to the language in attestation standards.[551] These changes are not intended to change the substance of the internal control report requirement.

Under the current audit provision, a pooled investment vehicle's annual audited financial statements must be prepared by a PCAOB-registered and -inspected independent public accountant for the adviser to such vehicle to be deemed to satisfy the surprise examination requirement and be excepted from the client notice and account statement delivery requirements.[552] Additionally, under the Advisers Act custody rule, if an adviser or a related person of the adviser maintains client funds or securities as a qualified custodian, an independent public accountant that is registered with, and subject to regular inspection by, the PCAOB must perform the required surprise examination and prepare the required internal control report.[553]

The PCAOB was established by the Sarbanes-Oxley Act of 2002 (“Sarbanes-Oxley Act”) to oversee the audit of companies that are subject to the securities laws, and related matters, in order to protect the interests of investors and further the public interest in the preparation of informative, accurate, and independent audit reports.[554] The requirement for independent public accountants to be registered with, and subject to regular inspection by, the PCAOB was added in the 2009 amendments to the Advisers Act custody rule.[555] The PCAOB registration and inspection requirements were intended to serve as a measure of quality of the audits and examinations required to be performed under the Advisers Act custody rule and the accountants performing these required audit and examination services. However, as the Commission acknowledged in the 2009 Adopting Release, PCAOB inspection is focused on public company audits, and the PCAOB does not inspect the engagements that are required solely because of the Advisers Act custody rule.[556] The Commission at that time stated that the PCAOB requirements could provide indirect benefits for purposes of the Advisers Act custody rule regarding the quality of the accountant's or auditor's other engagements.[557]

In light of the Commission's experience since the 2009 amendments, we now believe that any indirect benefits of the Advisers Act custody rule's PCAOB registration requirements may not justify the incremental cost of engaging a PCAOB-registered firm. A firm's PCAOB registration status does not indicate whether the firm is subject to PCAOB oversight or inspection nor whether its professional services are within the PCAOB's limited scope of oversight authority.[558] Although there has been some positive correlation between PCAOB-registered firms subject to inspection and the quality of audit services,[559] as the PCAOB has previously stated, PCAOB oversight status does not itself provide assurance of the quality of a firm's professional services.[560] As discussed above, the PCAOB's oversight authority does not cover the services that are required to be performed under the Advisers Act custody rule. Because the PCAOB does not currently examine or inspect accountants with respect to the services required under the Advisers Act custody rule, the PCAOB registration and inspection requirements are not an appropriate proxy for the quality of the audit and examination services required under the rule.

We also understand that the PCAOB requirement generally increases the ( printed page 63945) costs of audit and examination services.[561] Firms that register with the PCAOB are subject to annual registration fees, which vary depending on the size of the firm.[562] Further, firms that identify and market themselves as PCAOB-registered have generally been found to have charged higher fees after becoming PCAOB-registered than they previously charged.[563] Because, as discussed above, the audit and examination services under the Advisers Act custody rule are not within the scope of PCAOB's authority, this increased cost may not be offset by a commensurate benefit to investors in these circumstances.

Removing the PCAOB requirements would increase the supply of independent public accountants that are available to perform the required audit and examination services under the Advisers Act custody rule, which would increase competition for the provision of the required audit and examination services under the rule. This increased competition could ultimately reduce costs to advisers of complying with the rule.

We request comment on all aspects of the proposed amendments to remove the requirements in the Advisers Act custody rule for independent public accountants to be registered with, and subject to regular inspection by, the PCAOB, including the following items:

227. Should we, instead of the proposed rule, continue to require that the accountants performing surprise examinations or preparing internal control reports for an adviser (or its related person) that acts as a qualified custodian for client funds or securities and/or that perform annual audits of limited partnerships or other pooled investment vehicles be registered with, and subject to regular inspection by, the PCAOB? Is the current PCAOB requirement a meaningful measurement of quality for the types of audits and examinations that are required to be performed by independent public accountants under the Advisers Act custody rule?

228. Should the Advisers Act custody rule require that accountants and auditors performing audit and examination services pursuant to the rule be subject to an alternative registration and inspection standard? If so, describe these alternative requirements. For example, should the rule require that independent public accountants be enrolled in the American Institute of CPAs (“AICPA”) peer review program and have received a rating of `pass' in the most recently reviewed period? How would such a qualification requirement affect the number of available qualified independent public accountants? Do such accountants generally charge higher fees than other independent public accountants?

229. We note that accountants generally use Statements on Standards for Attestation Engagements (“SSAEs”) for attestation engagements in the U.S., may apply dual standards when a report will also be used internationally, and may use International Standards on Assurance Engagements (“ISAEs”) when serving non-U.S. clients. In light of this, should accountants performing examination services pursuant to the Advisers Act custody rule be explicitly permitted to conduct examinations pursuant to other attestation standards, such as ISAEs? If so, when? Would permitting the use of alternative attestation standards affect the number of independent public accountants offering examination services required under the Advisers Act custody rule? How would this affect the cost of such examination services?

230. Do the proposed conforming amendments to the description of the internal control report under proposed rule 223-1(a)(6)) align with the AICPA Attestation Standards (Clarified) [564] ? Do commenters agree that these proposed conforming amendments would not change the substance of the internal control report?

231. Should we amend any references in the Advisers Act custody rule to independent public accountants? For example, should the definition of “independent public accountant” under the Advisers Act custody rule be amended so that it is defined as a public accountant that meets the standards of independence described in rule 2-01 of Regulation S-X (17 CFR 210.2-01) (as opposed to rule 2-01(b) and (c) of Regulation S-X (17 CFR 210.2-01(b) and (c)), as proposed and in the current Advisers Act custody rule)? Why or why not?

4. Audit Provision

Under the audit provision of the Advisers Act custody rule, an adviser to a limited partnership, limited liability company, or other pooled investment vehicle is excepted from the client notice and account statement delivery requirements and is deemed to have complied with the rule's surprise examination requirement, provided that, among other things, audited financial statements are delivered to the investors in the pooled investment vehicle on an annual basis.[565]

We are proposing several amendments to the audit provision of the Advisers Act custody rule. First, we propose to amend the audit provision to specify that the reference to audited financial statements prepared in accordance with “generally accepted accounting principles” refers to U.S. Generally Accepted Accounting Principles (U.S. GAAP) or, for non-U.S.-based pooled investment vehicles, in accordance with accounting principles other than U.S. GAAP, provided that the financial statements contain information substantially similar to the information contained in financial statements prepared in accordance with U.S. GAAP, including a reconciliation to U.S. GAAP for material differences, and such reconciliation is delivered to the pooled investment vehicle's U.S. investors. Second, we propose to extend the audited financial statement distribution deadlines applicable to a fund of funds and fund of funds of funds to 180 days and 260 days, respectively, after fiscal year end. We also outline our view that the failure to distribute audited financial statements by the applicable deadline due to reasonably unforeseeable circumstances generally would not be considered a violation of the audit provision, provided that the audited financial statements are promptly delivered upon resolution of the reasonably unforeseeable circumstances. Third, we propose to modify the delivery requirements for audited financial statements for pooled investment vehicles that are formed within the 90-day period prior to the vehicle's fiscal year end to provide that the requirement would be deemed satisfied if financial statements (which may be unaudited) covering the first fiscal year are distributed within 90 days after the end of the first fiscal year and audited financial statements covering the first fiscal year and second fiscal year are delivered after the end of the second fiscal year. In connection with these proposed amendments, we are also ( printed page 63946) proposing to modify the distribution requirements of the audit provision to provide that the financial statements may be distributed to an independent representative of the investor.[566] These proposed amendments to the Advisers Act custody rule's audit provision would facilitate compliance with the audit provision, better address industry practices, and reduce burdens.

(a) Use of U.S. GAAP and Reconciliation to U.S. GAAP for Foreign Pooled Investment Vehicles

We are proposing amendments to the audit provision to specify that a pooled investment vehicle's audited financial statements must be prepared in accordance with U.S. GAAP, except for financial statements of pooled investment vehicles organized under non-U.S. law or that have a general partner or other manager with a principal place of business outside the United States (“foreign PIVs”).[567] We propose to allow financial statements of foreign PIVs to be prepared in accordance with accounting principles other than U.S. GAAP, provided that the financial statements contain information substantially similar to the information contained in financial statements prepared in accordance with U.S. GAAP, including a reconciliation to U.S. GAAP for material differences, and such reconciliation is delivered to the pooled investment vehicle's U.S. investors, along with the required audited financial statements.[568]

Under the current audit provision, financial statements must be prepared in accordance with “generally accepted accounting principles,” but the rule does not require that financial statements must be prepared in accordance with U.S. GAAP specifically.[569] Nonetheless, it has been the Commission's longstanding view that, except in the limited circumstances discussed below, audited financial statements would need to be prepared in accordance with U.S. GAAP.[570] We continue to believe that U.S. GAAP is the proper accounting framework. As a primary matter, U.S. GAAP is well understood by U.S. investors. U.S. GAAP also incorporates important industry-specific accounting and disclosure principles for common types of pooled investment vehicles, including private funds. For example, for pooled investment vehicles within the scope of the FASB ASC Topic 946, U.S. GAAP requires presentation of a schedule of investments and financial highlights and the measurement of trades on the trade date (as opposed to the settlement date) that may not be required under other accounting principles.[571] These features of U.S. GAAP are familiar to U.S. investors and, in turn, allow these investors to better understand and compare pooled investment vehicles.

We recognize, however, that foreign PIVs often have their financial statements prepared in accordance with accounting principles related to their local jurisdictions rather than U.S. GAAP. The proposed amendments would require that the financial statements must contain information substantially similar to the information contained in financial statements prepared in accordance with U.S. GAAP, including a reconciliation to U.S. GAAP for material differences.[572] This proposed requirement, along with the proposed requirement to deliver the audited financial statements including any reconciliations to U.S. GAAP to the pooled investment vehicle's U.S. investors, would promote consistency and comparability of audited financial statements, allowing U.S. investors to be better able to assess and monitor the vehicle's investments, particularly over multiple periods.

We request comment on all aspects of the proposed amendments to the audit provision to require U.S. GAAP and to permit foreign PIVs to use an accounting framework other than U.S. GAAP, subject to certain conditions, including the following items:

232. Should the rule require the audited financial statements be prepared in accordance with U.S. GAAP, as proposed?

233. We propose to define U.S. GAAP to mean accounting principles promulgated, or recognized by the Commission as generally accepted, in accordance with section 19 of the Securities Act of 1933 (15 U.S.C. 77s). Do commenters agree with this proposed definition? Is there a different definition we should use?

234. Should the requirement to deliver U.S. GAAP reconciliation to investors apply only to U.S. investors, as proposed? Alternatively, should the rule require that the reconciliation to U.S. GAAP be delivered to both U.S. and non-U.S. investors?

235. Should the proposed rule specify that the U.S. GAAP reconciliation must be included within the audited financial statements that are delivered pursuant to the audit provision? Alternatively, should the U.S. GAAP reconciliation be permitted to be included in a separate statement that accompanies the audited financial statements? If so, should an additional books and records requirement be added for such separate reconciliations in the Advisers Act recordkeeping rule?

236. Is the requirement that information be `substantially similar' to information contained in financial statements prepared in accordance with U.S. GAAP currently well-understood and consistently applied? Would it be helpful to clarify how foreign PIVs using an accounting standard other than U.S. GAAP provide information substantially similar to information contained in financial statements prepared in accordance with U.S. GAAP? What specific guidance would be most helpful?

237. Given the prevalence, for tax and other reasons, of private funds and other pooled investment vehicles being organized outside of the U.S. (even ( printed page 63947) when a substantial portion or majority of the invested assets come from U.S. investors), should we distinguish between foreign PIVs that have non-U.S. investment advisers and foreign PIVs that have a primary adviser with a principal office and place of business in the U.S.?

238. Similarly, should any ability to utilize non-U.S. GAAP in preparing and presenting financial statements be linked to a foreign PIV having a given threshold of non-U.S. investment ( e.g., a requirement that a majority of the invested capital be traced to clients that are not U.S. Persons)?

239. Should any different requirements apply for foreign PIVs that are also registered as a commodity pool with the CFTC and prepare financial statements in accordance with accounting principles or standards in accordance with applicable CFTC regulations?

(b) Distribution of Audited Financial Statements

We are proposing several amendments to the Advisers Act custody rule related to the distribution requirement under the audit provision. First, we propose to extend the current 120-day delivery deadline for annual audited financial statements to 180 days for funds of funds and 260 days for funds of funds of funds.[573] Second, we propose to amend the audit provision to permit an adviser to satisfy the distribution requirement by distributing the audited financial statements to a designated independent representative of an investor. We are also setting forth our view that a failure to distribute audited financial statements before the delivery deadline due to reasonably unforeseeable circumstances generally would not be considered to be a violation of the audit provision, provided that the audited financial statements are promptly delivered upon resolution of the reasonably unforeseeable circumstances.

Currently, annual audited financial statements are required to be delivered to all limited partners, members, or other beneficial owners of a pooled investment vehicle within 120 days of the end of its fiscal year and promptly upon completion of the audit at liquidation.[574] However, auditors performing the audit for a fund of funds may be unable to complete their work until the audited financial statements for the underlying funds are available, which may not be until 120 days or later after the pooled investment vehicle's fiscal year end. Similarly, for a fund of funds of funds, the auditors may be unable to complete their work until the audited financial statements for the underlying funds of funds are available.

To be able to prepare accurate audited financial statements for funds of funds and funds of funds of funds, auditors generally need more than 120 days after fiscal year end. Based on our experience, we believe that a 180-day deadline is appropriate for a fund of funds to allow for adequate time for the underlying audit to be completed and a 260-day deadline is appropriate for a fund of funds of funds to allow for adequate time for the underlying fund and fund of funds audits to be completed.[575] These proposed deadlines are designed to accommodate the timeframe for completion of the underlying audits for both funds of funds and funds of funds of funds, while continuing to ensure that investors in these vehicles receive audited financial statements reflecting their custodied assets in a timely manner.

In addition, we propose to amend the audit provision's delivery requirement to provide that the audited financial statements may be delivered to an independent representative of an investor.[576] The current Advisers Act custody rule allows a client to designate an independent representative to receive, on the client's behalf, the notices and account statements required under the rule.[577] Similarly, we understand that some pooled investment vehicle investors would also prefer to have an independent representative receive the distributed audited financial statements. This proposed amendment is designed to help facilitate investors' review of the audited financial statements by distributing them in accordance with the investor's preference. In connection with this proposed amendment, we are also proposing to modify the Advisers Act custody rule's provision related to independent representatives to add a cross-reference to the audit provision.[578]

We also acknowledge that there may be instances when an adviser reasonably believes that a pooled investment vehicle's audited financial statements will be distributed within the appropriate timeframe but are not distributed within that timeframe due to reasonably unforeseeable circumstances. For example, an adviser might experience unexpected technology issues or a force majeure event that delays the distribution of audited financial statements slightly past the deadline. To accommodate these instances or other similar short duration delays, in the Commission's view, an adviser's failure to distribute audited financial statements within the applicable timelines generally would not be considered a violation of the rule, provided that the adviser reasonably believed that the pooled investment vehicle's audited financial statements would be distributed within 120 days of fiscal year end (or the proposed 180-day or 260-day deadlines from fiscal year end for funds of funds or funds of funds of funds, as applicable) but failed to have them distributed in time due to reasonably unforeseeable circumstances. The adviser would be responsible for ensuring that the pooled investment vehicle's audited financial statements are promptly delivered upon resolution of the reasonably unforeseeable circumstances.[579]

We request comment on all aspects of the proposed rule's requirements for distributing audited financial statements, including the following items:

240. Are funds of funds currently unable to prepare and distribute financial statements within the current rule's 120-day requirement? Would the proposed 180-day or 260-day deadlines be an appropriate deadline for delivery of audited financial statements for funds of funds or funds of funds of funds, respectively? Would a longer or shorter period be more appropriate?

241. Are there any other types of entities or vehicles other than a fund of funds or fund of funds of funds that should be permitted additional time for delivery? If so, what entities or vehicles, why, and what should the applicable deadlines be?

242. Should the Commission amend the audit provision as proposed to permit delivery of the audited financial statements to the independent representative of the investor? Would this proposed amendment increase burdens for advisers?

243. Should the Commission provide any guidance on the circumstances ( printed page 63948) under which failure to timely distribute audited financial statements is reasonably unforeseeable?

244. Should the Commission provide any guidance on the timing that the audited financial statements must be delivered following the resolution of any reasonably unforeseeable circumstances?

(c) Audit and Delivery Requirement for Newly-Formed Pooled Investment Vehicles

The Commission is proposing amendments to the audit provision to modify the annual audited financial statements delivery requirement for pooled investment vehicles that are formed within the last 90 days of their fiscal year.[580] For such vehicles, the requirement to deliver audited financial statements within 120 days of fiscal year end would be deemed to be satisfied if (a) financial statements (which may be unaudited) covering the last 90 days of the first fiscal year are distributed to investors within 90 days of the end of the first fiscal year, and (b) audited financial statements are distributed to investors that cover the first fiscal year ( i.e., the last 90 days of the first fiscal year, if previously unaudited) and the entire second fiscal year after the end of the second fiscal year.

Newly-formed pooled investment vehicles may have limited assets and few investment activities or other transactions during their first fiscal quarter in existence. Based on our experience, the cost of obtaining audited financial statements for a single fiscal quarter may not be significantly less than the cost of obtaining audited financial statements for a full fiscal year, despite covering a much shorter period, in part because of certain fixed administrative costs associated with obtaining and delivering audited financial statements regardless of the period covered. However, there may be efficiencies gained when completing the audit work for both fiscal years at the same time, rather than through separate engagements in the first and second fiscal year.

For pooled investment vehicles formed during the fourth quarter of their fiscal year, the benefits of providing audited financial statements to investors may not justify the costs. Instead of requiring pooled investment vehicles to obtain audited financial statements after 90 days and then again 12 months later, it would be sufficient for these pooled investment vehicles to provide financial statements (which may be unaudited) after 90 days and then, after the end of their second fiscal year, audited financial statements covering the first fiscal year and second fiscal year of the vehicle's existence.[581] Investors would receive relevant information about these pooled investment vehicles from the initial financial statements (which may be unaudited), and would continue to receive audited financial statements annually for the pooled investment vehicles' remaining life. At the same time, these pooled investment vehicles would be able to reduce unnecessary costs (which may otherwise be passed on to investors) during an initial period when assets and activity of the vehicle may be minimal.

We believe 90 days is an appropriate amount of time after the end of the first fiscal year for these pooled investment vehicles to provide financial statements (which may be unaudited) to investors. Preparing unaudited financial statements is both less expensive and less time-intensive than preparing audited financial statements, and investors would benefit from receiving financial statements (which may be unaudited) by the beginning of the pooled investment vehicle's second fiscal quarter. Even though these financial statements would need to be delivered on a shorter time frame than the annual audited financial statements required under the audit provision, we expect the associated burdens to be small and to be justified by the benefits to investors.

We request comment on all aspects of the proposed amendment of the audit provision to provide relief for newly-formed entities, including the following items:

245. As proposed, should the rule permit advisers to satisfy the audit provision for pooled investment vehicles formed during the last 90 days of their fiscal year by distributing financial statements (which may be unaudited) after the first fiscal year and then audited financial statements after the second fiscal year covering the first fiscal year and second fiscal year of such pooled investment vehicles' existence?

246. Should the rule require that the first fiscal year financial statements (which may be unaudited) be reviewed by an independent public accountant? How would this differ with respect to burden and cost from requiring that the first fiscal year financial statements be audited by an independent public accountant?

247. Do commenters agree with our view that the cost of obtaining audited financial statements for a single fiscal quarter would not be significantly less than the cost of obtaining audited financial statements for a full fiscal year?

248. What effect, if any, would the proposed amendment that would defer the existing requirement under the audit provision to obtain audited financial statements for the initial fiscal year to the following fiscal year have on the overall costs and burdens of obtaining annual audited financial statements?

249. Is 90 days the appropriate amount of time to allow such pooled investment vehicles to distribute the financial statements (which may be unaudited)? Is there a different amount of time that would be more appropriate? For example, should the proposed rule require that the financial statements (which may be unaudited) be delivered within 60 days of fiscal year end? Should the financial statements (which may be unaudited) be required to be delivered within 120 days of fiscal year end, consistent with the delivery requirement for audited financial statements under the existing audit provision?

250. Should the proposed amendment be modified to extend the delivery deadline for the initial financial statements (which may be unaudited) for funds of funds or funds of funds of funds? For example, should the proposed rule require that the financial statements (which may be unaudited) for the first fiscal year of a newly-formed fund of funds (formed within the last 90 days of the fiscal year) be delivered within 180 days or 260 days for a newly-formed fund of funds of funds (formed with the last 90 days of the fiscal year), instead of, as proposed, within 90 days of fiscal year end?

251. Should we provide similar relief for pooled investment vehicles that are formed during the last 180 days of their fiscal year? I.e., should we modify the requirement to deliver audited financial statements for pooled investment vehicles that are formed during the last 180 days of their fiscal year to, in lieu of requiring the delivery of audited financial statements within 120 days of fiscal year end, permit them to instead distribute (a) financial statements (which may be unaudited) covering the last 180 days of the first fiscal year within 90 days of the end of the first fiscal year, and (b) audited financial statements that cover the first fiscal year ( printed page 63949) ( i.e., the last 180 days of the first fiscal year, if previously unaudited) and the entire second fiscal year after the end of the second fiscal year?

252. Are there unique risks to investors associated with newly-formed pooled investment vehicles in particular that the proposed amendments would not adequately address? If so, describe the risks and how the rule should be modified to address such risks.

5. Standing Letters of Authorization

We are proposing an exception from the independent verification requirement for client funds and securities if the adviser has custody of those funds and securities solely because of an arrangement between the adviser, the client, and the client's qualified custodian in which the adviser is authorized, in writing, to direct the qualified custodian to transfer funds and securities to a third-party recipient on a specified schedule or from time to time (a “standing letter of authorization” or “SLOA”) subject to certain conditions.[582]

Clients commonly grant their advisers limited powers to disburse funds or securities from their accounts to one or more specifically designated third-party recipients in a manner that limits the adviser's ability to redirect the funds or securities. For example, a client may grant its adviser this authority pursuant to a one-time or standing letter of instruction or other similar asset transfer authorization arrangement that the client establishes with qualified custodians. In granting such authority the client may authorize the adviser to perform transfers or disbursements via automated clearing house ( i.e., ACH) transfers, wires, checks, or other methods. Such authorizations can be for one-time wires out of the account or standing authorization where an adviser is given ongoing authority by the client to execute certain asset movements out of a client's account.

Advisers who receive transfer authority for normal client-directed disbursements may trigger the Advisers Act custody rule even in cases where such transfer authority is client-initiated and subject to restrictions that limit the adviser's ability to generally transfer client funds and securities.[583] However, where the arrangement is structured so that the client authorizes the adviser to act merely as its agent when disbursing the client's funds or securities, the adviser's role in effecting any change in beneficial ownership is circumscribed and ministerial, and there is little risk to clients of loss, misuse, misappropriation, or theft. In such circumstances a qualified custodian would be best positioned to ensure that the required authorizations and instructions are properly and verifiably issued by the client ( e.g., the client's signature is verifiable), provided the custodian is not the adviser or a related person of the adviser to reduce the incentive and opportunity to collude in such an arrangement.[584] In this context, the current rule's independent verification requirement would not be meaningfully additive to protect a client's funds or securities.[585]

Accordingly, we are proposing an exception from the independent verification requirement for SLOAs subject to certain conditions found in the proposed definition of SLOA. The SLOA is defined as an arrangement among the adviser, the client, and the client's qualified custodian in which the adviser is authorized, in writing, to direct the qualified custodian to transfer funds and securities to a third-party recipient on a specified schedule or from time to time and is subject to certain conditions.[586] In 2017, the staff took a similar position to the proposed rule change in a staff no-action letter that set forth considerations focused on client control, custodial safeguards, and the transparency of transactions made pursuant to such terms. As a first condition, the client's qualified custodian cannot be the adviser or the adviser's related person.[587] Second, the SLOA must include the client's signature, the third-party recipient's name, and either the third party recipient's address or account number at a custodian to which the transfer should be directed.[588] Third, the standing letter of authorization must provide that the investment adviser has no ability or authority to designate or change any information about the third party recipient, including name, address, and account number.[589] The client, as the party establishing the standing letter of authorization, would have the ultimate ability to terminate or change the instruction with the qualified custodian. Collectively, these conditions decrease misappropriation risk and decrease the utility of a surprise examination because they impose safeguards that curtail an adviser's role in effecting any change in beneficial ownership while ensuring a qualified custodian plays a role in verifying the instruction and authorization and conducting a signature review.

The required signature on the authorization would ensure that the instructions and authorizations are verifiably from the client. We believe qualified custodians generally are required by their primary functional regulator or otherwise to perform procedures to verify the instruction and authorization, through a signature review and, if determined to be necessary, based on the facts and circumstances, another method of verification.[590] The required information identifying the recipient's name and address or account number could help ensure that the instructions to the qualified custodian provide relevant information about the recipient. The written instructions for the standing letter of authorization could include a specified schedule for transfers, or they could include a more general instruction for the adviser to direct transfers to the recipient under certain conditions.

We request comment on all aspects of the proposed rule's standing letter of authorization exception, including the following items:

253. Do commenters agree that an adviser should be exempt from the independent verification requirements if it has custody solely because of a standing letter of authorization where the client grants its adviser the limited power for disbursements to third parties specifically designated by the client and the adviser complies with the ( printed page 63950) conditions of the proposed exception? Are there other protections we should require? If so, what protections?

254. Should this exception be available when the client's funds or securities are not maintained with a qualified custodian? Does a qualified custodian better protect client funds or securities subject to limited powers of attorney (such as by performing signature verification procedures under anti-money laundering and know-your-customer requirements that require the financial institution to verify signatures)?

255. Should this exception be unavailable when the client's funds or securities are at a related qualified custodian, as proposed? If not, what specific conditions would safeguard client funds or securities from the risks of loss, theft, misuse, or misappropriation in these circumstances?

256. Should the instructions and authorization for a standing letter of authorization include the name and either the address or the account number of the recipient to whom a transfer of funds or securities should be directed? Should the instructions and authorization include different, or additional, information, and if so, what? Should the rule specifically require the SLOA to be provided to the adviser on the same form the client delivers to its qualified custodian, or that it be provided separately, but it must be delivered to both parties?

257. Are qualified custodians required to verify SLOA or other limited power of attorney instructions under their governing regulations, such as a signature review or other method? If not, should we require the adviser to confirm or contract with the qualified custodian so that it takes these steps?

6. Treatment of Business Development Companies

We are proposing changes to the Advisers Act custody rule to extend the rule's exception for the accounts of a registered investment company to BDCs.[591] Relatedly, we propose to define the term “business development company” in the rule to mean an entity that has elected to be regulated or is regulated as a business development company pursuant to section 54 of the Investment Company Act and has not withdrawn the election.[592] We understand currently that market participants are already treating BDCs as registered closed-end investment companies for purposes of the Advisers Act custody rule. These changes would help filers understand that the rule's exception would apply to BDC accounts because they elect to be regulated as investment companies and would therefore be subject to the Investment Company Act's custody rules.[593]

This proposed amendment would ensure that such advisers and entities are not subject to duplicative or conflicting custody regulations. We are also proposing certain corresponding changes to Form ADV Item 9 to instruct advisers that the item excludes clients that are investment companies registered pursuant to the Investment Company Act of 1940 or BDCs that have elected to be regulated or are regulated as BDCs pursuant to section 54 of the Investment Company Act when reporting under Items 9A.-9.E.[594]

We request comment on the proposed amendment to extend the rule's exception for the accounts of a registered investment company to also cover certain BDCs:

258. Should we propose changes to the rule to indicate that the rule's exception for registered investment companies also extends to BDCs that have elected to be regulated or are regulated as business development companies under the Investment Company Act and have not withdrawn their elections? Would this help filers understand that the rule would not apply to BDCs because they elect to be regulated as investment companies and would therefore be subject to the Investment Company Act's custody rules?

7. Account Number in Notice to Clients

We are proposing amendments to the Advisers Act custody rule to require that a client's account number must be included in the notice sent by an adviser upon opening an account with a qualified custodian on behalf of such client.[595] Under the current rule, an adviser is required to notify a client in writing of the qualified custodian's name, address, and a description of the manner in which the funds or securities are maintained, upon opening an account with a qualified custodian on the client's behalf and following any changes to this information.[596] This notice provision is designed to alert investors to where their funds or securities are held so that they may monitor their accounts at the qualified custodian that will provide account statements and it provides clients with a tool for reference in any communications with the qualified custodian. However, advisers are not currently required to include the client's account number in this notice. By requiring the identification of the account number, the proposed amendment would enhance the specificity of custodial account information made available to clients as set forth in the proposed rule, thereby allowing them to more effectively oversee their accounts for theft, misuse, or misappropriation.

We request comment on the proposed amendment to require account numbers in the notice to clients:

259. Should we propose amendments requiring that the notice sent by an adviser upon opening an account with a qualified custodian on behalf of a client include the client's account number? What are the relative costs and benefits of including the account number in the notice? Do advisers already provide the account number in notices they currently send?

260. Should we require other types of information to be included in the notice? If so, what information, and why? Should we eliminate any of the required information from the notice?

261. Should we require advisers to provide notice to clients on account opening when funds and securities are not held at a qualified custodian? If yes, what form should these notices take? Should they be provided on a one-off or periodic basis?

8. Notice to the Commission of Material Discrepancies

We are proposing to amend the Advisers Act custody rule language related to the notice an accountant must provide upon the finding of any material discrepancies during the course of an independent verification to state that the accountant must send the notice by electronic means to the Division of Examinations.[597] This modified language replaces the current rule's ( printed page 63951) requirement to send such notice by means of a facsimile transmission or electronic mail, followed by first class mail to the Director of the Office of Compliance Inspections and Examinations.[598] This proposed amendment is designed to modernize this requirement by: (i) replacing the references to facsimile transmission and first class mail with a reference to electronic means and (ii) update the outdated reference to the Office of Compliance Inspections and Examinations.

We request comment on the notice to the Commission of material discrepancies:

262. Are these proposed changes related to the notice an accountant must provide upon the finding of any material discrepancies during the course of an independent verification appropriate? Why or why not? Should we make any other changes to this requirement?

263. Is the expected revision to the definition of a material discrepancy in updates to the 2009 Guidance for Accountants discussed below clear or should it be revised further? If so, how? Under the expected revision to the definition, is there a risk that an accountant would not report non-compliance that could lead to theft, loss, misuse, or misappropriation? Why or why not?

9. Inadvertent Custody

The Commission is proposing an exception from the Advisers Act custody rule with respect to funds and securities over which an adviser has custody arising solely from custodial agreements that the adviser has no knowledge or reason to know confers custody upon it provided that the adviser did not recommend the qualified custodian.[599] The Commission is also proposing to require that an adviser who gains knowledge of such custody promptly notify the client and qualified custodian in writing of such unwanted authority and repudiate such authority to the client and qualified custodian and request that such authority be removed from the custodial agreement or be superseded by a new agreement.

In certain circumstances, an adviser may inadvertently receive the authority to obtain possession of client funds or securities or withdraw them upon instruction to the custodian and thereby have custody under the Advisers Act custody rule. These circumstances can occur, for example, when a custodial agreement between a client and custodian grants an adviser broader access to client funds or securities than is contemplated by the adviser's own agreement with the client, and the adviser does not intend to have such access to client funds or securities.[600] Inadvertent custody often arises because a custodial agreement grants an adviser expansive authority to transact in or transfer funds and securities held in its client custodial accounts ( e.g., the ability to initiate wire transfers) that are often superfluous to the advisory services being provided.

Nonetheless, inadvertent custody can put client funds and securities at risk. When a client's agreement with its qualified custodian grants an adviser broad authority to possess or withdraw a client's funds and securities, without the implementation of further controls or actions, the adviser has the ability to effect a change in beneficial ownership of the funds and securities. In these circumstances, from the qualified custodian's perspective, the client has authorized the adviser to withdraw the client's funds and securities, and—though there may be constraints contained in the advisory agreement between the adviser and a client—the custodian may not be aware of these constraints or may be unwilling or unable to treat the terms of the advisory agreement as controlling. In this scenario, believing the adviser to have authority over the client's funds and securities, the custodian could accept the adviser's instructions to direct their disposition. This possibility puts client funds and securities at risk, because, for instance, a rogue advisory employee may misuse the authority to misappropriate a client's funds and securities held at the custodian.

However, advisers are rarely a party to these agreements between clients and their custodians and thus have a limited ability to discover or, if discovered, repudiate this unwanted authority. We understand that, where discovered, advisers have had little success in modifying or eliminating this unwanted authority either because a custodian will not accept an adviser's request to modify the custodian's agreement with its client, or because the client may lack the bargaining power to negotiate for modifications to the custodian's standard forms.

Although inadvertent custody can create an opportunity for adviser misappropriation, misuse or loss of client funds or securities, the relative risk to client funds or securities can be substantially mitigated if the adviser meets certain conditions and takes certain steps upon the discovery of inadvertent custody. Accordingly, we are proposing to except from compliance with the Advisers Act custody rule advisers with custody of client funds and securities pursuant to a custodial agreement under which:

(1) the adviser did not recommend, request, or require that the client select the qualified custodian maintaining such funds and securities; and

(2) either (A) the adviser does not have a copy of the client's custodial agreement, nor actual knowledge or reason to know that any custodial agreement between the client and such qualified custodian confers custody upon the adviser; or (B) if the adviser knows or has reason to know that a custodial agreement confers custody on the adviser, such adviser promptly notifies the client and qualified custodian in writing of such unwanted authority and repudiates such authority to the client and qualified custodian and requests in writing that such authority be removed from the custodial agreement or be superseded by a new agreement, consented to by both the client and the qualified custodian, that does not confer custody on the adviser.[601]

The first condition identified above is designed to ensure that the adviser did not have a hand in selecting the custodian as this could indicate that custody may not be truly inadvertent. An adviser that chooses a custodian for its client may have the ability to review custodial terms and ascertain whether such terms exceed the authorities necessary to execute the client's investment strategy. The second condition is bifurcated between two possibilities. The first possibility occurs when the adviser does not have a copy of the agreement, nor actual knowledge or reason to know that a custodial agreement between the client and the qualified custodian confers custody on the adviser. This possibility within the condition reflects the lower risk that an adviser without knowledge of its inadvertent custody would exercise such authority while also acknowledging the difficulty to advisers of ensuring that all of an adviser's client's agreements do not provide it with inadvertent custody. The second possibility, however, provides that if the adviser discovers that a custodial agreement gives it custody, it must take steps to repudiate and disavow such ( printed page 63952) authority by requesting in writing that such authority be removed from the agreement or the superseding of it with a new agreement. This discovery provision is intended to address the relative risks to client assets posed by inadvertent custody by requiring an adviser to take appropriate steps to mitigate the agreement that gives it custody. Although the client and custodians involved may not implement or consent to such remediation requests in all cases, these steps represent practical actions that the adviser can take to attempt to mitigate inadvertent custody risks when discovered and put the client and custodian on notice of such risks.

We are not requiring advisers to review every custodial contract their clients may have entered into to comply with this exception. However, advisers that are seeking to rely on this exception should have reasonably designed policies and procedures in place under the Advisers Act compliance rule to address circumstances where they become aware they have custody inadvertently from a custodial agreement.[602] Advisers that would like to rely on this proposed exception should also have policies and procedures as part of their compliance programs that review whether client custodial agreements to which they have access or knowledge of grant them unwanted authority, provide for the disavowing of unwanted authority, and provide for requesting amendments to agreements as applicable. As different controls may be appropriate for different advisers in designing effective compliance programs, we are not suggesting a single set of policies and procedures with regard to the inadvertent custody exception.

The Commission requests comment on our proposed exception regarding inadvertent custody under the Advisers Act custody rule.

264. Should we provide the proposed exception for inadvertent custody? Does the Commission's exception and its underlying conditions provide the safeguards necessary to counter the potential risk of inadvertent custody? Should we require that advisers take reasonable steps to notify the client and qualified custodian in writing of such unwanted authority and either request that such authority be removed from the custodial agreement or be superseded by a new document? Instead of providing an exception to the Advisers Act custody rule, should we provide an exception from the definition of custody for inadvertent custody? Instead of amending the rule, should we provide guidance on steps to mitigate unwanted custody conferred by custodial agreements?

265. Should we include as a condition that the adviser did not recommend, request, or require that the client select the qualified custodian maintaining the client's funds and securities? Why or why not? Should we instead allow an adviser to recommend a custodian provided the adviser does not know or have reason to know that a custodial agreement confers custody on the adviser? Are there circumstances in which this condition may prevent an adviser from recommending the best available custodian for their client?

266. Should we require that advisers have reasonably designed policies and procedures in place to address inadvertent custody and prevent the adviser or its supervised persons from acting on inadvertent authority? What policies, procedures, or actions have helped advisers address issues of inadvertent custody?

267. Are there any potential compliance complications with how this exception may interact with exceptions related to a separate basis of custody including exceptions for fee deduction, discretionary trading authority, and SLOAs?

268. Is it difficult for advisers that may have inadvertent custody, pursuant to a client's custodial agreement with a qualified custodian, to reduce or eliminate their authority over the client's custodial account? Would the proposed exception make it easier for advisers to reduce or repudiate this authority? Do qualified custodians often reject an adviser's request to modify its agreement with its client to reduce or eliminate the adviser's authority once discovered?

10. Segregation

(a) Segregation From Adviser and Qualified Custodian Proprietary Assets

We expect to provide our views with respect to how the Advisers Act custody rule's asset segregation requirement applies to both the segregation of client funds and securities from the proprietary assets of the adviser (and its related persons), as well as from those of the qualified custodian. Additionally, we expect to provide our view that the Advisers Act custody rule does not preclude qualified custodian banks from maintaining funds such that cash balances are held as general deposits and reflected on the custody bank's balance sheet as a liability to the client and, accordingly, are not segregated from the bank's own cash.

Asset segregation has been one of the foundational principles of the Advisers Act custody rule since its inception and is important for investor protection because it guards client funds and securities from loss, misuse, theft, and misappropriation as well as financial reverses, including insolvency.[603] The original Advisers Act custody rule, adopted in 1962, established the obligation to segregate client funds and securities from the assets of the adviser. That rule required that advisers that have custody of: (i) client funds, to hold those client funds in bank accounts containing only client funds and (ii) client securities, to segregate those client securities and hold them in a reasonably safe place.[604] In 2003, the Advisers Act custody rule was amended to require, for advisers with custody of client funds and securities, that a qualified custodian maintain those client funds and securities in a separate account for each client under that client's name or in accounts that contain only clients' funds and securities under the adviser's name as agent or trustee for its clients.[605] Along with banks, broker-dealers, and futures commission merchants, the 2003 amendments included foreign financial institutions (“FFIs”) as qualified custodians, provided that the FFI keeps the advisory clients' assets in customer accounts segregated from its proprietary assets.

We are aware that some advisers have experienced challenges applying the asset segregation requirement in certain contexts today. Although the Advisers Act custody rule generally requires that, for advisers with custody of client funds and securities, a qualified custodian maintains those funds and securities in a separate account for the client or in a separate account for the benefit of the client, it does not explicitly state that the funds and securities must be segregated from proprietary assets of the adviser or a qualified custodian. However, the application of the current rule has the effect of requiring that such client funds and securities be segregated from the proprietary assets of the adviser and qualified custodian.[606] Current rule 206(4)-2(a)(1) and proposed rule 223-1(a)(1) state that a ( printed page 63953) qualified custodian must maintain client funds and securities “[i]n a separate account for each client under that client's name” or “[i]n accounts that contain only [the adviser's] clients' funds and securities, under [the adviser's] name as agent or trustee for the clients.” Under the first option, the client's funds and securities must be separated from the funds and securities of all other persons, including the adviser and qualified custodian itself. Similarly, under the second option, the accounts may not contain any non-client funds and securities, including the adviser's and qualified custodian's accounts.

Requiring that a client's funds and securities be separated from the funds and securities of all other persons, including the adviser and qualified custodian itself, is consistent with existing custodial practices, as well as applicable laws and regulations covering certain categories of qualified custodians. For example, under applicable banking law, national banks and Federal savings associations are required to segregate all assets held in a fiduciary capacity from their general assets.[607] Similarly, under applicable rules, broker-dealers and futures commission merchants are generally required to segregate customer assets from their own assets.[608] We continue to believe that asset segregation is a fundamental protection of the Advisers Act custody rule and that segregation from the proprietary assets of the adviser (and its related persons), as well as the qualified custodian, remains important for investor protection.

We are also aware of some challenges regarding the application of the asset segregation requirement to cash depository accounts. In particular, some industry members have questioned whether the asset segregation requirement for client funds should be read to preclude cash balances at a custody bank from being held as general deposits and reflected on the custody bank's balance sheet as a liability to the client, and accordingly are not segregated from the bank's own cash. The Commission expects to provide its view that client bank deposits do not violate the Advisers Act custody rule's requirement that funds and securities be maintained in separate accounts or accounts that contain only clients' funds and securities because, once cash is deposited into a deposit account at a bank, the client has a separate liability of the bank to the client, recorded in that client's name in that client's bank account.[609]

(b) Treatment of Certain Escrow Accounts

The Commission also expects to provide our views on the use of certain escrow accounts in connection with the sale of portfolio companies owned by one or more pooled investment vehicle clients (each, a “Seller Escrow Account”). More specifically, we expect to provide our view that an adviser may maintain client funds in a Seller Escrow Account commingled with other client and non-client funds if certain conditions are met.

When one or more pooled investment vehicle clients (typically private equity funds) and other non-clients sell a jointly-owned portfolio company, they typically hold a portion of sale proceeds in a Seller Escrow Account following the closing of the sale or merger. The purpose of this escrow account is to hold a percentage of sale proceeds in the event of indemnification or an adjustment to the sale price of a portfolio company as included in the terms of the purchase or merger agreement between the sellers and buyer. A Seller Escrow Account typically exists for a limited period of time, and the funds remaining after such time are distributed on a predetermined formula to the sellers, including to the adviser's pooled investment vehicle client(s). The sellers also typically appoint a “sellers' representative” to act on their behalf with respect to the Seller Escrow Account; and the Commission understands that this sellers' representative is often the investment adviser or an affiliate and the escrow is typically held in the name of the sellers' representative. When a pooled investment vehicle client sells a portfolio company together with non-clients, a Seller Escrow Account would generally necessitate commingling the pooled investment vehicle client's funds—in the form of sale proceeds—with the funds of sellers who are third parties.

Advisers have stated that the protections of Seller Escrow Accounts for pooled investment vehicle clients are similar in material respects to separate segregated escrows with only client funds. For example, we understand that the portion of the Seller Escrow Account attributable to a pooled investment vehicle client is typically included in such client's financial statements and within the scope of its audit. Seller Escrow Accounts also typically have a limited duration, exist for a narrow purpose, and hold only a small percentage of sale proceeds. We also understand that there would be a significant cost to establish and maintain several separate escrow accounts in the names of various pooled investment vehicle clients and unrelated investors to fully comply with the Advisers Act custody rule segregation requirements, and that such cost would likely be borne, at least partially, by pooled investment vehicle investors.[610]

The Commission expects to provide its view that an adviser may maintain client funds in a Seller Escrow Account commingled with other client and non-client assets if: (1) the client is a pooled investment vehicle for which the adviser relies on the audit provision and the portion of the Seller Escrow Account attributable to the pooled investment vehicle is included in its financial statements; (2) the Seller Escrow Account is in connection with the sale or merger of a portfolio company owned by the client ( i.e., for indemnification or to adjust the purchase price); (3) the Seller Escrow Account contains an amount of money that is agreed upon as part of a bona fide negotiation between the buyer and the sellers; (4) the Seller Escrow Account exists for a period of time that is agreed upon as part of a bona fide negotiation between the buyer and the sellers; (5) the Seller Escrow Account is maintained at a qualified custodian; and (6) the sellers' representative is contractually obligated to promptly distribute the funds remaining in the Seller Escrow Account at the end of the escrow period on a predetermined formula to the sellers, including the pooled investment vehicle client.[611]

11. Accommodation Reporting Guidance

The Commission expects to provide its view on the disclosure that should accompany a client account statement that covers funds or securities on an accommodation basis. More specifically, we expect to share our view that any adviser who requests accommodation reporting on a client account statement ( printed page 63954) should generally ensure that such statement clearly discloses that the custodian does not hold or have authority to obtain such funds or securities, among other disclosures.

Custodians engage in accommodation reporting when they list funds or securities on a client's account statement but do not accept custodial liability for them ( i.e., on an “accommodation basis”). In such cases, the custodian does not attest to the holdings of or transactions in those funds or securities or take steps to ensure that the funds or securities are safeguarded appropriately; instead, the custodian only identifies the holdings or transactions as reported to it by the adviser. Advisers may request that qualified custodians include particular holdings and transactions on a custodial account statement on an “accommodation basis” for a variety of reasons, including to facilitate a client's monitoring of such funds or securities, or if custodians are unwilling or unable to take custody of certain kinds of private investments. In some instances, an adviser may request that a qualified custodian include particular funds or securities on a custodial account statement on an “accommodation basis” in an attempt to demonstrate that the funds and securities are “held” with a qualified custodian in compliance with the custody rule.

The Advisers Act custody rule requires advisers to have a reasonable basis, after due inquiry, for believing that a qualified custodian sends an account statement, at least quarterly, to each of its clients for which an adviser maintains funds or securities, identifying the amount of funds and of each security in the account at the end of the period and setting forth all transactions in the account during that period.[612] The account statement provision is a key prophylactic protection of the rule because it helps ensure that qualified custodians are preparing and sending account statements to facilitate client monitoring of their accounts for potential misappropriation or misuse, including through comparison of custodial account statements to account statements provided by an adviser.[613]

The Commission expects to provide its view that an adviser could not have a “reasonable basis, after due inquiry, for believing” that a qualified custodian sends the required account statements under rule 206(4)-2(a)(3) or proposed rule 223-1(a)(3) if it sends a misleading account statement that undermines the protections this provision is intended to provide. To satisfy the account statement delivery requirement under the Advisers Act custody rule, an adviser should have a reasonable basis, after due inquiry, for believing that the account statement is generally clear and accurate. Accordingly, an adviser who requests that funds or securities be included on a client account statement on an accommodation basis should also have a reasonable basis, after due inquiry, for believing that such account statement clearly discloses that the custodian does not hold or have authority to obtain any funds or securities included on an accommodation basis.[614] Clear disclosure that the qualified custodian does not maintain any funds or securities included in an account statement on an accommodation basis will alert clients that such funds or securities are not subject to safeguarding by that entity. Such disclosure also conveys to the client that information contained in the account statement regarding those funds or securities is not the responsibility of the qualified custodian and therefore the client should treat such information with appropriate caution under the circumstances.

In most cases, such disclosure of accommodation reporting should be done in the form of a disclaimer included in the account statement. To prevent misleading statements, such a disclaimer should generally indicate that such funds or securities are included on the statement at the request of the adviser; disclose that information (including valuation) for such externally held funds or securities included on the statement is derived from the adviser or other external source for which the custodian is not responsible; and identify that such externally held funds or securities may not be subject to certain protections typically available at such qualified custodians. In the example above, clearly disclosing that the qualified custodian does not maintain these funds or securities would alert clients that such funds or securities are not subject to safeguarding by that entity. Additionally, it would indicate that for such securities the custodian may only be providing figures on the account statements that the adviser or a third-party provided to it and the qualified custodian does not independently verify or stand behind them. Advisers should consider whether such disclaimer should generally disclose that funds and securities may not be subject to certain protections typical of other custody arrangements ( e.g., FDIC protections for banks or SIPC protections for broker-dealers) to outline to clients the relative risks to funds and securities that appear on the statement on an accommodation basis versus those held and safeguarded by the custodian. Such disclosures would remind clients that certain assets may not be subject to the same level of protections that may traditionally be expected to coincide with such qualified custodian entities and their respective regulatory regimes.

H. Recordkeeping Requirements

1. Adviser Recordkeeping

We are proposing several amendments to the Advisers Act recordkeeping rule, which requires registered investment advisers (and advisers required to be registered) to make and keep true, accurate, and current certain books and records.[615] First, we are proposing new recordkeeping requirements that would require advisers that have self-custody of client crypto assets to make and keep certain records related to the proposed self-custody rules discussed above.[616] Second, we are proposing new recordkeeping requirements for advisers with custody of client crypto assets that are maintained at a State trust company under the proposed State trust company rules discussed above.[617] Third, in connection with the proposed amendments to the Advisers Act custody rule related to the exception to the surprise examination requirement due to an adviser having custody solely as a result of a SLOA, as discussed further above in section II.G.5, we are proposing to add an associated recordkeeping requirement for advisers that rely on the proposed SLOA ( printed page 63955) exception to maintain and preserve any SLOAs and related records in connection with the adviser's reliance on the exception.[618]

All of these proposed new records would be required to be maintained and preserved in the same manner, and for the same period, as other books and records required to be maintained under the Advisers Act recordkeeping rule. That is, the adviser would generally be required to maintain and preserve these records in an easily accessible place for five years from the end of the fiscal year during which the last entry was made on such record, the first two years of which must be in an appropriate office of the adviser.[619] In addition, we are proposing conforming amendments to the Advisers Act recordkeeping rule to update references to rule 206(4)-2 to reflect the proposed redesignation of the Advisers Act custody rule to rule 223-1.[620]

We are also proposing to amend the existing provision that states that records made and kept for any required record for one requirement under paragraph (a) of the Advisers Act recordkeeping rule that contains all of the information required under any other provision of paragraph (a) need not be made in duplicate for purposes of the rule. We propose to amend this provision to also apply to any record required to be maintained under paragraph (b) of the rule, which applies to the records required to be maintained if the adviser has custody or possession of client securities or funds.[621] This proposed amendment is designed to facilitate the proposed amendments to add additional recordkeeping requirements related to crypto asset custody, as discussed above, to avoid imposing any potential duplicate recordkeeping obligations with respect to records required under the existing Advisers Act recordkeeping rule related to an adviser's custody or possession of client securities or funds, and to minimize burdens associated with duplicate requirements. Finally, we are proposing amendments to the Advisers Act recordkeeping rule to provide that records related to crypto assets that are required to be maintained and preserved under the rule may be maintained and preserved on a crypto network, provided that the adviser provides, promptly upon request by the Commission, such records to the Commission (including its examiners and other representatives) in a human-readable and reasonably usable electronic format.[622]

(a) Records Related to the Proposed Adviser Self-Custody Rule

We propose to amend the Advisers Act recordkeeping rule to add new recordkeeping requirements related to the proposed adviser self-custody of crypto assets. The proposed crypto asset self-custody recordkeeping requirements are designed to help ensure compliance with the proposed adviser self-custody rule and to support Commission staff's examination and inspection functions related to the proposed adviser self-custody rule. These proposed requirements would also benefit investors by giving Commission staff records to examine that could show potential theft, loss, misuse, or misappropriation of client crypto assets, thereby reducing the risk of harm to investors. The proposed recordkeeping requirements could also deter against adviser misconduct and result in better safeguarding practices by advisers by helping to identify potential areas of weakness or vulnerability in their self-custody practices, which would help support the investor protections of the proposed adviser self-custody rule requirements.

First, an adviser would be required to maintain a memorandum describing the basis for its required QC determination related to self-custody of client crypto assets.[623] Second, an adviser would be required to maintain a memorandum describing the basis upon which it has made the determination as to its safeguarding expertise for crypto assets as required under the proposed adviser self-custody rule.[624] Third, an adviser would be required to maintain records identifying the persons that have been designated persons with access to the crypto asset private key material pursuant to the proposed adviser self-custody rule.[625] Fourth, an adviser would be required to maintain a copy of any written assessment of cybersecurity risks as required under the proposed adviser self-custody rule.[626] Fifth, an adviser would be required to maintain a copy of the internal control reports required to be obtained pursuant to the proposed adviser self-custody rule.[627] Sixth, an adviser would be required to maintain records documenting its required annual review of its safeguarding systems and cybersecurity controls implemented in connection with self-custody.[628] Seventh, an adviser would be required to maintain copies of the account statements provided to clients and records of any transmissions and notices sent to clients as required under the proposed adviser self-custody rule.[629] Eighth, the adviser would be required to maintain a copy of any financial asset elections made pursuant to the proposed adviser self-custody rule.[630] Ninth, for each client for whom the adviser self-custodies crypto assets under the proposed adviser self-custody rule, an adviser would be required to maintain records that include such information as may be reasonably necessary to reconstruct all financial positions and transactions related to the client crypto assets that the adviser maintains including, at a minimum, client names, client account numbers, crypto asset addresses, transaction amounts, transaction destinations, transaction authorizations, and relevant metadata.[631] Finally, the adviser would continue to be required to maintain the records that are otherwise prescribed under the Advisers Act recordkeeping rule for an adviser ( printed page 63956) that has custody or possession of securities or funds of any clients, and this provision would apply to any records that the adviser makes and keeps pursuant to the proposed adviser self-custody rule, including with respect to regulated fund clients, provided that references to securities would also include any crypto assets of a regulated fund that the adviser self-custodies.[632]

The proposed recordkeeping requirements are designed to help support the proposed adviser self-custody rule by allowing Commission staff to examine such records and be able to determine whether the adviser has complied with the required safeguards. This would enhance investor protection by improving the Commission's ability to assess compliance with the proposed protective conditions. These proposed recordkeeping requirements would also help facilitate the adviser's identification of any potential weaknesses in its safeguarding practices (and remedy any issues, if needed), which would help reduce risks of harm to the applicable clients. The proposed recordkeeping requirement for the adviser's QC determination would allow our staff to understand the basis of the adviser's QC determination. Similarly, the proposed recordkeeping requirement for the adviser's determination as to whether it has the requisite safeguarding expertise to self-custody client crypto assets would allow our staff to assess whether the adviser has evaluated its safeguarding expertise for crypto assets and appropriately determined that it meets the adviser self-custody rule's expertise requirement. The proposed requirement to maintain records of the written assessment of cybersecurity risks would help facilitate the adviser's identification of any cybersecurity risks related to the adviser's self-custody of crypto assets and, if applicable, address such risks, which would help reduce risks of harm to clients. The proposed requirement would also help facilitate our staff's understanding of any cybersecurity risks related to the adviser's self-custody of crypto assets, which would help facilitate the staff's examination of the adviser's safeguarding practices related to cybersecurity (which supports investor protection efforts). The proposed requirement to maintain records related to the designated persons with access to the private key material would help ensure that the adviser is appropriately documenting who has access to clients' private key material and allow our staff to assess whether the adviser is appropriately managing access to the private key material. Maintaining copies of internal control reports would give our staff access to the findings of the independent public accountant(s) that assess the effectiveness of the adviser's safeguarding practices and perform procedures to verify the crypto assets maintained in the adviser's self-custody are reconciled to the crypto network. It would also allow Commission staff to understand any potential weaknesses in the adviser's safeguarding controls that the accountant may identify in the internal control report. Similarly, the proposed requirement to maintain records of the adviser's annual review of its safeguarding system and cybersecurity controls would allow the Commission's examination staff to identify potential weaknesses in an adviser's safeguarding system and cybersecurity controls and whether the adviser's systems and controls have addressed the core minimum elements under the proposed adviser self-custody rule. The proposed requirement to maintain copies of the account statements, transmissions and any required notices to clients would allow the Commission to confirm that the account statements were sent to the clients and help serve as a record of the crypto asset address information and related activities that were disclosed to clients. Quarterly account statements would also provide transparency and verifiability of records, facilitating easier comparison between records from advisers and data from independent sources, such as onchain records. Finally, the proposed requirement to maintain records of any financial asset election made pursuant to the proposed adviser self-custody rule would help the Commission staff understand how the crypto assets that the adviser self-custodies are attributed to a particular client, which would help facilitate an examination of the adviser and support investor protection efforts.

The proposed requirement to maintain records of positions and transaction activities for each client for which the adviser self-custodies crypto assets is designed to provide our examination staff with transparency into the activities and movement of client crypto assets that the adviser has in self-custody and can provide important information about the operation and effectiveness of the adviser's safeguarding controls. Commission staff can also use these records to compare against the account statements and other transmissions that are required to be provided to clients to be able to reconcile the wallet activities against the account information disclosed to clients.

The proposed requirement to maintain records of the information reasonably necessary to reconstruct all financial positions and transactions related to client crypto assets is designed to allow the Commission staff to be able to track the movement of client crypto assets and reconcile transactions, which would help provide insight into how the crypto assets are being safeguarded. This requirement would also help to ensure the adviser is aware of the movements and location of client crypto assets and provide transparency to the client of any activities related to its crypto assets. The adviser would be required to maintain, at a minimum, the client name, client account number, crypto asset address, transaction amount, transaction destination, transaction authorization, and relevant metadata to allow the Commission staff to be able to recreate any movements of the crypto asset. In addition to the information that the records of operations and transaction activities would be required to specifically include under the proposed amendments, the adviser should also consider whether any additional information may need to be included in the related records to adequately reconstruct all financial positions and transactions. Such additional information may include information about the wallet configuration and wallet access rights and may need to be supplemented by offchain records. This provides advisers with the flexibility to determine what additional information may be necessary to fully reconstruct transactions of client crypto assets that move crypto assets in or out of the wallet. Additional information may need to be retained to be able to adequately reconstruct DeFi activities, such as information related to the DeFi protocol and its operations. For example, if the client's crypto assets are staked, the adviser should maintain records of relevant information, including the crypto asset staking contract address, as well as information regarding the crypto asset's designation as being staked during the applicable staking period. Without these types of records, our staff would have limited visibility into the adviser's compliance with the adviser self-custody rule and its own safeguarding practices. Finally, consistent with the scope of the proposed adviser self-custody rule, which would apply to regulated funds and crypto asset securities and similar ( printed page 63957) investments in their accounts, the proposed rule would specify that advisers' other custodial records that are required to be maintained pursuant to the current Advisers Act recordkeeping rule would include any applicable records pertaining to crypto assets held in the adviser's self-custody on behalf of regulated funds.[633] The proposed amendment is designed to align the scope of the Advisers Act recordkeeping rule with the proposed adviser self-custody rule and to help ensure that advisers retain the required custodial records for crypto assets of regulated funds that the adviser self-custodies. True and accurate custodial records related to crypto assets that the adviser self-custodies can help reduce the risk of theft, loss, misappropriation, or misuse of client assets by the adviser. These custodial records would also facilitate effective regulatory oversight by allowing our staff to request from advisers the information necessary to identify potential fraud that could impact investors in regulated funds. We request comment on all aspects of the proposed amendments to the Advisers Act recordkeeping rule related to the proposed Advisers Act custody rule amendments to permit adviser self-custody of crypto assets, including the following items:

269. Should the Commission amend the Advisers Act recordkeeping rule as proposed? Are there any other records that an adviser should be required to maintain related to the proposed rulemaking relating to adviser self-custody of crypto assets? If so, what records and why?

270. The proposed recordkeeping rule amendments related to adviser self-custody of crypto assets would require the adviser to maintain a memorandum describing the basis for its required QC determination related to self-custody of client crypto assets. Is the proposed requirement clear as to the records advisers would be required to maintain? Should we specify certain elements that must be included in the written record of the QC determination? If so, what should those elements be?

271. The proposed amendments would require advisers to maintain custodial records relating to crypto assets the adviser has in self-custody for regulated funds. Should advisers be required to maintain these records? Why or why not?

272. Should the Advisers Act recordkeeping rule be amended, as proposed, to require an adviser that has self-custody of crypto assets to maintain records that include such information as may be reasonably necessary to reconstruct all financial positions and transactions related to client crypto assets that the adviser maintains, including, at minimum, client name, client account number, crypto asset address, transaction amount, transaction destination, transaction authorization, and relevant metadata? Should any of this information not be required to be maintained? Why or why not? Should any additional information be required to be maintained in such a record? If so, what information and why?

(b) Records Related to the Proposed State Trust Company Rule

To complement the proposed amendments to add State trust companies as a category of qualified custodian under the Advisers Act custody rule, we propose several related amendments to the Advisers Act recordkeeping rule.[634] An adviser that maintains client crypto assets with a State trust company as a qualified custodian would be required to make and keep the following records related to the proposed State trust company rule: (1) a memorandum describing the basis upon which the adviser made its required initial and annual determinations with respect to the State trust company as a qualified custodian, (2) records of the State trust company's audited financial statements obtained or received as required under the proposed State trust company rule, and (3) a copy of the State trust company's internal control reports obtained or received pursuant to the proposed State trust company rule.[635]

These proposed amendments to the Advisers Act recordkeeping rule would help facilitate the Commission's examination and enforcement functions, including determination of the adviser's compliance with the proposed State trust company qualified custodian requirements. These proposed amendments would also enhance investor protection by improving the Commission's ability to assess compliance with the proposed protective conditions. The proposed recordkeeping requirements would also help facilitate the adviser's identification of any potential weaknesses in the State trust company's policies and procedures, financial position, and internal controls, or other vulnerabilities that may impact its ability to safeguard crypto assets, which would help reduce risks of harm to the clients whose crypto assets are maintained at the State trust company. In particular, the proposed requirement to maintain a memorandum describing the basis for the adviser's initial and annual determination would enable our staff to better understand the adviser's basis for these determinations and help ensure that advisers are periodically reevaluating whether the State trust company continues to be an appropriate custodian for the client's crypto assets, which would help enhance investor protection. Finally, requiring the adviser to maintain records of the State trust company's audited financial statements and internal control reports would help enable our staff to understand the independent public accountant's assessments of the State trust company's financial statements and internal controls, which are relevant to the adviser's assessment of the State trust company's ability to appropriately safeguard crypto assets and would help enhance investor protection.

We request comment on all aspects of the proposed amendments to the Advisers Act recordkeeping rule related to the proposed State trust company rule, including the following items:

273. The proposed recordkeeping rule amendment would require the adviser to maintain a memorandum describing the basis for its required determinations with respect to the State trust company. Should the rule specify certain elements that must be included in the memorandum? If yes, what should those elements be?

274. Should advisers be required to maintain records of the State trust company's audited financial statements and internal control reports as records, as proposed? Are there any alternatives that we should consider? For example, should an adviser instead be permitted to maintain records of a certification or other evidence from the State trust company related to its audited financial statements and internal control reports? Alternatively, should the recordkeeping requirement be limited to the memorandum proposed to be required describing the adviser's basis for its determination?

275. The proposed recordkeeping rule for adviser self-custody of crypto assets would require that an adviser that has self-custody of crypto assets maintains records that include such information as ( printed page 63958) may be reasonably necessary to reconstruct all financial positions and transactions related to client crypto assets that the adviser has in self-custody. Should the Advisers Act recordkeeping rule be amended to likewise require the adviser to make and keep similar records related to the crypto assets that are maintained at a qualified custodian (including a State trust company pursuant to the proposed State trust company rules)? Why or why not? Would the adviser have access or be able to obtain access to the information necessary to make and keep such records? Would it be significantly burdensome for the adviser to obtain the necessary information to be able to make and keep such records?

(c) Records Related to Standing Letters of Authorization

We are also proposing to add a recordkeeping requirement related to the proposed amendment to the Advisers Act custody rule that provides an exception from the custody rule's surprise examination requirement if an adviser has custody of client assets solely because of a SLOA, as discussed further above in section II.G.5.[636] The adviser would be required to make and keep a record of any SLOA that the adviser has with a client and any related records pursuant to which the adviser relies on the proposed exception to the Advisers Act custody rule's surprise examination requirement.[637] The adviser would be required to retain such records for a SLOA that is in effect, or at any time within the past five years was, in effect. The proposed retention period is designed to be consistent with other retention periods required under the Advisers Act recordkeeping rule, which require that certain records be retained for five years from the fiscal year of the last entry. The adviser would also be required to retain any other related records that demonstrate its compliance with the conditions of the proposed exception. The proposed recordkeeping requirements related to SLOAs are designed to support compliance with the proposed exception and allow the Commission's staff to be able to verify whether the adviser has satisfied the conditions to avail itself of the proposed SLOA exception. As discussed further above in section II.G.5, the Commission is proposing the SLOA exception to the Advisers Act custody rule's surprise examination requirement on the basis that, although a SLOA establishes that the adviser has custody of client funds or securities, the limitations set forth in the proposed SLOA exception to the surprise examination requirement are designed to restrict the adviser's ability to transfer client funds or securities to third parties without the client's authorization. The proposed recordkeeping requirement is important for the Commission's examination and oversight function, particularly with respect to determining whether the protective conditions of the SLOA exception are in place. Further, the proposed SLOA recordkeeping requirement would also support investor protection by giving Commission staff records to examine that could show any compliance issues related to the SLOA, including those that may lead to any potential theft, loss, misappropriation, or misuse of client funds or securities related to SLOAs, and may serve as a deterrence against adviser misconduct related to SLOAs.

We request comment on the proposed requirement to make and keep records related to any SLOAs between the adviser and a client, as well as any related records, including the following items:

276. Is it clear what “related records” the adviser would be required to maintain? Should the rule be modified to require that the adviser maintain any specific related records? For example, should the rule be modified to require that the adviser maintain records evidencing that the client's qualified custodian is not a related person of the adviser?

277. Should any additional records be required with respect to the proposed amendments to the Advisers Act custody rule related to SLOAs? If so, what records and why? Are there alternatives to the proposed amendments to the Advisers Act recordkeeping rule that would minimize burdens and costs that we should consider? If so, what are they?

278. Should we amend the Advisers Act recordkeeping rule in any other respects related to this proposed rulemaking? If so, what amendments should be made and why?

2. Regulated Fund Recordkeeping

We are proposing amendments to rule 31a-2 under the Investment Company Act (“fund retention rule”) to add new recordkeeping requirements that would require records related to the proposed rules addressing regulated fund self-custody of crypto assets discussed above.[638] In addition, we are also proposing amendments to the fund retention rule to add new recordkeeping requirements for regulated funds that maintain their crypto assets at a State trust company under the proposed State trust company rules discussed above.[639] Finally, we are proposing amendments to the fund retention rule and rule 31a-1 under the Investment Company Act (together, the “regulated fund recordkeeping rules”) to specify the applicability of these rules to BDCs.[640]

The proposed self-custody related amendments would require a regulated fund to maintain, for each crypto asset of the fund held in custody under the proposed rule for fund self-custody of crypto assets, any report or other information provided to the fund's board in connection with the board oversight requirements.[641] As discussed above, such information would include the quarterly written report documenting the basis for the investment adviser's QC determination, as well as the adviser's annual written report regarding its expertise and systems, the most recent annual review of the adviser's safeguarding systems and cybersecurity controls if available, the most recent internal written control report if available, and any other information reasonably necessary for the board to evaluate the fund's custody arrangement.[642] The regulated fund would be required to maintain such reports and other information for at least six years, the first two years in an easily accessible place.[643] By having past documents available, a regulated fund's board could be better able to make the required annual determination as to whether the crypto assets maintained with the adviser would continue to be subject to reasonable care. The proposed amendments are also designed to promote effective regulatory oversight by the Commission and its staff, which provides investors with important protections.

For each crypto asset held in self-custody, the proposed self-custody rule under the Advisers Act and the current regulated fund recordkeeping rules would require a regulated fund to maintain records of resolutions regarding the board's designation of ( printed page 63959) supervised persons with access to key materials permanently, the first two years in an easily accessible place. This requirement is based on the proposed adviser self-custody rule limiting access to fund crypto asset key materials to those persons designated by resolution of the board to have such access and the current recordkeeping requirements.[644] This recordkeeping requirement is designed to promote both board oversight of key access materials and effective regulatory oversight by the Commission and its staff, which provides investors with important protections.

The proposed amendments related to State trust company custody would require a regulated fund that maintains client crypto assets and related cash and/or cash equivalents with a State trust company as a permitted custodian to make and keep the following records: (1) a memorandum describing the basis upon which the fund made its required initial and annual determinations with respect to the State trust company as a permitted custodian, (2) records of the State trust company's audited financial statements obtained or received as required under the proposed rules, and (3) a copy of the State trust company's internal control reports obtained or received pursuant to the proposed crypto custody rules.[645] The regulated fund would be required to maintain these records for at least six years, the first two years in an easily accessible place.[646] Similar to the parallel proposed amendments to the Advisers Act discussed above, the proposed amendments related to State trust company custody would help facilitate the Commission's examination and enforcement functions, including determination of the fund's compliance with the proposed State trust company rules.[647]

Finally, we are proposing amendments to the regulated fund recordkeeping rules to specify the applicability of these rules to BDCs.[648] Section 31 under the Investment Company Act, prescribing recordkeeping requirements, is incorporated by statute to apply to BDCs to the same extent as if the BDC were a registered closed-end investment company.[649] Compliance with the rules thereunder is mandatory for all registered investment companies, and BDCs are similarly subject to these requirements under the statutory incorporation.[650] The proposed amendments update the rule text to reflect their applicability to BDCs.

We request comment on all aspects of the proposed Investment Company Act recordkeeping rules, including the following items:

279. Should a regulated fund be required to maintain, for each crypto asset of the fund held in custody under the proposed rule for fund self-custody of crypto assets, the information provided to the fund's board in connection with the board oversight requirements? Is there any additional documentation relating to the board's oversight of the custody arrangement that the fund should maintain?

280. The proposed fund self-custody recordkeeping requirements would require the fund to maintain information provided to the fund's board in connection with the board oversight requirements for six years. Should regulated funds be required to maintain these records for a shorter or longer period? If so, what time period, and why?

281. Would the proposed fund self-custody recordkeeping requirements be overly burdensome for regulated funds? Why or why not? What alternatives to the proposed requirements would minimize recordkeeping burdens and the associated costs while promoting the goals of facilitating compliance with the proposed fund self-custody rule and effective regulatory oversight by the Commission and its staff? How would such alternatives minimize burdens while promoting compliance and regulatory oversight?

282. The proposed self-custody rule under the Advisers Act and the current regulated fund recordkeeping rules would require a regulated fund to maintain records of resolutions regarding the board's designation of supervised persons with access to key materials permanently, the first two years in an easily accessible place. Alternatively, should regulated funds be required to maintain these records for a shorter period? If so, what time period, and why?

283. The proposed State trust company recordkeeping requirements would require a regulated fund to maintain records for at least six years, the first two years in an easily accessible place. Should regulated funds be required to maintain these records for a shorter or longer period? If so, what time period, and why?

284. The proposed State trust company recordkeeping requirements would require the regulated fund to maintain a memorandum describing the basis for its required determinations with respect to the State trust company. Should the rule specify certain elements that must be included in the memorandum? If yes, what should those elements be?

285. Should regulated funds be required to maintain records of the State trust company's audited financial statements and internal control reports as records, as proposed? Are there any alternatives that we should consider? For example, should a fund instead be permitted to maintain records of a certification or other evidence from the State trust company related to its audited financial statements and internal control reports? Alternatively, should the recordkeeping requirement be limited to the memorandum proposed to be required describing the fund's basis for its determination?

286. Are the proposed amendments to the regulated fund recordkeeping rules specifying the applicability of these rules to BDCs appropriate? Why or why not?

3. Records Related to Crypto Assets From a Crypto Network

We are proposing amendments to the Advisers Act and Investment Company Act recordkeeping rules to provide that records related to crypto assets that are required to be maintained and preserved under the applicable recordkeeping rule may be maintained and preserved on a crypto network.[651] Advisers and ( printed page 63960) regulated funds [652] would be required to provide such records in a human-readable and reasonably usable electronic format promptly upon request by the Commission (including its examiners and other representatives) and continue to provide access for the same period that other books and records are required to be maintained and preserved under the Advisers Act and Investment Company Act recordkeeping rules.[653] The adviser or regulated fund may be required to maintain supplemental backup onchain or offchain records to ensure that records maintained on the crypto network remain accessible during the entire applicable retention period.[654] These proposed amendments would apply to any record required to be maintained and preserved under the Advisers Act and Investment Company Act recordkeeping rules related to crypto assets, including the proposed amendments related to crypto custody.

The development of crypto networks may afford advisers and regulated funds the opportunity to leverage the recordkeeping capabilities of crypto networks to support the recordkeeping obligations under the Advisers Act and Investment Company Act recordkeeping rules and provide information and records related to crypto asset transactions.[655] Permitting reference to a crypto network as a source for recordkeeping related to crypto assets would reduce burdens by eliminating the need for separate records when records are available via a crypto network. For example, recordkeeping rules under the Advisers Act and Investment Company Act require an adviser or regulated fund, respectively, to maintain a separate ledger account for each client showing purchases and sales of securities as well as the date and price of each such purchase and sale (among other information).[656] Allowing advisers and regulated funds to use onchain records would reduce costs of separate duplicate offchain recordkeeping, which could ultimately result in reduced costs for investors. These proposed requirements would also benefit investors by giving Commission staff records to examine that could show any compliance issues, including those that could lead to theft, loss, misuse, or misappropriation related to crypto assets, by being able to access and view the crypto network, which may have greater accuracy than offchain copies of onchain records and information, thereby reducing the risk of harm to investors.

Under the proposed amendments, an adviser or regulated fund may satisfy this requirement with respect to crypto assets by maintaining such ledger accounts on a crypto network, provided that the onchain record contains a true, accurate, and current record of the information required to be retained under the relevant provision of the applicable recordkeeping rule.

Under the proposed rules, the adviser or regulated fund would remain obligated to comply with the substantive provisions of the recordkeeping rules and provide the same information required under the current rules. This would require the adviser or regulated fund to supplement information available on the crypto network with offchain records for any required information that is not available onchain.[657] For example, because crypto asset ownership is designated by private keys, transaction information that is publicly available on a crypto network may need to be supplemented by the adviser's offchain records to identify the beneficial ownership of a crypto asset and attribute a particular public address to the corresponding client or regulated fund. Similarly, other personal information, like the client's name, investor ID, contact information, and other identifying or non-public information, may need to be maintained as offchain records because such information may not be available on the crypto network. While these proposed rule amendments are designed to provide advisers and regulated funds the flexibility to tailor their recordkeeping practices by permitting the use of onchain records, an adviser and regulated fund would be required to continue to ensure that its recordkeeping practices enable compliance with its obligations under the Advisers Act and Investment Company Act recordkeeping rules, including by considering whether offchain records are needed to supplement information available via onchain records to help ensure that the records available to the Commission reflect a true, accurate, and current record.

The adviser or regulated fund would also be required to provide records on the crypto network in a human-readable and reasonably usable electronic format promptly upon request by the Commission (including its examiners and other representatives) and continue to be able to provide access during the applicable record retention period. This requirement is designed to help ensure that Commission staff has access to consistent information across asset classes and is able to continue to review and analyze records reflecting the same underlying information to which the Commission staff currently has access.

Blockchain explorers are generally used to navigate a crypto network and view information available on the crypto network, including transaction information. Blockchain explorers may not be available for all crypto networks. For example, a nascent crypto asset may be transacted on a novel crypto network, which is not supported by a widely available blockchain explorer. The proposed requirement that onchain records provided to the Commission are in a human-readable and reasonably usable electronic format and can be made available to the Commission during the applicable record retention period is intended to ensure that the Commission is able to have the same access to onchain records that it currently has for offchain records and to help support the Commission's examination and oversight functions, notwithstanding whether those onchain ( printed page 63961) records can be viewed through a blockchain explorer. We request comment on the proposed amendment, including the following items:

287. As proposed, should the amendment be limited to records related to crypto assets? Do advisers and regulated funds currently make use of crypto networks with respect to any recordkeeping functions that are unrelated to crypto assets? If so, what recordkeeping functions?

288. The proposed amendments related to records for information available on a crypto network would apply for all records required under the Advisers Act and Investment Company Act recordkeeping rules relating to a crypto asset. Alternatively, should the proposed amendment be limited to particular records required under the Advisers Act and Investment Company Act recordkeeping rules? If so, which recordkeeping requirements should advisers and regulated funds be permitted to satisfy by reference to a crypto network and why?

289. Would the proposed requirements that the adviser or regulated funds comply with the substantive provisions of the recordkeeping rules and provide the same information required under the current rules inhibit the adviser or regulated fund's ability to maintain records on a crypto network that is a private or permissioned network that is not controlled by the adviser or a related person of the adviser? How would an adviser or regulated fund determine that such a private or permissioned crypto network that is not controlled by the adviser or a related person of the adviser is able to generate a true, accurate, and current record for a crypto network? How would an adviser or regulated fund determine that the adviser or regulated fund would be able to have access to the crypto network for the full record retention period? Should any different or additional requirements apply in the case of records that are maintained on a private or permissioned crypto network? For example, should the adviser or regulated fund be required to confirm that the network governance prevents unilateral control, allows independent verification of records, and/or limits the ability of a single administrator to alter or reverse transactions recorded on the private or permissioned crypto network?

290. The proposed Advisers Act recordkeeping rule for self-custody of crypto assets would require an adviser that has self-custody of crypto assets to maintain records that include such information as may be reasonably necessary to reconstruct all financial positions and transactions related to client or regulated fund crypto assets that the adviser self-custodies. Should the proposed amendment also require that advisers maintain backups for onchain records? Why or why not? Would the adviser have access or be able to obtain access to the information necessary to make and keep such records? Would it be significantly burdensome for the adviser to obtain the necessary information to be able to make and keep such records?

291. Is the requirement for the adviser or regulated fund to provide access to the crypto network to Commission staff clear? Why or why not? If not, what alternative requirements should we consider? For example, should the adviser be required to produce a copy or an offchain record evidencing the information that is available on the crypto network to Commission staff?

292. Should we consider other requirements to apply to the use of or reference to crypto networks for recordkeeping purposes? For example, should an adviser or regulated fund be required to perform due diligence of the applicable crypto network to determine whether the crypto network is a reliable and trustworthy source of information? Have any best practices developed regarding ascertaining the reliability or trustworthiness of a particular crypto network for recordkeeping purposes?

293. What are best practices that commenters have developed or are aware of with respect to recordkeeping practices for crypto assets or, alternatively, are there any recordkeeping practices with respect to crypto assets that commenters have found to be ineffective or relatively less effective?

294. Should we consider amending the existing Advisers Act or Investment Company Act recordkeeping rules in any other respects to accommodate records maintained on a crypto network under the rule? For example, should we amend the Advisers Act recordkeeping rule to address the application of the requirement to maintain books and records at an appropriate office of the investment adviser for the first two years for records that are maintained on a crypto network? Similarly, should we amend the Investment Company Act recordkeeping rules to address the application of the requirement to maintain books and records “in an easily accessible place” for the first two years for records that are maintained on a crypto network?

295. Should guidance be provided regarding an adviser's or regulated fund's compliance with the proposed provision in the event the crypto network is temporarily or permanently inaccessible? Should the rule require that an adviser or regulated fund maintaining records on a crypto network also be required to maintain backups and/or analogous offchain records?

I. Guidance for Accountants Updates

The Commission expects to revise certain aspects of the guidance for accountants set forth in the 2009 Guidance for Accountants to address auditing and attestation standards for crypto assets and other industry developments since its publication.[658] The Advisers Act custody rule requires that an adviser (or its related person) that maintains client funds or securities as a qualified custodian obtain an internal control report related to its custody services at least annually.[659] The examination conducted by the independent public accountant to support the internal control report assesses whether the controls of the adviser or its related person (in its capacity as a qualified custodian) have been placed in operation as of a specific date, and are suitably designed and are operating effectively to meet control objectives related to custody of funds and securities during the period specified.[660] The 2009 Guidance for Accountants sets forth the Commission's position on several control objectives that should be included.

In connection with the proposed changes to the Advisers Act custody rule, we expect to make certain revisions to the 2009 Guidance for Accountants. We also expect to make certain modifications to improve the 2009 Guidance for Accountants based on our experience with its implementation by industry members. Both sets of changes relate to the following and are described in greater detail below:

1. Revisions for Independent Verification

The Commission expects to revise the 2009 Guidance for Accountants to specify that a material discrepancy would be a variance, irregularity, or omission identified during an accountant's examination that, individually or in the aggregate, (1) results in the material misstatement of funds or securities; (2) creates a reasonable possibility of a material misstatement of funds or securities; (3) indicates actual or potential loss, theft, misuse, or misappropriation of funds or securities; or (4) indicates a failure by the adviser to maintain books and records in a manner that allows for the verification of funds or securities. This revision is intended to better align the definition of a material discrepancy with matters that the accountant's examination are designed to identify.

2. Revisions for Internal Control Report

The Commission also expects to provide guidance regarding how an adviser or its related person (in its capacity as a qualified custodian) who is required to obtain an internal control report for both crypto assets and funds and securities that are not crypto assets (“non-crypto funds and securities”) can satisfy these requirements. In determining whether one internal control report can satisfy the internal control report requirements for both crypto assets and non-crypto funds and securities, the parties engaging the independent public accountant to perform the engagement should consider which parties are responsible for which controls. When one party is responsible for controls related to both non-crypto funds and securities and crypto assets, determining if a single report is sufficient requires ensuring the report addresses all relevant control objectives for all relevant assets. To the extent the party responsible for controls related to non-crypto funds and securities is different than the party responsible for controls related to crypto assets, there should be two internal control reports—one satisfying the requirement for non-crypto funds and securities and one satisfying the requirement for crypto assets.

(a) Non-Crypto Funds and Securities

The internal control report related to the custodial services, including the safeguarding of non-crypto funds and securities, should address the following control objectives and associated controls related to the following areas: (1) client account setup and maintenance; (2) authorization and processing of client transactions; (3) security maintenance and setup; (4) processing of income and corporate action transactions; (5) reconciliation of funds and securities to depositories; (6) client reporting; and (7) information technology.

The control objectives in the 2009 Guidance for Accountants already address each of these areas, with the exception of control objectives addressing information technology, which are relevant when automated controls or reliance on computer-generated information is important to the achievement of other control objectives, and will be added as part of our revisions. The control objectives to address these areas include the following:

In addition, the 2009 Guidance for Accountants states the independent public accountant should directly confirm, on a test basis, with unaffiliated custodians to verify that the data used in reconciliations performed by the qualified custodian is obtained from unaffiliated custodians and is unaltered. We expect to revise the 2009 Guidance for Accountants to specify that the independent public accountant, instead of performing substantive testing as part of the control report procedures, should observe, inspect, and/or reperform a sample of reconciliations as part of testing the reconciliation control objective to verify that the data used in such reconciliations is obtained from unaffiliated custodians ( e.g., Depository Trust Corporation) and is unaltered. The Commission believes this revision would eliminate duplication of efforts, as we understand that independent public accountants are typically already performing tests of controls over these reconciliations, and would provide assurance throughout the period, rather than at a specific point in time.

(b) Crypto Assets

The internal control report related to the custodial services, including the safeguarding of crypto assets,[661] should address the following control objectives and associated controls related to the following areas: (1) client account setup and maintenance; (2) authorization and processing of client transactions; (3) ( printed page 63963) crypto asset maintenance and setup; (4) processing of onchain events; (5) reconciliation of crypto assets to crypto networks; (6) client reporting; and (7) information technology.

The control objectives that address these areas for crypto assets are the same as for non-crypto funds and securities and include the following:

Based on how ownership is proven and transactions are finalized for crypto assets, the control objectives addressing these areas specifically for crypto assets include the following:

As part of testing the reconciliation control objective, the independent public accountant should observe, inspect, and/or reperform a sample of reconciliations to verify that the data used in such reconciliations is obtained from crypto networks and is unaltered.

3. Other Revisions

Changes to the 2009 Guidance for Accountants to reflect the proposed changes in the Advisers Act custody rule are expected to include: (1) the redesignation of the current Advisers Act custody rule to rule 223-1; (2) the removal of the requirement for independent public accountants to be registered with, and subject to regular inspection by, the PCAOB; and (3) the updates regarding the notice to the Commission of material discrepancies, as discussed above.

We also expect to revise the 2009 Guidance for Accountants to reflect changes in technical references since 2009, as the AICPA professional standards referenced throughout the 2009 Guidance for Accountants have been superseded with new AICPA professional standards. For the internal control reports, three types of reports issued under the AICPA professional standards will be sufficient to satisfy the requirements—(1) SOC 1 Type 2 report conducted in accordance with AT-C section 320, Reporting on an Examination of Controls at a Service Organization Relevant to User Entities' Internal Control Over Financial Reporting (“AT-C 320”); (2) AT-C section 315, Compliance Attestation (“AT-C 315”); or (3) AT-C section 205, Assertion-Based Examination Engagements (“AT-C 205”). Additionally, a surprise examination will be a compliance examination conducted in accordance with AT-C 315.

We request comment on whether there are additional areas we should cover in updates to the 2009 Guidance for Accountants.

J. Disclosure and Reporting Requirements

1. Amendments to Form ADV

The Commission is proposing several amendments to Form ADV, including Part 1A, Form ADV General Instructions and Glossary of Terms, Form ADV-E, and Part 2A of Form ADV. In particular, the Commission is proposing to amend Form ADV to (1) add new questions in Part 1A and Schedule D related to the proposed crypto asset self-custody rule, as discussed above in section II; (2) add new questions to Item 9 that address an adviser's reliance on certain exceptions under the Advisers Act custody rule as well as an adviser's use of State trust companies as qualified custodians, and other amendments to Item 9 to promote more consistent reporting of an adviser's and a related person's custody; (3) add new questions to Schedule D of Form ADV regarding tokenized private funds; and (4) make certain conforming amendments to reflect the proposed amendments to the Advisers Act custody rule.[663]

The proposed amendments related to adviser self-custody of crypto assets and the use of State trust companies as qualified custodians are designed to provide the Commission and investors with important identifying information about the adviser's crypto asset custodial practices, in light of the novel risks associated with adviser self-custody and safeguarding crypto assets. The remaining proposed amendments are designed to provide the Commission staff with more accurate and consistent information about adviser custodial practices and streamline reporting for advisers. Because Form ADV data is publicly available, these proposed amendments will also enhance the information available to investors and support investor protection by providing better information about adviser custodial practices.

(a) Amendments Related to Crypto Asset Self-Custody

We propose changes to Form ADV, Part 1A, to add several new questions related to the proposed amendments to the Advisers Act custody rule that would permit advisers to self-custody client crypto assets.[664] The proposed changes include amendments to: (1) Item 9 to add several new questions ( printed page 63964) related to advisers' crypto asset self-custody practices under the proposed adviser self-custody rule; and (2) Item 5.K. and Section 7.B. of Schedule D to add questions about crypto assets self-custodied on behalf of separately managed account clients (“SMA clients”) and private funds. Relatedly, we propose to add the terms “crypto asset,” “crypto asset address,” and “self-custody,” which are referenced in the proposed Form ADV, Part 1A questions on adviser self-custody, to the Form ADV Glossary of Terms.[665] These proposed new questions are designed to provide the Commission and investors with important information about the custodial practices of advisers engaging in self-custody of crypto assets. As discussed further above in section II, while adviser self-custody of crypto assets may be appropriate subject to certain protective conditions, self-custody may present unique risks given the nature of crypto assets and the potential conflicts of interest associated with adviser self-custody. For this reason, we believe that additional Form ADV disclosure on adviser self-custody of crypto assets is appropriate and would serve investor protection.

First, we propose to revise Item 9 to instruct advisers to exclude regulated funds from “clients” reported under Items 9.A through 9.E (custody questions that are not related to self-custody of crypto assets), but to include regulated funds in “clients” when responding to questions related to crypto self-custody under proposed Item 9.F.[666] This instruction aligns the scope of self-custody reporting under proposed Item 9.F. with the scope of the proposed adviser self-custody rule, which would apply to crypto assets held in an adviser's self-custody for all advisory clients including regulated fund clients.[667]

We also propose to add new questions under proposed Item 9.F. related to advisers' crypto asset self-custody practices under the requirements of the proposed adviser self-custody rule. The proposed questions would require advisers to report whether the adviser has self-custody of client crypto assets, and if so, the approximate amount (in U.S. dollars), total number of clients for which the adviser has self-custody of crypto assets as well as the total number of crypto asset addresses that hold clients' crypto assets in the adviser's self-custody.[668] These questions would benefit investors by providing a view into the complexity and risk exposure of an adviser's crypto self-custody activities.[669]

We also propose to add new questions requiring advisers to report whether an independent public accountant prepares an internal control report with respect to custodial services in connection with the adviser having self-custody of client crypto assets and to report identifying information about any accountant(s) engaged to perform an internal control report.[670] We are also proposing to ask advisers that self-custody client crypto assets to report whether account statements are sent at least quarterly to the adviser's clients, or whether, in lieu of sending a consolidated account statement, the adviser transmits, or arranges for the transmission of, the information required in an account statement, to clients at least quarterly in a human-readable and reasonably usable electronic format.[671] Finally, for advisers that self-custody client crypto assets on behalf of pooled investment vehicles other than regulated funds, we propose to add new questions requiring such advisers to report whether an independent public accountant audits annually such pooled investment vehicles and whether audited financial statements are distributed to the investors in such pools as well as identifying information about the accountants engaged to perform the audit.[672] These additional questions will allow clients and investors to better discern how advisers safeguard the crypto assets in their self-custody and the methods used to do so as well as which accounting firms advisers engage for purposes of independent checks on their self-custody practices. These new required Form ADV disclosures would also enhance the Commission's investor protection efforts by providing the Commission with important information related to advisers' self-custody practices. It would also help our examination staff assess advisers' risk profiles and identify specific areas in need of outreach and examination.

We also propose to add new questions to Item 5.K. and Section 7.B. of Schedule D to request information about the crypto assets that an adviser self-custodies on behalf of SMA clients and private funds. Item 5.K. currently requires advisers to disclose certain information about SMA clients that they advise, including transactions that they engage in on behalf of SMA clients [673] and custodians that account for at least ten percent of separately managed account regulatory assets under management.[674] Section 7.B. of Schedule D requires information on ( printed page 63965) private funds managed by the adviser including custodians used by the private funds to hold their assets. We propose to add a new Item 5.K.(5)(a), which would require the adviser to indicate whether it has self-custody of crypto assets on behalf of SMA clients, and a new Item 5.K.(5)(b) that would require the adviser to provide the approximate amount of such self-custodied crypto assets in U.S. dollars, the number of SMA clients for which the adviser self-custodies crypto assets, and the number of crypto asset addresses that store client crypto assets in the adviser's self-custody.[675] Similarly, we propose to add a new question 25(h)(1) in Section 7.B. of Schedule D that would require the adviser to indicate whether it self-custodies crypto assets for a private fund, and a new question 25(h)(2) that would require the adviser to provide the approximate amount of such self-custodied crypto assets in U.S. dollars for the private fund and the total number of crypto asset addresses that store the crypto assets of which the adviser has self-custody for the private fund.[676] Although Item 9.F. under this proposal would request similar information on an aggregated basis, these additional questions would provide us with a more fulsome picture of advisers' self-custody practices for SMA clients and private funds, which present different risk profiles and operational structures. A breakout of this data for SMAs and private funds would not only benefit investors with specific disclosures about the scale and nature of crypto assets for an adviser's SMA and private fund clients, but it would also enhance the Commission staff's risk assessment efforts by allowing them to assess the size, client profile, and operational complexity of crypto assets of which advisers have self-custody.

We request comment on all aspects of the proposed amendments to Form ADV, Part 1A, relating to adviser self-custody of crypto assets, including the following items.

296. Is there any additional information that an adviser should be required to report in Form ADV, Part 1A, regarding its custodial practices for self-custody of client crypto assets? If so, what additional information should advisers that engage in self-custody of client crypto assets be required to report?

297. This proposal would add questions to Form ADV, Part 1A, that would require advisers to disclose in proposed Item 9.F. whether the adviser has self-custody of client crypto assets, and if so, the approximate amount (in U.S. dollars), total number of clients for which the adviser has self-custody of crypto assets as well as the total number of crypto asset addresses that hold clients' crypto assets in the adviser's self-custody. We also propose to add similar questions in Item 5.K. and Schedule D that would require advisers to report the specific amount of self-custodied crypto assets on behalf of SMA clients and private funds, the number of crypto asset addresses that store self-custodied crypto assets for SMAs and private funds, and the number of SMA clients for which advisers maintain crypto assets in self-custody. Should advisers be required to report this information? Why or why not? Would this information be meaningful? Why or why not? Should we require reporting of only a subset of this information? If so, which particular questions? Would public disclosure of all or a subset of this information expose advisers to increased risk of cybersecurity breaches and physical attacks? Should all or a subset of this information be filed with the Commission confidentially, and would doing so meaningfully reduce the risks of cybersecurity and physical attacks?

298. Should advisers be required to report in Item 9 whether any client crypto assets are maintained at a State trust company qualified custodian? Should all advisers be required to report identifying information about the State trust company qualified custodian? If so, what information should be required? Should advisers be required to report the approximate amount of client crypto assets that are maintained at a State trust company as a qualified custodian?

299. Should the Commission consider any additional amendments to Item 9 in connection with the proposed rulemaking? If so, what changes should be made?

(b) Custody: Item 9

We propose a number of other changes to Item 9 that do not relate to self-custody of crypto assets. Item 9 of Form ADV currently requires advisers to disclose whether the adviser or a related person of the adviser has custody of client assets and to provide information about the adviser's custodial practices, including the dollar amount and total number of clients for which the adviser (or its related person) has custody. Item 9 also includes questions about the use of qualified custodians and independent public accountants. We are proposing several modifications to Item 9 to conform to proposed changes to the Advisers Act custody rule as well as to more closely align certain questions with the rule, to add new questions that would address an adviser's reliance on certain exceptions (including new exceptions we are proposing as part of this rulemaking) under the Advisers Act custody rule, and to improve clarity and promote more consistent reporting of an adviser's and its related persons' custody.

(1) Item 9 Instructions

We propose to amend Item 9 to instruct advisers to exclude both registered investment companies and BDCs when reporting under Items 9A. through 9.E. ( i.e., custody questions that do not relate to adviser self-custody of crypto assets; as noted above, regulated funds would need to be included in Item 9.F. reporting regarding self-custody of crypto assets). Currently, the instructions to Item 9 refer to an adviser (or its related person) having custody of client assets, other than clients that are investment companies registered under the Investment Company Act. The proposed modification described above is intended to align with the proposed amendment to the Advisers Act custody rule discussed further above in section II.G.6 to extend the rule's exception for registered investment companies to BDCs.

We also propose to modify the existing reference to client “assets” in the instructions to Item 9 to instead refer to “funds or securities.” This proposed modification is designed to better align the instructions with the requirements of the Advisers Act custody rule and the required responses to the applicable questions in Item 9, which (except for Item 9.F.) only apply ( printed page 63966) to an adviser's custody of client funds and securities.

(2) Item 9.A.(1)

We propose amendments to Form ADV, Item 9.A.(1)(a), to modify the reference in this item to “cash or bank accounts” to instead refer to “funds ( e.g., cash or bank accounts)”.[677] Currently, Item 9.A.(1) requires an adviser to disclose whether it has custody of any advisory clients' cash or bank accounts, or securities.[678] However, the Advisers Act custody rule applies to an adviser that has custody of client funds or securities and does not specifically refer to an adviser having custody of client cash or bank accounts.[679] This proposed amendment is designed to be more consistent and better align this Form ADV question with the Advisers Act custody rule.

We are also proposing to amend the instructions to Item 9.A.(1) to help ensure that advisers more accurately and consistently disclose in this item whether the adviser has custody of any advisory funds or securities. Currently, the instructions to Item 9.A.(1) provide that an adviser should answer “no” if the adviser has custody solely because it deducts advisory fees or a related person that is operationally independent has custody. The proposed amended instruction would provide instead that an adviser should not complete the remainder of Item 9.A. if it answers “no” to having custody under Item 9.A.(1)(a) and (b). Further, the amended instruction would state that an adviser should answer “yes” to Item 9.A.(1) if the adviser or its related person has custody of client funds or securities, notwithstanding whether the adviser meets any of the exceptions listed under proposed Item 9.A.2.

In the Commission's experience, advisers currently report inconsistently because the instructions to Item 9.A.(1) provide that an adviser should answer “no” to Item 9.A.(1), despite the adviser having custody under the Advisers Act custody rule. The current Advisers Act rule exempts an adviser from the independent verification requirement of the custody rule if such adviser has custody solely because it deducts advisory fees or an operationally independent related person has custody, but it does not exempt such adviser from the custody rule more broadly.[680] The current Item 9.A.(1) instructions can thus result in inaccurate or incomplete reporting in the remainder of Item 9. Further, the current instructions may result in an adviser erroneously believing that it is not subject to the Advisers Act custody rule if the adviser has custody solely as a result of deducting advisory fees or having an operationally independent related person with custody. The proposed instructions are intended to reduce instances of this erroneous interpretation among advisers that they do not have custody because they meet an exception under the Advisers Act custody rule, which can result in incomplete reporting under Item 9. This would help improve consistency and accuracy of reporting on Form ADV.

(3) Item 9.A.(2): Custody Rule Exceptions

We also propose to add new questions under proposed Item 9.A.(2) to address an adviser's reliance on certain exceptions under the Advisers Act custody rule. Proposed Item 9.A.(2)(a) would require an adviser to disclose whether it relies on any of the following exceptions under the Advisers Act custody rule: (i) exception for privately offered securities under rule 223-1(b)(2) (which would be redesignated from current rule 206(4)-2(b)(2)); (ii) exception for fee deduction authority under rule 223-1(b)(3) (which would be redesignated from current rule 206(4)-2(b)(3)) (“fee deduction authority exception”); (iii) exception under rule 223-1(b)(6) (which would be redesignated from current rule 206(4)-2(b)(6)) for custody arising solely from an operationally independent related person having custody of client funds or securities in connection with advisory services the adviser provides to clients (“operationally independent related person exception”); (iv) exception for standing letters of authorization under proposed rule 223-1(b)(8) (“SLOA exception”); (v) exception for discretionary trading authority under proposed rule 223-1(b)(9) (“discretionary trading authority exception”); and (vi) exception for inadvertent custody under proposed rule 223-1(b)(10) and where the adviser knows, or has reason to know, that a custodial agreement confers custody on the adviser, and the adviser has taken the steps described in proposed rule 223-1(b)(10)(ii)(B) to repudiate such unwanted authority (“inadvertent custody exception”).[681] Furthermore, proposed Item 9.A.(2)(b) would require an adviser to indicate whether it has custody of client funds or securities solely as a result of discretionary trading authority and/or due to inadvertent custody ( i.e., the adviser does not have custody of any client funds or securities for any other reason, including fee deduction), and would instruct the adviser to disregard the remainder of Item 9 if it responds “yes” to this question.

These questions address an adviser's reliance on exceptions under the Advisers Act custody rule that would relieve it of certain obligations under the custody rule such as obtaining a surprise examination, maintaining client funds or securities at a qualified custodian, and, in the case of custody arising solely as a result of discretionary trading authority or inadvertent custody, complying with the custody rule altogether. These questions are intended to benefit investors by informing them of the extent to which an adviser is excepted from certain or all provisions of the Advisers Act custody rule. Moreover, the proposed questions would enhance our examination staff's ability to effectively carry out the Commission's risk-based examination program by facilitating more targeted assessments of material custody risks and allowing our staff to more readily identify an adviser's basis for custody and evaluate its compliance with the custody rule.

