On July 14, 2025, the Board of Governors of the Federal Reserve System (Board), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC) released new guidance for banks seeking to provide safekeeping services relating to cryptocurrencies. The statement follows on the heels of the federal regulators’ public withdrawals of prior joint supervisory statements on crypto-asset activities and exposures in April and May of this year. Generally speaking, the guidance withdrawn in the spring required banks to seek supervisory “non-objection” prior to engaging in crypto activities, including the provision of safekeeping or custodial services. These regulatory shifts clearly evidence the policy “flip” from the Biden to Trump administrations on crypto.

Summer Intern Kate Sargent and Lawyer Keith Gauer
According to the federal bank regulators, the latest joint guidance is designed to increase regulatory clarity, not to impose new regulations. In effect, it offers a roadmap or checklist for banks considering entry into crypto safekeeping services by outlining risk management expectations, operational safeguards, and compliance requirements. Much of the guidance aligns with existing frameworks for third-party vendor risk management. The statement strongly recommends that a financial institution’s board, officers, and employees have the requisite knowledge and understanding of crypto services before offering them to customers.
Interestingly, the guidance focused on the role of banks in providing “safekeeping” services related to crypto. They describe safekeeping services as sub-set of the larger category of “custodial” services that banks are empowered to provide to their customers and acknowledge that safekeeping services can be provided in both a fiduciary and non-fiduciary capacity. Relying on a 2020 OCC Interpretive Letter, the regulators define “safekeeping” as “holding an asset on a customer’s behalf.” By contrast, according to the older OCC Interpretive Letter, the broader category of “custodial services” can include services beyond simply holding an asset, including investment of the asset, settling trades, collecting income, processing, recordkeeping, and reporting services. While unstated in the guidance, it would seem that the additional services beyond safekeeping may increase the risks of the business to the bank. In our experience, most regulated entities that hold crypto on behalf of a customer do provide some sub-set of the broader services.
The federal bank regulators emphasize that crypto-asset safekeeping presents unique risks. One of the primary risks is the possible compromise of cryptographic keys and sensitive information. To address this risk, banks must maintain exclusive control over cryptographic keys to prevent unauthorized access and ensure secure key generation and storage. In addition, the bank must determine which crypto assets it will provide safekeeping for by thoroughly assessing each asset’s distinct risks and ensuring compatibility with existing systems. Because these assets are virtual, a strong focus on cybersecurity is essential. Banks engaged in safekeeping should frequently evaluate their security systems and address any technological threats.
In addition, the guidance provides a reminder that banks must still adhere to their legal and compliance obligations. Banks must ensure that their safekeeping services are operating in full compliance with BSA/AML, CFT, and OFAC requirements. This requires identity verification, monitoring, and reporting in a regulatory environment that is always evolving. Moreover, if banks engage sub-contractors to assist in the safekeeping services (which seems likely in the crypto space), they must conduct due diligence before selecting a third-party provider and apply strong third-party risk management practices, as the bank will be held responsible for the activities performed by the sub-custodian. Further, audit programs are essential to risk management. If the bank’s existing audit program does not provide appropriate coverage over crypto activities, management should engage external resources to assess safekeeping operations. Lastly, banks should prioritize clear, written agreements with customers that define the bank’s responsibilities and methods of safekeeping.
While the federal bank regulators have removed the prior approval requirements, we would continue to recommend that banks proactively engage with their primary federal and state regulators (as applicable) before launching crypto safekeeping operations. Banks planning to become crypto custodians should treat the most recent guidance as a roadmap for assessing their readiness to enter this evolving space.
Consulting with legal counsel can help ensure that your systems and operations align with regulatory expectations. The Financial Institutions lawyers at Davenport, Evans, Hurwitz & Smith can work with you to consider this business line. Contact a lawyer at 605-336-2880, [email protected], or find a specific attorney here.
Davenport, Evans, Hurwitz & Smith, LLP, located in Sioux Falls, South Dakota, is one of the state’s largest law firms. The firm’s attorneys provide business and litigation counsel to individuals and corporate clients in a variety of practice areas. For more information about Davenport Evans, visit www.dehs.com.
