Skip to main content

How to Audit Crypto Self-Custody Clients: SEC Rule Readiness

By LedgerLens team

9 min read

2026-10-07

sec-custody-rulecrypto-custody-attestationinvestment-advisersengagement-scopingself-custody-auditregulatory-compliance
How to Audit Crypto Self-Custody Clients: SEC Rule Readiness

Why This Proposal Changes Your Engagement Pipeline

The SEC gave investment advisers a compliant path to self-custody client crypto assets on October 1, 2026. Your clients noticed.

Your engagement scope probably wasn't built for what that path requires: quarterly documentation showing no qualified custodian was available, dedicated address-level controls for each client, and an annual review by an independent accountant covering both controls and cybersecurity. Three new requirements. Three new audit triggers. None of them covered by a typical advisory engagement letter.

The 60-day comment window that opened with the proposal is also your planning window. By the time a final rule lands — and SEC Chair Paul Atkins has signaled more regulatory proposals are on the horizon — your practice needs scoping language, workpaper templates, and a clear attestation framework ready for any adviser client who chooses to self-custody.

This post breaks down what the proposal requires, what it means for your fieldwork, and how to structure engagements before the final rule is adopted.

What the SEC Proposed — and How It Breaks from 2023

The new SEC crypto self-custody framework directly responds to a failure in the rules it's replacing.

In June 2025, the SEC withdrew its 2023 Gensler-era safeguarding proposal without adopting it. The core problem: qualified custodians weren't available for many crypto assets, making compliance technically impossible for advisers who wanted to offer crypto strategies. Requiring advisers to use custodians that didn't yet exist for certain assets effectively shut them out of those markets.

The October 2026 proposal takes a different approach. It amends both the Investment Advisers Act of 1940 and the Investment Company Act of 1940 — covering registered investment advisers, registered investment companies, and business development companies. Instead of requiring unavailable infrastructure, the proposal defines when self-custody is permissible and specifies the controls an adviser must implement to do it compliantly.

Commissioner Hester Peirce offered a clarification auditors should note: in the rule's terms, "self-custody" refers to an adviser acting as custodian for client assets — not to investors controlling their own private keys. The audit subject is the adviser's control environment, not the client's wallet.

The proposal also formally recognizes state-chartered trust companies as eligible crypto custodians, widening the set of entities your practice may need to assess or rely on.

The Three Custody Models the Proposal Recognizes

The framework creates a structured order of operations for how an adviser can hold client crypto:

  • Traditional qualified custodians: Banks and registered broker-dealers remain the default. If a qualified custodian is available for the asset, an adviser must use one.
  • State-chartered trust companies: Newly recognized as permitted custodians for digital assets. This expands the pool of entities that must meet custody standards — and that auditors may be asked to evaluate for reliance purposes.
  • Adviser self-custody: Available only when the adviser documents that no permitted custodian offers the service for that asset. This is a last resort, not a free choice.

That tiered structure matters for engagement scoping. Before any engagement involving adviser-held crypto, you need to understand where the client sits in that hierarchy — and whether their documentation supports the position they're claiming.

New Audit Triggers the Rule Creates for Your Clients

The proposed self-custody conditions aren't just internal compliance requirements. They are audit triggers with specific evidence requirements attached.

Three in particular carry direct fieldwork implications.

Quarterly documentation re-assessments. Each quarter, an adviser that self-custodies must re-document that no permitted custodian is available for the relevant assets. That documentation becomes a testable assertion. Your procedures need to verify it was prepared on schedule, that the assessment methodology was reasonable, and that conclusions were communicated appropriately.

Annual independent accountant review. Any adviser self-custodying client assets would face an annual review covering both controls and cybersecurity. The independent accountant reporting requirement creates a direct new engagement type — closer to agreed-upon procedures or a SOC 2 examination than a standard financial statement audit. How easily your team can scope and staff this work depends on your existing experience with control-environment testing and cybersecurity risk frameworks.

Address-level control evidence. The rule requires dedicated client addresses — meaning an adviser cannot co-mingle assets across clients in a shared wallet. Each client's holdings must be traceable to specific addresses. For fieldwork, that means address-level existence and completeness testing, not just total-balance confirmation at period end.

Taken together, these three triggers represent a materially expanded engagement scope for any adviser client who self-custodies. The pricing and staffing need to reflect that from the outset.

How to Scope Engagements When Clients Self-Custody

Standard advisory engagement letters don't contemplate any of these tests. If a client opts into self-custody under the proposed framework, your scope document needs to be rebuilt from the control requirements outward.