(4) Custody Reporting Under Items 9.A.(3) and 9.B.(2)

We also propose to modify the instructions for Item 9.A.(3) (which would be redesignated from current Item 9.A.(2)) and Item 9.B.(2) for reporting the amount of client funds and securities and the number of clients for which an adviser and its related persons have custody to improve clarity and facilitate more consistent reporting by advisers in response to these questions.[682] Specifically, proposed Item 9.A.(3) would instruct advisers to report thereunder the approximate amount of client funds and securities and the number of clients for which the adviser and its related persons have custody. Advisers would be required to exclude from this reporting the amount ( printed page 63967) of client funds and securities and the number of clients for which it has custody solely as a result of custodial arrangements described in certain exceptions under the custody rule. Revised Item 9.B.(2) would, in contrast, instruct advisers to report the amount of client funds and securities and the number of clients for which they have custody only because their related persons have custody.[683]

Currently, Item 9.A.(2) instructs an adviser to report the approximate amount of client funds and securities and the total number of clients for which the adviser itself has custody (“direct custody”). Current Item 9.A.(2) also instructs the adviser to exclude from this reporting the amount of client assets and the number of clients that relate to custody arising solely because the adviser deducts advisory fees directly from the clients' accounts. If the adviser's related person has custody of client assets in connection with the advisory services an adviser provides to clients (“indirect custody”), the adviser is required to exclude the amount of those assets and the number of those clients in the adviser's response to Item 9.A.(2). The adviser is instead required to report that information in Item 9.B.(2) where the adviser provides the amount of client funds and securities and total number of clients for which its related person has custody. Instructions with respect to reporting direct and indirect custody under current Items 9.A.(2) and 9.B.(2) have resulted in interpretive challenges and inconsistent reporting across advisers, especially among advisers with custodial arrangements that involve custodial authorities that are integrated between the adviser and its related persons or otherwise where the parameters of those custodial authorities between the adviser and its related persons are less than clear.

Proposed Item 9.A.(3) would instruct an adviser to report the approximate amount of client funds and securities and the total number of clients for which the adviser has custody and to include in its response any amounts and number of clients for which its related persons have custody. Proposed Item 9.B.(2), in contrast, would require reporting the approximate amount of client funds and securities and the total number of clients for which the adviser has custody only because an adviser's related persons have custody; Item 9.B.(2) would instruct the adviser to exclude from its response the amount of any client funds and securities and the number of clients for which the adviser has custody directly, which should instead be provided under Item 9.A.(3). Proposed Item 9.A.(3) and Item 9.B.(2) are intended to alleviate interpretive uncertainties regarding where the amount of custodied assets and associated number of clients in custodial arrangements that involve both the adviser and its related persons need to be reported. This would help promote more consistent reporting of direct and indirect custody by advisers and their related persons.

An adviser would also need to exclude from its responses to proposed Item 9.A.(3) the amount of client funds and securities and the number of clients for which the adviser has custody solely as a result of the custodial arrangements described in the exceptions listed under proposed Items 9.A.(2)(ii) through 9.A.(2)(vi).[684] It is appropriate to exclude the amount of custodied assets and number of associated clients relating to custody arising solely as a result of custodial arrangements described in proposed Items 9.A.(2)(ii) through (vi) from this reporting because material custodial risks are mitigated in these arrangements. These instructions would benefit investors and help our examination staff by allowing them to more accurately assess the degree of client exposure to material custodial risks, and enhance our examination staff's ability to focus their examination efforts on material custodial exposures.

The Commission requests comment on all aspects of the proposed amendments to Item 9, including the following items.

300. Is the existing instruction to Item 9 unclear with respect to advisers with BDC clients? If so, would the proposed modification to the Item 9 instructions, which would instruct advisers to exclude BDCs and registered investment companies in “clients” when reporting under Items 9.A. through 9.E., but to include them in the reporting for Item 9.F., address this issue?

301. Does the existing reference in Item 9.A.(1) and Item 9.B.(1) to advisory clients' “cash or bank accounts” cause confusion and reduce accuracy and consistency in reporting? Would the proposed amendments to Item 9.A.(1) and Item 9.B.(1) to revise this reference to “funds ( e.g., cash or bank accounts)” better align with the requirements of the Advisers Act custody rule and improve consistency and accuracy in reporting? Why or why not?

302. Does the existing instruction in Item 9.A.(1) that provides that an adviser should answer `no' to whether the adviser has custody solely because it deducts advisory fees or a related person that is operationally independent has custody, cause confusion and reduce accuracy and consistency in reporting? Would the proposed amendments to the instructions to Item 9.A.(1) make it easier for advisers to complete Item 9 accurately and reduce confusion caused by the current instructions?

303. Are the instructions for proposed Item 9.A.(2) sufficiently clear? Why or why not? What modifications, if any, should we adopt to the instructions for Item 9.A.(2) to improve clarity and promote consistent reporting of custody rule exceptions that advisers rely on?

304. Are the proposed changes to the Item 9.A.(3) and Item 9.B.(2) instructions on reporting the amount of client funds and securities and the number of clients for which advisers and their related persons have custody sufficiently clear? Why or why not? Would the proposed modifications facilitate more consistent reporting of direct and indirect custody? Why or why not? What, if any, other modifications should we adopt to these instructions to improve clarity and promote consistent reporting of direct and indirect custody?

305. Are the proposed instructions for Item 9.A.(3) requiring advisers to exclude from Item 9.A.(3) reporting the amount of client funds and securities and the number of clients for which they have custody solely as a result of the custodial arrangements described in the exceptions listed under proposed Items 9.A.(2)(a)(ii) through (vi), sufficiently clear? Why or why not? What, if any, other modifications should we adopt to these instructions to improve clarity and promote consistent reporting?

306. Should we adopt any additional modifications to the instructions to Item 9? If so, what changes could be made to the instructions?

(5) Item 9.C.(5): State Trust Companies

We also propose to amend Item 9.C to require an adviser to disclose whether a State trust company (as defined in proposed rule 223-1(d)(18)) maintains client funds or securities in accordance with proposed rule 223-1(d)(13)(v), the State trust company rule under the Advisers Act that would allow advisers to use State trust companies as qualified custodians to maintain clients' crypto ( printed page 63968) assets.[685] This proposed question is intended to benefit investors by providing a view into an adviser's use of State trust companies as qualified custodians and to assist the Commission's oversight activities and assessment of the use of State trust companies as qualified custodians for client crypto assets. Because State trust companies are subject to State regulations that can vary from State to State and in light of the novel risks associated with safeguarding crypto assets, proposed Item 9.C.(5) would assist investors in making informed decisions with respect to advisers that maintain client crypto assets at a State trust company as well as help the Commission staff assess emerging practices and inform policy in this area.

We request comment on all aspects of the proposed amendments to Form ADV, Part 1A, relating to proposed Item 9.C.(5), including the following items.

307. Is there any additional information that an adviser should be required to report regarding its use of State trust companies in Form ADV, Part 1A? If so, what additional information should advisers who engage State trust companies as qualified custodians be required to report?

308. Should advisers be required to report identifying information ( e.g., name and office location of the State trust company) about the State trust companies that maintain their clients' funds and securities? Why or why not? Would this information be meaningful? Why or why not?

309. Should advisers be required to identify the crypto asset(s) and/or report the amounts of crypto assets that are maintained by State trust companies? Why or why not? Would this information be meaningful? Why or why not?

(c) Questions on Tokenized Private Funds

Section 7.B.(1) of Schedule D of Form ADV requests certain information about each of the private funds managed by an adviser. We propose to add a new question 29 to this section that would require an adviser to indicate whether the private fund reported thereunder (or series or class thereof) is a tokenized fund. ERAs must complete Item 7 and any related items under Section 7.B.(1) of Schedule D and therefore would be required to respond to proposed question 29 in addition to registered investment advisers.[686] To the extent only certain series or classes of the private fund shares are tokenized, the adviser would be required to indicate the series or class involved. The adviser would also be required to identify all applicable crypto networks where the ownership of the private fund's interests are recorded. Relatedly, we propose to add to the Form ADV, Glossary of Terms, the term “tokenized fund,” which would be defined as a pooled investment vehicle or any series thereof that has issued shares in the format of a crypto asset, where the record of ownership is maintained in whole or in part on or through one or more crypto networks; and the term “crypto network,” which would have the same meaning as in rule 223-1 under the Advisers Act.

The proposed questions are intended to benefit investors by providing a view into an adviser's tokenization practices with respect to private funds and to assist the Commission's oversight activities and assessment of a novel and growing trend in the tokenization of pooled investment vehicles including private funds. Information regarding where ownership of private fund shares is recorded and maintained (for example, public blockchains versus private, permissioned blockchains) is important to assess the private fund's overall operations and transparency as well as the security and speed of its transactions. The proposed questions would assist investors in making informed decisions with respect to advisers that tokenize private fund shares as well as helping the Commission staff assess emerging practices and inform policy in this area.

We request comment on all aspects of the proposed amendments to Form ADV, Part 1A, relating to tokenized funds, including the following items.

310. Is there any additional information that an adviser should be required to report regarding its tokenization practices in Form ADV, Part 1A? For example, should an adviser be required to report tokenization of client assets on behalf of any advisory client, not just private funds as proposed? If so, what additional information should advisers who engage in tokenization be required to report?

311. Should advisers be required to report the specific series or class of the private fund that is tokenized, as proposed? Why or why not? Would this information be meaningful? Why or why not?

312. Should advisers be required to report the applicable blockchain or crypto networks where the ownership of the private fund's interests are recorded, as proposed? Why or why not? Would this information be meaningful? Why or why not?

313. Is the proposed term “tokenized fund” and its definition in Form ADV, Glossary of Terms, clear? Why or why not? Does it accurately reflect the current technology for tokenized funds and is it flexible enough to accommodate technological developments in the future? Is there a better definition we should use?

314. Proposed question 29(c) of Section 7.B.(1) of Schedule D would allow advisers to provide a freeform response identifying the applicable crypto networks used to record ownership of the private fund.

(d) Other Conforming Amendments to Form ADV

The Commission is proposing several other conforming amendments to Form ADV to correspond with the changes that are proposed to be made to the Advisers Act custody rule.

First, in connection with the proposed redesignation from rule 206(4)-2 to proposed new rule 223-1, we are proposing conforming amendments to Form ADV to update existing references to rule 206(4)-2 to proposed new rule 223-1.[687] In particular, we are proposing conforming amendments to Items 7.A. and 9 and Schedule D.[688] We are also proposing a similar conforming amendment to update the reference to rule 206(4)-2 in the General Instructions, Item 18, for Part 2A of Form ADV (the client brochure). Overall, these proposed conforming amendments would not substantively modify any information required to be reported on Form ADV.[689]

Second, in connection with the proposed removal of the requirement for independent public accountants to be ( printed page 63969) registered with, and subject to regular inspection by, the PCAOB, we are proposing to remove Sections 9.C.(3) and 9.C.(4) of Schedule D as well as questions 23(e) and 23(f) from Section 7.B.(1) of Schedule D.[690] Sections 9.C.(3) and 9.C.(4) of Schedule D ask the adviser to report if the independent public accountant that performs a surprise examination, audit of a pooled investment vehicle that the adviser manages, or prepares an internal control report is registered with, and subject to regular inspection by, the PCAOB. Questions 23(e) and 23(f) of Section 7.B.(1) of Schedule D ask whether the firm engaged to conduct an audit of the private fund's financial statements is registered with the PCAOB and subject to regular inspection by the PCAOB. These questions would no longer be applicable under the proposed amendments to the Advisers Act custody rule.[691] As discussed further above in section II.G.4.(a), the Commission now believes that any indirect benefits of the PCAOB registration requirement may not justify the incremental costs for purposes of the internal control reports and audits required to be performed under the Advisers Act custody rule and therefore does not believe that PCAOB registration is a meaningful disclosure requirement in Schedule D of Form ADV. Advisers would continue to be required to report the name and location of the independent public accountant, indicate what services the accountant was engaged to perform, and report whether all internal control reports or audits contain unqualified opinions.[692]

Finally, under this proposal, we are making a technical change to replace the term “unqualified opinion” with “unmodified opinion” throughout Form ADV Part 1A to reflect that AU-C 700.10 uses the term “unmodified opinion.” [693] This amendment does not change the substance of the questions affected in Form ADV Part 1A, which are Section 9.C.(6) (which would be redesignated as Section 9.C.(4) under this proposal) and question 23(h) (which would be redesignated as question 23(f) under this proposal) of Section 7.B.(1) of Schedule D of Form ADV.[694]

2. Amendments to Custody Reporting on Form N-CEN

The Commission is proposing amendments to Form N-CEN to require reporting of (1) the use of crypto asset regulated fund self-custody or of a State trust company to custody a certain regulated fund's assets and (2) whether the regulated fund (or Series or Class thereof) is a tokenized fund.[695] Currently, Form N-CEN requires regulated funds to disclose information in a structured data format about entities that provided custodial services to them, including checking a box corresponding to the different types of permitted custodians for regulated funds under applicable rules and statutes.[696] We are proposing to add additional checkboxes, corresponding to the proposed crypto asset self-custody and State trust company rules as well as redesignate checkboxes corresponding to the “Other” option in the current Form N-CEN.[697] These reporting requirements would provide comparable information for these new classes of custodians as exist for current custodians and assist the Commission and data users in assessing custodial risk and identifying areas of concern. We are also proposing to amend the title of the checkboxes for custody under rule 17f-1 from “Member national securities exchange” to “brokers or dealers” to correspond to the proposed title and scope of rule 17f-1.[698]

We are proposing to add a new Item to Form N-CEN where regulated funds would be required to report whether they (or a series or class thereof) are a tokenized fund and to provide a definition for the term “tokenized fund” for Form N-CEN.[699] Regulated funds would additionally be required to provide the series and/or class identification number(s) (if any) of the tokenized fund or class(es) thereof, if applicable, as well as the names of any crypto networks used to record ownership of the fund or class or series of the regulated fund.[700] As discussed above in the context of private funds, this proposed reporting would similarly assist investors in making informed investment decisions and provide the Commission with information for oversight of tokenized regulated funds.[701]

We request comment on the following:

315. Should we require specific reporting of crypto asset self-custody or of State trust company in Form N-CEN? If not, why? Should we instead just provide guidance that regulated funds should fill out the “Other” custodian checkbox and corresponding description to correspond to these types of custody? Is there somewhere other than Form N-CEN that this reporting should be required?

316. Is there additional information we should require regulated funds to report regarding the use of crypto asset self-custody or of State trust company custodians? If so, what? Should we require regulated funds to report that they have received airdrops or similar distributions of crypto assets?

317. Should we require custodian reporting by BDCs? If so, where would such reporting be made?

318. Is there any additional information that we should require ( printed page 63970) regulated funds that self-custody assets to disclose? Should regulated funds be required to disclose the date on which they took self-custody of the asset or, if self-custody of the asset ceased during the period, when that happened?

319. Should we require reporting on the tokenization of regulated funds? Should we require reporting on blockchain network(s) used to record ownership? Is the proposed definition of “tokenized fund” appropriate, and if not, how should this term be defined? Is there other information that we should require reporting on regarding the tokenization of regulated funds?

3. Adviser and Regulated Fund Risk Disclosure Requirements

Advisers are required to deliver to prospective and current clients a narrative brochure that discloses information about the adviser's business, conflicts of interest, and investment strategies, among other required information.[702] The instructions to Form ADV Part 2 establish the minimum disclosure items required to be made in the brochure. For example, Item 4 (Advisory Business) of the brochure requires, among other things, an adviser to describe its advisory firm, including the types of advisory services offered, whether it holds itself out as specializing in a particular type of advisory service, and the amount of client assets that it manages on each of a discretionary and non-discretionary basis. Additionally, Item 8 (Methods of Analysis, Investment Strategies, and Risk of Loss) requires, among other things, an adviser to describe the methods of analysis and investment strategies the adviser uses in formulating investment advice and managing assets and, for each significant investment strategy, requires an explanation of the material risks involved, including detailed disclosure if the investment strategy involves significant or unusual risks. These items are salient to the disclosure of the material risks and potential conflicts of interest discussed below as they relate to investing in crypto assets and holding crypto assets in self-custody. In addition, an adviser's fiduciary duty obligates the adviser to make full and fair disclosure to its clients of all material facts relating to the advisory relationship and all conflicts of interest which might incline an adviser to render advice which is not disinterested. This may require additional disclosure beyond what is specifically instructed to be disclosed on Form ADV Part 2.[703] Such additional disclosure can be made in the Form ADV Part 2 brochure or by separate disclosure.[704]

Similarly, regulated funds currently are required to disclose risks of investing in the fund to their current and prospective shareholders in their registration statements. Open-end funds are required to disclose principal risks in their prospectuses—that is, those risks that are reasonably likely to adversely affect the fund's net asset value, yield, and total return.[705] An open-end fund must disclose all of the principal risks associated with the fund's principal investments strategies. Closed-end funds are similarly required to describe principal risks in their prospectuses.[706] Additionally, open-end funds are required to disclose non-principal strategies and the risks of those strategies in the Statement of Additional Information (“SAI”) section of the registration statement; closed-end fund are similarly required to disclose investment policies not deemed fundamental and the risks associated with such policies in the SAI.[707] Regulated funds are also required to update their prospectuses so that they do not contain an untrue statement of material fact (or omit a material fact necessary to make the disclosure not misleading).[708]

In addition to prospectus disclosure, open-end funds are required to disclose in their shareholder reports the key factors that materially affected the fund's performance during the reporting period, including any investment strategies and techniques used by the regulated fund's adviser.[709] Regulated fund shareholder reports must also include disclosure of any material changes to the fund's principal investment strategies and risks, among other issues, that occurred during the reporting period.[710]

Accordingly, where a regulated fund invests in crypto assets, or an adviser invests its clients' assets in crypto assets, the adviser or regulated fund will be required to disclose the associated material risks in response to these requirements. This generally would include custodial risks because custodial risks are particularly acute for crypto assets, given that anyone with access to a crypto asset's private key can misappropriate the assets and for certain types of crypto assets, such transactions are generally irreversible. These attributes of crypto assets increase the risk of loss or misappropriation and also increase the risk that assets will be targeted or stolen in cyberattacks. The custodial risk of crypto assets are further heightened if an adviser holds client crypto assets in self-custody, which increases the risk of misappropriation of the assets and resulting risk of irreversible loss, particularly in the absence of backstops such as deposit insurance or SIPA protections available for assets held with traditional custodians. We discuss below the matters regulated funds and advisers would be required to disclose to adequately disclose the material risks when a fund or adviser invests in crypto assets, and particularly if the adviser were holding the crypto assets in self-custody.

(a) Self-Custody Risks

(1) Loss, Misappropriation and Conflicts of Interest Risks

If the proposed self-custody rules are adopted, an adviser or regulated fund would need to disclose whether crypto assets are held in the adviser's self-custody as well as the potentially heightened risk of loss or misappropriation of self-custodied crypto assets and measures put in place to address these risks. Additionally, advisers that self-custody client crypto assets, including assets of regulated funds, would need to disclose any ( printed page 63971) conflicts of interest arising from their self-custody arrangements that could incline an adviser to render advice that is not disinterested.[711] For example, advisers may need to disclose whether they or their related persons receive compensation or fees that are charged to the client in connection with their self-custody services, as these affiliated arrangements may influence the adviser's decision, consciously or unconsciously, as to whether it should pursue investments in crypto assets that must be self-custodied as well as the adviser's selection of self-custody services. Additionally, advisers and regulated funds would need to disclose risks associated with the unique technological challenges and bearer-asset features of the crypto investments their clients or the regulated fund holds. Given the highly technological nature of crypto assets, when an adviser has self-custody of client crypto assets, including the crypto assets of a regulated fund, disclosure regarding the adviser's technological competence, experience and resources related to the custody of crypto assets would be necessary to understand the risks posed by the self-custodial arrangement.

(2) Cybersecurity Risk and Risks Associated With Decentralized Finance Activities

If the proposed self-custody rules are adopted, the adviser or regulated fund would need to disclose the heightened cybersecurity risk associated with specific crypto assets that the adviser self-custodies and the adviser's self-custody practices. For example, it would be relevant for advisory clients and investors in regulated funds to know, among other things, what storage method the adviser uses to maintain key materials (cold wallets vs. hot wallets), and, if an adviser uses hot wallets to store self-custodied crypto assets, that hot wallets typically carry a greater risk of cybersecurity attacks relative to cold wallets due to their interconnectedness to the network.

Moreover, advisers and regulated funds should consider disclosing that access to the self-custodied crypto assets could be impacted by operational vulnerabilities and weaknesses in the crypto assets' crypto network and the limitations, if any, in the advisers' ability to recover those crypto assets in the event of a disruption to the crypto network.

Further, advisers and regulated funds that elect to engage client crypto assets in DeFi activities such as staking would need to disclose and describe these activities, including whether staked crypto assets would remain in the adviser's self-custody or with the applicable permitted custodian and any material risks involved, such as, for example, the risk of third parties impermissibly gaining access to those crypto assets through a vulnerability in the protocols governing the DeFi activity, staking and validator risks (for example, the risk of slashing and governance concentration), and liquidity risks arising from unbonding periods when staked crypto assets cannot be moved.

Finally, if a significant cybersecurity event occurs that materially raises the risk of harm to clients, or materially impacts a regulated fund's financial performance or otherwise renders the disclosure in the fund's registration statement false or misleading, such an event would need to be disclosed. Advisers, as fiduciaries, may also need to consider whether separate or additional disclosures to clients are appropriate. Similarly, for regulated funds, any events that materially affected the fund's performance would need to be disclosed in the fund's shareholder report for the relevant reporting period.

(3) Recourse if Crypto Assets Are Lost or Stolen

If the proposed self-custody rules are adopted, the adviser or regulated fund would need to disclose the heightened risk of loss if a crypto asset is lost or stolen. This heightened risk is relevant given that transactions in crypto assets generally are irreversible, advisers' primary business is providing advisory and not custodial services, and crypto assets held in self-custody by the adviser may be subject to different legal protections than crypto assets custodied with permitted custodians, such as not being federally insured like deposits at federally insured banks or lacking protections against loss and claims provided under regulations that govern liquidations of certain traditional custodians such as broker-dealers.[712] To adequately disclose these risks, the adviser or regulated fund should disclose that these kinds of backstops are not available and disclose what recourse an advisory client or a regulated fund investor, would have to the adviser if the advisory client's crypto assets, including those of a regulated fund, are misappropriated by advisory personnel, or lost by the adviser or stolen by third parties. This could include, for example, whether the adviser maintains insurance arrangements to make whole advisory clients, including regulated funds, in these circumstances and any limitations of such insurance arrangements; whether the adviser maintains insurance arrangements protecting itself from claims in connection with its self-custodial services; or other arrangements. To address the heightened risks associated with adviser self-custody, the adviser or regulated fund also should disclose steps taken by the adviser to protect client crypto assets, including regulated fund assets, from becoming part of the adviser's bankruptcy estate if the adviser were to enter bankruptcy proceedings, and the associated risks if the crypto assets were treated as part of the adviser's bankruptcy estate in these circumstances.[713]

(b) Custodial Risks of State Trust Companies

The proposed amendments to permit custody of client crypto assets, including the assets of regulated funds, with a State trust company as a qualified custodian may also require specific disclosure. In addition to disclosures regarding crypto asset investment strategies and risks associated with investing in crypto assets, an adviser or regulated fund should disclose any material risks associated with the use of a State trust company as a custodian that are appropriate. Since State trust companies are State- and not federally-regulated, such relevant considerations may include the lack of Federal oversight or regulation of State trust companies, the variability of State law regulatory regimes, and any relevant risks associated with any applicable State law regulatory framework.

The Commission requests comment on all aspects of adviser and regulated fund disclosure related to crypto assets, including the following items:

320. Are there other risks associated with an adviser holding a client's assets in self-custody on which we should ( printed page 63972) provide guidance? The discussion above focuses on custodial risks associated with crypto assets, including where an adviser is maintaining the crypto asset in self-custody. Should we provide guidance on other risks related to crypto assets? Are modifications needed to regulated fund registration forms or disclosure requirements or Form ADV to more effectively elicit disclosure related to crypto assets' custodial risks or risks associated with crypto assets more generally?

321. Are we correct in our understanding that the most significant risks of engaging in self-custody that should be disclosed to advisory clients and regulated fund investors are the risk of: (i) loss, misappropriation and conflicts of interests, (ii) cybersecurity risks and risks associated with decentralized finance activities; and (iii) recourse if crypto assets are lost or stolen? Why or why not? Are there other risks associated with self-custody that should be highlighted for advisory clients and regulated fund investors?

322. Are there material custodial risks associated with using State trust companies as custodians for crypto assets that should be disclosed? Why are why not?

323. Item 15 (Custody) of Form ADV Part 2A states that if an adviser has custody of client funds or securities and a qualified custodian sends quarterly, or more frequent, account statements directly to its clients, the adviser must explain that clients will receive account statements from the qualified custodian and that clients should carefully review those statements. Although we state above that advisers that self-custody crypto assets should disclose such arrangements in their brochures, should the instructions under Item 15 be modified to expressly require advisers to disclose whether they self-custody client crypto assets, to explain that account statements, or alternatively transmissions, are sent to clients about their self-custodied crypto assets' activities on the crypto network, and to urge clients to carefully review any transactions onchain against any statements, or alternatively transmissions, they receive from the adviser?

324. Should any additional specific disclosure be required on Form ADV Part 2 for advisers that self-custody client crypto assets or use State trust companies as custodians for client crypto assets?

325. Although this proposal would not require advisers or regulated funds to report the loss of self-custodied client crypto assets with the Commission, should advisers or regulated funds be required to confidentially report to the Commission the loss of self-custodied client crypto assets as part of Form ADV, Form N-RN, or in another manner? How soon after the loss of self-custodied client crypto assets should advisers or regulated funds be required to report the event to the Commission (for example, should the adviser or regulated fund report “promptly,” “as soon as practicable,” or a specific number of business days ( e.g., 3 or 5 business days) after the loss of those crypto assets)?

326. How should any fees that an adviser charges a regulated fund to self-custody crypto assets be disclosed? Should such fees be disclosed in a prospectus fee table and if so, would they be more appropriately classified as “Management Fees” or “Other Expenses”? Is there any additional disclosure that should be provided regarding fees charged by an adviser for crypto asset self-custody?

327. Item 6 of Form ADV, Part 1, requires an adviser to indicate whether it actively engages in the business of any of the enumerated financial industry entity types and, if the adviser engages in other business using a different name, to identify under Section 6.A. of Schedule D the type of financial industry entity that is the adviser's other business. Similarly, Item 7.A. of Form ADV, Part 1, requires an adviser to identify whether its related person is any of the enumerated financial industry entity types listed thereunder and to provide in Section 7.A. of Schedule D additional information about each related person listed in Item 7.A., including indicating in question 5 the type of financial industry entity that the related person is. In all of these questions, “trust company” is enumerated as one of the financial industry entity types. Should the State trust company rule be adopted, do commenters anticipate any interpretive challenges to responding to these questions? If adopted, would the State trust company rule necessitate any modifications to these questions or clarification as to whether a State trust company would count as a “trust company”? Is it appropriate to characterize a State trust company as a “trust company”? Why or why not?

4. Conforming Amendments to Form ADV-E

In connection with the Commission's proposal to redesignate the Advisers Act custody rule as rule 223-1, as discussed in section II.G. above, we are proposing conforming amendments to Form ADV-E to update existing references from current rule 206(4)-2 to proposed new rule 223-1. The proposed conforming amendments would not substantively modify Form ADV-E.

We request comment on the proposed amendments to Form ADV-E, including the following:

328. Should the Commission amend Form ADV-E in any other respects in connection with this proposed rulemaking? If so, what amendments should be made and why?

K. Existing Staff No-Action Letters and Other Staff Statements

We are aware that staff have previously expressed views on topics covered by the proposed rule. For the avoidance of doubt, to the extent the proposed rule is adopted, the Commission's views on such topics would control and any inconsistent staff views would be superseded.

Letters and statements identified as expressing staff views on topics addressed by the proposed rule are listed below. Such list may or may not be exhaustive. Commenters may name any additional staff letters or statements they identify as addressing topics covered by the proposed rule in their comment letters, particularly to the extent such letters or statements express views inconsistent with the rule as proposed.

L. Compliance Date

We are proposing that regulated funds and investment advisers would be able to rely on their respective rules regarding self-custody of crypto assets or the use of State trust company custodians as of the effective date of those rules as soon as the regulated fund ( printed page 63973) or investment adviser could comply with the rules' conditions and applicable recordkeeping requirements.

Certain proposed reporting requirements would require Commission staff to update Forms ADV, ADV-E, and N-CEN:

We are proposing that compliance with the Investment Company Act custody rules amendments to rules 17f-1, 17f-3, 17f-4, 17f-5, 17f-6, and 17f-7, and recordkeeping amendments to rule 31a-1 and rule 31a-2 will be required as of the effective date of those rules.

We are also proposing that compliance with the proposed Advisers Act custody rule amendments discussed in section II.G of this release, as well as the related Advisers Act recordkeeping rule amendment related to SLOAs discussed in section II.H.1.c) (collectively, “Advisers Act custody rule modernization amendments”), will be required as of the effective date of those rules. This includes compliance related to:

We request comment on this compliance period.

329. Should entities be permitted to rely on the proposed self-custody rules regarding self-custody as of the effective date of the rule? Are there investment advisers that currently have or may come into possession of portions of key material that would inadvertently have custody of these assets as a result of the proposed rule? Would such advisers need additional time to come into compliance with the proposed rule or to remove the key material from their possession? How much time would be needed?

330. Should Commission staff delay rescinding the State Trust Company NAL, as discussed in section II.K supra, following any adoption of final rules to provide additional time for a regulated fund or adviser using a State trust company as a custodian to come into compliance with any final rules related to State trust companies? How much time would be needed?

331. Should we provide additional time for advisers to come into compliance with the proposed Advisers Act custody rule modernization amendments? Do the proposed Advisers Act custody rule modernization amendments that are exemptive in nature require additional time to come into compliance? If so, how much additional time should be provided: six months, one year, or a different period of time? Should there be different compliance periods for different requirements or exceptions? Should there be different compliance periods for small advisers versus larger advisers? What specific operational, technological or contractual challenges would entities face in complying with these proposed rules? Please describe them.

332. Should we provide additional time for regulated funds to come into compliance with the proposed amendments to rules 17f-1 or 17f-3 and the Form N-CEN tokenized fund reporting? If so, why? Are there any challenges regulated funds would face complying with the proposed amendments to 17f-1? For example, are there any regulated funds that use broker-dealers to custody regulated fund assets that are not subject to rule 15c3-3 under the Exchange Act that would need time to find different custodians for those assets if the proposed amendments to rule 17f-1 were adopted? Are there any regulated funds relying on rule 17f-3 to maintain free cash accounts that would need time to dispose of the cash if that rule was rescinded? Would regulated funds need additional time between the effective date of this proposal and their annual filing of Form N-CEN to comply with the proposed tokenized fund reporting requirement?

333. General Instruction 4 of Form ADV requires an adviser to promptly file an other-than-annual amendment to its Part 1A if information provided in response to certain questions in Item 9 becomes inaccurate in any way. Because of the proposed addition of new questions and the proposed revision of certain existing questions under Item 9, General Instruction 4 of Form ADV may require advisers to promptly file an other-than-annual amendment to their Part 1A once the proposed amended Form ADV becomes available. Should advisers be required to file promptly an other-than-annual-amendment to their Form ADV Part 1A pursuant to General Instruction 4 of Form ADV when the proposed amended Form ADV becomes available for filing due to the proposed addition of new questions and the proposed revision of certain existing questions under Item 9? Would many advisers anticipate needing to promptly file an other-than-annual amendment to their Form ADV Part 1A as a result? If so, would such advisers expect such other-than-annual amendments to their Form ADV Part 1A to entail significant burdens? Should an adviser instead be required to update promptly only some of the questions under proposed Item 9, and if so, which questions under proposed Item 9, and why?

III. General Request for Comment

We request and encourage any interested person to submit comments regarding the proposed rules and forms, specific issues discussed in this release, and other matters that may have an effect on the proposed rules and forms. With regard to any comments, we note that such comments are of particular assistance to our rulemaking initiative if accompanied by supporting data and analysis of the issues addressed in those comments.

IV. Economic Analysis

A. Introduction

The SEC is mindful of the economic effects, including the costs and benefits, of the proposed rules and amendments. Section 202(c) of the Advisers Act and section 2(c) of the Investment Company Act provide that when the Commission is engaging in rulemaking under the Advisers Act or Investment Company Act and is required to consider or ( printed page 63974) determine whether an action is necessary or appropriate in the public interest, the Commission shall also consider whether the action will promote efficiency, competition, and capital formation, in addition to the protection of investors.[714] The analysis below addresses the likely economic effects of the proposed rules and amendments, including the anticipated and estimated benefits and costs of the amendments and their likely effects on efficiency, competition, and capital formation. The Commission also discusses the potential economic effects of certain alternatives to the approaches taken in this proposal.

We are proposing rules that would permit investment advisers to self-custody clients' crypto assets, including those of regulated funds, and would permit advisers and regulated funds to use State trust companies as custodians for such assets. The current market for crypto custody is constrained by high fixed costs associated with developing and maintaining crypto-specific safeguarding infrastructure, including those related to obtaining or developing highly specialized technical knowledge and abilities, which create barriers to entry that limit the number of permitted custodians able to support certain crypto assets.[715] As a result, some advisers and regulated funds cannot find custodians capable of supporting their clients' or their own investment strategies or to participate in certain crypto-native activities such as staking. At the same time, the highly specialized technical knowledge required to safeguard crypto assets also exacerbates information asymmetries that make it difficult for advisers, regulated funds, and their clients and investors to evaluate and monitor custodial arrangements effectively. These information asymmetries may exacerbate principal-agent problems, where custodians may have incentives to provide safeguarding that is less effective than anticipated.

The proposed crypto custody rules are designed to address these challenges, which may inhibit advisers' ability to provide investment advice and limit regulated funds' ability to invest in a broad range of crypto assets or pursue certain related investment strategies. The proposal also includes a series of protective conditions designed to mitigate the risks inherent in crypto asset custody and the inherent conflicts of interest associated with adviser self-custody,[716] and to help ensure that advisers and regulated funds use crypto asset custodians that provide secure, reliable, and effective services and that only advisers that are well-suited and have the capabilities to safeguard crypto assets take on self-custody of client crypto assets.

We are also proposing several amendments to the custody rules to modernize their requirements, to better address current industry practices and industry feedback, and to implement certain conforming amendments. We are also proposing amendments to the recordkeeping rules under the Advisers Act and Investment Company Act and to Forms ADV and N-CEN.[717] Finally, we outline our views on several aspects of the Advisers Act custody rule and on disclosures related to the proposed custody rules on Forms ADV (for advisers) and N-1A and N-2 (for regulated funds), and we expect to make revisions to the 2009 Guidance for Accountants.

Where possible, the Commission quantifies the likely economic effects of its proposed rules and amendments. However, the Commission is unable to quantify certain economic effects because it lacks the information necessary to provide estimates or ranges of costs. Additionally, in some cases, quantification would require numerous assumptions to forecast how affected parties would respond to the proposed rules and amendments, and how those responses would in turn affect the broader markets in which they operate. Furthermore, many factors determining the economic effects of the proposed rules and amendments would vary significantly among investment advisers and regulated funds. For example, whether an investment adviser is able to exercise self-custody of crypto assets, and the costs associated with doing so, would significantly depend on the adviser's existing practices and technological expertise. In addition, the cost of obtaining an internal control report may vary considerably among entities due to various factors, including the number and type of crypto assets that it can custody and the complexity of its safeguarding systems. This variance makes it practically difficult to quantify economic effects. Even if it were possible to calculate a range of potential quantitative estimates, that range could be so wide as not to be informative about the magnitude of the benefits or costs associated with the proposed rule. Many parts of the discussion below are, therefore, qualitative in nature. As described more fully below, the Commission is providing a qualitative assessment and, where practicable, a quantified estimate of the economic effects. The Commission seeks comments on all aspects of the economic analysis, especially any data or information that would enable a quantification of the proposal's economic effects.

B. Economic Baseline

The Commission assesses the economic effects of the proposed rules and amendments relative to the baseline that consists of existing regulations and market practices as they relate to the custody of assets by investment advisers and regulated funds. The economic analysis appropriately considers existing regulatory requirements, including recently adopted Commission rules as well as State and Federal laws and regulations as part of the economic baseline against which the economic effects of the proposed rules are measured.[718]

1. Crypto Assets and Market Overview

A crypto asset is any digital representation of value that is recorded on a cryptographically secured distributed ledger.[719] Crypto assets are generated, issued, and transferred using a blockchain or similar distributed ledger technology.[720] A distributed ledger is a technology through which data is shared across a network that creates a digital ledger of verified transactions or information among ( printed page 63975) network participants and in which cryptography is used to link the data to maintain the integrity of the digital ledger and execute other functions.[721] It provides a transparent environment for records to be created and maintained through a consensus mechanism, thereby enabling direct peer-to-peer transactions without a need for a central counterparty.[722]

Crypto networks use different types of consensus mechanisms. For example, proof-of-work requires miners to compete on solving cryptographic puzzles in order to earn the right to propose the next block, after which other nodes validate the block according to the protocol's rules. Block proposers receive rewards, which are generally crypto assets. Another consensus mechanism is proof-of-stake, where participants are able to validate blocks based on their “stake” in the network. This “stake” ( e.g., the quantity of crypto assets participants commit to the network for a period of time) acts as collateral to help ensure honest behavior by the validators. Distributed ledgers that are not blockchains typically use different types of consensus mechanisms.[723]

Ownership of a crypto asset is recorded on a crypto network, and access to the asset is controlled by a private key. A private key is a long alphanumeric string that a user who wishes to transfer assets to another user uses to authorize cryptocurrency transactions. A public key, derived from the private key, is visible to anyone and used to facilitate transactions by encrypting messages and verifying digital signatures. Hence, anyone who has access to the private key can control the crypto assets.

A private key is generally stored in a “wallet.” [724] There are two main types of wallets: software-based “hot” wallets and device-based “cold” wallets. “Hot” wallets are connected to the internet and enable faster and automated transactions. In contrast, “cold” wallets, such as paper wallets and hardware wallets, remain offline and require the private key to be accessed manually to authorize a transaction.[725] Cryptographic wallets can also be categorized as self-custodial wallets,[726] where users retain control of the private keys, and hosted wallets (also referred to as custodial wallets), where a third-party manages the private keys.[727]

There are many types of crypto assets encompassing a broad range of instruments with varying characteristics, uses, and functions, including digital commodities, digital collectibles, digital tools, stablecoins, and digital securities.[728] Many of these assets carry certain rights such as staking, yield farming, and exercising governance rights, which can be essential to the security and functionality of crypto networks and DeFi protocols. Some of these rights also provide benefits to the users. For example, when staking or yield farming, users can earn rewards, fees, or interest.[729]

Crypto assets can be traded directly between users or through intermediaries such as centralized platforms. Centralized platforms typically use a central limit order book, similar to those used by securities exchanges, as a matching system for buy and sell orders. Using a centralized platform may require users to transfer their funds or crypto assets before the transaction is completed ( i.e., the transaction may need to be “prefunded”).[730] Most crypto trading activities taking place on a centralized platform are not recorded on the network ledgers; rather, only transactions involving crypto assets being moved in or out of the platform are recorded onchain.[731] Crypto assets can also be traded via smart contracts or other non-custodial trading mechanisms that do not involve prefunding. For example, decentralized platforms are a set of smart contracts that function as peer-to-peer marketplaces where transactions occur directly between users without an intermediary being involved,[732] which typically allows users to maintain control over their crypto assets during the trading process.[733] Certain crypto asset transactions can also occur off the main crypto networks for faster and more cost-efficient execution.[734]

( printed page 63976)

The market for crypto assets has grown substantially since the advent of Bitcoin in 2008,[735] especially during the last few years. The global market capitalization for crypto assets grew from approximately $4.3 billion in January 2015 to $4.0 trillion in September 2025, before declining to approximately $2.5 trillion in March 2026.[736] The market capitalization is heavily concentrated, with the 10 crypto assets with the highest market capitalization comprising approximately 89 percent of the global market capitalization.[737] The average 24-hour global trading volume also increased, from approximately $149.6 million in January 2015 to $103.1 billion in March 2026.[738] Figure 1 plots the historical daily values of global market capitalization and 24-hour trading volume.

Figure 1: Market capitalization and 24-hour trading volume of global crypto markets. Data source: CoinGecko (April 2026).

The trading of crypto assets has also evolved substantially over time. As of April 2026, there were approximately 5,628 crypto assets traded on 814 venues globally.[739] This includes approximately 3,032 crypto assets traded on 175 centralized platforms and approximately 4,934 assets traded on 639 decentralized platforms.[740] Although the majority of spot crypto trading occurs on centralized platforms, the proportion of trading activity on decentralized platforms has increased over time. In March 2026, the average 24-hour trading volume on decentralized platforms accounted for 4.7 percent of the global trading volume, up from 2.3 percent in December 2023.[741]

( printed page 63977)

According to a report by the Office of Investor Research within the Commission's Office of the Investor Advocate, approximately 9.2 percent of U.S. adults held crypto assets as of 2025.[742] Similarly, a survey by the Federal Reserve Board found that in 2025, approximately 10 percent of adults bought or held cryptocurrencies for investment, up from approximately 7 percent in 2024.[743] According to a 2025 industry report, 22 percent of U.S. surveyed respondents owned crypto assets as of 2025, up from 14 percent in 2021.[744] In addition, according to a survey of institutional investors,[745] of the respondents that invested in digital or crypto assets,[746] 66 percent held spot crypto exchange-traded funds (“ETFs”) or exchange-traded products (“ETPs”) and 36 percent held spot crypto assets directly. Sixty-six percent of the institutional investors invested in digital or crypto assets also reported increases or significant increases in their digital asset holdings year-over-year between 2024 and 2025 and 73 percent expected to increase their allocations in 2026.[747]

According to a global report,[748] 55 percent of traditional hedge funds surveyed in 2025 had exposure to crypto assets, up from 47 percent in 2024 and 29 percent in 2023.[749] This report also indicates that family offices and high-net-worth individuals are the largest investor categories in crypto hedge funds, followed by funds of funds. In addition, the report finds that 39 percent of crypto hedge funds generate yield from custodial staking.

2. Regulatory Baseline

The custody rules govern the custodial practices of investment advisers and regulated funds to ensure the safekeeping of investors' funds, securities, and similar investments.[750] Advisers are subject to the requirements under the Advisers Act custody rule with respect to the “funds and securities” of clients that are not regulated funds.[751] Regulated funds are subject to the Investment Company Act custody rules, which govern the custody of the funds' “securities and similar investments.” Advisers of regulated funds are typically responsible for ensuring that the funds they manage comply with these regulations. The custody rules generally require, among other things, the use of a permitted custodian for the safekeeping of the applicable assets. While the rules cover a broad range of assets, they were designed to address the custody and safekeeping of traditional assets.[752]

In addition to the custody rules specifying which entities are permitted custodians and what other conditions relate to the use of such custodians, there are other requirements pertaining to the custody of assets. With certain exceptions, advisers are required to report information about custodial practices on Form ADV, and registered investment companies are required to disclose information about their custodians on Form N-CEN. In addition, rules 31a-1 and 31a-2 under the Investment Company Act and rule 204-2 under the Advisers Act regulate recordkeeping practices and require, among other things, that advisers and regulated funds keep records of all accounts, contracts, and transactions. Rule 38a-1 under the Investment Company Act requires the adoption, implementation, and annual review of policies and procedures reasonably designed to prevent violation of the Federal securities laws. Similarly, rule 206(4)-7 under the Advisers Act requires the adoption, implementation, and annual review of policies and procedures reasonably designed to prevent violation of the Advisers Act and of the rules that the Commission has adopted thereunder.

(a) Advisers Act Custody Rule

The regulatory framework regarding the custody of advisory clients' funds and securities is set forth in the Advisers Act custody rule.[753] As defined by Advisers Act rule 206(4)-2, “custody” means that the adviser, or its related persons, holds, directly or indirectly, client funds or securities, or has any authority to obtain possession of them.[754] Crypto assets that are funds or securities are in the scope of the current rule, and the Commission has recently published statements on the security status of certain crypto assets.[755] The Advisers Act custody rule applies to any investment adviser registered or required to be registered with the Commission under section 203 of the Advisers Act.[756]

The current rule requires advisers with custody of client funds and securities to maintain these funds and securities with a qualified custodian in a separate account for each client under that client's name or in accounts containing only the funds and securities of such adviser's clients and under the adviser's name as agent or trustee, subject to certain exceptions.[757] Qualified custodians generally include ( printed page 63978) banks and savings associations,[758] broker-dealers registered with the Commission,[759] FCMs registered with the CFTC,[760] and certain foreign financial institutions,[761] all of which are financial institutions that are currently subject to regular government oversight and periodic inspection and examination.[762] With respect to shares of a mutual fund, investment advisers may also use the mutual fund's transfer agent in lieu of a qualified custodian.[763] The current Advisers Act custody rule also generally requires an adviser with custody of client funds or securities to obtain an annual surprise examination from an independent public accountant to verify client funds and securities independently.[764]

The current Advisers Act custody rule also requires advisers to make certain communications to clients. An adviser is required to provide its clients notice if the adviser establishes an account with a qualified custodian on a client's behalf.[765] Advisers must also have a reasonable basis, after due inquiry, for believing that the qualified custodian sends an account statement, at least quarterly, to each of the adviser's applicable clients.[766] When an adviser has custody of funds and securities belonging to a client that is a pooled investment vehicle, these account statements must be sent to each limited partner, member, or other beneficial owner if the adviser or its related person is a general partner of a limited partnership, managing member of a limited liability company, or holds a comparable position for another type of pooled investment vehicle.[767]

Under the Advisers Act custody rule, an adviser is not required to comply with the notice and account statement delivery requirements of the rule and shall be deemed to comply with the surprise examination requirement with respect to the account of a limited partnership or other pooled investment vehicle that is subject to annual audit, provided certain conditions are satisfied.[768] To rely on this audit provision, the pool's financial statements must, among other things, be prepared in accordance with generally accepted accounting principles and distributed to all limited partners (or members or other beneficial owners) within 120 days of the end of the pool's fiscal year. The audit provision also requires the pool's financial statements to be audited by an independent public accountant that is registered with, and subject to regular inspection by, the PCAOB.

In situations where the adviser or a related person acts as a qualified custodian, the current Advisers Act custody rule requires that the adviser obtain, or receive from its related person, an annual internal control report with respect to the adviser's or its related person's custody controls.[769] The internal control report must be prepared by an independent public accountant that is registered with, and subject to regular inspection by, the PCAOB. When the adviser is required to comply with the internal control report requirement, the independent public accountants performing surprise examinations must also be registered with, and subject to regular inspection by, the PCAOB.

While the current Advisers Act custody rule addresses certain kinds of self-custody arrangements, namely, where the adviser maintains funds and securities itself or with a related person,[770] in all cases the funds and securities must be maintained at a qualified custodian.[771] Hence, this rule does not allow for arrangements where an adviser seeks to maintain client funds and securities as a custodian when the adviser or its related person does not meet the definition of qualified custodian.

(b) Investment Company Act Custody Rules

The Advisers Act custody rule does not apply to advisers with respect to accounts of regulated funds.[772] Instead, the Investment Company Act custody rules govern the custody practices of regulated funds.[773] While the Advisers Act custody rule applies to clients' funds and securities, the Investment Company Act custody rules apply to a fund's securities and other similar investments.

The Investment Company Act custody rules require that regulated funds' securities and similar investments be maintained with certain permitted custodians.[774] These permitted custodians include banks,[775] members of national securities exchanges, [776] ( printed page 63979) securities depositories,[777] FCMs and commodity clearing organizations (“CCOs”),[778] FFIs,[779] and foreign securities depositories.[780] Depending on the type of custodian used, regulated funds must meet certain requirements that are designed to help ensure the safety of their securities and similar investments. For example, when regulated funds use a member of a national securities exchange as their custodian, they must have a contract that requires segregation of fund assets from those of any other person and that includes a provision that prohibits the custodian from having authority to assign, hypothecate, pledge, or otherwise dispose of the fund's assets, except pursuant to the direction of the fund.[781] In addition, regulated funds' securities and similar investments custodied in this manner must be verified by examination at the end of each annual and semi-annual fiscal period by an independent public accountant and at least one other time, chosen by the accountant, during each fiscal year.[782]

Regulated funds may engage in self-custody under certain conditions. Specifically, securities and similar investments can be deposited in the safekeeping of, or in a vault or other depository maintained by, a bank or other company whose functions and physical facilities are supervised by Federal or State authorities.[783] The current rule requires that such investments be physically segregated at all times from those of any other person. The securities and similar investments must be verified by examination by an independent public accountant retained by the regulated fund at least three times during each fiscal year, at least two of which must be chosen by the accountant without prior notice to the regulated fund.

In addition to the requirements under the Investment Company Act custody rules, annual reports of regulated funds must include audited financial statements accompanied by a certificate of an independent public accountant.[784] The financial statements (including the regulated fund's schedule of portfolio investments) must provide data regarding the values of the regulated fund's portfolio investments as of the end of the reporting period.

(c) Recordkeeping

Advisers and regulated funds are subject to certain recordkeeping requirements regarding their custodial practices to help ensure that they make and keep current certain books and records.

The Advisers Act recordkeeping rule outlines recordkeeping requirements that apply to any registered investment adviser (or any adviser required to be registered). Advisers having custody of securities or funds of any client are required to maintain certain records relating to such client accounts.[785] For example, the Advisers Act recordkeeping rule requires, among other things, an adviser to make and keep records regarding all purchases, sales, receipts, and deliveries of securities for such accounts and all other debits and credits to such accounts, separate ledgers for such accounts, copies of confirmations of all effected transactions, a record for each security in which any such client has a position, and a memorandum describing the basis upon which the adviser has determined that the presumption that any related person is not operationally independent has been overcome.[786]

The recordkeeping requirements for regulated funds are set forth in the Investment Company Act recordkeeping rules.[787] These rules specify, among other things, what records a regulated fund must maintain and keep current and the retention periods for such records. For example, the Investment Company Act recordkeeping rules require that regulated funds maintain, among other things, a record of all purchases and sales of securities and of all receipts and deliveries of securities.[788]

(d) Custodians

While the custody rules govern what entities are permitted custodians and set forth the requirements to which advisers and regulated funds are subject when using these entities as custodians, other regulations also outline these entities' responsibilities as custodians.

Banks, whether chartered at the Federal or State level, are regulated by Federal agencies.[789] State-chartered banks that are members of the Federal Reserve System are regulated by the Federal Reserve Board. State-chartered banks that are not members of the Federal Reserve System are regulated by the FDIC. National banks and Federal savings associations are subject to OCC regulations, including when providing custody services in a fiduciary capacity.[790] In addition, the OCC has provided guidance with respect to the provision of custody services by national banks and Federal savings association.[791] For example, a custodian's accounting records and internal controls should ensure that assets of each custody account are kept separate from the assets of the custodian.[792] The OCC guidance also provides that the custodian's management has the responsibility to assess its control environment and ensure an appropriate system of internal controls, including separation of duties, and accounting controls to monitor and measure transactional workflows and their accuracy.[793] Furthermore, the OCC guidance provides specific guidelines for securities lending programs, as endorsed by the Federal Financial Institutions Examination Council. Securities under custody should not be subject to lending transactions without a written agreement between the custodian and the client.[794] Banking organizations are also required, in certain circumstances, to notify their prudential regulator no later than 36 hours after learning of a “computer-security incident,” which is defined as “an occurrence that results in actual harm to the confidentiality, integrity, or ( printed page 63980) availability of an information system or the information that the system processes, stores, or transmits.” [795]

Among other things, broker-dealers registered with the Commission under section 15(b)(1) of the Exchange Act are subject to Commission regulations. Among other rules, broker-dealers are subject to the broker-dealer financial responsibility rules, which establish a regulatory program designed to, among other things, protect customer funds and securities, ensure that broker-dealers can promptly satisfy customer claims, and maintain sufficient liquid resources to promote the prudent operation of broker-dealers.[796] For example, Exchange Act rule 15c3-1 imposes net capital requirements on broker-dealers.[797] Also, under Exchange Act rule 15c3-3, the customer protection rule, among other things, customers' assets must be segregated from the broker-dealer's proprietary assets.[798] Exchange Act rule 17a-13 requires broker-dealers to physically count, verify, and account for securities held in their physical possession or otherwise within their control or direction at least once in each calendar quarter.[799] Exchange Act rules 8c-1 and 15c2-1 generally prohibit broker-dealers from using customers' securities as collateral to finance their own trading, speculating, or underwriting transactions.

Section 17(a) of the Exchange Act requires registered broker-dealers to make and keep records, as required by Commission rules, and to furnish copies of the records to the Commission.[800] Further, section 17(b) of the Exchange Act authorizes representatives of the Commission to conduct “reasonable, periodic, special or other examinations” of “[a]ll records” of a broker-dealer. These examinations may be conducted at any time or from time to time as the Commission “deems necessary or appropriate in the public interest, for the protection of investors, or otherwise in furtherance of the purposes of the [Exchange Act.]” Exchange Act rules 17a-3 and 17a-4 require broker-dealers to make and keep, in an accessible manner, comprehensive records detailing, among other things, securities transactions, money balances, and securities positions.[801] Under Exchange Act rule 17a-11, a broker-dealer that fails to make and keep current the records required by rule 17a-3 must give notice to the Commission, to its DEA, and, if applicable, to the CFTC of this fact on the same day and, thereafter, within 48 hours transmit a report stating what the broker-dealer has done or is doing to correct the situation.[802] The rule also requires broker-dealers to provide notices and reports if they are experiencing specified financial or operational difficulties, including when, among other things, their net capital falls below 120 percent of the minimum required amount or below the minimum required amount.[803] Under rule 17a-4, the Commission may examine the books and records of any registered broker-dealer directly.[804] In addition, Exchange Act rule 17a-5 codifies broker-dealers' financial reporting requirements. It requires broker-dealers to file periodic unaudited reports containing information about their financial and operational conditions (FOCUS reports), and to annually file financial statements and certain reports, and a report covering the financial statements and reports prepared by an independent public accountant registered with the PCAOB (if registration is required by the Sarbanes-Oxley Act of 2002) in accordance with PCAOB standards.[805]

Broker-dealers are also subject to other Federal regulations. For example, broker-dealers must comply with the broker-dealer margin rules in Regulation T, which require securities customers to maintain a minimum level of equity in their securities accounts ( i.e., the customer's ownership interest in the account, computed by adding the current market value of long securities and the amount of any credit balance and subtracting the current market value of all short securities and the amount of any debit balance).[806]

Additionally, for broker-dealers that are members of FINRA, FINRA rules may set additional requirements designed to protect investors. In addition to the margin requirements in Regulation T, FINRA rule 4210 requires members to establish procedures to formulate their own margin requirements.[807] FINRA rule 3110(a) requires a member to have a system in place to supervise its activities so that it is in compliance with applicable rules and regulations.[808] FINRA rule 3120(a) requires a member to test and verify that its supervisory procedures are reasonably designed with respect to the activities of the member and its associated persons, as well as to achieve compliance with applicable securities laws and regulations and with applicable FINRA rules.[809] FINRA rule 3130(b) likewise requires that the member has in place processes to establish, maintain, review, test, and modify written compliance policies and written supervisory procedures reasonably designed to achieve compliance with applicable rules and Federal securities laws and regulations.[810] FINRA rule 4370(a) ( printed page 63981) requires each member to create and maintain a written business continuity plan identifying procedures relating to an emergency or significant business disruption, reasonably designed to enable the member to meet its existing obligations to customers.[811] Finally, FINRA rule 4530(b) states that each member shall report to FINRA promptly, but not later than 30 calendar days after the member has concluded or reasonably should have concluded, that an associated person of the member or the member itself has violated applicable laws, rules, regulations, or standards of conduct.[812] FINRA rule 2231 requires members to send statements of assets to customers no less frequently than quarterly.

Finally, broker-dealers that are members of a national securities exchange must comply with the exchange's rules of conduct.[813] These include rules to protect customers by requiring members to certify their written policies and procedures reasonably designed to comply with the securities laws and regulations,[814] requiring members to meet net capital requirements in addition to those in Exchange Act rule 15c3-1,[815] and requiring members to have business continuity plans reasonably designed meet their obligations toward customers during emergencies and business disruptions.[816] They may also include rules incorporating, as the exchange's own rules, FINRA rules discussed above.[817]

FCMs are subject to sections 4d(a)(2) and 4d(b) of the CEA and regulations issued thereunder, which require segregation of client funds from the entities' funds and impose related accounting and recordkeeping requirements.[818] In addition, the NFA examines FCMs for compliance with NFA Interpretive Notice 9070, which establishes general requirements for NFA members relating to their information systems security programs (“ISSPs”). The notice requires members to adopt and enforce written ISSPs that are reasonably designed to provide safeguards to protect against security threats or hazards to their technology systems.[819]

Securities depositories must be registered with the Commission as clearing agencies under section 17A of the Exchange Act; or a Federal Reserve Bank or other person authorized to operate the Federal book entry system described in the regulations of the Department of Treasury codified at 31 CFR 357, Subpart B, or book-entry systems operated pursuant to comparable regulations of other Federal agencies.[820]

Foreign custodians are regulated in their local jurisdictions and subject to laws and regulations established by their national jurisdictions. Requirements for the custody of assets, including of crypto assets, can vary by country and may differ from those applicable to U.S. permitted custodians.

Finally, foreign securities depositories are regulated by a foreign financial regulatory authority as defined under the Investment Company Act.[821]

(e) Effect of State Law

The relationship between clients and permitted custodians is also governed by the common law of agency and contracts, and—to the extent adopted under State law—corresponding articles of the UCC. Thus, under sections 8-504 and 8-509 of the UCC, unless otherwise agreed to, and unless duties are specified otherwise by statute, regulation, or rule, a custodian “may not grant security interests in a financial asset it is obligated to maintain” for the client and must exercise “due care in accordance with reasonable commercial standards to obtain and maintain the financial asset.” [822]

Several States have established legal frameworks to oversee and regulate State trust companies and other State-regulated entities that provide custody services, including, in some cases, specifically for the custody of crypto assets. New York has a licensing scheme for companies that conduct a virtual currency business without exercising fiduciary powers (BitLicenses), which expressly exempts fiduciary entities that are chartered under New York banking law and approved to engage in virtual currency activity: e.g., New York State banks and New York limited purpose trust companies.[823] Limited purpose trust companies are chartered under the bank and trust company provisions of the New York Banking Law; while they may be authorized to engage in virtual currency activity, they do not have the general power to accept deposits or to make loans.[824]

Wyoming law and regulations establish conditions for banks to provide custodial services for digital assets,[825] which also apply to supervised trust companies that are chartered in Wyoming.[826] South Dakota law authorizes State charters for nondepository public trust companies,[827] and banks performing digital asset services have obtained charters under this authority.[828]

3. Affected Parties and Industry Statistics

The proposed rules would affect registered investment advisers (and those required to be registered),829 registered investment companies, BDCs, as well as the current and prospective clients or investors of these entities. The proposed rules would also affect entities that are or could become permitted custodians for advisers or regulated funds under the proposed rules and independent public accountants that may provide services to these entities, advisers, or regulated funds. In addition, the proposed rules could also affect crypto asset related service providers that facilitate custodial solutions.

( printed page 63982)

(a) Registered Investment Advisers and Their Clients

As of December 2025, there were 16,442 investment advisers registered with the Commission.[830] These advisers reported $177.0 trillion in total regulatory assets under management (“RAUM”).[831] Average RAUM among advisers was $11.0 billion and the median was $477.0 million. In addition, 9.8 percent of advisers reported under $100 million, 57.3 percent reported between $100 million and $1 billion, 20.1 percent reported between $1 billion and $5 billion, 11.2 percent reported between $5 billion and $100 billion, and 1.6 percent reported $100 billion or more in RAUM.[832]

Form ADV requires investment advisers to indicate the approximate number of advisory clients and the amount of total RAUM attributable to various client types.[833] Table 1 provides information on the number of client accounts, total RAUM, and the number of advisers by client type. For example, a total of approximately 23,100 investment company clients, with a combined $67.63 trillion in attributable RAUM, were reported across 1,670 investment advisers.

As reported in Table 1, RIAs have numerous clients categorized under the “Pooled Investment Vehicles—Other” group, which mostly comprises private ( printed page 63983) funds.[834] Individuals eligible to invest in private funds are predominantly accredited investors, who must satisfy specific wealth, income, or financial sophistication criteria.[835] Consistent with this investor profile, a private fund adviser generally has broad discretion to make investment decisions on behalf of the fund.

Table 2 presents, for each type of private funds, the total number of funds, the total gross asset value of these funds, and the number of advisers reporting the funds. For example, as of December 2025, 5,912 registered investment advisers reported advising 62,637 private funds, which held $27.4 trillion in gross asset value.

(b) Investment Companies and Their Investors

Investment companies invest money they receive from investors on a collective basis, and each investor shares in the profits and losses in proportion to that investor's interest in the investment company. Regulated funds subject to the proposed rules and amendments include registered management investment companies, which include open-end funds, closed-end funds, and management company separate account (“MCSAs”), and BDCs.[836]

Table 3 summarizes the investment company universe that would be subject to the proposed rules and amendments. Many of the investment companies that would be subject to proposed rules are part of a “family” of investment companies that often share infrastructure for operations ( e.g., accounting, auditing, custody, legal) and potentially marketing and distribution. For each type of fund, this table also presents estimates of the number of investment company families and distinct entities. For example, as of December 2025, there are 14,297 investment companies, 303 families, and 1,129 distinct entities in total.

( printed page 63984)

As of December 2025, the total net assets of regulated funds were approximately $43.9 trillion. This included 8,212 mutual funds (excluding money market funds and mutual funds that offer at least one ETF share class), which held about $22.3 trillion in total net assets; 4,194 ETFs organized as open-end funds or share classes of open-end funds, holding approximately $13.0 trillion; 306 money market funds, holding approximately $7.7 trillion; 707 registered closed-end funds, holding approximately $427.7 billion; 15 MCSAs, holding approximately $279.0 billion in total net assets,[837] and 171 BDCs, holding approximately $235.3 billion in total net assets.[838] Separately, ( printed page 63985) 693 UITs held approximately $3.1 trillion in total assets.[839] An industry group estimated that at the end of 2025, 54 percent of U.S. households owned mutual funds, 15 percent owned exchange-traded funds, and 3 percent owned closed-end funds.[840]

(c) Custodians

Currently permitted custodians generally include banks and savings associations, broker-dealers, futures commission merchants or commodity clearing organizations, securities depositories, and certain foreign financial institutions and foreign securities depositories.[841] We estimate that there are approximately 728 national banks,[842] 65 national trust banks,[843] 219 Federal savings associations,[844] and 3,392 State-chartered banks and savings associations that may serve as a custodian under the custody rules.[845] We also estimate that there are approximately 484 State-chartered trust companies,[846] 269 SEC-registered transfer agents, and 55 bank-registered transfer agents.[847]

As of the end of the fourth quarter of 2025, there are 3,262 broker-dealers registered with the Commission, with 153 of them classified as carrying broker-dealers.[848] We estimate that 369 broker-dealers are members of a national securities exchange.[849] We also estimate that there are 69 futures commission merchants,[850] and 7 active clearing corporations registered with the Commission.[851] We do not have data on the number of foreign financial institutions or foreign securities depositories that are permitted custodians under the custody rules.

(d) Public Accountants

The Advisers Act custody rule generally requires an adviser with custody of client funds or securities to obtain an annual surprise examination from an independent public accountant or to rely on the rule's audit provision (for pooled investment vehicles).[852] In some cases, the independent public accountant must be registered with and subject to regular inspection by the PCAOB. First, if an adviser or its related person acts as a qualified custodian, the examination must be performed by an independent public accountant that is registered with, and subject to regular inspection by, the PCAOB. Second, the adviser that acts as qualified custodian must obtain, or receive from its related person that acts as qualified custodian, an internal control report prepared by an independent public accountant that is registered with, and subject to regular inspection by, the PCAOB. Finally, under the rule's audit provision, an adviser is deemed in compliance with the surprise examination provision with respect to the account of a pooled investment vehicle if the pooled investment vehicle undergoes a financial statement audit performed by an independent public accountant that is registered with, and subject to regular inspection by, the PCAOB, provided certain conditions are met.

The Investment Company Act custody rules require examinations by an independent public accountant when securities and similar investments are custodied with a broker-dealer, or in self-custody and maintained with a bank.[853] Regardless of the custodial practices, regulated funds must have their financial statements audited by an independent public accountant.[854] Accountants must audit the financial statements of issuers in accordance with the standards of the PCAOB for the purpose of expressing an opinion thereon.[855] Hence, regulated funds that meet the definition of “issuer” must have their financial statements audited by an independent public accountant that is registered with the PCAOB.[856]

As of December 2025, 11.9 percent of registered investment advisers (1,952 advisers) reported obtaining a surprise examination by an independent public accountant.[857] In addition, 33.5 percent ( printed page 63986) of advisers (5,509 advisers) reported that an independent public accountant audits annually the pooled investment vehicle(s) that they manage and that the audited financial statements are distributed to the investors in the pools.[858] Finally, as of December 2025, 2.2 percent of registered investment advisers (368 advisers) reported that an independent public accountant prepared an internal control report with respect to custodial services when the adviser or its related persons were qualified custodians for client funds and securities.[859]

As of May 2026, there are 1,430 accounting firms registered with the PCAOB.[860] Of those, approximately 632 are subject to regular inspection by the PCAOB.[861] Although there are no requirements to use a PCAOB-registered and inspected independent public accountant when the adviser or its related person does not act as a qualified custodian, 84.7 percent of accountants retained by advisers solely for conducting surprise examinations were reported by advisers as being registered with and regularly inspected by the PCAOB.[862] We also estimate that there are approximately 400 accounting firms reported on Form ADV as being used by advisers as independent public accountants. The 10 firms performing the highest number of reported engagements collectively account for 80 percent of engagements. We understand that auditing pooled investment vehicles may require significant investment in technology and operations and regulatory knowledge. Therefore, accounting firms conducting audits required by the Advisers Act custody rule may have capabilities to engage in additional business activities that also require PCAOB registration and inspection such as financial statement audits of public companies and broker-dealers.

(e) Crypto Service Providers

The proposed rules and amendments could also affect the providers of services related to the custody of crypto assets. For example, entities providing services related to private key creation and management, including wallet providers, as well as cybersecurity providers could be affected by the proposed rules and amendments.[863]

4. Market Practice

(a) Advisers' and Regulated Funds' Custody Practices

Registered investment advisers are required to report certain information about their custodial practices on Form ADV. As of December 2025, we observe that 9,883 advisers (60.1 percent of the total number of advisers) reported on Form ADV that they or their related persons, in aggregate, had custody of $60.8 trillion (30.1 percent of aggregate RAUM) of client assets.[864] Advisers reported having direct custody of approximately $29.5 trillion of assets and having indirect custody (through a related person) of $31.3 trillion in assets. As of December 2025, approximately 0.5 percent of all registered investment advisers (6.4 percent of aggregate RAUM) acted as a qualified custodian for their clients. Approximately 2.0 percent of all registered investment advisers (23.7 percent of aggregate RAUM) had a related person acting as a qualified custodian. We also observe that 1,446 advisers (8.8 percent of the total number of advisers) reported having a qualified custodian send quarterly statements to investors in pooled investment vehicles.

Regulated funds that are not BDCs are required to report information about their custodians on Form N-CEN. For example, 814 funds (7 percent of the total number of funds) reported having a custodian that is an affiliated person of the fund or its investment adviser.[865] In Table 4, we provide information on the number of funds reporting using each type of permitted custodian and the total net assets maintained by these custodians as of December 2025. For example, this table documents that banks hold the largest market share, both in terms of the number of fund clients (12,721) and the total net assets under their custody ($40,031 billion).[866]

( printed page 63987)

Various no-action letters, interpretive letters, and other staff statements (some of which are enumerated in section II.K), while not part of Federal regulation, relate to the custody rules and may play a role in how advisers and regulated funds comply with these rules.[867]

Furthermore, the 2009 Guidance for Accountants provides guidance on the surprise examinations and internal control reports required under the Advisers Act custody rule. For example, it sets forth several control objectives for internal control reports.

(b) Advisers' and Regulated Funds' Crypto Activity

Commission staff identified entities that are reported as custodians by registered advisers and that may specialize in crypto assets (“identified crypto custodians”).[868] We analyzed Form ADV filings for the reporting period ending in December 2025, with filings received through March 31, 2026, and identified 136 registered advisers that reported using these identified crypto custodians.[869] This suggests that at least 136 registered advisers currently have custody of crypto assets.[870]

To supplement this analysis, we also examined Form ADV Part 2A brochures. Based on an AI-assisted review of these disclosures, we identified 1,498 advisers that appear to give or plan to give investment advice related to crypto assets.[871] The set of advisers identified ( printed page 63988) by this analysis is larger than the set of advisers that report using identified crypto custodians.[872] This is likely because i) advisers providing or planning to provide advice with respect to crypto assets may not necessarily have custody of those assets, ii) advisers that do have custody of the crypto assets may use a custodian that does not specialize in providing crypto custody services or that does not appear in our list of identified crypto custodians for other reasons, and iii) some advisers may provide exposure to crypto assets indirectly, such as through derivatives or exchange-traded products that are not themselves crypto assets.

In addition, we estimate that, as of April 20, 2026, there are 10 crypto asset mutual funds with a total of approximately $432.5 million in net assets, 122 crypto asset ETFs with a total of approximately $8.7 billion in net assets and 72 crypto asset ETPs with a total of approximately $117.7 billion in net assets.[873]

We used Form N-CEN filings for the reporting period ending in December 2025, with filings received through March 31, 2026 to analyze the use of identified crypto custodians by regulated funds. We have identified only one regulated fund that reported using an identified crypto custodian.[874]

(c) Custodians for Crypto Assets

We understand that different types of entities currently offer custodial services for crypto assets. The OCC has issued three Interpretive Letters reaffirming that crypto-asset custody activities are permissible for national banks and Federal savings associations, and that these entities may buy and sell crypto assets held in custody at the customer's direction and are permitted to outsource bank-permissible crypto-asset activities, including custody and execution services, to third parties, subject to appropriate third-party risk management practices.[875] In July 2025, Federal bank regulatory agencies issued a joint statement on crypto-asset safekeeping.[876] The statement discusses existing risk-management principles that apply to crypto-asset safekeeping and reminds banks that provide or are considering providing safekeeping of such assets that they must do so in a safe and sound manner and in compliance with applicable laws and regulations. In addition, on December 12, 2025, the OCC announced conditional approvals for five national trust bank charter applications.[877] It has conditionally approved additional charters since then,[878] and multiple applications are still pending.[879] It is our understanding that many of the entities applying for these charters provide custodial services for crypto assets. Some of these entities currently are or previously were, or have related entities that are, State trust companies.[880]

( printed page 63989)

We estimate that approximately 19 State trust companies currently specialize in crypto asset custody services.[881] Under the current custody rules, a State trust company can serve as a permitted custodian (including for crypto assets) only if it meets the definition of “bank,” the determination of which typically requires a case-by-case analysis.[882]

In December 2025, the staff of the Division of Trading and Markets issued a statement on broker-dealers' obligation under rule 15c3-3(b)(1) to promptly obtain and thereafter maintain physical possession or control of all fully paid and excess margin securities it carries for the account of customers.[883] The statement provides that if the broker-dealer [884] undertakes five specified measures, the staff will not object to a broker-dealer deeming itself to have possession of a crypto asset security in accordance with the rule.[885]

Finally, crypto trading platforms and other digital native custody providers often serve as custodians for crypto assets.[886] These entities are not permitted custodians under the current custody rules.[887]

The Commission identified 136 registered advisers that reported using an identified crypto custodian.[888] These 136 advisers each reported between one and six identified crypto custodians, with an average of two identified crypto custodians per adviser.[889] Approximately half of them reported using more than one identified crypto custodian. Figure 2 provides additional information on the distribution of the number of identified crypto custodians reported per adviser as well as the average RAUM of advisers reporting different numbers of identified crypto custodians.

( printed page 63990)

Overall, advisers reported using 39 identified crypto custodians.[890] We classified these reported identified crypto custodians into four types.[891] Table 5 contains a breakdown of the different types of identified crypto custodians reported as well as the total number of advisers (and their total RAUM) who reported using them. The market for the custody of crypto assets for advisers counts a few large actors, with one custodian being reported by 76 advisers and another custodian being reported by 62 advisers. On the other hand, 22 of the 39 identified crypto custodians are reported by only one adviser. Figure 3 provides additional information on the distribution of the number of custodians being reported by different numbers of advisers.

( printed page 63991)

Using the same data, we also identified the private funds for which advisers reported using one or more of the identified crypto custodians on Form ADV. We found that 535 private funds (with a total gross asset value of $1,481.6 billion) use one or more identified crypto custodians, indicating that at least some of their holdings are crypto assets.[892] Of those private funds, the average and median gross asset values are $2.8 billion and $80.9 million, respectively. Table 6 below details these private funds by type and includes, for each type, the total number of funds, the total gross asset value of ( printed page 63992) these funds, and the number of advisers reporting the funds.[893]

C. Benefits and Costs

1. General Economic Considerations

(a) Permitted Custodians

An adviser's fiduciary duty requires the investment adviser to act in the best interests of its client at all times and to not subordinate its client's interest to its own.[894] This fiduciary duty extends to the entire relationship between the adviser and the client. Accordingly, when providing investment advice, including when managing clients' portfolios (including the portfolios of clients that are regulated funds), advisers' duty of care under the Advisers Act requires them to consider their clients' preferences regarding investment strategies and asset classes, to consider their clients' risk profiles, and to act in the best interests of their clients.

When implementing their clients' investment strategies, advisers can have custody of their clients' funds and securities and, when advisers have such custody,[895] they are generally required to maintain these funds and securities with qualified custodians for their clients that are not regulated funds.[896] Hence, when taking custody of such client assets, including crypto assets, advisers must be able to maintain those assets with custodians that have the ability to appropriately safeguard these assets, while enabling the adviser to act in the client's best interests. Similarly, the Investment Company Act custody rules generally require regulated funds to maintain their securities and similar investments with certain specified custodians.[897] While the adviser's fiduciary duty applies differently when the adviser's client is a regulated fund, an adviser performing activities related to the selection and oversight of a permitted custodian as part of its services to the regulated fund is required to act in the regulated fund's best interests, consistent with the regulated fund's investment objectives.[898]

One of the primary objectives associated with the custody of assets is to mitigate the different types of risks to which the assets are exposed, including (1) the misuse or misappropriation of the assets, (2) the loss of the assets due to the custodian's insolvency, and (3) the loss or theft of the assets resulting from the custodian's operational errors or deficiencies. Such incidents can result in significant costs for advisers and regulated funds as well as for their clients and investors.[899]

While the current custody rules apply to both traditional assets and crypto assets, custodial practices for these assets differ. Crypto assets are generated, issued, and transferred using a crypto network, on which ownership is also recorded.[900] Because of these features, crypto assets are subject to risks, including cybersecurity threats, that are different in nature or in magnitude from the risks to which ( printed page 63993) traditional assets are subject.[901] As a result, safeguarding crypto assets requires highly specialized technical knowledge, abilities, and infrastructure, including proficiency in cybersecurity practices.[902] Thus, offering robust crypto asset custodial services requires substantial resources and investments. In addition, certain technology and infrastructure required to safeguard crypto assets may be network- or asset-specific, limiting the degree to which economies of scale can offset the costs of providing crypto custodial services across different types of crypto assets.[903]

A firm looking to provide custodial services for crypto assets is therefore likely to face high fixed costs, including in the form of acquiring technical knowledge about the specific asset and the technology underlying it. High fixed costs often represent a barrier to entry into a market and can result in a relatively small number of suppliers.[904] Hence, even though, under the current custody rules, advisers and regulated funds can obtain custodial services from permitted custodians for traditional and crypto assets, the number of permitted custodians actually offering crypto asset custodial services remains generally small and we understand it to be zero for certain crypto assets.[905]

While barriers to entry are not necessarily a sign of market failure—and a small number of suppliers may be optimal in some contexts—the barriers described above may not result in the efficiencies that could justify a concentrated market. Because the technology and expertise required may be asset- or network-specific, a custodian's scale in one crypto asset may not materially reduce its cost of supporting the next, so concentration in this market may not yield meaningful efficiencies associated with economies of scale. The result is not only higher prices for custodial services but, potentially for certain crypto assets, no supply at any price. More competition in the market for crypto asset custodial services may therefore result in a wider variety of options, higher quality, and lower prices,[906] and could reduce the concentration risk that arises when a small number of custodians serve a large share of advisers and regulated funds.[907]

In addition, high barriers to entry can also make it difficult for advisers and regulated funds to find an appropriate custodian that fits their needs. For example, the available custodians may only support crypto assets with significant perceived demand,[908] or they may be unable or unwilling to provide custodial services that allow for the investor's or regulated fund's participation in certain rights or in certain crypto-native activities ( e.g., receiving airdropped assets).[909] This could prevent advisers from offering crypto-related services for which there would be demand, or from implementing their investment advice in the best interests of their clients, consistent with the client's investment objectives.[910] It could also prevent regulated funds from investing in crypto assets or from participating in associated rights or activities that would otherwise align with their investment strategy.

One of the ways in which the market has responded to these challenges is with the emergence of certain alternative custodians, including some State trust companies.[911] It is our understanding that some advisers, and possibly some regulated funds, have used or are currently using State trust companies as custodians because those State trust companies meet the definition of bank under the applicable current custody rules.[912] However, determining whether a State trust company is a bank for purposes of the custody rules requires additional legal and factual analysis from advisers and regulated funds, and the outcome of such analysis may not be clear.[913] In light of this, several crypto custodians, some of which are or previously were State trust companies, have recently applied for and, in some cases, obtained a national trust bank charter,[914] facilitating their use as custodians under the current custody rules by advisers and regulated funds. However, this outcome may not be economically optimal because applying for a national trust bank charter and operating an entity as a national trust bank, including complying with the applicable regulations, involves significant costs, which could be passed on to advisers, ( printed page 63994) regulated funds, and their respective clients and investors.[915]

Despite this market development, permitted custodians and State trust companies that would become permitted custodians under the proposed State trust company rules may not currently offer custodian services for nascent or novel crypto assets. One potential solution to this lack of available custodians is for advisers to self-custody their clients' crypto assets (including the assets of regulated fund clients). Advisers conducting extensive due diligence of the crypto asset may develop expertise on the functioning and operation of the crypto network, allowing them to be well-positioned to securely self-custody such a crypto asset and potentially to face lower costs of doing so compared to permitted custodians looking to provide custody services for those novel or nascent crypto assets. They may also be well-positioned to assess potential demand for these assets.[916] However, self-custody increases the potential for conflicts of interest, which could result in an increased risk of misuse or misappropriation of the asset by the adviser.[917] The nature of the distributed ledger technology also affects this risk. On the one hand, distributed ledger technology could mitigate custodial risk resulting from conflicts of interest by enabling real-time verification of crypto asset transactions.[918] On the other hand, because ownership is recorded pseudo-anonymously on the ledger, tracing and recovering stolen or misappropriated assets can be significantly more difficult than with traditional assets.

(b) Safeguarding Requirements

Because safeguarding crypto assets often requires highly specialized technical knowledge and abilities,[919] custodians of crypto assets are likely to be entities that have developed deep knowledge of the field and of the technology behind it. While this knowledge can help them safeguard crypto assets more effectively, it also creates an information asymmetry, where the custodian has more information than the adviser, client, regulated fund, or regulated fund investor about the technical details of the custodial services provided. Further, a custodian could, in theory, have incentives to put in place controls that are less costly, but also less effective, than what was agreed at the time when the custodian was selected by the adviser or regulated fund.[920] Thus, a principal-agent problem arises between the custodian and the adviser or regulated fund: the custodian may implement controls that are less costly but also less effective than anticipated, and the adviser or regulated fund may lack the technical knowledge to detect this deficiency.[921]

This problem can be particularly acute in the case of State trust company custodians. Most currently permitted custodians are regulated at the Federal level,[922] and Federal regulators have issued statements on the crypto asset custodial activities performed by the entities they regulate.[923] To the extent that these entities choose to follow the guidance or views outlined in these statements, these statements provide useful information to advisers and regulated funds on the type of safeguarding measures put in place by these entities. While some States have established legal frameworks on the custody of crypto assets by State trust companies, many have not, and the requirements are not uniform across jurisdictions.[924] Hence, the information asymmetry between custodians and advisers and regulated funds is likely to be greater when the custodians are State trust companies.

These challenges could result in an inefficient allocation of resources since they could result in advisers and regulated funds selecting State trust company custodians that they would not have chosen had they been able to effectively understand and monitor the work performed by these custodians. In the case of self-custody, this could result in investors choosing advisers or regulated funds they would similarly not have chosen.[925] At a wider scale, this can prevent the market from excluding custodians that do not fully comply with the custodial agreements they have with advisers or their clients, including regulated funds.[926]

Even in cases where the custodian is not the adviser (including a regulated fund's adviser) or a related person of the adviser, asymmetric information can also pose challenges in the relationship between an adviser and its clients and between a regulated fund and its investors, which can result in an ( printed page 63995) additional inefficiency in the allocation of resources. When choosing an adviser or a regulated fund, an investor may have limited access to information on how the adviser or regulated fund chooses the custodian, including the weight that is placed on the proper safeguarding of the assets compared to the costs of using a specific custodian, for example.[927] An investor may also have limited visibility and limited ability to observe or independently monitor the adviser's or regulated fund's oversight of the custodial services provided.[928] Further, the adviser or regulated fund could, in theory, have incentives to choose a custodian that provides a level of safeguarding services that may be less robust than what the investor anticipates in order to reduce its costs. Hence, there is also a principal-agent problem between the adviser and its clients or the regulated fund and its investors.[929] This could result in investors choosing advisers or regulated funds that they would not have chosen had they had better information.

In the next sub-sections, we describe the benefits and costs associated with the proposed rules and amendments. We discuss how the proposed self-custody rules and State trust company rules would help alleviate the economic challenges resulting from the small number of available custodians for crypto assets.[930] We also discuss how the conditions and requirements under these proposed rules would help alleviate the principal-agent problems described here.

The sections below discuss different costs that would or could be incurred by advisers and regulated funds, including costs that could be passed on to them from third parties such as custodians. We expect that some of these costs would be passed on to advisory clients or regulated funds' investors, for example via higher fees or expenses. We expect that the extent of this passthrough would depend on factors such as the size of the client or investor (institutional investors may have more bargaining power and be better able to negotiate smaller fees or avoid fee increases) or the type of contract in place between the adviser and the client (for example, such contract could include fixed fees or variable fees).

2. Adviser Self-Custody

The proposed adviser self-custody rule would allow advisers to hold client crypto assets for which they provide investment advice without maintaining them at a qualified custodian, under certain conditions designed to protect these assets. These conditions include a written determination by the adviser that a qualified custodian is not available to maintain the crypto assets, a requirement that the adviser have appropriate safeguarding expertise, and the adoption, implementation, and maintenance by the adviser of systems and processes necessary to safeguard the crypto asset against loss, theft, misuse, and misappropriation.[931]

(a) General Considerations

An adviser with custody of client funds or securities is generally required to maintain these assets at a qualified custodian under the Advisers Act custody rule.[932] Although there has been an increase in the number of qualified custodians offering custodial services for crypto assets,[933] and we anticipate this number to continue growing, it remains possible that certain crypto assets lack qualified custodians.[934] For example, qualified custodians may not be able to provide custodial services for all new crypto assets or may decide not to support a particular crypto asset for business or other reasons.[935] Thus, some advisers may currently be unable to provide some crypto-related advisory services to their clients. However, advisers may be well positioned to securely maintain some of the crypto assets and/or to do so on a timelier basis than a qualified custodian.[936] In addition, advisers conducting extensive due diligence of the crypto asset may develop expertise on the functioning and operation of the associated crypto network, which may allow them to better assess the potential demand for those assets and also to incur lower costs to custody them.[937] The proposed adviser self-custody rule would allow advisers to hold client crypto assets for which they provide investment advice without maintaining them at a qualified custodian,[938] under certain conditions that are designed to protect these assets.[939]

The proposed adviser self-custody rule would benefit investors by enhancing their access to advisory services and investment options for crypto assets for which a qualified custodian is not available. For example, the proposed adviser self-custody rule would allow advisers to offer investments in nascent crypto assets upon or shortly after launch.[940] To the extent that advisers would offer a greater variety of strategies involving ( printed page 63996) crypto assets under the proposed adviser self-custody rule, this may further benefit investors through increased diversification.[941]

The conditions under the proposed adviser self-custody rule would act as guardrails when advisers self-custody client assets and would benefit investors by mitigating the custodial risks of self-custody. Specifically, because of the potential for conflicts of interest that arises when the adviser is also the custodian, self-custody of clients' assets may result in an elevated risk of misuse or misappropriation compared to custody by an independent party.[942] Requirements that facilitate independent oversight, such as the proposed internal control report and recordkeeping requirements, as well as some of the safeguarding requirements, such as the proposed joint authorization requirement, would mitigate this risk. Moreover, some of the proposed requirements, such as those related to the adviser's safeguarding expertise and systems and to cybersecurity, would mitigate operational risks that could result from self-custody, as providing custodial services is beyond the scope of advisers' core business activities. Hence, we expect that these provisions would help reduce the risk of permanent loss of crypto assets in self-custody.[943]

We expect that the benefits of permitting self-custody would vary depending on the investment strategies offered by an adviser. For instance, advisers of clients whose investment strategies do not involve crypto assets or involve crypto assets for which qualified custodians are available are expected to see no benefits other than having the option to use self-custody for investments in crypto assets in the future.[944] Conversely, advisers of clients whose investment strategies involve exposure to crypto assets for which no qualified custodian is available, as well as these clients, would benefit more from the proposed adviser self-custody rule.[945]

The benefits could also vary depending on the size of an adviser. Having expertise, systems, and controls to self-custody crypto assets, as would be required under the proposed rule, is costly; an adviser may reasonably conclude that it does not have the resources to take advantage of the proposed rule to adequately safeguard client crypto assets.[946] Thus, smaller advisers may elect not to self-custody crypto assets.[947] Consequently, their clients would not benefit from the proposed adviser self-custody rule. Conversely, larger advisers could have adequate resources to meet the proposed safeguarding requirements and be more likely to offer self-custody to clients. The clients of such advisers would be more likely to benefit from the proposed adviser self-custody rule.

Advisers that would implement self-custody of client assets would incur direct costs to comply with the proposed adviser self-custody rule, most of which would likely be passed on to their clients and thus be reflected in fees or expenses.[948] We estimate certain one-time compliance costs of $173,499 and certain recurring annual compliance costs of $57,833 per adviser that would have self-custody of client crypto assets.[949] These estimates include costs that are associated with the adviser obtaining information or delivering communications. They also include costs associated with the proposed financial asset election requirement.[950]

Compliance costs would likely vary based on assets managed by advisers. Generally, advisers with more crypto assets and more types of crypto assets in self-custody would incur higher costs in absolute terms as the proposed requirements would apply to each crypto asset.[951] However, the cost per dollar of assets under management ( i.e., the total cost of self-custody divided by the adviser's RAUM, “per-dollar costs”) may be lower for large advisers. First, some costs, such as those associated with the QC determination and implementation of safeguarding systems and controls, could be distributed among a large client base, reducing the associated compliance per-dollar costs. Additionally, economies of scale could sometimes be achieved across crypto assets. For example, although many crypto assets have unique characteristics and require specific technology or infrastructure, certain aspects of safeguarding systems and cybersecurity measures may apply to multiple types of crypto assets. This means that the marginal cost to self-custody additional types of crypto assets may decrease as advisers provide self-custody for a larger set of crypto assets. Furthermore, costs may vary depending on each adviser's market power and their ability to negotiate with third-party service providers that facilitate self-custody related activities. Large advisers may be able to obtain better terms in these contract negotiations. We also anticipate that some of the compliance costs and other economic costs would likely be borne at the family level ( i.e., divided between the entities that are part of the family), so advisers and ( printed page 63997) funds belonging to a large family would incur lower costs.[952]

There may also be some indirect costs to investors related to the proposed adviser self-custody rule. First, despite the protective conditions we propose, because custodial services extend beyond the services usually provided by advisers, the operational risks of adviser self-custody could still be elevated, which could potentially lead to the loss or theft of clients' crypto assets.[953] Second, the digital nature of crypto assets and networks exacerbates the negative impact of potential vulnerabilities in custodial infrastructure and associated cybersecurity risks, which could result in significant financial loss following from a cybersecurity incident.[954] Third, there is inherent heightened misuse or misappropriation risk when the adviser directly controls client assets that follows from the potential for conflicts of interest.[955] To the extent that, as a result of these factors, an adviser's safeguarding systems are less robust than those of a qualified custodian that offers custodial services for similar crypto assets, the proposed adviser self-custody rule could result in indirect costs to some investors due to the heightened custodial risks.

Several conditions of the proposed adviser self-custody rule would require an adviser to assess and document its own safeguarding capabilities,[956] raising the question whether those conditions would reliably distinguish advisers capable of safeguarding crypto assets from those that are not. The proposed rule's framework would not rely on self-assessment alone. An independent public accountant would evaluate the design and effectiveness of the adviser's controls; [957] joint authorization would help prevent one person from effecting a transaction; [958] client-specific addresses and account statements would identify where assets are held; [959] a regulated fund's board would make and review specified determinations; [960] and the adviser's and, if applicable, regulated fund's determinations and records would be subject to Commission examination.[961] The conditions would also impose largely fixed costs,[962] which, together with the proposed QC determination requirement, could limit self-custody to advisers with sufficient scale in crypto assets for which no permitted custodian is available. These costs, however, do not directly establish safeguarding competence. Clients could also verify balances and transactions at disclosed crypto asset addresses, reducing information asymmetry, although such verification would not establish that all client assets are held at those addresses, that key materials remain secure, or that the assets are free of undisclosed encumbrances.

As an adviser would only be permitted to rely on the proposed adviser self-custody rule when it has a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset, the degree to which advisers would rely on the proposed rule may decrease over time. Specifically, over time, the number of qualified custodians offering custodial services for a wider range of crypto assets is likely to increase.[963] As crypto assets held in self-custody by the adviser increasingly would no longer meet the proposed QC determination requirement, the degree to which advisers would rely on the adviser self-custody rule would diminish. In addition, advisers could have self-custody of only a small number of crypto assets, or could be able to have self-custody for only a very short period of time. Furthermore, an adviser would be permitted to rely on the proposed adviser self-custody rule only with respect to crypto assets for which they provide investment advice, preventing them from serving primarily as custodians of crypto assets, rather than providers of investment advice. To the extent that costs associated with the requirements of the proposed adviser self-custody rule are largely fixed, this could make self-custody uneconomical for many advisers. Therefore, advisers may be unwilling to incur such costs and may choose not to have self-custody of crypto assets. This would decrease the benefits and costs associated with the proposed adviser self-custody rule.[964]

(b) Scope of Activity Subject to the Proposed Adviser Self-Custody Rule

(1) Definition of Self-Custody

The proposed rule would add a new term “self-custody” to mean, with respect to a client's crypto asset, possession of any portion of the crypto asset's key materials.[965] An adviser with self-custody of clients' crypto assets would be required to comply with the self-custody rule with respect to such crypto assets only if the adviser actually possesses (rather than merely having the authority to obtain possession of) the key materials to the crypto asset.[966]

Investors would benefit from the proposed definition of self-custody as it would help ensure safekeeping of all the key materials associated with a crypto asset. Loss of any portion of private keys could result in permanent loss of a client's crypto assets. Therefore, the application of the adviser self-custody rule when an adviser holds even any portion of the key materials would mitigate the associated risks because advisers would be required to comply with the proposed protective conditions.

The proposed conditions to safeguard clients' crypto assets are important as transactions are generally irreversible. In addition, as advisers' primary business area is not custody, the required conditions associated with the safeguarding systems and cybersecurity practices may differ from the practices they have adopted or would have adopted otherwise. As a result, these conditions would help ensure protection of clients' crypto assets when these assets are self-custodied by advisers.

Advisers having self-custody of client crypto assets would be required to comply with the requirements under the proposed adviser self-custody rule and would incur compliance costs ( printed page 63998) associated with these requirements, as discussed below.[967]

(2) Use of Service Providers

The proposed adviser self-custody rule generally would not prevent advisers from engaging a third-party or related person service provider to support its effectuating of crypto asset self-custody and to help administer the required safeguards under the proposed rule, provided the adviser exercises appropriate oversight and continues to comply with the proposed rule's substantive requirements.

Using service providers could benefit advisers and their clients. Advisers typically do not specialize in custody operations, and they may need to or choose to engage service providers to comply with the proposed self-custody requirements. Alternatively, advisers may choose to develop in-house systems instead of retaining such providers. However, the development of these safeguarding systems may be prohibitively expensive and may not provide the same level of safeguarding as those offered by the specialized service providers since custody is not advisers' primary area of business. The proposed guidance would therefore allow the use of service providers while specifying under which conditions advisers would be permitted to use such service providers, thereby allowing advisers to comply with the proposed adviser self-custody rule more efficiently by reducing cost and helping ensure the safeguarding of clients' crypto assets.[968]

Advisers that engage with service providers to have self-custody of crypto assets may incur costs associated with ensuring that the service providers do not have the ability to access the key materials. For example, an adviser may incur costs related to due diligence before engaging the service provider and to subsequent ongoing oversight and monitoring. While these providers generally would assist with managing key materials and developing security systems but would not be permitted to have access to the key materials, a lack of adviser oversight could create safeguarding risks.

(c) Airdropped Crypto Assets

An adviser holding a client's, including a regulated fund's, crypto asset at a permitted custodian or in self-custody under the proposed self-custody rules may receive a new crypto asset through an airdrop with little or no advance notice. Permitted custodians may not immediately offer custodial services for airdropped crypto assets or immediate compliance with the proposed self-custody rules' requirements with respect to a distributed crypto asset received with little or no advance notice may not be possible.[969] In these cases, advisers may need to have self-custody of these airdropped crypto assets without having had sufficient time to comply with the proposed custody rules' requirements.

The proposed Advisers Act custody rule and proposed rule 17f-9 under the Investment Company Act each would include a provision for such distributed crypto assets that would deem the receipt of airdropped crypto assets to not be in violation of the Advisers Act custody rule and section 17(f) of the Investment Company Act and the rules thereunder, as applicable, provided that, as soon as reasonably practicable, the adviser or regulated fund either (i) comes into compliance with the requirements of the proposed adviser self-custody rule and proposed rule 17f-9(b) under the Investment Company Act, as applicable, with respect to such distributed crypto asset; or (ii) places and maintains the distributed crypto asset at a permitted custodian.[970]

Advisory clients, including regulated funds, as well as regulated funds' investors would benefit from the proposed airdrop provisions as advisers could use the airdropped crypto assets to, for instance, sell them and generate a profit for their clients.[971] Clients, advisers, and regulated fund investors would also benefit from the proposed provision for airdropped crypto assets as a reasonably practicable compliance timeline would provide a grace period to comply with the Advisers Act and Investment Company Act custody rules, as applicable, and thus to adequately safeguard the airdropped crypto assets by either holding them in their self-custody or placing them at a permitted custodian.

While this flexibility would provide benefits for investors, airdropped crypto assets could be subject to increased custodial risks until the adviser and regulated fund, as applicable, are fully in compliance with the proposed self-custody rules' requirements. Custodial risks—including risk of loss, theft, misuse, or misappropriation—could become more pronounced when an adviser's actions to safeguard client assets are delayed. Additionally, advisory clients, including regulated funds, who receive high-value airdropped crypto assets could be exposed to increased risks.

(d) Qualified Custodian Determination

To be permitted to self-custody clients' crypto assets, advisers would be required to, among other things, have a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset.[972] Advisers would have to make this determination in writing, prior to taking self-custody of each crypto asset, and no less frequently than quarterly thereafter.[973]

The proposed QC determination requirements would benefit investors by limiting the type of crypto assets that are eligible for self-custody and specifying the circumstances under which self-custody is permitted. Maintaining assets with a qualified custodian is a way to mitigate custodial risk and adviser self-custody carries inherently heightened risks due to a lack of independent oversight when the adviser has the ability to change a client's ownership and possession of assets.[974] Therefore, the proposed QC determination requirements would benefit investors by helping ensure that client assets would be maintained with a qualified custodian that has the capability to safeguard the client's assets whenever such qualified custodian is reasonably determined to be available.

Because the crypto custodial service market is rapidly evolving, we expect the availability of qualified custodians and the services they provide to change as well. As a result, the quarterly determination would protect investors by ensuring that advisers would maintain crypto assets with an available qualified custodian following their next QC reassessment, limiting the period of self-custody to no more than one quarter after a qualified custodian becomes available.[975]

( printed page 63999)

Advisers would also incur costs related to the proposed initial and quarterly determinations.[976] Specifically, an adviser would incur costs when conducting an analysis to obtain a reasonably comprehensive understanding of the marketplace of custody services for each crypto asset it self-custodies or intends to self-custody on behalf of its client. These costs may vary based on factors such as the type of assets, the diversity of assets, the holding period of these assets, and investment strategies. For instance, an adviser holding relatively homogenous crypto assets may only have to monitor a single market for the availability of custodial services. In contrast, an adviser managing a variety of asset types would likely incur overall higher costs due to the need to evaluate custodial services across multiple markets, although there may exist some economies of scale in conducting this kind of market research.[977] Because advisers are required to make a quarterly determination for the assets in self-custody, advisers making short term investments would need to make fewer determinations for a given asset and, as a result, incur lower costs.

The proposed QC determination provision could also result in indirect costs for advisers and their clients. In some cases, maintaining the client crypto assets at a qualified custodian may be more expensive than maintaining them in self-custody or may result in the safeguarding services being of lower quality (for example, because the adviser has specific knowledge about the asset and the associated crypto network infrastructure that the custodian does not have). When a qualified custodian becomes available, an adviser would have to transfer the asset to the custodian, sell the client asset, or, depending on the type of client, transfer the asset to the client.[978] Transferring the crypto asset (to a qualified custodian or a client) could result in less effective safeguarding, including potential risks associated with transferring the asset.[979] Transferring the crypto asset to a qualified custodian would also create additional costs associated with putting in place a custodial services agreement between the client and the new custodian.[980] Finally, having to sell the crypto asset could result in lost investment opportunities for the clients.

In addition, the possibility of a qualified custodian becoming available after an adviser undertakes the investment to develop the systems necessary for self-custody also limits the degree to which we anticipate advisers planning to offer strategies for which no qualified custodian is currently available and which would make use of the proposed adviser self-custody rule.

(e) Safeguarding and Cybersecurity Measures

Advisers would be required to have safeguarding expertise and systems when relying on the adviser self-custody rule.[981] Specifically, the proposed adviser self-custody rule would specify that advisers must have safeguarding expertise for each crypto asset in self-custody and adopt, implement, and maintain the systems, including the appropriate technology, software, hardware, and other associated systems and processes around their use, necessary to safeguard each crypto asset against loss, theft, misuse and misappropriation. The proposed adviser self-custody rule would also specify that such systems must, at a minimum, (1) manage and protect key materials against loss and unauthorized access, (2) prevent unauthorized transfers, including through joint authorization requirements for transfers of crypto assets, and (3) maintain each client's crypto assets in one or more crypto asset addresses on the crypto network storing only such client's crypto asset.[982]

Additionally, advisers would be required to mitigate cybersecurity risks, including by implementing (1) periodic but no less than annual written assessments of cybersecurity risks to crypto assets in the adviser's self-custody and cybersecurity risks associated with the adviser's safeguarding systems; (2) measures reasonably designed to detect, mitigate, and remediate any cybersecurity threats and vulnerabilities with respect to the adviser's safeguarding systems; and (3) measures reasonably designed to detect, respond to, and recover from a cybersecurity incident relating to the adviser's safeguarding systems.[983]

The proposed adviser self-custody rule would also require advisers to review their safeguarding systems and the cybersecurity controls implemented pursuant to the proposed cybersecurity requirement within a year of taking self-custody of each crypto asset and no less frequently than annually thereafter.[984]

To the extent that the proposed safeguarding expertise and systems requirements would lead advisers to modify their practices and systems to more effectively safeguard crypto assets, the proposed adviser self-custody rule would benefit investors by reducing the risk that their crypto assets be subject to loss, theft, misuse, or misappropriation by an adviser.[985]

Specifically, the proposed safeguarding measures regarding key management, joint authorization, and asset segregation would benefit investors by helping ensure advisers are well-positioned to offer custody services. As advisers do not customarily provide custody services and are not subject to other extensive regulatory requirements for custodial services, a robust key management program requirement is essential to prevent the loss or theft of crypto assets, particularly because recovery of transferred crypto assets is typically more challenging compared to traditional assets.[986] Similarly, requiring advisers to implement an authorization policy that mandates joint authorization for crypto ( printed page 64000) transactions and restricts key access to designated individuals would likely reduce the risk of erroneous or fraudulent transactions that could lead to irreversible asset loss, thereby protecting investors from potential harm.[987] Additionally, segregating client assets from other entities' assets (including the adviser's proprietary assets) would reduce the risk of advisers misappropriating client assets and help protect investors from insolvency or bankruptcy of the adviser or its related persons, as client assets would be better protected from claims by third parties seeking to satisfy obligations of the adviser.

Segregating clients' assets from other clients' assets would also facilitate easier identification of and access to assets, reduce the potential for operational errors related to misidentification or transfer of client assets, and enhance transparency and verifiability of the ownership of clients' crypto assets. Additionally, maintaining crypto assets in separate crypto asset addresses for each client could mitigate the risk and potential loss subsequent to a cybersecurity attack, as the amount of assets held in each address would be smaller compared to what would be held in an omnibus account that includes many clients' crypto assets together.[988]

Furthermore, the proposed requirement for advisers to mitigate cybersecurity risks would also benefit advisers and their clients. The principle-based proposed core elements would allow advisers to adapt their systems in line with the industry-developed practices, while helping to ensure that all required standards are consistently maintained.[989] For example, a periodic risk assessment would enable advisers to accurately identify significant risk factors and better prepare for cybersecurity threats, thereby reducing the likelihood of cybersecurity incidents and enhancing investor protection. An adviser holding a client crypto asset in self-custody for less than a year would not be expected to conduct this period risk assessment, and the adviser would not incur such costs. However, if a material cybersecurity risk were to arise or if there were to be an internal or external change that could require a risk assessment before the periodic risk assessment due date, advisers would be required to conduct the risk assessment. Additionally, detection, mitigation, and remediation measures would also benefit investors by lowering the impact of cybersecurity attacks, such as by reducing the duration of exposure and limiting the scope of assets exposed, thereby reducing the likelihood of further compromising the safety of other assets under an adviser's self-custody and minimizing financial losses during adverse events. Response and recovery measures would benefit investors by helping to ensure business continuity during adverse events and minimizing disruptions to adviser-provided services.

The proposed requirement for advisers to conduct annual reviews of safeguarding systems and the cybersecurity controls implemented pursuant to the proposed cybersecurity requirement would additionally provide benefits for investors. Technological developments, compliance issues in the prior year or changes in the adviser's business activities may necessitate updates to safeguarding systems for adviser's self-custody of crypto assets. The proposed annual review requirement would help ensure that the adviser's safeguarding systems and cybersecurity measures continue to work as designed and remain effective, thereby enhancing investor protection. Furthermore, because an outdated system would likely increase cybersecurity risks and operational deficiencies and put assets in custody at risk, the annual reviews would help ensure the advisers' safeguarding systems remain adaptive and benefit investors by allowing advisers to leverage current industry-developed practices while adapting their systems and controls to technological advancements and innovations. To the extent that an adviser would not hold any client crypto assets in self-custody by the time an annual review would be due, the adviser would not be expected to conduct this annual review, and these benefits from the annual review could not apply.

Advisers that would offer self-custody services would likely incur both initial and ongoing costs related to the development of safeguarding expertise, the implementation of a safeguarding system, and the documentation of the material facts that demonstrate an adviser's ability to safeguard each crypto asset.[990] Relatedly, advisers would incur costs to implement cybersecurity protocols tailored to their safeguarding systems. Specifically, advisers may incur costs acquiring or developing appropriate technology, software, hardware, and/or other accompanying third-party services for establishing, implementing, and overseeing the appropriate systems and processes. There would likely be costs associated with wallet setup and key management systems for each crypto asset for each client.[991]

Advisers would also incur costs associated with annual review of safeguarding systems and the cybersecurity controls implemented pursuant to the proposed cybersecurity requirement with respect to each crypto asset they self-custody.[992] As a result of this review, there could be additional costs if the adviser would be required to update its safeguarding systems and cybersecurity controls to ensure that they remain effective and work as designed. To the extent that an adviser does not hold any client crypto assets in self-custody by the time an annual review would be due, the adviser would not be expected to conduct this annual review as the adviser would no longer be subject to the adviser self-custody rule, and the adviser would not incur such costs.

In addition, advisers would also incur costs to design and implement policies and procedures reasonably designed to prevent violations of the Advisers Act and rules under the Act, as required by the Advisers Act compliance rule.[993]

We expect advisers that maintain a greater variety of crypto assets or crypto assets with complex network ( printed page 64001) technological specifications to incur higher costs to implement safeguarding systems. These costs may also vary depending on the type of crypto assets in self-custody. For example, commercial-grade cryptographic wallet solutions may be available for certain crypto assets only, and the costs associated with acquiring robust wallet technology may also vary depending on the technical complexities inherent to each crypto network. To the extent that certain crypto networks are more susceptible to cybersecurity attacks and other vulnerabilities, the costs to implement effective safeguarding systems may be higher.[994] For example, certain crypto assets may require cybersecurity practices such as more frequent risk-assessments due to their evolving vulnerabilities; consequently, advisers that self-custody these assets may incur higher costs. The total costs to implement safeguarding measures covering multiple crypto assets would likely be higher, as distinct cybersecurity threats may exist for different crypto assets and their associated networks. However, to the extent cybersecurity controls can be applied to a larger set of crypto assets, per-dollar costs may be lower due to economies of scale.

Additionally, we expect the implementation of safeguarding systems and cybersecurity measures to differ across advisers.[995] As a result, the costs would vary based on the design and implementation of these protocols as well as each adviser's experience and current practices.[996] To the extent that advisers lack expertise in managing crypto assets or do not have existing safeguarding expertise or technology to implement safeguarding systems, the costs to develop the expertise and necessary safeguarding systems to comply with the proposed requirements would likely be higher. Conversely, for advisers with experience in cybersecurity controls, the costs of implementation would likely be lower. Additionally, advisers may be currently implementing cybersecurity measures consistent with the proposed core elements of the cybersecurity measures under the proposed adviser self-custody rule.[997] These advisers would also incur lower compliance costs associated with implementation of such measures.

While we anticipate that the proposed safeguarding and cybersecurity measures would reduce the risk of loss, theft, misuse, or misappropriation that crypto assets would be subject to, the effectiveness of safeguarding systems and their associated cybersecurity controls may vary. For example, custodial solutions for certain assets may necessitate more expensive measures, such as more advanced wallet technology or sophisticated cybersecurity controls, because of unique technical specifications or cybersecurity vulnerabilities associated with certain networks. To the extent an adviser fails to allocate sufficient resources or overestimates its safeguarding capabilities, such an adviser's safeguarding systems may be deficient in protecting client assets. Thus, we anticipate that the proposed safeguarding and cybersecurity measures would not eliminate all residual custodial risks and operational errors that could lead to inadvertent asset loss.

(f) Internal Control Reports

The proposed rule would require advisers with self-custody of clients' crypto assets to obtain a written internal control report prepared by an independent public accountant within six months of having self-custody and no less than once each calendar year thereafter.[998] The report must include an opinion of the independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of crypto assets held by the adviser on behalf of its clients.[999] In addition, the proposed rule would also require that the independent public accountant verify that the crypto assets are reconciled to the crypto network.

The proposed initial internal control report requirement would benefit investors by providing an important check on the safeguards relating to client crypto assets held by the adviser, thereby mitigating custodial risks and enhancing investor protection. The proposed annual internal control report requirement could increase the likelihood that significant control issues are detected and addressed on a regular basis. Specifically, independent assessment would likely help mitigate conflicts of interest when advisers, rather than unaffiliated custodians, custody client assets. In addition, the proposed verification of the reconciliation of the clients' crypto assets requirement would facilitate the detection of misconduct, thereby discouraging potential fraudulent behaviors, lowering agency costs, and protecting investors. Additionally, the proposed requirement that these reports be prepared by a public accountant that is independent of the adviser could also enhance both investor protection and investor confidence by further mitigating agency costs. To the extent that an adviser with self-custody of client crypto assets moves the crypto assets to a qualified custodian that becomes available before an internal control report would be due and does not hold any other crypto asset in self-custody, investors could lack these benefits from the internal control report that would otherwise be due.

Advisers would incur costs in obtaining the initial and annual internal control reports. We estimate that on average, the cost of obtaining an internal control report would be $376,000 per year per adviser with self-custody of client crypto assets.[1000] This cost may vary based on the number and type of crypto assets in self-custody as well as the complexity of their safeguarding systems. Specifically, advisers that have self-custody of various types of crypto assets may incur higher costs because they are likely to have more complex safeguarding systems and require internal control reports related to different networks. Advisers holding crypto assets with unique technical challenges or those within intricate networks requiring specialized attestation expertise for verification of the reconciliation may also incur higher costs. To the extent that an adviser with self-custody of client crypto assets moves the crypto assets to a qualified custodian that becomes available before ( printed page 64002) an internal control report would be due and does not hold any other crypto asset in self-custody, the adviser would not need to obtain that internal control report that would otherwise be due and would not incur the associated costs.

Additionally, to the extent that advisers choose to have self-custody of clients' crypto assets, the demand for accountants to prepare internal control reports would increase, which may result in higher costs for these services. Furthermore, increased demand may place some pressure on the supply of independent public accountants who have the knowledge and skills to prepare internal control reports with respect to the custody of crypto assets. This could create a challenge for advisers in engaging an independent public accountant, by either imposing a high cost on advisers that would seek to offer self-custody services or potentially making it economically not viable to do so. This challenge could be more pronounced for small advisers that have limited crypto assets under self-custody and limited bargaining power when negotiating with accounting firms. As a result, such advisers may have more limited access to qualified audit firms compared to larger advisers.[1001]

(g) Account Statements to Clients

Under the proposed adviser self-custody rule, advisers with self-custody of clients' crypto assets would be required to send each client an account statement—or alternatively, to transmit information or arrange for the transmission of the information otherwise required to be in an account statement in a human-readable and reasonably usable electronic format, provided that a notice is sent to the client—at least quarterly, with certain exceptions.[1002] These account statements (or transmissions) would be required to identify the crypto address that stores the client's crypto assets and the crypto network on which such crypto address operates, to identify the amount of crypto assets in the account at the end of the period and set forth all transactions in crypto assets in the account during the period, and to include a statement urging the client to compare the account statements from the adviser with the crypto asset balances and transaction information indicated under the client's crypto asset address. If an adviser or a related person is a general partner of a limited partnership (or a managing member of a limited liability company, or holds a comparable position for another type of pooled investment vehicle), the account statements, transmission, and any notices would be required to be sent to each limited partner (or member or other beneficial owner).[1003] In addition, the proposed rule would allow any account statements, transmissions and notices sent pursuant to this requirement to be delivered to the client's independent representative.[1004]

Quarterly account statements would provide transparency and verifiability of records, facilitating easier comparison between records from advisers and data from other independent sources ( e.g., onchain records). These statements would increase the likelihood of timely detection of any misappropriation, discourage fraudulent reporting, and mitigate the impact of adverse events while facilitating asset recovery. For example, software tools could enable real-time access to crypto asset balances and transaction records on the crypto network.[1005] Transmission of information using these tools could benefit clients by enabling them to review each transaction and balances directly and promptly on the crypto network in an easily readable format, reducing the risk of fraud by keeping clients informed about their crypto assets and facilitating prompt detection of suspicious activities. Therefore, alternative ways for transmitting information would offer benefits similar to those offered by account statements, to the extent that clients would be capable of using these tools and the information transmitted would be readily interpretable, thus clients could effectively identify potentially suspicious activities and achieve results comparable to those obtained by reviewing account statements. Such flexibility would also benefit advisers by aiding effective communication without imposing unnecessary compliance burdens.[1006]

Advisers having self-custody of clients' crypto assets would incur direct costs associated with preparing and sending account statements.[1007] However, to the extent that third-party services and tools supporting the transmission and delivery of such records become available, these costs may decrease over time. These costs may also vary across advisers. Advisers having a larger number of clients for which they self-custody crypto assets may incur higher absolute costs but lower per-dollar costs because of economies of scale.

Under the proposed adviser self-custody rule, an adviser would not be required to comply with the self-custody account statement requirement if it has self-custody of crypto assets for a pooled investment vehicle client that undergoes a financial statement audit at least annually and upon liquidation in accordance with the audit provision. An adviser would also not be required to comply with the proposed self-custody account statement requirement if the advisory client is a regulated fund,[1008] which is subject to annual audit. While audited financial statements provide an important check on adviser behavior and can identify erroneous or unauthorized activity, they are prepared and sent annually. As a result, they may not offer the same timeliness of fraud or error detection as quarterly account statements. However, for pooled investment vehicles and regulated funds, the annual audit is considered sufficient in light of the additional controls in place ( e.g., independent oversight, board review, and regulatory requirements) and the effectiveness of audits in detecting material misstatements or misappropriation.[1009] We do not expect that the account statement exception would reduce investor protection for pooled investment vehicle or regulated fund investors since account statements and audited financial statements provide comparable means to identify any erroneous or unauthorized activity as financial statement audits involve confirming account balances and transactions.

(h) Financial Asset Election

The proposed adviser self-custody rule would require an adviser and the ( printed page 64003) client to agree, in writing, to treat each crypto asset held in the adviser's self-custody for such client as a financial asset, and that the adviser holding the client's crypto asset in self-custody is a securities intermediary, pursuant to applicable State law that governs the written agreement between the adviser and the client.[1010] In addition, under this proposal, an adviser would be required to retain copies of these financial asset elections.[1011]

State law governs the written contractual treatment of an asset as a financial asset and a party to the written agreement as a securities intermediary pursuant to the applicable State's enacted version of Article 8 of the UCC. Article 8 of the UCC governs how financial assets are held by a securities intermediary that maintains securities accounts for others ( e.g., a clearing corporation, broker-dealer or a bank). The financial asset election, accompanied by the adviser crediting the asset to the client's securities account on the adviser's records, would enable the client to obtain a security entitlement and become an entitlement holder.[1012] This would provide certain protections and priorities to the client: for example, the adviser, as a securities intermediary, would be required to maintain the financial asset in sufficient quantities corresponding to all security entitlements with respect to the asset; the financial asset would not be the property of the adviser, and would generally not be subject to claims of creditors of the adviser; and the client would have priority of claims to the financial asset over the claims of other creditors.[1013]

Therefore, to the extent there would be uncertainty with respect to the proprietary status of self-custodied crypto assets in the event of adviser's bankruptcy or insolvency, a financial asset election would help protect client crypto assets from adviser's financial reverses.[1014]

Advisers that have self-custody of clients' crypto assets and such clients would incur expenses associated with the review and preparation of the initial agreement. These costs are included in the cost estimates provided above.[1015]

3. Regulated Fund Self-Custody of Crypto Assets

The proposed fund self-custody rule would permit an investment adviser to self-custody a regulated fund client's crypto asset if (a) the adviser complies with the proposed adviser self-custody rule and (b) the regulated fund's board of directors, including a majority of directors who are not interested persons of the fund, exercises oversight responsibilities by (i) evaluating, prior to the investment adviser maintaining the crypto asset and quarterly thereafter, the adviser's written report documenting the basis for its determination for believing that no qualified custodian will maintain the crypto asset and (ii) making a determination, prior to the investment adviser maintaining the fund's crypto asset and annually thereafter, that the fund's crypto asset will be subject to reasonable care, if maintained with the fund's adviser, after considering the factors relevant to the safekeeping of the crypto asset.[1016]

To facilitate the board's determination, the adviser would be required to furnish and the regulated fund's board would be required to evaluate, at a minimum, certain information as may reasonably be necessary for the board to evaluate the fund's custody arrangement of the crypto asset.

First, the adviser would need to provide a written report documenting the basis for its determination under the adviser self-custody rule, that it has safeguarding expertise and systems, including the appropriate technology, software, hardware, and other associated systems and processes, necessary to safeguard the crypto assets against loss, theft, misuse, and misappropriation.[1017]

Second, the adviser would be required to provide the board with the most recent written annual review of the adviser's safeguarding systems and cybersecurity controls including the effectiveness of their implementation pursuant to the annual review requirement under the proposed adviser self-custody rule, if one is available at the time of the board's determination, and if not available, such information would be required to be provided by the adviser to the board for its evaluation by the next regularly scheduled board meeting after the information becomes available.[1018]

Third, the adviser would be required to provide the board with the most recent written internal control report as required under the proposed adviser self-custody rule, if one is available at the time of the board's determination, and if not available, such information would be required to be provided by the adviser to the board for its evaluation by the next regularly scheduled board meeting after the information becomes available.[1019]

Finally, the adviser would be required to provide such other information as may reasonably be necessary for the board to evaluate the regulated fund's custody arrangement.[1020]

The requirements under the proposed adviser self-custody rule would also apply in the context of regulated fund self-custody of crypto assets, except that, in the case of regulated fund self-custody, they would apply to the crypto assets constituting “securities and similar investments.” [1021] In addition, for purposes of any QC determination made with respect to an account of a regulated fund, “qualified custodian” would mean a bank or other person authorized to hold assets for the regulated fund under section 17(f) of the Investment Company Act (15 U.S.C. 80a-17(f)) or the rules thereunder.[1022] Furthermore, in the case of regulated fund self-custody, the supervised persons that would have access to key materials would be required to be designated by resolution of the board of directors of the regulated fund.[1023] Consequently, to the extent that regulated funds choose to invest in crypto assets that no qualified custodian will maintain, we expect that the benefits and costs resulting from these proposed requirements and discussed in section III.C.2 would also apply when ( printed page 64004) regulated funds would maintain their crypto asset with their advisers. We expect that advisers of regulated funds with strategies that involve crypto asset exposures could face different costs than advisers of non-regulated fund clients due to the potentially different set of assets subject to the proposed fund self-custody rule compared to advisers that have solely non-regulated fund clients.

The proposed fund self-custody rule would require additional board oversight, which could further enhance investor protection. Specifically, the written reports documenting the basis for the adviser's determination that no qualified custodian will maintain the crypto asset would assist a board in evaluating the adviser's rationale and justification for self-custody. In addition, the written reports documenting the basis for the adviser's determination that it has safeguarding expertise and systems necessary to safeguard the crypto asset against loss, theft, misuse, and misappropriation would assist a board in evaluating the adviser's ability to safeguard the fund's crypto assets. Finally, the proposed requirement that the access to the regulated fund's crypto asset key materials be restricted to those persons designated by resolution of the board would facilitate board oversight of key access materials. This proposed requirement could benefit investors by enhancing independent monitoring by the fund's board and reducing custodial risks. It would also help ensure that the board agreed that there was a legitimate need for the regulated fund to place and maintain its crypto assets with its adviser and that the adviser had the capability to subject the crypto assets to reasonable care. This would help mitigate the heightened risk of misappropriation of the assets by the adviser that is present when the adviser is also the custodian ( i.e., when the adviser has direct access to the client's assets).[1024]

Additionally, the combination of the written reports with the adviser's most recent annual review of its safeguarding systems and with the adviser's most recent internal control report (at the time of the board's determination or promptly after they become available) would facilitate the board's assessment of the information provided by the adviser and would help the board evaluate the adviser's safeguarding systems, which could reduce risk for the regulated fund's assets.

The proposed fund self-custody rule's requirements that the review of the QC determination and the reasonable care determination be made by a majority of the regulated fund's directors who are not interested persons of the fund would strengthen these benefits by further helping ensure independent oversight of the adviser. This would benefit the fund's investors by helping further mitigate the conflicts of interest that occur when the adviser is also the custodian.[1025]

We expect that regulated funds would incur costs associated with the board oversight provisions. Specifically, we expect regulated funds to incur costs associated with the time necessary for the regulated fund's board's members to review and assess the information provided by the advisers. We estimate one-time compliance costs of $53,037 and recurring annual compliance costs of $21,660 generally per regulated fund that would maintain crypto assets in self-custody through its adviser.[1026] These estimates include costs that are associated with the board of directors' evaluation of the adviser's written reports and internal control reports. To the extent that the board would request from the adviser information beyond what the adviser would produce under the proposed adviser self-custody rule, the proposed fund self-custody rule could result in additional costs for regulated funds' advisers as they could incur costs associated with preparing and providing the information. The board would also incur costs associated with processing this additional information. These costs would vary based on the extent of the information that the board would request. Costs incurred by regulated funds and their advisers could be passed on to the funds' investors.

The proposed requirements that the review of the QC determination and the reasonable care determination be made by a majority of the regulated fund's directors who are not interested persons of the fund could result in additional costs since it could result in board members that are less familiar with crypto obtaining additional resources in order to be better able to review and assess the information provided by the adviser.

The costs associated with the proposed fund self-custody rule would likely vary with the size of the regulated funds. We expect the costs as a percentage of assets to be lower for larger regulated funds or funds within a complex sharing the same adviser and with common board members due to economies of scale,[1027] as the board's determination could be applied across multiple funds. In addition, certain boards could be less familiar with crypto assets. As a result, they could incur higher costs to obtain additional resources needed for effective oversight.

It is also possible that board oversight could be less effective in instances where a regulated fund's board of directors is less familiar with crypto assets, since board members could be less able to assess the information provided by the adviser despite potentially obtaining additional resources.[1028] This could result in higher custodial risks and agency costs associated with self-custody.[1029]

4. Custody of Crypto Assets by State Trust Companies

(a) Overview and Scope

Under the current custody rules, an adviser or regulated fund is permitted to use a State trust company as custodian to the extent that the State trust company meets the applicable definition of a bank.[1030] A State trust ( printed page 64005) company is a “bank,” and thus a permitted custodian for an adviser or regulated fund, if, among other conditions, a substantial portion of the State trust company's business consists of receiving deposits or exercising fiduciary powers similar to those permitted to national banks under the authority of the Comptroller of the Currency and the State trust company is supervised and examined by State or Federal authority having supervision over banks.

Under the proposed State trust company rules, State trust companies would be an additional category of permitted custodians for crypto assets and related cash and/or cash equivalents.[1031] A State trust company would be defined as “a legal entity organized under State law that is supervised and examined by a State authority having supervision over banks and permitted to exercise fiduciary duty powers under applicable State law.” [1032] Advisers and regulated funds using State trust companies as custodians pursuant to the proposed State trust company rules would be subject to certain requirements designed to help ensure that the crypto assets are appropriately safeguarded from the risk of loss, theft, misuse, and misappropriation, which are discussed further below.[1033]

Because State trust companies that meet the definition of bank under the custody rules are currently permitted custodians, the benefits and costs associated with the proposed State trust company rules may not apply when such State trust companies are used as custodians by advisers or regulated funds.[1034] These effects would only apply to situations where an adviser or regulated fund would rely on the proposed State trust company rules and the requirements specified therein. Under the proposed rules, advisers and regulated funds would continue to be permitted to use any entity that meets the applicable definition of bank as custodian, including for crypto assets, without relying on the proposed State trust company rules.[1035]

In addition, if State trust companies that provide or are planning on providing custodial services for crypto assets to advisers and regulated funds opt to obtain national bank charters,[1036] the economic effects discussed below would be lower since fewer advisers and regulated funds would rely on the proposed State trust company rules for the custody of crypto assets.

(1) Benefits

The main benefit of the proposed State trust company rules would be to increase the number of entities that could be available for advisers and regulated funds looking to custody crypto assets and related cash and/or cash equivalents under the custody rules.[1037] State trust companies that do not meet the definition of bank under the current custody rules would become permitted custodians to the extent that their adviser or regulated fund clients would be able to comply with the proposed requirements. This could result in some advisers and regulated funds being able to find custodians offering services that fit or better fit their needs, for example because these custodians support crypto assets or the participation in certain rights or activities associated with crypto assets that no or only a limited number of other custodians support, or because the custodian is available at a lower cost.[1038] This would allow these advisers and regulated funds to better serve their clients or investors by better implementing their investment advice or strategies. Hence, we expect that for some advisers or regulated funds, the effect of allowing State trust companies to custody crypto assets could be significant and directly affect the services that they are able to offer to their clients or investors. This could result in investors obtaining higher risk-adjusted returns or being able to implement investment strategies that better fit their objectives.[1039]

Another benefit of the proposed State trust company rules would be to simplify the custodian eligibility determination for advisers and regulated funds, potentially decreasing the costs associated with engaging State trust companies as custodians for crypto assets and related cash and/or cash equivalents. Determining whether a State trust company meets the definition of bank under the custody rules can be costly for advisers and regulated funds as it requires a fact-specific inquiry that involves analysis of both a particular State trust company's activities and applicable State and Federal banking laws. This may discourage some advisers and regulated funds from engaging as custodian a State trust company that could provide competent custodial services for crypto assets. Under the proposed State trust company rules, an adviser or regulated fund would still need to determine that a State trust company is supervised and examined by a State authority having supervision over banks, as is the case under the baseline. However, it would be required to determine that the entity is permitted to exercise fiduciary duty powers under applicable State law instead of determining that a substantial portion of the entity's business consists ( printed page 64006) of receiving deposits or exercising fiduciary powers similar to those permitted to national banks under the authority of the Comptroller of the Currency, which may be a more complicated assessment to make and result in higher costs.[1040] This could reduce the costs to advisers and regulated funds of finding a custodian for crypto assets and related cash and/or cash equivalents.[1041] These cost reductions would benefit advisers' clients and regulated funds' investors to the extent that they would be passed on to them, for example via lower fees or expenses.

A related benefit of the proposed State trust company rules would be to potentially decrease the costs for State trust companies to find clients that are advisers or regulated funds, which could affect the price charged to these clients for the provision of custodial services. Under the baseline, because of the challenges associated with the determination for believing that a State trust company meets the definition of bank under the custody rules and because the responsibility of making the determination rests on the adviser or regulated fund, State trust companies may be unable to provide custodial services for crypto assets to potential clients that are advisers or regulated funds, even when a substantial portion of their business consists of receiving deposits or exercising fiduciary powers similar to those permitted to national banks under the authority of the Comptroller of the Currency. This inability could lead some State trust companies to apply for, and potentially obtain, a national bank charter in order to facilitate their provision of custodial services for crypto assets to advisers and regulated funds.[1042] Because the proposed State trust company rules would make State trust companies a category of permitted custodians distinct from banks, fewer State trust companies could decide to obtain a national bank charter solely in order to facilitate their provision of crypto asset custodial services to advisers and regulated funds.[1043] This would significantly reduce costs for those State trust company custodians, which could allow them to charge lower prices to the advisers and regulated funds retaining their services or enhance the safeguarding controls they put in place.[1044] This would benefit these advisers' clients and regulated funds' investors to the extent that the lower prices would be passed on to them, for example via lower fees or expenses or by reducing the risk to which their assets are subject.

A potential indirect effect of the proposed State trust company rules could be to enable advisers' clients and regulated funds' investors to take advantage of investment opportunities that are not currently being taken advantage of. The proposed rules could result in advisers increasing their services related to crypto assets and in regulated funds increasing their investments in crypto assets by reducing custody-related challenges. Clients and investors of these advisers and regulated funds could therefore be able to obtain higher risk-adjusted returns or implement investment strategies that better fit their objectives.

In addition, some investors may wish to have exposure to crypto assets but may currently be unable to find an appropriate adviser or regulated fund to achieve this goal. As a result, they might make their investment decisions without the help of a registered adviser or gain exposure to crypto assets outside of regulated funds (and outside of funds that are not regulated funds but that are advised by a registered investment adviser). To the extent that the proposed State trust company rules result in more advisers offering crypto assets-related services or in more regulated funds investing in crypto assets, these investors may decide to invest instead under the advice of an adviser or in regulated funds. These investors would benefit by being covered by the investor protections associated with the involvement of an adviser or with investing in a regulated fund. This could also benefit investors to the extent that investing under the advice of an adviser or in a regulated fund helps them achieve investment strategies that yield higher returns or otherwise better fit their objectives.[1045]

(2) Costs

State trust companies are organized under State law, supervised and examined by a State authority, and permitted to exercise fiduciary powers under applicable State law.[1046] Under the current custody rules, entities that are permitted custodians are instead generally subject to Federal law.[1047] Because State laws vary from State to State, and because different States may allocate varying levels of resources towards the enforcement of such laws, the crypto assets that would be custodied by State trust companies under the proposed State trust company rules could be subject to varying levels of protection against the risk of theft, loss, misuse, and misappropriation.

However, we do not expect that in practice there would be significant risk, for three reasons. First, the proposed definition of State trust company would help ensure that a State banking authority regulates the custodial activities of the State trust company and that the State trust company is subject to State examination and supervision, similar to a State bank. In addition, several States have developed robust State law frameworks that oversee and regulate State trust companies and other State-regulated entities offering crypto asset custodial services.[1048] Second, the proposed State trust company rules include additional requirements, discussed in the subsequent sections, with which advisers and regulated funds would need to comply in order to be permitted to use a State trust company as custodian for crypto assets and related cash and/or cash equivalents.[1049] These requirements are designed specifically to help ensure that appropriate steps are taken by the State trust company custodian to safeguard client crypto assets from the risk of loss, ( printed page 64007) theft, misuse, and misappropriation. Third, advisers, including advisers to regulated funds, would continue to be required to exercise their fiduciary duty of care when selecting and monitoring a custodian.[1050]

(b) Initial and Annual Determinations

The proposed State trust company rules would require that an adviser or regulated fund make certain reasonable basis determinations both prior to engaging a State trust company as a custodian for crypto assets and related cash and/or cash equivalents and on an annual basis thereafter.[1051] The adviser or regulated fund would be required to determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company (i) is authorized by the relevant State banking authority to provide custody services for crypto assets and (ii) maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation.

Benefits

The proposed initial and annual determination requirements under the proposed State trust company rules would benefit advisers and regulated funds, as well as their clients and investors, by helping ensure that the assets custodied under the proposed State trust company rules would be custodied with custodians that are appropriate and capable, which would reduce the risk of theft, loss, misuse, and misappropriation for these assets, enhancing investor protection.

These requirements would mitigate the asymmetric information problem between the adviser or regulated fund and the State trust company custodian by helping ensure that the adviser or regulated fund reviews information about the custodian that it may not otherwise consider.[1052] This additional information, combined with the proposed requirement that advisers and regulated funds perform a due inquiry to reach the reasonable basis determinations, would result in advisers and regulated funds making better-informed decisions when selecting, or considering whether to continue doing business with, a custodian for crypto assets and related cash and/or cash equivalents. To the extent that the reduced information asymmetry would allow advisers and regulated funds to better evaluate the quality of custodians, this could lead to a more efficient allocation of resources.[1053] It could also result in investors' assets being maintained at State trust company custodians with more robust safeguards, which would support investor protection. In addition, it could also result in advisers and regulated funds being more confident in the quality of custodial services that they would receive from State trust company custodians, which could result in increased crypto-related services provided by advisers and increased investments in crypto assets by regulated funds.

By providing information to advisory clients and regulated funds' investors on the considerations that would be required to be included in advisers' and regulated funds' reasonable basis determinations when selecting or opting to continue doing business with a custodian, the proposed requirements would also contribute to increase transparency between advisers and regulated funds and their clients and investors. This could decrease the asymmetry of information and result in investors being more confident in the quality of custodial services provided by State trust company custodians,[1054] which could increase their propensity to invest in crypto assets under the advice of an adviser or via regulated funds. This would benefit these investors as they would be covered by the investor protections associated with the involvement of an adviser or investment in a regulated fund. In addition, it could facilitate investing in crypto assets among interested investors.[1055]

The proposed requirements specifying when the reasonable basis determinations would have to be made would also have benefits. First, the proposed requirement that the determinations be made prior to engaging the custodian would help ensure that no assets are transferred to the custodian before the adviser or regulated fund engaging the custodian has performed the due inquiry and concluded that it is able to make the required reasonable basis determinations. Second, the proposed requirement that the reasonable basis determinations be made annually after the custodian has been engaged to provide custodial services would help ensure that the custodian remains appropriate and capable over time, which would benefit investor protection.[1056] Different factors could result in the State trust company becoming less effective at safeguarding crypto assets over time. For example, the custodian's management team could change, a weakness in the cybersecurity risk defense of the firm could be discovered, or the State banking authority could modify its criteria regarding which entities are authorized to provide custodial services for crypto assets. In addition, the evolution of the technology related to crypto assets could affect the types of tools and procedures that make the safeguarding of crypto assets effective, and the degree to which any particular State trust custodian updates their systems to account for these changes may change over time. Hence, a State trust company's written policies and procedures are likely to be regularly updated or to be applied differently over time. The proposed requirement would help ensure that due diligence is performed at least annually by the adviser or regulated fund and that the assets continue to be safeguarded appropriately.

Costs

The proposed initial and annual determination requirements would entail costs for the advisers or regulated funds considering obtaining custodial services for crypto assets under the proposed State trust company rules. For example, the requirement that advisers ( printed page 64008) and regulated funds reach a “reasonable basis for believing” that the specified conditions are met could entail some costs for advisers and regulated funds, including potentially costs related to legal advice.[1057] These costs could be passed on to the adviser's clients or regulated fund's investors, for example via higher fees or expenses.[1058] We estimate one-time compliance costs of $30,460 and recurring annual compliance costs of $10,153 per adviser or regulated fund that would maintain crypto assets at a State trust company pursuant to the proposed State trust company rules.[1059]

Under the proposed requirements, the adviser or regulated fund would have to make a due inquiry prior to engaging a State trust company as custodian for crypto assets and related cash and/or cash equivalents under the State trust company rule. Because this inquiry would, in many instances, occur before there is an established business relationship between the adviser or regulated fund and the State trust company,[1060] the adviser or regulated fund might not have observed the State trust company's performance and might lack access to relevant information that is not publicly available. It may therefore be challenging for the adviser or regulated fund to complete it. This could result in additional costs, including related to obtaining relevant documentation. However, we expect that State trust companies would be aware of the proposed requirements to which advisers and regulated funds would be subject and, to the extent that they would be interested in providing custodial services to new clients that would be advisers or regulated funds, that they would cooperate with the adviser or regulated fund's request for information. Hence, we do not expect that this requirement would result in significant costs.

The adviser or regulated fund would also incur costs associated with the proposed ongoing annual determinations. However, we expect that in many instances, these costs would be significantly smaller than those of the initial determinations. This is because the adviser or regulated fund would already have in hand relevant information about the State trust company and would be able to focus its inquiry on the differences between the new information obtained and the previous information.

(1) Authorization to Custody Crypto Assets

Under the proposed State trust company rules, an adviser or regulated fund would be required to determine in writing that it has a reasonable basis for believing, after due inquiry, that the State trust company is authorized by the relevant State banking authority to provide custody services for crypto assets and related cash and/or cash equivalents.[1061]

Benefits

While the proposed definition of “State trust company” would help ensure that the entity that would be providing custodial services under the proposed State trust company rules would be supervised and examined by a State authority having supervision of banks and permitted to exercise fiduciary powers under applicable State law, this proposed requirement would require that the adviser or regulated has a reasonable basis for believing that the entity is authorized by the relevant State banking authority to provide custody services for crypto assets and related cash and/or cash equivalents. Depending on a State's regulatory framework, this could help ensure that the entity would be subject to regulatory oversight in relation to its provision of custodial services generally or for crypto assets and related cash and/or cash equivalents specifically.

Regulatory oversight generally ensures that entities are subject to and required to comply with specialized regulation. It also generally includes efforts made to enforce the regulation, which increases the likelihood that the regulation is complied with. Hence, this proposed requirement would help ensure that State trust companies that would be permitted custodians under the proposed State trust company rules would be authorized to do so by a State authority and would comply with requirements beyond those included in the proposed rules. This would benefit advisers and regulated funds using State trust companies as custodians under the proposed State trust company rules, as well as their clients and investors, by helping ensure that the adviser or regulated fund has a reasonable basis for believing that the State trust company custodian safeguarding the assets is appropriately qualified.

In addition, this proposed requirement could result in advisers and regulated funds choosing State trust company custodians that are organized in States where the regulatory framework covers the custody of crypto assets specifically.[1062] This could result in these custodians having better safeguarding controls in place, which would reduce the risk of theft, loss, misuse, and misappropriation for the crypto assets maintained at these custodians.

Costs

The proposed requirements would entail costs for an adviser or regulated fund considering using a State trust company as custodian for crypto assets and related cash and/or cash equivalents under the State trust company rules. In order to comply with the proposed requirements, an adviser or regulated fund would need to perform an analysis of the applicable State law and have a reasonable basis for believing that the State trust company is authorized to provide custody service for crypto assets.[1063] While some States have adopted regulatory frameworks for the custody of crypto assets specifically,[1064] many have not. This analysis could therefore be relatively costly to perform as, in some instances, it could be unclear whether a State trust company is authorized to custody crypto assets or ( printed page 64009) whether the applicable state law applies only to traditional assets.[1065]

In addition, because many States do not have a regulatory framework for the custody of crypto assets specifically, it is possible that some advisers or regulated funds would be unable to reach the proposed reasonable basis determination requirements with regard to some State trust companies. While this could happen when the adviser or regulated fund is not able to determine that the State trust company is authorized to custody crypto assets, it could also happen when the adviser or regulated fund does not have sufficient understanding of the applicable State law or where the applicable State law does not provide sufficient clarity. As a result, this proposed requirement could result in additional costs, including due diligence costs and uncertainty costs, for advisers and regulated funds. It could also prevent some advisers or regulated funds from using as custodian a State trust company that would be permitted under the proposed State trust company rules, which could result in advisers and regulated funds having to select custodians that charge higher fees or that have lower safeguards. However, this situation could happen infrequently, as the entities offering custodial services for crypto assets that are organized as State trust companies may choose to be organized in States where the applicable State law clearly authorizes them to custody crypto assets.

(2) Policies and Procedures

As part of the proposed initial and annual determinations, an adviser or regulated fund would be required to determine in writing that it has a reasonable basis for believing, after due inquiry, that the State trust company maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation, with such policies and procedures addressing, at a minimum, private key management and cybersecurity.[1066]

Benefits

To make the required determination, advisers and regulated funds would need to obtain sufficient information about the State trust company's policies and procedures. This could result in State trust companies sharing information that they would not have otherwise shared with advisers and regulated funds, and thus help reduce the level of asymmetry between the information available to the State trust company and that available to the adviser or regulated fund.[1067] As a result, advisers and regulated funds would be better equipped to make informed decisions when selecting (or deciding whether to continue doing business with) a State trust company custodian under the proposed State trust company rules.[1068] An adviser or regulated fund would be more likely to select a custodian that provides the level and type of services that it desires.

In addition, under the proposed requirements, the adviser or regulated fund would also be required to determine that the State trust company's written policies and procedures are reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation with such policies and procedures addressing, at a minimum, private key management and cybersecurity.[1069] This would help ensure that advisers and regulated funds select appropriate custodians.[1070] Written policies and procedures can help ensure that the State trust company's personnel knows the different steps to take when handling crypto assets, including during events that could put the assets at risk.[1071] Hence, these proposed requirements would help ensure that advisers' client crypto assets and regulated funds' crypto assets are appropriately safeguarded by custodians that are State trust companies.[1072] This would reduce the risk of theft, loss, misuse, and misappropriation, thereby increasing investor protection.[1073]

To facilitate their adviser or regulated fund clients' or potential clients' compliance with the proposed requirements, some State trust companies could choose to design and implement new policies and procedures or otherwise enhance the design or implementation of existing ones. To the extent this is the case, this would result in an increase in the quality of custodial services for crypto assets and support investor protection. To the extent that these new or enhanced policies and procedures would be applied to all of the crypto assets in custody with the State trust companies and not only those of advisers' clients or regulated funds, these benefits would apply to all investors whose crypto assets are maintained at these State trust companies.

Costs

In order to comply with the proposed requirements, an adviser or regulated fund using or considering using a State trust company as custodian under the proposed State trust company rules would need to obtain sufficient information to be able to make the required reasonable basis determinations. This would require the adviser or regulated fund to first determine the type of information that it would need to receive from the State trust company to be able to comply with the proposed requirements.[1074] It would also require the adviser or regulated fund to come to an agreement with the State trust company on the information to be received, relating to both the policies and procedures themselves and how they are implemented by the state trust company.[1075] Once it has received the information from the State trust company, the adviser or regulated fund would need to review it to be able to make the required determination.

Hence, these proposed requirements would impose costs on advisers and ( printed page 64010) regulated funds using, or considering using, State trust companies as custodians under the proposed State trust company rules. We expect that these costs would be higher for the advisers and regulated funds that are less familiar with the technology required to safeguard crypto assets, since they may need to hire third parties to comply with the proposed requirements or spend more time or resources making the required reasonable basis determinations, for example. These costs could be passed on to the advisers' clients or the regulated funds' investors, for example via higher fees or expenses. However, we expect that some of these costs would be significantly mitigated by the proposed requirements that advisers and regulated funds receive and review audited financial statements and a written internal control report from current or potential custodians.[1076]

To the extent that they would result in some State trust companies designing and implementing new policies and procedures, or enhancing the design or implementation of existing ones, the proposed requirements would also result in costs for these State trust companies. State trust companies could also face some additional costs related to responding to advisers' and regulated funds' requests for information. Some of these costs could be passed on to the advisers and regulated funds retaining the services of these State trust companies for the custody of crypto assets and further passed on the advisers' clients and regulated funds' investors. However, we expect that, to the extent that these new or enhanced policies and procedures would be applied to all of the crypto assets in custody with the State trust companies, and not only those of advisers' clients or of regulated funds, these costs would be spread among all of the State trust companies' clients for which they would maintain crypto assets. The costs eventually passed on to advisers' clients and regulated funds' investors could therefore be minimal, depending on the set of entities to which State trust companies provide custodial services for crypto assets.

(c) Financial Statement Audit

An adviser or regulated fund would be required, under the proposed State trust company rules, to receive and review the State trust company's most recent annual financial statements.[1077] The adviser or regulated fund would also be required to confirm that such financial statements were prepared in accordance with U.S. GAAP and subject to an audit performed by an independent public accountant.[1078]

Benefits

Appropriately safeguarding crypto assets can be costly for custodians.[1079] Hence, when choosing a custodian, an adviser or regulated fund could rely on its assessment of the financial health of potential custodians to predict whether these custodians would have the financial means to provide the custodial services that it expects.[1080] For that reason or for other reasons,[1081] some custodians may currently be reluctant to share detailed financial information with advisers or regulated funds. This information asymmetry can impede the adviser or regulated fund's decision-making process and result in the adviser or regulated fund choosing a custodian that it would not have chosen had it had better information.[1082] This could result in the adviser's client crypto assets or the regulated fund's crypto assets being at increased risk of theft, loss, misuse, and misappropriation.

To the extent that they would result in the sharing of information that would not be shared otherwise, the proposed requirements relating to audited financial statements would help reduce this market inefficiency in three ways. First, the State trust company would have to send its financial statements to the adviser or regulated fund in order for the adviser or regulated fund to be permitted to use it as custodian under the proposed State trust company rules. Hence, the adviser or regulated fund would receive important information about the State trust company's financial position. The adviser or regulated fund would then be able to use this information when assessing the financial stability of the State trust company, which could inform its assessment of the State trust company's ability to safeguard crypto assets to the level that meets its expectations. Second, the adviser or regulated fund would be required to confirm that the financial statements were prepared in accordance with U.S. GAAP. This would help the adviser or regulated fund review the financial statements it receives as it would have a better understanding of the accounting principles used to prepare the statements. In addition, because the adviser or regulated fund would receive financial statements prepared in accordance with U.S. GAAP from all potential State trust company custodians, it would be better able to compare options, which would support its decision-making process. Third, the adviser or regulated fund would be required to confirm that the financial statements were audited by an independent public accountant. This would further support the adviser or regulated fund in its decision-making process by potentially increasing the quality and reliability of the financial statements that it receives and by potentially increasing the level of trust that the adviser or regulated fund has in the accuracy of the information contained in the financial statements that it receives.[1083]

Costs

Obtaining financial statements that are prepared in accordance with U.S. GAAP and audited by an independent public accountant would entail costs for State trust companies providing custodial services to advisers and regulated funds under the State trust ( printed page 64011) company rules.[1084] These costs could be passed on to the adviser or regulated fund retaining the services of the State trust company and further passed on to the adviser's clients or the regulated fund's investors, for example via higher fees or expenses. However, we expect that, in many cases, the State trust companies would prepare their financial statements in accordance with U.S. GAAP and have them audited by an independent public accountant under the baseline.[1085] Hence we expect that, in these cases, the cost for State trust companies of this proposed requirement would be minimal as it would only consist of the cost of sharing the statements with the adviser or regulated fund.

Reviewing the audited financial statements they would receive would entail costs for advisers and regulated funds. These costs could be passed on to their clients and investors, for example via higher fees or expenses. However, we do not expect that these costs would be significant since regulated funds are required to produce audited financial statements themselves and are therefore likely to be familiar with them and since advisers, as part of the advice they provide to clients, would likely be familiar with reviewing audited financial statements of other entities.

(d) Internal Control Report

An adviser or regulated fund would be required, under the proposed State trust company rules, to receive and review the State trust company's most recent written internal control report prepared by an independent public accountant during the current or prior calendar year. The adviser or regulated fund would also be required to confirm that the internal control report contains an opinion of the independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of crypto assets and related cash and/or cash equivalents.[1086]

Benefits

The internal control reports that would be required under the proposed State trust company rules are assessments performed in accordance with specified standards where individuals with specific qualifications evaluate the design and effectiveness of an organization's internal control framework and report on their findings. They may include descriptions of control activities, testing procedures performed, identified deficiencies, remediation plans, and conclusions regarding control effectiveness. In this context, the internal control report would serve as a signal for a potential State trust company custodian communicating to an adviser or regulated fund that it has appropriate controls in place to effectively safeguard crypto assets and related cash and/or cash equivalents. To the extent that this sharing of information would not happen in the absence of this proposed requirement,[1087] this would help mitigate the principal-agent problem by reducing the level of asymmetry between the information available to the State trust company and that available to the adviser or regulated fund.[1088] By receiving and reviewing the internal control reports, advisers and regulated funds would gain important information on the design and effectiveness of internal control measures in place at the custodian to protect crypto assets from the risk of theft, loss, misuse, and misappropriation. As a result, advisers and regulated funds would be better equipped to make informed decisions when selecting (or deciding whether to continue doing business with) a custodian.[1089] An adviser or regulated fund would be more likely to select a custodian that provides the level and type of services that it expects.[1090]

In addition, under the proposed requirements, the adviser or regulated fund would also be required to confirm that the internal control report contains an opinion of the independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of crypto assets and related cash and/or cash equivalents. This would help ensure that advisers and regulated funds select appropriate custodians.[1091] This would help reduce the information asymmetry, and therefore the principal-agent problem, that can occur between the adviser or regulated fund and its clients or investors.[1092] Hence, these requirements would help ensure that client and fund crypto assets and related cash and/or cash equivalents are appropriately safeguarded by custodians that are State trust companies. This would reduce the risk of theft, loss, misuse, and misappropriation for these assets, thereby enhancing investor protection.[1093]

These benefits would be strengthened by the fact that, under the proposed requirements, the report would be prepared by an independent public accountant. This would help ensure that the report is prepared by individuals who have sufficient technical knowledge to adequately make a judgement on whether the controls in place at the custodian are suitably designed and implemented and operating effectively.[1094] It would also help ensure that the report would be ( printed page 64012) prepared by an accountant that is independent from the custodian. Hence, this proposed requirement could increase the reliability of the internal control report and potentially increase the level of trust that the adviser or regulated fund has in the accuracy of the information contained in the internal control report it receives.[1095]

The proposed internal control report requirements would also strengthen the benefits associated with the proposed audited financial statement requirements. An accountant auditing a State trust company's financial statements would have a better understanding of the State trust company's internal controls and processes, which could affect how it chooses to conduct the audit. Hence, the proposed internal control report requirements could result in a higher quality financial statement audit, which would strengthen the benefits described in section IV.C.4.c).

The proposed requirements that advisers and regulated funds receive an internal control report from potential State trust company custodians could also result in some State trust companies enhancing their controls in order to support potential clients that are advisers or regulated funds in their compliance with the proposed State trust company rules. This could result in crypto assets and related cash and/or cash equivalents being better safeguarded.[1096]

Costs

Obtaining an internal control report that is consistent with the proposed requirements would entail costs for State trust companies providing custodial services to advisers and regulated funds under the proposed State trust company rules.[1097] These costs could be passed on to the adviser or regulated fund retaining the services of the State trust company and further passed on to the adviser's clients or the regulated fund's investors, for example via higher fees or expenses. However, we expect that, in some cases, a State trust company would have obtained an internal control report even under the baseline.[1098] Hence we expect that, in these cases, the costs for State trust company of this proposed requirement would be relatively low as they would only consist in the cost of sharing the report with the adviser or regulated fund.

This proposed requirement could also result in an increase in the demand for independent public accountants preparing internal control reports, which may result in higher costs for these services if the supply of independent public accountants who have the knowledge and skills to prepare internal control reports with respect to the custody of crypto assets is limited. This could create a challenge for advisers and regulated funds if they are unable to obtain an internal control report from the State trust company they would like to use as custodian for crypto assets under the proposed State trust company rules. In this case, they would have to find an alternative custodian, which may charge higher fees or have lower safeguards.

To the extent that they would result in some State trust companies implementing enhanced controls to safeguard crypto assets, the proposed requirements would entail additional costs for State trust companies. These controls could be costly to design, implement, and operate, especially since they could be updated regularly as the technology and best practices evolves and to support advisers and regulated funds in their compliance with the proposed requirements. We expect that the costs of these controls would be reflected in the fees charged to advisers and regulated funds by these custodians, which could result in higher fees or expenses for adviser clients and regulated fund investors. However, we expect that, to the extent that these enhanced controls are applied to all of the crypto assets in custody with the State trust companies, and not only those of advisers' clients or regulated funds' investors, these costs would be spread among all of the State trust companies' clients for crypto assets. The costs ultimately passed on to advisers' clients and regulated funds' investors could therefore be reduced, depending on the set of entities to which State trust companies provide custodial services for crypto assets.

Reviewing the internal control reports they would receive would entail costs for advisers and regulated funds. These costs could be passed on to their clients and investors, for example via higher fees or expenses. Because advisers and regulated funds may not have extensive knowledge of the technology required to safeguard crypto assets properly, they could have to devote significant resources to be able to make the required reasonable basis determination, which could increase these costs. However, we expect that these costs would be mitigated by the fact that the internal control report would contain an opinion of the independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services. This would facilitate the adviser's or regulated fund's review of the report.

(e) Segregation of Assets

Under the proposed Investment Company Act State trust company rule, a regulated fund would be able to place and maintain the crypto assets and related cash and/or cash equivalents with a State trust company under the condition that the fund enters into a custodial services agreement with the State trust company and that this agreement provides that all crypto assets (and related cash and/or cash equivalents) held in custody for the fund would be held in accounts that are segregated from the State trust company's assets.[1099]

( printed page 64013)

Benefits

The proposed segregation requirements for regulated funds' crypto assets and related cash and/or cash equivalents held with State trust company custodians would help ensure that a regulated fund's assets are isolated and more readily identifiable as property of the State trust company custodian's clients. This would help protect the regulated fund's assets from claims by a third party looking to secure or satisfy an obligation of the State trust company custodian, including in cases of insolvency or bankruptcy of the custodian or its related persons. More generally, it would help protect the regulated fund's assets in instances where the State trust company custodian liquidates its own assets for any reason. In addition, making the regulated fund's assets more readily identifiable as property of the State trust company custodian's clients would help prevent misuse or misappropriation of the assets by the custodian. The proposed segregation requirements would benefit regulated funds' investors by helping ensure the safety of their investments in the funds. Any instance where a fund's assets are lost as a result of events occurring at the custodian results in investment losses for the fund's investors, who ultimately own the fund and its investments.

These benefits would apply to the extent that State trust companies that would be custodians for regulated funds' crypto assets and related cash and/or cash equivalents would not segregate fund assets in the absence of the proposed requirement. We expect that some entities that would provide custodial services for regulated funds' crypto assets under the proposed State trust company rules already segregate assets under the baseline. Those that meet the definition of bank under the current custody rules and are custodians for advisers have the obligation to segregate assets under the current Advisers Act custody rule.[1100] In addition, the internal practices of the State trust companies that would provide custodial services under the proposed State trust company rules may include asset segregation.[1101]

Costs

The proposed segregation requirements for regulated funds' crypto assets and related cash and/or cash equivalents held with State trust company custodians would result in costs for the State trust companies that would be custodians for these assets to the extent that they would have to modify their processes as a result of the proposed rules. We expect that many such State trust companies already segregate their clients' assets.[1102] For those that do not, they would need to familiarize themselves with the requirements to which potential regulated fund clients would be subject to under the proposed rules. Because segregation is a common custody requirement,[1103] we expect that most, if not all, State trust companies that would be providing custodial services under the proposed State trust company rules would be familiar with and understand what asset segregation entails, even though they may not be directly subject to asset segregation requirements. Hence, we do not expect that these costs would be significant. These entities would also need to design and implement modifications to their processes and procedures, which could entail more significant costs, depending on their existing processes.[1104] Finally, the proposed requirement that a regulated fund enter into a custodial services agreement with the State trust company and that this agreement provide that all crypto assets (and related cash and/or cash equivalents) held in custody for the fund be held in accounts that are segregated from the State trust company's assets would result in some costs for the regulated fund, which could be passed on to the fund's investors. We estimate one-time compliance costs of $6,966 and recurring annual compliance costs of $2,322 per regulated fund that would maintain its crypto assets at a State trust company custodian under the proposed State trust company rules.[1105]

5. Investment Company Custody Rule Modernizations

We are proposing amendments to the Investment Company Act custody rules to modernize the rules and correct certain errors or inconsistencies. Specifically, the proposed amendments include adding a reference to BDCs in the Investment Company Act custody rules, removing the existing conditions from the broker-dealer custody rule and permit regulated funds to custody securities and similar investments with a broker or dealer registered under section 15(b)(1) of the Exchange Act where the broker-dealer's custody of the securities or similar investments is subject to the requirements of rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections.[1106]

(a) BDCs

Section 17(f) of the Investment Company Act applies to BDCs to the same extent as if the BDC was a registered closed-end investment company.[1107] Specifically, under the statute, BDCs are required to place and maintain their securities and similar investments in the custody of a permitted custodian such as a bank or a member of a national securities exchange; or can self-custody, provided certain conditions are met.[1108] In addition to these statutory custodians, the custody rules under the Investment Company Act permit additional types of custodians.[1109] However, these rules do not include an explicit reference to BDCs as many of them were adopted before the Congress adopted the amendments to the Investment Company Act that created BDCs. We are proposing amendments to the Investment Company Act custody rules to explicitly include a reference to BDCs.[1110]

We understand that market practice has been to interpret the Investment Company Act custody rules as applying ( printed page 64014) to BDCs to the same extent as they apply to registered closed-end investment companies. Hence, we do not expect any benefits or costs from the proposed amendments.[1111]

Nevertheless, to the extent that any BDCs had not been maintaining securities and similar investments with eligible custodians, investors may benefit from BDCs having the explicit option to use a broader set of custodians. Specifically, the implementation of some investment strategies, such as investments in derivatives, may require the use of certain custodians that are not specified by the statute but permitted by the Investment Company Act custody rules. Since BDCs are not explicitly specified in these rules, some BDCs may choose not to engage those permitted custodians. To the extent some BDCs currently forgo these investment opportunities as a result, the proposed amendments would expand the investment opportunities available to investors and may enhance the risk-return tradeoff for investors. Additionally, even when a statutory custodian is available, the additional types of custodians specified in the rules under the Investment Company Act may be less costly for some assets held by the BDC.

(b) Broker-Dealer Custody

Rule 17f-1 under the Investment Company Act governs the custody of regulated funds' securities or similar investments with a broker-dealer. Section 17(f) of the Investment Company Act defined permissible custodians under that section to include members of national securities exchanges. At that time, the national securities exchanges were themselves subject to Commission registration and oversight; and direct regulation of brokers and dealers that solely effected securities transactions as members of a national securities exchange was to be conducted by the exchanges. Such brokers and dealers were subject to the rules and enforcement mechanisms established by the exchanges that provided significant oversight for exchange members. For broker-dealers that effected securities transactions in the OTC markets, the Commission had authority to prescribe rules, including rules that could provide for such broker-dealers to register with the Commission.[1112] However, the Commission has enacted a comprehensive regulatory regime that generally applies to all broker-dealers since then.[1113] In light of the changes in the regulatory landscape for broker-dealers, we are proposing amendments to rule 17f-1 to permit regulated funds to custody securities and similar investments at a broker or dealer registered under section 15(b)(1) of the Exchange Act, where the broker-dealer's custody of the securities or similar investments is subject to the requirements of rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections, without requiring specific enumerated conditions in rule 17f-1. Specifically, we are proposing to remove all the conditions, including those relating to segregation, rehypothecation, liens, examination, inspection, and possession in rule 17f-1. These conditions were initially established to protect investors at a time when customer protection requirements for broker-dealers such as rule 15c-3-3 did not exist in Federal regulations or the rules thereunder.[1114] Finally, we are also proposing to rescind Form N-17f-1 as we are proposing to rescind the examination condition under the current rule 17f-1.

While broker-dealers are generally required to be a member of at least one SRO, which can be either FINRA or an exchange, most broker-dealers are only members of FINRA.[1115] Consequently, only a limited number of broker-dealers are currently eligible to serve as custodians for regulated funds. Allowing all registered broker-dealers to serve as custodians would expand the pool of permitted custodians for regulated funds, which in turn could enhance competition between custodians and lower custody fees. We also anticipate that removing the segregation condition for securities or similar investments would make broker-dealers more viable custodial options for regulated funds as the current segregation condition requires physical segregation of assets.[1116]

Additionally, removing the examination condition would also benefit regulated funds and regulated fund investors. Under the current rule, when a regulated fund uses a broker-dealer as its custodian, the broker-dealer has to undergo three examinations annually, thereby incurring the costs associated with these examinations. The proposed amendments would remove the examination condition, thereby eliminating the associated costs. These cost savings may be passed on to funds and their investors. The proposed amendments would also eliminate the requirement for a written custodial contract and therefore also eliminate the requirement for the board of directors to ratify this contract and the associated costs. We estimate that the proposed eliminations of the conditions in rule 17f-1 would result in recurrent annual cost savings of $8,283 per regulated fund that relies on the rule. This includes cost savings associated with the proposed elimination of the requirement that the board of directors ratify the custodial contract ($6,093) and with the proposed elimination of the examinations of the regulated fund's securities and similar investments by an independent public accountant ($2,190).[1117] In addition, we estimate that the proposed rescission of Form N-17F-1 would result in recurrent annual cost savings of $1,521 per regulated fund who currently files Form N-17F-1.[1118]

As registered broker-dealers are subject to extensive regulation, including rules that provide protections for customers, we do not expect any reduction in investor protection due to the proposed broadening of the set of Investment Company Act custodians to include all registered broker-dealers. Similarly, we also do not expect any reduction in investor protection due to the proposed removal of the segregation, examination, inspection, possession, lien, and rehypothecation conditions.

The segregation condition requires a regulated fund's securities and similar ( printed page 64015) investments to be individually segregated from the securities and investments of any other person and marked to clearly identify them as the property of the regulated fund. Removing the current segregation condition in rule 17f-1 generally would not affect clients' ability to recover their securities and funds that are held at a broker-dealer for several reasons. First, the customer protection rule requires carrying broker-dealers to maintain physical possession or control over customers' fully paid and excess margin securities and to maintain a customer reserve bank account that includes funds or qualified securities with a value at least equal to the net cash owed to their customers. Second, the customer protection rule works in conjunction with the net capital rule to help ensure not only that the broker-dealer properly segregates customer assets from the firm's proprietary assets, but also that it maintains sufficient liquid assets to meet all liabilities to its creditors, including its obligations to customers, and to help ensure that the broker-dealer has adequate additional resources to wind-down its business in an orderly manner without the need for a formal proceeding under SIPA, helping to ensure that the liquidation of a firm will not result in excessive delay in repayment of the firm's obligations to customers.[1119] Third, SIPA affords certain protections against the loss of customer securities and related customer funds resulting from a broker-dealer failure. These protections include the right for customers to share pro rata with other SIPA customers in the customer property [1120] held by the carrying broker-dealer by way of a priority claim on the customer property compared to general unsecured creditors of the carrying broker-dealer.[1121] If the amount of customer property is insufficient, customers may receive up to $500,000 (of which $250,000 can be used to cover cash claims) to satisfy their claims for securities and/or cash in case of broker-dealer's insolvency.[1122]

While there is not a singular direct analog in the Exchange Act requirements for broker-dealers to the examination condition in rule 17f-1, its general purpose is collectively addressed by several different requirements found within the broker-dealer rules discussed above. In particular, rule 17a-5 under the Exchange Act requires broker-dealers to file periodic and annual financial reports, including audited annual statements, as well as FOCUS Reports. Similar to the inspection condition in rule 17f-1, rule 17a-4 under the Exchange Act requires a broker-dealer to promptly furnish records of the broker-dealer that are required to be preserved or any records of the broker-dealer subject to examination at the request of the Commission. Finally, unlike the current rule 17f-1 possession condition, rule 15c3-3 requires broker-dealers to promptly obtain and thereafter maintain the physical possession or control of all fully-paid and excess margin securities, but also requires, among other things, certain buy-ins of short security differences, steps to take when required securities are not in possession or control, and required items in the customer reserve formula for items that are failed to receive or deliver, which provide additional protection for assets not in possession of the broker-dealer.[1123]

The lien condition under rule 17f-1 provides that regulated funds' securities and similar investments shall be subject to no lien or charge of any kind in favor of the custodian or any persons claiming through the custodian. The customer protection rule provides similar protections for customers' fully paid and excess margin securities.[1124] However, broker-dealers are generally not required to maintain possession or control of margin securities except to the extent that the securities are excess margin securities.[1125] Therefore, when a customer opens a margin account to trade on margin, the broker-dealer may have a lien on, and rule 15c3-3's possession or control requirement may not apply to the customer's margin securities.[1126] Such liens help broker-dealers secure a customer's margin debit balance in the event the customer fails to pay or meet a margin call, thereby lowering risks for broker-dealers and allowing them to offer financing at more favorable terms to their customers. Since broker-dealers can exercise their lien rights only to secure the margin debit balance, we do not expect that removing the lien condition would involve costs for investors.

While the customer protection rule does not permit broker-dealers to rehypothecate customers' fully-paid or excess margin securities, broker-dealers are allowed to rehypothecate customers' margin securities up to a 140 percent threshold. However, the reserve requirement and the SIPA protections provide investor protection benefits when customer margin securities are subject to rehypothecation. Additionally, the rules governing broker-dealer hypothecation create further restriction on the broker-dealer's use of customer securities.[1127] As a result, we do not expect a reduction in investor protection due to the proposed removal of the rehypothecation condition.

While a number of the protections discussed in this section apply only to customer securities and funds, this proposal also limits when regulated funds can custody their similar investments with a broker-dealer to where that custody is subject to rule 15c3-3 or such other rule that the Commission determines provides similar customer protections.[1128] Therefore, for the same reasons as discussed above, we do not expect the proposed amendments to result in a reduction in investor protection with regard to broker-dealer custody of similar investments.

However, this provision of the proposed amendments could result in certain costs to regulated funds and their investors. Under the proposed amendments, if rule 15c3-3 remains limited to customer securities and funds and the Commission does not determine that there is another rule that provides similar customer protections, regulated funds would not be able to custody their similar investments with a broker-dealer, which could result in additional costs for regulated funds and their investors. These costs could result, for example, from the need to search for a different custodian or to use a custodian charging higher fees.

6. Investment Adviser Custody Rule Modernization

The Dodd-Frank Act provided the Commission with additional authority to impose requirements on registered investment advisers safeguarding client assets. Consistent with this authority, we are proposing to redesignate the custody rule as a new rule 223-1 under the Advisers Act. We are also proposing several amendments to the Advisers Act custody rule to address certain longstanding questions relating to the ( printed page 64016) application of the Advisers Act custody rule. Specifically, the proposed rule would include amendments regarding discretionary trading authority, the requirement relating to the registration with and inspection by the PCAOB for accountants performing certain engagements, audit provision, standing letters of authorization, treatment of BDCs, advisers' notice to clients upon opening an account with a qualified custodian, the accountants' notice to the Commission upon finding any material discrepancies, and inadvertent custody. Additionally, we are also outlining our views on segregation and accommodation reporting practices.[1129]

(a) Discretionary Trading Authority

In the 2003 Adopting Release, the Commission stated that an adviser's trading authority does not constitute custody, noting that DVP arrangements minimize the risks that the custody rule is designed to prevent. Market participants have expressed uncertainty as to whether trading authority over assets not settled on a DVP basis constitutes custody. The proposed amendment would specifically state that an adviser would not be required to comply with the Advisers Act custody rule with respect to funds and securities over which the adviser has custody due to its authority to trade at its discretion provided that the adviser: (1) executes (and only has the authority to execute) such trades only from and into designated client accounts in the client's name or the transfer is recorded in the client's name by the issuer; (2) has no authority (under the discretionary trading arrangement or otherwise) to transfer client funds or securities from the designated client account to itself, to an account controlled by the adviser or by its related person, or to any account that is not the client's, unless directed by the client in connection with such trading, and does not have the authority to have the transfer recorded by the issuer in the adviser's own name or that of a related person; and (3) complies with the Advisers Act custody rule for any other activities, rights, or authorities that cause the adviser to have custody of the funds or securities separate from discretionary trading authority, and with the requirements of any corresponding exceptions under the Advisers Act custody rule that the adviser exercises pursuant to such custody.[1130] If the proposed discretionary trading authority exception is adopted, the Commission expects to rescind the discussion in the 2003 Adopting Release on trading authority.

An adviser who currently has discretionary trading authority and complies with the requirements of the Advisers Act custody rule—or who would have such authority under the proposed rule—would benefit from the proposed amendment. Specifically, to the extent such an adviser meets the conditions in the proposed amendment, it would not be subject to the requirements of the Advisers Act custody rule and would not incur the associated compliance costs.

Additionally, clients whose advisers currently have authority that goes beyond the conditions in the proposed rule but were viewing such authority as not requiring compliance with the requirements of the Advisers Act custody rule as well as clients who would grant discretionary trading and other authority in the future under the proposed rule could both benefit from enhanced protections because their adviser would be required to either come into compliance with the Advisers Act custody rule or alter its practices to meet the proposed conditions to the exception.

Furthermore, current rule 206(4)-7 requires advisers to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act and the rules thereunder.[1131] Thus, an adviser relying on the proposed discretionary trading authority exception would need to adopt additional policies and procedures reasonably designed to ensure that the adviser's discretionary trading practices meet the conditions required under the proposed rule. The proposed conditions along with policies and procedures reasonably designed to prevent such violations could mitigate the misappropriation risks associated with discretionary trading authority.

Clients could also benefit from the proposed amendments if they currently avoid granting trading authority to advisers for assets where they perceive heightened risk of misappropriation related to an asset's trading complexity or delays in settlement. The proposed conditions could help mitigate the perceived misappropriation risk associated with an adviser's discretionary trading authority over such assets, making clients more likely to grant their advisers such authority, which could help clients to achieve better their intended risk-return objectives.

Advisers could incur costs related to complying with the proposed conditions. Advisers may need to modify their existing authorized discretionary trading arrangements or create new arrangements that are consistent with the proposed conditions. Alternatively, advisers that currently have discretionary trading authority but have different practices from the proposed conditions may choose not to meet the conditions described above. In these cases, they would be required to comply with the Advisers Act custody rule, incurring associated compliance costs. Some of these costs may be passed on to clients.

When an adviser is excepted from complying with the requirements of the Advisers Act custody rule, there may be a reduction in investor protection as clients' funds and securities may not be subject to the protections required under the Advisers Act custody rule. Specifically, without surprise examinations and the qualified custodian requirements, advisory clients who would grant discretionary trading authority could be subject to heightened misappropriation risks, and any risky activity may not be detected in a timely manner.[1132] However, these risks could be mitigated by the proposed conditions, as discussed above.

(b) PCAOB-Registered and Inspected Accountant Requirement

The current Advisers Act custody rule requires that if an adviser relies on the audit provision with respect to the account of a pooled investment vehicle, the independent public accountant that performs the financial statement audit must be registered with, and subject to regular inspection by, the PCAOB.[1133] Additionally, if an adviser or a related person of the adviser maintains client funds or securities as a qualified custodian, the independent public accountant performing the required surprise examination and preparing the required internal control report must be registered with, and subject to regular inspection by, the PCAOB.[1134] We are proposing an amendment to remove the ( printed page 64017) requirements that the accountants performing these engagements be registered with, and subject to regular inspection by, the PCAOB to allow advisers to retain any independent public accountant for these activities.

Accountants registered with the PCAOB primarily for the purpose of providing services required by the Advisers Act custody rule could benefit from the proposed amendments. Specifically, these accountants may choose to withdraw their registration with the PCAOB and could realize cost savings associated with the annual PCAOB registration fees. These cost savings would be $500 per accountant.[1135]

Additionally, removing the PCAOB-related requirements could also expand the pool of independent public accountants eligible to provide services required by the Advisers Act custody rule, resulting in enhanced competition among accountants and reduced costs for these services to advisers.[1136] However, these PCAOB-related requirements under the Advisers Act custody rule may not be the primary barrier to entry into this market; rather, it may be the setup of the necessary technology, operational capability, and regulatory knowledge. Accounting firms conducting audits or examinations required by the Advisers Act custody rule may have capabilities to engage in additional business activities and may be registered with the PCAOB to support other business lines, such as financial statement audits of public companies and broker-dealers. As a result, such accounting firms would continue to incur annual registration fees. Consequently, reductions in the cost of audits or examinations due to the removal of the PCAOB requirements could be limited.[1137]

We anticipate that the proposed removal of the PCAOB inspection requirement would likely not carry costs in the form of reduced investor protections, as the PCAOB does not inspect audit or examination engagements required solely by the Advisers Act custody rule.[1138] Whether the proposed removal of the PCAOB-registration requirement would impact audit quality is unclear. The findings in one study for non-U.S. companies suggest that PCAOB registration may improve audit quality through requirements that are part of the registration process.[1139] Therefore, to the extent that the proposed amendment would increase the market share of accounting firms not registered with the PCAOB, this could reduce audit quality. However, this study was not conducted specifically in the context of activities required under the Advisers Act custody rule, and therefore its implications may be limited for those activities.[1140]

(c) Audit Provision

The current Advisers Act custody rule provides that an adviser to a pooled investment vehicle is excepted from the client notice and account statement delivery requirements and is deemed to have complied with the annual surprise examination requirement, provided certain conditions are met, including that audited financial statements are delivered to the investors in the pooled investment vehicle on an annual basis.[1141] We are proposing to make several amendments to the audit provision and outlining our views on certain matters.

(1) Use of U.S. GAAP and Reconciliation to U.S. GAAP for Foreign PIVs

The current audit provision requires that audited financial statements be prepared in accordance with “generally accepted accounting principles.” [1142] The Commission's longstanding view has been that, except in limited circumstances, audited financial statements would need to be prepared in accordance with U.S. GAAP, and the Commission previously took a similar view in allowing advisers to foreign PIVs to rely on audited financial statements prepared in accordance with accounting principles other than U.S. GAAP in certain circumstances.[1143] We are proposing amendments that would incorporate these positions. Specifically, we are proposing amendments to the audit provision to specify that a pooled investment vehicle's audited financial statements must be prepared in accordance with U.S. GAAP, except for financial statements of foreign PIVs, provided certain conditions are met. In such cases, the proposed amendment would require that the statements of foreign PIVs contain information substantially similar to the information contained in financial statements prepared in accordance with U.S. GAAP, including a reconciliation to U.S. GAAP for material differences, and that such reconciliation is delivered to the pooled investment vehicle's U.S. investors, along with the required audited financial statements.[1144]

To the extent that advisers to foreign PIVs do not rely on the current audit provision or guidance and instead comply with the client notice, account statement, and surprise examination requirements, the proposed amendments would provide benefits for advisers and investors. Advisers of ( printed page 64018) foreign PIVs that do not currently rely on the audit provision but would do so under the proposed amendments would no longer incur the costs associated with the client notice, account statement, and surprise examination requirements. Advisers of foreign PIVs that rely on the current audit provision, but not on the Commission guidance permitting accounting principles other than U.S. GAAP under certain conditions, could save costs by instead preparing their financial statements in accordance with different standards and complying with the proposed requirement regarding reconciliation of material differences under the proposed amendments. In addition, the proposed amendments would ensure that U.S. investors receive statements that contain information substantially similar to the information contained in financial statements prepared in accordance with U.S. GAAP, which incorporates industry-specific accounting and disclosure principles for pooled investment vehicles within the scope of FASB ASC Topic 946, including a reconciliation to U.S. GAAP for any material differences. For example, such statements or reconciliation could include a presentation of a schedule of investments and financial highlights designed to ensure that the statements provide a complete view of a pooled investment vehicle's investments. Since U.S. investors are likely to be familiar with these features, the use of or reconciliation to U.S. GAAP would allow investors to better understand and compare pooled investment vehicles.

To the extent that an adviser to foreign PIVs does not rely on the current guidance and does not currently avail itself of the audit provision, the proposed rule could also involve costs for advisers and investors. Advisers of foreign PIVs may incur expenses to ensure that financial statements contain information substantially similar to the information contained in financial statements prepared in accordance with U.S. GAAP, including a reconciliation to U.S. GAAP for material differences. These costs could ultimately be borne by investors.

(2) Distribution of Audited Financial Statements

The current audit provision requires that annual audited financial statements be delivered to all limited partners, members, or other beneficial owners of a pooled investment vehicle within 120 days of the end of its fiscal year.[1145] The proposed rule would extend the current rule's 120-day distribution timeframe to 180 days in the case of a fund of funds and 260 days in the case of a fund of funds of funds.[1146] Second, we propose to amend the audit provision to permit an adviser to satisfy the distribution requirement by distributing the audited financial statements to a designated independent representative of an investor.

Accountants auditing financial statements of pooled investment vehicles that invest in other funds may only be able to complete those audits once the audited financial statements of the underlying funds have been received. As a result, these pooled investment vehicles may need longer periods to distribute their own audited financial statements due to this delay. These proposed amendments would give funds of funds and funds of funds of funds more time to perform their financial statement audits after receiving the audited financial statements of the underlying funds, which could increase audit quality and help ensure that investors have reliable information when making decisions about their investments. In addition, the proposed amendments that would permit advisers to distribute audited financial statements to a designated independent representative of an investor could also benefit pooled investment vehicle investors, as such investors may prefer to have an independent representative receive the audited financial statements on their behalf. Distribution of these statements in accordance with the investor's preference could facilitate investors' review of the statements.

The proposed amendments could also result in investors receiving the audited financial statements at a later date than under the baseline, which would extend the period before reliable information is disclosed to investors ( i.e., the audited financial statements).[1147]

(3) Audit Requirement for Newly-Formed Pooled Investment Vehicles

The current audit provision requires that annual audited financial statements be delivered within 120 days of the end of the pooled investment vehicle's fiscal year and promptly upon completion of the audit at liquidation.[1148] We are proposing amendments to the audit provision with respect to certain newly-formed pooled investment vehicles. If a pooled investment vehicle is formed within the last 90 days of its fiscal year, the audit provision would be satisfied if (a) financial statements (which may be unaudited) covering the last 90 days of the first fiscal year are distributed to investors within 90 days of the end of the first fiscal year and (b) audited financial statements are distributed to investors that cover the first fiscal year and second fiscal year after the end of the second fiscal year.[1149]

We understand that audits, regardless of the period covered, generally involve certain fixed administrative costs associated with obtaining and delivering audited financial statements. Therefore, the cost of audited financial statements that covers a single quarter may not be significantly less than the cost of an audit for the entire fiscal year, thereby potentially making these audits burdensome for advisers. The proposed amendments would benefit advisers and investors by allowing advisers to avoid the costs associated with obtaining audited financial statements covering only the pooled investment vehicle's first fiscal year, if applicable. These savings could be passed on to investors.

While advisers would benefit from the cost savings associated with the modification of the audited financial statement requirement for the first fiscal year, they would incur additional costs due to the requirement that audits in the following year cover the entire period since formation ( i.e., two separate sets of audited financial statements, one covering the first fiscal year and the second covering the entire second fiscal year), instead of only the second fiscal year. However, we anticipate that the cost associated with obtaining audits for the entire period since formation would be lower than the cost of obtaining audited financial statements for the first and second fiscal years at different times, in part because the work could be completed at the same time rather than through separate engagements in the first and second fiscal years. This could result in net cost savings for advisers; these savings could be passed on to investors.

The costs from the proposed requirement to prepare and distribute unaudited financial statements within 90 days of the end of the first fiscal year would likely be minimal for advisers. Since it is likely that advisers already prepare unaudited financial statements due to investor demand, we do not expect significant additional costs associated with the preparation aspect of unaudited financial statements. The 90-day distribution timeframe for the unaudited financial statements would ( printed page 64019) be different from the 120-day timeframe for audited financial statements. However, we expect that the distribution of unaudited financial statements would require less time and be less costly compared to that of audited financial statements. We estimate average recurring annual compliance costs associated with the preparation and distribution of unaudited financial statements of a pooled investment vehicle within 90 days of the end of the fiscal year of $76 per adviser that distributes unaudited financial statements to investors in the pool.[1150]

The proposed modification of the audited financial statement requirement for the pooled investment vehicle's first fiscal year could lead to a reduction in investor protection as it could extend the period before any fraudulent activities are detected. However, we anticipate that forgone benefits from modifying the first fiscal year audit requirement would be minimal for two reasons. First, newly-formed entities may have limited assets and few investment activities or other transactions to be audited during the first few months of their existence. While audits generally provide investor protection by identifying risks of material misstatements, these limited activities in the first few months may involve low misappropriation risks and audits covering this period may provide limited benefits. Second, audited financial statements delivered after the second year would encompass all activities since the formation of the fund, thereby helping to identify any potential high-risk activities that occurred during the initial months. Also, the distribution of financial statements, although unaudited, covering the initial 90-day period would allow investors to review an entity's assets and investments from an economic perspective. As a result, investors would be subject to limited additional risks due to the proposed amendments.

(d) Standing Letters of Authorization

Under the current Advisers Act custody rule, an adviser with custody of client funds and securities is generally required to have an annual surprise examination.[1151] We are proposing an amendment that would provide an exception from the surprise examination requirement if the adviser has custody of client funds and securities solely because of a SLOA.[1152] Under a SLOA, clients authorize their advisers, in writing, to direct a qualified custodian to transfer funds and securities to a third-party recipient, from time to time or on a specified schedule. For an adviser to rely on this proposed exception, the SLOA would need to satisfy certain conditions, which are described in the proposed rule.[1153]

The proposed rule is consistent with the staff's position provided in the IAA SLOA No-Action Letter.[1154] For advisers who already operate in accordance with the IAA SLOA No-Action Letter, and therefore forego surprise examinations, the benefits and costs associated with the proposed amendment, as discussed below, would be minimal.

This amendment would reduce compliance costs for investment advisers that currently undergo surprise examinations but would no longer be required to comply with the surprise examination requirement under the proposed rule. To the extent such advisers pass along the cost savings to clients, those clients would benefit from lower fees.

While investor protection could, in theory, be reduced when advisers forgo surprise examinations, an adviser's role would be limited when the adviser has custody of client funds and securities solely because of a SLOA, particularly given the conditions of the proposed rule. Specifically, the adviser would have no ability or authority to designate or change any information about the third-party recipient, so that the client would have the ultimate ability to terminate or change the instruction with the qualified custodian. Additionally, the qualified custodian would not be permitted to be an adviser's related party and clients would need to provide signed written instructions and authorization to both the adviser and the qualified custodian. The required signature would allow qualified custodians to verify the instructions and authorizations. Considering these proposed conditions, we anticipate that there would be little risk that an adviser could misappropriate its clients' funds or securities through such authorizations even in the absence of a surprise examination.

To rely on this exception, advisers could incur setup costs to comply with these conditions. We estimate one-time compliance costs of $471 and recurring annual compliance costs of $471 per adviser with clients that issue SLOAs.[1155]

(e) Treatment of Business Development Companies

Advisers are currently not required to comply with the Advisers Act custody rule with respect to the account of an investment company registered under the Investment Company Act.[1156] The current exception ensures that advisers and registered investment companies are not subject to duplicative or conflicting custody regulations. However, the current exception does not include an explicit reference to BDCs. We are proposing an amendment that would extend this exception to include the accounts of BDCs as well.[1157]

As the custody provisions under the Investment Company Act are incorporated by statute to apply to BDCs to the same extent these provisions apply to registered closed-end investment companies,[1158] we understand that market participants are already treating BDCs as registered closed-end investment companies for purposes of the Advisers Act custody rule. To the extent that market practice is not consistent with this approach, the proposed amendment could involve benefits and costs.

( printed page 64020)

The proposed amendment would benefit advisers by ensuring that they are not subject to duplicative or conflicting custody regulations with respect to BDC clients. To the extent that advisers currently incur additional costs for accounts of BDCs in complying with the Advisers Act custody rule alongside the Investment Company Act custody rules, this amendment would allow advisers to avoid the associated costs.

We do not expect any costs related to this proposed amendment. Specifically, we do not anticipate a reduction in investor protection as the Investment Company Act custody rules are designed to safeguard investor assets, with regulations tailored for regulated funds.

(f) Account Number in Notice to Clients

The current Advisers Act custody rule requires an investment adviser to notify clients of the qualified custodian's name, address, and the manner in which the funds or securities are maintained promptly upon opening an account with a qualified custodian on the client's behalf and following any changes to this information.[1159] The proposed rule would further require an adviser to include the custodial account number in this notice.[1160]

The addition of the custodial account number to the notice would benefit clients by enhancing the specificity of custodial account information made available to them in a timely manner, allowing them to monitor their accounts more effectively for loss, theft, misuse, or misappropriation. The proposed amendment would also provide clients with a tool for reference in any communications with the qualified custodian.

We understand that custodial account numbers are readily available from qualified custodians and, as a result, that the cost of including the custodial account number in the notice to clients would be minimal. We estimate recurring annual compliance costs associated with the addition of the custodial account number to client notices of $302 per adviser that would be affected by this proposed requirement.[1161]

(g) Inadvertent Custody

Advisers may inadvertently receive authority to obtain possession of client funds or securities because a custodial agreement between a custodian and an advisory client grants an adviser expansive authority to transact in or transfer funds and securities held in its client custodial accounts that are often superfluous to the advisory services being provided. We understand that, where such broad grants of authority are discovered by the adviser, advisers have had little success in modifying or eliminating this unwanted authority either because custodians are unwilling to accept an adviser's request to modify the custodian's agreement with its client or because the client may lack the bargaining power to negotiate for modifications to the custodian's standard forms. We are proposing an amendment that would provide an exception from the Advisers Act custody rule with respect to funds and securities over which an adviser has inadvertent custody arising from a custodial agreement provided that the adviser (1) did not recommend, request, or require that the client select the qualified custodian, and (2) either (A) does not have a copy of the client's custodial agreement, nor has knowledge or reason to know that the custodial agreement confers custody upon the adviser or (B) if the adviser knows or has reason to know of such custody, such adviser promptly notifies the client and qualified custodian in writing of such unwanted authority, repudiates such authority to the client and qualified custodian, and requests in writing that such authority be removed from the custodial agreement or be superseded by a new agreement, consented to by both the client and the qualified custodian, that does not confer custody on the adviser.[1162]

The proposed amendment granting advisers an exception from the Advisers Act custody rule could mitigate compliance risks arising from inadvertent custody. An adviser could be in violation of the Advisers Act custody rule without being aware that it has custody over client funds and securities, which could result in additional costs for the adviser. The proposed amendment would reduce this possibility. The proposed amendment would also reduce compliance costs for advisers that have inadvertent custody of client funds and securities, have unsuccessfully tried to modify or eliminate this unwanted authority, and as a result comply with the current Advisers Act custody rule with regard to such funds or securities. Under the proposed amendment, these advisers could realize cost savings by complying with the proposed conditions of the exception instead. Such cost savings could be passed on to their clients.

Providing an exception from the Advisers Act custody rule with respect to funds and securities over which an adviser has inadvertent custody could put client funds and securities at risk because advisers may misuse such authority to misappropriate a client's funds and securities held at the custodian. However, the proposed conditions would mitigate this risk by enhancing investor protection against inadvertent custody risks to which client assets may be exposed. Specifically, the first condition could mitigate the risk of misappropriation of client funds and securities as the risk of collusion could be less pronounced when the adviser is not involved in selecting the custodian. The first part of the second condition could further mitigate the risk of misappropriation as an adviser without knowledge of its inadvertent custody could not intentionally exercise such authority. When advisers would know or have a reason to know that a custodial agreement confers custody on them, they would be required to take the steps described in the second part of the second condition to mitigate the risks associated with the custodial agreement. Overall, the proposed conditions could mitigate risks that may arise from inadvertent custody. As a result, excepting advisers from the Advisers Act custody rule would likely present minimal risks to investors.

While the proposed amendments would not require advisers to review every client's custodial contract or to implement a specific set of policies and procedures related to the inadvertent custody exception, advisers may incur expenses associated with having reasonably designed policies and procedures in place under the Advisers Act compliance rule. Specifically, advisers may incur expenses associated with reviewing client custodial contracts that they have access to. To the extent they discover any unwanted authority, advisers would also incur costs associated with notifying the client and qualified custodian in writing, repudiating such unwanted authority, and requesting that certain agreements are amended. We estimate recurring annual compliance costs associated with this proposed requirement of $471 per adviser that ( printed page 64021) would repudiate inadvertent custody.[1163]

(h) Segregation

(1) Segregation From Adviser and Qualified Custodian Proprietary Assets

The current Advisers Act custody rule's segregation provision requires that a qualified custodian maintain client funds and securities in a separate account for each client or in accounts that contain only the adviser's clients' funds and securities under the adviser's name as agent or trustee for the clients.[1164] We expect to provide our views regarding the application of the segregation requirement above.[1165] In summary, we expect to provide our view that the segregation requirement encompasses segregation of such client funds and securities from the proprietary assets of the qualified custodian in addition to those of the adviser (and its related persons). We also expect to provide our view that the segregation requirement does not preclude cash balances at a custody bank from being held as general deposits and reflected on the custody bank's balance sheet as a liability to the client.[1166]

We do not expect any economic impact to result from providing such views regarding the segregation of clients' funds and securities from the proprietary assets of qualified custodians and advisers. This is because the views align with the applicable laws and regulations covering banks, broker-dealers, and futures commission merchants and is consistent with our understanding of current custodial practices.[1167]

While we do not anticipate any change in market practice to result from the view that the segregation requirement does not preclude keeping client cash in depository accounts at banks, the interpretation would benefit advisers to the extent that it would facilitate their compliance with the requirements. We do not expect any costs associated with this view.

(i) Accommodation Reporting Guidance

The Advisers Act custody rule requires an adviser to have a reasonable basis, after due inquiry, for believing that a qualified custodian that maintains client funds and securities sends an account statement, at least quarterly, to each of the adviser's applicable clients.[1168] These account statements provide information about the clients' funds and securities held by the custodian.[1169] On these statements, custodians sometimes include information regarding additional client assets that they do not hold to accommodate advisers' requests. Custodians engage in accommodation reporting when they list funds or securities on a client's account but do not accept custodial liability for them.[1170] The Commission outlines the views it expects to provide on the standards for such accommodation reporting above.[1171] If account statements sent by a custodian include assets not held by the custodian, advisers should generally ensure that such statement clearly discloses that the custodian does not hold or have authority to obtain such funds or securities, among other disclosures. Such disclosures should generally indicate that such funds or securities are included on the statement at the request of the adviser; the information (including valuation) for such externally held funds or securities included on the statement is derived from the adviser or other external source for which the custodian is not responsible; and such externally held funds or securities may not be subject to certain protections typically available at the qualified custodian.

To the extent that advisers would change their practices in response to these expected views, it could mitigate risks associated with potential misinterpretation of account statements by investors by clarifying to the clients that custodians neither attest to these assets nor offer protection for them. This clear disclosure would help ensure that clients are aware of potential custodial risks, and, as a result, they may independently verify the existence and valuations of these assets to safeguard against any misreporting risks.

Advisers that would change their practices in response to these expected views may incur expenses related to ensuring that account statements properly disclose holdings and transactions reported on an accommodation basis. The costs could be higher for advisers who have more clients receiving such statements, or for advisers whose clients hold a larger number of funds and securities reported in account statements provided on an accommodation basis. Advisers would need to have a reasonable basis for believing the qualified custodian is providing adequate disclosures in the account statement. However, we anticipate that these disclosures would generally follow standard formats, and the marginal cost of adding a disclosure would not be significant. Moreover, advisers currently incur costs for having a reasonable basis for believing that qualified custodians provide account statements to clients and are therefore likely to already have communication with the custodians about the account statements sent to clients. As a result, advisers may already ensure that such disclosures or similar disclosures are included in the account statements sent to clients by custodians. Therefore, on average, the marginal cost of relying on this view should be minimal. Furthermore, these disclosures would include information that is provided by advisers to custodians. Therefore, additional disclosure costs for custodians should be minimal as well.

7. Recordkeeping Requirements

(a) Adviser Recordkeeping

(1) Records Related to the Proposed Adviser Self-Custody Rule

The proposed amendments to the Advisers Act recordkeeping rule would introduce new recordkeeping requirements related to adviser self-custody of crypto assets. Under the proposed amendments, an adviser would be required to maintain: (i) the memorandum describing the basis for its required QC determination related to the self-custody of client crypto assets; (ii) the memorandum describing the basis for its required determination as to its safeguarding expertise; (iii) records identifying the persons that have been designated persons with access to the crypto asset private key material; (iv) a copy of the required written assessments of cybersecurity risks (v) a copy of the internal control reports required to be obtained or received pursuant to the proposed self-custody rule; (vi) records documenting its required annual review of its safeguarding systems and cybersecurity controls implemented in connection with self-custody; (vii) copies of the account statements provided to clients and records of any transmissions and notices sent to clients as required under ( printed page 64022) the proposed self-custody rule; (viii) a copy of the required financial asset elections, and (ix) for each client for which the adviser maintains crypto assets under the proposed self-custody rule, records that include such information as may be reasonably necessary to reconstruct all financial positions and transactions related to such client crypto assets including, at a minimum, client names, client account numbers, crypto asset addresses, transaction amounts, transaction destinations, transaction authorizations, and relevant metadata.[1172]

In addition, under the proposed recordkeeping amendments, the adviser would also be required to maintain the records that are otherwise required to be made and kept under paragraph (b) of rule 204-2 for advisers with custody or possession of securities or funds of any clients, related to client crypto assets maintained by the adviser under the proposed adviser self-custody rule, provided that references to securities in paragraph (b) would also include any crypto assets of a regulated fund maintained by the adviser pursuant to the proposed self-custody rules.[1173]

These proposed recordkeeping requirements could result in better safeguarding practices by advisers that would self-custody crypto assets under the proposed self-custody rules. For example, the proposed requirements that the adviser maintain records documenting its annual review of its safeguarding systems and of its assessment of cybersecurity controls could facilitate the identification, by the adviser, of any weaknesses in its systems. It could also result in advisers performing more exhaustive annual reviews or cybersecurity risk assessments, which could also help it identify any weaknesses in its systems. To the extent that advisers would be able to address weaknesses identified (or identified by the Commission during its examination or enforcement functions, as discussed below), these proposed requirements would reduce the risk to which investors' crypto assets could be subject. Hence, these proposed recordkeeping requirements could strengthen the benefits associated with the proposed safeguarding and cybersecurity requirements under the proposed self-custody rules.[1174]

The proposed recordkeeping requirements, by facilitating the Commission's examination and enforcement functions, could improve the accuracy of the information advisers maintain and transmit to clients. Hence, these proposed requirements could strengthen the benefits associated with the proposed requirements related to the communications made to clients under the proposed self-custody rules.[1175] The proposed requirements that the adviser maintain records that include such information as may be reasonably necessary to reconstruct all financial positions and transactions could also help advisers and their clients identify the correct legal entitlement of a crypto asset in the event of theft, loss, misuse, or misappropriation of the asset.

The proposed recordkeeping requirements would also help facilitate the Commission's examination and enforcement functions by helping the Commission staff assess compliance with the proposed self-custody rules, which would support the Commission's investor protection efforts. The proposed requirements that the adviser maintain a memorandum describing the basis for its required QC determination and a memorandum describing the basis for its required determination as to its safeguarding expertise would allow Commission staff to understand the basis of these determinations. The proposed requirements that the adviser maintain a copy of the internal control reports would give Commission staff access to the findings of the independent public accountant who prepared the report and allow them to understand any potential weaknesses identified by the accountant, which would support its evaluation of the effectiveness of the adviser's safeguarding practices. The proposed requirements that the adviser maintain records documenting its annual review of its safeguarding systems and its cybersecurity controls would allow Commission staff to confirm that the adviser sought to identify and address potential weaknesses in its systems. The proposed requirement that the adviser maintain records related to the designated persons with access to the private key material would help ensure that the adviser is appropriately documenting who has access to clients' private key material and allow Commission staff to assess whether the adviser is appropriately managing access to the private key material.

The proposed requirement that the adviser maintain copies of the account statements and other transmissions and notices sent to clients would help Commission staff determine whether the adviser has complied with its obligation to send such documents to clients under the proposed self-custody rule. The proposed requirement that the adviser maintain records of such information as may be reasonably necessary to reconstruct all financial positions and transaction activities for each client for which the adviser maintains crypto assets in self-custody would provide Commission staff with visibility into the activities and movements of client crypto assets. Commission staff would also be able to reconcile these records against the account statements and other disclosures sent to clients, which would help it assess the accuracy of the information disclosed to clients and give Commission staff records to examine that could show potential theft, misappropriation, loss, or misuse of client assets, resulting in more effective investor protections. The proposed requirement that the adviser maintain a copy of the applicable financial asset elections would help Commission staff determine whether the adviser has complied with the proposed financial asset election requirement. This would also help protect clients' assets in the event the adviser became insolvent or bankrupt.[1176]

The proposed amendment that would require that the records made and kept under paragraph (b) of rule 204-2 also includes the records related to crypto assets of a regulated fund maintained at the adviser pursuant to the proposed self-custody rules would also help facilitate the Commission's examination and enforcement functions. Under the proposed amendment, Commission staff would be able to request from advisers true and accurate custodial records related to the crypto assets of regulated funds, including records showing sales, receipts, and deliveries of the assets.[1177] This would help the Commission identify potential instances of fraud, which could reduce the risk of theft, ( printed page 64023) loss, misuse, or misappropriation for some regulated fund assets that would be maintained by the adviser under the proposed self-custody rules.[1178]

More generally, the proposed recordkeeping requirements for self-custody of crypto assets would enhance the transparency into an adviser's crypto asset custodial practices and strengthen the Commission's oversight capabilities. Improving the Commission's oversight capabilities could benefit clients and investors by lowering the risk of loss and providing greater transparency to the Commission in its investor protection efforts.

Advisers choosing to self-custody their clients' crypto assets would incur costs related to creating and maintaining the required records. We expect that some of the requirements would result in relatively low compliance costs for advisers, such as the requirements that the adviser maintain a copy of the internal control reports, of the account statements provided to clients and records of any other transmissions or notices sent to clients, and of the financial asset elections required under the proposed self-custody rules. We expect that copies of these documents would be produced even in the absence of the proposed recordkeeping requirements and that maintaining them would result in relatively low compliance costs for advisers, resulting from the requirement to create and maintain the records.

We expect that the compliance cost could be higher for the requirements that the adviser maintain a memorandum describing the basis for its required QC determinations, a memorandum describing the basis for its required determination as to its safeguarding expertise, and a copy of the written cybersecurity risk assessments, that the adviser maintain records documenting its required annual review of its safeguarding systems and cybersecurity controls, and that the adviser maintain, for each client for whom the adviser maintain crypto assets under the proposed self-custody rule, records that include such information as may be reasonably necessary to reconstruct all financial positions and transactions related to the client crypto assets that the adviser maintains. This is because the adviser would first have to determine what the records would include. Such a process could involve retaining the services of compliance professionals who would need to review and familiarize themselves with the proposed requirements before supporting the adviser in the creation and maintenance of the required records.

There would also be costs for advisers related to the proposed amendment that would require the records made and kept under paragraph (b) of rule 204-2 to also include the records related to the crypto assets of a regulated fund maintained at the adviser pursuant to the proposed self-custody rules. We expect that these costs would be limited since advisers are already subject to such requirements for clients that are not regulated funds and are therefore likely to be familiar with these requirements and to have appropriate staff, systems, and procedures in place.[1179] However, for advisers whose only clients are regulated funds and who would maintain client crypto assets under the proposed self-custody rules, the costs could be more significant.[1180]

We estimate recurring annual compliance costs associated with the proposed requirements of $309 per adviser that would have self-custody of client crypto assets.[1181] This estimate includes costs related to the creation and retention of the records and may include costs such as obtaining additional storage. We expect that these costs and other costs associated with the proposed recordkeeping requirements would vary across advisers based on a variety of factors, including, among others, the factors listed below. First, the particular situation that leads to the adviser determining that it can self-custody the crypto assets could result in a more or less complex memorandum describing the basis for the adviser's required QC determination. Second, the complexity of the adviser's safeguarding systems could affect the length and the depth of the required annual review and cybersecurity risk assessment.[1182] Third, the number of different assets in self-custody with the adviser, as well as the number of different crypto networks on which these assets are traded and the number of clients for which the adviser maintains crypto assets, would likely affect the compliance cost associated with many of the proposed recordkeeping requirements, with larger numbers resulting in higher costs. Hence, in some instances, the compliance costs could be significant for advisers.