For background on cryptographic ownership procedures, see Crypto Accounting: Signatures and Send-to-Self Methods — the same signing procedures used in custody verification apply here. For engagement design at the engagement level, How to Scope a Crypto Audit Engagement covers the field-guide basics that apply before you layer in custody-specific work.

A workable scoping framework covers four dimensions:

  1. Custodial model determination. Confirm where on the hierarchy the client sits. Is this a qualified-custodian relationship, reliance on a state trust company, or adviser self-custody? If self-custody: verify the basis for that determination and confirm the quarterly re-assessment cadence is in place.
  2. Address-level mapping. Obtain the complete address registry for client-attributed holdings. Verify that no client address shares a wallet with another client's assets. Test for movements that crossed client address boundaries during the period.
  3. Ownership proof. Apply message-signing or equivalent cryptographic procedures to verify the adviser controls the private keys at each address — not just that they have read access to the balance. Multi-signature arrangements require confirmation of the full threshold set.
  4. Control and cybersecurity review scope. Define control objectives covering key generation, key storage, access management, backup and recovery, and incident response. Map these to the cybersecurity framework the adviser has adopted — NIST CSF, ISO 27001, or equivalent — and determine evidence requirements for each.

That's a different workpaper package than a standard advisory engagement. The pricing and timeline should reflect it.

Documentation and Control Standards You'll Need to Test

The proposal's specific control requirements translate directly into test procedures.

  • Suitable expertise. The adviser must demonstrate that personnel responsible for custody operations have the knowledge to manage private key infrastructure safely. Examine credentials, training records, and job descriptions for custody-function staff.
  • Dedicated client addresses. Reconcile the address registry to the client account list. Trace asset movements at period end and around significant transfer dates. Flag any address serving more than one client.
  • Segregated-control safeguards. The adviser must implement controls preventing any single person from moving client assets unilaterally. Test the key management architecture — multi-signature thresholds, approval workflows, policy documentation — and confirm those controls operated as designed during the period.
  • Quarterly no-custodian-available documentation. Examine each quarterly assessment for completeness, timeliness, and methodology. Were relevant custodians actually surveyed? Was the assessment performed before assets were self-custodied, not after the fact?
  • Cybersecurity controls. Key generation environments, hardware security module usage, network isolation, penetration testing cadence, and incident response documentation all fall within scope of the annual review. If your practice doesn't have an established cybersecurity testing capability, this component may require a specialist subcontractor.

Address-level reconciliation, on-chain balance verification, and movement tracing are well within the capability set of purpose-built crypto audit software. The control-environment and cybersecurity testing is where human judgment and engagement design carry the weight.

Positioning Your Practice Before the Final Rule Lands

The comment window closes approximately 60 days after Federal Register publication. A final rule is unlikely before mid-2027, accounting for the comment review period and potential revisions. That window is your preparation runway.

Firms that wait until the rule is final will spend the first months retrofitting engagement templates under client pressure. Firms that build now can present a scoped engagement package to adviser clients before competitors have finished reading the rule text.

A four-step readiness plan:

  1. Map your adviser client base. Identify which existing clients hold crypto as part of the advisory relationship, which currently use qualified custodians, and which might shift to self-custody under the new framework. That map shows where scope changes are coming.
  2. Draft scoping language and engagement letter addenda. Write the four-dimension scope above into a template addendum your team can adapt per client. Price it. Name the quarterly documentation review and the annual accountant review as distinct service lines with separate fees.
  3. Build the address-level testing procedure. Define your standard procedure for address registry verification, ownership-proof testing, and co-mingling checks. Document the tooling your team will use and the evidence standards you'll require from clients before the engagement starts.
  4. Assess your cybersecurity testing capacity. Determine whether your practice can staff the annual control and cybersecurity review independently, or whether you need a referral relationship with a cybersecurity specialist. Clarify that before a client asks for a scope that includes it.

The custody framework is an early chapter in a longer regulatory build. As the 2025 review of changing crypto auditing showed, each regulatory shift creates a new engagement category — and the practices that build infrastructure ahead of the curve take the work when it arrives.

Conclusion: Build the Engagement Before the Rule Requires It

Firms that invest in repeatable crypto attestation workflows can handle adviser self-custody engagements, deliver stronger assurance, and do it faster than competitors who wait for final rule text. The four-step readiness plan above is executable today — while the comment window is still open, before a single client has asked whether their arrangement qualifies.

LedgerLens's Auditor's Workbench is purpose-built for exactly this kind of engagement: address-level reconciliation, cryptographic ownership verification, and workpaper documentation for crypto custody attestation work. If you're building engagement infrastructure for the adviser self-custody work this rule creates, explore the Auditor's Workbench or book a LedgerLens walkthrough with the team.