The proposed recordkeeping requirements could also result in indirect costs for advisers. To the extent that they would result in enhanced safeguarding practices by advisers maintaining client crypto assets under the proposed self-custody rules,[1183] the proposed requirements could result in higher costs for advisers associated with safeguarding systems and cybersecurity measures.[1184]

(2) Records Related to the Proposed State Trust Company Rule

Under the proposed Advisers Act State trust company rule, an adviser would be required to make certain reasonable basis determinations in writing prior to engaging the State trust company as a custodian and on an annual basis thereafter.[1185] As part of these determinations, the adviser would be required to receive copies of the State trust company's most recent audited annual financial statements and internal control report.[1186] Under the proposed recordkeeping amendments, the adviser would be required to make and keep a memorandum describing the basis upon which it made its required initial and annual determinations,[1187] and copies of the State trust company's financial statements and internal control reports obtained and received pursuant to the proposed State trust company rules.[1188]

These proposed recordkeeping requirements could support advisers in their annual reasonable basis determinations by enhancing their ability to compare the information they would receive in a given year with the information they would have received in prior years. For example, the proposed recordkeeping requirements could result in advisers making a more complete inquiry before concluding that the State trust company maintains and implements written policies and ( printed page 64024) procedures reasonably designed to safeguard crypto assets from the risk of theft, loss, misuse, and misappropriation. Hence, the proposed requirements could result in advisers maintaining crypto assets with State trust companies that maintain and implement more robust policies and procedures, potentially reducing the risks to which investors' crypto assets are subject. Hence, the proposed recordkeeping requirements could strengthen the benefits associated with the proposed initial and annual reasonable basis determination requirements.[1189]

These proposed recordkeeping requirements would also help facilitate the Commission's examination and enforcement functions related to determining compliance with the proposed Advisers Act State trust company rule, which would support its investor protection efforts. The proposed requirement that the adviser maintain a copy of the State trust company's financial statements and internal control reports would help Commission staff understand the basis upon which the adviser would have made its reasonable basis determination for believing that the State trust company maintains and implements appropriate written policies and procedures. The proposed requirement that the adviser maintain a copy of the State trust company's internal control report would also enable Commission staff to understand the independent public accountant's assessment of the State trust company's crypto asset safeguarding controls. The proposed requirements that the adviser maintain a memorandum describing the basis upon which it made its required initial and annual determinations would help Commission staff understand the due inquiry performed by the adviser and the basis upon which the adviser made its initial and annual reasonable basis determinations. The proposed recordkeeping requirements related to the use of a State trust company as a custodian for crypto assets would help Commission staff determine whether an adviser complied with the proposed initial and annual reasonable basis determinations, supporting its investor protection efforts.

Advisers choosing to maintain their client assets with a State trust company custodian would incur costs related to creating and maintaining the required records. We expect that some of the requirements would result in relatively low compliance costs for advisers, such as the requirements that the adviser maintain a copy of the State trust company's financial statements and internal control reports. We expect that these documents would be created even in the absence of the proposed recordkeeping requirements and that maintaining them would result in minimal costs for advisers. Advisers are already subject to extensive recordkeeping requirements.[1190] Hence, we do not expect that they would have to invest in new recordkeeping staff, systems, or procedures to satisfy these proposed recordkeeping requirements.

We expect that for the requirement that the adviser make and keep a record of a memorandum describing the basis upon which it made its required initial and annual determinations, the compliance cost could be higher. This is because the adviser would first have to determine what to include in the memorandum, which could include retaining the services of compliance professionals who would need to review and familiarize themselves with the proposed requirements before supporting the adviser in the creation and maintenance of the required records.

We estimate recurring annual compliance costs associated with the proposed requirements of $309 per adviser that would maintain client crypto assets with a State trust company custodian.[1191] This estimate includes costs related to the creation and retention of the records and may include costs such as obtaining additional storage. We expect that these and other costs associated with the proposed requirements would vary across advisers based on the complexity of the required memorandum, which would depend on the complexity of the initial and annual determinations performed by the adviser.

(3) Records Related to Standing Letters of Authorization

The Commission is proposing to add a recordkeeping requirement related to the proposed amendment to the Advisers Act custody rule that provides an exception from the custody rule's surprise examination requirement if an adviser has custody of client assets solely because of a SLOA.[1192] The adviser would be required to make and keep a record of any SLOA that the adviser has in effect with a client and any related records pursuant to which the adviser relies or relied on the proposed exception to the Advisers Act custody rule's surprise examination requirement.[1193] The adviser would be required to retain such records for a SLOA that is in effect, or at any time within the past five years was, in effect.[1194]

The proposed amendments would help facilitate the Commission's examination and enforcement functions, including determining compliance with the proposed exception to the Advisers Act custody rule's surprise examination requirement, which would support its investor protection efforts. The proposed recordkeeping requirement would provide Commission staff with the ability to evaluate whether the adviser has satisfied the conditions to avail itself of the proposed SLOA exception or if, instead, the client's funds and securities must be subject to an annual surprise examination pursuant to the Advisers Act custody rule. The proposed requirement to keep records for any SLOA that is in effect, or that at any time within the past five years was in effect, would further enable the Commission to more effectively assess compliance practices within a recent timeframe. This would reinforce the protective measures included in the proposed SLOA exception.

Advisers having custody of client assets solely because of a SLOA and relying on the proposed surprise examination exception would incur costs related to creating and maintaining the required records. Advisers would incur these costs for the period during which a SLOA is in effect and for the five following years. However, we do not expect that these costs would be economically significant. Since advisers are already subject to extensive recordkeeping requirements, we do not expect that they would have to invest in new recordkeeping staff, systems, or procedures to satisfy the proposed recordkeeping requirements.[1195] The recurring incremental compliance costs arising from maintaining additional ( printed page 64025) records related to these proposed requirements using existing systems are estimated to be $39 per year per adviser that has clients that issue SLOAs.[1196]

(b) Regulated Fund Recordkeeping

(1) Records Related to the Proposed Fund Self-Custody Rule

Under the proposed amendments to the Investment Company Act recordkeeping rules, a regulated fund relying on the proposed fund self-custody rule would be required to make and keep certain records related to the proposed fund self-custody rule. Specifically, regulated funds would be required to preserve for a period not less than six years, the first two years in an easily accessible place, any report or other information provided to the fund's board of directors in connection with the board oversight requirements under the proposed rule 17f-9(b)(1) for each crypto asset of the fund held in custody under the proposed rule for fund self-custody of crypto assets.[1197] Such information would include the quarterly written report documenting the basis for the investment adviser's QC determination, as well as the adviser's annual written report regarding its expertise and systems, the most recent annual review of the adviser's safeguarding systems and cybersecurity controls, if available, the most recent written internal control report, if available, and any other information reasonably necessary for the board to evaluate the fund's custody arrangement.[1198] In addition, the proposed adviser self-custody rule and current regulated fund recordkeeping rules would also require a regulated fund to maintain records of resolutions regarding the board's designation of supervised persons with access to key materials permanently, the first two years in an easily accessible place.[1199] This requirement is based on the proposed adviser self-custody rule limiting access to fund crypto asset key materials to those persons designated by resolution of the board to have such access and the current recordkeeping requirements.[1200]

The proposed requirements would help facilitate oversight by a regulated fund's board. By having past documents available, a regulated fund's board could be better able to make the required annual determination on whether the assets maintained with the adviser would continue to be subject to reasonable care.

In addition, the proposed amendment would help facilitate the Commission's examination and enforcement functions, including determining compliance with the proposed fund self-custody rule, which would support its investor protection efforts. Commission staff would be able to observe documents received and evaluated by the regulated fund's board as part of its determination that the crypto asset would be subject to reasonable care, based on the standards applicable to safekeeping such assets, if maintained with the fund's adviser. This would help Commission staff determine whether the regulated fund's board has complied with the proposed determination requirement.

We expect that these proposed recordkeeping requirements would result in minimal costs for regulated funds since they would not require the creation of new documents but instead consist of maintaining documents received by the regulated fund's board. In addition, regulated funds are already subject to several recordkeeping requirements, including some under which the records must also be preserved for a period not less than six years, the first two years in an easily accessible place. Hence, we do not expect that regulated funds would have to invest in new recordkeeping staff, systems, or procedures to satisfy the proposed amendment. We estimate recurring annual compliance costs of $578 per regulated fund that would maintain crypto assets in self-custody through its adviser.[1201] This estimate includes costs related to the creation and retention of the records and may include costs such as obtaining additional storage.

(2) Records Related to the Proposed State Trust Company Rule

Under the proposed State trust company rule for regulated funds, a regulated fund would be required to make certain reasonable basis determinations in writing prior to engaging the State trust company as a custodian and on an annual basis thereafter.[1202] As part of these determinations, the regulated fund would be required to receive and review copies of the State trust company's most recent audited annual financial statements and internal control report.[1203]

Under the proposed recordkeeping amendments related to State trust company custody, a regulated fund that maintains client crypto assets and related cash and/or cash equivalents with a State trust company pursuant to the proposed State trust company rules would be required to make and keep the following records for a period of not less than six years, the first two years in an easily accessible place: (1) a memorandum describing the basis upon which the fund made its required initial and annual determinations with respect to the State trust company as a qualified custodian, (2) records of the State trust company's audited financial statements obtained or received, and (3) a copy of the State trust company's internal control reports obtained or received.[1204]

The proposed recordkeeping requirements would be similar to those that would apply to advisers under the proposed Advisers Act recordkeeping rule amendments except that, in the case of regulated funds, they would apply to the crypto assets and related cash and/or cash equivalents constituting “securities and similar investments.” Consequently, we expect that the benefits and costs discussed in section IV.C.7.a)(2) would also apply when regulated funds would maintain crypto assets with a State trust company custodian.

We estimate recurring annual compliance costs of $578 per regulated fund that would maintain its crypto assets with a State trust company custodian.[1205] This estimate includes costs related to the creation and retention of the records and may include costs such as obtaining additional storage. We expect that these and other costs associated with the proposed requirements would vary across advisers based on the complexity of the required memorandum, which would depend on the complexity of the initial and annual determinations performed by the adviser.

(c) Records Related to Crypto Assets From a Crypto Network

The Commission is proposing amendments to the Advisers Act and Investment Company Act recordkeeping rules to provide that records related to ( printed page 64026) crypto assets that are required to be maintained and preserved under the applicable recordkeeping rule may be maintained and preserved on a crypto network.[1206] Advisers and regulated funds would be required to provide such records to the Commission (including its examiners and other representatives) in a human-readable and reasonably usable electronic format promptly upon request by a Commission representative and continue to provide access for the same period that for which other books and records are required to be maintained and preserved under the Advisers Act and Investment Company Act recordkeeping rules.[1207] These proposed amendments would apply to any record required to be maintained and preserved under the Advisers Act and Investment Company Act recordkeeping rules related to crypto assets, including the proposed amendments related to crypto custody.[1208]

The proposed amendments would benefit advisers and regulated funds by reducing their recordkeeping costs in the instances where they would be able to leverage the recordkeeping capabilities of crypto networks to reduce the quantity of offchain records that they would need to maintain and preserve.[1209] This would also avoid duplicate records, which would improve efficiency.[1210] More generally, providing flexibility to advisers and regulated funds could reduce their costs as they would be able to tailor their recordkeeping practices based on their needs and cost structures.[1211]

The proposed amendment that would require the adviser or regulated fund to provide to the Commission (including its examiners and other representatives) the applicable records in a human-readable and reasonably usable electronic format promptly upon request would help facilitate the Commission's examination and enforcement functions, including determining compliance with the recordkeeping requirements, which would support its investor protection efforts. This proposed requirement would help ensure that Commission staff is able to review and analyze records on the crypto network and that it is able to review the same underlying information to which it currently has access when performing these functions, notwithstanding the tool used by the adviser or regulated fund itself to view the onchain records.

Onchain records could face risks that are different from those to which offchain records are subject. This is because offchain records are maintained and preserved by, and therefore under the control of, the adviser or regulated fund. On the other hand, onchain records exist on the crypto network. Hence, certain events could result in the records being lost or temporarily unavailable without the adviser or regulated fund being able to remedy the situation, unless it has duplicate offchain records available.[1212] This could affect the Commission's ability to protect investors by affecting its ability to perform its examination and enforcement functions. We do not anticipate any compliance costs associated with the proposed amendments.[1213]

8. Guidance for Accountants Updates

The 2009 Guidance for Accountants provides interpretive guidance for accountants on surprise examinations and internal control reports.[1214] We expect to revise certain aspects of the guidance for accountants set forth in the 2009 Guidance for Accountants to address auditing and attestation standards for crypto assets and other industry developments since its publication.[1215]

Specifically, we expect to specify that a material discrepancy—requiring accountants who perform surprise examinations to notify the Commission pursuant to a written agreement between the adviser and the accountant [1216] —would be, for example, a variance, irregularity, or omission identified during an accountant's examination that, individually or in the aggregate, indicates actual or potential loss, theft, misuse, or misappropriation of funds or securities. We also expect to include additional control objectives for internal control reports regarding information technology for non-crypto funds and securities custody.[1217] These control objectives are intended to help ensure that other control objectives are achieved when automated controls or reliance on computer-generated information is important.[1218] In addition, we also expect to make revisions regarding verification procedures for internal control reports so that the independent public accountant, instead of substantive testing as part of the control report procedures, should observe, inspect, and/or reperform a sample of ( printed page 64027) reconciliations as part of testing the reconciliation control objective to verify that the data used in such reconciliations is obtained from unaffiliated custodians and is unaltered.

Consistent with the control objectives regarding non-crypto funds and securities, we also expect to revise the guidance to introduce comparable control objectives regarding crypto assets. Additionally, the revised guidance would state the internal control report requirements when the custodian maintains both crypto assets and non-crypto funds and securities. In these circumstances, if the party responsible for controls related to crypto assets is the same as the party responsible for controls related to non-crypto funds and securities, instead of two internal control reports for each type of assets, the revised guidance would specify that the adviser may obtain a single internal control report satisfying all relevant control objectives for all relevant assets.

The revised definition of material discrepancy would help ensure timely notification to the Commission regarding matters that may put client funds and securities at risk. For example, by covering situations that could create a reasonable possibility of a material misstatement of funds or securities, the revised definition of material discrepancy could better align the definition of material discrepancy with the matters that an accountant's examination is designed to identify.

To the degree that internal control reports are prepared consistent with the revised guidance, the additional control objectives for internal control reports for non-crypto funds and securities custody would help ensure that other control objectives are achieved when automated controls or computer-generated information play a significant role. Having internal control report objectives for crypto assets that are similar to those for non-crypto funds and securities would help ensure that internal control reports provide comparable safeguarding benefits for clients' crypto assets. Additionally, the revision related to verification procedures would benefit accountants by eliminating duplication of efforts as they are already testing a sample of reconciliations as part of the reconciliation control objective. The revised guidance regarding the internal control report objectives when the custodian has custody of both crypto assets and non-crypto funds and securities would also benefit advisers by specifying that advisers do not need to obtain two separate internal control reports, provided the above conditions are met. This would help advisers save costs, which may be ultimately passed on to clients.

The revised guidance would also involve costs for accountants, to the extent that they change their practices consistent with the revised guidance. They may incur costs associated with updating their business practices to examine the proposed control objectives for internal control reports on funds and securities custody. Accountants may incur additional costs related to understanding and testing the proposed control objectives for internal control reports on crypto asset custody. Additionally, to the extent that they change their practices consistent with the revised guidance, advisers or their related party custodians may also incur costs associated with updating their business practices to satisfy control objectives to be able to provide custody services to advisory clients. These costs may be passed on to advisers and, ultimately, to their clients.

9. Disclosure and Reporting Requirements

The proposed disclosure reporting requirements would include amendments to Form ADV, including Part 1A, Form ADV General Instructions and Glossary of Terms, Part 2A of Form ADV, and Form ADV-E,[1219] and to Form N-CEN, aimed to provide the Commission and investors with enhanced and accurate information about the adviser's custodial practices, and to streamline reporting for advisers.

(a) Amendments to Form ADV

The proposed amendments to Form ADV Part 1A would include new questions related to crypto asset self-custody, new questions on tokenized private funds, new questions to Item 9, and a change in instructions for Item 9.[1220] We are also proposing amendments to conform with the current Advisers Act custody rule and the proposed amendments.[1221]

(1) Amendments Related to Crypto Asset Self-Custody

We are proposing amendments to Form ADV to introduce new questions associated with the self-custody of crypto assets. The proposed changes include amendments to: (1) Item 9 to add several new questions related to advisers' crypto asset self-custody practices under the proposed adviser self-custody rule; and (2) Item 5.K. and section 7.B. of Schedule D to add questions about crypto assets self-custodied on behalf of SMA clients and private funds. The proposed new questions and related instructions would concern the approximate amount (in U.S. dollars) and total number of clients for which the adviser has self-custody of crypto assets as well as the total number of crypto asset addresses that hold clients' crypto assets in the adviser's self-custody; independent public accountants engaged to prepare internal control reports with respect to custodial services in connection with the adviser having self-custody of crypto assets; quarterly account statements or alternatively, transmission of the required information in an account statement in a human-readable and reasonably usable electronic format; and, for advisers having self-custody of crypto assets on behalf of pooled ( printed page 64028) investment vehicles, audited financial statements furnished to investors and independent public accountants engaged to audit the pooled investment vehicles. The new questions in Item 9 would need to be completed on an aggregate basis (that is, covering all of an adviser's clients) while the other new questions would need to be completed separately for adviser's SMA clients in aggregate (Item 5.K. in Part 1A) and private fund clients (section 7.B. of Schedule D), as applicable.

The proposed reporting requirements would help investors assess custodial risks and advisers' compliance practices related to the self-custody of crypto assets, thereby allowing investors to make more informed decisions in selecting advisers when investing in these assets. Disclosure of this information would also help the Commission to effectively identify potential risks and evaluate the need for an examination of the adviser. Anticipating this, advisers would have stronger incentives to avoid harmful activities, thereby reducing agency costs and benefiting investors.

We estimate that these proposed amendments to Form ADV would result in one-time compliance costs of $553 and recurring annual compliance costs of $780 per adviser.[1222]

(2) Amendments to Item 9

We are proposing to make several amendments to current Item 9.[1223] First, we are proposing to make amendments to current Item 9.A.(1) on Form ADV. The current instructions to this question provide that an adviser should answer `no' if the adviser has custody solely because it deducts advisory fees or an operationally independent related person has custody of client assets in connection with advisory services provided to clients. We are proposing an amendment to the instructions that would provide that advisers should answer “yes” to Item 9.A.(1) if the adviser or its related person has custody of client funds or securities, notwithstanding whether the adviser meets any of the exceptions listed under proposed Item 9.A.(2). If the adviser answers “no” to Item 9.A.(1), the proposed amended instruction would further specify that the adviser should not complete the remainder of Item 9.

Second, we are proposing to make amendments to the current Item 9.A.(2) that requires advisers to exclude indirect custody figures, which are currently required to be separately reported under current Item 9.B.(2), when reporting the approximate amount of client funds and securities, as well as the total number of clients for which they have custody. The proposed amendments would redesignate Item 9.A.(2) as Item 9.A.(3) and require advisers to include indirect custody figures as well.[1224] In addition, the proposed Item 9.B.(2) would instruct advisers to report the amount of client funds and securities and the number of clients for which advisers have custody only because their related persons have custody. Moreover, the current Item 9.A.(2) instructs advisers to exclude from this reporting the amount of client assets and number of clients relating to custody arising solely from their fee deducting authority. We are proposing to instruct advisers to exclude from proposed Item 9.A.(3) reporting the amount of client funds and securities and the number of clients for which they have custody solely as a result of activities that would except advisers from having to comply with the surprise examination requirement or with the Advisers Act custody rule.[1225]

Third, we are also proposing to add new questions to Item 9.A. under proposed Item 9.A.(2) to address the adviser's reliance on certain exceptions under the Advisers Act custody rule. Proposed Item 9.A.(2)(a) would ask the adviser to disclose whether it relies on certain exceptions under the Advisers Act custody rule.[1226] Proposed Item 9.A.(2)(b) would ask advisers to answer “yes” if they have custody of client funds or securities solely because they have discretionary trading authority (as described under proposed rule 223-1(b)(9)) and/or because they have inadvertent custody (as described under proposed rule 223-1(b)(10)). The proposed Item would instruct advisers who check “yes” to not complete the remainder of Item 9.

Finally, we are proposing to amend Item 9.C to require advisers to disclose whether a State trust company (as defined in proposed rule 223-1(d)(18)) maintains client funds or securities pursuant to proposed rule 223-1(d)(13)(v).[1227]

The proposed amendment to the instructions in Item 9.A.(1) would help ensure collection of accurate information and improve compliance practices. Advisers who have custody solely because they deduct advisory fees but respond `no' to Item 9.A.(1) as currently instructed, may mistakenly believe that they are not subject to the Advisers Act custody rule. These advisers may also provide incomplete or inaccurate reporting in the remainder of Item 9. The proposed amendment would reduce uncertainty, assisting in reporting accurate information and complying with the Advisers Act custody rule's requirements. This would help in safeguarding the assets of advisory clients and mitigate compliance risks for advisers. Additionally, investors would benefit from the proposed amendment as more accurate Form ADV data may assist Commission staff in identifying compliance risks, which would support investor protection. Furthermore, the proposed amendment could result in cost savings for advisers that do not have custody as these advisers would no ( printed page 64029) longer need to complete the rest of the section if they respond `no' to Item 9.A.(1).

The proposed amendments to current Item 9.A.(2) and 9.B.(2) would also involve benefit for advisers and investors. We understand that current instructions have resulted in interpretive challenges and inconsistent reporting across advisers, especially among advisers with custodial arrangements that involve custodial authorities that are integrated between the adviser and its related persons or otherwise where the parameters of those custodial authorities between the adviser and its related persons are less than clear.[1228] The revised instructions are intended to alleviate these interpretive challenges and promote more consistent reporting of direct and indirect custody by advisers and their related persons. The instructions for proposed Item 9.A.(3) to exclude certain activities with mitigated custodial risks would allow investors and our examination staff to more accurately assess the degree of client exposure to custodial risks that subject advisers to the full extent of the Advisers Act custody rule and enhance our examination staff's ability to focus their examination efforts on material custodial exposures, enhancing investor protection.

The proposed new Item 9.A.(2) that addresses the adviser's reliance on certain exceptions under the Advisers Act custody rule would enhance investor protection by enhancing the Commission staff's ability to effectively carry out the Commission's risk-based examination program by facilitating more targeted assessments of custody-related risks.

Finally, the proposed amendment to Item 9.C. would provide information to clients and prospective clients on the use of State trust companies as qualified custodians by advisers. Because State trust companies are subject to State regulations that can vary from State to State, their use as qualified custodians could involve different risk for advisory clients' crypto assets and securities.[1229] This proposed amendment would assist investors in making informed decisions with respect to the choice of an adviser and help Commission staff assess advisers' practices for the custody of crypto assets.

We anticipate that the proposed amendments to Item 9 would create additional costs for advisers as they would need to understand the new instructions and potentially adjust their systems to collect and report the new information.[1230] In addition, advisers that currently erroneously believe they are not subject to the Advisers Act custody rule as a result of deducting advisory fees or having an operationally independent related person with custody may incur costs associated with complying with the amended instructions.

(3) Questions on Tokenized Private Funds

We are proposing to make amendments to Form ADV that would require advisers to report whether any reported private fund (or series or class thereof) is a tokenized fund.[1231] To the extent only certain series or classes of the private fund shares are tokenized, the adviser would be required to indicate the series or class involved. Advisers would also be required to provide the names of any crypto networks used to record ownership of the fund or class or series of the private fund.[1232]

Tokenization may involve new types of risk, which could eventually contribute to systemic risk. The proposed amendments would enhance investor protection as they would facilitate the Commission's oversight activities and assessment of a novel and growing trend in the tokenization of private funds. Furthermore, this information would help the Commission accurately identify affected parties should operational challenges affecting trade settlements, redemption processes, and/or pricing arise within a crypto network. This information would also involve benefits for investors as public disclosure of this information would help prospective investors in making informed decisions with respect to advisers that tokenize private fund shares.

We estimate one-time compliance costs associated with the proposed amendments to the private fund reporting requirements of $55 per private fund reported on Form ADV.[1233]

(b) Form N-CEN

We are proposing to make amendments to Form N-CEN to require reporting of whether the regulated fund (or Series or Class thereof) is a tokenized fund. Regulated funds that are tokenized funds would additionally be required to provide the names of any crypto networks used to record ownership of the fund or class or series of the regulated fund.[1234] We are also proposing to make conforming amendments to Form N-CEN in relation to the proposed crypto custody rules. Currently, Form N-CEN requires regulated funds to disclose information about entities that provided custodial services to them, including checking a box corresponding to the different types of permitted custodians for regulated funds under applicable rules and statutes.[1235] We are proposing to add two additional checkboxes, corresponding to the proposed crypto asset self-custody and State trust company rules.[1236] We are also proposing to amend the title of the checkbox for custody under rule 17f-1 from “Member national securities exchange” to “brokers or dealers” to correspond to the proposed title and scope of rule 17f-1.

These proposed amendments to Form N-CEN would enhance investor protection by providing the Commission with information to support its oversight and assessment of tokenized regulated funds and by assisting the Commission and data users in monitoring custodial risk and areas of concern.

We estimate one-time compliance costs of $570 and recurring annual compliance costs of $382 per registrant that would be affected by the proposed fund tokenization disclosure, one-time compliance costs of $570 and recurring annual compliance costs of $382 per registrant that would be affected by the proposed State trust use disclosure, and one-time compliance costs of $570 and recurring annual compliance costs of $382 per registrant that would be affected by the proposed self-custody use disclosure.[1237]

( printed page 64030)

(c) Disclosures of Risks Related to Crypto Asset

Open-end and closed-end funds are required to disclose, among other things, the principal risks of investing in the fund to their current and prospective shareholders in their prospectuses. Additionally, open-end funds are required to disclose non-principal strategies and the risks of those strategies in the SAI section of the registration statement. Similarly, advisers are required to deliver to prospective and current clients a narrative brochure that discloses information about the adviser's business, conflicts of interest, and investment strategies, among other required information.[1238] In addition, advisers may also be required to provide additional disclosures as part of their fiduciary duty.

When a regulated fund or an adviser invests (on behalf of a client) in crypto assets, these disclosures would be required to appropriately address the associated material risks. This generally would include a description of their crypto asset investment strategies and the risks associated with investing in crypto assets as well as custodial risks related to crypto asset investments.[1239] If the proposed self-custody rules are adopted, the adviser or regulated fund would need to disclose whether it holds crypto assets in self-custody as well as the associated material risks and conflicts of interest, including disclosure of what measures are in place if the assets are lost, stolen, or misappropriated or in the event of bankruptcy.[1240] Finally, if the proposed State trust company rules are adopted, the adviser or regulated fund would need to disclose whether it uses a State trust company as custodian for crypto assets and the associated risks that may arise from this arrangement.[1241]

Advisers and regulated funds may have incentives to avoid disclosure of certain risks absent the proposed guidance. There may also be uncertainty about what types of risks related to crypto asset investments should be included in the disclosures. To the extent that current disclosure practices are inconsistent with the matters outlined in the Commission's views, the Commission's views are intended to help ensure that investors are fully informed about these risks.

Without clear and detailed disclosure, some investors may not fully understand the risks associated with investments in crypto assets. In particular, some investors may not be fully aware of investment risks as some of the crypto assets may carry excess market price volatility and associated risks. Disclosure of crypto asset investment risks would benefit investors by helping them to understand these risks and could enable them to make more informed investment decisions. Similarly, there may be information asymmetry between advisers and their clients and between regulated funds and their investors regarding the unique custodial risks that arise from investing in crypto assets, as understanding these risks may require a certain level of knowledge about the nature of these assets.[1242] Disclosures about custodial risks would further help investors understand the risks beyond the investment risks as anyone with access to the private key could transfer crypto assets, and these transactions are generally irreversible. Furthermore, when an adviser has self-custody of crypto assets, the principal-agent problem between the adviser and its clients could be exacerbated and result in suboptimal custody practices by advisers, putting investors' crypto assets at risk.[1243] Disclosures associated with self-custody practices would mitigate the risks by allowing clients and investors to monitor adviser's self-custody practices and encouraging advisers to implement comprehensive safeguarding measures for investors' crypto assets. Finally, there may be information asymmetry concern when an adviser uses a State trust company as regulations may differ across States, and investors may not assess State-specific risks themselves without disclosure as this may require specialized knowledge about regulations. Therefore, disclosures about using State trust companies as crypto asset custodians would also benefit investors by providing information about the potential risks in a particular jurisdiction, or a specific State trust or custodial arrangement. Overall, we believe that the disclosure of the risks described in the proposed guidance would be beneficial for investors when deciding whether to make an investment in crypto assets through a particular adviser or fund.[1244]

10. Aggregate Monetized Benefits and Costs

Throughout this economic analysis, we have estimated monetized benefits and costs per affected entity. In this section, we present aggregate measures of these monetized effects across entities and time. These aggregates include only benefits and costs that are monetized in the economic analysis and thus do not encompass all of the proposed rules' and amendments' benefits and costs. In addition, these estimates assume each entity will realize the full extent of possible benefits and costs as a result of the proposed rules and amendments; actual benefits or costs may vary across entities depending on their existing practices and whether those practices continue after the proposed rules and amendments.

(a) Aggregate Monetized Benefits and Costs Across Affected Entities

Tables 7 to 11 report the benefits (Table 7) and costs (Tables 8 to 11) that are monetized in this economic analysis, aggregated across all affected entities.[1245] To aggregate these monetized effects we use estimates of the number of affected parties [1246] and burdens under the Paperwork Reduction Act in section V. The proposed crypto custody rules would only apply to advisers and regulated funds who choose to maintain crypto assets with a State trust company custodian under the proposed State trust company rule or who would choose to self-custody crypto assets. Hence, the number of affected parties for requirements related to the proposed crypto custody rules (including applicable recordkeeping and disclosure requirements) are estimates that could present over- or under-estimates. For the other proposed rules and amendments, the number of affected entities depends on the current and future practices of advisers and regulated funds.[1247]

( printed page 64031)

We were unable to quantify the main benefits of the proposal, which include benefits from the ability of advisers and regulated funds to gain access to custodial services via State trusts and self-custody to implement strategies for investors who seek out crypto investments. For the ancillary benefits for which we were able to provide estimates, the total aggregate initial monetized benefit is $0 and the total aggregate annual monetized benefit is $176,472.

We estimate that the total aggregate initial monetized cost is $301,856,490 and the total aggregate annual monetized cost is $433,706,625.1248

( printed page 64032)

( printed page 64033)

( printed page 64034)

( printed page 64035)

(b) Present Values and Annualized Values of Aggregate Monetized Benefits and Costs

Consistent with the requirements of Executive Order 12866, the Commission reports estimated total monetized benefits and costs for all affected entities in two additional ways specified in Office of Management and Budget ( printed page 64036) (“OMB”) Circular A-4.[1249] The two presentations are intended to address the fact that the various benefits and costs of the proposed rules and amendments would not accrue at the same point in time; rather, benefits and costs that accrue sooner are generally more valuable than those that occur later in time.[1250]

We report (1) the present values of expected benefits and costs that are monetized in our Economic Analysis, aggregated across all affected entities, over a 10-year time horizon, starting in 2026, as well as (2) the annualized values over the same time horizon that are derived from the present values. This time horizon represents the period over which the principal benefits and costs that are monetized in the Economic Analysis are expected to accrue.[1251] The present values and annualized values account for the timing of benefits and costs through discounting, which is a procedure that accounts for the time value of money.[1252]

Table 12 reports the present values of the aggregate monetized benefits and costs from Tables 7 to 11, combining initial and annual monetized benefits and costs. The analysis uses annual real discount rates of 3 percent and 7 percent over a 10-year time horizon, starting in 2026.[1253] We estimate that the present value of total monetized benefits is $1,527,755 using a 3 percent discount rate and $1,282,113 using a 7 percent discount rate. We estimate that the present value of total monetized costs is $4,056,545,978 using a 3 percent discount rate and $3,452,843,217 using a 7 percent discount rate.

( printed page 64037)

D. Effects on Efficiency, Competition, and Capital Formation

1. Efficiency

(a) Additional Options for Crypto Asset Custody

The proposed rules would include more crypto asset custody options for advisers and regulated funds as the proposed self-custody rules would allow advisers to self-custody their clients' crypto assets and the proposed State trust company rules would allow advisers and regulated funds to use State trust companies as custodians for crypto assets.[1257]

The additional options for crypto asset custody could enable advisory clients and regulated funds to invest in crypto assets as the current permitted custodians may not provide custody services for some crypto assets or may not allow certain activities, which may limit investment opportunities that may otherwise serve the client's or regulated fund's best interests. Hence, the proposed rules could increase crypto asset exposure obtained through advisers and regulated funds among interested investors, which could improve the efficiency with which their portfolios are managed and increase their risk-adjusted returns.

In addition, the proposed self-custody rules could contribute to increased efficiency in situations where advisers conducting extensive due diligence of novel or nascent crypto assets as part of their regular business activities would be able to custody these assets at lower costs than other entities that are permitted custodians and that would have to de novo acquire knowledge and technical expertise about the assets and the infrastructure that supports them.

Finally, the proposed State trust company rules could contribute to increased operational efficiency for certain entities. To the extent that some entities that previously were or currently are State trust companies currently hold or are in the process of obtaining a national bank charter solely for the purpose of providing crypto asset custodial services to advisers or regulated funds,[1258] the proposed State trust company rules could result in a more efficient allocation of resources. Under the proposed rules, it would no longer be necessary for these entities to keep the bank charter, thereby reducing the resources that would need to be allocated to complying with Federal banking regulations.[1259]

(b) Safeguarding Requirements

The proposed self-custody rules and State trust company rules include requirements to help ensure that investors' assets would be appropriately safeguarded against the risk of loss, theft, misuse, and misappropriation.[1260] Because of asymmetric information, investors could be unable to tell whether a custodian has in place safeguarding measures that are appropriate.[1261] Hence, these proposed requirements would help ensure that investors' crypto assets are not being maintained at custodians (including advisers who would self-custody client assets) that do not have appropriate safeguarding measures in place, thereby improving allocative efficiency of matching advisers and regulated funds with custodians.[1262]

(c) Third-Party Service Providers

The proposed adviser self-custody rule would not preclude an adviser from engaging third parties (including related persons) and service providers to support its effectuating of crypto asset custody and to help administer the required safeguards under the proposed self-custody rule, provided the adviser exercises appropriate oversight and continues to comply with the substantive requirements of the adviser self-custody rule.

Advisers typically do not specialize in custody operations; therefore, they may engage with third-party service providers that are specialized and have expertise in crypto asset custody. Using these service providers could help reduce the risks associated with the self-custody of crypto assets, helping advisers to offer efficient safeguarding systems for their clients. Even when advisers could offer similar protections with in-house developments, service providers may offer these services at lower costs due to economies of scale as these providers could serve a large number of clients. These effects would be more pronounced for advisers with a limited amount of crypto assets under ( printed page 64038) custody, since developing such systems could involve considerable fixed costs, thereby increasing expenses relative to the amount of assets under custody.

(d) Onchain Recordkeeping

The proposed amendments to the Advisers Act and Investment Company Act recordkeeping rules would provide that records related to crypto assets that are required to be maintained and preserved under the applicable recordkeeping rule may be maintained and preserved on a crypto network.[1263]

The development of crypto networks may afford advisers and regulated funds the opportunity to leverage the recordkeeping capabilities of crypto networks to support their recordkeeping obligations under the Advisers Act and Investment Company Act recordkeeping rules by providing information and records related to crypto asset transactions. Hence, under the proposed rules, advisers and regulated funds could devote fewer resources to maintaining offchain records, which would improve their operational efficiency. In addition, onchain recordkeeping could also reduce the need for error detection and correction, further improving efficiency.[1264]

(e) Custody Rules Modernization

The proposed amendments to modernize the Investment Company Act custody rules could enhance efficiency by removing duplicative or outdated requirements. In particular, the conditions under rule 17f-1 we are proposing to remove were adopted in 1940. Since that time, the Commission has adopted a comprehensive set of broker-dealer rules that collectively address the risks that the current rule 17f-1 conditions were designed to mitigate. Hence, removing these conditions could reduce the regulatory burden on regulated funds that use broker-dealers as custodians while preserving investor protection through the existing broker-dealer financial responsibility rules, SIPA and SIPC protections, and SRO oversight, increasing regulatory efficiency.[1265]

Similarly, the proposed rescission of rule 17f-3 under the Investment Company Act, which governs free cash accounts for regulated funds with bank custodians,[1266] would eliminate a requirement that has become obsolete due to technological advances in banking and payment processing. We understand that regulated funds are no longer using this rule, and its continued existence imposes unnecessary regulatory complexity without any corresponding investor protection benefit. As a result, rescinding rule 17f-3 would simplify the regulatory framework governing regulated fund custody without any loss of investor protection, thereby increasing regulatory efficiency.

[P]Table 13 reports annualized aggregate monetized benefits and costs using real discount rates of 3 percent and 7 percent over a 10-year horizon.[SU]1254[/SU][FTREF] The lump sum present values of aggregate monetized benefits and costs reported in Table 12 are converted in Table 13 into a constant stream of annualized benefits and costs over a 10-year time horizon, starting in 2026.[SU]1255[/SU][FTREF] Annualized benefits and costs may differ from an aggregation of the recurring monetized annual benefits and costs discussed earlier in the Economic Analysis because they incorporate the timing of benefits and costs, through discounting, and combine one-time and recurring benefits and costs.[SU]1256[/SU][FTREF] We estimate that annualized total monetized benefits are $176,472 per year using a 3 percent discount rate and $176,472 per year using a 7 percent discount rate. We estimate that annualized total monetized costs are $468,574,265 per year using a 3 percent discount rate and $475,254,613 per year using a 7 percent discount rate. Because the annualized benefits and costs are discounted and include both initial and annual benefits and costs, they should not be compared directly to the aggregate annual monetized benefits and costs in Tables 7 to 11.

Additionally, the proposed amendments to the Advisers Act could improve efficiency by removing requirements that impose costs on regulated entities while maintaining comparable levels of investor protection. For example, the proposed amendment that excepts advisers with custody solely due to a SLOA from the Advisers Act custody rule's independent verification requirement would reduce compliance burden on such advisers. The conditions an adviser would need to comply to rely on the proposed SLOA exception, which include that the qualified custodian must not be the adviser's related person, that the client's authorization must include the client's signature and information on the third-party recipient, and the prohibition on adviser authority to change such recipient information, could substantially reduce the risk of misappropriation, such that the independent verification requirement would not be meaningfully additive to investor protection in these circumstances.[1267] As a result, the proposed exception could allow advisers to direct compliance resources toward purposes that address greater custodial risks, thereby increasing the efficiency of their compliance programs.

Further, the proposed exception from the Advisers Act custody rule for circumstances in which an adviser has inadvertent custody could help reduce unnecessary compliance burdens.[1268] Subjecting these advisers to the full requirements of the Advisers Act custody rule in these circumstances impose compliance costs. The proposed exception could reduce this burden while preserving investor protection through the required conditions, including the requirement that advisers promptly notify clients and qualified custodians upon discovering such inadvertent custody and take steps to repudiate the unwanted authority.

The proposed amendments to the Advisers Act custody rule that remove the PCAOB registration and inspection requirements for accountants and auditors could similarly enhance efficiency.[1269] While there has been some evidence that PCAOB registration may improve audit quality, the causal effect of the PCAOB requirements on the quality of the services required by the Advisers Act custody rule remains uncertain.[1270] Therefore, removing this requirement could increase efficiency by reducing compliance costs for advisers, as it would allow them to choose an accountant from a larger pool, and there is no clear evidence suggesting that such an amendment would adversely affect investor protection related to these services.

The proposed amendments to the audit provision of the Advisers Act custody rule could improve efficiency as well.[1271] For example, the proposed amendment that would allow foreign PIVs to have audited financial statements prepared in accordance with accounting principles other than U.S. GAAP could improve regulatory efficiency by providing advisers with additional flexibility in how they satisfy the rule's requirements, while maintaining similar investor protections through the required conditions, including the reconciliation to U.S. GAAP for material differences. In addition, the proposed amendment that would extend the audited financial statement delivery deadline for advisers to a fund of funds and to a fund of funds of funds could reduce operational burdens associated with meeting a deadline that may not practicably be met given that these funds must first receive audited financial statements of the funds in which they invest. Furthermore, the proposed amendment that would modify the financial statement audit and delivery requirements for advisers to pooled investment vehicles formed within the 90 day period prior to the pooled investment vehicle's first fiscal year end could eliminate the cost of obtaining audited financial statements for a short initial period when assets and activity may be minimal, while ensuring that investors continue to receive relevant financial information (which may be unaudited) covering the first fiscal year of the pooled investment vehicle and annual audited financial statements covering both the first fiscal year and ( printed page 64039) second fiscal year after the end of the second fiscal year.

The proposed amendments could also improve efficiency by updating certain references. While the proposed amendments that would explicitly except advisers to BDCs from the Advisers Act custody rule and that would add references to BDCs in the Investment Company Act custody rules may not change existing market practices, the proposed amendments could still improve regulatory efficiency by reducing regulatory complexity and promoting more consistent compliance. In addition, the proposed amendments to rule 17f-4 and rule 17f-7 to update certain references and addresses would facilitate more efficient compliance without any reduction in investor protection.

2. Competition

(a) Additional Options for Crypto Asset Custody

The proposed State trust company rules would enhance competition among custodians for crypto assets.[1272] There is currently a limited number of permitted custodians that provide custodial services for a substantial range of crypto assets. Therefore, it may be difficult for advisers or regulated funds to find a permitted custodian for some crypto assets, or it may be prohibitively expensive. The proposed State trust company rules would permit such companies to serve as custodians for crypto assets, under certain conditions, thus increasing the number of permitted custodians. The increased number of custodians would enhance competition among custodians for crypto assets, which could benefit investors by lowering custody fees for crypto assets. Increased competition could also lead to an increase in the quality of the custodial services provided, including custodians' safeguarding systems, which could provide enhanced protection for investors' crypto assets.[1273]

The proposed self-custody rules would allow advisers to have self-custody of clients' crypto assets if they have a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset.[1274] Currently, advisers are not permitted to have self-custody of clients' crypto assets; [1275] consequently, there may be some crypto assets that advisory clients, including clients that are regulated funds, are not holding in their portfolio as a result of a lack of available permitted custodians. This may limit the visibility of, and therefore demand for, these assets. Under the proposed rules, advisory clients and regulated funds would be able to invest in these assets to the extent that the adviser and, if applicable, the regulated fund would be complying with the conditions in the proposed rules.[1276] This could increase the visibility of these assets and, as a result, increase the demand for them from other investors. This increase in demand could increase the incentives for permitted custodians to expedite the development of systems to be able to provide custody services for these crypto assets since it could signal that a larger number of advisers or regulated funds would demand their custodial services. Once permitted custodians establish the systems and are able to offer custody services, an adviser or regulated fund would be required to maintain the client crypto asset with a permitted custodian instead of having self-custody or, in the case of a regulated fund, maintaining the assets with the fund's adviser.[1277] Consequently, enhanced competition among permitted custodians could benefit investors by reducing the period of self-custody.[1278] As a result, investors could begin to realize the benefits of having permitted custodians safeguarding their crypto assets in a timelier manner.

In addition, the proposed additional options for the custody of crypto assets could result in a larger number of advisers offering crypto-related services and in a larger number of regulated funds investing in crypto assets to interested investors. This increase in competition among advisers and among regulated funds could benefit investors by making available additional investment strategies and by reducing fees and expenses related to these services.

(b) Accountants

The requirements under the proposed self-custody rules and State trust company rules could result in increased competition among accountants. Specifically, the internal control report requirement under the proposed self-custody rules and the internal control report and the financial statement audit requirements under the proposed State trust company rules could increase the demand for services provided by accountants. In response to this, new accountants could enter the market and begin offering these services. These effects would be mitigated if some of these State trust companies already engage independent public accountants to obtain internal control reports and have their financial statements audited under the baseline. Nevertheless, there would likely be more accountants in this market over time, resulting in greater competition. Enhanced competition could improve the quality of the associated audit services and thus benefit investors through more robust oversight provided by accountants and reduced custodial risks associated with self-custody and the use of State trust companies as crypto asset custodians. Prices for these services could go up initially as the demand increases; however, as new accountants enter the market, they would likely decrease over time.

In addition, the proposed amendments to the Advisers Act custody rule would remove the requirement that accountants must be registered with and subject to regular inspection by the PCAOB to perform certain activities.[1279] To the extent that accountants that do not meet the current PCAOB-registration and inspection requirements have sufficient technology, operational capabilities, and regulatory knowledge to provide these services, removing such requirements could increase the number of eligible ( printed page 64040) accountants. However, if PCAOB registration is not the primary barrier to entry into this market, the increase could be limited.[1280] In addition, the effect on competition could also vary between the services related to traditional assets and crypto assets. The effect on competition could be particularly significant for services related to crypto assets, as the current pool of accountants providing such services may be limited. Therefore, crypto-specialized accounting firms that are not registered with the PCAOB may potentially benefit from a competitive advantage.[1281]

An increased number of accountants that could provide services required by Advisers Act custody rule could promote competition, thereby potentially reducing the cost for advisers of obtaining services from accountants. To the extent that advisers pass on any such cost savings, their clients could benefit, for example from reduced fees.

Enhanced competition could also increase the quality of the services. Additional firms that are not registered with the PCAOB but capable of delivering high-quality services could enter the market to offer these services, which could lead to increased competition based on service quality. Therefore, removing the PCAOB requirement could lead to a greater number of high-quality firms in the market.

(c) Broker-Dealer Custody

The proposed amendments to rule 17f-1 would update and modernize the circumstances in which regulated funds may use broker-dealers as custodians. The proposed amendment permitting all registered broker-dealers, rather than only members of a national securities exchange, to serve as custodians for regulated funds would expand the pool of permitted custodians; which in turn could enhance competition among custodians. Additionally, removing the conditions in rule 17f-1 would also enhance competition among custodians as these amendments could enhance the feasibility of broker-dealers acting as custodians for regulated fund securities and similar investments. For example, the proposed amendment that would remove the condition requiring broker-dealer custodians to undergo three annual examinations could enhance competition among custodians as three annual examinations may be too costly for some broker-dealers, potentially limiting their ability to offer custody services for regulated funds. Therefore, removing this condition could expand the number of available custodians and enhance competition in the custody market. Furthermore, we also anticipate that removing the segregation condition could further promote competition, as the current segregation condition requires physical segregation of assets, which is inconsistent with the uncertificated nature of most of the current assets.

Regulated funds that currently use broker-dealers as their custodians could benefit from these amendments as they could incur lower custody fees due to enhanced competition. Additionally, regulated funds that may prefer broker-dealer custodians but are currently constrained by high costs could also benefit from these amendments. This would be particularly relevant for funds that may have low negotiating power regarding custody fees.

3. Capital Formation

The proposed self-custody rules could promote capital formation as they could lead to an increase in demand for nascent crypto assets among interested investors.[1282] For example, the proposed adviser self-custody rule would make it easier for venture capital funds to invest in new firms that could eventually issue nascent crypto assets, which they could distribute to their investors or in which the funds could decide to invest. Under the proposed rule, the funds' advisers would be able to self-custody crypto assets for which no permitted custodian would be available, under certain conditions.[1283] This would make it easier for the firms issuing these crypto assets to raise capital. To the extent that investment in nascent crypto assets represent new capital formation rather than a reallocation from other investment vehicles, the proposed self-custody rules would promote capital formation.

E. Reasonable Alternatives

1. Alternative Qualified Custodian Determination Criteria in Adviser Self-Custody

We propose to require that, in order to be permitted to self-custody client crypto assets, advisers make a determination in writing, prior to taking self-custody of each crypto asset and no less frequently than on a quarterly basis thereafter, that the adviser has a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset.

As an alternative, we considered allowing advisers to self-custody client crypto assets when no qualified custodians are available or when using them would prevent the adviser from implementing investment advice in the best interests of its client, based on the client's investment objective. Compared to the proposal, this approach could increase the benefits of self-custody for investors, as advisers could be able to support certain investment strategies, for example strategies involving network-related activities ( e.g., staking) that they may not be able to support under the proposal if at least one qualified custodian is available to maintain the crypto asset but no qualified custodians facilitate such activities. However, this alternative could also increase costs for advisers by potentially adding a need for additional research into auxiliary services provided by qualified custodians in order to be able to make the required QC determination. Additionally, this method would broaden the eligibility for and potentially the use of self-custody, thereby potentially increasing misappropriation risks that are inherent to self-custody arrangements.[1284]

As another alternative approach, we considered permitting advisers to self-custody client crypto assets without any determination criteria, provided that the adviser has a reasonable belief that self-custody serves the client's best interests. For instance, for advisers that have established adequate safeguarding systems, the incremental costs associated with the self-custody of additional crypto assets could be relatively low. Consequently, the expenses related to self-custody could potentially be lower than the fees incurred for custodial services offered by a qualified custodian.[1285] Hence, under this alternative, self-custody could represent a more cost-effective solution, which could benefit investors. To the extent that the costs of implementing certain strategies would decrease due to more economical custody solutions, investors could benefit, for example from higher returns or lower fees. In addition, to the extent that lower costs encourage more advisers to implement strategies involving crypto assets, investors could further benefit from greater investment ( printed page 64041) options. However, self-custody could increase the risk of misappropriation of assets by advisers and could introduce additional operational risks if the adviser's safeguarding systems are less robust than those implemented by qualified custodians.[1286]

2. Alternative Protective Measures in Adviser Self-Custody

We are proposing certain conditions designed to address custodial risks associated with self-custody, including requirements for safeguarding expertise and systems and cybersecurity controls. We considered several alternative approaches to these custodial protection conditions.

As an alternative to the proposed safeguarding system requirements, we considered less prescriptive approaches. For instance, we considered allowing advisers to maintain more than one client's crypto assets in a single crypto asset address, while still mandating the segregation of clients' assets from an adviser's proprietary assets (that is, the adviser's proprietary assets would need to be maintained in a different crypto asset address), similar to the current requirement for qualified custodians.[1287] Compared to the proposed approach, which requires each client's assets to be segregated from those of other clients, advisers would likely incur lower costs associated with wallets and key management. However, this alternative would also make it more difficult for investors to monitor their balances and transactions since it would be difficult for investors to identify their portion of the assets maintained in a given address. This cost is especially relevant in the context of self-custody, given the heightened risk of misuse and misappropriation.

We also considered requiring advisers to make the QC determination less frequently than quarterly, for example, annually. Compared to the proposed approach, this alternative would result in lower compliance costs for advisers, which could be passed on to investors as lower fees. However, the crypto market is rapidly evolving, as is the market for crypto custodial services.[1288] It is possible that using a qualified custodian for certain assets becomes possible, shortly after an adviser takes custody of the clients' assets. An annual review requirement could therefore result in crypto assets remaining in self-custody, rather than with a qualified custodian, for longer than necessary.

We also considered more prescriptive approaches. For example, we considered requiring advisers to implement specific key management procedures that are current industry practices ( e.g., multi-signature wallets, MPC, etc.). Compared to the principle-based approach we are proposing, this alternative would likely result in more homogenous safeguarding systems and controls across advisers, facilitating easier comparison of custodial practices for investors and potentially reducing monitoring costs. However, technology and market practices related to crypto assets are rapidly evolving, with each crypto network having unique characteristics and potential vulnerabilities. As a result, a prescribed approach may not be able to accommodate the characteristics and specific custodial risks of each crypto asset in self-custody and could become outdated quickly, thereby compromising the efficacy of safeguarding systems and increasing custodial risks.

As another alternative, we considered requiring advisers to review their safeguarding systems more frequently than annually, for example, on a quarterly basis. Crypto networks frequently undergo protocol improvement upgrades. To the extent that an adviser's annual review would occur too long after these upgrades, the adviser could fail to adapt its safeguarding systems accordingly, thereby exposing clients' assets to higher risk.[1289] Hence, more frequent reviews would help ensure that advisers' safeguarding systems are promptly updated to addressing emerging risks. However, compared to the proposed approach, this alternative would result in higher compliance costs. In addition, advisers' fiduciary duty would continue to apply, requiring the adviser to act in the best interests of its client at all times. Hence, advisers could monitor such protocol improvement upgrades and modify their safeguarding systems accordingly more frequently than annually, mitigating the benefits of a more frequent review requirement.

We also considered requiring advisers to designate a responsible person, or group of persons, in connection with the safeguarding systems and cybersecurity program used for the adviser's self-custody of crypto assets. This responsible person or group of persons—for example, a chief information security officer, chief compliance officer, or other designated person or group—would be responsible for overseeing and implementing the adviser's safeguarding systems and cybersecurity program or parts thereof, including functions and services performed by third parties in connection with the adviser's self-custody of crypto assets. Under this alternative, advisers would be required to establish, maintain, and enforce reasonably designed written policies and procedures that specify the criteria for identifying such individual(s) and provide for the documentation of their designation.

Designating a responsible person or group of persons to oversee and implement an adviser's safeguarding systems and cybersecurity programs could promote more effective implementation and oversight of those systems and programs. A designated responsible person or group of persons could help ensure that potential vulnerabilities or incidents affecting the safeguarding of crypto assets are identified, allowing the adviser to determine whether corrective action is needed and to take any appropriate steps without a delay. By improving the timeliness and quality of an adviser's response to safeguarding deficiencies, this alternative could reduce the likelihood and severity of client asset loss, theft, or unauthorized access, thereby benefiting investors.

Advisers would incur costs associated with drafting, maintaining, and periodically updating written policies and procedures that specify criteria for identifying responsible individuals and documenting their designation. Advisers could also incur additional costs from recruiting or training staff to ensure certain qualifications or experience for any designee serving in this capacity. These costs would likely be largely fixed and therefore would be more burdensome for advisers with a limited amount of crypto assets under self-custody, as such advisers would have a smaller base of self-custodied assets over which to spread these costs.

3. Alternative Board Oversight Measure in Regulated Fund Self-Custody

The proposed fund self-custody rule would permit regulated funds to self-custody their crypto assets by maintaining such assets with their adviser if (a) the adviser complies with the proposed adviser self-custody rule and (b) the fund's board of directors exercises oversight responsibilities by making an initial and annual determination that the fund's crypto ( printed page 64042) assets will be subject to reasonable care, if maintained with the fund's adviser, after considering the factors relevant to the safekeeping of the crypto assets. To facilitate the board's determination, the adviser would be required to furnish such information as may reasonably be necessary for the board to evaluate the fund's custody arrangement.[1290]

As an alternative, we considered more prescriptive approaches regarding the information that a board would be required to evaluate. Some regulated fund boards may lack proficiency in crypto assets and the associated technology, potentially limiting their ability to evaluate the information provided by the adviser.[1291] Hence, in addition to the information required to be provided by the adviser under the proposed fund self-custody rule, we considered requiring that a regulated fund's board obtain independent assessments from third parties. For example, we considered requiring that a regulated fund's board receives a custody service landscape study conducted by a third party to facilitate its evaluation of the adviser's determination that a qualified custodian is not available to maintain the crypto assets. Such information obtained from independent third parties could serve as potential benchmarks when evaluating the information provided by advisers. Additionally, independent information could serve as a discipline mechanism, encouraging advisers to be more thorough in their determination process.[1292] However, compared to the proposed approach, the additional third-party assessments would result in additional costs for regulated funds. In addition, it would be challenging for the Commission to prescribe more specific information to be obtained by the board that would be appropriate in all cases and would remain so over time. Furthermore, regulated fund boards are empowered to demand information beyond the information that would be required by the proposed rule, if necessary to the board's determination of whether to permit an adviser to hold the fund's crypto assets in self-custody.

4. State Trust Companies as Permitted Custodians

Under the proposed State trust company rules, advisers and regulated funds would be permitted to use State trust companies as custodians for crypto assets, under some conditions. As an alternative, the Commission considered permitting the use of State trust companies as custodians by advisers and regulated funds for all types of assets, including both traditional assets and crypto assets. Under this alternative, additional initial and annual reasonable basis determination requirements would be added to complement the proposed requirements that would apply only to crypto assets.[1293]

To the extent that the number of State trust companies providing custodial services for traditional assets to advisers and regulated funds would increase as a result of this alternative,[1294] this alternative could make it more likely that advisers and regulated funds find a custodian that fits their needs or does so at a lower cost. It could also result in advisers and regulated funds that have both crypto and traditional assets being able to find a custodian that fits all of their custody needs (instead of having a custodian for traditional assets and a different custodian for crypto assets), which could reduce their costs associated with custodial services.[1295] This would benefit investors as it could increase the quality of the custodial services provided or reduce the fees and expenses charged by advisers and regulated funds.

However, it is our understanding that there is no shortage of permitted custodians for traditional assets. In addition, we are not aware of adviser or regulated fund demand for custodial services from State trust companies for traditional assets.[1296] Hence, we do not expect that this alternative would, in practice, result in significant benefits for advisers and regulated funds. Furthermore, while we are aware of State trust companies that have built an expertise in the custody of crypto assets, we are not aware that these or other State trust companies would have comparable expertise in the custody of traditional assets.

5. Alternative Conditions Attached to the Use of State Trust Companies as Custodians for Crypto Assets

Policies and Procedures

The proposed State trust company rules also include as a requirement that the adviser or regulated fund have a reasonable basis for believing, after due inquiry, that the State trust company maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation, with such policies and procedures addressing, at a minimum, private key management and cybersecurity.

Instead of this last requirement, the Commission considered alternative, more prescriptive approaches where the adviser or regulated fund would be required to have a reasonable basis to believe, after due inquiry, that the State trust company's policies and procedures include specific safeguarding elements, such as joint authorization for transactions ( e.g., using multi-signature wallets), specific key management procedures ( e.g., the encryption of store key material), or the use of cold wallets in certain circumstances.[1297] The Commission also considered requiring that the adviser or regulated fund have a reasonable basis to believe that the State trust company is appropriately mitigating cybersecurity risks, for example by making periodic assessments of cybersecurity risks associated with the safeguarding of crypto assets.[1298] These approaches would provide additional information to advisers and regulated funds and could result in them selecting a custodian that ( printed page 64043) better fits their needs. It could also result in the crypto assets being placed and maintained with State trust company custodians that have in place more protective controls, which could result in the assets being at lower risk of theft, loss, misuse, and misappropriation.

However, these approaches would result in higher costs for advisers and regulated funds, who would have to verify that a State trust company that they are using or considering using as custodian for crypto assets has the prescribed safeguarding or cybersecurity measures in place. Due to the highly technical nature of the task, the adviser or regulated fund could be unable to understand and appropriately interpret information that it would receive from a custodian without significant effort or external help. In addition, because different crypto assets are traded on different networks, the same safeguarding elements could be unequally effective across different assets. As a result, these alternative requirements could result in advisers and regulated funds being unable to use as custodians State trust companies that have in place controls that are more effective at safeguarding crypto assets than the controls that would be specified in the requirements. Furthermore, these more prescriptive approaches could, by requiring the sharing of potentially sensitive information, result in bad agents having additional information on the types of controls that are put in place by State trust company custodians, which could result in an increased risk that the controls become compromised and that the assets get stolen. Finally, as the technology supporting crypto assets evolves, the prescribed safeguarding elements could become less effective over time and inconsistent with industry best practices.

Audited Financial Statements and Internal Control Report

Under the proposed State trust company rules, the adviser or regulated fund would be required to receive and review the State trust company's most recent audited financial statements and internal control report.

As alternatives, the Commission considered not requiring that the adviser or regulated fund receive and review one or both of these documents.[1299] To the extent that they would choose not to receive and review these documents in the absence of the proposed requirements, these alternatives would result in lower costs for advisers as they would not need to review the documents, which could be technical and challenging to understand.[1300] They would also lower the costs for the State trust companies providing custodial services under the proposed State trust company rules, to the extent that they would not obtain audited financial statements or an internal control report in the absence of a request from an adviser or regulated fund. This could result in lower costs for advisers and regulated funds if State trust companies reduce their prices as a result. However, we expect that many State trust companies providing custodial services for crypto assets would obtain these documents even in the absence of the proposed requirements on advisers and regulated funds.[1301]

In the absence of the proposed requirements that the adviser or regulated fund receive and review the State trust company's financial statements and internal control report, it would be uncertain whether the adviser or regulated fund, as part of its due inquiry, would review documents that would not have been prepared by the State trust company itself.[1302] Being audited or prepared by independent public accountants, these documents provide a credible external perspective of the State trust company's ability to implement its policies and procedures relating to the safeguarding of crypto assets. Hence, we expect that, without the proposed requirements, an adviser or regulated fund could be less well informed when making decisions on the selection of a custodian for crypto assets. This could result in the assets being less well safeguarded and therefore at higher risk of theft, loss, misuse, and misappropriation.

Rehypothecation

The Commission considered permitting regulated funds or investment advisory clients engaging State trust companies as custodians under the proposed State trust company rules to provide consent to have their assets rehypothecated. Under this alternative, rehypothecation would be permitted only in instances where the regulated fund or advisory client has given prior consent and where rehypothecation is done for the benefit of the regulated fund or advisory client. Rehypothecation of client assets is used primarily by custodians to finance lending to their clients and to reduce the costs of this financing. Hence, the benefits of alternative would include financing at a lower cost or fee reduction for a margin account for the regulated funds and advisory clients. Regulated funds' investors would benefit via higher returns and/or lower fees.

The rehypothecation of crypto assets by custodians can expose the assets to certain types of risk. For example, the assets being rehypothecated could be lost if they are lent to a counterparty that is unable to repay. Without necessarily being lost, the assets could also be unavailable to the fund or advisory client at a time where it would otherwise trade them, which could potentially impact the implementation of its investment strategy. Such events could negatively affect a fund's or advisory client's return. The potential benefits and costs of this alternative would apply to the extent that rehypothecation would take place. The Commission does not currently have sufficient information to understand whether permitting rehypothecation would change market practice.[1303] For this reason, we are not proposing this alternative.

Additional Conditions

The Commission considered additional conditions to the use of State trust companies as custodians for crypto assets by advisers and regulated funds. For example, the Commission considered requiring that the adviser or regulated fund have a reasonable basis to believe, after due inquiry, that the State trust company has insurance coverage for the crypto assets for which it is the custodian. As another example, the Commission considered requiring that the adviser or regulated fund have a reasonable basis to believe, after due inquiry, that the State trust company is subject to capital requirements under applicable State law or posts sufficient collateral to the adviser or regulated fund.

These alternatives would benefit investors by potentially reducing their losses in the event that their crypto assets would be lost or stolen.[1304] In ( printed page 64044) addition, to the extent that they would result in more State trust company custodians obtaining insurance or posting collateral in order to facilitate their potential adviser and regulated fund clients' compliance with the custody rules, the alternative requirements could provide incentives to State trust company custodians to have better safeguards in place in order to avoid increases in insurance premiums or losses of collateral that could result from safeguarding failures. This would result in the crypto assets being better safeguarded and reduce the risk of theft, loss, misuse, and misappropriation.[1305]

However, these alternatives would result in an increase in costs for advisers and regulated funds, which would have to perform the due inquiry to be able to make the reasonable basis determination. In the case of the capital requirement alternative, this cost could be significant, especially if the adviser or regulated fund considers custodians organized in different States. These alternative requirements could also increase the cost of the custodial services agreement, to the extent that the custodian would pass along insurance, collateral, or capital requirement costs to its clients. Increased costs for advisers and regulated funds could be passed on to advisers, for example via higher fees or expenses. In addition, these alternative requirements could result in fewer custodians available for advisers and regulated funds as some State trust companies may not include insurance, collateral, or capital requirements in their services.[1306]

6. Crypto Asset Trading

The Commission considered the possibility of proposing a new, stand-alone rule to permit advisers and regulated funds to maintain assets on crypto trading platforms that are not permitted custodians and would not be permitted custodians under the proposed rules, under certain conditions. The Commission considered permitting advisers and regulated funds to maintain crypto assets at a crypto trading platform for a limited period of time, for example 24 hours. The Commission also considered permitting advisers and regulated funds to maintain crypto assets at a crypto trading platform for a period longer than 24 hours, but only under certain conditions. These conditions could have included, for example, that the adviser (including a regulated fund's adviser) (1) reasonably determines that placing and maintaining crypto assets at the crypto trading platform is in the best interests of the client and presents minimal risk of loss, theft, or misuse of the assets; (2) receives and reviews the crypto trading platform's policies and procedures regarding the safeguarding of crypto assets and has a reasonable basis to believe that such policies and procedures are reasonably designed to safeguard crypto assets from the risk of theft, loss, misuse, and misappropriation before placing client assets on the crypto trading platform; and (3) regularly obtains and reviews internal control reports of the crypto trading platforms.[1307]

These alternatives could result in investors obtaining higher risk-adjusted returns or being able to follow investment strategies that better fit their objectives. For example, these alternatives could allow advisers and regulated funds to use certain platforms that require pre-funding and potentially to trade crypto assets that may be available only on such platforms.[1308] The alternative allowing advisers and regulated funds to maintain crypto assets at a crypto trading platform for periods longer than 24 hours could also allow advisers to implement strategies that require frequent and rapidly-executed trading, such as arbitrage strategies. However, the Commission currently lacks sufficient data to conclude that such benefits would be significant, and therefore preliminarily does not expect that such a rule would significantly affect investors' and regulated funds' market practice. In addition, to the extent that advisers and regulated funds would rely on such a rule, investors' assets could be subject to higher risk, depending on the conditions that would be included in the rule. Stricter conditions would reduce such risk but could result in significant costs for advisers and regulated funds, potentially making it impractical or not in the client's best interests to rely on the rule.[1309]

7. Other Alternatives for Investment Company Custody Rule Modernization

We considered proposing additional Investment Company Act custody rules or amendments to the Investment Company Act custody rules to accommodate certain custodial arrangements, including custody of regulated fund assets with an affiliated custodian and custody of certain uncertificated securities that cannot be placed with a securities depository.[1310]

Regulated funds may be subject to rule 17f-2 as a result of using an affiliated custodian, requiring them to undergo three examinations annually in addition to the annual audit requirement for all regulated funds.[1311] We considered amending rule 17f-2 to require internal control reports in lieu of the three annual examination requirements.[1312]

This alternative could benefit investors of regulated funds using an affiliated custodian. Related person custody arrangements can present higher risks; and as acknowledged in the 2009 Adopting Release, surprise examination alone may not adequately address custodial risks associated with these arrangements because the independent public accountant seeking to verify client assets would rely, in ( printed page 64045) part, on custodial reports issued by the adviser or the related person.[1313] However, internal control reports would provide an important check on the safeguards relating to custodial practices of an affiliated party custodian and verify that the fund's reported assets exist, enhancing investor protection in these arrangements. In addition, regulated funds would also benefit from this alternative by saving costs associated with three examinations annually.

This alternative could also involve costs. Instead of three examinations, affiliated custodians could incur costs associated with obtaining internal control reports, which can be passed on to regulated fund investors through higher fees or expenses. However, we understand that custodians often already provide internal control reports to clients who demand a rigorous evaluation of internal control as a condition of obtaining their business, therefore regulated funds may use these internal control reports to satisfy the requirement at no additional cost.

We also considered amendments to rule 17f-4 and 17f-2 regarding custody of uncertificated securities. Regulated funds can generally hold their investments in the uncertificated securities with an Investment Company Act custodian, but we understand that regulated funds have difficulty custodying certain uncertificated securities that cannot be placed with a securities depository, including regulated fund shares, privately offered securities, and loan shares. Ownership records of regulated fund shares are maintained by the transfer agent of the fund, privately offered securities are generally recorded only on the books of the issuer, and loan interests and the principal amount of the loan attributable to each investor are maintained by the administrative agent on behalf of borrowers. None of these entities maintaining ownership records is a permitted custodian, making it difficult for a regulated fund to custody with a permitted custodian.[1314]

We considered proposing to amend rule 17f-4, which governs custody of regulated fund assets with securities depositories, to designate transfer agents as an additional type of permitted custodians for custody of regulated fund shares.[1315] This alternative could technically benefit acquiring funds' investors as the conditions under 17f-4 that are designed to safeguard fund assets could enhance investor protection.[1316] However, additional investor protection benefits from these conditions could be limited, as regulated funds are already subject to annual audits in which an independent public accountant verifies regulated fund's investments, helping ensure safekeeping of these assets. Moreover, these benefits would not apply for acquiring funds that already operate in accordance with the Commission staff's no-action letter regarding maintaining acquired fund shares at the transfer agents.[1317]

If the acquiring fund has self-custody of the acquired fund shares or the transfer agent is an affiliated party of the acquiring fund, acquiring funds are required to comply with rule 17f-2 instead of 17f-4; and certain requirements under rule 17f-2 may not be achievable.[1318] In particular, it may not be achievable to keep ownership records in a vault or other depository maintained by a bank or regulated entity, satisfy the written notation requirement for each transaction, and satisfy three examination requirements by an independent public accountant to physically verify such assets.[1319] Therefore, designating transfer agents as permitted custodians under rule 17f-4 could not provide any benefits in these arrangements.

Designating transfer agents as permitted custodian under rule 17f-4 could also involve costs. Specifically, transfer agents planning to offer custody services could incur compliance costs to the extent they need to modify their practices to meet the requirements of rule 17f-4.

We also considered proposing an exception for privately offered securities from the requirement that regulated fund assets must be held with a permitted custodian.[1320] This exception could benefit regulated funds investing in privately offered securities as custody of privately offered securities with current permitted custodians could pose difficulties as ownership of such assets generally is recorded only on the books of the issuer.

We do not expect this exception would reduce investor protection because risk of loss or theft is low with respect to privately offered securities as they are not easily transferable.[1321] In addition, an independent public accountant verifies regulated fund's investments as part of the annual audit, providing additional protection against the risk that the custody rules seek to prevent.

We also considered proposing a new rule for custody of regulated funds' investments in uncertificated loan interests, subject to conditions described in the K&L Gates NAL.[1322] This alternative could provide benefits to regulated funds investing in loan interest because custody of loan interests with current permitted custodians may involve difficulties, and compliance with vaulting, access, and notation requirements under rule 17f-2 may not be achievable. The conditions in the K&L Gates NAL would help achieve the same goal as rule 17f-2—the prevention of misappropriation. However, benefits from these conditions could be limited because an independent public accountant already verifies regulated funds' investments in loan interests as part of an annual audit.

Overall, we are not proposing these alternatives as the Commission could benefit from further feedback on such a comprehensive set of topics to determine the scope of appropriate modernizations to the Investment Company Act custody rules.

8. Alternative to the Independent Verification Requirement

As an alternative to the independent verification requirement of the Advisers Act custody rule,[1323] we considered a combination of reconciliation obligations, enhanced client disclosure, and mandatory incident reporting. Under this alternative, we would require advisers with custody of client funds and securities to implement daily system-based reconciliations of their internal books and records against the records maintained by qualified ( printed page 64046) custodians, supported by documented exception management procedures that identify, escalate, and resolve discrepancies. In addition to the reconciliation component, this alternative would require advisers to furnish clients, on a quarterly basis, with a summary of custodial balances and any material reconciliation exceptions, accompanied by a standing notice explaining how clients may independently confirm their account balances and positions directly with the qualified custodian.

There have been significant advances in data aggregation and recordkeeping technology that have occurred since the surprise examination requirement was first adopted. Continuous, potentially automated, reconciliations of this manner could potentially provide more timely detection of safeguarding failures than a periodic surprise examination conducted on an annual basis. By empowering clients with the information and means necessary to verify their holdings and any exceptions on an ongoing basis, this element of the alternative could deter and detect misappropriation without imposing the compliance costs associated with engaging an independent public accountant to conduct a surprise examination. In addition, this alternative would complement the foregoing requirements with a mandatory incident reporting obligation, under which advisers would be required to report significant safeguarding incidents, including unauthorized transfers and material reconciliation breaks, to the Commission and to affected clients within a prescribed period following detection. Timely reporting to the Commission would facilitate regulatory oversight and allow the Commission to identify patterns of safeguarding failures across the industry, while prompt notification to affected clients would enable them to take protective action.

This alternative could also involve costs. Specifically, there could be uncertainty about how to define reportable incidents with sufficient precision. This uncertainty could lead to both under-reporting and an undue volume of immaterial disclosures, thereby potentially making aggregate deterrent and detection benefits uncertain. Moreover, such an alternative would require advisers to invest significantly in internal controls related to reconciliation systems and technology while also relying on the adviser itself, as opposed to a qualified custodian or an independent third-party, to provide the summary of custodial balances, any material reconciliation exceptions, and self-report any significant safeguarding incidents.

9. Adviser Account Statements

Under the current Advisers Act custody rule, an adviser with custody of client funds or securities is required to have a reasonable basis, after due inquiry, for believing that the qualified custodian holding those assets sends account statements to the adviser's clients on at least a quarterly basis.[1324] The current Advisers Act custody rule does not, however, mandate that advisers themselves prepare and deliver account statements, relying instead on the custodian's statement as the primary vehicle for client disclosure, supplemented in certain circumstances by an adviser-prepared statement where the adviser is also the qualified custodian or an affiliate. The Commission considered requiring advisers to prepare account statements in addition to the account statements from qualified custodians. Specifically, the Commission considered requiring each adviser with custody of client funds and securities to prepare and deliver to clients, on a quarterly basis, an account statement providing a clear itemization of the amount of funds and each security held in the account at the end of the period, together with a complete record of all transactions, including incoming and outgoing transfers, occurring during that period. The adviser's account statement would identify each security or instrument by name and quantity, provide a summary of all fees deducted from the account during the period, and include a prominent notation directing clients to compare the adviser's statement against any account statement they receive directly from their qualified custodian.

Adviser-prepared account statements could serve as another important disclosure mechanism for advisory clients. In addition, this alternative could provide clients with a more granular and adviser-specific view of their account activity than a custodian statement alone, particularly where custodian statements may not reflect the adviser's fee calculations or the full context of portfolio transactions. This alternative could also leverage the client's own ability to identify discrepancies between the adviser's representations and the custodian's independent records, thereby providing a check on the accuracy of the adviser and custodian's disclosures. However, its effectiveness as a safeguarding mechanism would depend in significant part on clients' willingness and ability to actively compare statements received from two separate sources.

This alternative would also impose additional preparation and compliance costs on advisers and require advisers to implement and maintain written policies and procedures reasonably designed to ensure that adviser-prepared statements are accurate and delivered in a timely manner.

10. Sharing Key Materials

The proposed adviser self-custody rule would require an adviser with self-custody of client crypto assets to limit access to key materials to only supervised persons designated by the adviser.[1325] Therefore, the adviser would not be permitted to share key materials with anyone outside of the adviser including the client. As an alternative, we considered permitting advisers to share key materials with the client whose crypto asset the key materials are associated with. Under this alternative, private keys would be distributed between the adviser and the client in an arrangement that the client's share is necessary but not sufficient to move the crypto assets, and advisers would therefore be required to obtain explicit client authorization for each transfer of the client's crypto assets.

This alternative could benefit investors by reducing the risk of unauthorized transfer of crypto assets by the adviser, as any movement of a given crypto asset would require the explicit and mutual authorization of both the client and the adviser.

While unauthorized transfer and misappropriations risks could diminish, sharing key materials with the client could exacerbate other types of custodial risks. Even though advisers would have robust safeguarding systems and cybersecurity measures to self-custody clients' crypto assets, sharing the key materials with clients would expose those materials to additional parties that are not subject to the adviser's supervision and control. To the extent that the client would not be able to adopt or be subject to robust safeguarding systems and cybersecurity measures, sharing key materials with the client could increase the risk of theft or loss of the key materials, which could result in the permanent and irreversible loss of the crypto assets. Furthermore, to the extent an adviser would seek to trade the client's crypto assets frequently, sharing key materials could create operational difficulties, as the client would be needed to authorize ( printed page 64047) each transfer as well. To the extent there would be a delay in authorization for crypto asset transfers, this could result in missed trading opportunities, potential financial losses due to market volatility, and an overall reduction in the adviser's ability to effectively manage the client's crypto assets in a timely and efficient manner.

F. Request for Comments

The Commission requests comment on all aspects of our economic analysis, including the potential benefits and costs of the proposed rules and amendments and alternatives thereto, and whether the proposed rules and amendments, if the Commission were to adopt them, would promote efficiency, competition, and capital formation. In addition, the Commission requests comments on our selection of data sources, empirical methodology, and the assumptions the Commission has made throughout the analysis. Commenters are requested to provide data, documentation (including about any empirical analysis conducted), and other factual support for their views. In addition, the Commission requests comment on:

334. What types of non-custodial service providers would be affected by the proposed rules and amendments? Please describe the nature of the services these providers offer, the extent to which the proposed rules and amendments would alter their business practices or compliance obligations, and whether the proposed rules and amendments would result in any material costs or benefits for such providers.

335. How common is it currently for State trust companies that provide custodial services for crypto assets to prepare financial statements in accordance with U.S. GAAP? Of those that do, how frequently are these financial statements audited by an independent public accountant as defined under SEC rules? For those that do not currently obtain such audits, what impediments, if any, exist to doing so? How much does such an audit typically cost, and how does that cost vary based on the size and complexity of the State trust company's operations?

336. How common is it currently for custodians that provide custodial services for crypto assets to obtain an internal control report from an independent public accountant as defined under SEC rules? For those that do not currently obtain such reports, what impediments, if any, exist to doing so? How much does such a report typically cost? How much does the cost vary based on the number and type of crypto assets in custody, the specific crypto networks involved, and the complexity of the custodian's safeguarding systems? How, if at all, does the cost differ for advisers exercising self-custody of client crypto assets as compared to third-party custodians? How, if at all, does this cost differ across different types of custodians? What is the cost for a state trust company?

337. Under the proposed adviser self-custody rule, advisers that self-custody client crypto assets would be required to obtain internal control reports prepared by an independent public accountant. How much does obtaining an internal control report of this nature typically cost? How much does the cost vary based on the number and type of crypto assets held in self-custody, the complexity of the adviser's safeguarding systems, and the specific crypto networks involved? Are there additional factors, such as adviser size or the availability of qualified independent public accountants with relevant expertise in crypto assets, that would materially affect the cost of obtaining such reports?

338. To what extent are advisers currently unable to offer certain crypto-related investment strategies or advice because of a lack of qualified custodians capable of supporting particular crypto assets or crypto-native activities? Which specific types of crypto assets or investment strategies are most affected by this limitation? In those instances, what is the magnitude of the cost, whether measured in foregone returns, investment value, or otherwise, of this limitation for advisers and their clients?

339. For private funds that invest in crypto assets, what proportion of a fund's gross asset value is typically invested in crypto assets? Does this proportion vary significantly based on the fund's investment strategy, structure, or size? Are there particular types of private funds, such as hedge funds, venture capital funds, or other pooled vehicles, for which crypto assets represent a more substantial or more variable share of gross asset value? How has this proportion changed over time, and how might it be expected to change in response to the proposed rules and amendments?

340. We use a large language model to identify advisers that provide, or plan to provide, investment advice related to crypto assets.[1326] Is this methodology appropriate for identifying the relevant population of affected advisers? Are there limitations or potential sources of error in using a large language model for this purpose? Are there alternative methodologies that would more accurately or efficiently identify the relevant population?

341. What specific costs would be associated with transferring crypto assets from self-custody to a qualified custodian? For example, are there transaction costs, tax consequences, operational challenges, or risks of loss or delay associated with such transfers? Would these costs vary based on the type or volume of crypto assets being transferred, the specific crypto network involved, or the capabilities of the receiving qualified custodian? To the extent that such transfers would require the liquidation and reacquisition of crypto asset positions, what are the potential market impact costs or opportunity costs for clients?

342. Do commenters believe that the proposed rules and amendments could have an effect on capital formation that is not discussed in the economic analysis? For example, could the proposed amendment to the audit provision with respect to newly formed pooled investment vehicles that permit such entities to obtain and distribute audited financial statements covering the first fiscal year and second fiscal year after the end of the second fiscal year reduce costs enough to encourage capital formation? In addition, could the proposed amendment to the audit provision that permits advisers of foreign PIVs to have and distribute audited financial statements prepared in accordance with accounting principles other than the U.S. GAAP in certain circumstances reduce costs enough to encourage capital formation?

V. Paperwork Reduction Act Analysis

A. Introduction

Certain provisions of our proposal would result in new “collection of information” requirements within the meaning of the Paperwork Reduction Act of 1995 (“PRA”).[1327] The proposed new rule 223-1 and related amendments to rules 206(4)-2 and 204-2 under the Advisers Act and Form ADV would have an impact on current collection of information burdens. Specifically, we are proposing new collection of information requirements under proposed rule 223-1 and corresponding amendments to currently approved collection of information burdens under: (i) “Rule 206(4)-2 under the Investment Advisers Act of 1940—Custody of Funds or Securities of ( printed page 64048) Clients by Investment Advisers” (OMB control number 3235-0241); (ii) “Rule 204-2 under the Investment Advisers Act of 1940” (OMB control number 3235-0278); and (iii) “Form ADV” (OMB control number 3235-0049). We are also proposing conforming amendments to Form ADV-E to update existing references from current rule 206(4)-2 to proposed new rule 223-1, which do not amend our estimates from the current approved collection of information burden under “Form ADV-E, Cover Sheet for Each Certificate of Accounting of Client Securities and Funds in Custody of an Investment Adviser” (OMB control number 3235-0361). The proposed new rules 17f-8 and 17f-9 and amendments to rules 17f-1, 17f-2, 17f-4, 17f-5, 17f-6, 17f-7, 31a-1, and 31a-2 under the Investment Company Act and Form N-CEN, as well as the rescission of Form N-17f-1, would have an impact on current collection of information burdens.[1328] Specifically, we are proposing new collection of information requirements under proposed rules 17f-8 and 17f-9 and corresponding amendments to currently approved collection of information burdens under: (i) “Investment Company Act Rule 17f-1, Custody of Securities with Members of National Securities Exchanges” (OMB control number 3235-0222); (ii) “Rule 17f-4 (17 CFR 270.17f-4) under the Investment Company Act of 1940, Custody of Investment Company Assets with a Securities Depository” (OMB control number 3235-0225); (iii) “Rule 17f-5 (17 CFR 270.17f-5) under the Investment Company Act of 1940, Custody of Investment Company Assets Outside the United States” (OMB control number 3235-0269); (iv) “Rule 17f-6 (17 CFR 270.17f-6), Custody of Investment Company Assets with Futures Commission Merchants and Commodity Clearing Organizations” (OMB control number 3235-0447); (v) “Rule 17f-7 (17 CFR 270.17f-7) under the Investment Company Act of 1940, Custody of Investment Company Assets with a Foreign Securities Depository” (OMB control number 3235-0529); (vi) “Rule 31a-1 under the Investment Company Act of 1940 (7 CFR 270.31a-1)” (OMB control number 3235-0178); (vii) “Rule 31a-2: Records to be preserved by registered investment companies, certain majority-owned subsidiaries thereof, and other persons having transactions with registered investment companies” (OMB control number 3235-0179); (viii) “Form N-CEN” (OMB control number 3235-0729); (ix) “Investment Company Act Form N-17f-1, Certificate of Accounting of Securities and Similar Investments of a Management Investment Company in the Custody of Members of National Securities Exchanges” (OMB control number 3235-0359). The Commission is submitting these collections of information to the OMB for review and approval in accordance with 44 U.S.C. 3507(d) and 5 CFR 1320.11. An agency may not conduct or sponsor, and a person is not required to respond to, a collection of information unless it displays a currently valid OMB control number.

We discuss below these proposed amendments and new collection of information burdens. To the extent the Commission receives confidential information pursuant to the collections of information provided to the Commission in the context of its examination and oversight program concerning the proposed amendments to rule 31a-2, such information will be kept confidential, subject to the provisions of applicable law.[1329] Responses to the disclosure requirements of Form N-CEN are not kept confidential. Responses provided to the Commission in the context of its examination and oversight program concerning the proposed redesignation of rule 206(4)-2 as new rule 223-1, and corresponding amendments to rule 204-2 would be kept confidential subject to the provisions of applicable law. Responses to the disclosure requirements of the proposed amendments to Form ADV and responses to Form ADV-E are not kept confidential. Rules 17f-1, 17f-2, 17f-4, 17f-5, 17f-6, 17f-7, 17f-8, 17f-9, and 31a-1 involve no disclosure to the Commission, and therefore confidentiality requirements are inapplicable in the context of these rules' information collections.

B. Advisers Act Custody Rule 223-1

Proposed rule 223-1 under the Advisers Act, which will effectively replace current rule 206(4)-2 by a redesignation, states that an adviser registered or required to be registered under section 203 of the Advisers Act, must take certain steps to safeguard client funds and securities of which the adviser has custody.[1330] Under this proposal, we are adding the adviser self-custody rule, an exception for advisers that self-custody client crypto assets, provided that they comply with the required safeguarding conditions, from the qualified custodian requirement as well as the requirement to notify the client in writing of certain information if the adviser opens an account with a qualified custodian on the client's behalf and to have a reasonable basis, after due inquiry, for believing that the qualified custodian sends quarterly account statements to clients.[1331] We also propose to add State trust companies to the list of qualified custodians permitted to maintain client crypto assets.[1332] Finally, we propose a number of modernizing amendments to the current rule including new exceptions from the requirement to comply with the custody rule and the annual surprise examination requirement and modernizations to the audit requirements for pooled investment vehicles.[1333]

Each requirement to disclose or obtain information, deliver communications, or cause reporting by an independent public accountant constitutes a “collection of information” requirement under the PRA and is mandatory. Advisory clients would use this information to confirm proper handling of their accounts. The Commission's staff uses the information obtained through these collections in its enforcement, regulatory, and examination programs. The respondents to these collections of information requirements would be investment advisers that are registered or required to be registered with the Commission that have custody of client funds and securities. As of December 2025,[1334] there were 16,442 investment advisers registered with the Commission and 9,926 registered investment advisers reported to have custody of client funds and securities in Item 9 of Form ADV.[1335] The application of the ( printed page 64049) provisions of the rule—and thus, the extent to which there are collections of information and their related burdens—would be contingent on a number of factors, such as the types of services the adviser provides, the number of clients to whom it provides those services, and the nature of the relevant assets. The currently approved burden for rule 206(4)-2 is 33,514,391 responses resulting in 315,925 burden hours at a cost of $28,525,065 as well as a $176,577,000 total estimated accounting fee.[1336] Because of the wide diversity of services and relationships offered by investment advisers, we expect that the obligations imposed by the rule will, accordingly, vary substantially among advisers. However, we have made certain estimates of this data solely for the purpose of this PRA analysis.

Table 14 below summarizes the various proposed components of the total annual burden for investment advisers with custody of client funds and securities.

( printed page 64050)

( printed page 64051)

( printed page 64052)

( printed page 64053)

C. Investment Company Act

1. Proposed Rule 17f-9

Proposed rule 17f-9 would permit a regulated fund to maintain its crypto assets with the regulated fund's adviser if the adviser complies with the adviser self-custody rule and if the regulated fund's board of directors engages in oversight of the custody arrangement as required under proposed rule 17f-9. Prior to the investment adviser maintaining the crypto asset and annually thereafter, the regulated fund's board would need to determine that the fund's crypto asset will be subject to reasonable care, if maintained with the regulated fund's adviser, after considering the factors relevant to the safekeeping of the crypto asset.

The proposed rule would require the regulated fund's adviser to furnish such information as may reasonably be necessary for the board to evaluate the fund's custody arrangement of the crypto asset, but at a minimum: (1) a written report documenting the basis of the adviser's self-custody determination; (2) the most recent written annual review of the adviser's safeguarding systems and cybersecurity controls pursuant to the annual review requirement in the adviser self-custody rule, if one is available; and (3) the most recent written internal control report as required under the adviser self-custody rule, if one is available. Advisers would be required to provide any additional information as may reasonably be necessary for the board to evaluate the regulated fund's custody arrangement. Compliance with rule 17f-9 would be mandatory for all regulated funds with self-custodied crypto assets.

Table 15 below summarizes the proposed PRA initial and ongoing annual burden estimates associated with the board oversight and reporting requirements under proposed rule 17f-9.

( printed page 64054)

( printed page 64055)

2. Proposed Rule 17f-8

Under the proposed rule, regulated funds that choose to engage a State trust company as a custodian would be required to, prior to engaging the State trust company and on an annual basis thereafter, determine in writing that they have a reasonable basis, after due inquiry, for believing that: the State trust company (1) is authorized by the relevant State banking authority to provide custody services for crypto assets and (2) maintain and implement policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation. Additionally, the regulated fund would need to receive and review the State trust company's most recent financial statements and internal control report.

Under the proposed rule, regulated funds would be required to enter into a custodial services agreement providing that all crypto assets (and related cash and/or cash equivalents) held in custody for the regulated fund will be held in accounts that are segregated from the State trust company's assets. Compliance with rule 17f-8 would be mandatory for all regulated funds that choose to custody their crypto assets with a State trust company custodian.

Table 16 below summarizes the proposed PRA initial and ongoing annual burden estimates associated with the reasonable basis determination and custodial service agreement requirements under proposed rule 17f-8.

( printed page 64056)

( printed page 64057)

3. Proposed Rule 17f-1

Our proposed amendments would remove the current requirements for the board of directors to ratify the custodial contract and the examinations of the regulated fund's securities and similar investments by an independent public accountant in rule 17f-1.[1337] Therefore, the proposed amendments to rule would eliminate current paperwork requirements on regulated funds. The proposed amendments to rule 17f-1 would affect all management investment companies that use broker-dealers to custody assets. We estimate that 8 funds rely on the rule annually, with a total of 8 responses. Thus, the staff estimates that the total annual hour burden for rule 17f-1 is 28 hours and $32,712.[1338] Accordingly, we estimate that, in the aggregate, the proposed amendment would eliminate the 28 annual burden hours associated with rule 17f-1.[1339] Additionally, we currently estimate that there are no external costs associated with rule 17f-1 in general.

4. Inclusion of BDCs in Investment Company Act Custody and Recordkeeping Rules

The proposed amendments would add references to BDCs to the Investment Company Act custody rules and regulated fund recordkeeping rules.[1340]

BDCs do not file Form N-CEN, the form where regulated funds disclose if they rely on rules 17f-2, 17f-4, 17f-5, 17f-6 or 17f-7. Due to this we do not have any data on how many BDCs currently rely on these rules. As discussed above, compliance with the rules under section 31 under the Investment Company Act, is mandatory for all registered investment companies, and BDCs are similarly subject to these requirements under statutory incorporation.[1341]

All regulated funds that deal directly with securities depositories in reliance on rule 17f-4 should have either modified their contracts with the relevant securities depository, or negotiated a modification in the securities depository's written rules when the rule was amended. Therefore, we estimate there is no ongoing burden for regulated funds associated with this collection of information.[1342]

The Commission anticipates that the number of existing registrants that change their foreign custody managers is negligible and, therefore, the compliance burden of rule 17f-5 falls primarily on new registrants. In practice, not all registrants will use foreign custody managers. The actual figure therefore may be smaller.

Because rule 17f-6 does not impose any ongoing obligations on funds or FCMs, the Commission estimates there are only costs related to new contracts between funds and FCMs. The Commission estimates that new contracts pursuant to the rule take approximately 1 hour.

The Commission estimates that regulated funds relying on rule 17f-7 will make an average of 8 responses annually under the rule to address depository compliance with minimum requirements, any indemnification or insurance arrangements, and reviews of risk analyses or notifications. The Commission estimates each response will take 6 hours.

The proposed amendments specifying the applicability of the regulated fund recordkeeping rules to BDCs are not anticipated to result in a change in burden. BDCs are already subject to these rules.[1343]

( printed page 64058)

D. Recordkeeping Rules

1. Rule 204-2

Under section 204 of the Advisers Act, investment advisers registered or required to register with the Commission under section 203 of the Advisers Act are required to make and keep for prescribed periods such records (as defined in section 3(a)(37) of the Exchange Act), furnish copies thereof, and make and disseminate such reports as the Commission, by rule, may prescribe as necessary or appropriate in the public interest or for the protection of investors. Rule 204-2 sets forth the requirements for making and keeping specified books and records. This collection of information is found at 17 CFR 275.204-2 and is mandatory. The Commission staff uses the collection of information in its examination and oversight program. Responses provided to the Commission in the context of its examination and oversight program concerning the rule 204-2 are kept confidential subject to the provisions of applicable law.[1344] The respondents to this collection of information are investment advisers registered or required to be registered with the Commission.

The current approved annual aggregate burden for rule 204-2 is 2,941,493.4 hours, based on an estimate of 15,906 registered advisers, or 184.9298 hours per registered adviser. We now estimate that the revised annual aggregate hourly burden for rule 204-2 would be 2,946,962.15 hours, based on an estimate of 16,442 registered advisers, and represented by a monetized cost of $240,576,972.80. A table summarizing the various components of the total annual burden associated with the proposed Advisers ( printed page 64059) Act recordkeeping rule amendments is found below.

( printed page 64060)

( printed page 64061)

2. Rule 31a-2

Rule 31a-1 under the Act specifies the books and records that each registered investment company, BDC, and certain underwriters, broker-dealers, investment advisers, and depositors must maintain. Rule 31a-2 specifies the time periods that entities must retain certain books and records, including those required to be maintained under rule 31a-1.[1345] We have previously estimated that it takes a total of 607,315 hours, and involves a total external cost burden of $111,818,274 to comply with the collection of information associated with rule 31a-2.[1346] Compliance with the rule's collection of information requirements is mandatory. To the extent the Commission receives confidential information pursuant to the collections of information, such information will be kept confidential, subject to the provisions of applicable law.[1347] The table below summarizes our PRA initial and ongoing annual burden estimates associated with the proposed amendments to rule 31a-2.[1348] Staff estimates there will be no external costs associated with this collection of information.

( printed page 64062)

( printed page 64063)

E. Disclosure

1. Form ADV

Form ADV is a three-part investment adviser form. Part 1 of Form ADV contains information used primarily by Commission staff, Part 2 is the client brochure, and Part 3 requires registered investment advisers that offer services to retail investors to prepare and file with the Commission, post to the adviser's website (if it has one), and deliver to retail investors a relationship summary. The Commission uses the information in Form ADV to determine eligibility for registration with us and to manage our regulatory, examination, and enforcement programs. Clients and prospective clients use the information required in Form ADV to determine whether to hire or retain an investment adviser, and, if hired, how to manage that relationship. Rule 204-1 under the Advisers Act requires any adviser that is required to complete Form ADV to update the form at least annually, including ERAs that report to the Commission pursuant to rule 204-4, and requires advisers to submit electronic filings through the Investment Adviser Registration Depository (“IARD”).[1349] Compliance with the disclosure requirements of Form ADV is mandatory. Responses to the disclosure requirements are not kept confidential. The paperwork burdens associated with rules 203-1, 204-1, and 204-4, as well as the obligation to deliver codes of ethics to clients under rule 204A-1, are included in the approved annual burden associated with Form ADV and thus do not entail a separate collection of information.[1350]

The current approved annual aggregate burden for Form ADV is 251,851.53 hours, or 10.85 hours per registered adviser. The proposed changes to the rule would increase the annual aggregate burden to 259,438 hours, or 11.17 hours per registered adviser. The table below summarizes our PRA initial and ongoing annual burden estimates associated with the proposed amendments to Form ADV.

( printed page 64064)

( printed page 64065)

( printed page 64066)

( printed page 64067)

2. Form N-CEN

Form N-CEN is an annual report filed with the Commission by all registered investment companies, other than FACCs. We have previously estimated that it takes a total of 62,239 hours, and involves a total external cost burden of $605,520, to comply with the collection of information associated with Form N-CEN.[1351] Compliance with the disclosure requirements of Form N-CEN is mandatory. Responses to the disclosure requirements are not kept confidential. The table below summarizes our PRA initial and ongoing annual burden estimates associated with the proposed amendments to Form N-CEN. Staff estimates there will be no external costs associated with this collection of information.

( printed page 64068)

( printed page 64069)

3. Rescission of Form N-17F-1

Our proposed amendments would rescind Form N-17F-1.[1352] The proposed rescission of Form N-17F-1 would affect all management investment companies required to file reports on the form. We currently estimate on average 21 funds file Form N-17f-1 three times annually and that each fund requires an average of approximately 1.5 hours to prepare and file Form N-17f-1 for a total estimated annual burden of 95 hours.[1353] Accordingly, we estimate that, in the aggregate, our proposed rescission would eliminate the 95 annual burden hours associated with filing Form N-17f-1. Additionally, we currently estimate that there are no external costs associated with filing Form N-17F-1 in general.

F. Request for Comments

We request comment on whether our estimates are reasonable. Pursuant to 44 U.S.C. 3506(c)(2)(B), the Commission solicits comments to: (1) evaluate whether the proposed collection of information is necessary for the proper performance of the functions of the Commission, including whether the information will have practical utility; (2) evaluate the accuracy of the Commission's estimate of the burden of the proposed collection of information; (3) determine whether there are ways to enhance the quality, utility, and clarity of the information to be collected; and (4) determine whether there are ways to minimize the burden of the collection of information on those who are to respond, including through the use of automated collection techniques or other forms of information technology.

Any member of the public may direct to us any comments concerning the accuracy of these burden estimates and any suggestions for reducing these burdens. Persons submitting comments on the collection of information requirements should direct their comments to the OMB Desk Officer for the Securities and Exchange Commission, , and should send a copy to Vanessa A. Countryman, Secretary, Securities and Exchange Commission, using any of the methods in the ADDRESSES section, with reference to File No. S7-2026-35. Requests for materials submitted to OMB by the Commission with regard to the collection of information should be in writing, refer to File No. S7-2026-35 and be submitted to the Securities and Exchange Commission, Office of FOIA Services, 100 F Street NE, Washington DC 20549-2736. OMB is required to make a decision concerning the collections of information between 30 and 60 days after publication of this release. Consequently, a comment to OMB is best assured of having its full effect if OMB receives it within 30 days of publication.

VI. Initial Regulatory Flexibility Analysis

The Commission has prepared the following Initial Regulatory Flexibility Analysis (“IRFA”) in accordance with section 3(a) of the Regulatory Flexibility Act (“RFA”).[1354] The IRFA relates to proposed amendments to rules 17f-1 and 17f-2, along with amendments to rules 17f-4 through 17f-7, 31a-1, 31a-2, 204-2, and 206(4)-2 (redesignated as rule 223-1), and Forms N-CEN, ADV, and ADV-E, as well as proposed new rules 17f-8 and 17f-9.

A. Reason for and Objectives of the Proposed Action

As discussed above, we are proposing amendments to the Advisers Act custody rule and new custody rules under the Investment Company Act to enhance investor protection by imposing protective conditions and promote investor choice and ability to invest by tailoring the custody rules to address the existing limitations of the custody rules that may inhibit advisers' ability to provide investment advice and regulated funds to invest in the full range of crypto assets and pursue certain crypto asset-related investment strategies. Specifically, the Commission is proposing new rules under the Investment Company Act and amendments to reporting and recordkeeping requirements to address how regulated funds custody crypto assets and amendments to the custody rule and related reporting and recordkeeping rules under the Advisers Act to address how registered investment advisers custody client assets. In particular, the Commission is proposing to provide a tailored framework for crypto asset custody ( printed page 64070) based on consideration of the evolution and growth of the crypto asset market, public and industry feedback provided to the Crypto Task Force and the Digital Assets PWG Report's recommendations to the Commission.

We are proposing to amend the Advisers Act custody rule and add a new Investment Company Act custody rule to permit self-custody of client and fund crypto assets, subject to several conditions, including recordkeeping requirements related to the proposed self-custody rules. For example, the proposed self-custody rules would require the adviser to first determine that a permitted custodian is not available to maintain the crypto asset, as an initial matter and on a quarterly basis. Further, the proposed self-custody rules would require, among other things, the adviser to have the expertise (and to document the basis of its determination that it has the expertise) and the systems to safeguard the crypto assets against loss, theft, misuse, or misappropriation, and to review the adequacy of its safeguarding systems on an annual basis. Additionally, the proposed regulated fund self-custody rule would require a regulated fund's board to determine that a crypto asset of the fund would be subject to reasonable care if self-custodied with the fund's investment adviser prior to the investment adviser maintaining the crypto asset and annually thereafter. As described above, further proposed conditions involve, among other things, the mitigation of (and controls associated with) cybersecurity risks associated with safeguarding clients' crypto assets; requirements for the adviser to obtain internal control reports concerning its safeguarding of crypto assets; and requirements to send quarterly account statements to each of the adviser's clients whose crypto assets the adviser has self-custody.

Separately, we are proposing to amend the custody rules to permit custody of client and regulated fund crypto assets by State trust companies, subject to the conditions discussed earlier in the release, including, but not limited to, related recordkeeping requirements. For example, the proposed State trust company rules would, among other things, require that the adviser or regulated fund must have a reasonable basis, after due inquiry, for believing that the State trust company is authorized by the relevant State banking authority to provide crypto asset custody. As another example, the proposed rules would require that the adviser or regulated fund must have a reasonable basis, after due inquiry, for believing that the State trust company maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation. Further proposed conditions require that the adviser or regulated fund receive and review of the State trust company's audited financial statements and internal control reports, and for regulated funds, a custodial agreement that provides for the segregation of the regulated fund's crypto assets (and related cash and/or cash equivalents) from the State trust company's proprietary assets.

The Commission also is proposing to amend the current custody rules to modernize the custody rules so that the rules better address, among other things, current industry practices and industry feedback. For example, for the Investment Company Act rules, we are proposing to add references to BDCs throughout the Investment Company Act custody rules to clarify that BDCs, like registered investment companies, may rely on the rules to use permitted custodians other than banks. We also are proposing, among other things, to amend rule 17f-1 (the rule related to broker-dealer custody) to expand the eligible broker-dealer custodians to include all registered broker-dealers rather than just members of a national securities exchange, and to replace the numerous conditions in the rule with the condition that regulated fund securities and similar investments may be placed or maintained with a broker-dealer where the broker-dealer's custody of the securities or similar investments is subject to the requirements of the rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections. Likewise, we are proposing to amend the Advisers Act custody rule in several respects, including to modernize the rule and outline Commission views on several topics related to the application of the Advisers Act custody rule.

We are proposing amendments to the recordkeeping rules under the Advisers Act and Investment Company Act related to the proposed self-custody rules, proposed state trust company rules, and the proposed modernization amendments to the custody rules under the Advisers Act and the Investment Company Act. Additionally, we are proposing amendments to the recordkeeping rules to provide that records required to be maintained and preserved under the applicable recordkeeping rules may be maintained and preserved on a crypto network, provided that the adviser or registered fund can provide, promptly upon request by the Commission (including its examiners and other representatives), such records to the Commission in a human-readable and reasonably usable electronic format.

Lastly, we are proposing amendments to certain Commission forms, including amendments to Forms ADV and ADV-E (for advisers) and Forms N-CEN (for regulated funds). The proposed amendments to Form ADV would (1) add new questions related to the proposed rule amendments to permit adviser crypto asset self-custody; (2) add new questions related to an adviser's reliance on certain exceptions under the Advisers Act custody rule and use of State trust companies as qualified custodians for crypto assets; (3) add new questions regarding tokenized private funds; and (4) make conforming amendments to reflect the proposed amendments to the Advisers Act custody rule. The proposed conforming amendments to Form ADV-E would update existing references to the current Advisers Act custody rule to reflect the proposed redesignation to rule 223-1. The proposed amendments to Form N-CEN would require reporting of the use of crypto asset self-custody or of a State trust company to custody regulated fund crypto assets.

B. Legal Basis

The Commission is proposing amendments to rules 17f-1, 17f-2, 17f-4, 17f-5, 17f-6, 17f-7, 31a-1, and 31a-2 under the Investment Company Act pursuant to authority set forth in sections 6(c), 7(d), 17(f), 31(a), and 38(a) of the Investment Company Act. The Commission is proposing new rules 17f-8 and 17-9 under the Investment Company Act pursuant to authority set forth in sections 6(c), 7(d), 17(f), and 38(a) of the Investment Company Act. The Commission is proposing to rescind rule 17f-3 and Form N-17f-1 under the Investment Company Act. The Commission is proposing amendments to Form N-CEN under the authority set forth in sections 8, 30, 35, and 38 of the Investment Company Act.

The Commission is proposing new rule 223-1 by a redesignation of rule 206(4)-2 under the Advisers Act under the authority set forth in sections 206(4), 211(a), and 223 of the Advisers Act. The Commission is proposing corresponding amendments to rule 204-2 under the Advisers Act under the authority set forth in sections 204, 206(4), and 211(a) of the Advisers Act. The Commission is proposing to amend Form ADV pursuant to the authority set forth in sections 203(c)(1), 204, 211(a), and 223 of the Advisers Act. The Commission is ( printed page 64071) proposing to amend Form ADV-E pursuant to authority set forth in sections 204, 206, and 211(a) of the Advisers Act.

C. Small Entities Subject to the Rule and Rule Amendments

For purposes of Commission rulemaking in connection with the RFA, an investment company is a small entity if, together with other investment companies in the same group of related investment companies, it has net assets of $50 million or less as of the end of its most recent fiscal year (a “small fund”).[1355] Commission staff estimates that, as of December 31, 2025, approximately 20 registered open-end mutual funds, 7 registered ETFs, 34 registered closed-end funds, one UIT, and five BDCs (collectively, 67 funds) are small entities.[1356] Under the Advisers Act, a small entity is an investment adviser that: (1) has assets under management having a total value of less than $25 million; (2) did not have total assets of $5 million or more on the last day of the most recent fiscal year; and (3) does not control, is not controlled by, and is not under common control with another investment adviser that has assets under management of $25 million or more, or any person (other than a natural person) that has had total assets of $5 million or more on the last day of the most recent fiscal year.[1357] The Commission estimates that 466 registered investment advisers are small, based on a review of Form ADV filings for the reporting period ending December 2025, with filings received through March 31, 2026.

D. Projected Reporting, Recordkeeping and Other Compliance Requirements

The Commission is considering amendments and additions to the reporting, recordkeeping, and other compliance requirements of regulated funds and advisers related to the custody of crypto assets. In particular, the Commission is proposing rule amendments that would, among other things: (1) allow advisers and regulated funds to self-custody crypto assets, subject to certain conditions; (2) allow advisers and regulated funds to custody crypto assets with State chartered trusts, subject to certain conditions; (3) modernize the custody rules; (4) amend certain recordkeeping rules; and (5) amend several Commission forms. The Commission considered the potential that the proposed amendments to existing rules and addition of new rules could affect the compliance burden imposed on small entities.

The proposed regulated fund self-custody rule would require, prior to the investment adviser maintaining a regulated fund's crypto asset and quarterly thereafter, that the regulated fund's board of directors, including a majority of directors who are not interested persons of the regulated fund, reviews the investment adviser's written report documenting the basis for the adviser's determination that no qualified custodian will maintain the crypto asset. In addition, the proposed regulated fund self-custody rule would require, prior to the investment adviser maintaining the regulated fund's crypto asset and annually thereafter, that the board of directors, including a majority of directors who are not interested persons of the regulated fund, determines that the crypto asset will be subject to reasonable care if maintained with the regulated fund's adviser, after considering the factors relevant to the safekeeping of the crypto asset.[1358]

Under the proposed adviser self-custody rule, as an initial matter and no less than quarterly, the adviser would need to determine that a qualified custodian is not available to maintain the crypto asset and record that determination in writing. Further, to help ensure that only those advisers who are well-suited and have the capabilities to safeguard crypto assets have self-custody of client crypto assets, the proposed adviser self-custody rule also would require the adviser to have expertise regarding the safeguarding of each crypto asset, and to document in writing the basis of such determination, and to also adopt, implement, and maintain the systems necessary to safeguard each crypto asset against loss, theft, misuse, and misappropriation.[1359]

Under the proposed State trust company rules, prior to engaging a State trust company as a custodian for crypto assets and related cash and/or cash equivalents, and on an annual basis thereafter, the adviser or regulated fund would need to determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company: (1) is authorized by the relevant State banking authority to provide custody services for crypto assets and related cash and/or cash equivalents and (2) maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation. Further, the adviser or regulated fund would be required to receive and review the State trust company's most recent internal control report and audited annual financial statements. Further, under the proposed State trust company rules, all client crypto assets must be held in segregated accounts.[1360]

In connection with the proposal's efforts to modernize the custody rules, we are proposing to add references to BDCs to the Investment Company Act custody rules and recordkeeping rules, remove the conditions in current rule 17f-1 and make it permissible for regulated funds to custody their securities or similar investments with all broker-dealers registered under section 15(b)(1) of the Securities Exchange Act of 1934 where the broker-dealer's custody of the securities or similar investments is subject to rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections, rescind rule 17f-3, update the address to access the Uniform Commercial Code in rule 17f-4, and correct a cross-reference for the ( printed page 64072) definition of a “Eligible Securities Depository” in rule 17f-7.[1361]

As discussed above, the proposed amendments will modify certain reporting, recordkeeping, and disclosure requirements applicable to advisers and regulated funds. For example, advisers are required to report information about custodial practices on Form ADV, and registered investment companies are required to disclose information about their custodians on Form N-CEN. Furthermore, rule 31a-1 under the Investment Company Act and rule 204-2 under the Advisers Act regulate recordkeeping practices that require, among other things, keeping records of all accounts, contracts, and transactions.

Rule 31a-1 under the Investment Company Act requires regulated funds to create and maintain certain records, including documents relating to purchases and sales of securities and advisory fees.[1362] As discussed above, we expect the proposed amendment to rule 31a-1, which has the narrow focus of providing that records related to crypto assets that are required to be maintained and preserved under the applicable recordkeeping rule may be maintained and preserved on a crypto network, would lower the burden on regulated funds—including small entities—related to rule 31a-1. We also are proposing to add a crypto network as an additional format that advisers can use to maintain records under proposed rule 204-2(g)(1)(iii). In connection with this proposed amendment, we are also proposing conforming amendments to rules 204-2(g)(2) and (3) to prescribe maintenance, preservation, and access procedures for records maintained on a crypto network.

As mentioned above, rule 31a-2 spells out the retention periods required for regulated fund records mandated by rule 31a-1. We are proposing amendments to rule 31a-2 that would address the records required to be maintained and the retention periods for records related to regulated fund self-custody of crypto assets and for regulated funds that maintain their crypto assets at a State trust company under the proposed State trust company rules. The proposed self-custody related amendments would require a regulated fund to maintain, for each crypto asset of the fund held in custody under the proposed rule for fund self-custody of crypto assets, any report or other information provided to the fund's board in connection with the board oversight requirements. As discussed above, such information would include, at a minimum, the adviser's written report documenting the QC determination, the adviser's written reports regarding its expertise and systems, the most recent annual review of the adviser's safeguarding systems and cybersecurity controls if available, and the most recent internal written control report, if available. The regulated fund would be required to maintain such reports and other information for at least six years, the first two years in an easily accessible place. The proposed amendments related to State trust company custody would require a regulated fund that maintains client crypto assets with a State trust company as a qualified custodian to make and keep the certain records, including a memorandum describing the basis upon which the fund made its required initial and annual determinations with respect to the State trust company as a qualified custodian, records of the State trust company's audited financial statements obtained or received as required under the proposed rule, and a copy of the State trust company's internal control reports obtained or received pursuant to the proposed rule.

Rule 204-2 sets forth the requirements for making and keeping specified books and records. We are proposing to amend rule 204-2 to add new recordkeeping requirements associated with the proposed amendments to the Advisers Act custody rule that would require investment advisers to maintain records related to client accounts including, but not limited to, certain records related to the proposed self-custody and State trust custody rules discussed above. Rule 204-2 applies to all investment advisers, including those that are small entities.

As discussed above, Form N-CEN requires regulated funds to disclose information about entities that provided custodial services to them, including checking a box corresponding to the different types of permitted custodians for regulated funds under applicable rules and statutes. The proposed amendments to Form N-CEN would require management investment companies reporting custodians on Item C.12 of Form N-CEN to report the use of crypto asset self-custody or of a State trust company. More specifically, we are proposing to add two additional checkboxes, corresponding to the proposed crypto asset self-custody and State trust company rules to Item C.12 that would provide comparable information for these new classes of custodians as exist for current custodians. The proposed rule form text also would add Item D.14 for small business investment companies. Our proposal to create new Item C.23 on Form N-CEN would require disclosure regarding whether a fund is tokenized.

As discussed above, Form ADV is a registration and disclosure document that requires an investment adviser to provide information about their business, fees, and other matters. The proposed amendments to Form ADV would, among other things, implement the proposed rule amendments related to adviser crypto asset self-custody, improve the readability of Item 9 and make conforming amendments, such as those necessary to implement the proposed redesignation of the Advisers Act custody rule to rule 223-1. More specifically, the Commission is proposing several amendments to Form ADV to (1) add new questions related to the proposed crypto asset self-custody rule, as discussed above in section II; (2) add new questions that address an adviser's reliance on certain exceptions under the Advisers Act custody rule and the use of State trust companies as qualified custodians for crypto assets; (3) add new questions to collect information regarding tokenized private funds; and (4) make certain conforming amendments to reflect the proposed amendments to the Advisers Act custody rule.[1363]

The proposed amendments related to adviser self-custody of crypto assets are designed to provide the Commission and investors with important identifying information about the adviser's crypto asset custodial practices, in light of the novel risks associated with adviser self-custody and safeguarding crypto assets. The remaining proposed amendments are designed to provide the Commission staff with more accurate and consistent information about adviser custodial practices and streamline reporting for advisers. Because Form ADV data is publicly available, these proposed amendments will also enhance the information available to investors and support investor protection by providing better information about ( printed page 64073) adviser custodial practices. We are proposing to make amendments to Form ADV that would require advisers to report whether any reported private fund (or series or class thereof) is a tokenized fund. Advisers would also be required to provide the names of any crypto networks used to record ownership of the fund or class or series of the private fund.

Form ADV-E requires that the independent public accountant conducting the annual surprise examination of custodied assets file a certificate on Form ADV-E with the Commission within 120 days of the time chosen by the independent public accountant for the surprise examination. As discussed earlier, the proposed amendments to Form ADV-E would not substantively modify Form ADV-E, as we are only proposing conforming amendments to Form ADV-E in connection with the proposed redesignation of the Advisers Act custody rule to rule 223-1. All registered investment advisers, including those that are small entities, must file Form ADV. Only registered investment advisers with custody of client assets need to file Form ADV-E.

In addition to the amendments related to recordkeeping, reporting, and disclosure, the proposed amendments would impose other compliance burdens on regulated funds and advisers. For example, the proposed amendments would create compliance obligations related to the following aspects of the proposal: (1) adviser and regulated fund self-custody practices; (2) the custody of crypto assets by State trust companies; (3) the investment company custody rule modernization; and (4) investment adviser custody rule modernization.

The proposed amendment's compliance requirements in connection with adviser and regulated fund self-custody of crypto assets are generally related to the features of crypto assets that make their custody different from those of other types of assets. For example, the Commission's proposed adviser self-custody rule would require heightened safeguards to help ensure the protection of the key materials that are critical to the safekeeping of a client's crypto asset because, unlike mechanisms used to transact in more traditional assets, access to crypto assets generally requires the use of public and private cryptographic key pairings, and the loss or theft of key materials can result in the irreversible loss of crypto assets. As discussed in more detail earlier, the proposed adviser self-custody rule would require, among other things, that advisers engage in certain safeguarding measures, including implementing cybersecurity controls and obtaining an annual internal control report prepared by an independent public accountant. Another compliance requirement under the proposed adviser self-custody rule would be that an adviser that custodies crypto assets would have to have expertise regarding the safeguarding of each crypto asset and to document in writing the basis for its determination that it has the expertise. The proposed adviser self-custody rule also would require an adviser to adopt, implement, and maintain the systems, including the appropriate technology, software, hardware, and other associated systems and processes around their use, necessary to safeguard each crypto asset against loss, theft, misuse and misappropriation. Further, in addition to the safeguards required of registered advisers with self-custody of crypto assets under the proposed self-custody rule, under the proposed amendments, a regulated fund's board of directors would need to engage in the oversight of the self-custody arrangement as required under the proposed fund self-custody rule under the Investment Company Act. This would allow regulated funds to place and maintain crypto assets with an adviser to the regulated fund, but subject both to the protections in the proposed adviser self-custody rule and the regulated fund's board of director's oversight of the arrangement under the proposed fund self-custody rule. More specifically, the proposal would permit a regulated fund to maintain its crypto assets with the regulated fund's adviser if the adviser complies with the adviser self-custody rule (as described above), and if the regulated fund's board of directors engages in oversight of the custody arrangement as required under proposed rule 17f-9, the fund self-custody rule. The Commission tailored these new compliance requirements in the proposed amendments to the specific risks posed by self-custody of crypto assets by advisers and regulated funds.

With regard to custody of crypto assets by State trust companies, as discussed above, the Commission is proposing amendments to the Advisers Act custody rule and a new custody rule under the Investment Company Act to add State trust companies as an additional category of permitted custodian for crypto assets, subject to certain conditions designed to safeguard client crypto assets from loss, theft, misuse, and misappropriation. The proposed compliance conditions are designed to address common custodial risks that bank regulations generally address, as well as to address the custodial risks that are unique to the custody of crypto assets. More specifically, the proposed conditions are designed to provide that the adviser or regulated fund has made a determination that the State trust company is authorized and regulated by an applicable State authority and that certain protective conditions apply that are designed to help ensure that the State trust company is an appropriate custodian for crypto assets.

Under the proposed State trust company rules, prior to engaging a State trust company as a custodian for crypto assets and related cash and/or cash equivalents, and on an annual basis thereafter, the adviser or regulated fund would need to determine in writing that it has a reasonable basis, after due inquiry, for believing that the State trust company: (1) is authorized by the relevant State banking authority to provide custody services for crypto assets and related cash and/or cash equivalents, and (2) maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation. The adviser or regulated fund also would be required to receive and review the State trust company's audited financial statements and internal control reports, and a regulated fund would be required to enter into a custodial agreement with the State trust company that provides for the segregation of the regulated fund's crypto assets (and related cash and/or cash equivalents) from the State trust company's proprietary assets. The compliance requirements around the proposed State trust company rules are, as with other elements of our proposal, designed to address the unique risks posed by custodying crypto assets while providing regulatory clarity for advisers and regulated funds.

In connection with Investment Company Act custody rule modernization, we are proposing to amend the Investment Company Act custody rules to modernize the rules and correct certain errors or inconsistencies. These amendments would, among other things, add references to BDCs to certain Investment Company Act rules, remove the conditions in current rule 17f-1 and make it permissible for regulated funds to custody securities and similar investments with broker-dealers registered under section 15(b)(1) of the Exchange Act where the broker-dealer's custody of those securities or similar ( printed page 64074) investments is subject to rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections, and correct the cross-reference in the definition of a “Eligible Securities Depository” in rule 17f-7. Various provisions of the Investment Company Act, including section 17(f) governing custody of securities and section 31 prescribing recordkeeping requirements, are incorporated by statute to apply to BDCs to the same extent as if the BDC was a registered closed-end investment company. While industry practice has been to interpret the Investment Company Act's application of section 17(f) to BDCs to allow BDCs to rely on the Investment Company Act custody rules to the same extent as registered closed-end investment companies, but the rules' conditions do not turn on the distinction of whether a fund is registered under the Investment Company Act or regulated under the Act in the case of a BDC, which is why we are proposing to add appropriate references to BDCs in the Investment Company Act custody rules to make clear that BDCs may rely on them. Additionally, due to the comprehensive modern broker-dealer financial responsibility rules, including the customer protection rule, which the Commission adopted after the adoption of rule 17f-1 in 1940, the risks to clients that use broker-dealers for custodial services are very different than in 1940. In connection with Commission efforts to update its rulebook, the proposal would amend rule 17f-1 to permit regulated funds to custody securities and similar investments at a broker or dealer registered under section 15(b)(1) of the Exchange Act without requiring specific enumerated conditions where the custody of the securities or similar investments is subject to the requirements of rule 15c3-3 under the Exchange Act or such other rule that the Commission determines provides similar customer protections. The proposed amendments would improve the utility of rule 17f-1 as a pathway for broker-dealer custody of regulated fund assets by making the compliance obligations of such custody suitable for modern regulatory practices on broker-dealers.

The proposed amendments that seek to implement Advisers Act custody rule modernization aim to address certain longstanding questions relating to the application of the Advisers Act custody rule. As discussed above, we are proposing a number of modernizing amendments to the rule and proposing to provide guidance on certain known custody issues. These proposed modernizations include rule amendments to, among other things, (1) except discretionary trading authority from the Advisers Act custody rule subject to conditions that limit executions to designated client accounts and prohibit transfers to accounts controlled by the adviser or related persons, (2) eliminate the requirements for accountants engaged to perform audit and examination services under the Advisers Act custody rule to be registered with, and subject to regular inspection by, the PCAOB, (3) modernize the audit requirements for pooled investment vehicles, (4) except accounts subject to standing letters of authorization from asset verification requirements, (5) explicitly except accounts of BDCs from the Advisers Act custody rule since they are subject to Investment Company Act custody requirements, (6) require an account number be included in the notice sent to the client by an adviser upon opening an account with a qualified custodian, (7) modernize rule language related to the notice an accountant must provide to the Commission upon the finding of any material discrepancies during the course of an independent verification, and (8) except advisers from the rule with respect to inadvertent custody of client funds or securities.

E. Duplicative, Overlapping, or Conflicting Federal Rules

We do not believe that the proposed amendments would duplicate, overlap, or conflict with other existing Federal rules.

F. Significant Alternatives

The RFA directs the Commission to consider significant alternatives that would accomplish our stated objectives, while minimizing any significant economic impact on small entities. We considered the following alternatives for small entities in relation to the proposed rules and rule amendments: (1) establishing different requirements that take into account the resources available to small entities; (2) exempting small entities from all or part of the requirements; (3) clarifying, consolidating, or simplifying requirements under the rules for small entities; and (4) using performance rather than design standards.

We do not believe that exempting small regulated funds or advisers from the proposed amendments and new rules related to the custody of crypto assets would permit us to achieve our stated objectives. For example, we believe that all regulated funds and advisers, regardless of size, should have the expertise, systems, and controls necessary to self-custody crypto assets. To the extent an adviser or regulated fund can satisfy the proposed conditions discussed above, the proposed new rules and amendments would, among other things, provide all regulated funds and advisers with greater flexibility to maintain crypto either in self-custody under the proposed crypto self-custody rules or with a State trust company under the proposed State trust company rules. Only those regulated funds and advisers with clients' crypto assets would be able to comply with the proposed self-custody and State trust company rules. For small regulated funds and advisers that would be more significantly affected by the proposed amendments and new rules because they are investing in crypto assets, the proposed self-custody and State trust company rules, along with the other proposed amendments, could provide small regulated funds and advisers with greater flexibility to invest in crypto assets to meet the objectives of investors interested in such investments. We also do not believe that it would be appropriate to prohibit small regulated funds and advisers from being able to use the proposed self-custody and State trust company custody rules. The proposed new rules and amendments stand to benefit small regulated funds and advisers by, among other things, providing regulatory clarity around the circumstances under which regulated funds and advisers can custody crypto assets.

Similar to the concerns discussed above, if the proposal included different requirements for small regulated funds and advisers, it could raise investor protection concerns for investors in small regulated funds or clients of a small adviser in that a small regulated fund and advisers would not be subject to crypto asset custody requirements that are as robust as those requirements for other regulated funds and advisers.

We also do not believe that clarifying, consolidating, or simplifying the compliance requirements under the proposal for small regulated funds and advisers, beyond that already proposed for regulated all funds and fund advisers, would permit us to achieve our stated objectives because this would raise investor protection concerns for investors in small funds and advisers. The conditions necessary to rely on proposed self-custody and State trust company rules are designed to maintain important investor protection benefits, including, among other things, helping to ensure that regulated fund and ( printed page 64075) advisory client crypto assets are appropriately protected.

Regarding the proposed Investment Company Act and Investment Advisers Act modernization amendments, we do not believe that we can establish different, simplified or consolidated requirements for small regulated funds and advisers without compromising our objectives. The rules we are amending provide important investor protection benefits, and these benefits should apply to investors in smaller regulated funds and advisory clients of smaller advisers as well as investors in larger regulated funds and advisory clients of larger advisers. The proposed amendments to the Advisers Act custody rule also include exceptions to the application of the rule that apply to both large and small advisers. Similarly, we do not believe it would be in the interest of regulated fund investors and advisory clients to exempt small regulated funds and advisers from the proposed recordkeeping amendments. We believe that all advisory clients and regulated investors, including investors in small regulated funds and clients of small advisers, would benefit from the proposed amendments. We note that the rules being amended do not currently distinguish between small regulated funds and advisers and other regulated funds and advisers.

The costs associated with the proposed amendments and new rules would vary depending on the particular circumstances of funds and advisers, and thus the amendments and new rules could result in different burdens on the resources of regulated funds and advisers.

Finally, with respect to the use of performance rather than design standards, the proposed amendments and new rules generally use performance standards that provide small regulated funds and advisers with an appropriate degree of flexibility. The amendments that relate to design standards—such as, for example, the addition on Forms ADV and N-CEN of a checkbox to indicate a tokenized private fund (Form ADV) or fund (Form N-CEN) and checkboxes to indicate if an adviser or regulated fund is self-custodying crypto assets or employing a State trust company to do so—are straightforward, minimally burdensome, and consistent with existing information requirements associated with the form.

G. Solicitation of Comments

The Commission requests comments regarding this IRFA. We request comments on the number of small entities that may be affected by our proposed amendments and whether the proposed amendments would have any effects not considered in this analysis. We request that commenters describe the nature of any effects on small entities subject to the rules and forms, and provide empirical data to support the nature and extent of such effects. We also request comment on the proposed compliance burdens and the effect these burdens would have on smaller entities.

VII. Congressional Review Act

For purposes of Subtitle E of the Small Business Regulatory Enforcement Fairness Act of 1996 (also known as the Congressional Review Act),[1364] the Commission must seek the OMB's determination whether a final regulation constitutes a “major” rule. Under the Congressional Review Act, a rule is considered “major” where, if adopted, it results in or is likely to result in:

To help inform OMB's determination whether any final rule that results from the proposal would be a “major rule,” the Commission solicits comment and data on:

Commenters are requested to provide empirical data and other factual support for their views, to the extent possible, to inform OMB's determination regarding whether any final rule following this proposal is likely to be a “major rule” for the purposes of the Congressional Review Act.

VIII. Other Matters

This action is an economically significant regulatory action under section 3(f)(1) of Executive Order 12866 and has been reviewed by OMB, consistent with Executive Order 14215. This action, if finalized as proposed, is expected to be an Executive Order 14192 deregulatory action.

Incorporation by Reference

The Uniform Commercial Code governs commercial transactions in the United States, and Article 8 of the Uniform Commercial Code governs transfers of investment securities. The Uniform Commercial Code is reasonably available from the Uniform Law Commission (ULC, also known as National Conference of Commissioners on Uniform State Laws) at www.uniformlaws.org.

Statutory Authority

The Commission is proposing amendments to rules 17f-1, 17f-2, 17f-4, 17f-5, 17f-6, 17f-7, 31a-1, and 31a-2 under the Investment Company Act pursuant to authority set forth in sections 6(c), 7(d), 17(f), 31(a), and 38(a) of the Investment Company Act [15 U.S.C. 80a-6(c), 80a-7(d), 80a-17(f), 80a-30(a) and 80a-37(a)]. The Commission is proposing new rules 17f-8 and 17f-9 under the Investment Company Act pursuant to authority set forth in sections 6(c), 7(d), 17(f), and 38(a) of the Investment Company Act [15 U.S.C. 80a-6(c), 80a-7(d), 80a-17(f) and 80a-37(a)]. The Commission is proposing to rescind rule 17f-3 and Form N-17f-1 under the Investment Company Act. The Commission is proposing amendments to Form N-CEN under the authority set forth in sections 8, 30, 35, and 38 of the Investment Company Act of 1940 [15 U.S.C. 80a-8, 80a-18, 80a-34, and 80a-37].

The Commission is proposing new rule 223-1 by a redesignation of rule 206(4)-2 under the Advisers Act under the authority set forth in sections 206(4), 211(a), and 223 of the Advisers Act [15 U.S.C. 80b-6(4), 80b-11(a), and 80b-18b]. The Commission is proposing corresponding amendments to rule 204-2 under the Advisers Act under the authority set forth in sections 204, 206(4), and 211(a) of the Advisers Act [15 U.S.C. 80b-4, 80b-6(4), and 80b-11(a)]. The Commission is proposing to amend Form ADV pursuant to the authority set forth in sections 203(c)(1), 204, 211(a), and 223 of the Advisers Act [15 U.S.C. 80b-3(c)(1), 80b-4, 80b-11(a), and 80b-18b]. The Commission is proposing to amend Form ADV-E pursuant to authority set forth in sections 204, 206, and 211(a) of the Advisers Act [15 U.S.C. 80b-4, 80b-6, and 80b-11(a))].

List of Subjects

17 CFR Part 270

  • Incorporation by reference
  • Investment companies
  • Reporting and recordkeeping requirements
  • Securities

17 CFR Part 274

  • Investment companies
  • Reporting and recordkeeping requirements
  • Securities

17 CFR Parts 275 and 279

  • Reporting and recordkeeping requirements
  • Securities

Text of Proposed Rules and Rule and Form Amendments

For the reasons set out in the preamble, title 17, chapter II of the Code of Federal Regulations is proposed to be amended as follows:

PART 270—RULES AND REGULATIONS, INVESTMENT COMPANY ACT OF 1940

1. The authority citation for part 270 continues to read, in part, as follows:

Authority: 15 U.S.C. 80a-1 et seq., 80a-34(d), 80a-37, 80a-39, 1681w(a)(1), 6801-6809, 6825, and Pub. L. 111-203, sec. 939A, 124 Stat. 1376 (2010), unless otherwise noted.

* * * * *

2. Amend § 270.17f-1 by:

a. Revising the section heading.

b. Revising paragraph (a).

c. Removing paragraphs (b) through (d).

The revisions read as follows:

Custody of investment company assets with brokers or dealers.

An investment company registered under the Investment Company Act (15 U.S.C. 80a) or a business development company may place or maintain its securities and similar investments at a broker or dealer registered under section 15(b)(1) of the Securities Exchange Act of 1934 (15 U.S.C. 78o(b)(1)) where the broker-dealer's custody of the securities or similar investments is subject to the requirements of rule 15c3-3 under the Securities Exchange Act of 1934 (17 CFR 240.15c3-3) or such other rule that the Commission determines provides similar customer protections.

3. Amend § 270.17f-2 by:

a. Revising the section heading.

b. Revising paragraph (a).

The revisions read as follows:

Custody of investments by registered management investment companies and business development companies.

(a) The securities and similar investments of a registered management investment company or a business development company may be maintained in the custody of such company only in accordance with the provisions of this section. Investments maintained by such a company with a bank or other company whose functions and physical facilities are supervised by Federal or State authority under any arrangement whereunder the directors, officers, employees or agents of such company are authorized or permitted to withdraw such investments upon their mere receipt are deemed to be in the custody of such company and may be so maintained only upon compliance with the provisions of this section.

* * * * *

4. Amend § 270.17f-3 by removing and reserving.

The revisions read as follows:

[Reserved]

5. Amend § 270.17f-4 by:

a. Revising paragraph (c)(1).

b. Revising paragraph (c)(3).

The revisions read as follows:

Custody of investment company assets with a securities depository.
* * * * *

(c) Definitions. For purposes of this section the terms:

(1) Clearing corporation, financial asset, securities intermediary, and security entitlement have the same meanings as is attributed to those terms in § 8-102, § 8-103, and §§ 8-501 through 8-511 of the Uniform Commercial Code, 2002 Official Text and Comments, which is incorporated by reference into this section with the approval of the Director of the Federal Register under 5 U.S.C. 552(a) and 1 CFR part 51. This material is available for inspection at the Securities and Exchange Commission (Commission) and at the National Archives and Records Administration (NARA). Contact the Commission at: 100 F Street NE, Washington, DC 20549-1090, (202) 551-6787, ,www.sec.gov. For information on the availability of this material at NARA, visit www.archives.gov/​federal-register/​cfr/​ibr-locations.html or email . You may obtain a copy of the Uniform Commercial Code from the Uniform Law Commission (ULC, also known as National Conference of Commissioners on Uniform State Laws) at (312) 450-6600; ; www.uniformlaws.org.

* * *

(3) Fund means an investment company registered under the Act or a business development company and, where the context so requires with respect to a fund that is a unit investment trust or a face-amount certificate company, includes the fund's trustee.

* * * * *

6. Amend § 270.17f-5 by:

a. Revising paragraph (a)(4).

The revisions read as follows:

Custody of investment company assets outside the United States.

(a) Definitions. For purposes of this section:

* * *

(4) Fund means a management investment company registered under the Act (15 U.S.C. 80a) or a business development company and incorporated or organized under the laws of the United States or of a state.

* * * * *

7. Amend § 270.17f-6 by revising paragraph (b)(3).

The revisions read as follows:

Custody of investment company assets with Futures Commission Merchants and Commodity Clearing Organizations.
* * * * *

(b) For purposes of this section:

* * *

(3) Fund means an investment company registered under the Act (15 U.S.C. 80a-1 et seq.) or a business development company.

8. Amend § 270.17f-7 by revising paragraph (b).

The revisions read as follows:

Custody of investment company assets with a foreign securities depository.
* * * * *

(b) Definitions. The terms Foreign Assets, Fund, Qualified Foreign Bank, Registered Canadian Fund, and U.S. Bank have the same meanings as in § 270.17f-5. In addition:

(1) Eligible Securities Depository means a system for the central handling of securities where all securities of any particular class or series of any issuer deposited within the system are treated as fungible and may be transferred or pledged by bookkeeping entry without physical delivery of securities that:

(i) Acts as or operates a system for the central handling of securities or equivalent book-entries in the country where it is incorporated, or a transnational system for the central handling of securities or equivalent book-entries;

(ii) Is regulated by a foreign financial regulatory authority as defined under section 2(a)(50) of the Act (15 U.S.C. 80a-2(a)(50));

(iii) Holds assets for the custodian that participates in the system on behalf of the Fund under safekeeping conditions no less favorable than the conditions that apply to other participants;

(iv) Maintains records that identify the assets of each participant and segregate the system's own assets from the assets of participants; ( printed page 64077)

(v) Provides periodic reports to its participants with respect to its safekeeping of assets, including notices of transfers to or from any participant's account; and

(vi) Is subject to periodic examination by regulatory authorities or independent accountants.

9. Add § 270.17f-8 to read as follows:

Custody of Crypto Assets by State Trust Companies.

A fund may place and maintain the fund's crypto assets and related cash and/or cash equivalents with a state trust company, provided that it satisfies the conditions of paragraph (a) of this section. A fund may rely on section 17(f) of the Act (15 U.S.C. 80a-17(f)), in lieu of this section, to place and maintain crypto assets and related cash and cash equivalents with a state trust company that is a bank as defined in section 2(a)(5) of the Act (15 U.S.C. 80a-2(a)(5)).

(a) Prior to engaging the state trust company and on an annual basis thereafter, the fund must:

(1) Determine in writing that it has a reasonable basis, after due inquiry, for believing that the state trust company:

(i) Is authorized by the relevant state banking authority to provide custody services for crypto assets and related cash and/or cash equivalents; and

(ii) Maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse and misappropriation, with such policies and procedures addressing, at a minimum, private key management and cybersecurity; and

(2) Receive and review the state trust company's most recent annual financial statements and confirm that such financial statements are prepared in accordance with U.S. GAAP and are subject to an audit (as defined in rule 1-02(d) of Regulation S-X (17 CFR 210.1-02(d))) that is performed by an independent public accountant; and

(3) Receive and review the state trust company's most recent written internal control report prepared by an independent public accountant during the current or prior calendar year and confirm that such internal control report contains an opinion of such independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of client crypto assets and related cash and/or cash equivalents.

(b) The fund enters into a custodial services agreement with the state trust company, providing that all crypto assets (and related cash and/or cash equivalents) held in custody for the fund will be held in accounts that are segregated from the state trust company's proprietary assets.

(c) Definitions. For purposes of this section:

Crypto Asset has the same meaning as in 17 CFR 275.223-1(d)(3).

Fund means a management investment company registered under the Act (15 U.S.C. 80a) or a business development company.

Independent public accountant has the same meaning as in 17 CFR 275.223-1(d)(8).

State trust company means a legal entity organized under state law that is supervised and examined by a state authority having supervision over banks and permitted to exercise fiduciary powers under applicable state law.

U.S. Generally Accepted Accounting Principles (U.S. GAAP) has the same meaning as in 17 CFR 275.223-1(d)(19).

10. Add § 270.17f-9 to read as follows:

Custody of Crypto Assets by Registered Investment Companies and Business Development Companies.

(a) Safekeeping Required.

(1) A fund may place and maintain a crypto asset of the fund with an investment adviser to the fund that complies with 17 CFR 275.223-1(b)(7) with respect to the crypto asset, if the fund satisfies the provisions of paragraph (b) of this section with respect to the arrangement. A crypto asset placed and maintained with an investment adviser under this section will be deemed to be in the custody of the fund and subject to this section in lieu of 17 CFR 270.17f-2.

(b) Investment Adviser Custody Conditions.

(1) Board oversight of custody arrangement.

(i) Quarterly review of qualified custodian determination. Prior to the investment adviser maintaining the crypto asset and quarterly thereafter, the fund's board of directors, including a majority of directors who are not interested persons of the fund, reviews the written report documenting the basis for the investment adviser's determination for believing that no qualified custodian will maintain the crypto asset pursuant to 17 CFR 275.223-1(b)(7)(i) with respect to the fund's crypto asset; and

(ii) Annual review. Prior to the investment adviser maintaining the crypto asset and annually thereafter, the fund's board of directors, including a majority of directors who are not interested persons of the fund, determines that the crypto asset will be subject to reasonable care, if maintained with the investment adviser, after considering the factors relevant to the safekeeping of the crypto asset. To facilitate the board's assessment, the investment adviser must furnish, and the fund's board of directors must evaluate, such information as may reasonably be necessary for the board to evaluate the fund's custody arrangement, including at a minimum:

(A) A written report documenting the basis for the investment adviser's determination under 17 CFR 275.223-1(b)(7)(ii) that it has expertise regarding the safeguarding of the crypto asset and the systems, including the appropriate technology, software, hardware, and other associated systems and processes, necessary to safeguard the crypto asset against loss, theft, misuse, and misappropriation;

(B) The most recent written annual review of the adviser's safeguarding systems and cybersecurity controls pursuant to 17 CFR 275.223-1(b)(7)(v) if a written annual review of the adviser's safeguarding systems is available at the time of the board's determination; and

(C) The most recent written internal control report as required by 17 CFR 275.223-1(b)(7)(iv), if a written internal control report is available at the time of the board's determination; and

(D) If the most recent written annual review of the adviser's safeguarding systems and cybersecurity controls or the adviser's most recent written internal control report are not available at the time required in paragraphs (b)(1)(ii)(B) or (b)(1)(ii)(C) of this section, such information shall be furnished by the adviser to the board for its evaluation by the next regularly scheduled board meeting after the information becomes available.

(c) Distributed crypto assets. The receipt of a distributed crypto asset will be deemed to not be in violation of section 17(f) of the Investment Company Act of 1940 (15 U.S.C. 80a-17(f)) and the rules thereunder, provided that, as soon as reasonably practicable, the fund places and maintains the distributed crypto asset with (A) an investment adviser to the fund in compliance with 17 CFR 270.17f-9(b); or (B) a custodian permitted to hold the distributed crypto asset in compliance with section 17(f) of the Investment Company Act of 1940 (15 U.S.C. 80a-17(f)) or the rules thereunder.

(d) Definitions. For purposes of this section: ( printed page 64078)

Crypto asset has the same meaning as in 17 CFR 275.223-1(d)(3).

Distributed crypto asset has the same meaning as in 17 CFR 275.223-1(d)(7).

Fund means a management investment company registered under the Act (15 U.S.C. 80a) or a business development company.

11. Amend § 270.31a-1 to read as follows:

Records to be maintained by investment companies, certain majority-owned subsidiaries thereof, and other persons having transactions with investment companies.

(a) Every investment company, and every underwriter, broker, dealer, or investment adviser which is a majority-owned subsidiary of such a company, shall maintain and keep current the accounts, books, and other documents relating to its business which constitute the record forming the basis for financial statements required to be filed pursuant to section 30 of the Investment Company Act of 1940 and of the auditor's certificates relating thereto. In the case of an investment company that is a business development company, the financial statements required to be filed are pursuant to section 13 of the Securities Exchange Act of 1934.

(b) Every investment company shall maintain and keep current the following books, accounts, and other documents:

(1) Journals (or other records of original entry) containing an itemized daily record in detail of all purchases and sales of securities (including sales and redemptions of its own securities), all receipts and deliveries of securities (including certificate numbers if such detail is not recorded by custodian or transfer agent), all receipts and disbursements of cash and all other debits and credits. Such records shall show for each such transaction the name and quantity of securities, the unit and aggregate purchase or sale price, commission paid, the market on which effected, the trade date, the settlement date, and the name of the person through or from whom purchased or received or to whom sold or delivered. In the case of a money market fund, also identify the provider of any Demand Feature or Guarantee (as defined in § 270.2a-7(a)(9) or § 270.2a-7(a)(16) respectively) and give a brief description of the nature of the Demand Feature or Guarantee ( e.g., unconditional demand feature, conditional demand feature, letter of credit, or bond insurance) and, in a subsidiary portfolio investment record, provide the complete legal name and accounting and other information (including sufficient information to calculate coupons, accruals, maturities, puts, and calls) necessary to identify, value, and account for each investment.

(2) General and auxiliary ledgers (or other records) reflecting all assets, liability, reserve, capital, income and expense accounts, including:

(i) Separate ledger accounts (or other records) reflecting the following:

( a) Securities in transfer;

( b) Securities in physical possession;

( c) Securities borrowed and securities loaned;

( d) Monies borrowed and monies loaned (together with a record of the collateral therefor and substitutions in such collateral);

( e) Dividends and interest received;

( f) Dividends receivable and interest accrued.

Instruction.

(a) and (b) of this subdivision shall be stated in terms of securities quantities only; (c) and (d) of this subdivision shall be stated in dollar amounts and securities quantities as appropriate; (e) and (f) of this subdivision shall be stated in dollar amounts only.

(ii) Separate ledger accounts (or other records) for each portfolio security, showing (as of trade dates)

(a) the quantity and unit and aggregate price for each purchase, sale, receipt, and delivery of securities and commodities for such accounts, and

(b) all other debits and credits for such accounts. Securities positions and money balances in such ledger accounts (or other records) shall be brought forward periodically but not less frequently than at the end of fiscal quarters. Any portfolio security, the salability of which is conditioned, shall be so noted. A memorandum record shall be available setting forth, with respect to each portfolio security account, the amount and declaration ex-dividend, and payment dates of each dividend declared thereon.

(iii) Separate ledger accounts (or other records) for each broker-dealer bank or other person with or through which transactions in portfolio securities are effected, showing each purchase or sale of securities with or through such persons, including details as to the date of the purchase or sale, the quantity and unit and aggregate price of such securities, and the commissions or other compensation paid to such persons. Purchases or sales effected during the same day at the same price may be aggregated.

(iv) Separate ledger accounts (or other records), which may be maintained by a transfer agent or registrar, showing for each shareholder of record of the investment company the number of shares of capital stock of the company held. In respect of share accumulation accounts (arising from periodic investment plans, dividend reinvestment plans, deposit of issued shares by the owner thereof, etc.), details shall be available as to the dates and number of shares of each accumulation, and except with respect to already issued shares deposited by the owner thereof, prices of each such accumulation.

(3) A securities record or ledger reflecting separately for each portfolio security as of trade date all “long” and “short” positions carried by the investment company for its own account and showing the location of all securities long and the off-setting position to all securities short. The record called for by this paragraph shall not be required in circumstances under which all portfolio securities are maintained by a bank or banks or a member or members of a national securities exchange as custodian under a custody agreement or as agent for such custodian.

(4) Corporate charters, certificates of incorporation or trust agreements, and by-laws, and minute books of stockholders' and directors' or trustees' meetings; and minute books of directors' or trustees' committee and advisory board or advisory committee meetings.

(5) A record of each brokerage order given by or in behalf of the investment company for, or in connection with, the purchase or sale of securities, whether executed or unexecuted. Such record shall include the name of the broker, the terms and conditions of the order and of any modification or cancellation thereof, the time of entry or cancellation, the price at which executed, and the time of receipt of report of execution. The record shall indicate the name of the person who placed the order in behalf of the investment company.

(6) A record of all other portfolio purchases or sales showing details comparable to those prescribed in paragraph (b)(5) of this section.

(7) A record of all puts, calls, spreads, straddles, and other options in which the investment company has any direct or indirect interest or which the investment company has granted or guaranteed; and a record of any contractual commitments to purchase, sell, receive or deliver securities or other property (but not including open orders placed with broker-dealers for the purchase or sale of securities, which may be cancelled by the company on notices without penalty or cost of any kind); containing, at least, an identification of the security, the number of units involved, the option ( printed page 64079) price, the date of maturity, the date of issuance, and the person to whom issued.

(8) A record of the proof of money balances in all ledger accounts (except shareholder accounts), in the form of trial balances. Such trial balances shall be prepared currently at least once a month.

(9) A record for each fiscal quarter, which shall be completed within ten days after the end of such quarter, showing specifically the basis or bases upon which the allocation of orders for the purchase and sale of portfolio securities to named brokers or dealers and the division of brokerage commissions or other compensation on such purchase and sale orders among named persons were made during such quarter. The record shall indicate the consideration given to

(i) sales of shares of the investment company by brokers or dealers,

(ii) the supplying of services or benefits by brokers or dealers to the investment company, its investment adviser or principal underwriter or any persons affiliated therewith, and

(iii) any other considerations other than the technical qualifications of the brokers and dealers as such. The record shall show the nature of the services or benefits made available, and shall describe in detail the application of any general or specific formula or other determinant used in arriving at such allocation of purchase and sale orders and such division of brokerage commissions or other compensation. The record shall also include the identities of the persons responsible for the determination of such allocation and such division of brokerage commissions or other compensation.

(10) A record in the form of an appropriate memorandum identifying the person or persons, committees, or groups authorizing the purchase or sale of portfolio securities. Where an authorization is made by a committee or group, a record shall be kept of the names of its members who participated in the authorization. There shall be retained as part of the record required by this paragraph any memorandum, recommendation, or instruction supporting or authorizing the purchase or sale of portfolio securities. The requirements of this paragraph are applicable to the extent they are not met by compliance with the requirements of paragraph (b)(4) of this section.

(11) Files of all advisory material received from the investment adviser, any advisory board or advisory committee, or any other persons from whom the investment company accepts investment advice, other than material which is furnished solely through uniform publications distributed generally.

(12) The term “other records” as used in the expressions “journals (or other records of original entry)” and “ledger accounts (or other records)” shall be construed to include, where appropriate, copies of voucher checks, confirmations, or similar documents which reflect the information required by the applicable rule or rules in appropriate sequence and in permanent form, including similar records developed by the use of automatic data processing systems.

(13)

(i) The written policies and procedures required to be adopted and implemented pursuant to § 248.30(a)(1);

(ii) The written documentation of any detected unauthorized access to or use of customer information, as well as any response to, and recovery from such unauthorized access to or use of customer information required by § 248.30(a)(3);

(iii) The written documentation of any investigation and determination made regarding whether notification is required pursuant to § 248.30(a)(4), including the basis for any determination made, any written documentation from the United States Attorney General related to a delay in notice, as well as a copy of any notice transmitted following such determination;

(iv) The written policies and procedures required to be adopted and implemented pursuant to § 248.30(a)(5)(i);

(v) The written documentation of any contract or agreement entered into pursuant to § 248.30(a)(5); and

(vi) The written policies and procedures required to be adopted and implemented pursuant to § 248.30(b)(2).

(14) The records required to be maintained and preserved under this section related to a crypto asset (as defined in § 275.223-1(d)(3)) may be maintained and preserved by the investment company on a crypto network (as defined in § 275.223-1(d)(5)), provided that such records can be provided promptly upon request by the Commission (including its examiners and others representatives) in a human-readable and reasonably usable electronic format during the period that such book or record is required to be maintained and preserved under 17 CFR 270.31a-2.

(c) Every underwriter, broker, or dealer which is a majority-owned subsidiary of an investment company shall maintain in the form prescribed therein such accounts, books and other documents as are required to be maintained by brokers and dealers by rule adopted under section 17 of the Securities Exchange Act of 1934.

(d) Every depositor of any investment company, and every principal underwriter for any investment company other than a closed-end investment company, shall maintain such accounts, books and other documents as are required to be maintained by brokers and dealers by rule adopted under section 17 of the Securities Exchange Act of 1934, to the extent such records are necessary or appropriate to record such person's transactions with such investment company.

(e) Every investment advisor which is a majority-owned subsidiary of an investment company shall maintain in the form prescribed therein such accounts, books and other documents as are required to be maintained by registered investment advisers by rule adopted under section 204 of the Investment Advisers Act of 1940.

(f) Every investment adviser not a majority-owned subsidiary of an investment company shall maintain such accounts, books and other documents as are required to be maintained by registered investment advisers by rule adopted under section 204 of the Investment Advisers Act of 1940, to the extent such records are necessary or appropriate to record such person's transactions with such investment company.

(g) Definitions. For purposes of this section the term:

Investment company means a registered investment company or a business development company.

12. Amend § 270.31a-2 to read as follows:

Records to be preserved by investment companies, certain majority-owned subsidiaries thereof, and other persons having transactions with investment companies.

(a) Every investment company shall:

(1) Preserve permanently, the first two years in an easily accessible place, all books and records required to be made pursuant to paragraphs (1) through (4) of § 270.31a-1(b);

(2) Preserve for a period not less than six years from the end of the fiscal year in which any transaction occurred, the first two years in an easily accessible place, all books and records required to be made pursuant to § 270.31a-1(b)(5) through (12) and all vouchers, memoranda, correspondence, checkbooks, bank statements, cancelled checks, cash reconciliation, cancelled stock certificates, and all schedules ( printed page 64080) evidencing and supporting each computation of net asset value of the investment company shares, including schedules evidencing and supporting each computation of an adjustment to net asset value of the investment company shares based on swing pricing policies and procedures established and implemented pursuant to § 270.22c-1(a)(3), all schedules evidencing and supporting each computation of a liquidity fee by a money market fund pursuant to § 270.2a-7(c)(2), and other documents required to be maintained by § 270.31a-1(a) and not enumerated in § 270.31a-1(b).

(3) Preserve for a period not less than 6 years from the end of the fiscal year last used, the first 2 years in an easily accessible place, any advertisement, pamphlet, circular, form letter or other sales literature addressed to or intended for distribution to prospective investors;

(4) Preserve for a period not less than six years, the first two years in an easily accessible place, any record of the initial determination that a director is not an interested person of the investment company, and each subsequent determination that the director is not an interested person of the investment company. These records must include any questionnaire and any other document used to determine that a director is not an interested person of the company;

(5) Preserve for a period not less than six years, the first two years in an easily accessible place, any materials used by the disinterested directors of an investment company to determine that a person who is acting as legal counsel to those directors is an independent legal counsel;

(6) Preserve for a period not less than six years, the first two years in an easily accessible place, any documents or other written information considered by the directors of the investment company pursuant to section 15(c) of the Act (15 U.S.C. 80a-15(c)) in approving the terms or renewal of a contract or agreement between the company and an investment adviser; and

(7) Preserve for a period not less than six years, the first two years in an easily accessible place, any shareholder report required by § 270.30e-1 (including any version posted on a website or otherwise provided electronically) that is not filed with the Commission in the exact form in which it was used; and

(8) Preserve for a period not less than six years, the first two years in an easily accessible place, the records required by § 270.31a-1(b)(13) apart from any policies and procedures thereunder and, in the case of policies and procedures required under § 270.31a-1(b)(13), preserve a copy of such policies and procedures in effect, or that at any time within the past six years were in effect, in an easily accessible place.

(9) For a fund as defined in defined in § 270.17f-8, and with respect to each crypto asset of the fund and related cash and/or cash equivalents held in custody under § 270.17f-8, preserve for a period not less than six years, the first two years in an easily accessible place:

(i) A memorandum describing the basis upon which the fund has made the determinations as required by § 270.17f-8(a).

(ii) Records of the audited financial statements obtained or received as required by § 270.17f-8(a)(2).

(iii) A copy of any internal control report obtained or received as required by § 270.17f-8(a)(3).

(10) For a fund as defined in § 270.17f-9, and with respect to each crypto asset of the fund held in custody under § 270.17f-9, preserve for a period not less than six years, the first two years in an easily accessible place, any report or other information that is provided to the fund's board of directors as required under § 270.17f-9(b)(1).

(b) Every underwriter, broker, or dealer which is a majority-owned subsidiary of an investment company shall preserve for the periods prescribed therein such accounts, books and other documents as are required to be preserved by brokers and dealers by rule adopted under section 17 of the Securities Exchange Act of 1934.

(c) Every depositor of any investment company, and every principal underwriter for any investment company other than a closed-end company, shall preserve for a period of not less than six years such accounts, books and other documents as are required to be maintained by brokers and dealers by rule adopted under section 17 of the Securities Exchange Act of 1934, to the extent such records are necessary or appropriate to record such person's transactions with such investment company.

(d) Every investment adviser which is a majority-owned subsidiary of an investment company shall preserve for the periods prescribed therein such accounts, books and other documents as are required to be preserved by investment advisers by rule adopted under section 204 of the Investment Advisers Act of 1940.

(e) Every investment adviser not a majority-owned subsidiary of an investment company shall preserve for a period of not less than six years such accounts, books and other documents as are required to be maintained by registered investment advisers by rule adopted under section 204 of the Investment Advisers Act of 1940, to the extent such records are necessary or appropriate to record such person's transactions with such investment company.

(f) Micrographic and electronic storage permitted—

(1) General. The records required to be maintained and preserved under this part may be maintained and preserved for the required time by, or on behalf of, an investment company on:

(i) Micrographic media, including microfilm, microfiche, or any similar medium; or

(ii) Electronic storage media, including any digital storage medium or system that meets the terms of this section.

(2) General requirements. The investment company, or person that maintains and preserves records on its behalf, must:

(i) Arrange and index the records in a way that permits easy location, access, and retrieval of any particular record;

(ii) Provide promptly any of the following that the Commission (by its examiners or other representatives) or the directors of the company may request:

(A) A legible, true, and complete copy of the record in the medium and format in which it is stored;

(B) A legible, true, and complete printout of the record; and

(C) Means to access, view, and print the records; and

(iii) Separately store, for the time required for preservation of the original record, a duplicate copy of the record on any medium allowed by this section.

(3) Special requirements for electronic storage media. In the case of records on electronic storage media, the investment company, or person that maintains and preserves records on its behalf, must establish and maintain procedures:

(i) To maintain and preserve the records, so as to reasonably safeguard them from loss, alteration, or destruction;

(ii) To limit access to the records to properly authorized personnel, the directors of the investment company, and the Commission (including its examiners and other representatives); and

(iii) To reasonably ensure that any reproduction of a non-electronic original record on electronic storage media is complete, true, and legible when retrieved.

(4) Notwithstanding the provisions of paragraphs (a) through (e) of this section, any record, book or other document may be destroyed in accordance with a plan previously ( printed page 64081) submitted to and approved by the Commission. A plan shall be deemed to have been approved by the Commission if notice to the contrary has not been received within 90 days after submission of the plan to the Commission.

(g) Definitions. For purposes of this section the term:

Investment company means a registered investment company or a business development company.

PART 274—FORMS PRESCRIBED UNDER THE INVESTMENT COMPANY ACT OF 1940

13. The general authority citation for part 274 continues to read, in part, as follows:

Authority:15 U.S.C. 77f, 77g, 77h, 77j, 77s, 78c(b), 78 l, 78m, 78n, 78n-1, 78o(d), 80a-8, 80a-24, 80a-26, 80a-29, and sec. 939A, Pub. L. 111-203, 124 Stat. 1376, unless otherwise noted.

14. Amend Form N-CEN (referenced in § 274.101) by:

a. Amending General Instruction E;

b. Adding Items B.24, C.12.a.vii.9, C.12.a.vii.10, D.14.a.vii.9, and D.14.a.vii.10;

c. Amending Items C.12.a.vii.2 and Item D.14.a.vii.2;

d. Redesignating Item C.12.a.vii.9 as Item C.12.a.vii.11;

e. Redesignating Item D.14.a.vii.9 as Item D.14.a.vii.11.

Note: Form N-CEN is attached as Appendix A to this document. Form N-CEN will not appear in the Code of Federal Regulations.

15. Remove and reserve § 274.219.

[Removed and Reserved]

PART 275—RULES AND REGULATIONS, INVESTMENT ADVISERS ACT OF 1940

16. The general authority citation for part 275 is revised, to read in part and add a sectional authority for § 275.223-1, as follows:

Authority: 15 U.S.C. 80b-2(a)(11)(G), 80b-2(a)(11)(H), 80b-2(a)(17), 80b-3, 80b-4, 80b-4a, 80b-6(4), 80b-6a, and 80b-11, unless otherwise noted.

* * * * *

§ 275.204-2 is also issued under 15 U.S.C. 80b-6.

* * * * *

§ 275.223-1 is also issued under 15 U.S.C. 80-18b.

17. Amend § 275.204-2(a)(17)(iii) to read as follows:

Books and records to be maintained by investment advisers.

(a) * * *

(17) * * *

(iii) A copy of any internal control report obtained or received pursuant to § 275.223-1(a)(6).

* * * * *

18. Add §§ 275.204-2(a)(26) and (a)(27) to read as follows:

Books and records to be maintained by investment advisers.
* * * * *

(a) * * *

(26)

(i) A memorandum describing the basis upon which you have made the determinations as required by § 275.223-1(b)(7)(i).

(ii) A memorandum describing the basis upon which you have made the determination as to its safeguarding expertise required under § 275.223-1(b)(7)(ii).

(iii) Records identifying persons that have been designated pursuant to § 275.223-1(b)(7)(ii)(A).

(iv) A copy of the written assessment of cybersecurity risks as required by § 275.223-1(b)(7)(iii)(A).

(v) A copy of any internal control report obtained as required by § 275.223-1(b)(7)(iv).

(vi) Records documenting the investment adviser's annual review as required by § 275.223-1(b)(7)(v).

(vii) Account statements provided to clients as required by § 275.223-1(b)(7)(vi), and records of any transmissions and notices sent to clients pursuant to § 275.223-1(b)(7)(vi).

(viii) A copy of any financial asset election made pursuant to § 275.223-1(b)(7)(viii).

(ix) For each client for whom you maintain client crypto assets under § 275.223-1(b)(7), records that include such information as may be reasonably necessary to reconstruct all financial positions and transactions related to such client crypto assets, including, at minimum, client name, client account number, crypto asset address, transaction amount, transaction destination, transaction authorization, and relevant metadata.

(x) Any records required to be made and kept under paragraph (b) of this section related to client crypto assets that you maintain under § 275.223-1(b)(7), provided that references to securities in paragraph (b) shall be understood to also include any “crypto asset” of a “registered investment company” or “business development company,” as those terms are defined in § 275.223-1, maintained by you under § 275.223-1(b)(7).

(27)

(i) A memorandum describing the basis upon which the investment adviser made the determinations as required by § 275.223-1(d)(13)(v).

(ii) Records of the audited financial statements obtained or received as required by § 275.223-1(d)(13)(v)(B).

(iii) A copy of any internal control report obtained or received as required by § 275.223-1(d)(13)(v)(C).

* * * * *

19. Amend § 275.204-2(b)(5) to read as follows:

(b) * * *

(5) A memorandum describing the basis upon which you have determined that the presumption that any related person is not operationally independent under § 275.223-1(d)(12) has been overcome.

* * * * *

20. Add § 275.204-2(b)(6) to read as follows:

* * * * *

(b) * * *

(6) Any standing letter of authorization (as defined in § 275.223-1(d)(17) of this chapter) and any related records pursuant to § 275.223-1(b)(8), that is in effect, or at any time within the past five years was, in effect.

* * * * *

21. Revise § 275.204-2(e)(1) as follows:

* * * * *

(e) (1) All books and records required to be made under the provisions of paragraphs (a) to (c)(1)(i), inclusive, and (c)(2) of this section (except for books and records required to be made under the provisions of paragraphs (a)(11), (a)(12)(i), (a)(12)(iii), (a)(13)(ii), (a)(13)(iii), (a)(16), (a)(17)(i), and (b)(6) of this section), shall be maintained and preserved in an easily accessible place for a period of not less than five years from the end of the fiscal year during which the last entry was made on such record, the first two years in an appropriate office of the investment adviser.

* * * * *

21. Revise § 275.204-2(g) as follows:

* * * * *

(g) Micrographic, electronic storage, and crypto network permitted —(1) General. The records required to be maintained and preserved pursuant to this part may be maintained and preserved for the required time by an investment adviser on:

(i) Micrographic media, including microfilm, microfiche, or any similar medium;

(ii) Electronic storage media, including any digital storage medium or system that meets the terms of this section; or

(iii) A crypto network (as defined in § 275.223-1(d)(5) of this chapter) related to a crypto asset (as defined in ( printed page 64082) § 275.223-1(d)(3) of this chapter) that meets the terms of this section.

(2) General requirements. Except for records maintained on a crypto network pursuant to paragraph (g)(4) of this section, the investment adviser must:

(i) Arrange and index the records in a way that permits easy location, access, and retrieval of any particular record;

(ii) Provide promptly any of the following that the Commission (by its examiners or other representatives) may request:

(A) A legible, true, and complete copy of the record in the medium and format in which it is stored;

(B) A legible, true, and complete printout of the record; and

(C) Means to access, view, and print the records; and

(iii) Separately store, for the time required for preservation of the original record, a duplicate copy of the record on any medium allowed by this section.

(3) Special requirements for electronic storage media. In the case of records on electronic storage media under paragraph (g)(1)(ii) of this section, the investment adviser must establish and maintain procedures:

(i) To maintain and preserve the records, so as to reasonably safeguard them from loss, alteration, or destruction;

(ii) To limit access to the records to properly authorized personnel and the Commission (including its examiners and other representatives); and

(iii) To reasonably ensure that any reproduction of a non-electronic original record on electronic storage media is complete, true, and legible when retrieved.

(4) Special requirements for records on a crypto network. In the case of records on a crypto network under paragraph (g)(1)(iii) of this section, the investment adviser must provide, promptly upon request by the Commission (including its examiners and others representatives), such records in a human-readable and reasonably usable electronic format during the period that such book or record is required to be maintained and preserved under this section.

22. Revise § 275.204-2(h)(2) as follows:

* * * * *

(h) * * *

(2) A record made and kept pursuant to any provision of paragraph (a) or (b) of this section, which contains all the information required under any other provision of paragraph (a) or (b) of this section, need not be maintained in duplicate in order to meet the requirements of the other provision of paragraph (a) or (b) of this section.

* * * * *

23. Remove and reserve § 275.206(4)-2.

[Reserved]

24. Add § 275.223-1 to read as follows:

* * * * *
Safeguarding client assets.

(a) Safekeeping required. If you are an investment adviser registered or required to be registered under section 203 of the Act (15 U.S.C. 80b-3), you must take the following steps to safeguard client funds and securities of which you have custody, provided that, where this section (17 CFR 275.223-1) applies to the account of a registered investment company or a business development company, references to funds and securities shall be understood to refer to the securities and similar investments held for such account:

(1) Qualified custodian. A qualified custodian must maintain client funds and securities:

(i) In a separate account for each client under that client's name; or

(ii) In accounts that contain only your clients' funds and securities, under your name as agent or trustee for the clients.

(2) Notice to clients. If you open an account with a qualified custodian on your client's behalf, either under the client's name or under your name as agent, you must promptly notify the client in writing of the qualified custodian's name, address, account number, and the manner in which the funds or securities are maintained, when the account is opened and following any changes to this information. If you send account statements to a client to which you are required to provide this notice, include in the notification provided to that client and in any subsequent account statement you send that client a statement urging the client to compare the account statements from the custodian with those from the adviser.

(3) Account statements to clients. You must have a reasonable basis, after due inquiry, for believing that the qualified custodian sends an account statement, at least quarterly, to each of your clients for which it maintains funds or securities, identifying the amount of funds and of each security in the account at the end of the period and setting forth all transactions in the account during that period.

(4) Independent verification. The client funds and securities of which you have custody must be verified by actual examination at least once during each calendar year, except as provided below, by an independent public accountant, pursuant to a written agreement between you and the accountant, at a time that is chosen by the accountant without prior notice or announcement to you and that is irregular from year to year. The written agreement must provide for the first examination to occur within six months of becoming subject to this paragraph, except that, if you maintain client funds or securities pursuant to this section as a qualified custodian, the agreement must provide for the first examination to occur no later than six months after obtaining the internal control report. The written agreement must require the accountant to:

(i) File a certificate on Form ADV-E (17 CFR 279.8) with the Commission within 120 days of the time chosen by the accountant in paragraph (a)(4) of this section, stating that it has examined the funds and securities and describing the nature and extent of the examination;

(ii) Upon finding any material discrepancies during the course of the examination, notify the Commission within one business day of the finding, by electronic means directed to the attention of the Division of Examinations; and

(iii) Upon resignation or dismissal from, or other termination of, the engagement, or upon removing itself or being removed from consideration for being reappointed, file within four business days Form ADV-E accompanied by a statement that includes:

(A) The date of such resignation, dismissal, removal, or other termination, and the name, address, and contact information of the accountant; and

(B) An explanation of any problems relating to examination scope or procedure that contributed to such resignation, dismissal, removal, or other termination.

(5) Special rule for limited partnerships and limited liability companies. If you or a related person is a general partner of a limited partnership (or managing member of a limited liability company, or hold a comparable position for another type of pooled investment vehicle), the account statements required under paragraph (a)(3) of this section must be sent to each limited partner (or member or other beneficial owner).

(6) Investment advisers acting as qualified custodians. If you maintain, or if you have custody because a related person maintains, client funds or securities pursuant to this section as a ( printed page 64083) qualified custodian in connection with advisory services you provide to clients, you must obtain, or receive from your related person, within six months of becoming subject to this paragraph and thereafter no less frequently than once each calendar year a written internal control report prepared by an independent public accountant:

(i) The internal control report must include an opinion of an independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of funds and securities held by either you or a related person on behalf of your advisory clients; and

(ii) The independent public accountant must verify that the funds and securities are reconciled to a custodian other than you or your related person.

(7) Independent representatives. A client may designate an independent representative to receive, on its behalf, notices and account statements as required under paragraphs (a)(2) and (a)(3), any financial statements pursuant to paragraph (b)(4), and any account statements, transmissions and notices sent pursuant to paragraph (b)(7)(vi) of this section.

(b) Exceptions.

(1) Shares of mutual funds. With respect to shares of an open-end company as defined in section 5(a)(1) of the Investment Company Act of 1940 (15 U.S.C. 80a-5(a)(1)) (“mutual fund”), you may use the mutual fund's transfer agent in lieu of a qualified custodian for purposes of complying with paragraph (a) of this section.

(2) Certain privately offered securities. (i) You are not required to comply with paragraph (a)(1) of this section with respect to securities that are:

(A) Acquired from the issuer in a transaction or chain of transactions not involving any public offering;

(B) Uncertificated, and ownership thereof is recorded only on the books of the issuer or its transfer agent in the name of the client; and

(C) Transferable only with prior consent of the issuer or holders of the outstanding securities of the issuer.

(ii) Notwithstanding paragraph (b)(2)(i) of this section, the provisions of this paragraph (b)(2) are available with respect to securities held for the account of a limited partnership (or a limited liability company, or other type of pooled investment vehicle) only if the limited partnership is audited, and the audited financial statements are distributed, as described in paragraph (b)(4) of this section.

(3) Fee deduction. Notwithstanding paragraph (a)(4) of this section, you are not required to obtain an independent verification of client funds and securities maintained by a qualified custodian if:

(i) you have custody of the funds and securities solely as a consequence of your authority to make withdrawals from client accounts to pay your advisory fee; and

(ii) if the qualified custodian is a related person, you can rely on paragraph (b)(6) of this section.

(4) Pooled investment vehicles subject to annual audit. (i) You are not required to comply with paragraphs (a)(2) and (a)(3) of this section and you shall be deemed to have complied with paragraph (a)(4) of this section with respect to the account of a limited partnership (or limited liability company, or another type of pooled investment vehicle) that undergoes a financial statement audit at least annually and upon liquidation as follows:

(A) The audit meets the definition in rule 1-02(d) of Regulation S-X (17 CFR 210.1-02(d)) and is performed by an independent public accountant;

(B) Audited financial statements are prepared in accordance with U.S. Generally Accepted Accounting Principles (“U.S. GAAP”) or, in the case of financial statements of pooled investment vehicles organized under non-U.S. law or that have a general partner or other manager with a principal place of business outside the United States, such financial statements may be prepared according to accounting principles other than U.S. GAAP provided they contain information substantially similar to the information contained in financial statements prepared in accordance with U.S. GAAP, including a reconciliation to U.S. GAAP for material differences; and

(C) Within 120 days (or 180 days in the case of a fund of funds or 260 days in the case of a fund of funds of funds) of a pooled investment vehicle's fiscal year end, and promptly following its liquidation, the pooled investment vehicle's audited financial statements are distributed to the investors in the pooled investment vehicle (or their independent representatives), including any reconciliations to U.S. GAAP (which are required to be distributed to the U.S. investors in the pooled investment vehicle (or their independent representatives)).

(ii) Notwithstanding paragraph (b)(4)(i)(C), for a pooled investment vehicle that is formed within the 90 day period prior to the pooled investment vehicle's fiscal year end, the pooled investment vehicle's audited financial statements shall not be required to be distributed to investors in the pooled investment vehicle (or their independent representatives) within 120 days of the pooled investment vehicle's fiscal year end for the first fiscal year of the pooled investment vehicle, provided that (A) financial statements (which may be unaudited) are distributed to investors in the pooled investment vehicle (or their independent representatives) within 90 days of the pooled investment vehicle's fiscal year end and (B) the audited financial statements related to the following fiscal year are distributed pursuant to paragraph (b)(4)(i) and cover both that fiscal year and the unaudited period of the prior fiscal year.

(5) Registered investment companies and business development companies. Except with respect to crypto assets of which you have self-custody, you are not required to comply with this section (17 CFR 275.223-1) with respect to the account of a registered investment company or the account of a business development company. If you have self-custody of crypto assets that are securities or similar investments for the account of a registered investment company or a business development company, you are only required to satisfy the requirements of paragraph (b)(7) of this section with respect to such crypto assets.

(6) Certain Related Persons. Notwithstanding paragraph (a)(4) of this section, you are not required to obtain an independent verification of client funds and securities if:

(i) you have custody under this rule solely because a related person holds, directly or indirectly, client funds or securities, or has any authority to obtain possession of them, in connection with advisory services you provide to clients; and

(ii) your related person is operationally independent of you.

(7) Crypto Assets. If you have self-custody of client crypto assets for which you provide investment advice, you are not required to comply with paragraphs (a)(1), (a)(2) and (a)(3) of this section with respect to such crypto assets, and you must self-custody such crypto assets in accordance with this paragraph (b)(7) as follows:

(i) Qualified Custodian Determination. Prior to taking self-custody of each crypto asset, and no less frequently than quarterly thereafter with respect to crypto assets in your self-custody, you must determine in writing ( printed page 64084) that you have a reasonable basis, after due inquiry, for believing that no qualified custodian will maintain the crypto asset. For purposes of any qualified custodian determination made under this paragraph with respect to the account of a registered investment company or a business development company, qualified custodian shall be understood to refer to a bank or other person authorized to hold assets for the registered investment company or business development company under section 17(f) of the Investment Company Act (15 U.S.C. 80a-17(f)) or the rules thereunder. If you determine that a qualified custodian has become available to maintain the client's crypto asset, you must place such crypto asset with the qualified custodian as soon as reasonably practicable.

(ii) Safeguarding Expertise and Systems. You must have expertise regarding the safeguarding of each crypto asset, and document in writing the basis for your determination that you have such safeguarding expertise, and adopt, implement, and maintain the systems, including the appropriate technology, software, hardware, and other associated systems and processes around their use, necessary to safeguard each crypto asset against loss, theft, misuse and misappropriation. Such systems at a minimum must:

(A) Key management. Manage and protect key materials against loss and unauthorized access, including by limiting access to key materials to only persons that are supervised persons designated by the adviser, provided that with respect to crypto assets held for an account of a registered investment company or a business development company, such supervised persons shall be designated by resolution of the board of directors of such registered investment company or business development company;

(B) Joint Authorization. Prevent unauthorized transfers of crypto assets including by requiring joint authorization of transfers of crypto assets by two or more persons designated pursuant to paragraph (b)(7)(ii)(A), at least one of which shall be a management person and, in the case of crypto assets held for an account of a registered investment company or a business development company, such management person shall be an officer of such registered investment company or business development company;

(C) Segregation. Maintain each client's crypto assets in one or more crypto asset addresses on the crypto network storing only such client's crypto assets.

(iii) Cybersecurity. You must mitigate any cybersecurity risks to the safeguarding of each crypto asset of which you have self-custody, including by implementing:

(A) periodic but no less than annual written assessments of cybersecurity risks to crypto assets in the adviser's self-custody and cybersecurity risks associated with the safeguarding systems implemented pursuant to paragraph (b)(7)(ii);

(B) measures reasonably designed to detect, mitigate and remediate any cybersecurity threats and vulnerabilities with respect to the safeguarding systems implemented pursuant to paragraph (b)(7)(ii); and

(C) measures reasonably designed to detect, respond to, and recover from a cybersecurity incident relating to your safeguarding systems implemented pursuant to paragraph (b)(7)(ii).

(iv) Internal control report. You must obtain within six months of taking self-custody of a client crypto asset and thereafter no less frequently than once each calendar year a written internal control report prepared by an independent public accountant:

(A) The internal control report must include an opinion of an independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of crypto assets held by you on behalf of your advisory clients; and

(B) the independent public accountant must verify that the crypto assets are reconciled to the crypto network;

(v) Annual review. Within a year of taking self-custody of each crypto asset and no less frequently than annually thereafter, you must review, and document in writing your review of, the following including the effectiveness of their implementation: (A) the safeguarding systems implemented pursuant to paragraph (b)(7)(ii), and (B) the cybersecurity controls implemented pursuant to paragraph (b)(7)(iii).

(vi) Account statements or transmissions. Account statements must be provided, at least quarterly, to each of your clients whose crypto assets you have self-custody of, identifying the crypto asset address on the crypto network that stores the client's crypto assets and the crypto network on which such crypto asset address operates, the amounts of crypto assets stored in the client's crypto asset address at the end of the period and setting forth all transactions from that crypto asset address during that period, and a statement urging the client to compare the account statements from the adviser with the crypto asset balances and transaction information indicated under the client's crypto asset address. You may satisfy the requirement to send an account statement under this paragraph by transmitting, or arranging for the transmission, of the information required under this paragraph (b)(7)(vi) in a human-readable and reasonably usable electronic format, at least quarterly in lieu of a consolidated account statement, provided that a notice is sent to the client identifying the crypto asset address that stores the client's crypto assets and the crypto network on which such crypto asset address operates. If you are, or a related person is, a general partner of a limited partnership (or managing member of a limited liability company, or hold a comparable position for another type of pooled investment vehicle), the account statements, transmissions and any notices required under this paragraph must be sent to each limited partner (or member or other beneficial owner).

(vii) Pooled investment vehicles with crypto assets. You are not required to comply with paragraph (b)(7)(vi) of this section with respect to the account of a limited partnership (or limited liability company, or another type of pooled investment vehicle) that undergoes a financial statement audit at least annually and upon liquidation in accordance with paragraphs (b)(4)(i) through (b)(4)(ii) of this section, or with respect to the account of any registered investment company or business development company.

(viii) Financial asset election. You and the client must agree, in writing, to treat each crypto asset held in your self-custody for such client as a financial asset, and that the adviser holding the client's crypto asset in self-custody is a securities intermediary, pursuant to applicable State law that governs the written agreement between you and the client.

(8) Standing letters of authorization. Notwithstanding paragraph (a)(4) of this section, you are not required to obtain an independent verification of client assets if you have custody of client assets solely because of a standing letter of authorization.

(9) Discretionary trading authority. You are not required to comply with this section (17 CFR 275.223-1) with respect to funds and securities over which you have custody due to your authority to trade at your discretion provided that:

(i) you execute (and only have authority to execute) such trades only from and into designated client ( printed page 64085) accounts in the client's name or the transfer is recorded in the client's name by the issuer;

(ii) you have no authority (under the discretionary trading arrangement or otherwise) to transfer client funds and securities from the designated client account to an account in your own name, to an account you control, to an account controlled by your related person as defined in rule 223-1(d)(15), or to any account that is not the client's unless such transfer is directed by the client in connection with such trading, nor do you have the authority to have the transfer recorded by the issuer in your own name or that of a related person; and

(iii) you comply with this section for any other activities, rights, or authorities that otherwise cause you to have custody of such funds or securities separate from such discretionary trading authority and with the requirements of any corresponding exceptions under this section that you may exercise pursuant to such custody.

(10) Inadvertent Custody. You are not required to comply with this section (17 CFR 275.223-1) with respect to funds and securities over which you have custody solely to the extent such custody arises from custodial agreements under which:

(i) you did not recommend, request, or require that the client select the qualified custodian maintaining such funds and securities; and

(ii) either (A) you do not have a copy of the client's custodial agreement, nor actual knowledge or reason to know that any custodial agreement between the client and such qualified custodian confers custody upon you; or (B) if you know or have reason to know that a custodial agreement confers custody on you, you promptly notify the client and qualified custodian in writing of such unwanted authority and repudiate such authority to the client and qualified custodian and request in writing that such authority be removed from the custodial agreement or be superseded by a new agreement, consented to by both the client and the qualified custodian, that does not confer custody on you.

(11) Distributed crypto assets. The receipt of a distributed crypto asset will be deemed to not be in violation of this section, provided that, as soon as reasonably practicable, you either (A) come into compliance with the requirements of paragraph (b)(7) of this section with respect to such distributed crypto asset; or (B) place and maintain the distributed crypto asset with a qualified custodian.

(c) Delivery to Related Person. Sending an account statement under paragraphs (a)(5) and any account statement, transmissions and notices required under paragraph (b)(7)(vi) of this section or distributing audited financial statements under paragraph (b)(4) of this section (or distributing financial statements under paragraph (b)(4)(ii) of this section) shall not satisfy the requirements of this section if such account statements or financial statements are sent solely to limited partners (or members or other beneficial owners) that themselves are limited partnerships (or limited liability companies, or another type of pooled investment vehicle) and are your related persons.

(d) Definitions. For the purposes of this section:

(1) Business development company means an entity that has elected to be regulated or is regulated as a business development company pursuant to section 54 of the Investment Company Act of 1940 (15 U.S.C. 80a-53) and has not withdrawn the election.

(2) Control means the power, directly or indirectly, to direct the management or policies of a person, whether through ownership of securities, by contract, or otherwise. Control includes:

(i) Each of your firm's officers, partners, or directors exercising executive responsibility (or persons having similar status or functions) is presumed to control your firm;

(ii) A person is presumed to control a corporation if the person:

(A) Directly or indirectly has the right to vote 25 percent or more of a class of the corporation's voting securities; or

(B) Has the power to sell or direct the sale of 25 percent or more of a class of the corporation's voting securities;

(iii) A person is presumed to control a partnership if the person has the right to receive upon dissolution, or has contributed, 25 percent or more of the capital of the partnership;

(iv) A person is presumed to control a limited liability company if the person:

(A) Directly or indirectly has the right to vote 25 percent or more of a class of the interests of the limited liability company;

(B) Has the right to receive upon dissolution, or has contributed, 25 percent or more of the capital of the limited liability company; or

(C) Is an elected manager of the limited liability company; or

(v) A person is presumed to control a trust if the person is a trustee or managing agent of the trust.

(3) Crypto asset means any digital representation of value that is recorded on a cryptographically secured distributed ledger.

(4) Crypto asset address means the unique identifier on the crypto network that designates the destination for sending, receiving, and storing a crypto asset on the crypto network.

(5) Crypto network means a blockchain or similar distributed ledger technology network.

(6) Custody means holding, directly or indirectly, client funds or securities, or having any authority to obtain possession of them. You have custody if a related person holds, directly or indirectly, client funds or securities, or has any authority to obtain possession of them, in connection with advisory services you provide to clients. Custody includes:

(i) Possession of client funds or securities (including possession of client crypto assets via self-custody) (but not of checks drawn by clients and made payable to third parties) unless you receive them inadvertently and you return them to the sender promptly but in any case within three business days of receiving them;

(ii) Any arrangement (including a general power of attorney) under which you are authorized or permitted to withdraw client funds or securities maintained with a custodian upon your instruction to the custodian; and

(iii) Any capacity (such as general partner of a limited partnership, managing member of a limited liability company or a comparable position for another type of pooled investment vehicle, or trustee of a trust) that gives you or your supervised person legal ownership of or access to client funds or securities.

(7) Distributed crypto asset means a crypto asset received as a distribution for no or nominal consideration in connection, or as a result of activity associated, with a client's crypto asset in your custody.

(8) Independent public accountant means a public accountant that meets the standards of independence described in rule 2-01(b) and (c) of Regulation S-X (17 CFR 210.2-01(b) and (c)).

(9) Independent representative means a person that:

(i) Acts as agent for an advisory client, including in the case of a pooled investment vehicle, for limited partners of a limited partnership (or members of a limited liability company, or other beneficial owners of another type of pooled investment vehicle) and by law or contract is obliged to act in the best interest of the advisory client or the limited partners (or members, or other beneficial owners); ( printed page 64086)

(ii) Does not control, is not controlled by, and is not under common control with you; and

(iii) Does not have, and has not had within the past two years, a material business relationship with you.

(10) Key materials means the cryptographic private keys or any part thereof that is necessary to access and effectuate transactions in the corresponding crypto asset.

(11) Management persons has the same meaning as set forth in Form ADV, Glossary of Terms.

(12) Operationally independent: for purposes of paragraph (b)(6) of this section, a related person is presumed not to be operationally independent unless each of the following conditions is met and no other circumstances can reasonably be expected to compromise the operational independence of the related person: (i) client assets in the custody of the related person are not subject to claims of the adviser's creditors; (ii) advisory personnel do not have custody or possession of, or direct or indirect access to client assets of which the related person has custody, or the power to control the disposition of such client assets to third parties for the benefit of the adviser or its related persons, or otherwise have the opportunity to misappropriate such client assets; (iii) advisory personnel and personnel of the related person who have access to advisory client assets are not under common supervision; and (iv) advisory personnel do not hold any position with the related person or share premises with the related person.

(13) Qualified custodian means:

(i) A bank as defined in section 202(a)(2) of the Advisers Act (15 U.S.C. 80b-2(a)(2)) or a savings association as defined in section 3(b)(1) of the Federal Deposit Insurance Act (12 U.S.C. 1813(b)(1)) that has deposits insured by the Federal Deposit Insurance Corporation under the Federal Deposit Insurance Act (12 U.S.C. 1811);

(ii) A broker-dealer registered under section 15(b)(1) of the Securities Exchange Act of 1934 (15 U.S.C. 78o(b)(1)), holding the client assets in customer accounts;

(iii) A futures commission merchant registered under section 4f(a) of the Commodity Exchange Act (7 U.S.C. 6f(a)), holding the client assets in customer accounts, but only with respect to clients' funds and security futures, or other securities incidental to transactions in contracts for the purchase or sale of a commodity for future delivery and options thereon;

(iv) A foreign financial institution that customarily holds financial assets for its customers, provided that the foreign financial institution keeps the advisory clients' assets in customer accounts segregated from its proprietary assets;

(v) A state trust company, but only with respect to the clients' crypto assets and related cash and/or cash equivalents, provided that the following conditions are met. An adviser may rely on section 223-1(d)(13)(i), in lieu of this section, to place and maintain client crypto assets and related cash and/or cash equivalents with a state trust company that is a bank as defined in section 202(a)(2) of the Advisers Act (15 U.S.C. 80b-2(a)(2)) or a savings association as defined in section 3(b)(1) of the Federal Deposit Insurance Act (12 U.S.C. 1813(b)(1)) that has deposits insured by the Federal Deposit Insurance Corporation under the Federal Deposit Insurance Act (12 U.S.C. 1811). Prior to engaging a state trust company as a qualified custodian and on an annual basis thereafter, the adviser must:

(A) Determine in writing that it has a reasonable basis, after due inquiry, for believing that the state trust company:

1. Is authorized by the relevant state banking authority to provide custody services for crypto assets and related cash and cash equivalents; and

2. Maintains and implements written policies and procedures reasonably designed to safeguard crypto assets and related cash and/or cash equivalents from the risk of theft, loss, misuse, and misappropriation, with such policies and procedures addressing, at a minimum, private key management and cybersecurity; and

(B) Receive and review the state trust company's most recent annual financial statements and confirm that such financial statements are prepared in accordance with U.S. GAAP and are subject to an audit (as defined in rule 1-02(d) of Regulation S-X (17 CFR 210.1-02(d))) that is performed by an independent public accountant; and

(C) Receive and review the state trust company's most recent written internal control report prepared by an independent public accountant during the current or prior calendar year and confirm that such internal control report contains an opinion of such independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of client crypto assets and related cash and/or cash equivalents.

(14) Registered investment company means an investment company registered under the Investment Company Act of 1940 (15 U.S.C. 80a-1 to 80a-64).

(15) Related person means any person, directly or indirectly, controlling or controlled by you, and any person that is under common control with you.

(16) Self-custody means, with respect to crypto assets, possession of any portion of a client crypto asset's key materials, provided that you do not have self-custody of a crypto asset if you possess, or a related person possesses, key materials associated with the crypto asset solely in your or your related person's capacity as a qualified custodian maintaining the crypto asset under paragraph (a)(6) of this section.

(17) Standing letter of authorization means an arrangement among you, the client, and the client's qualified custodian in which you are authorized, in writing, to direct the qualified custodian to transfer funds and securities to a third-party recipient on a specified schedule or from time to time, provided:

(i) The client's qualified custodian is not you or your related person;

(ii) The client's authorization includes the client's signature, the third-party recipient's name, and either the third party recipient's address or account number at a custodian to which the transfer should be directed; and

(iii) You have no ability or authority to designate or change any information about the third-party recipient, including name, address, and account number.

(18) State trust company means a legal entity organized under state law that is supervised and examined by a state authority having supervision over banks and permitted to exercise fiduciary powers under applicable state law.

(19) U.S. Generally Accepted Accounting Principles (U.S. GAAP) means accounting principles promulgated, or recognized by the Commission as generally accepted, in accordance with section 19 of the Securities Act of 1933 (15 U.S.C. 77s).

* * * * *

PART 279—FORMS PRESCRIBED UNDER THE INVESTMENT ADVISERS ACT OF 1940

25. The authority citation for part 279 continues to read as follows:

Authority: The Investment Advisers Act of 1940, 15 U.S.C. 80b-1, et seq.,Pub. L. 111-203, 124 Stat. 1376.

26. Amend Form ADV (referenced in § 279.1) by:

a. In Part 1A, adding Item 5.K.(5); ( printed page 64087)

b. In Part 1A, revising Items 7.A. and 9;

c. In Schedule D, revising sections 7.B(1) and 9.C;

d. In General Instructions for Part 1 of Form ADV, adding the defined terms “crypto asset” and “self-custody” and revising the definitions of “custody” and “related person.”

e. In General Instructions for Part 2 of Form ADV, revising Instruction to Item 18.A.

Note: Form ADV is attached as Appendix B to this document. Form ADV will not appear in the Code of Federal Regulations.

27. Amend Form ADV-E (referenced in § 279.1) by:

a. In the sub-heading to Form ADV-E (beginning “Certificate of Accounting of Client Securities . . .”), revising the reference to “rule 206(4)-2 [ 17 CFR 275.206(4)-2]” to read “rule 223-1 [17 CFR 275.223-1]”

b. In Instructions 2 and 3, revising references to “rule 206(4)-2” to read “rule 223-1”;

c. In the paragraph with the heading “SEC's Collection of Information,” revising references to “rule 206(4)-2(a)(4)(i)” to read “rule 223-1(a)(4)(i)”.

d. In the paragraph with the heading “SEC's Collection of Information,” revising reference to “Adviser Act” to read “Advisers Act”.

Note: Form ADV-E is attached as Appendix C to this document. Form ADV-E will not appear in the Code of Federal Regulations.

By the Commission.

Dated: October 1, 2026.

Vanessa A. Countryman,

Secretary.

Note: The following appendices will not appear in the Code of Federal Regulations.

( printed page 64088)

( printed page 64089)

( printed page 64090)

( printed page 64091)

( printed page 64092)

( printed page 64093)

( printed page 64094)

( printed page 64095)

( printed page 64096)

( printed page 64097)

( printed page 64098)

( printed page 64099)

( printed page 64100)

( printed page 64101)

( printed page 64102)

( printed page 64103)

Footnotes

1.  Unless otherwise noted, when we refer to the Investment Company Act, we are referring to 15 U.S.C. 80a, and when we refer to rules under the Investment Company Act, we are referring to title 17, part 270 of the Code of Federal Regulations [17 CFR 270].

Back to Citation

2.  Unless otherwise noted, when we refer to the Advisers Act, we are referring to 15 U.S.C. 80b, and when we refer to rules under the Advisers Act, we are referring to title 17, part 275 of the Code of Federal Regulations [17 CFR 275].

Back to Citation

3.  Given the very limited universe of face-amount certificate companies (“FACCs”) and their particular regulatory requirements, the proposed rules related to regulated fund self-custody of crypto assets and custody of crypto assets by State trust companies (as proposed to be defined in proposed rule 17f-8) would not be applicable to FACCs. See 15 U.S.C. 80a-28(b). See also proposed rules 17f-8 and 17f-9. A FACC may apply for an order under section 28(c) of the Investment Company Act if they wish to hold crypto assets in the manner discussed in this release. Unit investment trusts (“UITs”) would similarly not be able to rely on the proposed rules related to regulated fund self-custody of crypto assets and custody of crypto assets by State trust companies. Given that UITs lack investment advisers and are unmanaged, it would not be possible for them to comply with certain aspects of the proposed rules.

Back to Citation

4.  15 U.S.C. 80a-17(f). See also17 CFR 270.17f-1 (rule 17f-1) (custody with members of national securities exchanges); 17 CFR 270.17f-2 (rule 17f-2) (custody with the regulated fund); 17 CFR 270.17f-4 (rule 17f-4) (custody with a securities depository); 17 CFR 270.17f-5 (rule 17f-5) (custody of assets outside the U.S. with a foreign bank custodian); 17 CFR 270.17f-6 (rule 17f-6) (custody with a futures commission merchant or commodity clearing organization); 17 CFR 270.17f-7 (rule 17f-7) (custody with a foreign securities depository).

Back to Citation

6.  As used in this release, all references to registered investment advisers refer to SEC-registered investment advisers or investment advisers required to be SEC-registered, unless otherwise indicated.

Back to Citation

7.   See Custody or Possession of Funds or Securities of Clients, Advisers Act Release No. 123 (Feb. 27, 1962) [27 FR 2149 (Mar. 6, 1962)] (“1962 Adopting Release”). See also Custody of Funds or Securities of Clients by Investment Advisers, Advisers Act Release No. 2176 (Sept. 25, 2003) [68 FR 56692 (Oct. 1, 2003)] (“2003 Adopting Release”); Custody of Funds or Securities of Clients by Investment Advisers, Advisers Act Release No. 2968 (Dec. 30, 2009) [75 FR 1456 (Jan. 11, 2010)] (“2009 Adopting Release”). In 2023, the Commission proposed, but did not adopt, a new rule under the Advisers Act that would have redesignated and amended the Advisers Act custody rule. See Safeguarding Advisory Client Assets, Advisers Act Release No. 6240 (Feb. 15, 2023) [88 FR 14672 (Mar. 9, 2023)] (“2023 Safeguarding Proposal”). The Commission formally withdrew the 2023 Safeguarding Proposal on June 12, 2025. See Withdrawal of Proposed Regulatory Actions, Advisers Act Release No. 6885 (June 12, 2025) [90 FR 25531 (June 17, 2025)].

Back to Citation

8.  The scope of investments subject to the custody rule under the Advisers Act custody rule differs from the scope under the Investment Company Act custody rules. The Advisers Act custody rule only applies to custody of client funds or securities, while the Investment Company Act custody rules apply to a regulated fund's securities and similar investments. See rule 206(4)-2(a) and section 17(f)(1).

Back to Citation

9.   See rule 206(4)-2(d)(2) (defining “custody” for purposes of the Advisers Act custody rule).

Back to Citation

10.   See rule 206(4)-2(d)(6) (defining “qualified custodian” for purposes of the Advisers Act custody rule).

Back to Citation

11.   See 1962 Adopting Release, supra footnote 7; see also Custody of Funds or Securities of Clients by Investment Advisers, Advisers Act Release No. 2044 (July 18, 2002) [67 FR 48579 (July 25, 2002)], at nn.3-4 and accompanying text.

Back to Citation

12.   See Investment Trusts and Investment Companies: Hearings on S. 3580 Before a Subcomm. of the Senate Comm. on Banking and Currency, 76th Cong., 3d Sess. 264 (1940). Cf. 10 SEC ANN.REP. 169 (1994) (discussing section 17(f) of the Investment Company Act and its protections against theft and embezzlement by affiliated persons).

Back to Citation

13.   See infra section I.A.1 for discussion of development and growth of crypto asset market, including the definition of “crypto asset” as used herein.

Back to Citation

14.   See infra section I.A.2 for discussion of challenges presented by crypto assets to the existing custodial framework.

Back to Citation

15.   See SEC Press Release, SEC Crypto 2.0: Acting Chairman Uyeda Announces Formation of New Crypto Task Force, Press Release No. 2025-30 (Jan. 21, 2025), available at www.sec.gov/​newsroom/​press-releases/​2025-30. See also SEC, Crypto Task Force Designation Letter from Acting Chairman Mark T. Uyeda (Feb. 4, 2025), available at www.sec.gov/​files/​crypto-task-force-designation-letter.pdf. See also SEC, Crypto Task Force, available at www.sec.gov/​about/​crypto-task-force.

Back to Citation

16.   See SEC, Crypto Task Force Roundtables, available at www.sec.gov/​about/​crypto-task-force/​crypto-task-force-roundtables. See also Statement of Commissioner Hester Peirce, There Must Be Some Way Out of Here (Feb. 21, 2025), available at www.sec.gov/​newsroom/​speeches-statements/​peirce-statement-rfi-022125; SEC, Crypto Task Force Written Input, available at www.sec.gov/​about/​crypto-task-force/​crypto-task-force-written-input; SEC, Crypto Task Force Meetings, available at www.sec.gov/​about/​crypto-task-force/​crypto-task-force-meetings.

Back to Citation

17.   See SEC, Crypto Task Force Roundtable—Know Your Custodian: Key Considerations for Crypto Custody (Apr. 25, 2025), available at www.sec.gov/​newsroom/​meetings-events/​know-your-custodian-key-considerations-crypto-custody. The written input letters submitted to the Commission's Crypto Task Force are available at www.sec.gov/​about/​crypto-task-force/​crypto-task-force-written-input. Unless otherwise specified, all references in this release to comment letters are to the written input letters submitted to the Crypto Task Force.

Back to Citation

18.   See Exec. Order No. 14178, Strengthening American Leadership in Digital Financial Technology (Jan. 23, 2025) [90 FR 8647 (Jan. 31, 2025)] (“Executive Order 14178”).

Back to Citation

19.   See id. at § 4.

Back to Citation

20.   See id. at § 4(c)(i).

Back to Citation

21.   See Digital Assets PWG, Strengthening American Leadership in Digital Financial Technology (July 30, 2025), available at www.whitehouse.gov/​wp-content/​uploads/​2025/​07/​Digital-Assets-Report-EO14178.pdf.

Back to Citation

22.   See id., at 52. The Digital Assets PWG Report also recommended that the Commission evaluate whether certain State-chartered trusts should be deemed a `qualified custodian' under the Advisers Act custody rule or a `bank' under the Investment Company Act.

Back to Citation

23.   See Statement of Chairman Paul S. Atkins, American Leadership in the Digital Finance Revolution (July 31, 2025), available at www.sec.gov/​newsroom/​speeches-statements/​atkins-digital-finance-revolution-073125.

Back to Citation

24.   See Application of the Federal Securities Laws to Certain Types of Crypto Assets and Certain Transactions Involving Crypto Assets, Securities Act Release No. 11412 (Mar. 17, 2026) [91 FR 13714 (Mar. 23, 2026)] (“Commission Security Status Interpretation”), at n.1.

Back to Citation

25.   See section 2(6) of the Guiding and Establishing National Innovation for U.S. Stablecoins Act, Public Law 119-27, 139 Stat. 419 (2025) (“GENIUS Act”).

Back to Citation

26.   See section 2(8) of the GENIUS Act.

Back to Citation

27.   See, e.g., U.S. Securities and Exchange Commission, Division of Corporation Finance, Statement on Certain Protocol Staking Activities (May 29, 2025) (“Protocol Staking Statement”), available at www.sec.gov/​newsroom/​speeches-statements/​statement-certain-protocol-staking-activities-052925; U.S. Securities and Exchange Commission, Division of Corporation Finance, Statement on Certain Liquid Staking Activities (Aug. 5, 2025) (“Liquid Staking Statement”), available at www.sec.gov/​newsroom/​speeches-statements/​corpfin-certain-liquid-staking-activities-080525. Staff reports, statistics, and other staff documents (including those cited herein) represent the views of Commission staff and are not a rule, regulation, or statement of the Commission. Furthermore, the Commission has neither approved nor disapproved these documents and, like all staff statements, they have no legal force or effect, do not alter or amend applicable law, and create no new or additional obligations for any person.

Back to Citation

28.   See, e.g., Tuongvy Le and Austin Campbell, Crypto and the Evolution of the Capital Markets (May 12, 2025), available at papers.ssrn.com/​sol3/​papers.cfm?​abstract_​id=​5250986.

Back to Citation

29.   See Gemini, What Are Privacy Tokens (Nov. 7, 2024), available at www.gemini.com/​cryptopedia/​what-are-privacy-tokens.

Back to Citation

30.   See Commission Security Status Interpretation, supra footnote 24, at section III.E; see also Comment Letter to Crypto Task Force of Securitize Inc. (May 7, 2025); Comment Letter to Crypto Task Force of Robinhood Markets, Inc. and Robinhood Crypto (Apr. 25, 2025).

Back to Citation

31.   See Satoshi Nakamoto, Bitcoin: A Peer-to-Peer Electronic Cash System (Oct. 31, 2008), available at bitcoin.org/​bitcoin.pdf.

Back to Citation

32.   See CoinGecko, Global Cryptocurrency Market Cap Charts, available at www.coingecko.com/​en/​charts (last visited May 20, 2026); see also Darren Aiello, Scott R. Baker, et. al., The Effects of Cryptocurrency Wealth on Household Consumption and Investment (Feb. 9, 2024), available at www.fdic.gov/​system/​files/​2024-07/​johnson-paper.pdf.

Back to Citation

33.   See U.S. Securities and Exchange Commission, Office of the Investor Advocate (“OIAD”), Experiences with Crypto Assets in the U.S. Population, OIAD Working Paper 2026 No. 4 (July 2026), available at www.sec.gov/​files/​experiences-crypto-assets-us-population.pdf (“OIAD Report I”) (finding that 9.2% of adults in the U.S. hold crypto assets based on July 2025 survey results)]; see also Board of Governors of the Federal Reserve System (the “Federal Reserve Board”), Economic Well-Being of U.S. Households in 2025 (May 13, 2026), available at www.federalreserve.gov/​publications/​files/​2025-report-economic-well-being-us-households-202605.pdf (stating that, as of 2025, approximately one in ten U.S. adults bought or held cryptocurrencies for investment purposes in the prior 12 months).

Back to Citation

34.   See U.S. Securities and Exchange Commission, OIAD, Cryptocurrency Owners in the U.S. Population, OIAD Working Paper 2026 No. 3 (July 2026), available at www.sec.gov/​files/​cryptocurrency-owners-findings-us-population.pdf (“OIAD Report II”).

Back to Citation

35.   See,e.g., Gemini, Global State of Crypto 2025, 2025 Trends Data-Driven Insights Into the Crypto Market, available at www.gemini.com/​state-of-crypto-2025 (the “Gemini Global State of Crypto 2025”); Gemini, State of U.S. Crypto 2021, available at www.gemini.com/​gemini-2021-state-of-crypto-us.pdf (the “Gemini Global State of Crypto 2021”); see also Chris Wheat & George Eckerd, JPMorgan Chase, Crypto investor waves since 2017: What retail investor behavior reveals about digital asset adoption (Aug. 27, 2025), available at www.jpmorganchase.com/​institute/​all-topics/​financial-health-wealth-creation/​crypto-investor-waves-since-2017-what-retail-investor-behavior-reveals-about-digital-asset-adoption (finding 17% of customer accounts were invested in crypto assets from Jan. 2017 to May 2025).

Back to Citation

36.   See rule 206(4)-2(d)(6).

Back to Citation

37.   See section 17(f) and rules 17f-1 through 17f-7.

Back to Citation

38.   See, e.g., Comment Letter to Crypto Task Force of The Digital Chamber (May 12, 2025) (“TDC Comment Letter I”); Comment Letter to Crypto Task Force of Neel Maitra, Dechert LLP (Apr. 15, 2025) (“Dechert Comment Letter”); s ee also The Future of Digital Assets: Identifying the Regulatory Gaps in Digital Asset Market Structure, Hearing Before the Subcomm. on Digit. Assets, Fin. Tech., and Inclusion of the H. Comm. on Fin. Servs., 118th Cong. (2023), available at www.congress.gov/​event/​118th-congress/​house-event/​115821/​text.

Back to Citation

39.   See Division of Trading and Markets and FINRA, Joint Staff Statement on Broker-Dealer Custody of Digital Asset Securities (July 8, 2019), available at www.sec.gov/​newsroom/​speeches-statements/​joint-staff-statement-broker-dealer-custody-digital-asset-securities-joint-staff-statement-broker-dealer-custody-digital-asset-securities-withdrawn-may-15-2025 (the “2019 FINRA Joint Statement”). The 2019 FINRA Joint Statement was withdrawn on May 15, 2025. See Division of Trading and Markets, SEC, Office of General Counsel, FINRA, Withdrawal of Joint Staff Statement on Broker-Dealer Custody of Digital Asset Securities (May 15, 2025), available at www.sec.gov/​newsroom/​speeches-statements/​withdrawal-joint-staff-statement-broker-dealer-custody-digital-asset-securities.

Back to Citation

40.   See Custody of Digital Asset Securities by Special Purpose Broker-Dealers, Exchange Act Release No. 90788 (Dec. 23, 2020) [86 FR 11627 (Feb. 26, 2021)]. This statement was limited to the custody of digital asset securities and did not address the custody of crypto assets that are not offered or sold as securities.

Back to Citation

41.   See, e.g., Comment Letter to Crypto Task Force of Coinbase Global, Inc. (Mar. 19, 2025); Comment Letter to Crypto Task Force of Securities Industry and Financial Markets Association (May 9, 2025) (“SIFMA Comment Letter”); Comment Letter to Crypto Task Force of Blockchain Association (May 2, 2025).

Back to Citation

42.   See, e.g., Office of the Comptroller of the Currency (the “OCC”), Authority of a National Bank to Provide Cryptocurrency Custody Services for Customers, Interpretive Letter No. 1170 (July 22, 2020), available at www.occ.gov/​topics/​charters-and-licensing/​interpretations-and-decisions/​2020/​int1170.pdf; OCC, OCC Chief Counsel's Interpretation on National Bank and Federal Savings Authority to Hold Stablecoin Reserves, Interpretative Letter No. 1172 (Sept. 21, 2020), available at www.occ.gov/​topics/​charters-and-licensing/​interpretations-and-decisions/​2020/​int1172.pdf; OCC, OCC Chief Counsel's Interpretation on National Bank and Federal Savings Association Authority to Use Independent Node Verification Networks and Stablecoins for Payment Activities, Interpretative Letter No. 1174 (Jan. 4, 2021), available at www.occ.gov/​news-issuances/​news-releases/​2021/​nr-occ-2021-2a.pdf; Federal Reserve Board, Federal Deposit Insurance Corporation (the “FDIC”), and OCC, Joint Statement on Crypto-Asset Risks to Banking Organizations (Jan. 3, 2023), available at www.fdic.gov/​news/​press-releases/​2023/​pr23002a.pdf (withdrawn).

Back to Citation

43.   See OCC, Authority of a National Bank to Provide Cryptocurrency Custody Services for Customers, Interpretive Letter 1170 (July 22, 2020), available at www.occ.gov/​topics/​charters-and-licensing/​interpretations-and-actions/​2020/​int1170.pdf.

Back to Citation

44.   See OCC, Chief Counsel's Interpretation Clarifying: (1) Authority of a Bank to Engage in Certain Cryptocurrency Activities and (2) Authority of the OCC to Charter a National Trust Bank, Interpretive Letter 1179 (Nov. 18, 2021), available at www.occ.gov/​topics/​charters-and-licensing/​interpretations-and-actions/​2021/​int1179.pdf (rescinded) (“OCC Interpretative Letter 1179”); see also OCC, Letter Addressing Certain Crypto-Asset Activities, Interpretive Letter No. 1183 (Mar. 7, 2025), available at www.occ.treas.gov/​topics/​charters-and-licensing/​interpretations-and-decisions/​2025/​int1183.pdf (“OCC Interpretative Letter 1183”) (rescinding Interpretative Letter 1179); OCC, Clarification of Bank Authority Regarding Crypto-Asset Custody Services, Interpretive Letter 1184 (May 7, 2025), available at www.occ.gov/​topics/​charters-and-licensing/​interpretations-and-actions/​2025/​int1184.pdf (“OCC Interpretative Letter 1184”) (confirming, in relevant part, that national banks and Federal savings associations may buy and sell crypto assets held in custody at the customer's direction in a manner consistent with the customer agreement and applicable law). See Financial Stability Oversight Council, Report on Digital Asset Financial Stability Risks and Regulation 27 (2022), available at home.treasury.gov/​system/​files/​261/​FSOC-Digital-Assets-Report-2022.pdf, at 18 (stating “some banks have indicated publicly that they have interest in offering crypto-asset products and services but are waiting on regulatory clarity before doing so.”).

Back to Citation

45.   See Staff Accounting Bulletin No. 121, Release No. SAB 121 (Mar. 31, 2022) (“SAB 121”).

Back to Citation

46.   See,e.g., Dechert Comment Letter; TDC Comment Letter I.

Back to Citation

47.   See Staff Accounting Bulletin No. 122, Release No. SAB 122 (Jan. 23, 2025) (rescinding SAB 121).

Back to Citation

48.   See, e.g., NY Banking Law, Article 3, § 102-a; Wyo. Stat. Ann. § 34-29-104; SDCL Chapter 51A-6A.

Back to Citation

49.  The OCC has since stated that custody and safekeeping activities are generally considered to be non-fiduciary activities of national banks. See OCC, National Bank Chartering, 91 FR 9977 (Mar. 2, 2026).

Back to Citation

50.   See Simpson Thacher & Bartlett LLP, SEC Staff No-Act. Letter (pub. avail. Sept. 30, 2025), available at www.sec.gov/​rules-regulations/​no-action-interpretive-exemptive-letters/​division-investment-management-staff-no-action-interpretive-letters/​simpsonthacherbartlett093025 (the “2025 State Trust Company NAL”).

Back to Citation

51.   See id. In addition to the custody rules, the 2025 State Trust Company NAL also addresses section 26(a) of the Investment Company Act.

Back to Citation

52.   See infra footnotes 877 through 879 and accompanying text.

Back to Citation

53.   See, e.g., Comment Letter to Crypto Task Force of Veda Tech Labs Inc. (Mar. 23, 2026); Comment Letter of Wave Digital Assets LLC Regarding Application of the Federal Securities Laws to Certain Types of Crypto Assets and Certain Transactions Involving Crypto Assets, File No. S7-2026-09 (Apr. 28, 2026), available at www.sec.gov/​comments/​S7-2026-09/​s7202609-764287-2345754_​0.pdf (“Wave Digital Assets Comment Letter”) (stating that crypto asset custodial infrastructure is “developing but incomplete”).

Back to Citation

54.   See,e.g., Comment Letter to Crypto Task Force of Unit 410, LLC (May 7, 2025) (“Unit 410 Comment Letter”).

Back to Citation

55.   See,e.g., Wave Digital Assets Comment Letter.

Back to Citation

56.  Rule 17f-2 provides that a fund's investments are deemed to be in the custody of the fund if directors, officers, or employees or agents of the fund are authorized or permitted to withdraw the investments from a bank (or certain other companies) “upon their mere receipt.” See rule 17f-2(a).

Back to Citation

57.   See rule 17f-2(b).

Back to Citation

58.   See,e.g., Comment Letter to Crypto Task Force of Kimber Labs Inc. (d/b/a Plume) (Apr. 23, 2026).

Back to Citation

59.  As discussed further below in section II.D, the Commission also considered, but is not proposing at this time, amendments to the custody rules related to crypto asset trading.

Back to Citation

60.  However, in such a circumstance, the adviser would not be limited in its ability to provide nondiscretionary investment advice to its client regarding investing in a particular crypto asset where the client then makes the investment on its own and not through the adviser.

Back to Citation

61.   See proposed rule 223-1(d)(3); see also infra section II.A.1.b) for discussion of the proposed adviser self-custody rule terms and definitions. See also proposed rules 17f-8 and 17f-9.

Back to Citation

62.  The proposed adviser self-custody rule under the Advisers Act is rule 223-1(b)(7). The proposed fund self-custody rule under the Investment Company Act is rule 17f-9.

Back to Citation

63.   See infra section II.A for discussion of the proposed definition of “self-custody” under the Advisers Act custody rule.

Back to Citation

64.   See,e.g., Comment Letter to Crypto Task Force of Alternative Investment Management Association (Mar. 25, 2025) (“AIMA Comment Letter”) (stating that “an exemption should allow investment advisers to engage in self-custody subject to certain conditions—such as maintaining written risk controls—if the investment adviser can document that no qualified custodian with appropriate capabilities exists for a particular asset”); Dechert Comment Letter (stating that allowing registered investment advisers to “self-custody crypto assets” would free them “from having to find qualified custodians at a time when very few crypto asset custodians clearly meet the Advisers Act's definition of a qualified custodian”); Comment Letter to Crypto Task Force of World Federation of Exchanges (Mar. 18, 2025) (“World Federation of Exchanges Comment Letter”) (describing “self-custody” as the owner directly holding the crypto asset, using a “personal digital wallet” and where “the owner is responsible for the safekeeping of their private keys”).

Back to Citation

65.  Proposed rule 223-1(b)(7)(i).

Back to Citation

66.  Proposed rule 223-1(b)(7)(ii).

Back to Citation

67.  Proposed rule 223-1(b)(7)(v).

Back to Citation

68.  Proposed rule 223-1(b)(7)(ii).

Back to Citation

69.  Proposed rule 223-1(b)(7)(iii).

Back to Citation

70.  Proposed rule 223-1(b)(7)(iv).

Back to Citation

71.  Proposed rule 223-1(b)(7)(vi).

Back to Citation

72.  Proposed rule 223-1(b)(7)(viii). State law governs the written contractual treatment of an asset as a financial asset and a party to the written agreement as a securities intermediary pursuant to the applicable State's enacted version of Article 8 of the Uniform Commercial Code (“UCC”).

Back to Citation

73.  Proposed rule 17f-9(b)(1)(ii).

Back to Citation

74.  Proposed rule 17f-9(b)(1)(i).

Back to Citation

75.  Proposed rule 223-1(b)(11); proposed rule 17f-9(c).

Back to Citation

76.  Proposed rule 204-2(a)(26); proposed rule 31a-2(a)(10).

Back to Citation

77.  The proposed State trust company rule under the Advisers Act is rule 223-1(d)(13)(v). The proposed Investment Company Act State trust company rule is rule 17f-8.

Back to Citation

78.  Proposed rule 223-1(d)(13)(v)(A)(1); proposed rule 17f-8(a)(1)(i).

Back to Citation

79.  Proposed rule 223-1(d)(13)(v)(A)(2); proposed rule 17f-8(a)(1)(ii).

Back to Citation

80.  Proposed rule 223-1(d)(13)(v)(B); proposed rule 17f-8(a)(2).

Back to Citation

81.  Proposed rule 223-1(d)(13)(v)(C); proposed rule 17f-8(a)(3).

Back to Citation

82.  Proposed rule 223-1(a)(1); proposed rule 17f-8(b).

Back to Citation

83.  Proposed rule 17f-8(b).

Back to Citation

84.  Proposed rule 204-2(a)(27); proposed rule 31a-2(a)(9).

Back to Citation

85.  Certain of these proposed amendments are also consistent with previously stated staff views.

Back to Citation

86.  See section 411 of the Dodd-Frank Wall Street Reform and Consumer Protection Act, Public Law 111-203, 124 Stat. 1376 (2010).

Back to Citation

87.  Proposed rule 223-1(b)(9).

Back to Citation

88.   See infra footnote 652. As used here, regulated fund would refer to all registered investment companies and BDCs and would include UITs and FACCs.

Back to Citation

89.   See Commission Guidance Regarding Independent Public Accountant Engagements Performed Pursuant to Rule 206(4)-2 Under the Investment Advisers Act of 1940, Advisers Act Release No. 2969 (Dec. 30, 2009) [75 FR 1492 (Jan. 11, 2010)] (the “2009 Guidance for Accountants”).

Back to Citation

90.  Unlike investment advisers registered with the SEC, which must complete all of Form ADV, exempt reporting advisers (“ERAs”) that are not also registering with any State securities authority only need to complete certain items of Form ADV, Part 1A (Items 1, 2, 3, 6, 7, 10, and 11, as well as corresponding schedules). Because such ERAs are required to complete Item 7 of Form ADV Part 1A to which Schedule D relates, such ERAs would also be required to respond to the proposed additional questions related to tokenized funds. See infra section II.J.1.c) for further discussion. ERAs that are registering with any State securities authority must complete all of Form ADV, Part 1A. See Form ADV Instruction 3. An ERA is an investment adviser that is not registered with the Commission because the adviser relies on an exemption from registering with the Commission under section 203(l) or 203(m) of the Advisers Act. ERAs are subject to certain reporting, recordkeeping, and other obligations. See rule 204-4 [17 CFR 275.204-4].

Back to Citation

91.  We are also proposing to amend Item 1.I of Form ADV and section 1.I. of Schedule D to Form ADV to remove a parenthetical that lists examples of social media platforms. Additionally, we are also proposing conforming amendments to Form ADV-E to implement the proposed redesignation of the Advisers Act custody rule to rule 223-1. See infra sections II.J.1.d) and II.J.4.

Back to Citation

92.   See General Instruction A to Form N-CEN.

Back to Citation

93.   See current rule 206(4)-2(a)(1).

Back to Citation

94.   See,e.g., TDC Comment Letter I (stating that the range of crypto assets supported by qualified custodians is limited because of the “fast-moving space where new tokens and protocols are constantly being launched” and due to the fact that “every blockchain protocol generally requires the development of a custom technology build, which takes a significant amount of engineering work”); Dechert Comment Letter (stating that of the categories of qualified custodians permitted to hold client assets under the Advisers Act custody rule, “very few are qualified to custody crypto assets, and even these few serve a relatively small number of crypto assets”).

Back to Citation

95.   See,e.g., Unit 410 Comment Letter.

Back to Citation

96.   See,e.g., TDC Comment Letter I (stating that some advisers have “declined token allocations at the potential detriment of investors or asked portfolio companies to hold tokens until a custodial solution becomes available”).

Back to Citation

97.   See supra section I.B for a more detailed discussion of the reasons we are proposing an adviser self-custody rule that would allow advisers to self-custody clients' crypto assets.

Back to Citation

98.   See proposed rule 223-1(d)(16) for the proposed definition of “self-custody” and proposed rule 223-1(b)(7).

Back to Citation

99.   See,e.g., U.S. Securities and Exchange Commission, Office of Investor Education and Assistance, Crypto Asset Custody Basics for Retail Investors—Investor Bulletin (Dec. 12, 2025), available atwww.investor.gov/​introduction-investing/​general-resources/​news-alerts/​alerts-bulletins/​investor-bulletins/​crypto-asset-custody-basics-retail-investors-investor-bulletin-0 (“OIEA Investor Bulletin”) (describing Commission staff's observations that the loss of private keys can result in permanent loss of access to the crypto assets).

Back to Citation

100.   See Changelly, Permissioned vs. Permissionless Blockchains (Oct. 31, 2025), available at changelly.com/​blog/​permissioned-vs-permissionless-blockchain/​.

Back to Citation

101.   See current rule 206(4)-2(b)(5); proposed rule 223-1(b)(7); and proposed rule 223-1(b)(5).

Back to Citation

102.   See 2003 Adopting Release, supra footnote 7, at section II.D.1 (stating that adviser need not comply with the Advisers Act custody rule with respect to clients that are registered investment companies because registered investment companies and their advisers must comply with the strict requirements of section 17(f) of the Investment Company Act and the custody rules adopted by the Commission under that section).

Back to Citation

103.   See proposed rule 223-1(b)(5); proposed rule 223-1(a). But see proposed rule 223-1(b)(7)(vii) which would except advisers from the proposed requirement to send account statements to clients for which the adviser maintains crypto assets in self-custody with respect to the account of any regulated fund. See infra section II.A.7 for a detailed discussion of the proposed self-custody account statement requirement. See also infra section II.B for a detailed discussion of the proposed fund self-custody rule under the Investment Company Act that would apply to regulated funds with self-custody of crypto assets.

Back to Citation

104.   See proposed rule 223-1(a).

Back to Citation

105.   See infra section II.B for a detailed discussion of the proposed fund self-custody rule for regulated funds.

Back to Citation

106.  Proposed rule 223-1(b)(7)(i). See also discussion infra Section II.A.2.

Back to Citation

107.  Proposed rule 223-1(b)(7)(ii).

Back to Citation

108.  Proposed rule 223-1(b)(7)(ii)(A) through (C). See also discussion infra Section II.A.3(a).

Back to Citation

109.  Proposed rule 223-1(b)(7)(iii).

Back to Citation

110.  Proposed rule 223-1(b)(7)(iv).

Back to Citation

111.  Proposed rule 223-1(b)(7)(v).

Back to Citation

112.  Proposed rule 223-1(b)(7)(vi).

Back to Citation

113.  Proposed rule 223-1(b)(7)(viii).

Back to Citation

114.   See proposed rule 223-1(b)(7).

Back to Citation

115.   See current rule 206(4)-2(a)(2) (to be redesignated under this proposal as rule 223-1(a)(2) (“notice requirement”)) and current rule 206(4)-2(a)(3) (to be redesignated under this proposal as rule 223-1(a)(3) (“account statement delivery requirement”)).

Back to Citation

116.   See current rule 206(4)-2(a)(4) which would be redesignated as rule 223-1(a)(4) under this proposal (the “surprise examination requirement”); current rule 206(4)-2(b)(4), which would be redesignated as rule 223-1(b)(4) under this proposal (the “audit provision”). See also infra section II.G.4 for a detailed discussion of the proposed amendments to the audit provision.

Back to Citation

117.   See proposed rule 223-1(b)(5).

Back to Citation

118.   See infra section II.J.1 for a detailed discussion of the proposed amendments to Form ADV, Part 1A.

Back to Citation

119.   See infra section II.J.3 for a detailed discussion of disclosures regarding adviser self-custody of crypto assets.

Back to Citation

120.   See,e.g.,SEC v. Moran, 944 F. Supp. 286, 297 (S.D.N.Y 1996) (“Investment advisers are entrusted with the responsibility and duty to act in the best interest of their clients.”). See also Commission Interpretation Regarding Standard of Conduct for Investment Advisers, Investment Advisers Act Release No. 5248 (June 5, 2019) [84 FR 33669 (July 12, 2019)] at section II (“Standard of Conduct Release”) at section II and n.23 (discussing various interpretations of an adviser's fiduciary duty spanning several decades); Compliance Programs of Investment Companies and Investment Advisers, Advisers Act Release No. 2204 (Dec. 17, 2003) [68 FR 74714 (Dec. 24, 2003)] (“Compliance Program Adopting Release”), at n.22 and accompanying text (in discussing this fiduciary obligation in the context of business continuity plans, stating that an adviser's fiduciary obligation to its clients includes the obligation to take steps to protect the clients' interests from being placed at risk as a result of the adviser's inability to provide advisory services).

Back to Citation

121.   See Standard of Conduct Release, supra footnote 120, at n. 17 (discussing the broad scope of the fiduciary duty in a variety of contexts); 2003 Adopting Release, supra footnote 7, at n.22 (in discussing an adviser's selection of a foreign financial institution to hold clients' assets, stating that an adviser's fiduciary obligations require it either to have a reasonable basis for believing that the foreign institution will provide a level of safety for client assets similar to that which would be provided by a “qualified custodian” in the United States or to fully disclose to clients any material risks attendant to maintaining the assets with the foreign custodian).

Back to Citation

122.   See Standard of Conduct Release, supra footnote 120, at section II.A.

Back to Citation

123.   See infra section II.C for a detailed discussion of the proposed rule that would allow custody of crypto assets at State trust companies. See also supra section I.A.2 for a discussion of related staff actions such as the rescission of SAB 121 and the staff issuance of the 2025 State Trust Company NAL.

Back to Citation

124.   See current rule 206(4)-2(b)(2) which would be redesignated as rule 223-1(b)(2) under this proposal (“privately offered securities exception”).

Back to Citation

125.   See Commission Security Status Interpretation, supra footnote 24, at section IV.

Back to Citation

126.   See Commission Security Status Interpretation, supra footnote 24, at n.1; U.S. Securities and Exchange Commission, Division of Corporation Finance, Division of Investment Management, Division of Trading and Markets, Statement on Tokenized Securities (Jan. 28, 2026), available atwww.sec.gov/​newsroom/​speeches-statements/​corp-fin-statement-tokenized-securities-012826-statement-tokenized-securities (“Tokenization Statement”), at n.1; U.S. Securities and Exchange Commission, Division of Trading and Markets, Staff Statement Regarding Broker-Dealer Registration of Certain User Interfaces Utilized to Prepare Transactions in Crypto Asset Securities (Apr. 13, 2026), available atwww.sec.gov/​newsroom/​speeches-statements/​staff-statement-regarding-broker-dealer-registration-certain-user-interfaces-utilized-prepare-staff-statement-regarding-broker-dealer-registration-certain-user-interfaces-utilized#_​ftn3 (“User Interface Statement”), at n.3.

Back to Citation

127.   See proposed rule 223-1(d)(3).

Back to Citation

128.  A “payment stablecoin” is, subject to certain exclusions, defined as a digital asset that is, or is designed to be, used as a means of payment or settlement, and the issuer of which is obligated to convert, redeem, or repurchase the digital asset for a fixed amount of monetary value, not including a digital asset denominated in a fixed amount of monetary value, and represents that it will maintain, or create the reasonable expectation that it will maintain, a stable value relative to the value of a fixed amount of monetary value. See section 2(22) of the GENIUS Act. The term “digital asset” in the GENIUS Act is generally consistent with the proposed definition of “crypto asset” in the proposed Advisers Act custody rule. See section 2(6) of the GENIUS Act. A “permitted payment stablecoin issuer” is defined as a person formed in the United States that is: (1) a subsidiary of an insured depository institution that has been approved to issue payment stablecoins under section 5 of the GENIUS Act; (2) a Federal qualified payment stablecoin issuer; or (3) a State qualified payment stablecoin issuer. See section 2(23) of the GENIUS Act. A “foreign payment stablecoin issuer” is defined as an issuer of a payment stablecoin that is: (1) organized under the laws of or domiciled in a foreign country, a territory of the United States, Puerto Rico, Guam, American Samoa, or the Virgin Islands; and (2) not a permitted payment stablecoin issuer. See section 2(12) of the GENIUS Act.

Back to Citation

129.   See rule 206(4)-2(a) under the Advisers Act and section 17(f)(1) of the Investment Company Act. See also proposed rule 223-1(a) and proposed rule 223-1(b)(5).

Back to Citation

130.   See Commission Security Status Interpretation, supra footnote 24, at n.49 (providing that the term “native” in the context of a crypto asset refers to a crypto asset generated for use on a particular crypto system). See also id., at section VII.A. (defining “crypto system” to refer collectively to crypto networks and software applications running on a crypto network (“crypto applications”)).

Back to Citation

131.  However, as discussed in the Commission Security Status Interpretation, digital commodities may be offered and sold subject to an investment contract, which is a security. See supra footnote 24.

Back to Citation

132.   See also Commission Security Status Interpretation, supra footnote 24, at section III.A (discussing digital commodities).

Back to Citation

133.   See also Commission Security Status Interpretation, supra footnote 24, at section III.E.

Back to Citation

134.   See proposed rule 223-1(d)(4).

Back to Citation

135.   See proposed rule 223-1(b)(7)(ii)(C) and infra section II.A.3.b)(3) for a detailed discussion of the proposed segregation requirement; proposed rule 223-1(b)(7)(vi) and infra section II.A.7 for a detailed discussion of the proposed self-custody account statement requirement.

Back to Citation

136.   See proposed rule 223-1(d)(5).

Back to Citation

137.   See proposed rule 223-1(d)(10).

Back to Citation

138.   See proposed rule 223-1(d)(16).

Back to Citation

139.   See proposed rule 223-1(b)(7)(ii)(A).

Back to Citation

140.   See proposed rule 223-1(d)(16).

Back to Citation

141.   See proposed rule 223-1(d)(6)(i) (stating that custody includes possession of client funds or securities (including possession of client crypto assets via self-custody of crypto assets) (but not of checks drawn by clients and made payable to third parties) unless the adviser receives them inadvertently and the adviser returns them to the sender promptly but in any case within three business days of receiving them).

Back to Citation

142.   See proposed rule 223-1(d)(7).

Back to Citation

143.   See proposed rule 223-1(b)(11).

Back to Citation

144.   See infra section II.A.3.b)(2) for further discussion of how the Form ADV, Glossary of Terms, defines “Management Persons,” and examples of persons that could qualify as management persons.

Back to Citation

145.   See proposed rule 223-1(b)(7)(ii)(B).

Back to Citation

146.   See Commission Security Status Interpretation, supra footnote 24, at section III.E. (discussing digital securities).

Back to Citation

147.   See proposed rule 223-1(d)(16).

Back to Citation

148.   But see infra section II.A.1(c)(2) for a discussion of how custody (though not self-custody) and the attendant obligations under the Advisers Act custody rule may still be imputed to an adviser if an adviser has the authority to obtain possession of (but does not actually possess) the key materials to a client's crypto asset.

Back to Citation

149.   See current rule 206(4)-2(d)(2)(i).

Back to Citation

150.   See proposed rule 223-1(b)(7)(iii) and infra section II.A.4 for a detailed discussion of the cybersecurity requirement under the proposed adviser self-custody rule.

Back to Citation

151.  Commission staff has taken a similar view. See User Interface Statement (defining for purposes of that staff statement a wallet as software or hardware that is used to store a crypto asset security investor's private key, which is used to engage in crypto asset securities transactions).

Back to Citation

152.   See,e.g., Ledger, Manage Your Private Keys, Own Your Crypto (Oct. 31, 2025), available at support.ledger.com/​article/​360000380313-zd (“When you set up your device, a unique set of private keys is created by Ledger's secure hardware and software.”); Fireblocks, Digital Asset Custody and Transaction Processing Leading Practices Using Fireblocks' MPC Solution (June 26, 2025), available at www.fireblocks.com/​report/​digital-asset-custody-and-transaction-processing-leading-practices-using-fireblocks-mpc-solution (stating that Fireblocks provides multi-party computational (“MPC”) wallet infrastructure that offers “governance, generation, storage and recovery of key shares”). See infra section II.A.3.b)(2) for a more detailed discussion of MPC solutions for private key management.

Back to Citation

153.   See User Interface Statement (stating that covered user interfaces can be used for a variety of purposes, such as preparing code enabling users to interact with blockchain protocols or providing users with market data, such as potential execution routes, asset prices, and estimated transaction costs for crypto asset transactions).

Back to Citation

154.  Commission staff has taken a similar view. See id.

Back to Citation

155.   See proposed rule 223-1(b)(7)(ii)(A) and infra section II.A.3.b)(1) for further discussion of the proposed key management requirement.

Back to Citation

156.   See current rule 206(4)-2(d)(2), which would be redesignated as rule 223-1(d)(6) under this proposal.

Back to Citation

157.   See id.

Back to Citation

158.  Compare current rule 206(4)-2(d)(2) with proposed rule 223-1(d)(6).

Back to Citation

159.   See id.

Back to Citation

160.   See proposed rule 223-1(b)(7)(i).

Back to Citation

161.   See current rule 206(4)-2(a)(2), 206(4)-2(a)(3), and 206(4)-2(b)(4), which would be redesignated as rule 223-1(a)(2), rule 223-1(a)(3), and rule 223-1(b)(4) respectively.

Back to Citation

162.   See infra footnotes 550 and 551 and accompanying text for further discussion of the proposed changes to the related person QC rule.

Back to Citation

163.   See current rule 206(4)-2(d)(5)(stating that a related person is presumed not to be operationally independent unless each of the following conditions is met and no other circumstances can reasonably be expected to compromise the operational independence of the related person: (i) Client assets in the custody of the related person are not subject to claims of the adviser's creditors; (ii) advisory personnel do not have custody or possession of, or direct or indirect access to client assets of which the related person has custody, or the power to control the disposition of such client assets to third parties for the benefit of the adviser or its related persons, or otherwise have the opportunity to misappropriate such client assets; (iii) advisory personnel and personnel of the related person who have access to advisory client assets are not under common supervision; and (iv) advisory personnel do not hold any position with the related person or share premises with the related person).

Back to Citation

164.   See proposed rule 223-1(b)(11); proposed rule 223-1(d)(7) (defining “distributed crypto asset” as a crypto asset received as a distribution for no or nominal consideration in connection, or as a result of activity associated, with a client's crypto asset in the adviser's custody).

Back to Citation

165.   See rule 17f-9(c); see also infra section II.B for a discussion of the proposed regulated fund self-custody rule.

Back to Citation

166.   See rule 17f-9(d).

Back to Citation

167.   See Commission Security Status Interpretation, supra footnote 24, at section VII.A.

Back to Citation

168.   Id. (stating that airdrops may be used for a variety of reasons, “such as to generate interest in and expand ownership and use of . . . crypto assets, reward early users or loyalty of users of a crypto system, promote a software application, build a community, decentralize governance authority with respect to an open-source crypto system, or award high-scoring players of an associated video game”).

Back to Citation

169.   Id.

Back to Citation

170.   See, e.g., Kraken, What is a crypto airdrop? (June 11, 2025), available at www.kraken.com/​learn/​what-are-crypto-airdrops#:~:text=​In%20crypto%2C%20an%20airdrop%20refers,for%20being%20a%20loyal%20client; Coinbase, Earning Through Crypto Airdrops (2025), available at www.coinbase.com/​learn/​crypto-basics/​what-is-a-crypto-airdrop.

Back to Citation

171.   See proposed rule 223-1(b)(7)(i); infra section II.A.2 for a detailed discussion of the proposed qualified custodian determination requirement.

Back to Citation

172.   See proposed rule 17f-9(b).

Back to Citation

173.   See proposed rule 223-1(b)(7)(ii); infra section II.A.3 for a detailed discussion of the proposed safeguarding expertise and systems requirement.

Back to Citation

174.   See proposed rule 223-1(b)(vi); proposed rule 223-1(b)(7)(viii).

Back to Citation

175.  See proposed rule 223-1(b)(7)(i). We are also proposing an amendment to Advisers Act rule 204-2 to include the adviser's written QC determination as a required record. See proposed rule 204-2(a)(26)(i) and infra section II.H.1 for a detailed discussion of the proposed amendments to rule 204-2.

Back to Citation

176.   See proposed rule 223-1(b)(7)(i) (stating that for purposes of any of any qualified custodian determination made with respect to the account of a regulated fund, qualified custodian shall be understood to refer to a bank or other person authorized to hold assets for the regulated fund under section 17(f) of the Investment Company Act or the rules thereunder). Commission staff issued no-action letters stating that the staff would not recommend enforcement actions if certain entities custodied assets for regulated funds subject to certain conditions, and this proposal would not withdraw those letters. See, e.g., Franklin Templeton Investments, SEC Staff No-Act. Letter (pub. avail. June 19, 2009), available at www.sec.gov/​divisions/​investment/​noaction/​2009/​franklintempleton061909.htm; The Brink's Company, SEC Staff No-Act. Letter (pub. avail. Feb. 11, 2014), available at www.sec.gov/​divisions/​investment/​noaction/​2014/​brinks-021114-17f1.htm; Depository Trust Company of Delaware, LLC dba Delaware Depository, SEC Staff No-Act. Letter (pub. Avail. Sept. 12, 2026), available at www.sec.gov/​divisions/​investment/​noaction/​2016/​depository-trust-company-of-delaware-091216.html; See also infra section II.K for discussion and requests for comment on status of certain no-action letters in connection with this proposal.

Back to Citation

177.   See supra section I.A.2 for a more detailed discussion of challenges of custodial compliance for crypto assets.

Back to Citation

178.   See supra section I.A for a detailed discussion of the view the Commission has historically taken about maintaining client assets with only certain types of entities. See also 2009 Adopting Release, supra footnote 7, at section II.C for a discussion of the rationale for prophylactic safeguards under the custody rule applied to advisers and their related persons holding client assets in custody rather than keeping them at an independent custodian.

Back to Citation

179.   See Unit 410 Comment Letter (stating that nascent and novel crypto networks heighten the challenges of supporting early-stage digital assets).

Back to Citation

180.   See, e.g., Comment Letter to Crypto Task Force of Andreessen Horowitz (Apr. 9, 2025) (“A16z Comment Letter II”) (supporting a self-custody solution where a qualified custodian is not readily available); Dechert Comment Letter (stating that an adviser should be required to determine that no qualified custodian can provide the full scope of services required to custody a crypto asset prior to such adviser holding the crypto asset in self-custody, among other conditions).

Back to Citation

181.   See proposed rule 223-1(b)(7)(i).

Back to Citation

182.   See proposed rule 223-1(b)(7)(i).

Back to Citation

183.   See supra section I.A for a detailed discussion of the view the Commission has historically taken with respect to maintaining client assets with only certain types of entities.

Back to Citation

184.   See proposed rule 223-1(b)(7)(i) (stating that the quarterly reassessment of the QC determination must be done “with respect to crypto assets in [the adviser's] self-custody”).

Back to Citation

185.   See also Commission Security Status Interpretation, supra footnote 24, at section III.A.

Back to Citation

186.   See proposed rule 223-1(b)(7)(ii). We also propose to amend rule 204-2 to include this written determination as a required record. See proposed rule 204-2 (a)(26)(ii); infra section II.H for further discussion of the proposed recordkeeping requirement.

Back to Citation

187.   See proposed rule 223-1(b)(7)(ii).

Back to Citation

188.   See 2003 Adopting Release, supra footnote 7, at section II.B. (explaining that “qualified custodians” under the Advisers Act custody rule include the types of financial institutions to which clients and advisers customarily turn to for custodial services).

Back to Citation

189.   See proposed rule 223-1(b)(7)(ii).

Back to Citation

190.   See , e.g., OIEA Investor Bulletin, supra footnote 99 (describing Commission staff's observations that because characteristics and designs of crypto assets, and the distributed ledger or blockchain technology through which they are issued and/or transferred, can vary significantly, different crypto assets present different benefits or risks); A16z Comment Letter II (stating that custodians of crypto assets should “take steps to assess, document and reasonably guard against the specific risks and vulnerabilities associated with the individual blockchains or networks on which specific crypto assets are based (including, for example, around the speed, scalability, resiliency, extensibility, and consensus mechanisms of such blockchains)”).

Back to Citation

191.  Commission staff has previously outlined similar considerations in the context of broker-dealer custody of crypto assets. See U.S. Securities and Exchange Commission, Division of Trading and Markets, Statement on the Custody of Crypto Asset Securities by Broker-Dealers (Dec. 17, 2025), available at www.sec.gov/​newsroom/​speeches-statements/​trading-markets-121725-statement-custody-crypto-asset-securities-broker-dealers (“BD Crypto Custody Statement”), at nn.9-10 and accompanying text (discussing the various aspects of a crypto asset security's distributed ledger technology and associated crypto network that a broker-dealer carrying crypto asset securities for customers should consider).

Back to Citation

192.   See proposed rule 223-1(b)(7)(ii).

Back to Citation

193.   See proposed rule 223-1(b)(7)(ii)(A) through (C).

Back to Citation

194.   See Compliance Program Adopting Release, supra footnote 120.

Back to Citation

195.   See infra section II.A.4 for further discussion of the cybersecurity requirement under the proposed adviser self-custody rule.

Back to Citation

196.   See supra section II.A.3.a) discussing key aspects of a crypto asset's crypto network that may be relevant to an adviser's assessment of the crypto network's risks. See also Federal Reserve Board, et al., Crypto-Asset Safekeeping by Banking Organizations (July 14, 2025), available at www.federalreserve.gov/​newsevents/​pressreleases/​files/​bcreg20250714a1.pdf (“FRB Statement”) (in discussing crypto asset safekeeping by banking organizations, stating that different types of crypto assets may require different key management solutions).

Back to Citation

197.   See, e.g., Comment Letter to Crypto Task Force of Professor J.W. Verret (Feb. 23, 2025) (stating that common risks of hot wallets include phishing and malware); A16z Comment Letter II (stating that online systems for holding crypto assets generally have greater risks but, with “well-managed risk mitigation systems,” can be more secure than offline storage systems that are less rigorously managed); Comment Letter to Crypto Task Force of The Digital Chamber (June 23, 2025) (“TDC Comment Letter II”) (stating that cold storage solutions mitigate risks associated with hacking and fraud); Blockchain Association Comment Letter II (stating that policies and procedures to identify, mitigate, and prevent hacks are particularly relevant with respect to hot storage). See also infra section II.A.3.b)(1) (discussing key management best practices including measures to mitigate risks associated with hot wallets).

Back to Citation

198.   See, e.g., A16z Comment Letter II (stating that one of the main categories of custodial risks relating to crypto assets is the loss of funds to an external attacker); World Federation of Exchanges Comment Letter (explaining that security controls provided by wallet services are structured to “necessitate individual approvals from different operators within the organisation, enhancing protection against insider threats and collusion”).

Back to Citation

199.   See, e.g., A16z Comment Letter II (explaining that risk mitigation measures should address the potential loss of keys and funds resulting from inside risk or user error).

Back to Citation

200.  Commission staff has previously outlined similar considerations in the context of broker-dealer custody of crypto assets. See BD Crypto Custody Statement, supra footnote 191 (stating that broker-dealers carrying customers' crypto asset securities for purposes of rule 15c3-3 of the Exchange Act should establish, maintain and enforce reasonably designed written policies, procedures and arrangements to identify, in advance, the steps it would take in the wake of certain events that could affect the firm's possession of crypto asset securities). See also, e.g., Comment Letter to Crypto Task Force of Blockchain Association (June 26, 2025) (“Blockchain Association Comment Letter II”) (stating that registered investment advisers seeking to custody crypto assets should have policies and procedures addressing disaster recovery); A16z Comment Letter II (stating that audits of crypto asset custodians' practices should include tests of their disaster recovery procedures and business continuity plans). See also Compliance Program Adopting Release, supra footnote 120, at section II.A.1 (stating that an adviser's policies and procedures implemented pursuant to the Advisers Act compliance rule should address, among other issues, business continuity plans to the extent relevant to that adviser).

Back to Citation

201.   See, e.g., Deloitte, Quantum Computers and the Bitcoin Blockchain, available at www.deloitte.com/​nl/​en/​services/​consulting-risk/​perspectives/​quantum-computers-and-the-bitcoin-blockchain.html (last visited July 14, 2026) (stating that quantum computers pose serious challenges to the security of the Bitcoin blockchain); Chainalysis, Quantum Computing and Cryptocurrency: Preparing for the Next Security Revolution, available at www.chainalysis.com/​blog/​quantum-computing-crypto-security/​ (last visited July 14, 2026) (“While cryptocurrencies face theoretical vulnerability to quantum computing . . . practical limitations and ongoing development of quantum-resistant solutions provide a window for preparation”).

Back to Citation

202.   See, e.g., Blockchain Association Comment Letter II (stating that registered investment advisers seeking to custody crypto assets should have policies and procedures addressing private key management); A16z Comment Letter II (describing key management as “the foundation of wallet security”). See also Coindesk, Private Keys, Not Smart Contracts, Caused 40% of Crypto's $16 Billion Hack Losses (Jun. 29, 2026), available at www.coindesk.com/​tech/​2026/​06/​29/​private-keys-not-smart-contracts-caused-40-of-crypto-s-usd16-billion-hack-losses-here-s-whats-being-done (stating that private key hacks account for roughly 40% of all crypto hack losses to date).

Back to Citation

203.   See section 202(a)(25) of the Advisers Act (15 U.S.C. 80b-2(a)(25)) (defining “supervised person” as “any partner, officer, director (or other person occupying a similar status or performing similar functions), or employee of an investment adviser, or other person who provides investment advice on behalf of the investment adviser and is subject to the supervision and control of the investment adviser”).

Back to Citation

204.   See infra section II.B for a detailed discussion of the fund self-custody rule proposed under the Investment Company Act applicable to self-custody of crypto assets by regulated funds.

Back to Citation

205.   See A16z Comment Letter II (discussing secure key generation practices).

Back to Citation

206.   See, e.g., A16z Comment Letter II (describing measures to ensure airgapping such as using “Faraday cages (shields that block wireless signals), biometrics access (like fingerprint or iris scanners), motion sensors (to trip alarms in case of unauthorized use), and SCIFs, or Sensitive Compartmented Information Facilities (special areas for processing classified information)”); Dechert Comment Letter.

Back to Citation

207.   See Blockchain Association Comment Letter II (explaining that advisers should be permitted to use any combination of cold and/or hot storage as they reasonably deem appropriate based on, for example, their and their clients' specific trading activity and investment strategies, provided that they implement appropriate cybersecurity safeguards).

Back to Citation

208.   See Fireblocks, Hot vs. cold vs. warm wallets: Which crypto wallet is right for me?, available at www.fireblocks.com/​blog/​hot-vs-warm-vs-cold-which-crypto-wallet-is-right-for-me (Apr. 15, 2022) (describing “warm wallets”, which “combine the transaction speed of hot wallets with an additional level of security, similar to cold wallets. The keys are held online and transactions can be created automatically, but human involvement is needed to sign the transaction and send it to the blockchain”).

Back to Citation

209.   See A16z Comment Letter II.

Back to Citation

210.   See, e.g., A16z Comment Letter II (describing multi-signature wallets as requiring “the cryptographic coordination of multiple independent keys in the construction of a complete transaction” and that this “can be achieved using offchain advanced cryptographic methods ( e.g., secure multiparty computation or threshold signature schemes) or onchain enforced by smart contract logic ( e.g., “multisig wallets”); AIMA Comment Letter.

Back to Citation

211.   See, e.g., A16z Comment Letter II (“[w]hitelisting and address verification . . . restrict transfers to addresses approved through separate processes, or addresses verified as being under the control of known counterparties”); AIMA Comment Letter (stating that risk mitigation measures for hot wallets include “withdrawal allowlists”). For purposes of this release, “whitelisting” is the practice of explicitly allowing only pre-approved applications, users, email addresses, or IP addresses to access a crypto system or service. See also Commission Security Status Interpretation, supra footnote 24, at section III.B.

Back to Citation

212.   See AIMA Comment Letter.

Back to Citation

213.   See A16z Comment Letter II. See also Bloomberg, Small-Time Crypto Investors Are Facing Violent Attacks (Jan. 2, 2026), available at www.bloomberg.com/​features/​2026-crypto-thieves-kidnappers/​ (discussing physical security vulnerabilities related to crypto assets).

Back to Citation

214.   See A16z Comment Letter II (stating that a best practice is avoiding reuse of key materials for more than a single purpose, for example, using separate key materials for encryption and signing).

Back to Citation

215.  This proposal includes amending Advisers Act rule 204-2 to require records identifying designated persons. See proposed rule 204-2(a)(26)(iii). See also infra section II.H.1 for a detailed discussion of the proposed amendments to rule 204-2.

Back to Citation

216.   See rule 17f-2(d).

Back to Citation

217.   See also supra section II.A.1c)(1) for a discussion on the use of service providers and our stated view that in order to ensure their compliance with the proposed adviser self-custody rule, advisers would need to determine, as part of their due diligence of these service providers prior to engaging them, whether or not the service providers' capabilities impermissibly give them access to the key materials and/or other means to unilaterally move a client's crypto asset.

Back to Citation

218.   See proposed rule 223-1(b)(7) (providing that an adviser is not required to comply with paragraphs (a)(1), (a)(2) and (a)(3) of the Advisers Act custody rule if it has self-custody of client crypto assets for which it provides investment advice).

Back to Citation

219.   See section IV.E.10 for a discussion on this alternative that would have permitted an adviser to share key materials with the client.

Back to Citation

220.   See proposed rule 223-1(b)(7)(ii)(B).

Back to Citation

221.   See, e.g., World Federation of Exchanges Comment Letter (explaining that a key aspect of security controls used by wallet providers is requiring “multiple verifications for a transaction to proceed, ensuring that no single individual or group can unilaterally move assets”); A16z Comment Letter II (stating that the risk of loss and theft of crypto assets can be mitigated by the use of multi-party computation (“MPC”) or multi-signature transaction controls that require the involvement of multiple persons to approve transactions); Comment Letter to Crypto Task Force of Figure Markets (Mar. 25, 2025) (“Figure Markets Comment Letter”) (explaining that self-custody of crypto assets should be accommodated by the use of MPC to “prevent unilateral asset movement”).

Back to Citation

222.   See supra section II.A.3.b)(1) for a discussion of designated persons under the proposed adviser self-custody rule.

Back to Citation

223.   See rule 17f-2(d).

Back to Citation

224.   See, e.g., Figure Markets Comment Letter (explaining that MPC distributes private key shares among vetted persons, “ensuring no single entity can unilaterally move assets”); A16z Comment Letter II (stating that investment advisers that custody crypto assets will typically use, among other protective measures, MPC, which is “a method for joint computation of a crypto asset transaction while each component input is maintained privately from one another”); Dechert Comment Letter (stating that “most” entities that custody crypto assets use, among other measures, MPC); Blockchain Association Comment Letter II (stating that crypto asset custodians should adopt, among other safeguards, MPC).

Back to Citation

225.   See supra footnote 210 for examples of comment letters submitted to the Crypto Task Force describing multi-signature wallets; A16z Comment Letter II (stating that multi-signature wallets help prevent a single stored key from being compromised to effectuate malicious transactions); see also Fireblocks, MPC vs. Multi-sig, (Nov. 1, 2024), available at www.fireblocks.com/​blog/​mpc-vs-multi-sig (explaining that “[w]hen it comes to securing digital assets, multisig wallet solutions and MPC crypto technologies represent two leading approaches to enhanced security”).

Back to Citation

226.   See A16z Comment Letter II (explaining that multifactor authentication involves “multiple independent verification methods ( e.g., passwords, TOTP codes, hardware authentication devices, or biometrics) to authenticate users initiating or approving transactions”).

Back to Citation

227.  It is our understanding that a known problem for private key management is authorized signatories not knowing what they are signing. One way to address this issue is to explain to signatories in plain English the details of the transaction that they are authorizing. See, e.g., Coinbureau, What You Need to Know About Crypto Blind Signing (Before It's Too Late) (Dec. 19, 2025), available at coinbureau.com/​education/​what-is-crypto-blind-signing

Back to Citation

228.   See supra footnote 211 for examples of comment letters submitted to the Crypto Task Force describing whitelisting and other safeguards utilizing crypto asset address verifications.

Back to Citation

229.  Regulated fund officers are typically elected by the fund's board. See Investment Company Institute, Understanding the Role of Mutual Fund Directors, available at www.ici.org/​system/​files/​attachments/​pdf/​bro_​mf_​directors.pdf (last visited May 7, 2026) (stating that duties of mutual fund directors include electing officers); 8 DE Code § 142 (b) (“Officers shall be chosen in such manner and shall hold their offices for such terms as are prescribed by the bylaws or determined by the board of directors or other governing body”).

Back to Citation

230.   See proposed rule 223-1(d)(11); Form ADV, Glossary of Terms (defining “management persons”).

Back to Citation

231.   See Form ADV, Glossary of Terms (definition of “Management Persons”).

Back to Citation

232.   See proposed rule 223-1(b)(7)(ii)(C); proposed rule 223-1(d)(4) (defining “crypto asset address” as the unique identifier on the crypto network that designates the destination for sending, receiving, and storing a crypto asset on the crypto network).

Back to Citation

233.   See A16z Comment Letter II (stating that custodians of crypto assets should generally segregate crypto assets from those of other entities).

Back to Citation

234.   See Ledger Academy, What is A Crypto Wallet Address? (June 28, 2024) available at www.ledger.com/​academy/​topics/​blockchain/​what-is-a-crypto-wallet-address (“A crypto wallet address is derived from your public key. To explain, every blockchain account has a unique key pair comprised of a private key and a public key. The private key grants you control over the account, allowing you to sign transactions. The public key, on the other hand, serves as the account's unique identifier.”); Coinbase, What is a wallet address?, available at www.coinbase.com/​learn/​wallet/​what-is-a-wallet-address (last visited Feb. 11, 2026) (“Wallet addresses play a vital role in cryptocurrency transactions. They allow users to send and receive digital assets across blockchain networks. When you want to receive cryptocurrency, you provide your wallet address to the sender. Conversely, to send cryptocurrency, the recipient's wallet address is required.”).

Back to Citation

235.   See, e.g., Financial Stability Board, The Financial Stability Implications of Multifunction Crypto-Asset Intermediaries (Nov. 28, 2023) at 15-16, available at www.fsb.org/​uploads/​P281123.pdf (explaining that lack of adequate segregation of crypto assets could result in misappropriation and permanent loss of crypto assets); A16z Comment Letter II (stating that audits performed on crypto assets self-custodied with a registered investment adviser should confirm that such assets are duly segregated from the assets of the adviser); TDC Comment Letter I (stating that registered investment advisers should be permitted to self-custody crypto assets under a principles-based framework informed by concepts of the current custody rule including, among others, segregation of client and proprietary assets).

Back to Citation

236.   See World Federation of Exchanges Comment Letter (in discussing segregated accounts at crypto asset trading platforms, stating that segregated accounts help protect client assets in the event of the trading platform's bankruptcy as well as against the platform using client assets for their own purposes).

Back to Citation

237.   See infra section II.A.7 for a detailed discussion of the proposed self-custody account statement requirement, which would allow an adviser, in lieu of sending a consolidated account statement prepared offchain, to transmit the information required in an account statement to a client, for example by providing the client access to records onchain and sending quarterly notifications of onchain activity. See proposed rule 223-1(b)(7)(vi).

Back to Citation

238.   See, e.g., Fortris, Omnibus vs Segregated Accounts in Digital Asset Management (last visited May 7, 2026), available at www.fortris.com/​blog/​omnibus-vs-segregated-account-digital-assets (“Commingling individual assets within the shared account makes it difficult to track specific assets allocated to each user, raising concerns regarding asset ownership and auditability”).

Back to Citation

239.   See infra section II.H.3 for a detailed discussion of the use of onchain records to satisfy recordkeeping obligations under the Advisers Act.

Back to Citation

240.   See proposed rule 223-1(b)(7)(iii).

Back to Citation

241.   See supra footnote 130 (defining “crypto systems”).

Back to Citation

242.   See, e.g., Reuters, Crypto's biggest hacks and heists after $1.5 billion theft from Bybit (Feb. 24, 2025), available at www.reuters.com/​technology/​cybersecurity/​cryptos-biggest-hacks-heists-after-15-billion-theft-bybit-2025-02-24/​; Reuters, Coinbase warns of up to $400 million hit from cyberattack (May 15, 2025), available at www.reuters.com/​business/​coinbase-says-cyber-criminals-stole-account-data-some-customers-2025-05-15/​.

Back to Citation

243.  Gemini, Dao Hack Explained: How a Vulnerability Split Ethereum (Dec. 4, 2025), available at www.gemini.com/​cryptopedia/​the-dao-hack-makerdao.

Back to Citation

244.   See, e.g., TDC Comment Letter II (stating that a rule that allows investment companies to self-custody crypto assets should require advanced cybersecurity measures to protect crypto assets from theft, hacking, and other cyberthreats); Blockchain Association Comment Letter II (stating that in evaluating its custody arrangements for crypto assets, an adviser should consider whether it or its custodian of crypto assets has policies and procedures in place to regularly test the effectiveness of cybersecurity controls).

Back to Citation

245.   See Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information (May 16, 2024) [89 FR 47688 (June 3, 2024)] (“Regulation S-P Release”); 17 CFR 248.30(d)(4); 17 CFR 248.30(d)(5)(i); 17 CFR 248.3(j); 17 CFR 248.3(g)(1); 17 CFR 248.3(k)(1).

Back to Citation

246.   See Identity Theft Red Flags Rules, Advisers Act Release No. 3582 (Apr. 10, 2013) [78 FR 23638 (Apr. 19, 2013)] (“Regulation S-ID Adopting Release”).

Back to Citation

247.   See Regulation S-ID Adopting Release at section II (discussing and providing illustrative examples of entities registered with the Commission, including registered investment advisers, that could fall within the definition of financial institutions, and examples of covered accounts).

Back to Citation

248.   See supra section II.A.3.b) which discusses the proposed safeguarding systems requirement. We are also proposing to amend Advisers Act rule 204-2 to include a copy of this written assessment as a required record. See proposed rule 204-2(a)(26)(iv); infra section II.H.1 for a detailed discussion of the proposed amendments to rule 204-2.

Back to Citation

249.   See Blockchain Association Comment Letter II.

Back to Citation

250.   See supra footnote 197 for examples of comment letters submitted to the Crypto Task Force discussing risks associated with hot wallets.

Back to Citation

251.   See supra section II.A.3.a), which discusses aspects of a crypto asset's crypto network that may be relevant to an adviser's assessment of the network's risks.

Back to Citation

252.   See TDC Comment Letter II (stating that cybersecurity measures accompanying self-custody of crypto assets should undergo audits and penetration testing by independent third parties).

Back to Citation

253.   See, e.g., CISA, Cybersecurity Alerts & Advisories, available at www.cisa.gov/​news-events/​cybersecurity-advisories (last visited Feb. 10, 2026) (providing information about current security issues, vulnerabilities, and exploits).

Back to Citation

254.   See proposed rule 223-1(b)(7)(v). This annual review can be included in the annual review of the adviser's policies and procedures conducted pursuant to Advisers Act rule 206(4)-7(b).

Back to Citation

255.  This proposal also includes an amendment to rule 204-2 to include records documenting the adviser's annual review as required records. See proposed rule 204-2(a)(26)(vi). See infra section II.H for further discussion of the proposed recordkeeping requirements related to the proposed adviser self-custody rule.

Back to Citation

256.   See infra section IV.E.2 for a discussion of reasonable alternatives for protective measures under the adviser self-custody rule.

Back to Citation

257.   See proposed rule 223-1(b)(7)(iv).

Back to Citation

258.  We also propose to amend rule 204-2 to include a copy of any internal control report obtained pursuant to the proposed adviser self-custody rule as a required record. See proposed rule 204-2(a)(26)(v); infra section II.H.1 for further discussion of the proposed amendments to rule 204-2.

Back to Citation

259.   See infra section II.I for a detailed discussion of the expected revisions to the 2009 Guidance for Accountants.

Back to Citation

260.   See 2009 Adopting Release, supra footnote 7, at n.75 and accompanying text. See also Custody of Funds or Securities of Clients by Investment Advisers, Advisers Act Release No. 2876 (May 20, 2009) [74 FR 25354 (May 27, 2009)] (“2009 Proposing Release”) at n.11.

Back to Citation

261.   See, e.g., Blockchain Association Comment Letter II (stating that advisers that maintain self-custody of crypto assets should obtain independent financial and technical audits); A16z Comment Letter II (stating that custodians of crypto assets should undergo financial controls and technical audits no less than annually); Unit 410 Comment Letter (recommending that an adviser that acts as a custodian of crypto assets should, among other things, receive independent verifications of the digital assets such as through an internal control report); Comment Letter to Crypto Task Force of KPMG LLP (Apr. 24, 2025) (“KPMG Comment Letter”) (highlighting the continued importance of SOC reports “for preparers and auditors to be able to evaluate and rely on the design and operating effectiveness of controls at third-party service organizations ( e.g. third-party custodians), particularly over the security and accessibility of private keys”).

Back to Citation

262.   See current rule 206(4)-2(a)(6)(ii) and proposed rule 223-1(a)(6).

Back to Citation

263.   See proposed rule 223-1(d)(8).

Back to Citation

264.   See Revision of the Commission's Auditor Independence Requirements, Securities Act Release No. 7919 (Nov. 21, 2000) [65 FR 76008 (Dec. 5, 2000)].

Back to Citation

265.   See Qualifications of Accountants, Securities Act Release No. 10876 (Oct. 16, 2020) [85 FR 80508 (Dec. 11, 2020)] (discussing bedrock principles).

Back to Citation

266.   See current rule 206(4)-2(a)(6)(ii)(B).

Back to Citation

267.   See 2009 Guidance for Accountants, supra footnote 89, at section III. See also infra section II.I for a detailed discussion of expected revisions to the guidance for accountants set forth in the 2009 Guidance for Accountants.

Back to Citation

268.   See also infra section II.I for a detailed discussion of expected revisions to the guidance for accountants set forth in the 2009 Guidance for Accountants.

Back to Citation

269.   See proposed Section 9.C.(4) of Schedule D of Form ADV, Part 1. Under this proposal, we are making a technical change to replace the term “unqualified opinion” with “unmodified opinion” throughout Form ADV Part 1A to reflect that AU-C 700.10 uses the term “unmodified opinion.” See infra section II.J.1.d) for further discussion of this change.

Back to Citation

270.   See infra section II.J.1 for a detailed discussion of the proposed amendments to Form ADV, Part 1.

Back to Citation

271.   See definition of “independent public accountant” under current rule 206(4)-2(d)(3) and proposed rule 223-1(d)(8).

Back to Citation

272.  Under an adviser's duty of loyalty, an investment adviser must eliminate or make full and fair disclosure of all conflicts of interest which might incline an investment adviser—consciously or unconsciously—to render advice which is not disinterested such that a client can provide informed consent to the conflict. See Standard of Conduct Release, supra footnote 120, at section II.

Back to Citation

273.   See supra section II.A.1.c)(1) for a detailed discussion of the use of service providers.

Back to Citation

274.   See proposed rule 223-1(b)(7)(vi).

Back to Citation

275.   See id.

Back to Citation

276.   See proposed rule 204-2(a)(26)(vii); infra section II.H.1 for further discussion of the proposed amendments to rule 204-2.

Back to Citation

277.   See supra section II.A.3.b)(3) for a discussion about crypto asset addresses.

Back to Citation

278.   See proposed rule 223-1(b)(7)(ii)(C); supra section II.A.3.b)(3) for a detailed discussion of the proposed segregation requirement.

Back to Citation

279.   See current rule 206(4)-2(a)(3).

Back to Citation

280.   See current rule 206(4)-2(a)(5).

Back to Citation

281.  Some commenters writing to the Crypto Task Force mentioned account statements as an important protection of crypto asset custody. See, e.g., Unit 410 Comment Letter; A16z Comment Letter II.

Back to Citation

282.   See current rule 206(4)-2(a)(2). The notice required under this rule must include the qualified custodian's name, address, and the manner in which the funds or securities are maintained.

Back to Citation

283.   See proposed rule 223-1(b)(7)(ii)(C).

Back to Citation

284.   See, e.g., Blockchain Association Comment Letter II; A16z Comment Letter II; Figure Markets Comment Letter.

Back to Citation

285.   See also Electronic Recordkeeping Requirements for Broker-Dealers, Security-Based Swap Dealers, and Major Security-Based Swap Participants, Exchange Act Release No. 96034 (Oct. 12, 2022) [87 FR 66412 (Nov. 3, 2022)] at section II.D.5.

Back to Citation

286.   See Wall Street Journal, It's a More Secret Version of Bitcoin and It's on a Tear (May 14, 2026), available at www.wsj.com/​finance/​currencies/​zcash-crypto-winklevoss-78d71d51?​mod=​lead_​feature_​below_​a_​pos1 (describing a privacy token that helps users to “hide sensitive data, such as the sender, receiver and transaction amount”); TRM Labs, Privacy Coins, available at trmlabs.com/glossary/privacy-coins (last visited Feb. 11, 2026); Ledger Academy, Privacy Token (Dec. 16, 2025), available at www.ledger.com/​academy/​glossary/​privacy-token.

Back to Citation

287.   See current rule 206(4)-2(a)(5).

Back to Citation

288.   See proposed rule 223-1(b)(7)(vi).

Back to Citation

289.   See 2003 Adopting Release, supra footnote 7, at section II.C (explaining the rationale for the account statement delivery requirement under the current Advisers Act custody rule for affiliated pooled investment vehicles).

Back to Citation

290.  We also are proposing to amend current rule 206(4)-2(c), which would be redesignated as proposed rule 223-1(c), to include account statements, transmissions, and notices sent pursuant to proposed rule 223-1(b)(7)(vi) in the delivery requirement relating to recipients that are related persons of the adviser. Accordingly, sending an account statement, transmission, or notice pursuant to proposed rule 223-1(b)(7)(vi) would not satisfy the requirement of that rule if the account statement, transmission or notice is sent solely to limited partners (or members or other beneficial owners) that themselves are limited partnerships (or limited liability companies, or another type of pooled investment vehicle) and are the adviser's related persons.

Back to Citation

291.   See proposed rule 223-1(b)(7)(vii).

Back to Citation

292.   See proposed rule 223-1(b)(4), which would be redesignated from the current audit provision under rule 206(4)-2(b)(4), with proposed amendments.

Back to Citation

293.   See current rule 206(4)-2(b)(4).

Back to Citation

294.   See proposed rule 223-1(b)(7)(vii).

Back to Citation

295.   See, e.g.,17 CFR 210.3-18 and 210.6-10 [rules 3-18 and 6-10 of Regulation S-X].

Back to Citation

296.   See Tailored Shareholder Reports for Mutual Funds and Exchange-Traded Funds; Fee Information in Investment Company Advertisements, Investment Company Act Release No. 34731 (Oct. 26, 2022) [87 FR 72758 (Nov. 25, 2022)]; see also Items 27 and 27A of Form N-1A; Item 7 of Form N-CSR.

Back to Citation

297.   See Item 24 of Form N-2; Item 1 of Form N-CSR.

Back to Citation

298.   See Item 8 of Form 10-K.

Back to Citation

299.   See current rule 206(4)-2(a)(7).

Back to Citation

300.   See proposed rule 223-1(a)(7). We are also proposing to amend this provision to provide that the audited financial statements required to be distributed to investors under the Advisers Act custody rule's audit provision may be distributed to an independent representative of the investor. See infra section II.G.4.b).

Back to Citation

301.   See current rule 206(4)-2(d)(4), which would be redesignated as rule 223-1(d)(9) under this proposal, for the definition of “independent representative.”

Back to Citation

302.   See proposed rule 223-1(b)(7)(viii).

Back to Citation

303.   See proposed rule 204-2(a)(26)(viii); infra section II.H.1 for a detailed discussion of proposed amendments to rule 204-2.

Back to Citation

304.   See UCC § 8-102(a)(9).

Back to Citation

305.   See UCC § 8-102(a)(14).

Back to Citation

306.   See UCC § 8-501(a).

Back to Citation

307.   See Uniform Law Commission and the American Law Institution, Uniform Commercial Code Amendments (2022) with Prefatory Note and Comments (May 29, 2025), available at www.uniformlaws.org/​viewdocument/​final-act-164?​CommunityKey=​1457c422-ddb7-40b0-8c76-39a1991651ac&​tab=​librarydocuments (stating that a person need not be a clearing corporation, bank, or a broker in order to be a securities intermediary and that a person may be a securities intermediary even if that person does not credit securities to a securities account).

Back to Citation

308.   See UCC § 8-102(a)(9) and UCC § 8-501(a). See also American Bar Association, Missing an Opportunity: Cryptocurrency Exchanges and Their Customers Should Consider Using UCC Article 8 (Apr. 3, 2023), available at www.americanbar.org/​groups/​business_​law/​resources/​business-law-today/​2023-april/​missing-opportunity-cryptocurrency-exchanges-their-customers/​ (“American Bar Association”) (stating that a financial asset “could, indeed, be cryptocurrencies”).

Back to Citation

309.  “Entitlement holder” means a person identified in the records of a securities intermediary as the person having a security entitlement against the securities intermediary. If a person acquires a security entitlement by virtue of section 8-501(b)(2) or (3) of the UCC, that person is the entitlement holder. See UCC § 8-102(a)(7). “Security entitlement” means the rights and property interest of an with respect to a specified in Part 5 of Article 8 of the UCC. See UCC § 8-102(a)(17).

Back to Citation

310.   See current rule 204-2(b)(4). An adviser would continue to be required to maintain the records that are prescribed under rule 204-2 for an adviser that has custody or possession of securities or funds of any clients. See current rule 204-2(b).

Back to Citation

311.   See proposed rule 204-2(a)(26)(x) and infra section II.H.1 for further discussion of the proposed amendments to rule 204-2.

Back to Citation

312.   See UCC § 8-504(a).

Back to Citation

313.   See UCC § 8-503(a).

Back to Citation

314.   See UCC § 8-511(a).

Back to Citation

315.  In 2022, the UCC was amended to address emerging technologies such as virtual currencies, and not all States have adopted the 2022 amendments to the UCC. See Uniform Law Commission, UCC, 2022 Amendments to, available at www.uniformlaws.org/​committees/​community-home?​communitykey=​1457c422-ddb7-40b0-8c76-39a1991651ac (last visited Jul. 21, 2026).

Back to Citation

316.   See American Bar Association (“We have seen a tsunami of cryptocurrency exchange bankruptcies—FTX, Celsius, and Voyager, to name a few. Often, disputes arise among stakeholders in these bankruptcy cases regarding whether cryptocurrency maintained by a customer with an exchange in a pure custody relationship is property of the customer or property of the bankruptcy estate.”).

Back to Citation

317.   See id. (“Usually the litigation turns on the account agreement, including what are often referred to as the ‘Terms of Service,’ entered into between the customer and the exchange, and the application of nonstatutory common law contract and property law principles.”).

Back to Citation

318.  For the reasons discussed herein, permitting a regulated fund to maintain its crypto assets with the regulated fund's adviser if the adviser complies with the adviser self-custody rule is necessary or appropriate in the public interest and consistent with the protection of investors and the purposes fairly intended by the policy and provisions of the Investment Company Act. See 15 U.S.C. 80a-6(c).

Back to Citation

319.   See proposed rule 17f-9(b)(1)(i); proposed rule 223-1(b)(7)(i). The fund airdrop provision provides an exception to this general requirement for a regulated fund that receives distributed crypto assets, provided that, as soon as reasonably practicable, the regulated fund places and maintains the distributed crypto asset with (i) an investment adviser to the regulated fund in compliance with proposed rule 17f-9(b); or (ii) a permitted custodian. See proposed rule 17f-9(c); supra section II.A.1.d) (further discussion about the fund airdrop provision and corresponding requests for comment).

Back to Citation

320.   See proposed rule 17f-9(b)(1)(ii).

Back to Citation

321.   Id.

Back to Citation

322.   See proposed rule 17f-9(b)(1)(ii)(A); proposed rule 223-1(b)(7)(ii); see also supra section II.A.3.

Back to Citation

323.   See proposed rules 17f-9(b)(1)(ii)(B) and 17f-9(b)(1)(ii)(D); proposed rule 223-1(b)(7)(v).

Back to Citation

324.   See proposed rules 17f-9(b)(1)(ii)(C) and 17f-9(b)(1)(ii)(D); proposed rule 223-1(b)(7)(iv); see also supra section II.A.5.

Back to Citation

325.   See rule 17f-2(d) and rule 17f-2(e).

Back to Citation

326.   See proposed rule 223-1(b)(7)(i); supra section II.A.2 for a further discussion of the proposed adviser self-custody rule's requirement that an investment adviser reassess its QC determination in writing at least quarterly after taking self-custody of each crypto asset.

Back to Citation

327.   See proposed rule 17f-9(b)(1)(ii)(A); proposed rule 223-1(b)(7)(ii).

Back to Citation

328.   See proposed rule 17f-9(b)(1)(ii)(B); proposed rule 223-1(b)(7)(v).

Back to Citation

329.   See supra section II.A.6.

Back to Citation

330.   See proposed rule 17f-9(b)(1)(i); proposed rule 223-1(b)(7)(i).

Back to Citation

331.   See proposed rule 17f-9(b)(1)(ii)(A); proposed rule 223-1(b)(7)(ii).

Back to Citation

332.   See proposed rule 17f-9(b)(1)(ii)(B) and proposed rule 223-1(b)(7)(v).

Back to Citation

333.   See proposed rule 17f-9(b)(1)(ii)(D).

Back to Citation

334.   See proposed rule 17f-9(b)(1)(ii)(C) and proposed rule 223-1(b)(7)(iv).

Back to Citation

335.  A written internal control report may not be available if, at the time of the board's determination, the adviser has not been holding a crypto asset in self-custody for any client for at least six months.

Back to Citation

336.   See proposed rule 17f-9(b)(1)(ii)(D) and proposed rule 223-1(b)(7)(iv).

Back to Citation

337.   See proposed rule 223-1(b)(7)(i); supra section II.A.2.

Back to Citation

338.   See supra section II.A.8.

Back to Citation

339.   See proposed rules 223-1(d)(13)(v) and 17f-8; see also supra section I.A.2 for discussion of State trust company custodians and related custodial compliance challenges. For the reasons discussed below, permitting a fund to place and maintain its crypto assets and related cash and/or cash equivalents with a State trust company is necessary or appropriate in the public interest and consistent with the protection of investors and the purposes fairly intended by the policy and provisions of the Investment Company Act. See 15 U.S.C. 80a-6(c).

Back to Citation

340.   See proposed rule 17f-8 and current rule 206(4)-2(a)(1) (proposed to be redesignated as rule 223-1(a)(1)).

Back to Citation

341.   See proposed rule 17f-8(b).

Back to Citation

342.   See infra section II.J.1.b)(5) for discussion of this proposed amendment to Form ADV.

Back to Citation

344.   See Standard of Conduct Release, supra footnote 120.

Back to Citation

345.   See id., at section II (“The investment adviser's fiduciary duty is broad and applies to the entire adviser-client relationship.”).

Back to Citation

346.   See proposed rules 17f-8(c) and 223-1(d)(18).

Back to Citation

347.   See proposed rules 17f-8 and 223-1(d)(13)(v).

Back to Citation

348.  As is the case under the existing regulatory framework, an adviser or regulated fund could determine that a particular State trust company satisfies the applicable definition of a bank for purposes of the custody rules and continue to apply the existing custody rule applicable for use of a bank as a custodian. See supra footnote 346.

Back to Citation

349.  The adviser or fund would also be required to maintain records documenting these required reasonable basis determinations. See infra section II.H for discussion of proposed recordkeeping requirements related to the proposed custody rules.

Back to Citation

350.   See infra section II.H for discussion of the proposed amendments to the recordkeeping rules.

Back to Citation

351.  The complexity of this analysis may vary depending on the applicable State laws and regulations and how and to what extent those laws and regulations address crypto asset custody.

Back to Citation

352.   See supra section II.A.3.b)(1).

Back to Citation

353.   See, e.g., New York Department of Financial Services (the “NYDFS”), Cybersecurity Resource Center, available at www.dfs.ny.gov/​industry_​guidance/​cybersecurity.

Back to Citation

354.   See, e.g., Chainanalysis, 2026 Crypto Crime Report, available at www.chainalysis.com/​blog/​crypto-hacking-stolen-funds-2026; see also supra footnote 213.

Back to Citation

355.  For the purposes of the State trust company rules, an independent public accountant means a public accountant that meets the standards of independence described in rule 2-01(b) and (c) of Regulation S-X (17 CFR 210.2-01(b) and (c)). See rule 206(4)-2(d)(3) (proposed to be redesignated as rule 223-1(d)(8)) and proposed rule 17f-8(c).

Back to Citation

356.   See infra section II.H for discussion of the proposed recordkeeping rule amendments related to the proposed State trust company rules.

Back to Citation

357.   See infra section II.H for discussion of the proposed recordkeeping rule amendments related to the proposed State trust company rules.

Back to Citation

358.   See supra section II.A.6 for discussion of the proposed adviser self-custody rule related to internal control reports.

Back to Citation

359.  Proposed rule 17f-8(b); proposed rule 223-1(a)(1) (applicable with respect to all custodians, including State trust companies). See also infra section II.G.10 (setting forth the Commission's views on the Advisers Act custody rule's asset segregation requirement).

Back to Citation

360.  Proposed rule 17f-8(b).

Back to Citation

361.   See rule 206(4)-2(a)(1)(i); see also 1962 Adopting Release, supra footnote 7; see also supra section II.A.3.b)(3) (discussing this requirement in the context of the adviser serving as the custodian when self-custodying assets).

Back to Citation

362.   See, e.g., NYDFS, Updated Guidance on Custodial Structures for Customer Protection in the Event of Insolvency (Sept. 30, 2025), available at www.dfs.ny.gov/​industry-guidance/​industry-letters/​il20250930-updated-guidance-custodial-structures (“NYDFS Custodial Structures Guidance”); see also Comment Letter to Crypto Task Force of the Bank Policy Institute, et. al. (Sept. 18, 2025) (discussing application of bankruptcy law to banks); Jessica G. McKinlay, Enforcing the Rights of Cryptocreditors, 20 Berkeley Bus. L.J. 83 (2023) (discussing treatment of crypto assets in crypto exchange bankruptcy proceedings).

Back to Citation

363.   See Comment Letter to the Crypto Task Force from Anchorage Digital (Apr. 2025). See also GBBC Comment Letter; see also Comment Letter to the Crypto Task Force from Daniel Bruno Corvelo Costa (Jan. 12, 2026).

Back to Citation

364.   See Statement of Commissioner Hester Peirce, Getting Smart—Tokenization and the Creation of Networks for Smart Assets: Opening Remarks for Tokenization Roundtable (May 12, 2025), available at www.sec.gov/​newsroom/​speeches-statements/​peirce-statement-rfi-022125 (describing smart contracts and their use in the context of tokenized securities including in DeFi applications).

Back to Citation

365.   See Protocol Staking Statement supra footnote 27 (explaining “protocol staking,” or staking on networks that use proof-of-stake (“PoS”) as a consensus mechanism (“PoS Networks”), and how node operators in PoS Networks must stake the network's crypto asset to be selected programmatically by the network's underlying software protocol, as a “validator,” to validate new blocks of data to, and update the state of, the network); Liquid Staking Statement supra footnote 27 (explaining a specific type of protocol staking known as “liquid staking” whereby owners of crypto assets (“depositors”) deposit their crypto assets with a third-party protocol staking service provider (“liquid staking provider”), who then holds the deposited crypto assets, either in a smart contract or a cryptographic “wallet” that the liquid staking provider controls, and stakes the deposited crypto assets on behalf of the depositor for an agreed-upon fee that reduces the amount of rewards that would otherwise accrue to the deposited crypto assets).

Back to Citation

366.   See, e.g., Agostino Capponi, Garud Iyengar, Jay Sethuraman, Decentralized Finance: Protocols, Risks, and Governance , 5 Foundations and Trends in Privacy and Security, 3 (Sept. 2023), available at www.emerald.com/​ftsec/​article-abstract/​5/​3/​144/​1324608/​Decentralized-Finance-Protocols-Risks-and.

Back to Citation

367.   See YahooFinance, April 2026 Becomes Worst Month for Crypto Hacks Since February 2025 (Apr. 20, 2026), available at finance.yahoo.com/​markets/​crypto/​articles/​april-2026-becomes-worst-month-041530077.html (reporting a roughly 68% year-over-year rise of DeFi hack incidents); The Block, DeFi Exploits, available at www.theblock.co/​data/​decentralized-finance/​exploits (last visited July 21, 2026) (data tracking, among other things, amount of funds stolen by DeFi attackers and large DeFi exploits).

Back to Citation

368.   See Comment Letter to Crypto Task Force of Sarah Helena Brennan and Jay Stolkin (Dec. 19, 2025).

Back to Citation

369.   See id. (suggesting a “reasonableness-based standard” under the Advisers Act custody rule where an adviser would be deemed to have maintained custody of the crypto asset if it “maintains verifiable authority to initiate, monitor, and redeem such positions, and where the transaction is executed under disclosed policies and risk parameters”).

Back to Citation

370.   See, e.g., Comment Letter to Crypto Task Force of INATBA (May 30, 2025) (stating that true DeFi protocols, when activated, are meant to reduce legal risks because they are meant to be “automated, self-executable financial operations due to their transparency, automation and immutability”); Comment Letter to Crypto Task Force of Phantom Technologies (Apr. 17, 2025) (explaining that the “fully transparent, auditable, and immutable nature of DeFi protocols mitigates the risks customary in the traditional centralized intermediary model” that justify broker registration requirements under the Exchange Act).

Back to Citation

371.   See Protocol Staking Statement, supra footnote 27.

Back to Citation

372.   See U.S. Securities and Exchange Commission, Division of Investment Management, Staff Guidance on Securities Lending by U.S. Open-End and Closed-End Investment Companies (Feb. 27, 2014), available at www.sec.gov/​investment/​divisionsinvestmentsecurities-lending-open-closed-end-investment-companieshtm (providing guidance on certain no-action letters that funds consider when engaging in securities lending and summarizing areas those letters address).

Back to Citation

373.   See Olympix, Understanding Smart Contract Exploits: How and Why They Happen, available at olympix.security/​blog/​understanding-smart-contract-exploits-how-and-why-they-happen (last visited Jul. 22, 2026) (stating that a “smart contract exploit occurs when a flaw in a contract's code allows attackers to manipulate it for their own gain” and describing common smart contract exploits).

Back to Citation

374.   See Chain Score Labs, What is An Admin Role? available at chainscorelabs.com/​glossary/​smart-contract-security-and-patterns/​access-control-patterns/​admin-role (last visited Jul. 22, 2026) (describing an “admin role” as a “designated address or set of addresses within a smart contract that holds special privileges to perform administrative functions, such as upgrading contract logic, pausing operations, or modifying critical parameters”).

Back to Citation

375.   See Blockchain Council, Smart Contract Security Guide: Principles, Tools, and Best Practices (Jul. 18, 2026), available at www.blockchain-council.org/​smart-contracts/​smart-contract-security-guide/​ (stating that “DeFi exploit reports from firms that track on-chain losses show recurring damage in the hundreds of millions to billions of dollars,” and that the “most damaging failures” come from, among other things, “weak access control”).

Back to Citation

376.   See supra footnote 367 for reporting on DeFi hacks and exploits.

Back to Citation

377.  For example, staff explored if there might be circumstances where an adviser could determine that it is in the client's best interest to pursue a particular crypto asset investment strategy but be prohibited from doing so by the Commission's custody rules.

Back to Citation

378.  Proposed amendments to rules 17f-1, 17f-2, 17f-4, 17f-5, 17f-6.

Back to Citation

380.  Proposed rule 17f-4(c)(1).

Back to Citation

381.  Proposed rule 17f-7(b)(1).

Back to Citation

384.   See proposed amendments to rules 17f-1, 17f-2, 17f-4, 17f-5 and 17f-6. Amendments to rule 17f-7 are not necessary as that rule states that various defined terms, including “fund” have the same meaning as in rule 17f-5.

Back to Citation

385.  Proposed rule 17f-1.

Back to Citation

387.  Rule 17f-1.

Back to Citation

388.  Custody Of Securities with Members of National Securities Exchanges, 5 FR 4317 (Oct. 31, 1940) (“Rule 17f-1 Release”). See also section 17(f)(1)(B) of the Investment Company Act. Rule 17f-1 was amended in 1989 to require the filing of a Form N-17f-1 as a cover page for examination certificates filed by accountants under the rule. Forms for Filing by Accountants, Investment Company Act Release No. 17085 (Aug. 4, 1989) [54 FR 32048 (Aug. 4, 1989)].

Back to Citation

389.  A certification of the accountant stating the examination has been made and describing the nature and extent of the examination of must be filed with the Commission on Form N-17f-1. See 17 CFR 274.219.

Back to Citation

390.  Public Law 76-768 (1940), Sec. 17(f). The Commission adopted rule 17f-1 less than two months after the Investment Company Act was enacted and used language identical to the statute to define members of a national securities exchange as the entities that may serve as custodians under this rule. See Rule 17f-1 Release, supra footnote 388.

Back to Citation

391.  Public Law 73-291, 48 Stat. 881, 895-96 (1934); The primary purpose of an SRO is to regulate its members. See, e.g., S. Doc. No. 93-13 at 147 (1973) (describing the structure of the self-regulatory system in which SROs “are delegated governmental power in order to enforce, at their own initiative, compliance by members of the industry with legal and ethical standards going beyond the basic requirements laid down in the Act.”).

Back to Citation

392.  Public Law 73-291, 48 Stat. 881 (June 6, 1934); Public Law 74-621, 49 Stat. 1985 (June 29, 1936).

Back to Citation

393.  Public Law 73-291, 48 Stat. 881 (June 6, 1934), Sec. 6(b) (“No registration [of an exchange] shall be granted or remain in force unless the rules of the exchange include provision for the expulsion, suspension, or disciplining of a member for conduct or proceeding inconsistent with just and equitable principles of trade.”).

Back to Citation

394.  Public Law 73-291, 48 Stat. 881 (June 6, 1934), Sec. 5, 6(a), (d), 19(a)(3), (a)(4), (b). Registration with the Commission was not required for persons conducting business exclusively through an exchange until 1975. Public Law 94-29, 89 Stat. 97 (June 4, 1975).

Back to Citation

395.   See Pecora Committee Final Report, S. Rep. No. 1455, 73d Cong. (1934), Ch. I, Sec. 11(a); History of the NYSE, available at www.nyse.com/​history-of-nyse (Constitution adopted in 1817 provided “detailed rules for the transaction of business and imposed fines to keep disorderly brokers in check.”).

Back to Citation

396.   See SEC Special Study of Securities Markets, Ch. I-II, H.R. Doc. No 88-95, Pt. 1 (1963) (“[The] regulatory technique of the Exchange Act is reliance on supervised self-regulation. This involves control of exchange markets by requiring or permitting national securities exchanges to adopt rules governing their practices and procedures and the business conduct of their members, and in each case imposes the responsibility for enforcement of these rules on the exchanges themselves.”).

Back to Citation

397.  Public Law 73-291, Sec. 19(a)(3). See also Public Law 73-291, Sec. 19(a)(1), (4).

Back to Citation

398.  Public Law 75-719, 52 Stat. 1070 (June 25, 1938). See also National Association of Securities Dealers, Inc., 5 SEC 627 (1939).

Back to Citation

399.   See National Association of Securities Dealers, Inc., available at www.finra.org/​sites/​default/​files/​Corporate/​p009762.pdf.

Back to Citation

400.  The Exchange Act generally defines a “broker” as “any person engaged in the business of effecting transactions in securities for the account of others,” and a “dealer” as “any person engaged in the business of buying and selling securities . . . for such person's own account through a broker or otherwise.” Exchange Act section (3)(a)(4)(A) and section (3)(a)(5)(A).

Back to Citation

401.  Exchange Act section 15(b)(8) and Exchange Act rule 15b9-1.

Back to Citation

402.   Id.

Back to Citation

403.   See Public Law 91-598, 84 Stat. 1635 (Dec. 30, 1970); Public Law 94-29, 89 Stat. 97 (June 4, 1975).

Back to Citation

404.   See 17 CFR 240.3a40-1. See also Recordkeeping and Reporting Requirements for Security-Based Swap Dealers, Major Security-Based Swap Participants, and Broker-Dealers; Capital Rule for Certain Security-Based Swap Dealers; Proposed Rule, Exchange Act Release No. 71958 (Apr. 17, 2014), 79 FR 25194, 25285 (May 2, 2014) (discussing financial responsibility rules).

Back to Citation

405.   See Capital, Margin, and Segregation Requirements for Security-Based Swap Dealers and Major Security-Based Swap Participants and Capital Requirements for Broker-Dealers, Exchange Act Release No. 68071 (Oct. 18, 2012) [77 FR 70214 (Nov. 23, 2012)] (“Capital, Margin and Segregation Release”).

Back to Citation

406.   See Exchange Act section 15(b)(8) and Exchange Act rule 15b9-1. FINRA is the sole national securities association registered with the SEC under section 15A of the Exchange Act. See 15 U.S.C. 78o(b)(1)(B) (This section provides that a broker-dealer's registration with the Commission will not be effective until such broker or dealer has become a member of a registered securities association ( i.e., FINRA), or a member of a national securities exchange if the broker or dealer effects transactions solely on the exchange.).

Back to Citation

407.   See rule 15b9-1 under the Exchange Act. See also Exemption for Certain Exchange Members, Release No. 34-98202 (Aug. 23, 2023) [88 FR 61850 (Sept. 7, 2023)].

Back to Citation

408.   See Capital, Margin and Segregation Release, supra footnote 405.

Back to Citation

409.   See Adoption of Uniform Net Capital Rule and an Alternative Net Capital Requirement for Certain Brokers and Dealer, Exchange Act Release No. 11497 (June. 26, 1975) [40 FR 29795 (July 16, 1975)].

Back to Citation

410.   See Capital, Margin, and Segregation Requirements for Security-Based Swap Dealers and Major Security-Based Swap Participants and Capital and Segregation Requirements for Broker-Dealers, Exchange Act Release No. 86175 (June 21, 2019) [84 FR 43872 (Aug. 22, 2019)].

Back to Citation

411.   See id.

Back to Citation

412.   See id.

Back to Citation

413.   See id.

Back to Citation

414.  15 U.S.C. 78o(c)(3)(A). The amendments to section 15(c)(3) of the Exchange Act granting this rulemaking authority were adopted in section 7(d) of the Securities Investor Protection Act of 1970 (“SIPA”). Public Law 91-598, 7(d), Dec. 30, 1970, 84 Stat. 1563. Rule 15c3-3 was promulgated in the aftermath of the securities industry “paper work crisis” of 1967-1970. See Commission, Study of Unsafe and Unsound Practices of Brokers and Dealers, H.R. Doc. No. 231, 92d Cong., 1st Sess. 6 (1971).

Back to Citation

415.   See Daily Computation of Customer and Broker-Dealer Reserve Requirements Under the Broker-Dealer Customer Protection Rule, Exchange Act Release No. 102022 (Dec. 20, 2024) [90 FR 2790 (Jan. 13, 2025)] (“Daily Computation Final Rule”).

Back to Citation

416.   See id.

Back to Citation

417.   See id.

Back to Citation

418.   See id.

Back to Citation

419.   See 15 U.S.C. 7lll( 4) (defining customer property for purposes of SIPA as cash and securities (except customer name securities delivered to the customer) at any time received, acquired, or held by or for the account of a debtor from or for the securities accounts of a customer, and the proceeds of any such property transferred by the debtor, including property unlawfully converted).

Back to Citation

420.   See 15 U.S.C. 78aaa et seq; See also Covered Broker-Dealer Provisions Under Title II Of The Dodd-Frank Wall Street Reform And Consumer Protection Act, Release No. 89394 (July 24, 2020) [85 FR 53645 (Aug. 31, 2020)] (discussing broker-dealer liquidations under SIPA in more detail).

Back to Citation

430.   See 17 CFR 240.15c3-3(e)(1). The purpose of giving the account this title is to alert the bank and creditors of the carrying broker-dealer that this reserve fund is to be used to meet the carrying broker-dealer's obligations to customers (and not the carrying broker-dealer's obligations to general creditors) in the event the carrying broker-dealer is liquidated in a formal proceeding.

Back to Citation

432.   See id.

Back to Citation

433.   See 17 CFR 240.15c3-3a, Items 1-9.

Back to Citation

434.   See 17 CFR 240.15c3-3a, Items 10-15.

Back to Citation

437.  Broker-dealers are subject to margin requirements in Regulation T, in rules promulgated by the SROs they are members of ( see, e.g., FINRA rules 4210-4240 and Cboe Exchange, Inc. rules 10.1-10.12), and with respect to security futures, in rules jointly promulgated by the Commission and the Commodity Futures Trading Commission (“CFTC”) (17 CFR 242.400-406). Broker-dealers also may establish their own margin requirements, so long as they are as restrictive as regulatory margin requirements. These requirements are often referred to as “house” margin requirements. See, e.g., FINRA rule 4210(d)(1) (requiring broker-dealers to establish procedures to formulate their own margin requirements). See also FINRA rule 4210(a)(5) (defining the term “equity” for purposes of FINRA margin requirements).

Back to Citation

438.   See Financial Responsibility Rules for Broker-Dealers, Exchange Act Release No. 70072 (July 30, 2013) [78 FR 51824 (Aug. 21, 2013)].

Back to Citation

439.   See id.

Back to Citation

440.   See id. The attractiveness of the over-collateralized debits facilitates the bulk transfer of customer accounts from a failing or failed carrying broker-dealer to another broker-dealer. Regulation T, SRO margin rules, and a broker-dealer's house margin rules help to ensure that the customer maintains a minimum level of equity in their account, i.e., that the debit is over-collateralized. See id. at 51827 note 23.

Back to Citation

441.   See e.g. rules 17a-3, 17a-4, 17a-5, 17a-11, and 17a-13 under the Exchange Act. These rules were promulgated by the Commission pursuant to the authority in section 17(a) of the Exchange Act, which authorizes the Commission to prescribe broker-dealer recordkeeping and reporting rules. See 15 U.S.C. 78q(a).

Back to Citation

442.  These rules impose minimum recordkeeping requirements that are based on standards a prudent broker-dealer should follow in the normal course of business. The requirements are an integral part of the investor protection function of the Commission, and other securities regulators, in that the preserved records are the primary means of evaluating compliance with applicable securities laws, including antifraud provisions and financial responsibility standards. See Recordkeeping and Reporting Requirements for Security-Based Swap Dealers, Major Security-Based Swap Participants, and Broker-Dealers; Capital Rule for Certain Security-Based Swap Dealers, Exchange Act Release No. 71958 (Apr. 17, 2014) [79 FR 25194 (May 2, 2014)].

Back to Citation

443.   See id.

Back to Citation

444.   See id.

Back to Citation

445.   See id.

Back to Citation

446.   See 17 CFR 240.17a-5. Other notice requirements relating to the Commission's financial responsibility or reporting rules are contained in rules 15c3-1, 15c3-1d, 15c3-3, 17a-5, and 17a-12. See 17 CFR 240.17a-5(i).

Back to Citation

447.   See Financial Responsibility Rules, Exchange Act Release No. 24553 (June 4, 1987) [52 FR 22295 (June 11, 1987)].

Back to Citation

448.   See OTC Derivatives Dealers, Exchange Act Release No. 39454 (Dec. 17, 1997) [62 FR 67940 (Dec. 30, 1997)].

Back to Citation

449.   See id.

Back to Citation

450.  Rule 17f-1(b)(1).

Back to Citation

451.  Rule 15c3-3(b) and (c). Paragraph (l) of rule 15c3-3 also states that nothing stated in this section (15c3-3) shall be construed as affecting the absolute right of a customer of a broker-dealer to receive in the course of normal business operations following demand made on the broker-dealer, the physical delivery of certificates for fully-paid securities to which the customer is entitled, and, margin securities upon full payment by such customer to the broker or dealer of the customer's indebtedness to the broker-dealer.

Back to Citation

452.  Rule 17a-3(a)(3).

Back to Citation

453.   See Daily Computation Final Rule, supra footnote 415, at 2794.

Back to Citation

457.  Rule 17f-1(b)(2).

Back to Citation

458.  Rule 15c3-3(b)(1) (“broker or dealer shall promptly obtain and shall thereafter maintain the physical possession or control of all fully-paid securities and excess margin securities”) and rule 15c3-3(a)(5). See also17 CFR 240.15c2-1 (Hypothecation of customers' securities).

Back to Citation

459.   See, e.g.,17 CFR 240.15c3-3a, Items 2 and 3. Carrying broker-dealers are permitted to use customer margin securities to, for example, obtain bank loans to finance the funds used to lend to customers to purchase the securities. The amount of the bank loan is a credit in the customer reserve computation—which is accounted for in Item 2—because this is the amount that the carrying broker-dealer would need to pay the bank to retrieve the securities. See Daily Computation of Customer and Broker-Dealer Reserve Requirements Under the Broker-Dealer Customer Protection Rule; Proposed Rule, Exchange Act Release No. 97877 (July 12, 2023), [88 FR 45836 (July 18, 2023)], at n.15.

Back to Citation

461.  Rule 17f-1(b)(3).

Back to Citation

462.   See 17 CFR 240.15c3-3; See also17 CFR 240.15c3-3(b)(1) (defining excess margin securities and fully paid securities).

Back to Citation

463.   Id.

Back to Citation

464.  Additionally, the terms on which broker-dealers can extend credit for securities transactions are governed by federal regulation and by SRO rules. See, e.g., Regulation T and FINRA Rule Series 4200.

Back to Citation

465.  Rule 17f-1(b)(4).

Back to Citation

466.  Rule 17a-13(b) (quarterly securities account rule).

Back to Citation

467.  Rule 17a-5(a), (d).

Back to Citation

468.   See rule 17a-5(d)(3)(i)(A). The term “internal control over compliance” means internal controls that have the objective of providing the broker-dealer with reasonable assurance that non-compliance with rules 15c3-1, 15c3-3(e), 17a-13, or any rule of the DEA of the broker-dealer that requires account statements to be sent to the customers of the broker-dealer, will be prevented or detected on a timely basis. See rule 17a-5(d)(3)(ii).

Back to Citation

470.   See Exchange Act Release No. 49830 (June 8, 2004) [69 FR 34428 (June 21, 2004)] (Commission's adoption of Appendix E to rule 15c3-1 under the Exchange Act) and Exchange Act Release No. 30929 (July 16, 1992) [57 FR 32159 (July 21, 1992)] (Commission's adoption of rules 17h-1T and 17h-2T under the Exchange Act).

Back to Citation

471.  Rule 17f-1(b)(5). Cf.17 CFR 240.17a-4(j).

Back to Citation

472.  Rule 17f-1(b)(6).

Back to Citation

473.  Rule 15c3-3(b)(1).

Back to Citation

474.  Rule 15c3-3(d), (h).

Back to Citation

475.  Rule 17f-1(a).

Back to Citation

476.  Rule 17f-1(c), (d).

Back to Citation

477.  17 CFR 274.219. See also supra footnote 389 (noting that Form N-17f-1 is used to file a certification of the accountant who conducted the examination with the Commission).

Back to Citation

478.  Rule 17f-4(c)(1).

Back to Citation

479.  Proposed rule 17f-4(c)(1).

Back to Citation

480.  Deposits of Securities in Securities Depositories, Investment Company Act Release No. 10453 (Oct. 26, 1978) [43 FR 50869 (Nov. 1, 1978)] (“1978 Securities Depository Adopting Release”).

Back to Citation

481.  Custody of Investment Company Assets Outside the United States, Investment Company Act Release No. 24424 (Apr. 27, 2000) [65 FR 25630 (May 3, 2000)].

Back to Citation

482.  Custody of Investment Company Assets with a Securities Depository, Investment Company Act Release No. 25266 (Nov. 15, 2001) [66 FR 58412 (Nov. 21, 2001)] (“Securities Depository Proposing Release”).

Back to Citation

483.  Custody of Investment Company Assets with a Securities Depository, Investment Company Act Release No. 25934 (Feb. 13, 2003) [68 FR 8437 (Feb. 20, 2003)] (“Securities Depository Adopting Release”).

Back to Citation

484.  Austraclear Ltd, Staff No-Action Letter (Apr. 28, 2004).

Back to Citation

485.  Proposed rule 17f-7(b)(1).

Back to Citation

486.  15 U.S.C. 80a-17(f). See also15 U.S.C. 80a-58 (applying section 17(f) to business development companies as if they are a registered closed-end management company).

Back to Citation

487.  The Commission adopted rule 17f-2 in 1941 and has only substantively revised it once, in 1947, to clarify when it applies. See Adoption of Rule N-17f-2, Investment Company Act Release No. 172 (July 31, 1941) [6 FR 3827 (Aug. 1, 1941)]; Custody of Investments by Registered Management Investment Company; Bonding of Officers and Employers of Registered Investment Companies, Investment Company Act Release No. 1112 (Oct. 3, 1947) [12 FR 6717 (Oct. 11, 1947)].

Back to Citation

488.  The accountant must also complete Form N-17f-2 (17 CFR 274.220) and transmit the same to the Commission promptly after each examination. See rule 17f-2(f).

Back to Citation

489.   See section 30(g) under the Investment Company Act for registered investment companies and section 13(a) of the Exchange Act for BDCs.

Back to Citation

490.   See Securities Depository Proposing Release, supra footnote 482, at n.65; Maxim Series Fund, Inc., SEC Staff No-Action Letter (Jan. 15, 2004) (“Maxim NAL”) at n.5 and accompanying text. See infra sections II.F.5.b)(1) and II.F.5.b)(3) for further examples of circumstances in which rule 17f-2 is implicated.

Back to Citation

491.   See Maxim NAL at nn.6-7 and accompanying text.

Back to Citation

492.   See Maxim NAL.

Back to Citation

493.   See proposed rule 17f-9(a)(1).

Back to Citation

494.   See rule 206(4)-2(a)(6); proposed rule 223-1(a)(6) (the proposed related person QC rule, which would be a redesignation of current rule 206(4)-2(a)(6), the current related person QC rule). See infra section II.G for further detail on the proposed modernization of the Advisers Act custody rule.

Back to Citation

495.   See rule 206(4)-2(a)(6)(ii)(A); proposed rule 223-1(a)(6)(i). In the proposed rule, the opinion is as to whether controls were suitably designed and implemented, among other changes. See infra section II.G for further detail on the proposed modernization of the Advisers Act custody rule.

Back to Citation

496.   See rule 206(4)-2(a)(6)(ii)(B); proposed rule 223-1(a)(6)(ii).

Back to Citation

497.   See 2009 Adopting Release, supra footnote 7, at section II.C.1.

Back to Citation

498.   Id.

Back to Citation

499.   Id.

Back to Citation

500.   See id., at n.86 and accompanying text. Similarly, in a no-action letter provided to K&L Gates, Commission staff stated that they would not recommend enforcement action to the Commission against certain regulated funds if, in lieu of the rule 17f-2 exam requirement, the regulated funds used alternative procedures designed to provide the same protections. See K&L Gates, SEC Staff No-Action Letter (Jan. 13, 2021) (“K&L Gates NAL”). The alternative procedures are consistent with the Advisers Act approach to adviser and related person custody.

Back to Citation

501.   See e.g., American Pension Investors Trust, SEC Staff No-Action Letter (Feb. 1, 1991) (acquiring fund custodian maintains acquired fund shares in the book-entry systems of the acquired funds' transfer agents; FundVest, SEC Staff No-Action Letter (Nov. 21, 1984). Some of the procedures described in the no-action letters were based on the 1978 version of rule 17f-4. See Deposits of Securities in Securities Depositories, Investment Company Act Release No. 10453 (Oct. 26, 1978) [43 FR 50869 (Nov. 1, 1978)].

Back to Citation

502.   See Gardner Fund, SEC Staff No-Action Letter (Mar. 7, 1988) (“Gardner NAL”). Commission staff stated that it would not recommend enforcement action against an acquiring fund for not technically complying with the vaulting, notation, and exam requirements of rule 17f-2 and the requirements of former rule 17f-4; Franklin Investors Securities Trust (Sept. 24, 1992) (“Franklin NAL”). For the avoidance of doubt, rule 17f-2, rather than the proposed fund self-custody rule, applies to fund crypto assets maintained at an affiliated custodian of the investment adviser. Proposed rule 17f-9 provides that a fund crypto asset placed and maintained with an investment adviser itself is subject to that rule in lieu of rule 17f-2. See proposed rule 17f-9(a)(1).

Back to Citation

503.   See Gardner NAL, supra footnote 502; Franklin NAL, supra footnote 502.

Back to Citation

504.   See Gardner NAL, supra footnote 502; Franklin NAL, supra footnote 502. Some of the procedures described in the Commission staff no-action letters were based on the 1978 version of rule 17f-4. See 1978 Securities Depository Adopting Release, supra footnote 480.

Back to Citation

505.   See Securities Depository Proposing Release, supra footnote 482, at n.30 and accompanying text.

Back to Citation

506.   See Securities Depository Proposing Release, supra footnote 482, at section II.B.

Back to Citation

507.   See Securities Depository Adopting Release, supra footnote 483, at n.15.

Back to Citation

508.   See rule 206(4)-2(b)(2).

Back to Citation

509.   See rule 206(4)-2(b)(2)(i).

Back to Citation

510.  Notwithstanding the rule's definition of privately offered securities, this custody rule exception is available with respect to securities held for the account of a limited partnership or other type of pooled investment vehicle only if the pooled investment vehicle is audited and the audited financial statements are distributed as described in rule 206(4)-2(b)(4). See rule 206(4)-2(b)(2)(ii) (proposed to be redesignated as rule 223-1(b)(2)(ii)).

Back to Citation

511.   See 2003 Adopting Release, supra footnote 7, at section II.B. Even if a regulated fund has paper ownership documents, many permitted custodians do not provide safekeeping services for such paper documents.

Back to Citation

512.   See 2003 Adopting Release, supra footnote 7, at section II.B. There are certain impediments to transferability typically associated with certain privately offered securities—specifically, the need to obtain the consent of the issuer or other securities holders prior to any transfer of ownership—that make certain of these assets less susceptible to some of the risks the rule is designed to address. In particular, they would be less likely to be stolen by a third party or simply lost. Id.

Back to Citation

513.  K&L Gates NAL, supra footnote 500.

Back to Citation

514.  These procedures mirror those in the Gardner NAL, supra footnote 502.

Back to Citation

515.   See K&L Gates NAL, supra footnote 500.

Back to Citation

516.   See supra sections II.F.5.b)(1)-II.F.5.b)(3).

Back to Citation

517.   See rule 17f-6 (“a Fund may place and maintain cash, securities, and similar investments with a Futures Commission Merchant”); see also Custody of Investment Company Assets with Futures Commission Merchants and Commodity Clearing Organizations, Investment Company Act Release No. 22389 (Dec. 11, 1996) [61 FR 66207 (Dec. 17, 1996)].

Back to Citation

518.   See sections 723 and 724 of the Dodd-Frank Wall Street Reform and Consumer Protection Act, Public Law 111-203, 124 Stat. 1376 (2010).

Back to Citation

519.   See 17 CFR part 22 (Cleared Swaps); 17 CFR 22.2 (Futures Commission Merchants: Treatment of Cleared Swaps and Associated Cleared Swaps Customer Collateral); see also Protection of Cleared Swaps Customer Contracts and Collateral; Conforming Amendments to the Commodity Broker Bankruptcy Provisions [77 FR 6336 (Feb. 7, 2012)].

Back to Citation

520.   See ICE Clear Credit LLC, Staff No-Action Letter (Dec. 19, 2017); Chicago Mercantile Exchange, Staff No-Action Letter (Dec. 19, 2017); LCH Limited and LCH.Clearnet LLC, Staff No-Action Letter (Dec. 19, 2017).

Back to Citation

521.   See 1962 Adopting Release, supra footnote 7. See also 2003 Adopting Release supra footnote 7; 2009 Adopting Release, supra footnote 7.

Back to Citation

522.   See 2009 Adopting Release, supra footnote 7. See also Judgment, ECF Doc No. 100, 4, United States v. Madoff, No. 09 Cr. 213 (S.D.N.Y. June 29, 2009) (Bernard L. Madoff pled guilty to eleven felony charges including securities fraud, investment adviser fraud, mail fraud, wire fraud, three counts of money laundering, false statements, perjury, and making false filings with the SEC); Order Granting Motion for Summary Judgment, SEC v. Stanford Int'l Bank, Ltd., Civil Action No. 3:09-CV0298 (N.D. Tex. Apr. 25, 2013) (the SEC obtained a $5.9 billion judgment against R. Allen Stanford who was convicted in a parallel criminal case of conspiracy to commit mail and wire fraud, four counts of wire fraud, five counts of mail fraud, one count of conspiracy to obstruct an SEC investigation, one count of obstruction of an SEC proceeding, and one count of conspiracy to commit money laundering and sentenced to a total of 110 years in prison).

Back to Citation

523.   See section 411 of the Dodd-Frank Wall Street Reform and Consumer Protection Act, Public Law 111-203, 124 Stat. 1376 (2010) (adding section 223 to the Advisers Act which provides “[a]n investment adviser registered under this subchapter shall take such steps to safeguard client assets over which such adviser has custody, including, without limitation, verification of such assets by an independent public accountant, as the Commission may, by rule, prescribe.” 15 U.S.C. 80b-18b).

Back to Citation

524.   See supra footnote 523.

Back to Citation

525.  Though we propose to redesignate the rule to 223-1 under section 223 of the Advisers Act rather than 206, an adviser's fiduciary obligations would still apply with regard to the custody and safeguarding of client funds and securities. See discussion at supra section II.A.1.a).

Back to Citation

526.   See proposed rule 223-1(b)(9).

Back to Citation

527.   See 2003 Adopting Release, supra footnote 7, at n.10.

Back to Citation

528.   Id. In addition to n.10 of the 2003 Adopting Release, the Commission stated in n.5 that the “definition [of custody] and other examples make it clear that the adviser has custody when it can control client funds or securities for purposes other than authorized trading.”

Back to Citation

529.   See Inadvertent Custody: Advisory Contract Versus Custodial Contract Authority, Division of Investment Management Guidance Update No. 2017-01 (Feb. 2017) (“2017 Inadvertent Custody IMGU”). See also, Engaging on Non-DVP Custodial Practices Letter, Division of Investment Management (Mar. 12, 2019), available at www.sec.gov/​investment/​non-dvp-and-custody-digital-assets-031219-206 (“Engaging on Non-DVP Custodial Practices Letter”), and the Securities Industry and Financial Markets Association Asset Management Group (“SIFMA AMG”) and Investment Adviser Association (“IAA”) Letter to Dalia Blass and Peter Driscoll Re: IM Guidance Update No. 2017-01 (Mar. 2018) (“SIFMA AMG and IAA Non-DVP Letter”).

Back to Citation

530.   See 2017 Inadvertent Custody IMGU, supra footnote 529.

Back to Citation

531.   See SIFMA AMG and IAA Non-DVP Letter, supra footnote 529.

Back to Citation

532.   See Engaging on Non-DVP Custodial Practices Letter, supra footnote 529.

Back to Citation

533.   See SIFMA AMG and IAA Non-DVP Letter and IAA, SIFMA AMG, and the Loan Syndications and Trading Association (“LSTA”) Letter to Vanessa Countryman Re: Engaging on Non-DVP Custodial Practices (May 13, 2021), available at www.sec.gov/​files/​iaa-sifma-lsta-051321.pdf.

Back to Citation

534.   See proposed rule 223-1(b)(9).

Back to Citation

535.   See proposed rule 223-1(b)(9)(i). The current Advisers Act custody rule's privately offered securities exception has a provision for securities that are “[u]ncertificated, and ownership thereof is recorded only on the books of the issuer or its transfer agent in the name of the client.” See rule 206(4)-2(b)(2) and proposed rule 223-1(b)(2).

Back to Citation

536.  As a practical matter, clients should have knowledge of the specific designated client accounts in which the adviser's discretionary trading activity will occur, as such accounts would typically be identified and agreed upon at account opening or during the course of the advisory relationship. Such client awareness would be consistent with the informed consent that underlies any discretionary trading arrangement and would help ensure that clients have notice of where such activity will occur and can monitor their assets accordingly.

Back to Citation

537.   See rules 206(4)-2(a)(2) and (3).

Back to Citation

538.   See Letter to Paul Cellupica from LSTA Re: Custody Rule and Trading Controls Relating to Bank Loans (July 22, 2019), available at www.sec.gov/​files/​loan-syndications-and-trading-association-072219.pdf. Under the current Advisers Act custody rule, the privately offered securities exception utilizes a provision (among others) to except advisers from the use of a qualified custodian where indicia of ownership are “uncertificated, and ownership thereof is recorded only on the books of the issuer or its transfer agent in the name of the client.” See rule 206(4)-2(b)(2)(i)(B) and proposed rule 223-1(b)(2)(i)(B).

Back to Citation

539.  Financial institutions are typically subject to anti-money laundering requirements under the Bank Secrecy Act (“BSA”), including requirements to have a reasonably designed anti-money laundering compliance program and risk-based procedures to verify the identity of customers. Specific rule requirements, for example, include 31 CFR 1020.210 (requiring banks to have a written, board approved program that meets certain minimum requirements, including internal controls, BSA officers, training, testing, and risk-based customer due diligence); FINRA rule 3310 (setting forth the minimum standards for broker-dealer firms' written anti-money laundering compliance programs); FINRA rule 2090 (requiring broker-dealers to use reasonable diligence, in regard to the opening and maintenance of customer accounts, to know (and retain) essential facts concerning its customers and concerning the authority of each person acting on behalf of such customers). See also Federal Financial Institutions Examination Council, Bank Secrecy Act/Anti-Money Laundering Examination Manual, available at bsaaml.ffiec.gov/​manual.

Back to Citation

540.   See proposed rule 223-1(b)(9)(ii).

Back to Citation

541.   See SIFMA AMG and IAA Non-DVP Letter, supra footnote 529.

Back to Citation

542.  Activities unrelated to trading ( e.g., “bill pay” arrangements or other one-way payments or transfers of funds or securities) would not qualify for the proposed discretionary trading authority exception.

Back to Citation

543.   See proposed rule 223-1(b)(9)(iii).

Back to Citation

544.   See discussion infra at section II.G.5. A standing letter of authorization would serve as a separate basis of custody. We note that our staff expressed a view in a 2017 no-action letter regarding standing letters of authorization that an adviser with the power to disburse funds to one or more third parties does have access to the client's assets and therefore has custody. However, the staff stated that notwithstanding this view, they would not recommend enforcement action if the adviser does not undergo a surprise examination if it complies with certain prophylactic conditions. See Investment Adviser Association, SEC Staff No-Action Letter (Feb. 21, 2017) (“IAA SLOA No-Action Letter”). In addition, we note with regard to these authorities that both the current and proposed rule maintain an exception for fee deduction from the independent verification requirement. See rule 206(4)-2(b)(3).

Back to Citation

545.   See rule 206(4)-7 and Compliance Program Adopting Release supra footnote 120. See also discussion in the 2009 Adopting Release, supra footnote 7, at section II.G. (providing guidance regarding the maintenance of strong policies and procedures “relating to safekeeping of client assets that advisers should consider including in their compliance programs”).

Back to Citation

546.   See proposed rule 223-1(b)(9).

Back to Citation

547.  Though discretionary trading authority is excepted from the compliance requirements of the proposed rule, we note that advisers would still have recordkeeping obligations with regard to their custody of such assets. See rule 204-2(a)(8) and (9) and 204-2(b). See also discussion of the proposed recordkeeping amendments at infra section II.H.1.

Back to Citation

548.   See current rule 206(4)-2(b)(2), which would be redesignated as rule 223-1(b)(2) under this proposal; supra footnote 124 and accompanying text.

Back to Citation

549.  For example, the existing Advisers Act recordkeeping rule addresses discretionary power (rule 204-2(a)(8)), powers of attorney (rule 204-2(a)(9)), and written agreements (rule 204-2(a)(10)).

Back to Citation

550.   See rule 206(4)-2(a)(4) (proposed to be redesignated as rule 223-1(a)(4)), rule 206(4)-2(a)(6) (proposed to be redesignated as 223-1(a)(6)), and rule 206(4)-2(b)(4) (proposed to be redesignated as 223-1(b)(4)). (Current rule 206(4)-2(a)(4) does not require (nor would proposed rule 223-1(a)(4) require) that the independent public accountant performing the surprise examination be registered with, and subject to regular inspection, by the PCAOB, when neither the adviser nor its related person maintains custody as a qualified custodian.)

Back to Citation

551.  Specifically, the amendments would replace “The internal control report must include an opinion of an independent public accountant as to whether controls have been placed in operation as of a specific date, and are suitably designed and are operating effectively to meet control objectives relating to custodial services, including the safeguarding of funds and securities held by either you or a related person on behalf of your advisory clients, during the year,” with “The internal control report must include an opinion of an independent public accountant as to whether controls were suitably designed and implemented and operating effectively throughout the period to achieve control objectives relating to custodial services, including the safeguarding of funds and securities held by either you or a related person on behalf of your advisory clients.” See proposed rule 223-1(a)(6). See also AICPA Attestation Standards (Clarified), Glossary of Terms, available at www.aicpa-cima.com/​resources/​download/​aicpa-ssaes-currently-effective (“AICPA Attestation Standards (Clarified)”).

Back to Citation

552.   See rule 206(4)-2(b)(4).

Back to Citation

553.   See rule 206(4)-2(a)(6)(i)-(ii).

Back to Citation

554.   See section 101(a) of the Sarbanes-Oxley Act of 2002, Public Law 107-204, 116 Stat. 745 (2002).

Back to Citation

555.   See 2009 Adopting Release, supra footnote 7, at section II.C.3.

Back to Citation

556.   See id. In 2010, the Dodd-Frank Act amended the Sarbanes-Oxley Act to provide the PCAOB with oversight of auditors of broker-dealers that are registered with the Commission. See section 982 of the Dodd-Frank Act, Public Law 111-203, 124 Stat. 1376 (2010).

Back to Citation

557.   See 2009 Adopting Release, supra footnote 7, at section II.C.3.

Back to Citation

558.  The scope of the PCAOB's authority includes the audits of issuers, brokers, and dealers. See 15 U.S.C.7212 (requiring registration of public accounting firms that “prepare or issue, or participate in the preparation or issuance of, any audit report with respect to any issuer, broker, or dealer”); 15 U.S.C. 7214(a)(1) (setting forth the PCAOB's inspection authority over registered public accounting firms and associated persons “in connection with [the] performance of audits, issuance of audit reports, and related matters involving issuers”); 15 U.S.C. 7214(a)(2) (providing that the PCAOB may, by rule, conduct inspections “on a basis to be determined by the Board, of registered public accounting firms that provide one or more audit reports for a broker or dealer”).

Back to Citation

559.   See, e.g., Philip T. Lamoreaux, Does PCAOB Inspection Access Improve Audit Quality? An Examination of Foreign Firms Listed in the United States, 61 J. Acct. & Econ. 313 (2016); and Simon Yu Kit Fung et al., Does the PCAOB International Inspection Program Improve Audit Quality for Non-US Listed Foreign Clients?, 64 J. Acct. & Econ. 15 (2017).

Back to Citation

560.   See, e.g., PCAOB, Proposals Regarding False or Misleading Statements Concerning PCAOB Registration and Oversight and Constructive Requests to Withdraw from Registration, PCAOB Release No. 2024-001 (Feb. 27, 2024) (discussing impact on user perception of nature and value of the services resulting from “misperceiving that they are obtaining a level of assurance provided by a PCAOB-registered firm that is providing PCAOB-regulated services, when in fact . . . the service is not subject to PCAOB oversight”).

Back to Citation

561.   See, e.g., Partha S. Mohapatra, Hamilton Elkins, et al., The Impact of PCAOB International Registration on Audit Quality and Audit Fees, J. Account. Public Policy 41 (2022), available at www.sciencedirect.com/​science/​article/​pii/​S0278425422000102 (finding that PCAOB-registered firms charge higher audit fees after PCAOB-registration than before becoming PCAOB-registered).

Back to Citation

563.   See supra footnote 561.

Back to Citation

564.   See supra footnote 551.

Back to Citation

565.   See current rule 206(4)-2(b)(4), which would be redesignated as rule 223-1(b)(4) under this proposal. For purposes of this section, references to a pooled investment vehicle refer to each of a “limited partnership, limited liability company, or other pooled investment vehicle,” as referenced in the audit provision.

Back to Citation

566.   See proposed rule 223-1(b)(4). In connection with these proposed amendments, we are proposing a corresponding amendment to rule 206(4)-2(a)(7) (proposed to be redesignated as rule 223-1(a)(7)) to add a cross-reference to proposed rule 223-1(b)(4).

Back to Citation

567.   See proposed rule 223-1(b)(4)(i)(B). In connection with this proposed change, we are also proposing to add a new defined term for U.S. GAAP, which we propose to define as accounting principles promulgated, or recognized by the Commission as generally accepted, in accordance with section 19 of the Securities Act of 1933 (15 U.S.C. 77s). See proposed rule 223-1(d)(19).

Back to Citation

568.   See proposed rules 223-1(b)(4)(i)(B) and (C). The pooled investment vehicle's audited financial statements, along with any reconciliations to U.S. GAAP, are required to be delivered to U.S. investors in the pooled investment vehicle pursuant to the audit provision. See rule 206(4)-2(b)(4)(i) (proposed to be redesignated rule 223-1(b)(4)(i)(B)). An adviser would be required to make and keep a record of the reconciliation to U.S. GAAP under the Advisers Act recordkeeping rule. See rule 204-2(a)(6).

Back to Citation

569.   See rules 206(4)-2(b)(4)(i) and (iii).

Back to Citation

570.   See 2003 Adopting Release, supra footnote 7, at n.41 (“We are aware that a small percentage of advisers subject to the rule advise foreign pooled investment vehicles that prepare their financial statements in accordance with International Accounting Standards or some comprehensive body of accounting standards other than U.S. Generally Accepted Accounting Principles (`U.S. GAAP'). An adviser may use such financial statements to qualify for this exception with respect to pools that have a place of organization outside the U.S. or a general partner or other manager with a principal place of business outside the U.S., if such financial statements contain information that is substantially similar to financial statements prepared in accordance with U.S. GAAP and contain a footnote reconciling any material variations between such comprehensive body of accounting standards and U.S. GAAP.”).

Back to Citation

571.   See Financial Accounting Standards Board (“FASB”) Accounting Standards Codification (“ASC”) Topic 946, Financial Services — Investment Companies.

Back to Citation

572.  Commission staff has also previously taken a similar view regarding advisers to foreign PIVs delivering audited financial statements that were prepared in accordance with accounting principles other than U.S. GAAP in certain circumstances. See SEC, Staff Responses to Questions About the Custody Rule (last updated Feb. 21, 2017), available at www.sec.gov/​rules-regulations/​staff-guidance/​division-investment-management-frequently-asked-questions/​staff-responses-questions-about-custody-rule (“Custody Rule FAQs”), Question VI.5.

Back to Citation

573.   See proposed rule 223-1(b)(4)(i)(C).

Back to Citation

574.   See rule 206(4)-2(b)(4)(i) through (iii).

Back to Citation

575.   See, e.g., ABA Subcommittee on Private Investment Entities, SEC Staff Letter (Aug. 10, 2006), available at www.sec.gov/​divisions/​investment/​noaction/​aba081006.pdf (discussing the practical difficulties faced by advisers to funds of funds in obtaining completion of audits prior to completion of the audits for the underlying funds in which the fund of funds invests).

Back to Citation

576.   See proposed rule 223-1(b)(4).

Back to Citation

577.  Under the proposed adviser self-custody rule, the account statements required to be delivered to clients may also be delivered to an independent representative of the client. See supra section II.A.7.

Back to Citation

578.   See proposed rule 223-1(a)(7).

Back to Citation

579.  Commission staff has taken a similar view. See Custody Rule FAQs, supra footnote 572, Questions VI.7 and VI.9.

Back to Citation

580.   See proposed rule 223-1(b)(4)(ii).

Back to Citation

581.  This requirement could be satisfied by the adviser obtaining and delivering a single set of audited financial statements covering the first and second fiscal years separately on a comparative basis or two separate sets of audited financial statements, one set of audited financial statements covering the first fiscal year and the other set covering the second fiscal year, at the end of the second fiscal year.

Back to Citation

582.   See proposed rule 223-1(b)(8). See also proposed rule 223-1(d)(17) (defining standing letter of authorization).

Back to Citation

583.  We understand these transactions are typically routine client-authorized disbursements. Examples of such transactions include bill payment, transfers to family members (or other designated individuals), charitable donations, funding the client's external accounts at other financial institutions, or tax payments.

Back to Citation

584.  Qualified custodians are generally subject to anti-money laundering and know your customer requirements that require the financial institution to verify signatures. See supra footnote 539.

Back to Citation

585.  An adviser would be required to report to the Commission on Form ADV if it is relying on this exception. See proposed Form ADV amendment to Item 9 (Safeguarding). See also infra section II.J.1. In addition, we are proposing corresponding amendments to the books and records rule. Proposed rule 204-2(b)(6) would require advisers to retain true, accurate, and current copies of, and records relating to, any standing letter of authorization issued by a client to the adviser. Proposed rule 204-2(b)(6). See also infra section II.H.1.c).

Back to Citation

586.   See proposed rule 223-1(d)(17). See IAA SLOA No-Action Letter, supra footnote 544 (indicating the staff would not recommend enforcement action to the Commission if advisers exercise limited authority pursuant to a SLOA without undergoing an annual surprise examination, if the SLOA arrangement meets certain specified items).

Back to Citation

587.  Proposed rule 223-1(d)(17)(i). The term “related person” would have the same meaning as in the current rule. See rule 206(4)-2(d)(7) and proposed rule 223-1(d)(15).

Back to Citation

588.  Proposed rule 223-1(d)(17)(ii).

Back to Citation

589.  Proposed rule 223-1(d)(17)(iii).

Back to Citation

590.   See discussion of custodial obligations in supra footnote 584.

Back to Citation

591.   See proposed rule 223-1(b)(5).

Back to Citation

592.   See proposed rule 223-1(d)(1).

Back to Citation

593.  Section 59 of the Investment Company Act applies section 17(f) of the Act to business development companies notwithstanding their exclusion from registration under section 6(f). See 15 U.S.C. 80a-58. We note, however, that the self-custody provisions of the proposed adviser self-custody rule would nonetheless apply with respect to BDCs, meaning that if adopted, the adviser would need to comply with the adviser self-custody rule and the BDC, as a regulated fund, would need to engage its board of directors in oversight of the custody arrangement as required under proposed rule 17f-9, the fund self-custody rule. See discussion supra at section II.B.

Back to Citation

594.   See proposed Form ADV Part 1, Items 9A.-9.E. Regulated funds, including BDCs, would need to be included in Item 9.F. reporting regarding self-custody of crypto assets. See infra section II.J.1 for further discussion of the proposed changes to Form ADV, Part 1.

Back to Citation

595.   See proposed rule 223-1(a)(2).

Back to Citation

596.   See proposed rule 223-1(a)(2); rule 206(4)-2(a)(2).

Back to Citation

597.   See proposed rule 223-1(a)(4)(ii).

Back to Citation

598.   See current rule 206(4)-2(a)(4)(ii).

Back to Citation

599.   See proposed rule 223-1(b)(10).

Back to Citation

600.   See IM Guidance Update, Inadvertent Custody: Advisory Contract Versus Custodial Contract Authority, No. 2017-01 (Feb. 2017), available at www.sec.gov/​investment/​im-guidance-2017-01.pdf (the “2017 IM Guidance”).

Back to Citation

601.   See proposed rule 223-1(b)(10).

Back to Citation

602.   See rule 206(4)-7 and Compliance Program Adopting Release, supra footnote 120. See also, discussion in the 2009 Adopting Release, supra footnote 7, at section II.G. (providing guidance regarding the maintenance of strong policies and procedures “relating to safekeeping of client assets that advisers should consider including in their compliance programs”).

Back to Citation

603.   See 1962 Adopting Release, supra footnote 7, and 2003 Adopting Release, supra footnote 7.

Back to Citation

604.   See 1962 Adopting Release, supra footnote 7.

Back to Citation

605.   See 2003 Adopting Release, supra footnote 7.

Back to Citation

606.   See rule 206(4)-2(a)(1).

Back to Citation

608.   See 17 CFR 240.15c3-3 and Financial Responsibility Rules of Broker-Dealers, Exchange Act Release No. 70072 (July 30, 2013) [78 FR 51824 (Aug. 21, 2013)]; see also 17 CFR 1.20 under the CEA.

Back to Citation

609.  We understand this treatment of client cash deposits is a well-established, legally recognized, and regulated feature specific to banking.

Back to Citation

610.   See IM Guidance Update, Private Funds and the Application of the Custody Rule to Special Purpose Vehicles and Escrows, No. 2014-07, available at www.sec.gov/​investment/​im-guidance-2014-07.pdf.

Back to Citation

611.  The Commission anticipates that this contractual obligation will be referenced in the escrow agreement. The IM staff took a similar view. See id.

Back to Citation

612.   See rule 206(4)-2(a)(3) and proposed rule 223-1(a)(3).

Back to Citation

613.  In addition to the account statement provision, the current Advisers Act custody rule's notice to client provision requires advisers that send account statements to a client to which they provide the notice, to include in the notification and in any subsequent account statement they send to that client a statement urging the client to compare the account statements from the custodian with those from the adviser. See rule 206(4)-2(a)(2); see also proposed rule 223-1(a)(2).

Back to Citation

614.  We note that FINRA rule 2231 Customer Account Statements outlines similar requirements regarding broker-dealer customer account statements for assets externally held.

Back to Citation

615.   See rule 204-2 (the “Advisers Act recordkeeping rule”). For purposes of this section, references to advisers refer to both SEC-registered investment advisers and investment advisers that are required to be SEC-registered.

Back to Citation

616.   See proposed rule 204-2(a)(26). As discussed further below in section II.H.2, similar recordkeeping requirements would also apply for regulated funds related to crypto asset self-custody.

Back to Citation

617.   See proposed rule 204-2(a)(27). As discussed further below in section II.H.2, similar recordkeeping requirements would also apply for regulated funds that maintain fund crypto assets at a State trust company custodian.

Back to Citation

618.   See proposed rule 204-2(b)(6).

Back to Citation

619.   See current and proposed rule 204-2(e)(1). As discussed below, for the proposed records related to SLOAs, the adviser would be required to retain such records for any SLOA that is in effect, or at any time within the past five years was, in effect. See proposed rule 204-2(b)(6). See infra section II.H.1.c) for discussion of the proposed recordkeeping requirement related to SLOAs.

Back to Citation

620.   See proposed rules 204-2(a)(17)(iii) and 204-2(b)(5).

Back to Citation

621.   See proposed rule 204-2(h)(2).

Back to Citation

622.   See proposed rules 204-2(g)(1)(iii) and 204-2(g)(4). We are also proposing a similar amendment to the Investment Company Act recordkeeping rules for regulated funds. See infra section II.H.2. We would interpret promptly to mean generally within 24 hours in this context. See,e.g. Electronic Recordkeeping by Investment Companies and Investment Advisers, Advisers Act Release No. 1945 (May 24, 2001) [66 FR 29224 (May 30, 2001)] (“While the `promptly' standard imposes no specific time limit, we expect that a fund or adviser would be permitted to delay furnishing electronically stored records for more than 24 hours only in unusual circumstances. At the same time, we believe that in many cases funds and advisers could, and therefore will be required to, furnish records immediately or within a few hours of request.”).

Back to Citation

623.   See proposed rule 204-2(a)(26)(i). See supra section II.A.2 for discussion of the proposed QC determination requirement.

Back to Citation

624.   See proposed rule 204-2(a)(26)(ii). See supra section II.A.3.a) for discussion of the proposed safeguarding expertise requirement.

Back to Citation

625.   See proposed rule 204-2(a)(26)(iii). See supra section II.A.3.b)(1) for discussion of the proposed requirements related to private key management.

Back to Citation

626.   See proposed rule 204-2(a)(26)(iv). See supra section II.A.4 for discussion of the proposed cybersecurity requirement.

Back to Citation

627.   See proposed rule 204-2(a)(26)(v). See supra section II.A.6 for discussion of the proposed internal control report requirement.

Back to Citation

628.   See proposed rule 204-2(a)(26)(vi). See supra section II.A.5 for discussion of the proposed annual review requirement.

Back to Citation

629.   See proposed rule 204-2(a)(26)(vii). See supra section II.A.7 for discussion of the proposed self-custody account statement requirement.

Back to Citation

630.   See proposed rule 204-2(a)(26)(viii). See supra section II.A.8 for discussion of the proposed financial asset election requirement.

Back to Citation

631.   See proposed rule 204-2(a)(26)(ix).

Back to Citation

632.   See proposed rule 204-2(a)(26)(x); see also current rule 204-2(b).

Back to Citation

633.   See proposed rule 204-2(a)(26)(x); see also current rule 204-2(b), which imposes additional recordkeeping obligations on advisers that have custody or possession of securities or funds of any client. See also supra section II.A for a detailed discussion of the proposed adviser self-custody rule, including its scope.

Back to Citation

634.   See supra section II.C for discussion of the proposed State trust company rule.

Back to Citation

635.   See proposed rule 204-2(a)(27). In addition, the adviser would continue to be required to maintain the records that are otherwise required to be maintained by an adviser that has custody or possession of securities or funds of any client. See rule 204-2(b).

Back to Citation

636.   See supra section II.G.5 for discussion of the proposed amendments related to the surprise examination requirement for advisers that custody client assets solely pursuant to a standing letter of authorization; see also proposed rule 223-1(b)(8).

Back to Citation

637.   See proposed rule 204-2(b)(6).

Back to Citation

638.   See proposed rule 31a-2(a)(10).

Back to Citation

639.   See proposed rule 31a-2(a)(9).

Back to Citation

640.   See paragraphs (a)-(g) of rule 31a-1 and paragraphs (a)-(e), (g) of rule 31a-2.

Back to Citation

641.   See proposed rule 31a-2(a)(10); proposed rule 17f-9(b)(1).

Back to Citation

642.   See supra section II.B; proposed rule 17f-9(b)(1).

Back to Citation

643.   See proposed rule 31a-2(a)(10). This timing is consistent with the timing that is generally required by the fund retention rule.

Back to Citation

644.  The proposed adviser self-custody rule, in order to protect key materials against loss and unauthorized access, requires that access to regulated fund crypto asset key materials be limited to those supervised persons designated by resolution of the board to have such access. See proposed rule 223-1(b)(7)(ii)(A). The current recordkeeping rules require minute books of board meetings, among other things, to be preserved permanently, the first two years in an easily accessible place. See rule 31a-1(b)(4); rule 31a-2(a)(1). We understand board resolutions, including those related to the board's designation of access persons, are included in the relevant board meeting's minute books. Accordingly, such resolutions would be maintained in the same manner and for the same duration as the minute books.

Back to Citation

645.   See proposed rule 31a-2(a)(9).

Back to Citation

646.   See id.

Back to Citation

647.   See supra section II.H.1.b).

Back to Citation

648.   See paragraphs (a)-(g) of rule 31a-1 and paragraphs (a)-(e),(g) of rule 31a-2.

Back to Citation

649.  15 U.S.C. 80a-63(a) (“section 80a-30 of this title shall apply to a business development company to the same extent as if it were a registered closed-end investment company”).

Back to Citation

650.   See rule 31a-1; see also supra footnote 649 (addressing 15 U.S.C. 80a-63(a)).

Back to Citation

651.  For regulated funds, see proposed rule 31a-1(b)(14). For advisers, we propose to add crypto networks as an additional format that advisers can use to maintain their records. See proposed rule 204-2(g)(1)(iii). For the avoidance of doubt, we are proposing crypto network records as a separate category and proposing conditions specific to crypto network records. See proposed rule 204-2(g)(4). In connection with this proposed amendment, we are also proposing conforming amendments to rule 204-2(g)(2) and (g)(3) to exclude the application of these paragraphs to records maintained on a crypto network. The Commission believes that these proposed amendments are consistent with its interpretation of the Electronic Signatures in Global and National Commercial Act. See Electronic Recordkeeping by Investment Companies and Investment Advisers, Advisers Act Release No. 2945 (May 24, 2001) [66 FR 29224 (May 30, 2001)].

Back to Citation

652.  For purposes of this section II.H.3 of this release, the term “regulated fund” includes all registered investment companies and BDCs, including UITs and FACCs. See supra footnote 3 and accompanying text. While the proposed amendments are generally applicable only to management investment companies and BDCs, all registered funds and BDCs are subject to recordkeeping requirements. See 15 U.S.C. 80a-30.

Back to Citation

653.  For advisers, rule 204-2(e) sets forth the applicable record retention requirements. Most records are required under the rule to be maintained and preserved in an easily accessible place for a period of not less than five years from the end of the fiscal year during which the last entry was made on such record, the first two years in an appropriate office of the investment adviser. See rule 204-2(e)(1) of the Advisers Act. For regulated funds, the fund retention rule generally requires funds to preserve records for a period of six years, the first two years in an easily accessible place. See rule 31a-2 of the Investment Company Act.

Back to Citation

654.   See infra footnote 1212 and accompanying text for discussion of circumstances under which onchain records may be temporarily unavailable or difficult to obtain.

Back to Citation

655.   See, e.g., AIMA Comment Letter, supra footnote 210; Blockchain Association Comment Letter II, supra footnote 200; Comment Letter to Crypto Task Force of Digital Asset Holdings LLC (Feb. 25, 2025) (“Digital Asset Holdings Comment Letter”).

Back to Citation

656.   See rule 204-2(b)(2) under the Advisers Act and rule 31a-1(b)(2) under the Investment Company Act.

Back to Citation

657.   See, e.g., Tokenization Statement, supra footnote 126 (stating Commission staff's observations that “[a]s part of this recordkeeping system, the issuer (or its agent) [of tokenized securities] uses onchain database records alongside offchain database records and associates the onchain information.”) (emphasis added).

Back to Citation

658.   See 2009 Guidance for Accountants, supra footnote 89.

Back to Citation

659.   See current rule 206(4)-2(a)(6).

Back to Citation

660.   See 2009 Guidance for Accountants, supra footnote 89. For an explanation of proposed conforming amendments to the description of the internal control report under current rule 206(4)-2(a)(6) (proposed to be redesignated as rule 223-1(a)(6)), see supra footnote 551.

Back to Citation

661.  An internal control report related to crypto assets of a regulated fund maintained in self-custody by the adviser under proposed rule 223-1(b)(7) would be required to cover the regulated fund's securities and similar investments. See proposed rule 223-1(b)(5) (providing that an adviser is required to comply with the Advisers Act custody rule with respect to the regulated fund's crypto assets that are securities or similar investments of the fund and held in self-custody by the adviser).

Back to Citation

662.  For internal control reports prepared pursuant to proposed rule 223-1(b)(7)(iv), “custodian” would mean the adviser holding client crypto assets in self-custody.

Back to Citation

663.  Because Form ADV, Part 1A is submitted in a structured, XML-based data language specific to that Form, the information in the amended Form ADV, Part 1A, would continue to be structured ( i.e., machine readable) as well.

Back to Citation

664.   See supra section II.A for discussion of the proposed amendments to permit adviser self-custody of client crypto assets.

Back to Citation

665.  Under this proposal, Form ADV Glossary of Terms would define “crypto asset,” “crypto asset address,” and “self-custody” as having the same meaning as those terms in rule 223-1 under the Advisers Act. We also propose to revise the definition of “custody” in the Form ADV, Glossary of Terms, to cross-reference to the definition of custody in the Advisers Act custody rule to ensure that the term “custody” as referenced throughout Form ADV aligns with the definition for custody in the Advisers Act custody rule. This proposal would also make a correction edit to the definition of “custody” to add a reference to Schedule D in the list of Form ADV Items where the term “custody” is currently used.

Back to Citation

666.  This proposal also includes the removal of current Item 9.E., which asks advisers filing an annual updating amendment and that were subject to a surprise examination by an independent public accountant in the last fiscal year to provide the date on which the examination commenced. This information is not necessary to our examination staff's risk assessment efforts and, in many instances, is provided with the accountant's report filed with the Form ADV-E. With the removal of current Item 9.E., current Item 9.F. would be redesignated as Item 9.E.

Back to Citation

667.  All proposed changes to Item 9, if adopted, would affect advisers registering with the SEC as well as ERAs that are registering with a State securities authority. See supra footnote 90, which discusses Form ADV reporting obligations of ERAs and registered investment advisers.

Back to Citation

668.   See proposed Form ADV, Part 1A, Item 9.F.(1) and Item 9.F.(2)(a). Consistent with the scope of assets subject to the proposed adviser self-custody rule, Item 9.F. would specify that “crypto asset” for purposes of Item 9.F. means crypto assets that are funds or securities, or with respect to the account of a regulated fund, securities or similar investments. Updates to Item 9.F.(2)(a) would not require a prompt other-than-annual amendment. See proposed General Instruction 4 for Form ADV, which instructs advisers on when to file an other-than-annual amendment to the Form ADV.

Back to Citation

669.  Item 9.F. would also instruct advisers to not check “yes” in response to Item 9.F.(1) if the adviser or its related person maintains crypto assets as qualified custodians. This is because crypto assets maintained at an adviser or its related person acting in its capacity as a qualified custodian would not be subject to the proposed adviser self-custody rule but instead would be governed by the related person QC rule. See supra section II.A. for a more detailed discussion on the scope of activities subject to the proposed adviser self-custody rule.

Back to Citation

670.  See proposed Form ADV, Part 1A, Item 9.F.(2)(b). Relatedly, we propose changes to Section 9.C. of Schedule D to require advisers to indicate whether the independent public accountant is engaged to prepare an internal control report in connection with the adviser or its related persons acting as qualified custodians, and/or because the adviser has self-custody of client crypto assets. See proposed Section 9.C. of Schedule D of Form ADV, Part 1A.

Back to Citation

671.   See proposed Form ADV, Part 1A, Item 9.F.(2)(c).

Back to Citation

672.   See proposed Form ADV, Part 1A, Item 9.F.(2)(d) and Item 9.F.(2)(e); proposed Section 9.C. of Schedule D of Form ADV, Part 1A. Consistent with the instructions for current Item 9.C.(2), which requests whether an independent public accountant audits annually the pooled investment vehicles managed by the adviser, proposed Item 9.F.(2)(e) would state that an adviser does not have to list auditor information in Section 9.C. of Schedule D if the adviser already provided this information with respect to private funds it advises in Section 7.B.(1) of Schedule D.

Back to Citation

673.   See Form ADV, Part 1A, Item 5.K.(2) which asks the adviser whether it engages in borrowing transactions on behalf of any of the SMA clients that it advises, and Item 5.K.(3) which asks whether the adviser engages in derivative transactions on behalf of any SMA clients that it advises.

Back to Citation

674.   See Form ADV, Part 1A, Item 5.K.(4) and Section 5.K.(3) of Schedule D.

Back to Citation

675.  Proposed Item 5.K.(5)(a) would provide that crypto assets for purposes of Item 5.K. means crypto assets that are funds or securities. Item 5.K.(5)(a) would also instruct advisers to not check “yes” if the adviser or its related persons maintain crypto assets solely as a qualified custodian(s), consistent with the scope of the proposed definition of “self-custody” in the proposed custody rule that would not include an adviser or a related person's possession of key materials associated with a crypto asset solely in its capacity as a qualified custodian. Relatedly, we are revising the definition of “Related Person” in the proposed Form ADV, Glossary of Terms, to add Item 5 in the list of Items where this term is used. Although unrelated to this proposal, we are also making a correction edit to this definition to add Item 1 to the list of Items where the term “Related Person” is used, because related person is referenced in current Item 1.J.(2).

Back to Citation

676.  Because ERAs are not subject to the Advisers Act custody rule, proposed question 25(h) would state that an ERA is not required to respond to this question. Similar to proposed Item 5.K.(5)(a), proposed question 25(h)(1) would provide that crypto assets for purposes of this question means crypto assets that are funds or securities, and would also instruct advisers to not check “yes” if the adviser or its related persons maintain crypto assets solely as a qualified custodian(s).

Back to Citation

677.  For similar reasons, we are also proposing conforming amendments to Item 9.B.(1)(a), which requires an adviser to disclose whether its related persons maintain advisory clients' cash or bank accounts, or securities. See Form ADV Item 9.B.(1)(a).

Back to Citation

678.   See Form ADV Item 9.A.(1).

Back to Citation

679.   See rule 206(4)-2(a) (proposed to be redesignated as rule 223-1(a)).

Back to Citation

680.   See current rule 206(4)-2(b)(3) and current rule 206(4)-2(b)(6).

Back to Citation

681.   See supra section II.G for a detailed discussion of the proposed exceptions for standing letters of authorization, discretionary trading authority, and inadvertent custody.

Back to Citation

682.  Under this proposal, General Instruction 4 for Part 1A would also be amended to reflect the proposed changes to Item 9. Specifically, General Instruction 4 would be amended to redesignate Item 9.A.(2) as Item 9.A.(3) and Item 9.F. as Item 9.E.

Back to Citation

683.  We are also proposing a conforming amendment to remove from Item 9.B.(1) the instruction, “You are required to answer this item regardless of how you answered Item 9.A.(1)(a) or (b).”

Back to Citation

684.  These exceptions are the fee deduction authority exception; operationally independent related person exception; SLOA exception; discretionary trading authority exception; and inadvertent custody exception under proposed rule 223-1.

Back to Citation

685.   See proposed Form ADV Item 9.C.(5). See supra section II.C for further discussion of the proposed State trust company rules under the Advisers Act and the Investment Company Act. The Commission is also proposing rule 17f-8 under the Investment Company Act, the State trust company rule that would apply to regulated funds.

Back to Citation

686.   See supra footnote 90, which discusses Form ADV reporting obligations of ERAs and registered investment advisers.

Back to Citation

687.   See supra section II.G.1 for discussion of the proposed redesignation of the Advisers Act custody rule to proposed rule 223-1.

Back to Citation

688.  Proposed changes to Item 7 and any corresponding sections in Schedule D (Section 7.A. and Section 7.B.(1)), if adopted, would impact ERAs as well as registered investment advisers. See supra footnote 90, which discusses reporting obligations of ERAs.

Back to Citation

689.  We also propose to remove from Item 1.I and Section 1.I. of Schedule D a parenthetical that lists examples of social media platforms (“Twitter, Facebook, and LinkedIn”) so that these questions on websites and social media accounts held by the adviser adapt to developments over time. ERAs must complete Item 1 and therefore this change would impact ERAs as well as registered investment advisers.

Back to Citation

690.   See supra section II.G.3 for a detailed discussion of the proposal to remove the PCAOB requirement. Proposed changes to Item 7 and any corresponding sections in Schedule D (Section 7.A. and Section 7.B.(1)), if adopted, would impact ERAs as well as registered investment advisers. See supra footnote 90, which discusses reporting obligations of ERAs.

Back to Citation

691.   See Form ADV, Schedule D Sections 9.C.(3) and (4).

Back to Citation

692.   See Form ADV, Schedule D Sections 9.C.(1), (2), (5), and (6). We propose to renumber current Sections 9.C.(5) and (6) to Sections 9.C.(3) and (4), respectively, in connection with the proposed removal of current Sections 9.C.(3) and (4) from Schedule D of Form ADV. We also propose to renumber current questions 23(g) and 23(h) in Section 7.B.(1) of Schedule D to questions 23(e) and 23(f) respectively, in connection with the proposed removal of current questions 23(e) and 23(f) from Section 7.B.(1) of Schedule D. Relatedly, this renumbering would result in the amendment of the following instruction under question 23(a), “If the answer to question 23.(a)(1) is “yes,” respond to questions (b) through (h) below. If the private fund uses more than one auditing firm, you must complete questions (b) through (f) separately for each auditing firm,” as follows: “If the answer to question 23.(a)(1) is “yes,” respond to questions (b) through (f) below. If the private fund uses more than one auditing firm, you must complete questions (b) through (d) separately for each auditing firm.”

Back to Citation

693.   See AICPA Auditing Standards, AU-C Section 700.10, and AICPA Attestation Standards (Clarified), supra footnote 551.

Back to Citation

694.  Proposed changes to Item 7 and any corresponding sections in Schedule D (Section 7.A. and Section 7.B.(1)), if adopted, would impact ERAs as well as registered investment advisers. See supra footnote 90, which discusses reporting obligations of ERAs.

Back to Citation

695.  Proposed Form N-CEN, Items B.24, C.12.a.vii.9 through 10, D.14.a.vii.9 through 10. Form N-CEN is currently submitted using a structured, XML-based data language that is specific to that Form.

Back to Citation

696.   See Form N-CEN, Item C.12.a.vii. Item C must be filled out by “management investment companies” which does not include regulated funds which are BDCs. See also Form N-CEN, Item D.14.a.vii (an identical custodian reporting requirement for small business investment companies).

Back to Citation

697.   See proposed rule 17f-8; proposed rule 17f-9. See also Form N-CEN, Items C.12.a.vii.9 and D.14.a.vii.9.

Back to Citation

698.   See proposed Form N-CEN, Items C.12.a.vii.2 and D.14.a.vii.2; see also supra section II.F.2; proposed rule 17f-1.

Back to Citation

699.   See proposed Form N-CEN, Item B.24 (“purpose of this item, a “tokenized fund” is an investment company or series thereof registered under the Act that has issued shares in the format of a crypto asset, where the record of ownership is maintained in whole or in part on or through one or more crypto networks”). The staff has taken a similar view regarding the definition of the term “tokenized”. See Tokenization Statement, supra footnote 126.

Back to Citation

700.   See proposed Form N-CEN, Item B.24.a.

Back to Citation

701.   See supra section II.J.1.c).

Back to Citation

702.   See CFR 275.204-3; see also Amendments to Form ADV, Advisers Act Release No. 3060 (July 28, 2010) [75 FR 155 (Aug. 12, 2010)].

Back to Citation

703.   See Standard of Conduct Release, supra footnote 120, at section II.C; see also General Instruction 3 for Part 2 of Form ADV.

Back to Citation

704.   See General Instruction 3 for Part 2 of Form ADV.

Back to Citation

705.   See Items 4(b)(1)(i) and 9(c) of Form N-1A; see also Improving Principal Risks Disclosure, ADI 2019-08 (Aug. 2019); Registration Form Used by Open-End Management Investment Companies, Investment Company Act Release No. 23064 (Mar. 13, 1998) [63 FR 13916 (Mar. 23, 1998)] (noting that the information contained in the risk/return summary about a fund's investment objectives and principal strategies is intended to meet the needs of an average or typical fund investor).

Back to Citation

706.   See Item 8.3 of Form N-2 (“Discuss the principal risk factors associated with investment in the Registrant specifically as well as those factors generally associated with investment in a company with investment objectives, investment policies, capital structure, or trading markets similar to the Registrant's”). BDCs similarly provide risk disclosure on Form N-2, as well as in annual report on Form 10-K [17 CFR 249.310].

Back to Citation

707.   See Item 16(b) of Form N-1A; Item 17.3 of Form N-2.

Back to Citation

708.   See generally 17 CFR 230.497; section 12(a)(2) of the Securities Act (providing a civil remedy if a prospectus includes an untrue statement of a material fact or omits to state a fact necessary in order to make the statements, in the light of the circumstances under which they were made, not misleading); 17 CFR 230.408 (requiring registrants to include, in addition to the information expressly required to be included in a registration statement, such further material information, if any, as may be necessary to make the required statements, in the light of the circumstances under which they are made, not misleading).

Back to Citation

709.   See Item 27A(d) of Form N-1A.

Back to Citation

710.   See Item 27A(g) of Form N-1A; see also17 CFR 270.8b-16(b)(2) and (4).

Back to Citation

711.   See Standard of Conduct Release, supra footnote 120, at section II.C. Similarly, regulated funds should disclose these conflicts of interests in Forms N-1A and N-2, as applicable.

Back to Citation

712.   See supra section II.F.2 for a discussion of the regulatory regime for broker-dealers, including SIPA's governance of broker-dealer liquidation and customer assets through the SIPC.

Back to Citation

713.  The treatment of client crypto assets held in an adviser's self-custody during the adviser's bankruptcy proceeding and their status relative to the adviser's bankruptcy estate may depend on, among other things, the particular facts and circumstances (such as contractual terms setting forth the rights to the assets) and, to the extent adopted by the relevant State, applicable provisions under the UCC such as Articles 8, 9 and 12 of the UCC.

Back to Citation

715.   See infra footnote 906 for a discussion of regulatory requirements as an additional barrier to entry in this market.

Back to Citation

716.   See infra section IV.C.2.

Back to Citation

717.  We are also proposing conforming amendments to Form ADV-E related to the proposed redesignation of the Advisers Act custody rule to rule 223-1.

Back to Citation

718.   See, e.g., Nasdaq v. SEC, 34 F.4th 1105, 1111-14 (D.C. Cir. 2022). This approach also follows SEC staff guidance on economic analysis for rulemaking. See SEC Staff, Current Guidance on Economic Analysis in SEC Rulemaking (Mar. 16, 2012), available at www.sec.gov/​divisions/​riskfin/​rsfi_​guidance_​econ_​analy_​secrulemaking.pdf (“The economic consequences of proposed rules (potential costs and benefits including effects on efficiency, competition, and capital formation) should be measured against a baseline, which is the best assessment of how the world would look in the absence of the proposed action.”); id. at 7 (“The baseline includes both the economic attributes of the relevant market and the existing regulatory structure.”).

Back to Citation

719.   See supra footnote 24 and accompanying text.

Back to Citation

720.  Many prominent crypto networks use blockchain as their underlying distributed ledger technology for transfer and exchange of their crypto assets. Each block contains a set of transactions, and the network must reach a distributed consensus on the validity of the transactions before the block can be added to the chain and incorporated into the permanent record. Distributed ledgers that are not blockchains use different structures. See, e.g., Ahmad J. Alkhodair et al., Consensus Algorithms of Distributed Ledger Technology—A Comprehensive Analysis (preprint Sept. 26, 2023). available at arxiv.org/​pdf/​2309.13498 (Alkhodair et al. (2025)).

Back to Citation

721.   See supra footnote 26 and accompanying text.

Back to Citation

722.  Some crypto networks are permissionless, which means that anyone is able to see, join, and participate in the network's activities. In comparison, a permissioned network is accessible only to nodes (or users) that have been granted access by the administrator, adding a layer of security and privacy. In addition, see supra footnote 100 and accompanying text.

Back to Citation

723.   See, e.g., Rainer Alt & Max Gräser, Distributed Ledger Technology, 35 Elec. Mkts. 53 (2025) available at doi.org/​10.1007/​s12525-025-00784-w (Alt & Gräser (2025)); Alkhodair et al. (2025).

Back to Citation

724.   See supra footnote 151 and accompanying text. A wallet typically contains the public and private keys as well as a public receiving address. A wallet address, mathematically derived from the wallet's public key, is a unique identifier used to identify a destination for digital asset transactions. The wallet address can be used to view the corresponding crypto asset's balances and transactions on the crypto network on which the crypto asset's transfers and ownership are recorded.

Back to Citation

725.  Some wallets, known as “warm” wallets, offer characteristics of both hot and cold wallets.

Back to Citation

726.   See supra footnote 154 and accompanying text.

Back to Citation

727.  For example, third-party service providers such as centralized crypto exchanges can hold clients' crypto assets in a hosted wallet, where a user accesses her assets through an account interface but a custodian authorizes the blockchain transactions on behalf of the client.

Back to Citation

728.   See SEC, Application of the Federal Securities Laws to Certain Types of Crypto Assets and Certain Transactions Involving Crypto Assets, available at www.sec.gov/​rules-regulations/​2026/​03/​s7-2026-09. Real world assets (including financial assets such as securities) can be formatted as or represented by a crypto asset.

Back to Citation

729.   See supra paragraph preceding footnote 723 for a description of staking. While staking rewards vary, they can be significant. See, e.g., Lin William Cong et al., The Tokenomics of Staking (Nat'l Bureau of Econ. Rsch., Working Paper No. 33640, 2025) available at www.nber.org/​system/​files/​working_​papers/​w33640/​w33640.pdf, finding staking rewards as low as 0.02% and as high as 75.39%, with an average of 14.86%. Yield farming is a strategy in which users provide liquidity, for example in liquidity pools, in exchange for rewards. See, e.g., T.N. Li et al., Yield Farming for Liquidity Provision (working paper June 14, 2023), available at dauphine.psl.eu/​fileadmin/​mediatheque/​chaires/​fintech/​articles/​Yield_​Farming_​14_​06_​2023.pdf.pdf; see also infra footnote 733.

Back to Citation

730.  Historically, users were typically required to deposit assets (fiat currency or crypto assets) into their accounts before being able to trade on a centralized platform, thereby ceding control of the assets to the platform. However, industry members have pointed out that more recently, new practices that either limit the need for prefunding or allow assets that are required to be moved before trading to be transferred to a custodian that is permitted under the current custody rules have been developed. Outreach by Commission staff has shown that some centralized trading platforms permit trading without requiring assets or control of the assets to be moved to entities that are not permitted custodians. See supra section II.E. In addition, some crypto asset securities are traded on Alternative Trading Systems that do not require prefunding of trades.

Back to Citation

731.  Transactions taking place on a centralized platform do not typically involve the access to the assets being moved to a different wallet until users take their assets outside of their accounts on the platform and regain direct control of the assets.

Back to Citation

732.  Smart contracts are computer programs that trigger actions (such as the transfer of ownership of crypto assets) based upon the occurrence of pre-defined events. See, e.g., Alt & Gräser (2025).

Back to Citation

733.  Unlike centralized platforms, decentralized platforms typically do not facilitate transactions between fiat currency and crypto assets. Some decentralized platforms use an order book model and smart contracts to match buy and sell orders and execute trades automatically. Other decentralized platforms rely on automated market makers that use algorithms to price assets through liquidity pools. On these platforms, trades occur when a user swaps one digital asset for another in the liquidity pool and the transaction is subsequently validated and recorded on the ledger.

Back to Citation

734.  For example, Layer-2 networks are built on top of other public distributed ledger technology (Layer-1 networks) and enable transactions operating independently from the associate Layer-1 network. Most transactions on Layer-2 networks are ultimately recorded on the main blockchain. See, e.g., The Impact of Distributed Ledger Technology in Capital Markets Ready for Adoption, Time to Act, Glob. Fin. Mkts. Ass'n., available at www.gfma.org/​wp-content/​uploads/​2025/​08/​2.-exec-sum-impact-of-dlt-in-cap-mkts-final.pdf (last visited May 26, 2026). Certain transactions may also be effectuated through private and anonymous offchain liquidity venues ( i.e., dark pools). For example, brokers may source liquidity directly from wholesalers, where transactions are netted before being recorded onchain. See Thomas Ernst, et al., Dark Crypto (Mar. 20, 2025) available at papers.ssrn.com/​sol3/​papers.cfm?​abstract_​id=​5186551 (retrieved from SSRN Elsevier database).

Back to Citation

735.   See supra footnote 31 and accompanying text.

Back to Citation

736.  The market capitalization is calculated as the monthly average of the daily market capitalization. The highest daily market capitalization was reached on Oct. 7, 2025, at $4.4 trillion. Based on data from CoinGecko. See www.coingecko.com/​en/​methodology for a description of the methodology used by CoinGecko.

Back to Citation

737.  Based on Commission staff analysis of CoinGecko data as of Apr. 24, 2026.

Back to Citation

738.  The 24-hour trading volume is calculated as the monthly average of the daily 24-hour global trading volume. The highest daily 24-hour trading volume was reached on May 20, 2021, at $516 billion. Based on data from CoinGecko. See www.coingecko.com/​en/​methodology for a description of the methodology used by CoinGecko.

Back to Citation

739.  Based on CoinGecko data as of Apr. 24, 2026. The analysis only includes crypto assets with a market capitalization of at least $100,000. The numbers discussed in this paragraph and in the previous paragraph should be viewed as approximations as CoinGecko includes or excludes assets and exchanges in its statistics according to its own methodology and criteria. See www.coingecko.com/​en/​methodology.

Back to Citation

740.  The 639 decentralized platforms operate on 97 crypto networks and are deployed by 388 projects, with some projects enabling trading on multiple networks. Analysis of the same data reveals that 15 centralized platforms account for more than 50% of spot transactions.

Back to Citation

741.  Based on Commission staff analysis of CoinGecko data. The average 24-hour trading volume on decentralized platforms accounted for 3.2% global trading volume in Dec. 2024, and 5.3% in Dec. 2025.

Back to Citation

742.   See supra footnote 33.

Back to Citation

743.   See Bd. Governors Fed. Rsrv. Sys, Economic Well-Being of U.S. Households in 2025 (May 2026), available at www.federalreserve.gov/​publications/​files/​2025-report-economic-well-being-us-households-202605.pdf. See also Bd. Governors Fed. Rsrv. Sys, Economic Well-Being of U.S. Households in 2024 (May 2025), available at www.federalreserve.gov/​publications/​files/​2024-report-economic-well-being-us-households-202505.pdf.

Back to Citation

744.   See Gemini Global State of Crypto 2025, supra footnote 35, and Gemini Global State of Crypto 2021, supra footnote 35.

Back to Citation

745.   See Coinbase & EY Parthenon, 2026 Institutional Investor Digital Assets Survey (Mar. 2026), at 14, available at www.ey.com/​content/​dam/​ey-unified-site/​ey-com/​en-us/​campaigns/​financial-services/​documents/​ey-volatility-drives-discipline-not-retreat.pdf (the “Coinbase & EY 2026 Crypto Report”).

Back to Citation

746.  This includes respondents that invest in companies that are exposed to crypto assets, such as investments in digital asset companies and investments in mutual funds, ETFs, or ETPs focused on exposure to crypto or blockchain companies. See Coinbase & EY Crypto 2026 Report, supra footnote 745, at 10.

Back to Citation

747.   See Coinbase & EY Crypto 2026 Report, supra footnote 745, at 14.

Back to Citation

748.   See AIMA, 7th Annual Global Crypto Hedge Fund Report (Oct. 2025), available at www.aima.org/​compass/​insights/​digital-assets/​7th-annual-global-crypto-hedge-fund-report.html.

Back to Citation

749.  In this report, crypto hedge fund managers are defined as managers investing more than 50% of their total assets under management in crypto assets. Traditional hedge fund managers are hedge fund managers that are not crypto hedge fund managers.

Back to Citation

750.   See supra section I.A.

Back to Citation

751.  Advisers are currently not required to comply with the Advisers Act custody rule with respect to the accounts of registered investment companies. See rule 206(4)-2(b)(5). In addition, BDCs are subject to section 17(f) the Investment Company Act. Industry practice has been to interpret the Investment Company Act's application of section 17(f) to BDCs to allow BDCs to rely on the Investment Company Act custody rules to the same extent as registered closed-end investment companies. See 15 U.S.C. 80a-58; supra section II.F.1. It is our understanding that industry members have interpreted the exception in the Advisers Act custody rule to also apply to the accounts of BDCs.

Back to Citation

752.   See supra section I.A.

Back to Citation

753.  As fiduciaries subject to a duty of care, advisers must consider their clients' preferences regarding investment strategies and asset classes, consider their clients' risk profiles, and act in the best interests of their clients when providing investment advice, including when managing clients' portfolios. See supra section II.A.1; Standard of Conduct Release, supra footnote 120.

Back to Citation

754.   See rule 206(4)-2(d)(2). The Commission stated in 2003, however, that “custodians are generally under instructions to transfer funds (or securities) out of a client's account only upon corresponding transfer of securities (or funds) into the account.” Because this “delivery versus payment” arrangement minimizes the risk of client loss, an adviser's authority to issue instructions to a broker-dealer or another custodian to effect or to settle trades does not constitute “custody” under the current rule. See 2003 Adopting Release, supra footnote 7, at n. 10. See also rule 206(4)-2(d)(7), defining “related person” as “any person, directly or indirectly, controlling or controlled by [the adviser], and any person that is under common control with [the adviser].”

Back to Citation

755.   See Commission Security Status Interpretation, supra footnote 24. Whether a particular crypto asset is a security is an asset-specific inquiry, depending on the facts and circumstances of the particular crypto asset.

Back to Citation

756.   See rule 206(4)-2(a).

Back to Citation

757.   See rules 206(4)-2(a)(1) and 206(4)-2(b).

Back to Citation

758.  Under rule 206(4)-2(d)(6), a qualified custodian includes a “bank,” i.e., a “bank” as defined in section 202(a)(2) of the Advisers Act or a savings association that meets certain requirements. The definition of “bank” includes (i) any banking institution organized under the laws of the United States, (ii) any member bank of the Federal Reserve System, and (iii) any other banking institution or trust company, “whether incorporated or not, doing business under the laws of any State or of the United States, a substantial portion of the business of which consists of receiving deposits or exercising fiduciary powers similar to those permitted to national banks under the authority of the Comptroller of the Currency,” which is “supervised and examined by State or Federal authority” having supervision over banks, and which is “not operated for the purpose of evading the provisions” of the Advisers Act.

Back to Citation

759.  Under the Advisers Act custody rule, qualified custodians include broker-dealers registered under section 15(b)(1) of the Securities Exchange Act of 1934 (15 U.S.C. 78o(b)(1)) and that are holding the client assets in customer accounts. See rule 206(4)-2(d)(6).

Back to Citation

760.  Under the Advisers Act custody rule, qualified custodians include futures commission merchants registered under section 4f(a) of the CEA (7 U.S.C. 6f(a)) but only with respect to clients' funds and security futures, or other securities incidental to transactions in contracts for the purchase or sale of a commodity for future delivery and options thereon. See rule 206(4)-2(d)(6).

Back to Citation

761.   See rule 206(4)-2(d)(6).

Back to Citation

762.   See infra section IV.B.2.d).

Back to Citation

763.   See rule 206(4)-2(b)(1).

Back to Citation

764.   See rule 206(4)-2(a)(4). See also rule 206(4)-2(b)(3) for an exception from independent examinations for advisers that have custody solely because they have authority to deduct fee from client accounts and rule 206(4)-2(b)(6) for an exception from independent examinations for advisers that have custody solely because a related person holds the adviser's client assets and the related person is operationally independent of the adviser.

Back to Citation

765.   See rule 206(4)-2(a)(2).

Back to Citation

766.   See rule 206(4)-2(a)(3).

Back to Citation

767.   See rule 206(4)-2(a)(5).

Back to Citation

768.   See rule 206(4)-2(b)(4).

Back to Citation

769.   See rule 206(4)-2(a)(6).

Back to Citation

770.   See rule 206(4)-2(a)(6).

Back to Citation

771.  For example, an adviser that is dually-registered as a broker-dealer would meet the definition of qualified custodian.

Back to Citation

772.   See rule 206(4)-2(b)(5); supra footnote 751. While the Advisers Act custody rule does not apply with respect to accounts of regulated funds, the Advisers Act requires the adviser to exercise fiduciary duty within the scope of its relationship with the regulated fund. The scope of an adviser's services to the fund—and the limitations on the adviser's authority—are typically set forth with substantial specificity in its agreement with the fund. The adviser has a duty of care in performing any responsibilities set forth in the agreement related to the selection and oversight of a permitted custodian. See Standard of Conduct Release, supra footnote 120.

Back to Citation

773.  Various provisions of the Investment Company Act, including section 17(f), are incorporated by statute to apply to BDCs to the same extent as if the BDC was a registered closed-end investment company. See 15 U.S.C. 80a-58.

Back to Citation

774.   See section 17(f)(1) of the Investment Company Act; rules 17f-1 to 17f-7.

Back to Citation

775.  Under section 17(f)(1) of the Investment Company Act, a permitted custodian includes a “bank” as defined in section 2(a)(5) of the Act that meets the qualification requirements of section 26(a)(1) of the Act. The definition of “bank” includes (i) any depository institution (as defined in section 1813 of title 12) or any branch or agency of a foreign bank (as such terms are defined in section 3101 of title 12), (ii) any member bank of the Federal Reserve System, and (iii) any other banking institution or trust company, “whether incorporated or not, doing business under the laws of any State or of the United States, a substantial portion of the business of which consists of receiving deposits or exercising fiduciary powers similar to those permitted to national banks under the authority of the Comptroller of the Currency,” which is “supervised and examined by State or Federal authority” having supervision over banks, and which is “not operated for the purpose of evading the provisions” of the Investment Company Act.

Back to Citation

776.  Under section 17(f)(1)(B) of the Investment Company Act (15 U.S.C. 80a-17(f)(1)(B)) and rule 17f-1 thereunder, broker-dealers that are members of a national securities exchange are permitted custodians under certain conditions. See rule 17f-1.

Back to Citation

777.  A “securities depository” is a clearing corporation that is registered with the Commission as a clearing agency, or a Federal reserve bank or other person authorized to operate the Federal book-entry system for U.S. Treasury securities. Under the Investment Company Act custody rules, securities depositories may custody regulated funds' assets under certain conditions. See rule 17f-4.

Back to Citation

778.  Under the Investment Company Act custody rules, futures commission merchants are permitted custodians under certain conditions and only as necessary to effect a fund's transactions in exchange-traded futures contracts and commodity options. See rule 17f-6.

Back to Citation

779.   See rule 17f-5.

Back to Citation

780.   See rule 17f-7.

Back to Citation

781.   See rule 17f-1(b).

Back to Citation

782.   Id.

Back to Citation

783.   See rule 17f-2.

Back to Citation

784.   See sections 30(a), 30(e), 30(g), and 32(a) of the Investment Company Act, section 13(a)(2) of the Securities Exchange Act, and rule 13a-1 under the Securities Exchange Act.

Back to Citation

785.   See rule 204-2(b).

Back to Citation

786.   Id.

Back to Citation

787.   See rules 31a-1 and 31a-2. 15 U.S.C. 80a-63 subjects BDCs to the Investment Company Act recordkeeping rules.

Back to Citation

788.   See rule 31a-1(b)(1).

Back to Citation

789.  State-chartered banks are also regulated at the State level. See infra section IV.B.2.e).

Back to Citation

790.   See 12 CFR 9.1 et seq. (rules governing fiduciary powers of national banks); 12 CFR 150.10 et seq. (rules governing fiduciary powers of Federal savings associations).

Back to Citation

791.  OCC, Custody Services, Comptrollers Handbook (Jan. 2002) available at www.occ.gov/​publications-and-resources/​publications/​comptrollers-handbook/​files/​custody-services/​index-custody-services.html. While this guidance is not part of OCC regulations, we believe that entities subject to OCC regulations observe this guidance as best practice.

Back to Citation

792.   Id. at 15.

Back to Citation

793.   Id. at 6-7.

Back to Citation

794.   Id. at 12, 29-31.

Back to Citation

795.   See 12 CFR 53.1 through 53.4 (OCC); 12 CFR 225.300 through 225.303 (Federal Reserve Board); 12 CFR 304.21 through 24 (FDIC).

Back to Citation

796.   See 17 CFR 240.3a40-1; supra text accompanying footnote 405.

Back to Citation

797.   See supra footnote 410 and accompanying text.

Back to Citation

798.   See 17 CFR 240.15c3-3. Specifically, see rules 15c3-3(b)(1) (requirement for a carrying broker-dealer to promptly obtain and maintain the physical possession or control of all fully-paid securities and excess margin securities carried for the account of customers); 15c3-3(c) (securities must be held in one of several locations specified in the rule and free of liens or any other interest that could be exercised by a third-party to secure an obligation of the carrying broker-dealer); 15c3-3(e) (requiring a carrying broker-dealer to maintain a reserve of funds or securities in an account at a bank that is at least equal in value to the net cash owed to customers, where the amount of net cash owed to customers is computed weekly or daily as of the close of the last business day of the week pursuant to the formula set forth in rule 15c3-3a); and 15c3-3(f) (requiring written notification that the bank was informed that cash or securities are being held for the exclusive benefit of the broker-dealer's customers and account holders, separate from the broker-dealer's other accounts; and that the broker-dealer must have a written contract with the bank providing that the cash or securities will not be used as security for a loan to the broker-dealer by the bank, and will not be subject to any right, charge, security interest, lien, or claim in favor of the bank or any person claiming through the bank).

Back to Citation

803.   See 17 CFR 240.17a-11, rule 17a-11(a) (same-day notice of insolvency or deficiency in meeting net capital requirements); 17a-11(b) (prompt notice, within no later than 24 hours, of certain net capital events); 17a-11(d) (notice within 24 hours after discovery of—or after notification by an independent public accountant of—a material inadequacy or material weakness, and a corrective action report within 48 hours thereafter); 17a-11(f) (immediate notice of failure to make a required deposit in a special reserve account for the exclusive benefit of security-based swap customers).

Back to Citation

805.   See 17 CFR 240.17a-5. Rule 17a-5(f)(1) provides that the independent public accountant “must be registered with the Public Company Accounting Oversight Board if required by the Sarbanes-Oxley Act of 2002.”

Back to Citation

806.   See 12 CFR 220.1 et seq.

Back to Citation

807.   See FINRA rule 4210(d). Rule 4210 prescribes initial margin requirements for non-equity securities that Regulation T does not address and specifies maintenance requirements for margin accounts. See Overview of Margin Requirements, FINRA, www.finra.org/​rules-guidance/​key-topics/​margin-accounts (last visited May 8, 2026).

Back to Citation

808.   See FINRA rule 3110(a).

Back to Citation

809.   See FINRA rule 3120(a)(1). In addition, a broker-dealer member must create additional supervisory procedures or amend existing supervisory procedures when a need is identified by testing and verification. See FINRA rule 3120(a)(2). Designated individual(s) must submit to the broker-dealer member's senior management no less than annually, a report detailing each member's system of supervisory controls, the summary of the test results and significant identified exceptions, and any additional or amended supervisory procedures created in response to the test results.

Back to Citation

810.   See FINRA rule 3130(b).

Back to Citation

811.   See FINRA rule 4370(a). Under rule 4370(b), each member must update its plan in the event of any material change to its operations, structure, business or location, and must conduct an annual review to determine whether any modifications are necessary in light of changes. Rule 4370(c) specifies the elements that comprise a business continuity plan, including, inter alia, all mission-critical systems.

Back to Citation

812.   See FINRA rule 4530(b).

Back to Citation

813.  Rule 17f-1 under the Investment Company Act permits funds to custody their securities and other similar investments with a broker-dealer that is a member of a national securities exchange.

Back to Citation

814.   See, e.g., NYSE rule 3130(b).

Back to Citation

815.   See, e.g., NYSE rule 4110(a).

Back to Citation

816.   See, e.g., NYSE rule 4370(a).

Back to Citation

817.   See, e.g., Nasdaq General 9 section 20 (incorporating FINRA rule 3110); Nasdaq General 9 section 21 (incorporating FINRA rule 3120).

Back to Citation

819.   See NFA Interpretive Notice 9070.

Back to Citation

820.   See rule 17f-4.

Back to Citation

822.  U.C.C. 8-504(b), (c), 8-509(a) (Am. L. Inst. & Unif. L. Comm'n 2021).

Back to Citation

823.   See N.Y. Comp. Codes R. & Regs. tit. 23, § 200.3(c)(1); see also Virtual Currency Business Licensing, NNYDFS, www.dfs.ny.gov/​virtual_​currency_​businesses#bitlicense-faqs (last visited Apr. 22, 2026).

Back to Citation

824.   See NYDFS Organization of a Limited Purpose Trust Company, available at www.dfs.ny.gov/​apps_​and_​licensing/​banks_​and_​trusts/​procedure_​certificate_​merit_​trust_​comp (last visited June 23, 2026); see generally N.Y. Banking Law Art. XV; N.Y. Comp. Codes R. & Regs. tit. 3, Sup. Pol. CB 1.3 (Limited Purpose Organizations).

Back to Citation

825.   See Wyo. Stat. Ann. § 34-29-104(a); 021.002.19 Wyo. Code R. §§ 1-12.

Back to Citation

826.   See Wyo. Stat. Ann. § 34-29-104(q).

Back to Citation

827.   See S.D. Codified Laws ch. 51A-6A.

Back to Citation

828.   See Comment Letter of BitGo Holdings, Inc. (May 8, 2023). (BitGo Trust Company Inc. subsequently obtained a national trust bank charter; see infra footnote 843.)

Back to Citation

829.  ERAs would also be affected by some of the proposed amendments to Form ADV. See infra footnote 830.

Back to Citation

830.  Form ADV data for the reporting period ending December 2025 with filings received through March 31, 2026. In addition, there were 5,921 ERAs, which would be affected by some of the proposed amendments to Form ADV. See supra section II.J.1.c); infra footnotes 1222 and 1221. Four of those ERAs are registered with a state securities authorities and would be affected by all the proposed amendments to Form ADV. See infra footnote 1220.

Back to Citation

831.   See supra footnote 830. The term “regulatory assets under management” refers to an adviser's assets under management as reported in response to Item 5.F. of Part 1A of Form ADV. See Form ADV, Item 5.F. of Part 1A.

Back to Citation

832.   See supra footnote 830. The total may not add to 100% due to rounding.

Back to Citation

833.  If a client fits into more than one category, Form ADV requires an adviser to select one category that most accurately represents the client (to avoid double counting clients and assets).

Back to Citation

834.  This category may also include other pooled investment vehicles such as collective investment trusts.

Back to Citation

835.  Private funds are not required to be registered or regulated as investment companies under the Federal securities laws. See sections 3(c)(1) and 3(c)(7) of the Investment Company Act.

Back to Citation

836.  UITs and FACCs are currently eligible to use rules 17f-4 and 17f-6, which would be amended under the proposal, and rule 17f-3, which would be rescinded under the proposal. However, UITs and FACCs would not be able to rely on proposed rules 17f-8 (Custody of Crypto Assets by State Trust Companies) and 17f-9 (Custody of Crypto Assets by Registered Investment Companies and Business Development Companies). See supra footnote 3; section II.F. In addition, UITs and FACCs are subject to recordkeeping requirements and would be subject to proposed rule 31a-1(b)(14). See supra footnote 652.

Back to Citation

837.  Net assets for mutual funds, ETFs, closed-end funds, MCSAs, and money market funds are reported in Item C.19 of Form N-CEN. Total net assets reflect the sum of monthly average net assets for mutual funds and ETFs, daily average net assets for money market funds, and total assets for UITs. ETF counts include mutual funds offering at least one ETF share class, and ETF net assets include the assets of those mutual funds. Among the ETFs reported, three are money market ETFs.

Back to Citation

838.  BDC counts and net asset value information were obtained from Form 10-K filings for 2025.

Back to Citation

839.  Total asset value for UITs was obtained from Item F.11 of Form N-CEN and, for the funds for which Item F.11 was not available, from Item F.14 of Form N-CEN. FACCs issue face-amount certificates rather than fund shares and do not maintain a net asset value comparable to other registered fund types; therefore, no total net asset figure is reported for FACCs.

Back to Citation

840.   See Investment Company Institute (“ICI”), 2026 Investment Company Fact Book, available at www.ici.org/​system/​files/​2026-04/​2026-factbook.pdf. In addition, the Federal Reserve's Survey of Consumer Finance for 2022 found that 11.5% of U.S. families owned pooled investment funds directly and that 54.5% owned retirement accounts, which could be invested in pooled investment funds. In the survey, pooled investment funds include stock funds, tax-free bond funds, government bond funds, and other bond funds but exclude money market funds. See Bd. Governors Fed. Rsrv. Sys., Changes in U.S. Family Finances from 2019 to 2022, Evidence From the Survey of Consumer Finances (Oct. 2023), available atwww.federalreserve.gov/​publications/​files/​scf23.pdf.

Back to Citation

841.   See supra sections IV.B.2.a) and IV.B.2.b). With respect to shares of a mutual funds, investment advisers may also custody funds and securities with the fund's transfer agent, instead of with a permitted custodian. See rule 206(4)-2(b)(1).

Back to Citation

843.   Id. Active as of March 31, 2026. We understand that four of the national trust banks are organized to provide digital asset services. These include Anchorage Digital N.A., BitGo Bank & Trust N.A., Fidelity Digital Assets N.A., and Paxos Trust Company N.A. See OCC News Release 2021-6, OCC Conditionally Approves Conversion of Anchorage Digital Bank (Jan. 13, 2021), www.occ.gov/​news-issuances/​news-releases/​2021/​nr-occ-2021-6.html and OCC News Release 2025-125, OCC Announces Conditional Approvals for Five National Trust Bank Charter Applications (Dec. 12, 2025), www.occ.gov/​news-issuances/​news-releases/​2025/​nr-occ-2025-125.html.

Back to Citation

845.  This number is as of April 2026. This number was obtained by pulling all active banks from the FDIC BankFind Suite tool, keeping only the institutions chartered at the State level, and removing those institutions chartered in U.S. territories that are not states of or the District of Columbia ( i.e., Federated States of Micronesia, Guam, Puerto Rico, U.S. Virgin Islands). See BankFind Suite: Find Insured Banks, FDIC, banks.data.fdic.gov/​bankfind-suite/​bankfind (last updated June 19, 2026).

Back to Citation

846.  This includes limited-purpose trust companies. This number was obtained from the State banking regulators' websites. It is possible that some State trust companies are chartered in more than one state and therefore that the same entity is counted more than once in our estimates. This analysis was performed in April 2026. State trust companies must meet the definition of bank under the custody rules to serve as permitted custodians. Their eligibility may require a case-by-case analysis. See supra section I.A.2. Hence, this number should be considered as an upper bound on the number of State-chartered trust companies that are currently permitted custodians. Under the proposed State trust company rules, State trust companies would be permitted custodians under certain conditions. See proposed rules 223-1(d)(13)(v) and 17f-8.

Back to Citation

847.  As of Dec. 31, 2025. See SEC, Statistics & Data Visualizations, Transfer Agents, available atwww.sec.gov/​data-research/​statistics-data-visualizations/​transfer-agents.

Back to Citation

848.  These numbers are based on FOCUS filings as of the end of the fourth quarter of 2025. Per EDGAR Form Custody: A “carrying broker-dealer” is a broker-dealer that carries customer or broker or dealer accounts and receives or holds funds or securities for those customers.

Back to Citation

849.   See Consolidated Audit Trail (“CAT”), Reference Data, available atwww.catnmsplan.com/​reference-data.

Back to Citation

850.  This number is as of February 28, 2026. See CFTC, Financial Data for FCMs, available atwww.cftc.gov/​MarketReports/​financialfcmdata/​index.htm.

Back to Citation

852.   See rules 206(4)-2(a)(4); 206(4)-2(b)(4). An SEC staff no-action letter indicates that the staff would not recommend enforcement action to the Commission if advisers exercise limited authority pursuant to a SLOA without undergoing an annual surprise examination, if the SLOA arrangement meets certain specified conditions. See IAA SLOA No-Action Letter, supra footnote 544.

Back to Citation

853.   See rules 17f-1(b)(4), 17f-2(f).

Back to Citation

854.   See sections 30(e), 30(g), and 32(a) of the Investment Company Act and rules 13a-1 and 13a-2 under the Securities Exchange Act.

Back to Citation

855.   See rule 1-02(d) of Regulation S-X.

Back to Citation

856.   See section 2(a)(7) of the Sarbanes-Oxley Act of 2002, 15 U.S.C. 7201(a)(7), for the definition of “issuer.”

Back to Citation

857.  Based on advisers' responses to Item 9.C.(3) of Part 1A of Form ADV. Form ADV data for the reporting period ending December 2025 with filings received through March 31, 2026.

Back to Citation

858.  Based on advisers' responses to Item 9.C.(2) of Part 1A of Form ADV.

Back to Citation

859.  Based on advisers' responses to Item 9.C.(4) of Part 1A of Form ADV. Many advisers do not report using the services of independent public accountants in their compliance with the Advisers Act custody rule. This can be because they do not have custody of client assets, because they only advise regulated funds and are therefore not subject to the Advisers Act custody rule, or because they rely on another exception to the surprise examination requirement ( see rules 206(4)-2(b)(3) and 206(4)-2(b)(6)).

Back to Citation

860.   See Registered Firms, PCAOB, pcaobus.org/​oversight/​registration/​registered-firms (last visited June 23, 2026).

Back to Citation

861.  The frequency of inspection depends on the number of issuers for which a registered public accounting firm has issued audit reports during specified time periods. See PCAOB rules 4003(a), (b). A percentage of registered public accounting firms are also subject to regular inspection based on having played a substantial role in the preparation or furnishing of an audit report with respect to an issuer, without having issued an audit report with respect to an issuer during a specified reporting period. See PCAOB rule 4003(h). On an interim basis, under PCAOB rule 4020T, the Board also conducts a program of inspection to assess the policies, practices, and procedures of any registered public accounting firm related to the performance of audits, or the issuance of audit reports, for brokers and dealers. See Robert Van Grover Esq., Seward & Kissel LLP, SEC Staff No-Act. Letter (Dec. 11, 2019), available at www.sec.gov/​investment/​grover-seward-kissel-121119-rule206 (investment adviser's engagement of a public accounting firm in connection with the adviser's custody of client funds and securities, when the accounting firm is registered with the Board, engaged to audit broker-dealer financial statements, and subject to the Board's interim program of inspection). We include as subject to regular inspection by the PCAOB firms that reported the following audit report activities in their three most recent annual reports: issued an audit report for at least one broker-dealer; issued an audit report for at least one issuer; did not issue an audit report for a broker-dealer, but played a substantial role in an audit of at least one broker-dealer; did not issue an audit report for an issuer, but played a substantial role in an audit of at least one issuer. See PCAOB, Registered Firms, available at pcaobus.org/​oversight/​registration/​registered-firms.

Back to Citation

862.  Based on advisers' responses to section 9.C.(3), section 9.C.(4), and section 9.C.(5) of Schedule D of Form ADV. Form ADV data for the reporting period ending December 2025 with filings received through March 31, 2026.

Back to Citation

863.  We are also requesting comment on the types of services providers that could be affected by the proposed rules and amendments. See infra section IV.F.

Back to Citation

864.  This analysis is based on advisers' responses to Items 9.A. and 9.B. of Part 1A of Form ADV from data for the reporting period ending December 2025 and received through March 31, 2026. The instructions to Item 9.A. of Part 1A of Form ADV provide that an adviser that has custody solely because (i) it deducts advisory fees directly from client accounts, or (ii) an operationally independent related person has custody of client assets in connection with advisory services provided to clients, should answer “No” in response to Item 9.A.(1), which asks whether the adviser has custody of client assets. Hence, the actual number of advisers with custody of client assets is likely larger.

Back to Citation

865.  Form N-CEN filings for the period ending December 2025, with filings received through March 31, 2026.

Back to Citation

866.  While regulated funds can “self-custody” their assets under certain conditions, these conditions include references to “physical facilities.” Hence, we do not expect any of the assets currently in self-custody at regulated funds to be crypto assets. See rule 17f-2; supra text accompanying footnote 783.

Back to Citation

867.  Commission staff has also issued responses to 70 FAQs on a wide range of topics about the Advisers Act custody rule. See Custody Rule FAQs, supra footnote 572.

Back to Citation

868.  This list is likely not exhaustive but reflects Commission staff's experience based on examinations of and engagement with advisers. In addition, this list does not include custodians that do not specialize in crypto assets but that may nevertheless provide custodial services for crypto assets.

Back to Citation

869.  Advisers are required to report on Form ADV information, such as name, for each custodian that holds 10% or more of the adviser's aggregate separately managed account RAUM. See Form ADV Item 5.K.(4) and section 5.K.(3) of Schedule D. In addition, advisers are required to report information for each custodian holding assets of a private fund advised by the adviser. See Form ADV section 7.B.(1)B of Schedule D. Because of the 10% threshold for separately managed accounts and because of the limitations of our list of crypto custodians ( see supra footnote 868), the list of advisers that we identify is unlikely to include all advisers with custody of crypto assets. Advisers do not have to report custodian information for the registered investment companies that they advise. This information is instead collected on Form N-CEN. See supra section IV.B.2.

Back to Citation

870.  However, these assets may not be client “funds or securities” and may therefore not be covered by the Advisers Act custody rule. See supra footnote 754 and accompanying text. In addition, we analyze below the type of custodians that are used by these advisers. See infra section IV.B.4.c).

Back to Citation

871.  We analyzed advisers' most recent Form ADV Part 2A filing, taking into account filings received between January 1, 2025 and June 30, 2026. Our analysis covered 15,964 registered advisers, or 97% of the 16,442 registered advisers and 86% of the total RAUM of registered advisers. See supra section IV.B.3.a). The remaining advisers were not included because they are exempt from the requirement to file Part 2A for Form ADV (337 advisers) or for other reasons (141 advisers). We asked a large language model (“LLM”, Anthropic Sonnet 5) to determine whether the adviser is giving or planning to give investment advice related to crypto assets. The LLM model used does not give users control of the temperature setting. The model does not have access to the internet, and the internet cut-off date was January 2026 ( see How Up-to-Date is Claude's Training Data? Claude Support, support.claude.com/​en/​articles/​8114494-how-up-to-date-is-claude-s-training-data (last visited July 24, 2026)). We first converted the Form ADV Part 2A filings from PDF to text, then uploaded each filing to the LLM and queried the LLM about the filing with the following prompt: “You are reading one adviser's Form ADV brochure: either Part 2A (firm brochure) or Part 2A Appendix 1 (wrap fee). | Definition: “crypto assets”, also known as digital assets, include, but are not limited to, digital commodities ( e.g., Bitcoin, Ether, Solana), digital collectibles, digital tools, stablecoins (including payment stablecoins), tokenized deposits, and digital securities (including tokenized securities). | Task: Answer YES if the brochure indicates the adviser provides OR plans to provide advice involving crypto assets, based on client facing signals ( e.g., services/strategies offered to clients, portfolio level exposure, program features, custody/brokerage handling for client accounts, or portfolio manager selection); otherwise answer NO. Prioritize the items listed below, but consider the entire document provided. | Prioritized headings verbatim): | Part 2A: (firm brochure) | • Item 4—Advisory Business | • Item 8—Methods of Analysis, Investment Strategies, and Risk of Loss | • Item 15—Custody | • Item 16—Investment Discretion | Appendix 1 (wrap fee) | • Item 4—Services, Fees and Compensation | • Item 6—Portfolio Manager Selection and Evaluation | Inference rule (to reduce false positives): | • Count as YES only if crypto assets are tied to client accounts, portfolios, strategies, program participation, manager selection/evaluation, or custody/brokerage policies for clients. | • Do NOT count as YES if mentions are limited to: employee or “Code of Ethics” personal trading restrictions; personnel biographies, credentials, or certifications; general affiliations or activities of related/third party entities without a clear link to services provided to clients; generic market commentary or research monitoring with no client service linkage. | • If both client facing and non client mentions appear, base the decision on the client facing evidence. | Output (exactly): YES or NO | Then 1-2 exact verbatim quotes (≤200 chars each) that your answer is based on, each labeled with the Item heading and page/section if available.” The main text reports the number of advisers with “yes” answers obtained from this prompt. If an adviser submitted more than one brochure, the adviser is counted as “yes” if the LLM returned a “yes” answer for at least one of the adviser's brochures. We note that a large language model analysis can result in both false positives and false negatives, and that this analysis is stochastic in nature. Hence, re-running the same algorithm could yield different results. To assess and improve the accuracy of the results, we performed two additional steps. First, we ran an additional analysis of the results by using the explanation provided by the LLM as input for a second analysis and by querying the same LLM with the following prompt: “You are a strict binary classifier. Given a response to the question represented by the prompt, decide if the answer is yes or no. Return only one word: yes or no.” This process identified one false negative and 334 false positives. Second, we manually reviewed the LLM's “yes” responses (reflecting the corrections made as a result of the first additional step) to confirm that the explanation provided by the LLM was consistent with the “yes” answer given. When a discrepancy was observed, we analyzed the adviser's brochure manually. This process found a false positive rate below 3%. The results reported in the main text reflect corrections made following these two additional steps. According to the analysis, 14,466 advisers neither currently provide nor plan to provide advice involving crypto assets. However, some of these advisers may have been incorrectly categorized; therefore, the reported figure may represent a lower bound for the number of advisers providing or planning to provide investment advice related to crypto assets. For additional robustness, we compared the set of advisers identified with this analysis to the set of 136 advisers that we identified as using one or more of the identified crypto custodians ( see supra footnote 869). We found that, of the 136 advisers that reported using one or more identified crypto custodians, 13 were not identified by our analysis as providing or planning to provide crypto-related services. A manual review of these 13 advisers' brochures concluded that the brochures of 11 advisers do not indicate that the advisers are providing or planning to provide crypto-related services. The manual review of the remaining two advisers' brochures concluded that the brochures indicate that the advisers are providing or planning to provide crypto-related services.

Back to Citation

872.   See supra footnote 869 and accompanying text.

Back to Citation

873.  Based on staff analysis of data from Morningstar Direct. In our analysis, we include all funds in the Morningstar category “Digital Asset Funds.” Morningstar describe “Digital Asset Funds” as those that “invest the majority of their assets into one or more broadly classified areas including Decentralized Finance (DeFi) assets, stable coins, currency assets, smart contracts platforms, exchange assets, privacy assets, yield farming, and nonfungible tokens (NFTs) among others. Portfolios may gain access to digital assets through physical or derivative exposures and incorporate both long only investments and other hedging techniques. To qualify for inclusion, funds in this category must have a material portion of risk coming from digital assets.” See Digital Asset Funds, Morningstar,www.morningstar.com/​best-investments/​digital-asset-funds (last visited May 26, 2026). Mutual funds and ETFs refer to funds that are registered as open-end investment companies and are subject to the Investment Company Act. Advisers of such funds are required to be registered investment advisers and are subject to the Advisers Act. In this release, ETPs refer to those commodity-based trusts that are not registered investment companies, and thus are not subject to the Investment Company Act, and whose shares are instead registered under the Securities Act of 1933. While ETPs typically provide crypto exposure by holding spot crypto assets, ETFs and mutual funds generally provide crypto exposure by tracking the price of futures contracts on underlying crypto assets. However, ETFs holding spot crypto assets are also listed and available for trading.

Back to Citation

874.  There are different reasons why the regulated funds identified as crypto asset funds in the analysis above may not use one of the identified crypto custodians. First, these funds may provide exposure to crypto assets without directly holding them (for example, by holding crypto asset futures). See supra footnote 873. Second, they may be using as custodian an entity that does not specialize in crypto assets but still provides crypto custody services. Third, they could be using an entity that specializes in crypto assets but that is not included in our list of identified crypto custodians. See supra footnote 868.

Back to Citation

875.   See OCC Interpretative Letter 1183, supra footnote 44; OCC Interpretive Letter No. 1184, supra footnote 44, Clarification of Bank Authority Regarding Crypto-Asset Custody Services (2025), available at www.occ.treas.gov/​topics/​charters-and-licensing/​interpretations-and-decisions/​2025/​int1184.pdf; OCC, Interpretive Letter No. 1170, Authority of a National Bank to Provide Cryptocurrency Custody Services for Customers (2020), available at www.occ.gov/​topics/​charters-and-licensing/​interpretations-and-decisions/​2020/​int1170.pdf.

Back to Citation

876.   See Federal Reserve Board, FDIC, and OCC, Crypto-Asset Safekeeping by Banking Organizations (2025), available at www.fdic.gov/​news/​press-releases/​2025/​agencies-issue-joint-statement-risk-management-considerations-crypto-asset (“Interagency Crypto Statement”).

Back to Citation

877.   See OCC, OCC Announces Conditional Approvals for Five National Trust Bank Charter Applications (Dec. 12, 2025), available at www.occ.gov/​news-issuances/​news-releases/​2025/​nr-occ-2025-125.html.

Back to Citation

879.  As of April 15, 2026, there are 10 pending applications to the OCC for new national bank charters (including national trust bank charters) or conversions to national banks submitted by entities planning to offer digital asset products or services, including crypto-assets. See www.occ.gov/​topics/​charters-and-licensing/​digital-assets-licensing-applications/​index-digital-assets-licensing-applications.html.

Back to Citation

880.   See, e.g., OCC Letter, Re: Application by BitGo Trust Company, Inc., Sioux Falls, South Dakota to Convert to a National Bank and Operate with Full Trust Powers (Dec. 12, 2025) (“BitGo Trust Co. Dec. 12, 2025”), available at www.occ.gov/​news- issuances/news-releases/2025/nr-occ-2025-125c.pdf and OCC Letter, Re: Applications to (1) Convert Fidelity Digital Asset Services, LLC, New York, New York to an Uninsured National Trust Bank Fidelity Digital Assets, National Association, New York, New York (2) Charter Fidelity Digital Assets Temporary Bank, National Association, Boston, Massachusetts and (3) Merge Fidelity Digital Assets, National Association with and into Fidelity Digital Assets Temporary Bank, National Association and Request to Waive Residency Requirements (collectively, Application), available at occ.gov/​news-issuances/​news-releases/​2025/​nr-occ-2025-125d.pdf.

Back to Citation

881.  This estimate was obtained by analyzing the website of the 484 trust companies we identified, with some exceptions. (For some State trust companies, we were unable to find an associated website. In some of these cases, we relied on alternative sources such as regulatory filings. For other cases, we could not find any reliable source and classified the State trust company as not specializing in crypto asset services.) This analysis was performed in May 2026. While this analysis allowed us to identify the State trust companies that appear to offer services mainly related to crypto assets, it is possible that these entities also offer custodial services for traditional assets or that other State trust companies offer crypto asset custody services.

Back to Citation

882.   See supra sections I.A.2 and II.C.1. In addition, on September 30, 2025, IM staff issued a no-action letter regarding the use of State trust companies as crypto asset custodians for purposes of the custody rules. The letter stated that IM staff would not recommend enforcement action to the Commission against an adviser or regulated fund if they elect to treat a State trust company as a bank for purposes of the custody rules for the placement and maintenance of advisory or regulated fund crypto assets and related cash and/or cash equivalents, subject to certain considerations designed to address whether the State trust company is capable of protecting crypto assets from loss, theft, misuse, and misappropriation. See supra footnote 50 and accompanying text. Like all staff statements, this letter has no legal force or effect and does not alter or amend applicable law.

Back to Citation

883.   See BD Crypto Custody Statement, supra footnote 191.

Back to Citation

884.  This statement includes broker-dealers that conduct a traditional securities business.

Back to Citation

885.   See BD Crypto Custody Statement, supra footnote 191. The measures relate to the broker-dealer's access to the crypto asset security and ability to transfer it; the broker-dealer's reasonably designed policies and procedures for evaluating the distributed ledger technology and related network for significant weaknesses or operational issues; the broker-dealer's awareness of any material security or operational problems or weaknesses; the broker-dealer's reasonably designed policies and procedures for protecting private keys against theft, loss, misuse, or accidental use; and the broker-dealer's reasonably designed policies and procedures for safekeeping and accessing crypto asset securities in the event of disruption, wind-down, or liquidation.

Back to Citation

886.   See supra section IV.B.1.

Back to Citation

887.  Some crypto trading platforms may be affiliated with business entities, such as State trust companies or broker-dealers, which could be permitted custodians under the current custody rules. See supra section IV.B.1. This would allow such trading platforms to provide custodial services to advisers and regulated funds consistent with the custody rules.

Back to Citation

888.   See supra footnote 869 and accompanying text. We have identified only one regulated fund using an identified crypto custodian. See supra section IV.B.4.b). Hence, this analysis focuses on advisers.

Back to Citation

889.  Almost all of these 136 advisers reported using an identified crypto custodian for one or more of the private funds that they manage. Only 13 advisers, with a combined RAUM of $7.84 billion, reported using an identified crypto custodian for separately managed accounts only.

Back to Citation

890.  Different advisers may report the same custodian under different names. We have grouped together custodian names that refer to the same legal entity and custodian type to the best of our abilities. Where related entities are custodians of different types, such as when there is a national trust bank and a foreign institution operated by a related entity, or another custodian type, we have counted those separately in each corresponding custodian type.

Back to Citation

891.  Some of these custodians may not be qualified custodians. Advisers are required to report on Form ADV custodian information for all assets, as applicable, not only client “funds and securities.” Assets that are not client “funds and securities” are not covered by the Advisers Act custody rule, both current and as proposed, and therefore are not required to be maintained at a qualified custodian.

Back to Citation

892.  We do not have data on the holdings of these private funds and therefore do not know whether these crypto assets are “funds or securities,” which would make them subject to the Advisers Act custody rule, or what proportion of their holdings is in crypto assets. See infra section IV.F.

Back to Citation

893.  We did not identify any liquidity funds or real estate funds using an identified crypto custodian.

Back to Citation

894.   See supra sections II.A.1 and footnote 753.

Back to Citation

895.  Not all advisers take custody of client assets. An investment adviser has custody of client funds and securities when the adviser, or its related person, holds, directly or indirectly, the client funds or securities, or has any authority to obtain possession of them. See rule 206(4)-2(d)(2); supra sections IV.B.2 and IV.B.4.a).

Back to Citation

896.   See rules 206(4)-2(a) and 206(4)-2(b)(5); supra section IV.B.2.

Back to Citation

897.   See Investment Company Act section 17(f); rules 17f-1 to 17f-7; supra section IV.B.2. The custody rules apply to funds and securities with respect to the Advisers Act and to securities and similar investments with respect to the Investment Company Act.

Back to Citation

898.   See supra footnote 772.

Back to Citation

899.  The effect on clients and investors depends on the extent to which custodians, advisers, and regulated funds compensate them for the assets that were stolen, lost, misused, or misappropriated.

Back to Citation

900.   See supra sections I.A.1 and IV.B.1.

Back to Citation

901.  For example, the bearer nature of the private keys used to transfer crypto assets leads to heightened challenges of recovering many types of crypto assets when lost or stolen as opposed to legal and beneficial ownership structures in traditional assets.

Back to Citation

902.  For example, custodial practices for crypto assets typically include secure key governance and management ( i.e., choosing the appropriate type of wallet) and interaction with distributed ledger technology networks. Additionally, crypto asset custodians often implement safety protocols such as multi-signature or multi-party computation to bolster the security of clients' assets. See supra section IV.B.1. See also the FRB Statement, supra footnote 196, for a discussion of certain risk-management considerations for banking organizations offering custodial services for crypto assets.

Back to Citation

903.   See, e.g., TDC Comment Letter I, supra footnote 38 (stating that “every blockchain protocol generally requires the development of a custom technology build, which takes a significant amount of engineering work (often taking two to three months), by any financial institution agreeing to provide custody services for the given asset/token”). However, entities specializing in crypto asset custody services may nevertheless face lower fixed costs when offering services for a new crypto asset or network compared to firms that specialize in traditional asset custody and that are looking to enter the market of crypto asset custody services.

Back to Citation

904.  These challenges can also result in asymmetric information problems, which can lead to principal-agent problems. See infra footnote 921 and accompanying text.

Back to Citation

905.   See supra section I.A.2.

Back to Citation

906.  In addition, it is important to distinguish between a lack of available custodians that arises naturally from economies of scale (where high fixed costs make it unprofitable for firms to enter a market where demand is small) and a lack of available custodians that results from additional barriers, such as regulatory requirements that restrict entry. Under the current custody rules, regulatory constraints such as the requirement to meet the definition of “bank” for State trust companies may be limiting entry beyond what would be economically efficient.

Back to Citation

907.  The integrity of a distributed ledger technology network depends on its decentralized nature, which prevents any single entity, or a small number of entities, from manipulating network operations for their own benefit, for example by reversing transactions. See, e.g., corporatefinanceinstitute.com/​resources/​cryptocurrency/​what-is-a-51-attack/​. In addition, an asset held in a concentrated group of custodians may be at higher risk of cybersecurity incidents, which could create systemic vulnerabilities and compromise the entire blockchain. See, e.g., Dechert Comment Letter (arguing for measures to avoid “the concentration of crypto assets in the hands of a few custodians, so that the failure of any one custodian or a cybersecurity breach at any one custodian is less likely to result in systemic consequences for the crypto asset ecosystem as a whole”).

Back to Citation

908.  Hence, there may be no or a very limited number of custodians available for crypto assets for which there is low demand or for newly-issued assets, for which demand is more likely to be uncertain. See supra section I.A.2. See also, e.g., TDC Comment Letter I, supra footnote 38. Custodians that would implement custody of client assets would seek to recover their costs through fees charged to their clients, and demand from these clients at those fee levels should be sufficient to enable custodians to recover their costs.

Back to Citation

909.   See supra text accompanying footnote 27; section II.A.1.d). See also Blockchain Association Comment Letter II (stating that “non-crypto asset-native custodians often are reluctant to retrieve `forked' or `airdropped' assets”).

Back to Citation

910.   See supra section IV.B.1. For example, when staking their assets, users typically earn rewards. See supra footnote 729.

Back to Citation

911.   See supra section I.A.2. These alternative custodians, by specializing in crypto assets, may also face lower costs when deciding to extend their services to additional assets or networks. See supra footnote 903 and accompanying text. This would make it more profitable for them to offer a wider variety of services.

Back to Citation

912.  In addition, it is possible that some advisers or regulated funds use a State trust company that does not meet the definition of “bank” as custodian for crypto assets. See supra footnotes 50 (discussing the 2025 State Trust Company NAL) and 877 and accompanying text.

Back to Citation

913.   See supra section I.A.2. It is also possible that some State trust companies do not meet the definition of bank under the custody rules. These State trust companies are not permitted custodians under the current custody rules.

Back to Citation

914.   See supra footnote 877 and accompanying text.

Back to Citation

915.  The organizers of a national bank or Federal savings association must present a business plan or operating plan that adequately addresses a number of statutory and policy considerations, such as the ability and experience of its management, the sufficiency of its capital for the volume and type of business, its expectation of profitability, and the safety and soundness of operations. See 12 CFR 5.20(e), (f), (h). The application will be reviewed for compliance with applicable banking laws and regulations, such as sections 23A and 23B of the Federal Reserve Act, 12 U.S.C. 371c, c-1, and Regulation W, 12 CFR part 223. See, e.g., BitGo Trust Co. Dec. 12, 2025.

Back to Citation

916.  For example, an adviser could know that some of its clients will invest in the asset after it launches.

Back to Citation

917.   See supra section I.A. An adviser is less likely to engage in unauthorized trading in a client's account when the adviser knows that the client will be receiving from the custodian an account statement detailing any trading activity. To mitigate the risks associated with self-custody, the current custody rules include additional requirements in the instances where the custodian is the adviser or a related party of the adviser. See, e.g., rule 206(4)-2(a)(6).

Back to Citation

918.  For example, records recorded onchain, particularly on public networks, can provide investors with low-cost options to verify the transaction history and could facilitate the identification of potential instances of misuse or misappropriation by the adviser.

Back to Citation

919.   See supra footnotes 701 and 903 and accompanying text.

Back to Citation

920.  When the adviser's client is not a regulated fund, the custodial services agreement is typically between the custodian and the adviser's client. Nevertheless, the Advisers Act custody rule imposes requirements on the adviser. It is also part of the adviser's fiduciary duty, which includes the entire relationship between the adviser and the client, to select and monitor a custodian that will act in the best interests of its client. See supra footnotes 121, 753, and 772 and accompanying text. Hence, even when the agreement does not involve the adviser directly, we expect that the adviser would, in many cases, negotiate the terms of the agreement on behalf of its client.

Back to Citation

921.  A principal-agent problem happens when the principal (here, the adviser, client, or regulated fund) comes into an agreement with the agent (the custodian) regarding the provision of services (the custody of crypto assets), but the principal's and the agent's incentives are not perfectly aligned. This situation can result in the agent taking actions that are different from those it agreed to take in its agreement with the principal, for example to increase its own profit. Under perfect information, that is, when the principal is able to fully observe the agent's actions, the terms of the agreement can generally be enforced. For example, the principal can withhold payment until the terms of the agreement have been fully reached, which significantly mitigates the principal-agent problem. Under asymmetric information, however, the principal is unable to fully observe the agent's actions and may therefore be unable to enforce the terms of the agreement. The costs associated with such conflict are referred to as agency costs. See, e.g., Michael C. Jensen & William H. Meckling, Theory of the Firm: Managerial Behavior, Agency Costs and Ownership Structure, 3 J. Fin. Econ. 305 (1976).

Back to Citation

922.   See supra section IV.B.2.d).

Back to Citation

923.  For example, the Interagency Crypto Statement applies to national banks, Federal savings association, Federal branches and agencies of foreign banks, and State-chartered banks, among others. See supra footnote 876 and accompanying text.

Back to Citation

924.   See supra section IV.B.2.e). In addition, because requirements under State law can vary significantly across States, this can make it more challenging for advisers and regulated funds to be familiar with them.

Back to Citation

925.  The asymmetric information could also be particularly acute in the case of self-custody by the adviser, since there is currently no regulatory framework covering advisers' custodial activities. Advisers are currently permitted to maintain client assets only if they or a related person meets the definition of qualified custodian. See supra section IV.B.2.a).

Back to Citation

926.  Under perfect information, these custodians would either lose their clients and therefore stop existing, or they would be forced to charge a price that reflects the true quality of the services that they provide.

Back to Citation

927.  An investor typically knows the name of the custodian chosen by the adviser or regulated fund, either because the custodial agreement is between the client and the custodian or through other disclosures such as Form N-CEN or Form ADV.

Back to Citation

928.  While an oversight failure can result in costs to an adviser, including a regulated fund's adviser, such as reputational costs or fiduciary liabilities, an adviser's oversight activities are at least partly unobservable to the adviser's clients or regulated fund's investors.

Back to Citation

929.  The magnitude of this inefficiency is likely to differ across different types of clients. For example, it is likely to be lower for the adviser clients or regulated fund investors that are regulated funds, private funds, or institutional investors such as pension plans since these entities are likely to have a higher ability to observe or independently monitor the adviser's or regulated fund's oversight of the custodial services provided by the custodian. See supra sections IV.B.3.a).

Back to Citation

930.   See infra sections IV.C.2, IV.C.3, and IV.C.4. Other proposed amendments, such as the proposed amendments to rule 17f-1 to permit regulated funds to use any broker-dealer registered with the Commission as custodians, where the broker-dealer's custody of the securities or similar investments is subject to the requirements of rule 15c3-3 under the Exchange Act, could also alleviate these challenges. See infra section IV.C.5.b).

Back to Citation

931.   See supra section II.A. The specific conditions are described in more detail in the sections below.

Back to Citation

932.  Different custody rules apply when the client is a regulated fund. See supra section IV.B.2.

Back to Citation

933.   See supra footnotes 877-879 and accompanying text.

Back to Citation

934.   See supra section I.A.1.

Back to Citation

935.   See supra section II.A.1. These points could continue to apply even if, as proposed, the set of qualified custodians were expanded to include State trust companies.

Back to Citation

936.   See supra section IV.C.1.

Back to Citation

937.   See supra footnote 916 and accompanying text.

Back to Citation

938.  An adviser that holds any key materials associated with its client's crypto asset would have self-custody of the crypto asset and would thus be required to maintain such key materials according to the proposed adviser self-custody rule. See proposed rule 223-1(d)(16) for the proposed definition of “self-custody” and proposed rule 223-1(b)(7); supra section II.A. However, if the adviser maintains clients' crypto assets through its related person acting in the capacity of a qualified custodian, it would not need to comply with the proposed adviser self-custody rule, but instead with proposed rule 223-1(a)(6). See supra section II.A.1.c).

Back to Citation

939.  Although regulated funds are generally excepted from the application of the Advisers Act custody rule, “client” for purposes of the proposed adviser self-custody rule would include regulated funds. Under the proposed fund self-custody rule, regulated funds would be permitted to place and maintain their crypto assets with their adviser if the adviser complies with the proposed adviser self-custody rule and if the fund complies with the additional requirements in the proposed fund self-custody rule. See supra section II.B; proposed rule 17f-9. See infra section IV.C.2 for a discussion of the benefits and costs associated with the proposed fund self-custody rule. The proposed rules also include new definitions and amendments to existing definitions of terms in connection with the proposed self-custody rules. See proposed rules 223-1(d)(1), (d)(3), (d)(4), (d)(5), (d)(6)(i), (d)(10), and (d)(16).

Back to Citation

940.  Many crypto assets are not widely known at launch. After an asset launches, as investors learn about the characteristics of the asset, demand can increase. This can result in an increase in the value of the asset, providing potentially higher returns to early investors. See, e.g.,Decenturalized Dog, HYPE Token Gains Over 200% in Value, Reaches $12 Billion Fully Diluted Valuation After Launch, Crypto News,coinmarketcap.com/​academy/​article/​hype-token-gains-over-200percent-in-value-reaches-dollar12-billion-fully-diluted-valuation-after-launch (last visited May 26, 2026).

Back to Citation

941.  We expect any such diversification benefits to be limited, however. While early investments in nascent tokens may present opportunities for returns, these assets typically have limited circulating supply. As a result, these tokens may not be readily tradable or widely accessible for investment strategies that seek diversification benefits. Moreover, to the extent the prices of these nascent tokens become more correlated with broader crypto asset markets or with other risk assets during periods of market stress, any diversification benefits they may appear to provide in normal market conditions could be substantially reduced at the times when investors most need them. See Roshan Iyer & Adina Popescu, New Evidence on Spillovers Between Crypto Assets and Financial Markets (IMF Working Paper No. WP/2023/213, 2023), available at www.elibrary.imf.org/​view/​journals/​001/​2023/​213/​article-A001-en.xml.

Back to Citation

942.   See supra section I.A and footnote 917 and accompanying text for discussions of these conflicts of interest.

Back to Citation

943.  Many crypto asset transactions are irreversible, which makes the recovery of lost assets more challenging.

Back to Citation

944.  The option to self-custody could still benefit investors to the extent that exposure to crypto assets for which there is no qualified custodian would be considered in weighing different investment options.

Back to Citation

945.  For example, venture capital funds may be more likely to be investing in early-stage crypto projects associated with crypto assets for which there are no qualified custodians available.

Back to Citation

946.   See supra section II.A.3.

Back to Citation

947.  For example, the proposed adviser self-custody rule includes requirements on safeguarding systems, cybersecurity, and internal control reports, which may require a high setup cost. For example, operating (or, where service providers are engaged, overseeing) systems for key management, joint authorization of transactions, and segregation of client crypto assets requires proficiency in crypto technology that might be beyond advisers' customary expertise. In such cases, it may not be economical for advisers to invest additional resources to provide self-custody services. Furthermore, smaller advisers may only have limited amounts of assets under management that could be invested in crypto assets that would require self-custody and therefore may not have a financial incentive to invest in safeguarding systems that would meet the requirements under the proposed rule.

Back to Citation

948.  In the cases where these clients themselves have investors, for example clients that are private investment vehicles, these costs could be further passed on to the clients' investors.

Back to Citation

949.  We estimate that one-time compliance costs would consist of 300 burden hours at $578.33 per hour (300 hours × $578.33 per hour = $173,499) and that recurring annual compliance costs would consist of 100 burden hours at $578.33 per hour (100 hours × $578.33 per hour = $57,833). See infra section V.B.

Back to Citation

950.   See infra section IV.C.2.h). Hence, the estimates do not include all of the costs an adviser would incur. For example, they do not include all of the costs associated with an adviser acquiring new technology, software, hardware, and other associated systems and processes as part of its compliance with the proposed requirements. We expect these costs to be economically significant for advisers. The cost of obtaining an internal control report is separately discussed in section IV.C.2.f).

Back to Citation

951.  For example, the proposed rule would require the adviser to have safeguarding expertise, including the appropriate technology, software, hardware, and other associated systems and processes around their use, for each crypto asset in self-custody.

Back to Citation

952.   See supra section IV.B.3.b).

Back to Citation

953.  The conditions outlined in the proposed adviser self-custody rule are principles-based and are consistent with the current best practices based on our understanding and feedback from industry outreach; nevertheless, the custodial risks for crypto assets remain significant.

Back to Citation

954.  For example, according to an industry report, over $3.4 billion was stolen through wallet compromises and other attacks on private key infrastructure in 2025. See Chainalysis, North Korea Drives Record $2 Billion Crypto Theft Year, Pushing All-Time Total to $6.75 Billion (Dec. 18, 2025), available at www.chainalysis.com/​blog/​crypto-hacking-stolen-funds-2026/​. It is possible, however, that qualified custodians face similar technical and operational challenges or face higher risks of cybersecurity attack compared to advisers who would self-custody client assets under the proposed rule.

Back to Citation

955.   See supra section I.A and footnote 917 and accompanying text for discussions of these conflicts of interest. In addition, as in the case of third-party custody, there are agency costs that follow from the investor's inability to fully observe the custodian's safeguarding measures. See supra footnote 921 and accompanying text. These agency costs could result in the assets being less well protected.

Back to Citation

956.   See infra section IV.C.2.e).

Back to Citation

957.   See infra section IV.C.2.f).

Back to Citation

958.   See infra section IV.C.2.e).

Back to Citation

959.   See infra sections IV.C.2.e) and IV.C.2.g).

Back to Citation

960.   See infra section IV.C.3.

Back to Citation

961.   See infra sections IV.C.7.a)(1) and IV.C.7.b)(1).

Back to Citation

962.  Some of these costs are estimated at $173,499 initially and $433,833 annually per adviser, including $376,000 annually for the internal control report. See supra footnote 949 and accompanying text and infra footnote 1000 and accompanying text.

Back to Citation

963.   See supra section IV.B.4.b) for an analysis of the crypto custodians used by advisers, as reported on Form ADV.

Back to Citation

964.   See infra section IV.C.2.d) for additional discussion of the benefits and costs associated with the QC determination provision of the proposed rule.

Back to Citation

965.   See proposed rule 223-1(d)(16).

Back to Citation

966.   See proposed rule 223-1(d)(16).

Back to Citation

967.  For a detailed discussion of costs, see infra sections IV.C.2.d), IV.C.2.e), and IV.C.2.f).

Back to Citation

968.   See supra section II.A.1.c)(1).

Back to Citation

969.   See supra section II.A.1.d).

Back to Citation

970.   See proposed rule 223-1(b)(11); proposed rule 17f-9(c). See also supra section II.A.1.d).

Back to Citation

971.  “Distributed crypto asset” is defined as a crypto asset received as a distribution for no or nominal consideration in connection, or as a result of activity associated, with a client's crypto asset in the adviser's custody. See proposed rule 223-1(d)(7); proposed rule 17f-9(d).

Back to Citation

972.  For purposes of any QC determination made with respect to an account of a regulated fund, “qualified custodian” would mean a bank or other person authorized to hold assets for the regulated fund under section 17(f) of the Investment Company Act (15 U.S.C. 80a-17(f)) or the rules thereunder.

Back to Citation

973.   See proposed rule 223-1(b)(7)(i) and related proposed amendments to rule 204-2(a) under the Advisers Act.

Back to Citation

974.   See supra section I.A. See also supra footnote 917 and accompanying text.

Back to Citation

975.  An adviser would be required to place the crypto assets with a qualified custodian as soon as reasonably practicable after determining that a qualified custodian has become available. See proposed rule 223-1(b)(7)(i). We do not expect that transferring the assets to the qualified custodian would involve significant costs for the adviser. The qualified custodian would incur costs related to the opening of the account (for example, to generate a new key). We expect that these costs would be passed on to the adviser, and eventually to the client, via a custody fee charged by the custodian. We do not expect that this fee would differ based on whether the assets would be initially maintained at the adviser or whether they would be maintained at the custodian directly.

Back to Citation

976.   See supra footnote 949 and accompanying text for estimates of some of the costs associated with the proposed adviser self-custody rule.

Back to Citation

977.  For example, although different crypto networks have unique characteristics, they often share certain technical aspects; consequently, in an event of system updates, the costs could be shared among multiple types of assets, which reduce the per-asset cost.

Back to Citation

978.  This option would not be available for clients that are regulated funds since regulated funds would only be allowed to self-custody their crypto assets through their adviser. See supra section II.F.5.a).

Back to Citation

979.  Transferring the asset would also result in additional costs associated with the generation of a new private key to safeguard the asset. We understand these costs to be minimal.

Back to Citation

980.  These costs could vary based on the number and type of clients whose crypto assets would be transferred to a qualified custodian as well as on the type of qualified custodian ( e.g., bank, broker-dealer, etc.).

Back to Citation

981.  We understand that in implementing the safeguarding systems and other protection measures, advisers may engage service providers. However, to the extent the service provider does not have access to key materials stored in or generated by the wallet or maintained on the platform or does not have other means to access and/or move a client's crypto assets, they should not be deemed to have custody of client crypto assets.

Back to Citation

982.   See proposed rule 223-1(b)(7)(ii).

Back to Citation

983.   See proposed rule 223-1(b)(7)(iii).

Back to Citation

984.   See proposed rule 223-1(b)(7)(v).

Back to Citation

985.  To the extent some advisers already have safeguarding systems in place, the proposed rule may still benefit investors by establishing a minimum safeguarding standard which they can expect would be applied to those assets, increasing investors' confidence in the market for advisory services.

Back to Citation

986.   See supra section II.A.3.b)(1).

Back to Citation

987.  Under the proposed adviser self-custody rule, advisers would be required to establish an appropriate joint authorization system which requires joint authorization of transfers of crypto assets by two or more supervised persons designated by the adviser, with at least one person being a management person. In the case of crypto assets held for the account of a regulated fund, such management person shall be an officer. See supra section II.A.3.b)(2).

Back to Citation

988.  The proposed adviser self-custody rule, however, would not prescribe specific wallet management methods or a procedure for segregating client assets. This is because the adviser's level of due care would depend on the facts and circumstances, and wallet technology is continuing to evolve. This flexibility would allow advisers to leverage technology advancements to choose the most economical and secure way to comply with the segregation requirement.

Back to Citation

989.  Although specific vulnerabilities may differ based on factors such as crypto asset type, investment strategy, and trading activities, the principle of risk assessment remain crucial for enhancing cybersecurity measures.

Back to Citation

990.   See supra footnote 949 and accompanying text for estimates of some of the costs associated with the proposed adviser self-custody rule.

Back to Citation

991.  To the extent certain advisers currently do not currently segregate client crypto assets, advisers would incur costs associated with adapting existing systems and processes to meet the proposed requirement.

Back to Citation

992.  Advisers would also be expected to account for novel cybersecurity threats to crypto assets as they emerge, which may lead them to review, modify, or update their systems more frequently than annually. See supra section II.A.5. This could result in additional costs.

Back to Citation

993.  This existing requirement would apply to the proposed adviser self-custody rule. See supra footnote 194 and accompanying text; section IV.B.2.

Back to Citation

994.  The marginal benefit per dollar cost associated with each of these proposed requirements may differ as well. For example, post-attack intervention may be more effective for certain crypto assets than for others. If the marginal benefit is higher for certain recovery measures than for certain detection and prevention measures, an adviser may incur more costs on those recovery measures.

Back to Citation

995.  For example, there are different methods that can facilitate joint authorization. The effectiveness of these methods may, however, differ depending on the specific requirements imposed by the advisers.

Back to Citation

996.  For example, it is our understanding that physical wallets (or cold wallets), which typically are considered more secure, are more expensive than software-based wallets (hot wallets). See supra footnote 724 and accompanying text.

Back to Citation

997.   See supra section II.A.4 for similar requirements under Regulation S-P and Regulation S-ID.

Back to Citation

998.   See proposed rule 223-1(b)(7)(iv).

Back to Citation

999.  The internal control report from an independent public accountant with an opinion regarding the design, implementation, and operating effectiveness of internal controls that would be required is consistent with the existing custody rule that applies when advisers and affiliates act as qualified custodians. See rule 206(4)-2(a)(6). The Commission also expects to revise certain aspects of the guidance for accountants to, among other things, specify the minimum control objectives for these reports. Such objectives would generally cover the design, implementation, and operating effectiveness of the controls. See supra section II.I; infra section IV.C.8.

Back to Citation

1000.   See infra section V.B.

Back to Citation

1001.  In some cases, this could result in advisers having to delay or forego taking self-custody of client crypto assets, which could result in advisory clients being unable to invest in some assets.

Back to Citation

1002.   See proposed rule 223-1(b)(7)(vi). Advisers are excepted from complying with the account statements provision if their clients are pooled investment vehicles and receive audited financial statements, or if their clients are regulated funds. See supra section IV.B.2.a). Advisers would be required to maintain records of these statements. See supra section II.H.1.a) and infra section IV.C.7.a)(1).

Back to Citation

1003.   See proposed rule 223-1(b)(7)(vi).

Back to Citation

1004.   See proposed rule 223-1(a)(7).

Back to Citation

1005.   See supra section II.A.7.

Back to Citation

1006.  However, an adviser may choose the delivery format that is most cost efficient or convenient for itself, which may not be preferred by the client.

Back to Citation

1007.   See supra footnote 949 and accompanying text for estimates of some of the costs associated with the proposed adviser self-custody rule.

Back to Citation

1008.   See proposed rule 223-1(b)(7)(vii).

Back to Citation

1009.  Academic research suggests that there is a robust negative association between audit effort and annual report restatements. See, e.g., Gerald J. Lobo & Yuping Zhao, Relation Between Audit Effort and Financial Report Misstatements: Evidence From Quarterly and Annual Restatements, 88 Acct. Rev. (2013) available at papers.ssrn.com/​sol3/​papers.cfm?​abstract_​id=​2265051 (retrieved from SSRN Elsevier database).

Back to Citation

1010.   See proposed rule 223-1(b)(7)(viii).

Back to Citation

1011.   See proposed rule 204-2(a)(26)(viii); see also infra section IV.C.7.a)(1) for a discussion of the benefits and costs associated with this proposed requirement.

Back to Citation

1012.  While the UCC does not have the effect of law unless a State enacts it, currently, all fifty States have enacted Article 8, although the version of the UCC adopted may vary from State to State. The proposed requirement is intended to allow the adviser and the client to invoke the definitions of “financial asset” and “securities intermediary” and the attendant obligations that result from a financial asset election as provided for in the UCC as adopted under applicable State law. See supra section II.A.8.

Back to Citation

1013.   See id.

Back to Citation

1014.   See id. This proposed requirement would complement the proposed segregation requirement discussed in section IV.C.2.e) in protecting client assets from advisers' financial reverses.

Back to Citation

1015.   See supra footnote 949 and accompanying text for estimates of some of the costs associated with the proposed adviser self-custody rule.

Back to Citation

1016.   See proposed rule 17f-9; see also supra section II.B.

Back to Citation

1017.   See proposed rule 17f-9(b)(1)(ii)(A); proposed rule 223-1(b)(7)(ii); see also supra section II.A.3.

Back to Citation

1018.   See proposed rules 17f-9(b)(1)(ii)(B) and 17f-9(b)(1)(ii)(D); proposed rule 223-1(b)(7)(v). See also supra text surrounding footnote 323.

Back to Citation

1019.   See proposed rules 17f-9(b)(1)(ii)(C) and 17f-9(b)(1)(ii)(D); proposed rule 223-1(b)(7)(iv); supra section II.A.5. See also supra text surrounding footnote 324.

Back to Citation

1020.  We are also proposing related disclosure and recordkeeping requirements. See supra sections II.H.2 and II.J.2; see also infra sections IV.C.9 and IV.C.7.b) for discussions of the benefits and costs associated with these proposed requirements.

Back to Citation

1021.   See proposed rules 223-1(a) and 223-1(b)(5).

Back to Citation

1022.   See proposed rule 223-1(b)(7)(i).

Back to Citation

1023.   See proposed rule 223-1(b)(7)(ii)(A).

Back to Citation

1024.   See supra section I.A and footnote 917 and accompanying text for discussions of the conflicts of interest that arise when the adviser is also the custodian.

Back to Citation

1025.   Id.

Back to Citation

1026.  We estimate that one-time compliance costs would consist of 9 burden hours for the evaluation of the investment adviser's written reports at $4,539 per hour and of 1 hour for the evaluation of internal control reports at $12,186 per hour (9 hours × $4,539 per hour + 1 hour × 12,186 per hour = $53,037). We estimate that recurring annual compliance costs would consist of 3 burden hours for the evaluation of the investment adviser's written reports at $4,539 per hour and 0.66 burden hours for the evaluation of internal control reports at $12,186 per hour (3 hours × $4,539 per hour + 0.66 hours × $12,186 per hour = $21,660). See infra section V.C.2.

Back to Citation

1027.  Regulated funds are often organized in such families. See supra section IV.B.3.b). See also Elif Sisli-Ciamarra & Abigail Hornstein, Board Overlaps in Mutual Fund Families (Working Paper Series, 2015) available at www.brandeis.edu/​economics/​RePEc/​brd/​doc/​Brandeis_​WP92.pdf.

Back to Citation

1028.  We expect that even board members that are not familiar with the custody of crypto assets would be able to understand the opinion given by the independent public accountant in the internal control report as to whether controls were suitably designed and implemented and operating effectively. Hence, we expect that the proposed board oversight requirements would provide benefits to regulated funds' investors even when a regulated fund's board of directors is not familiar with the custody for crypto assets.

Back to Citation

1029.  While a regulated fund's investors would not know explicitly the fund's board of directors' level of familiarity with crypto assets, they would typically have access to the fund's Statement of Additional Information, or other disclosure, which generally contains information on board members and their expertise.

Back to Citation

1030.  Under section 17(f)(1) of the Investment Company Act, a permitted custodian includes a “bank” as defined in section 2(a)(5) of the Act that meets the qualification requirements of section 26(a)(1) of the Act. Under rule 206(4)-2(d)(6) under the Advisers Act, a qualified custodian includes a “bank,” i.e., a “bank” as defined in section 202(a)(2) of the Advisers Act or a savings association that meets certain requirements. In both cases, the term “bank” is defined to include, among other things, a “banking institution” or “trust company” “whether incorporated or not, doing business under the laws of any State or of the United States, a substantial portion of the business of which consists of receiving deposits or exercising fiduciary powers similar to those permitted to national banks under the authority of the Comptroller of the Currency,” which is “supervised and examined by State or Federal authority” having supervision over banks, and which is “not operated for the purpose of evading the provisions” of the Investment Company Act or Advisers Act, as applicable. See also supra section IV.B.2.

Back to Citation

1031.  This new category of permitted custodians would be distinct from the current category of custodians that includes banks. See proposed rules 223-1(d)(13)(v) and 17f-8; see also supra section II.C.1. The proposed State trust company rules would apply to advisers' client funds and securities that are crypto assets and to regulated funds' securities and similar investments that are crypto assets, as applicable. In addition, the Advisers Act custody rule includes requirements, including requirements related to surprise examinations, that apply regardless of the type of qualified custodian. These requirements, as well as the proposed amendments to these requirements, would continue to apply, as applicable, including in instances where the qualified custodian would be a State trust company. See rule 206(4)-2; supra section II.G.

Back to Citation

1032.   See proposed rules 223-1(d)(18) and 17f-8(c). Hence, to meet the proposed definition of State trust company, an entity would have to be permitted to exercise fiduciary power. On the other hand, to meet the definition of bank under the current custody rule, a substantial portion of its business must consist of receiving deposits or exercising fiduciary powers.

Back to Citation

1033.   See proposed rules 223-1(d)(13)(v) and 17f-8(a). See supra section II.C for a more detailed description of these conditions. See infra sections IV.C.4.b)—IV.C.4.e) for discussions of the benefits and costs associated with these conditions.

Back to Citation

1034.  It is also possible that some advisers and regulated funds currently use entities that would meet the definition of State trust company as crypto asset custodian. See supra footnote 50 (discussing the 2025 State Trust Company NAL) and accompanying text; supra footnote 882. To the extent that this is the case, the proposed State trust company rules could result in a limited change in market practice, which would decrease the magnitude of the benefits and costs discussed below.

Back to Citation

1035.   See proposed rules 17f-8 and 223-1(d)(13)(v); supra footnote 346.

Back to Citation

1036.   See supra footnote 877 and accompanying text.

Back to Citation

1037.  Allowing self-custody of crypto assets by advisers (including regulated funds' advisers) that are not currently permitted custodians because they are not and do not have a related person that is a qualified custodian would also help mitigate the challenges associated the instances where there are no permitted custodians available. See supra discussion in sections IV.C.2 and IV.C.3.

Back to Citation

1038.   See supra section IV.C.1; infra section IV.D.2.a).

Back to Citation

1039.   See supra footnote 910. In addition, increasing the number of permitted custodians would increase competition in this market, which would have benefits for advisers, regulated funds, and their clients and investors. See infra section IV.D.

Back to Citation

1040.  Nevertheless, the reasonable determination under the proposed rule could still result in uncertainty and prevent some advisers or regulated funds from using certain State trust companies as custodians. In addition, the adviser or regulated fund would be required to determine in writing that it has a reasonable basis to believe, after due inquiry, that the State trust company is authorized by the relevant State banking authority to provide custody services for crypto assets and related cash and/or cash equivalent. See infra section IV.C.4.b)(1) for a discussion of the benefits and costs associated with this proposed requirement.

Back to Citation

1041.  The costs of finding a custodian would not necessarily be reduced because the proposed State trust company rules include additional requirements that must be complied with prior to engaging the State trust company as a custodian but that would not apply in the cases where the custodian meets the definition of bank under the custody rules. These additional requirements would result in costs for advisers and regulated funds. See infra sections IV.C.4.b)-IV.C.4.e). In addition, because of these additional costs, it could be the case that the same State trust company would provide custodial services for crypto assets to some adviser or regulated fund clients under the existing custody rules, that is, without relying on the proposed State trust company rules, and to some other adviser or regulated fund clients under the proposed State trust company rules. See supra section II.C.1.

Back to Citation

1042.   See supra footnotes 877 and 914 and accompanying text.

Back to Citation

1043.  Some state trust companies could still apply for a national bank charter, for example to provide different services or to attract additional clients.

Back to Citation

1044.   See infra section IV.D.1.a).

Back to Citation

1045.  In the case of investing with an adviser, this could be true also for such investors' investments in traditional assets to the extent that they would decide to discuss such investment decisions with their advisers.

Back to Citation

1046.   See proposed rules 223-1(d)(18) and 17f-8(c); supra section IV.B.2.e).

Back to Citation

1047.  For example, banks, whether nationally-chartered or State-chartered, are regulated by Federal agencies. See supra section IV.B.2.d).

Back to Citation

1048.   See supra section IV.B.2.e).

Back to Citation

1049.   See proposed rules 223-1(d)(13)(v) and 17f-8.

Back to Citation

1050.   See supra footnote 344 and accompanying text; footnotes 753 and 772.

Back to Citation

1051.   See proposed rules 223-1(d)(13)(v) and 17f-8(a). The adviser or regulated fund would also be required to maintain records documenting these required determinations. See proposed rules 204-2(a)(27) and 270.31a-2(a)(9); supra sections II.H.1.b) and II.H.2. See also infra sections IV.C.7.a)(2) and IV.C.7.b)(2) for discussions of the benefits and costs associated with these proposed requirements.

Back to Citation

1052.   See supra section IV.C.1 for a description of the asymmetric information problem, and the principal-agent problem to which it can give rise, in this context.

Back to Citation

1053.   See infra section IV.D.1. An adviser deciding whether to switch from its current crypto custodian to a newly-permitted custodian that is a State trust company would take the cost of switching custodians into account when making this decision.

Back to Citation

1054.  The extent to which this would be the case depends on factors such as the information that advisers and regulated funds would disclose to their clients and investors in the absence of this requirement and the effectiveness of this disclosure. It would also depend on how clients and investors would choose and be able to use this additional information in their decision-making process. In addition, while these proposed requirements would impose a minimum on what advisers and regulated funds would be required to do, they would not fully resolve the asymmetric information problem because, among other things, some advisers and regulated funds could decide to apply additional criteria when selecting a State trust company as custodian. Clients and investors may not be able to observe these additional criteria.

Back to Citation

1055.   See infra section IV.D for a discussion of the benefits and costs associated with an increase in demand for crypto assets in general.

Back to Citation

1056.  An adviser's (including a regulated fund's adviser's) fiduciary duty would continue to apply. Hence, circumstances could continue to require that the adviser reconsiders its relationship with the custodian more frequently than annually.

Back to Citation

1057.  For example, the audited financial statements received by the adviser or regulated fund (as required by proposed rules 223-1(d)(13)(v)(B) and 17f-8(a)(2) for advisers and regulated funds, respectively) could indicate that the State trust company's financial condition has moderately deteriorated. This could make it difficult for the adviser or regulated fund to determine whether the State trust company retains its ability to effectively safeguard crypto assets and related cash and/or cash equivalents.

Back to Citation

1058.  We expect that these costs would be lower for regulated funds that are part of a family of funds, to the extent that the selection of a custodian takes place at the family level and that the associated costs are shared across all funds in the family. See supra section IV.B.3.b). Fee increases passed on to these regulated funds' investors could be lower as a result.

Back to Citation

1059.  We estimate that one-time compliance costs would consist of 60 burden hours at $507.67 per hour (60 hours × $507.67 per hour = $30,460) and that recurring annual compliance costs would consist of 20 burden hours at $507.67 per hour (20 hours × $507.67 per hour = $10,153). See infra sections V.B and V.C.2.

Back to Citation

1060.  Some State trust companies could be subsidiaries of other entities. Hence, it is possible that the adviser or regulated fund would already have a business relationship with the State trust company's parent.

Back to Citation

1061.   See proposed rules 223-1(d)(13)(v) and 17f-8(a); supra section II.C.2.a).

Back to Citation

1062.  As discussed below, not all States have adopted regulatory frameworks for the custody of crypto assets specifically, which could increase the costs associated with making this proposed initial determination. This proposed requirement could also provide incentives for State regulators to adopt regulatory frameworks explicitly covering the custody of crypto assets by State trust companies, which could lead to additional investor protection benefits in the longer term.

Back to Citation

1063.  This could involve obtaining a legal opinion of counsel, for example. See supra section II.C.2.a).

Back to Citation

1064.   See, e.g., 23 NYCRR § 200 et seq.; Wyo. Stat. Ann. § 34-29-104.

Back to Citation

1065.   See supra footnote 351. After some time, participants in this market could converge on which states authorize State trust companies to custody crypto assets. Such convergence could reduce the costs associated with this analysis.

Back to Citation

1066.   See proposed rules 223-1(d)(13)(v) and 17f-8(a). See also supra section II.C.2.b).

Back to Citation

1067.   See supra footnote 921 and accompanying text.

Back to Citation

1068.  Commenters writing to the Crypto Task Force have recommended that an adviser considers whether a custodian has appropriate policies and procedures in place as part of its evaluation of custodians. See, e.g., Blockchain Association Comment Letter II, supra footnote 200.

Back to Citation

1069.  To the extent an adviser or regulated fund lacks the technical expertise to make this determination, the benefits of this proposed requirement could be limited, or this proposed requirement could lead to additional costs for the adviser. See infra discussion of costs.

Back to Citation

1070.  An adviser or regulated fund could, in order to reduce its costs, have incentives to select a custodian with less robust policies and procedures for safeguarding crypto assets without appropriate disclosure. See supra text surrounding footnote 928.

Back to Citation

1071.  For example, written policies and procedures can help ensure that the State trust company's personnel know the steps to be taken quickly to protect the assets during a cyberattack.

Back to Citation

1072.  This benefit could vary based on the adviser or regulated fund's ability to understand the detail of the State trust company's policies and procedures.

Back to Citation

1073.  This could increase trust by investors and lead them to invest more with advisers or regulated funds. This could benefit investors, who would be covered by additional investor protections and could potentially obtain higher returns on their investments. See supra section IV.C.4.a).

Back to Citation

1074.  This discussion refers to information received in addition to the required financial statements and internal control report, which are discussed in sections IV.C.4.c) and IV.C.4.d). For example, an adviser or regulated fund may consider obtaining a certification from the State trust company regarding the adequacy and implementation of its policies and procedures to support its reasonable basis determinations.

Back to Citation

1075.  However, we expect that market practice would develop around this proposed requirement and therefore do not expect that this would entail significant costs for advisers.

Back to Citation

1076.  Audited financial statements could provide the adviser or regulated fund with information on the custodian's financial ability to implement the written policies and procedures. The internal control report could help the adviser or regulated fund determine the level of adequacy of the policies and procedures and of their implementation. See infra sections IV.C.4.c) and IV.C.4.d). Hence, these documents could facilitate the adviser's or regulated fund's reasonable basis determination for believing that a State trust company maintains and implements appropriate written policies and procedures, which would reduce the associated costs.

Back to Citation

1077.   See supra section II.C.3 for a discussion of the case where the State trust company's financial statements are presented on a consolidated basis.

Back to Citation

1078.   See proposed rules 223-1(d)(13)(v)(B) and 17f-8(a)(2). See also supra section II.C.3. Under both the current and proposed Advisers Act custody rule, as well as under the proposed Investment Company Act State trust company rule, an independent public accountant means a public accountant that meets the standard of independence described in rule 2-01(b) and (c) of Regulation S-X (17 CFR 210.2-01(b) and (c)). See rule 206(4)-2(d)(3) and proposed rules 223-1(d)(8) and 17f-8(c). Under the proposed rules, the adviser or regulated fund would also be required to maintain copies of the audited financial statements it receives. See supra sections II.H.1.b) and II.H.2. See also infra sections IV.C.7 for an analysis of the benefits and costs associated with these requirements.

Back to Citation

1079.   See supra section IV.C.4.a).

Back to Citation

1080.  For example, a custodian in bad financial health could be tempted to cut costs to restore profitability, which could affect the quality of the controls put in place to safeguard the assets.

Back to Citation

1081.  For example, some financial information could contain proprietary business information that the State trust company would prefer not sharing publicly.

Back to Citation

1082.   See supra section IV.C.1.

Back to Citation

1083.  Because audits may uncover evidence of fraudulent activity, they also serve as an important deterrence against fraudulent conduct. See PCAOB AS 1000.03, General Responsibilities of the Auditor in Conducting an Audit (stating that the objectives of an auditor in audit of financial statements include obtaining reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud).

Back to Citation

1084.  We do not have estimates of the costs of such services. See infra section IV.E.8.

Back to Citation

1085.  This could be, for example, because this is a requirement under the laws of the State under which the State trust company is organized, because other clients of the State trust company demand that the State trust company obtain audited financial statements, because this is part of the State trust company's internal procedures, or because the State trust company is a subsidiary of another entity who is a public company, for which audited financial statements are required. See also supra footnote 50 (discussing the 2025 State Trust Company NAL). However, in all these instances, it is possible that the financial statements could be audited by public accountants that do not meet the independence requirement of the proposed State trust company rules. See supra footnote 1078. This could require a State trust company to find a different public accountant to audit its financial statements, which could result in additional costs.

Back to Citation

1086.   See proposed rule 223-1(d)(13)(v)(C) and proposed rule 17f-8(a)(3). See also supra section II.C.4. Under the proposed rules, the adviser or regulated fund would also be required to maintain copies of the internal control reports it receives. See supra sections II.H.1.b) and II.H.2. See also infra sections IV.C.7.a)(2) and IV.C.7.b)(2) for an analysis of the benefits and costs of these proposed requirements.

Back to Citation

1087.   See infra footnote 1098 and accompanying text.

Back to Citation

1088.   See supra footnote 921 and accompanying text.

Back to Citation

1089.   See supra section IV.C.1.

Back to Citation

1090.  The internal control report could also support accountants auditing financial statements for advisers' clients or for regulated funds, which would improve the quality of the statements. See, e.g., KPMG Comment Letter, Comment Letter to Crypto Task Force of EY (May 22, 2025) (“EY Comment Letter”).

Back to Citation

1091.  An adviser or regulated fund could, in order to reduce its costs, have incentives to select a custodian with controls that may not be viewed by an independent public accountant as being suitably designed, implemented, or operating effectively to safeguard crypto assets without appropriate disclosure. See supra footnote 929 and accompanying text.

Back to Citation

1092.   See supra footnote 929 and accompanying text.

Back to Citation

1093.   See supra footnote 1073.

Back to Citation

1094.  The independent public accountant preparing the internal control report would have to comply with the AICPA Statements on Standards for Attestation Engagements, which states that when providing services under the standards, “practitioners are responsible for having the appropriate competence and capabilities to perform the engagement” and for “exercising professional judgment throughout the planning and performance of the engagement,” where professional judgment is defined as the “application of relevant training, knowledge, and experience, within the context provided by attestation and ethical standards in making informed decisions about the courses of action that are appropriate in the circumstances of the attestation engagement.” See AICPA Attestation Standards (Clarified), supra footnote 551.

Back to Citation

1095.   See supra footnote 1083.

Back to Citation

1096.  Because such enhanced controls could be in place to all of the crypto assets in custody at a given State trust company, and not only those that are advisory client funds or securities, or fund investments in securities or similar investments, this potential benefit could extend to other assets and to other investors as well.

Back to Citation

1097.  The cost of obtaining the internal control report would vary across State trust companies, depending on different characteristics such as the complexity of the entity's safeguarding systems. The cost could also depend on the choice of the independent public accountant preparing the internal control report, with larger, better known accounting firms typically charging higher prices. See, e.g., www.thoropass.com/​blog/​soc-1-audit-cost-a-guide, discussing different factors affecting the price of certain internal control reports. Additionally, we estimate that the cost of obtaining an internal control report under the proposed adviser self-custody rule would be $376,000 on average for an adviser. The cost of obtaining a similar internal control report for a State trust company could be higher or lower. See infra section IV.F.

Back to Citation

1098.  For example, State trust companies providing custodial services for crypto assets could obtain an internal control report in order to find potential clients or retain existing clients. See, e.g., EY Comment Letter (stating that custodians for institutional customers now often issue SOC 1 Type 2 reports to provide their customer with relevant information about their internal controls). See also supra footnote 50 (discussing the 2025 State Trust Company NAL). However, it is possible that independent public accountants preparing such internal control reports would not meet the proposed independence requirement. This could require a State trust company to find a different independent public accountant, which could result in additional costs.

Back to Citation

1099.   See proposed rule 17f-8(b). See also supra section II.C.5. The Advisers Act custody rule generally requires that advisers with custody of client funds and securities maintain those funds and securities with a qualified custodian in separate accounts under the client's name or in accounts containing only the funds and securities of the adviser's clients, under the adviser's names as agent or trustee. See rule 206(4)-2(a)(1). The Commission proposes to renumber this provision but not to amend it substantively. See proposed rule 223-1(a)(1). Because segregation is already a requirement on the adviser side, we do not discuss the associated benefits and costs here. But see supra section II.G.10; infra section IV.C.6.h).

Back to Citation

1100.   See supra footnote 1099.

Back to Citation

1101.  For example, State trust companies that are chartered as limited-purpose trust companies in New York are expected to “separately account for and segregate customer virtual currency” from the assets of the limited-purpose trust company and its affiliated entities, both onchain and on the limited-purpose trust company's internal ledger accounts. See NYDFS Custodial Guidance, supra footnote 362.

Back to Citation

1102.   See supra text accompanying footnote 1100.

Back to Citation

1103.   See supra section IV.B.2.

Back to Citation

1104.  This could entail steps such as creating new wallets and generating new keys.

Back to Citation

1105.  We estimate that one-time compliance costs would consist of 9 burden hours at $774 per hour (9 hours × $774 per hour = $6,966) and that recurring annual compliance costs would consist of 3 burden hours at $774 per hour (3 hours × $774 per hour = $2,322). See infra section V.C.2.

Back to Citation

1106.  We are proposing to make technical corrections to rules 17f-5 and 17f-7, and we do not anticipate that the proposed corrections would have economic effects. In addition, we are also proposing to rescind rule 17f-3. While we do not think regulated funds currently use this rule, we expect this amendment to have an effect on efficiency. See infra section IV.D.1.e).

Back to Citation

1107.   See supra section II.F.1.

Back to Citation

1108.   See supra section II.F.1; Investment Company Act section 59, 15 U.S.C. 80a-58 (applying section 17(f) to a BDC “to the same extent as if it were a registered closed-end investment company”). See also Investment Company Act section 64(a), 15 U.S.C. 80a-63(a) (likewise applying section 31 to a BDC, with certain exceptions, “to the same extent as if it were a registered closed-end investment company”).

Back to Citation

1109.   See supra section IV.B.2.b).

Back to Citation

1110.   See supra section II.H.2. We are also proposing to add references to BDCs to rules 31a-1 and 31a-2. See supra footnote 640 and accompanying text. We do not expect that this amendment would result in costs or benefits since BDCs are already subject to the rules. See supra footnote 787.

Back to Citation

1111.  While complying with the conditions under the Investment Company Act custody rules involves some costs, we expect that BDCs already incur these costs, and we do not expect that the proposed amendments would result in a change in market behavior.

Back to Citation

1112.   See supra section II.F.2.

Back to Citation

1113.   See id.

Back to Citation

1114.   See id.

Back to Citation

1115.   See supra section IV.B.3.c). See also Sec. & Exch. Comm'n, Div. of Trading & Mkts., Guide to Broker-Dealer Registration (2008), available at www.sec.gov/​about/​divisions-offices/​division-trading-markets/​division-trading-markets-compliance-guides/​guide-broker-dealer-registration.

Back to Citation

1116.   See infra section IV.D.2. Existing permitted custodians generally offer comparable custody services; therefore, we do not expect that the benefits would extend to enabling additional strategies that currently permitted custodians may not support.

Back to Citation

1117.  We estimate that recurring annual compliance costs associated with the conditions included in rule 17f-1 consist of 0.5 burden hour at $12,186 per hour for the fund's board of directors to review and ratify the custodial contracts (0.5 hour × $12,186 per hour = $6,093) and of 3 burden hours at $730 per hour for the fund's financial manager to assist the fund's independent public accountant in verifying the fund's assets (3 hours × $730 per hour = $2,190). See infra section V.C.3.

Back to Citation

1118.  We estimate that filing Form N-17F-1 costs on average $507 to a regulated fund. This consists of 1 burden hour at $142 per hour for an office clerk and 0.5 burden hour at $730 per hour for the fund's financial manager (1 hour × $142 per hour + 0.5 hour × $730 per hour = $507). The form is filed three times per year, for a total annual cost of $1,521 per fund per year. See infra section V.E.3.

Back to Citation

1119.   See supra section II.F.2 for a more detailed discussion of the net capital rule.

Back to Citation

1120.   See supra section II.F.2 for a more detailed discussion of SIPA, including the definition of customer property.

Back to Citation

1122.   See supra footnotes 455 and 456 and accompanying text.

Back to Citation

1123.   See supra section II.F.2.

Back to Citation

1124.   See supra section II.F.2.

Back to Citation

1125.   See rule 15c3-3(a)(5).

Back to Citation

1126.  However, the terms on which broker-dealers can extend credit for securities transactions are governed by federal regulation and by SRO rules. See,e.g., Regulation T and FINRA Rule Series 4200.

Back to Citation

1127.   See supra section II.F.2.

Back to Citation

1128.   See proposed rule 17f-1.

Back to Citation

1129.  We anticipate that some of the amendments we are proposing would not have any economic effects. These include: (i) redesignating the custody rule as new rule 223- and (ii) amending the language concerning notice upon the finding of any material discrepancies during the course of an examination.

Back to Citation

1130.   See proposed rule 223-1(b)(9).

Back to Citation

1131.   See supra section IV.B.2.

Back to Citation

1132.  We understand that some advisers would likely have both discretionary trading authority and fee deduction authority over a client account. With respect to such funds or securities that are subject to fee deduction the proposed rule would only except them from the surprise examination, but they would still be required to comply with the remainder of the Advisers Act custody rule.

Back to Citation

1133.   See current rule 206(4)-2(b)(4).

Back to Citation

1134.   See rule 206(4)-2(a)(6)(i) and (ii)(C).

Back to Citation

1135.   See PCAOB, Registration, Annual Fee, available atpcaobus.org/​oversight/​registration/​annual-fee. This is the PCAOB registration fee for firms with 200 or less issuer audit clients and 1,000 or less personnel. Accountants registered with the PCAOB specifically for the purpose of providing services required by the Advisers Act custody rule would likely fit in that category.

Back to Citation

1136.   See infra section IV.D.2.b).

Back to Citation

1137.  Accounting services related to crypto assets, as required under the proposed crypto custody rules, may require a different set of skills compared to those required by traditional assets. To the extent that the number of PCAOB-registered and -inspected accounting firms capable of providing crypto asset related services is currently limited, crypto-specialized accounting firms that are not registered with the PCAOB may gain more market share relative to accounting firms providing services for traditional assets.

Back to Citation

1138.   See 2009 Adopting Release, supra footnote 7. While there is some evidence that PCAOB inspections may improve audit quality in the context of non-U.S. companies that were audited, this evidence relates to public company audits, which the PCAOB directly inspects. See, e.g., Philip T. Lamoreaux, Does PCAOB Inspection Access Improve Audit Quality? An Examination of Foreign Firms Listed in the United States, 61 J. Acct. & Econ. 313 (2016); and Simon Yu Kit Fung et al., Does the PCAOB International Inspection Program Improve Audit Quality for Non-U.S. Listed Foreign Clients?, 64 J. Acct. & Econ. 15 (2017).

Back to Citation

1139.   See Partha S. Mohapatra et al., The Impact of PCAOB International Registration on Audit Quality and Audit Fees: Evidence from China, 41 J. Acct. & Pub. Pol'y 106947 (2022). Firms registered with the PCAOB are required to comply with certain standards, including certain quality control standards. See Sarbanes-Oxley Act of 2002, section 101(c)(2), 15 U.S.C. 7211(c)(2) and section 103(a)(1), 15 U.S.C. 7213(a)(1); see also Quality Control Standards, PCAOB, pcaobus.org/​oversight/​standards/​qc-standards (last visited July 7, 2026).

Back to Citation

1140.  When amending the custody rule to include the PCAOB requirements, the Commission stated that the PCAOB requirements could provide indirect benefits for purposes of the Advisers Act custody rule regarding the quality of the accountant's or auditor's other engagements. See 2009 Adopting Release, supra footnote 7, at section II.C.3. As the PCAOB has previously stated, PCAOB registration does not itself provide assurance of the quality of a firm's professional services. See supra footnote 560.

Back to Citation

1141.   See rule 206(4)-2(b)(4).

Back to Citation

1142.   See rule 206(4)-2(b)(4).

Back to Citation

1143.   See supra footnote 570. In connection with audits under rule 206(4)-2(b)(4), foreign PIVs may have their financial statements prepared in accordance with accounting standards other than U.S. GAAP so long as they contain information substantially similar to statements prepared in accordance with U.S. GAAP and contain a footnote reconciling any material variations between such comprehensive body of accounting standards and U.S. GAAP. Commission staff has taken a similar view. See also Question VI.5 in the Custody Rule FAQ.

Back to Citation

1144.   See proposed rule 223-1(b)(4); supra section II.G.4.a). While the audited financial statements would be required to be distributed to all investors in the pooled investment vehicle (or their independent representatives), the reconciliations to U.S. GAAP would be required to be distributed to U.S. investors only (or their independent representatives).

Back to Citation

1145.   See rule 206(4)-2(b)(4)(i) through (iii).

Back to Citation

1146.   See proposed rule 223-1(b)(4)(i)(C); supra section II.G.4.b).

Back to Citation

1147.  These benefits and costs would only apply to the extent that market practice is not currently consistent with the proposed amendments. See Custody Rule FAQs supra footnote 572.

Back to Citation

1148.   See rule 206(4)-2(b)(4)(i) through (iii).

Back to Citation

1149.   See proposed rule 223-1(b)(4)(ii).

Back to Citation

1150.  We estimate that recurring annual compliance costs would consist of 0.1784 burden hours at $423.67 per hour (0.1784 hour × $423.67 per hour = $76). See infra section V.B. We do not anticipate that the requirement to distribute the first audited financial statements covering the first fiscal year and the following fiscal year under proposed rule 223-1(b)(4)(ii) would result in significant costs for advisers as advisers relying on the audit provision are already required to audit and deliver their financial statements every year, and we understand that adding a single quarter to the audit period does not add significantly more to the cost of distributing the audited financial statements.

Back to Citation

1151.   See rule 206(4)-2(a)(4).

Back to Citation

1152.   See proposed rule 223-1(b)(8).

Back to Citation

1153.   See proposed rule 223-1(d)(17). Under the proposed rule, the qualified custodian must not be the adviser's related person, the client's authorization must include the client's signature, the third-party recipient's name, and either its address or account number at a custodian to which the transfer should be directed, and the adviser must have no ability or authority to designate or change any information about the third-party recipient, including the name, address, and account number.

Back to Citation

1154.   See supra footnote 544.

Back to Citation

1155.  We estimate that one-time compliance costs would consist of 1 burden hour at $471 per hour (1 hour × $471 per hour = $471) and that recurring annual compliance costs would consist of 1 burden hour at $471 per hour (1 hour × $471 per hour = $471). See infra section V.B.

Back to Citation

1156.   See rule 206(4)-2((b)(5). Registered investment companies are subject to the Investment Company Act custody rules.

Back to Citation

1157.   See proposed rule 223-1(b)(5). As a regulated fund, a BDC would be permitted to self-custody its crypto asset by maintaining its crypto asset in self-custody with its investment adviser if the adviser complies with the proposed adviser self-custody rule and subject to additional conditions. See supra sections II.A, IV.C.2, and IV.C.3. In addition, we are proposing to define the term “business development company” in the rule to mean an entity that has elected to be regulated or is regulated as a business development company pursuant to section 54 of the Investment Company Act and has not withdrawn the election. See proposed rule 223-1(d)(1). See also supra section II.G.6.

Back to Citation

1158.   See supra footnote 593.

Back to Citation

1159.   See rule 206(4)-2(a)(2).

Back to Citation

1160.   See proposed rule 223-1(a)(2).

Back to Citation

1161.  We estimate that recurring annual compliance costs would consist of 1 burden hour at $302 per hour (1 hour × $302 per hour = $302). See infra section V.B.

Back to Citation

1162.   See proposed rule 223-1(b)(10); supra section II.G.9. The proposed amendments are consistent with the 2017 IM Guidance and would not involve economic effects for advisers that already rely on this guidance. See supra footnote 600.

Back to Citation

1163.  We estimate that recurring annual compliance costs would consist of 1 burden hour at $471 per hour (1 hour × $471 per hour = $471). See infra section V.B.

Back to Citation

1164.   See rule 206(4)-2(a)(1).

Back to Citation

1165.   See supra section II.G.10.a).

Back to Citation

1166.   See supra section II.G.10.

Back to Citation

1167.   See supra section II.G.10.a); supra footnotes 607 and 608. While some FFIs may be subject to regulations that do not include a segregation requirement, under the current Advisers Act custody rule, an FFI can only serve as a qualified custodian provided that it keeps the clients' assets in customer accounts segregated from its proprietary assets.

Back to Citation

1168.   See rule 206(4)-2(a)(3); see also supra footnote 766 and accompanying text.

Back to Citation

1169.   See rule 206(4)-2(a)(3).

Back to Citation

1170.   See supra section II.G.11.

Back to Citation

1171.   See supra section II.G.11.

Back to Citation

1172.   See proposed rules 204-2(a)(26)(i) through (ix); supra section II.H.1.a).

Back to Citation

1173.   See proposed rule 204-2(a)(26)(x). Rule 204-2(b) imposes additional recordkeeping obligations on advisers that have custody or possession of client securities or funds. We are also proposing amendments to rule 204-2(b) to address standing letters of authorization. See supra sections II.H.1.c) and IV.C.6.d); infra section IV.C.7.a)(3). Separately, the current recordkeeping requirements in rule 204-2 would continue to apply. Notably, paragraph (b) would continue to apply to the cases where the adviser has custody of client funds and securities, including when the funds and securities would be maintained at the adviser under the proposed self-custody rules. In addition, we are proposing conforming amendments to the Advisers Act recordkeeping rule to update references to rule 206(4)-2 to reflect the proposed redesignation of the Advisers Act custody rule to rule 223-1. See proposed rules 204-2(a)(17)(iii) and 204-2(b)(5). We do not expect that these amendments would have any economic effects.

Back to Citation

1174.   See supra section IV.C.2.e) for a discussion of these benefits.

Back to Citation

1175.   See supra section IV.C.2.f) for a discussion of these benefits.

Back to Citation

1176.   See supra section II.A.8.

Back to Citation

1177.   See proposed rule 204-2(b)(1).

Back to Citation

1178.  Paragraph (b) of rule 204-2 already applies to client assets that are securities and funds. See supra footnote 1173.

Back to Citation

1179.  Under proposed rule 204-2(h)(2), an adviser would not be required to make and keep more than one distinct copy of the records required under paragraph (b) of rule 204-2. See supra footnote 619 and accompanying text.

Back to Citation

1180.  These advisers are likely to be familiar with the Investment Company Act recordkeeping rules, and they could be able to leverage this familiarity as well as the staff, systems, and procedures they have in place to comply with these rules when complying with the proposed requirements. This could lower their costs.

Back to Citation

1181.  We estimate that recurring annual compliance costs would consist of 2 burden hours at $154.50 per hour (1 hour × $154.50 per hour = $309). See infra section V.D.1.

Back to Citation

1182.   See supra section IV.C.2.e).

Back to Citation

1183.  This could be, for example, because the proposed requirements would result in advisers identifying weaknesses in their systems.

Back to Citation

1184.   See supra section IV.C.2.e) for a discussion of the types of costs that can result from enhanced safeguarding practices.

Back to Citation

1185.   See proposed rule 223-1(d)(13)(v); supra sections II.C.2.a) and IV.C.4.b).

Back to Citation

1186.   See proposed rules 223-1(d)(13)(v)(B) through (C); supra sections II.C.3, II.C.4, IV.C.4.c), and IV.C.4.d).

Back to Citation

1187.   See proposed rule 204-2(a)(27)(i); supra section II.H.1.b).

Back to Citation

1188.   See proposed rules 204-2(a)(27)(ii) through (iii); supra section II.H.1.b).

Back to Citation

1189.   See supra section IV.C.4.b).

Back to Citation

1190.   See rule 204-2.

Back to Citation

1191.  We estimate that recurring annual compliance costs would consist of 2 burden hours at $154.50 per hour (2 hours × $154.50 per hour = $309). See infra section V.D.1.

Back to Citation

1192.   See supra sections II.G.5 and IV.C.6.d) for discussions of the proposed amendments related to the surprise examination requirement for advisers that custody client assets solely pursuant to a SLOA.

Back to Citation

1193.   See proposed rule 204-2(b)(6); supra section II.H.1.c).

Back to Citation

1194.  We are also proposing to amend rule 204-2(e)(1) to include proposed rule 204-2(b)(6) as an exception to the requirement that books and records required to be made under the provisions of paragraph (a) to (c)(1)(i), inclusive, and (c)(2) of rule 204-2 be maintained and preserved in an easily accessible place for a period of not less than five years from the end of the fiscal year during which the last entry was made on such record, the first two years in an appropriate office of the investment adviser. See proposed rule 204-2(e)(1).

Back to Citation

1195.  See rule 204-2.

Back to Citation

1196.  We estimate that recurring annual compliance costs would consist of 0.25 burden hour at $154.50 per hour (0.25 hours × $154.50 per hour = $39). See infra section V.D.1.

Back to Citation

1197.   See proposed rule 31a-2(a)(10); supra sections II.H.2 and II.B.

Back to Citation

1198.   See supra section II.B; proposed rule 17f-9(b)(1).

Back to Citation

1199.   See supra section II.H.2.

Back to Citation

1200.   See supra footnote 644.

Back to Citation

1201.  We estimate that recurring annual compliance costs would consist of 2 burden hours at $289 per hour (2 hours × $289 per hour = $578). See infra section V.D.2.

Back to Citation

1202.   See proposed rule 17f-8(a); supra sections II.C.2.a) and IV.C.4.b).

Back to Citation

1203.   See proposed rule 17f-8(a)(2) and (3); supra sections II.C.3, II.C.4, IV.C.4.c), and IV.C.4.d).

Back to Citation

1204.   See proposed rule 31a-2(a)(9); supra section II.H.1.b).

Back to Citation

1205.  We estimate that recurring annual compliance costs would consist of 2 burden hours at $289 per hour (2 hours × $289 per hour = $578). See infra section V.D.2.

Back to Citation

1206.  For regulated funds, see proposed rule 31a-1(b)(14). For advisers, we propose to add a crypto network as an additional format that advisers can use to maintain its records. See proposed rule 204-2(g)(1)(iii). In connection with this proposed amendment, we are also proposing conforming amendments to rules 204-2(g)(2) and (3) to prescribe maintenance, preservation, and access procedures for records maintained on a crypto network. See supra section II.H.3.

Back to Citation

1207.   See proposed rules 31a-1(b)(14) and 204-2(g)(4). See also supra footnote 653. For purposes of this section IV.C.7.c) of this release, the term “regulated fund” includes all registered investment companies and BDCs, including UITs and FACCs.

Back to Citation

1208.  The adviser or regulated fund would remain obligated to comply with the substantive provisions of the recordkeeping rules and provide the same information required under the current rules. This may require that the adviser or regulated fund supplement information available on the crypto network with offchain records. See supra section II.H.3.

Back to Citation

1209.  For example, blockchain explorers can generally be used to navigate a crypto network and view information available on the crypto network, including transaction information. See Supra section II.H.3.

Back to Citation

1210.   See infra section IV.D.1.d).

Back to Citation

1211.  For some assets or networks, options to view information, including information on transactions taking place on the network, may be limited or inexistent. See supra section II.H.3. Hence, some advisers and regulated funds may not be able to take advantage of the proposed onchain recordkeeping option and would need to keep all of their records offchain, as is currently required. This would limit the benefits associated with the proposed amendments.

Back to Citation

1212.  For example, the tool used by the adviser or regulated fund to view the onchain records could be temporarily unavailable. As another example, a smaller blockchain could become “abandoned” ( i.e., ceased to be maintained or used), which could result in its records becoming unavailable or difficult to retrieve. See, e.g.,crypto.lethanhnamwork.com/​the-archaeology-of-abandoned-blockchains/​ (stating that accessing abandoned blockchains can be difficult). Offchain records are also subject to risks, but because they are controlled by the adviser or regulated fund, the adviser or regulated fund is able to put appropriate recovery measures in place in case of incidents. This may not be the case for onchain records.

Back to Citation

1213.   See infra section V.D.1.

Back to Citation

1214.   See 2009 Guidance for Accountants, supra footnote 89.

Back to Citation

1215.  The proposed amendments to the custody rules, if ultimately adopted by the Commission, would also result in the Commission making conforming changes to the guidance. Specifically, the conforming changes to the guidance would include (1) updating references associated with the proposed redesignation of the current Advisers Act custody rule to rule 223-1; (2) the removal of the requirement for independent public accountants to be registered with, and subject to regular inspection by, the PCAOB; and (3) the updates made to the notice of material discrepancies to electronic means and to the more recently designated Division of Examinations. The amendments we expect to make to the 2009 Guidance for Accountants would also reflect changes in technical references, as the AICPA professional standards referenced throughout the 2009 Guidance for Accountants have been superseded with new AICPA professional standards. We anticipate that the economic effect of these conforming changes to the guidance would likely be minimal.

Back to Citation

1216.   See rule 206(4)-2(a)(4)(ii).

Back to Citation

1217.  The current control objectives and associated controls for internal control reports include the following areas: (1) client account setup and maintenance; (2) authorization and processing of client transactions; (3) security maintenance and setup; (4) processing of income and corporate action transactions; (5) reconciliation of funds and securities to depositories and other unaffiliated custodians; (6) client reporting. See 2009 Guidance for Accountants, supra footnote 89.

Back to Citation

1218.   See supra section II.I.2.

Back to Citation

1219.  The proposed amendment to Form ADV-E only includes conforming amendments and do not involve any substantives change in the requirement. See infra footnote 1221.

Back to Citation

1220.  All advisers registering with the SEC must complete Form ADV, Part 1A. Although ERAs that are not also registering with any state securities authority only need to complete certain items of Form ADV, Part 1A (Items 1, 2, 3, 6, 7, 10, and 11, as well as corresponding schedules), ERAs that are registering with a State securities authority must complete all of Form ADV, Part 1A. See Form ADV Instruction 3. Hence, for the purposes of this section IV.C.9.a) of this release, “advisers” includes both registered advisers and ERAs that are registered with a state securities authority. See also infra footnote 1231.

Back to Citation

1221.  We are proposing to make amendments to Form ADV that include (1) removing PCAOB-related questions, (2) updating existing references to rule 206(4)-2 to proposed new rule 223-1 (this amendment would also be applied to Form ADV-E and to Item 18 of Form ADV Part 2A), (3) replacing the term “unqualified opinion” with “unmodified opinion,” and (4) removing from Item 1.I and section 1.I. of Schedule D a parenthetical that lists examples of social media platforms. This last amendment would affect ERAs in addition to registered investment advisers. See supra section II.J.1.d). In addition, we are proposing to make conforming amendments to Item 9 to (1) instruct advisers to exclude both registered investment companies and BDCs when reporting under Items 9.A through 9.E, (2) refer to “funds or securities” instead of “assets” in Item 9, and (3) refer to “funds” instead of “cash or bank accounts” in Item 9.A.(1)(a) to be consistent with the Advisers Act custody rule. See supra section II.J.1.b)(1). (Additional amendments to Item 9 are discussed below.) Finally, we are proposing amendments to the Form ADV Glossary of Terms to (1) define “crypto asset,” “crypto asset address,” and “self-custody” as having the same meaning as those terms in proposed rule 223-1 under the Advisers Act, (2) revise the definition of “custody” to cross-reference to the definition of custody in proposed rule 223-1, (3) make a correction edit to the definition of “custody” to add a reference to Schedule D in the list of Form ADV Items where the term “custody” is currently used, and (4) revise the definition of “Related Person” to add Item 5 in the list of Items where this term is used. Although unrelated to this proposal, we are also making a small correction edit to this definition to add Item 1 to the list of Items where the term “Related Person” is used, because related person is referenced in current Item 1.J.(2). See supra footnote 665. Overall, these proposed conforming amendments would not substantively modify any information required to be reported. Therefore, we expect that any associated economic impacts would not be significant.

Back to Citation

1222.   See infra section V.E.1. We estimate that one-time compliance costs would consist of 1 burden hour at $553 per hour (1 hour × $553 per hour = $533) and that recurring annual compliance costs would consist of the sum of $221 in internal costs (0.4 burden hour at $553 per hour; 0.4 × $553 per hour = $221) and $559 in external costs (1 burden hour for a lawyer at $774 per hour for 25% of advisers and 1 burden hour for a financial manager at $730 per hour for 50% of advisers; 0.25 × 1 hour × $774 per hour + 0.5 × 1 hour × $730 per hour = $559). These estimates are associated with the proposed changes to Part 1A and Schedule D of Form ADV (not including private fund reporting), which include the proposed amendments to Item 9 discussed in section II.J.1.b). We expect that these cost estimates would apply equally to registered advisers and ERAs registered with a state securities authority.

Back to Citation

1223.   See supra section II.J.1.b). In addition to the amendments described below, we are also proposing to remove current Item 9.E. We do not expect that this amendment would have significant economic effect since similar information is collected on Form ADV-E. See supra footnote 666.

Back to Citation

1224.   See supra section II.J.1.b)(4).

Back to Citation

1225.  These activities would include: (i) fee deducting authority, (ii) the adviser having a standing letter of authorization, (iii) a related person having custody of client funds or securities in connection with advisory services the adviser provides to clients, but the adviser has overcome the presumption that it is not operationally independent (pursuant to Advisers Act rule 223-1(d)(12)) from the related person; (iv) the adviser having authority to trade at its discretion and meets the conditions set forth under Advisers Act rule 223-1(b)(9); and/or (v) custodial agreements described under Advisers Act rule 223-1(b)(10) that confer unwanted authority upon the adviser, and the adviser has taken the steps set forth under Advisers Act rule 223-1(b)(10)(ii)(B) to repudiate any such unwanted authority. See supra section II.J.1.b).

Back to Citation

1226.  These exceptions include: (i) the privately offered securities exception under rule 223-1(b)(2) (which would be redesignated from current rule 206(4)-2(b)(2)); (ii) exception for fee deducting authority under rule 223-1(b)(3) (which would be redesignated from current rule 206(4)-2(b)(3)); (iii) exception under rule 223-1(b)(6) for custody arising solely from an operationally independent related person having custody of client funds or securities in connection with advisory services the adviser provides to clients (which would be redesignated from current rule 206(4)-2(b)(6)); (iv) exception for standing letters of authorization under proposed rule 223-1(b)(8); (v) exception for discretionary trading authority under proposed rule 223-1(b)(9); and (vi) exception for inadvertent custody under proposed rule 223-1(b)(10) and where the adviser knows, or has reason to know, that a custodial agreement confers custody on the adviser, and the adviser has taken the steps described in proposed rule 223-1(b)(10). See supra section II.J.1.b).

Back to Citation

1227.   See proposed Form ADV Item 9.C.(5).

Back to Citation

1228.   See supra section II.J.1.b)(4).

Back to Citation

1229.   See supra section IV.C.4.

Back to Citation

1230.  These costs are included in the cost estimates provided above. See supra footnote 1222 and accompanying text.

Back to Citation

1231.  This proposed requirement would apply to all registered advisers and all ERAs. See form ADV Instruction 3. Hence, for the purposes of this section IV.C.9.a) of this release, “advisers” includes both registered advisers and ERAs. See also supra footnote 1220.

Back to Citation

1232.  Relatedly, we propose to add to the Glossary of Terms of Form ADV the term “tokenized fund,” which would be defined as a pooled investment vehicle or any series thereof that has issued shares in the format of a crypto asset, where the record of ownership is maintained in whole or in part on or through one or more crypto networks, and the term “crypto network,” which would have the same meaning as proposed in rule 223-1 under the Advisers Act. See supra section II.J.1.c).

Back to Citation

1233.  We estimate that recurring annual compliance costs would consist of 0.1 burden hour at $553 per hour (0.1 hour × $553 per hour = $55). See infra section V.E.1.

Back to Citation

1234.   See supra section II.J.2.

Back to Citation

1235.   See supra footnote 696.

Back to Citation

1236.   See supra footnote 698 and accompanying text.

Back to Citation

1237.  For each of these proposed amendments, we estimate that one-time compliance costs would consist of 1 burden hour at $570 per hour (1 hour × $570 per hour = $570) and that recurring annual compliance costs would consist of 0.67 burden hour at $570 per hour (0.67 hour × $570 per hour = $382). See infra section V.E.2.

Back to Citation

1238.   See supra section II.J.3.

Back to Citation

1239.  We discuss earlier in the proposal matters regulated funds and advisers would be required to disclose to adequately disclose the material risks when a fund or adviser invests in crypto assets, and particularly if the adviser were holding the crypto assets in self-custody. See supra section II.J.3.

Back to Citation

1240.   See supra section II.J.3.a) for a discussion of different examples of elements this disclosure would include.

Back to Citation

1241.   See supra section II.J.3.b).

Back to Citation

1242.   See supra section IV.C.1.

Back to Citation

1243.   See supra section IV.C.1.

Back to Citation

1244.  We do not expect that the guidance discussed in this section would result in additional costs for advisers and regulated funds since advisers and regulated funds currently are and would remain subject to the underlying Form ADV and prospectus requirements, respectively, that are underlying the requirements discussed in this section IV.C.9.c).

Back to Citation

1245.  For all tables in this section, the total in the last row may be different from the sum of the rows above due to rounding.

Back to Citation

1246.   See supra section IV.B.3.

Back to Citation

1247.   See supra sections IV.C.5 through IV.C.9 and infra section V for additional discussions of entities that would be affected by the proposed rules and amendments not related to the crypto custody rules.

Back to Citation

1248.  The total aggregate initial monetized cost is the sum of the total aggregate initial cost in Tables 8-11: $284,337,627 + $1,002,636 + $0 + $16,516,227 = 301,856,490. The total aggregate annual monetized cost is the sum of the total aggregate annual cost in Tables 8-11: $407,073,452 + $11,257,656 + $2,084,732 + $13,290,785 = $433,706,625.

Back to Citation

1249.   See E.O. 12866 (Sept. 30, 1993) [58 FR 51735, 51741 (Oct. 4, 1993)] (requiring agencies to provide an analysis of benefits, costs, and regulatory alternatives to the Office of Information and Regulatory Affairs for significant regulatory actions); OMB, Circular A-4, at 31-34, 45 (Sept. 17, 2003) (providing guidance to agencies regarding compliance with E.O. 12866); see alsoE.O. 14215 (Feb. 18, 2025) [90 FR 10447, 10448 (Feb. 24, 2025)] (requiring all Federal agencies, including the Securities and Exchange Commission, to comply with E.O. 12866). In addition, E.O. 14192 requires agencies to provide their best approximation of the total costs or savings associated with each new regulation or repealed regulation consistent with the analyses required by E.O. 12866. See E.O. 14192 (Jan. 31, 2025) [90 FR 9065, 9066 (Feb. 6, 2025)]. For purposes of approximating the total cost savings and costs under E.O. 14192, the Commission uses the annualized monetized benefits and costs using a real discount rate of 7%. See Table 13 and accompanying discussion.

Back to Citation

1250.   See Circular A-4, at 32.

Back to Citation

1251.  See id. at 31 (stating that “[t]he ending point should be far enough in the future to encompass all the significant benefits and costs likely to result from the rule”). For the purposes of this analysis, we assume the effective date of the rule, as well as the start year for the analysis's time horizon, is the present year. The analysis uses calendar years and accounts for the compliance periods included in the release (see note a in Table 12).

Back to Citation

1252.   See id. at 32 (“The Rationale for Discounting”) & 45 (“Treatment of Benefits and Costs over Time”); see also OIRA, Regulatory Impact Analysis: A Primer, at 11 (Aug. 15, 2011), available at www.reginfo.gov/​public/​jsp/​Utilities/​circular-a-4_​regulatory-impact-analysis-a-primer.pdf (“To provide an accurate assessment of benefits and costs that occur at different points in time or over different time horizons, an agency should use discounting. Agencies should provide benefit and cost estimates using both 3% and 7% annual discount rates expressed as a present value as well as annualized.”); Harvey S. Rosen & Ted Gayer, Public Finance 151 (8th ed. 2008) (defining present value as “the value today of a given amount of money to be paid or received in the future”).

Back to Citation

1253.  This approach is consistent with OMB Circular A-4. See Circular A-4, at 31-34 (stating that, “[f]or regulatory analysis, [agencies] should provide estimates of net benefits using both 3 percent and 7 percent” discount rates and discussing why those rates are reasonable default rates). Also, we use a mid-year discount rate. See OMB, Circular A-94, at 21-22 (Oct. 19, 1992) (stating that, “When costs and benefits occur in a steady stream, applying mid-year discount factors is more appropriate.”).

Back to Citation

1254.  This approach is consistent with the recommended treatment of benefits and costs over time in Circular A-4. See id. at 45 (“You should present annualized benefits and costs using real discount rates of 3 and 7 percent”).

1255.  For each discount rate, the annualized monetized benefits (costs, respectively) in Table 13 represent the constant annual stream of benefits (costs, respectively) whose present value over the time horizon equates the corresponding present value in Table 12. See note a, Table 13 for additional calculation details.

1256.  The annualized benefits and costs present these values over the 10-year time horizon, starting in the 2026.

Back to Citation

1257.  The sub-sections below describe effects on efficiency from certain of the proposed rule provisions and amendments. We do not expect any effect on efficiency from the proposed amendments under the Investment Company Act and Advisers Act custody rule modernizations, from the proposed amendments to the disclosure requirements, or from the other proposed amendments to the recordkeeping requirements.

Back to Citation

1258.   See supra footnotes 877-879 and accompanying text.

Back to Citation

1259.   See supra section IV.C.4.a) for additional discussion of this effect.

Back to Citation

1260.   See supra sections IV.C.2, IV.C.3, and IV.C.4 for additional discussions of these proposed requirements.

Back to Citation

1261.   See supra section IV.C.1.

Back to Citation

1262.   See supra section IV.C.1 for a discussion of how asymmetric information could result in an inefficient matching of advisers and regulated funds to custodians in the absence of the proposed requirements. In addition, because the proposed requirements would reduce inefficiency in the allocation of resources, we do not expect that the additional costs associated with these proposed requirements would result in lower efficiency.

Back to Citation

1263.   See proposed rules 31a-1(b)(14) and 204-2(g)(4); see also supra sections II.H.3 and IV.C.7.c). For purposes of this section IV.D.1.d) of this release, the term “regulated fund” includes all registered investment companies and BDCs, including UITs and FACCs. See supra footnotes 653 and 1207.

Back to Citation

1264.   See Digital Asset Holdings Comment Letter (stating that “a blockchain is ultimately a better set of electronic books and records” and “one that synchronizes automatically with the books and records of counterparties”).

Back to Citation

1265.   See supra sections II.F.2 and IV.C.5.b.).

Back to Citation

1266.   See supra section II.F.3.

Back to Citation

1267.   See supra sections II.G.5 and IV.C.6.d).

Back to Citation

1268.   See supra sections II.G.9 and IV.C.6.g).

Back to Citation

1269.   See supra sections II.G.3 and IV.C.6.b).

Back to Citation

1270.   See supra section IV.C.6.b).

Back to Citation

1271.   See supra sections II.G.4 and IV.C.6.c).

Back to Citation

1272.  The sub-sections below describe effects on competition from certain of the proposed rule provisions and amendments. We do not expect any effect on competition from the other proposed amendments under the Investment Company Act and Advisers Act custody rule modernizations or from the proposed amendments to the disclosure and recordkeeping requirements.

Back to Citation

1273.  For example, the proposed State trust company rules could result in some State trust companies designing and implementing new policies and procedures or enhancing the design or implementation of existing ones. See supra section IV.C.4.b)(2) for a discussion of the benefits of policies and procedures. In addition, establishing or enhancing policies and procedures can facilitate discussion among the State trust company's personnel and expose flaws in the State trust company's safeguarding approach.

Back to Citation

1274.  When the client is a regulate fund, “qualified custodian” would mean a bank or other person authorized to hold assets for the regulated fund under section 17(f) of the Investment Company Act or the rules thereunder. See supra section II.A.2.

Back to Citation

1275.  The custody rules apply to “funds and securities” in the case of clients that are not regulated funds and “securities and similar investments” in the case of clients that are regulated funds. Hence, currently, advisers can have self-custody of client assets that do not meet these definitions, as applicable.

Back to Citation

1276.  The current custody rules do not prevent advisory clients that are not regulated funds from investing in these assets, but they cannot do so through their adviser, that is, the adviser is not permitted to have custody of these assets at any point during the investment process.

Back to Citation

1277.  This could result in a decrease in economic efficiency since a permitted custodian could have higher costs of providing custodial services for a specific crypto asset. However, we expect that, eventually, a competitive market for the custody of the asset would develop and that this market would exclude less efficient custodians.

Back to Citation

1278.   See supra section IV.C.2.a).

Back to Citation

1279.   See supra section IV.C.6.b).

Back to Citation

1280.   Id.

Back to Citation

1281.   See supra footnote 1137.

Back to Citation

1282.  We do not expect any effect on capital formation from the proposed custody rule modernization amendments under the Investment Company Act and Advisers Act, from the proposed State trust company rules, or from the amendments to the disclosure and recordkeeping requirements.

Back to Citation

1283.   See supra sections II.A and IV.C.2.

Back to Citation

1284.   See supra footnote 917 and accompanying text.

Back to Citation

1285.  For example, there could be cases where only one or a few qualified custodians are available for a certain crypto asset, resulting in high costs due to low competition.

Back to Citation

1286.   See supra section II.A.5.

Back to Citation

1287.   See current rule 206(4)(20(a)(1); see also supra section IV.C.6.h).

Back to Citation

1288.   See supra section I.A.

Back to Citation

1289.  For example, protocol upgrades may change the cybersecurity risk profile; therefore, failure to adapt in a timely matter would increase the risk of cyberattack.

Back to Citation

1290.  Such information would be required to include, at a minimum, (i) a written report documenting the basis for the adviser's determination that a qualified custodian is not available to maintain the crypto assets and the basis for the adviser's determination that it has expertise regarding the safeguarding of crypto assets and has the systems necessary to safeguard the crypto assets against loss, theft, misuse, and misappropriation, (ii) the most recent written annual review of the adviser's safeguarding systems, if available at the time of the board's determination, and (iii) the most recent written internal control report, if available at the time of the fund's determination. See proposed rule 270.17f-9; supra sections II.A.8 and IV.C.3.

Back to Citation

1291.   See supra section IV.C.3.

Back to Citation

1292.  To the extent that board oversight reduces adviser misconduct, other clients of the adviser holding the same crypto assets could also benefit from this alternative approach.

Back to Citation

1293.  For example, this alternative could include an additional requirement that in order to be permitted to use a State trust company as custodian for traditional assets, the adviser or regulated fund must determine in writing that it has a reasonable basis to believe that the State trust company maintains and implements written policies and procedures reasonably designed to safeguard traditional assets from the risk of theft, loss, misuse, or misappropriation.

Back to Citation

1294.  Some State trust companies may already provide custodial services for traditional assets to advisers and regulated funds. See supra footnote 1030 and accompanying text.

Back to Citation

1295.  This could be because the adviser or regulated fund would spend fewer resources on activities that have to be done for each custodian, such as negotiating agreements. It could also be because a custodian providing a wider range of services to a given client could charge a price that is lower than the sum of the prices that would be charged by the different custodians providing the different services, for example because of the presence of economies of scale.

Back to Citation

1296.   See supra section II.C.1.

Back to Citation

1297.   See supra section IV.E.2 for a discussion of the benefits and costs of requiring specific safeguarding elements for crypto assets in the context of self-custody by the adviser.

Back to Citation

1298.   See supra section IV.C.2.e) for a discussion of the benefits and costs of cybersecurity requirements for the custody of crypto assets in the context of self-custody by the adviser.

Back to Citation

1299.  Under this alternative, the adviser or regulated fund would still be required to make the proposed reasonable basis determination about the State trust company's policies and procedures.

Back to Citation

1300.   See supra section IV.C.4.d).

Back to Citation

1301.   See supra footnotes 1085 and 1098 and accompanying text.

Back to Citation

1302.  In the absence of these proposed requirements, an adviser or regulated fund could have more difficulty obtaining the State trust company's audited financial statements or internal control report.

Back to Citation

1303.  The Commission is seeking comment on this topic. See supra questions 160-164.

Back to Citation

1304.  For the alternative insurance requirement, this would depend on whether the event that led to the assets being lost or stolen would be covered by the custodian's insurance.

Back to Citation

1305.  Because the better safeguards would likely apply to all of the crypto assets in custody at a given State trust company, and not only those that are adviser client funds or securities or fund investments in securities or other similar investments, we expect that this potential benefit would extend to other assets and to other investors as well.

Back to Citation

1306.  Some State trust company custodians could have instead other measure to compensate their clients in the event of asset loss or theft. For example, State trust company custodians could set aside reserves to be able to compensate their clients in the case of crypto asset loss or theft. These reserves would not necessarily satisfy formal capital requirements under applicable State law.

Back to Citation

1307.   See supra section II.E for additional examples of such conditions.

Back to Citation

1308.  It is our understanding that many trading platforms have developed practices that are consistent with the existing custody rules and that would also be consistent with the proposed rules. See supra section II.E. However, some trading platforms may not have put in place such practices and would therefore not be available to advisers and regulated funds under both the current and proposed custody rules.

Back to Citation

1309.  The Commission is requesting comment on the conditions that it should consider in this context. See supra section II.E.

Back to Citation

1310.  Some regulated funds have sought no-action letters from Commission staff relating to certain Investment Company Act custody rules, such as rule 17f-2 and rule 17f-4, for the regulated fund to follow alternative procedures designed to achieve the same goals as the relevant Investment Company Act custody rule including the prevention of misappropriation.

Back to Citation

1311.  The Commission and its staff has taken the position that, where a regulated fund's investment adviser controls or is controlled by, or is under common control with an affiliated custodian, such arrangements may be subject to rule 17f-2, which governs custody of investments by registered management investment company. See supra footnote 490.

Back to Citation

1312.  The Advisers Act custody rule requires that investment adviser or its related person maintaining client funds or securities must obtain an internal control report from an independent public accountant. Such internal control report must include an opinion of an independent public accountant as to whether controls have been placed in operation as of a specific date, and are suitably designed and are operating effectively to meet control objectives relating to custodial services, including the safeguarding of client funds and securities held by the adviser or its related person, during the year. The accountant must also verify that the client's funds and securities are reconciled to a custodian unaffiliated with the adviser or its related person.

Back to Citation

1313.   See 2009 Adopting Release, supra footnote 7.

Back to Citation

1314.  We understand that regulated funds place a copy of the ownership records with a bank to satisfy Investment Company Act custody rule requirements.

Back to Citation

1315.   See supra footnote 501 and supra section II.F.5.b)(1).

Back to Citation

1316.   See rule 17f-4.

Back to Citation

1317.   See, e.g., American Pension and FundVest, supra footnote 501. Commission staff would not recommend enforcement action under rule 17f-4 where acquired fund shares are maintained at the transfer agents of those funds and where the acquiring funds represented that certain procedures designed to comply with then-current rule 17f-4 would be implemented. See supra section II.F.5.b)(1).

Back to Citation

1318.   See supra footnote 502.

Back to Citation

1319.   See Gardner NAL and Franklin NAL, supra footnote 502. The Commission staff gave assurance that they would not recommend enforcement action under rule 17f-2 subject to the acquiring funds representing that certain procedures would be implemented. See supra section II.F.5.b)(1) .

Back to Citation

1320.   See rule 206(4)-2(b)(2) and proposed rule 223-1(b)(2). The current and proposed Advisers Act custody rules permit an adviser to custody its advisory clients' holdings of privately offered securities outside of a qualified custodian. See supra footnote 508.

Back to Citation

1321.  Privately offered securities are transferable only with prior consent of the issuer or holders of the outstanding securities of the issuer.

Back to Citation

1322.   See supra footnote 513 and supra section II.F.5.b)(3).

Back to Citation

1323.   See rule 206(4)-2(a)(4).

Back to Citation

1324.   See rule 206(4)-2(a)(3).

Back to Citation

1325.   See proposed rule 223-1(b)(7)(ii)(A). See also supra section II.A.3.b)(1).

Back to Citation

1326.   See supra footnote 871 and accompanying text for a description of this analysis and the methodology we used.

Back to Citation

1328.  Rule 17f-3 does not have an assigned OMB control number or associated information collection burden.

Back to Citation

1329.   See, e.g.,15 U.S.C. 80b-10 and 5 U.S.C. 552. Section 10 of the Investment Company Act generally prohibits disclosure of information obtained during the course of an investigation. In addition, Exemption 4 of the Freedom of Information Act provides an exemption for trade secrets and commercial or financial information obtained from a person and privileged or confidential. Exemption 8 of the Freedom of Information Act provides an exemption for matters that are contained in or related to examination, operating, or condition reports prepared by, or on behalf of, or for the use of an agency responsible for the regulation or supervision of financial institutions.

Back to Citation

1330.  Proposed rule 223-1.

Back to Citation

1331.   See supra section II.A for a detailed discussion of the proposed self-custody rule.

Back to Citation

1332.   See supra section II.C for a detailed discussion of the proposed State trust company rule.

Back to Citation

1333.   See supra section II.G for a detailed discussion of the modernizing amendments to the Advisers Act custody rule.

Back to Citation

1334.  Incorporating Form ADV filings received through March 31, 2026.

Back to Citation

1335.  The estimated number of advisers with custody of client funds and securities is derived from the responses to Form ADV Item 9.A.(1) or Item 9.B.(1).

Back to Citation

1336.   See Supporting Statement for the Paperwork Reduction Act Information Collection Submission for Rule 206(4)-2, OMB Report, OMB Control Number 3235-0241 (April 2025) (“2025 Rule 206(4)-2 PRA”).

Back to Citation

1337.  While rule 17f-1 has a number of other requirements, these are the only two that are collections of information for PRA purposes. Any collections of information associated with the proposed requirement that custody of funds and securities be subject to the requirements of rule 15c3-3 of the Exchange Act are included in the approved burden for that rule. See OMB control number 3235-0078.

Back to Citation

1338.  $2,385 to review and ratify the custodial contracts + $1,704 to assist the fund's independent public accountants in verifying the fund's assets = $4,089 (total annual cost per fund) × 8 funds = $32,712

Back to Citation

1339.  0.5 hours for the board of directors to review and ratify the custodial contracts + 3 hours for the fund's controller or administrator to assist the fund's independent public accountants in verifying the fund's assets = 3.5 hours × 8 funds = 28 hours.

Back to Citation

1340.  The following rules, while being amended to reference BDCs, are not discussed here. As discussed above, the proposed amendments to rule 17f-1 would not impose a PRA burden. The PRA for rule 17f-2 already accounts for BDCs.

Back to Citation

1341.   See supra footnotes 649-650 and accompanying text.

Back to Citation

1342.  The Commission assumes that new funds relying on rule 17f-4 would choose to use a custodian instead of directly dealing with a securities depository because of the high costs associated with maintaining an account with a securities depository. Thus, new funds would not be subject to this condition.

Back to Citation

1343.   See discussion supra at section II.H.2.

Back to Citation

1345.  The proposal amends rule 31a-1 to add references to BDCs and provide that records related to crypto assets that are required to be maintained and preserved may be maintained and preserved on an associated crypto network. See proposed rule 31a-1(b)(14). Staff estimates there will be no burden or costs associated with this collection of information. See also supra section V.C.4.

Back to Citation

1346.  This estimate is based on the last time the rule's information collection was submitted for PRA renewal in 2023. See ICR Reference No. 202309-3235-013, available at www.reginfo.gov/​public/​do/​PRAViewICR?​ref_​nbr=​202309-3235-013.

Back to Citation

1347.   See, e.g.,15 U.S.C. 80b-10 and 5 U.S.C. 552. Section 10 of the Investment Company Act generally prohibits disclosure of information obtained during the course of an investigation. In addition, Exemption 4 of the Freedom of Information Act provides an exemption for trade secrets and commercial or financial information obtained from a person and privileged or confidential. Exemption 8 of the Freedom of Information Act provides an exemption for matters that are contained in or related to examination, operating, or condition reports prepared by, or on behalf of, or for the use of an agency responsible for the regulation or supervision of financial institutions.

Back to Citation

1348.   See supra section II.H.2. This table does not, however, address the proposed amendments to add references to BDCs to the regulated fund recordkeeping rules, which are discussed above in section V.C.4.

Back to Citation

1351.  This estimate is based on the last time the rule's information collection was submitted for PRA renewal in 2024. See ICR Reference No. 202507-3235-010, available at www.reginfo.gov/​public/​do/​PRAViewICR?​ref_​nbr=​202507-3235-010.

Back to Citation

1352.   See supra footnote 389. Form N-17F-1 and rule 17f-1 have separate OMB control numbers and collections of information that are renewed at different time using different data therefor the effected entities may be different between the form and the rule.

Back to Citation

1353.  This estimate is based on the following calculations: Commission staff estimates that it takes: (i) 1 hour of clerical time, at a cost of $73 per hour, to prepare and file Form N-17F-1; and (ii) 0.5 hour for the fund's chief compliance officer, at a cost of $618 per hour (or $309 for half an hour), to review Form N-17F-1 prior to filing with the Commission, for a total of 1.5 hours at a total cost of $382.3. Each fund is required to make 3 filings annually, for a total annual internal hour burden per fund of approximately 4.5 hours at a cost of $1,146. Commission staff estimates that an average of 21 funds currently file Form N-17F-1 with the Commission 3 times each year, for a total of 64 responses annually. 4.5 hours × 21 funds = 94.5 total hours. $1,146 × 21 funds = $24,066.

Back to Citation

1355.  17 CFR 270.0-10 (defining small entities under the Investment Company Act). The Commission has a pending proposing release addressing the definitions under the Investment Company Act and Advisers Act of small organization and small business for purposes of the Regulatory Flexibility Act. The Commission encourages commenters to review the proposal to determine whether it might affect their comments on this IRFA. See Amendments to the “Small Business” and “Small Organization” Definitions for Investment Companies and Investment Advisers for Purposes of the Regulatory Flexibility Act, Investment Company Act Release No. 35864 (Jan. 6, 2026) [91 FR 1107] (Jan. 12, 2026)] (the “Small Entity Proposal”). Under the Small Entity Proposal, an investment adviser would generally be a small entity for purposes of the Advisers Act and the Regulatory Flexibility Act if the adviser: (1) has assets under management of less than $1 billion, (2) did not have total assets of $5 million or more on the last day of the most recent fiscal year, and (3) does not control, is not controlled by, and is not under common control with another investment adviser that has assets under management of $1 billion or more, or any person (other than a natural person) that had total assets of $5 million or more on the last day of the most recent fiscal year. Additionally, an investment company would be a small entity for purposes of the Investment Company Act and the Regulatory Flexibility Act under the Small Entity Proposal if the investment company has, or together with other funds in the same family of investment companies has, net assets of $10 billion or less as of the end of its most recent fiscal year.

Back to Citation

1356.  As discussed above, the proposed amendments are generally applicable only to management investment companies and BDCs, although all registered funds and BDCs are subject to the recordkeeping requirements. See 15 U.S.C. 80a-30.

Back to Citation

1358.  For a complete description of the proposed regulated fund self-custody rule, see section II.B of this release.

Back to Citation

1359.  For more information about the proposed adviser self-custody rule, see section II.A of this release.

Back to Citation

1360.  For a complete description of the proposed State trust company custody rule, see section II.C of this release.

Back to Citation

1361.  For a complete discussion of the proposals related to custody rules modernization, please see section II.F of this release.

Back to Citation

1362.  As discussed above, for purposes of the proposed amendments under the Investment Company Act recordkeeping rules, the term, “regulated fund,” includes all registered investment companies and BDCs, including UITs and FACCs.

Back to Citation

1363.  As discussed above in section II.J.1, rule 204-1 under the Advisers Act requires any adviser that is required to complete Form ADV to update the form at least annually, including ERAs that report to the Commission pursuant to rule 204-4, and requires advisers to submit electronic filings through the IARD. Therefore, even though ERAs are not subject to the Advisers Act custody rule, some of the proposed amendments to Form ADV would—as detailed in section II.J.1 above—affect ERAs.

Back to Citation

1365.   See 5 U.S.C. 804(2) (defining “major rule”).

Back to Citation

BILLING CODE 8011-01-P

BILLING CODE 8011-01-C

[FR Doc. 2026-20466 Filed 10-5-26; 8:45 am]

Legal Citation

Federal Register Citation

Use this for formal legal and research references to the published document.

91 FR 63870

Web Citation

Suggested Web Citation

Use this when citing the archival web version of the document.

“Adviser and Regulated Fund Custody Rules; Crypto Custody Rules,” thefederalregister.org (October 6, 2026), https://thefederalregister.org/documents/2026-20466/adviser-and-regulated-fund-custody-rules-crypto-custody-rules.