Key Facts
Federal banking regulators maintain inter-agency guidelines on how banks supervise third-party suppliers. More and more banks are choosing to outsource crypto asset custody to professional providers rather than build their own internal capabilities.
Existing guidelines predate most banks 'crypto asset custody arrangements and are mainly developed for traditional suppliers. However, as more banks enter the crypto-asset custody space by outsourcing rather than building this capability internally in stages, the core rules governing banks to oversee the external suppliers they rely on-namely, the Cross-Agency Guidelines for Third-Party Relations jointly issued by the Federal Reserve, the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC)-are facing a new round of review.
Why crypto asset custody puts pressure on old frameworks
Traditional third-party risk guidelines assume supplier relationships are similar to scenarios such as outsourced payment processing or core banking software. In these scenarios, banks can audit the supplier's operations, request contractual remedies, and reasonably assume that the underlying asset (such as customer deposits) remains legally there, regardless of what happens to the supplier. Crypto-asset custody breaks this assumption in a specific way: if the custodian holding the private key on behalf of the bank is compromised or becomes insolvent, it is not the service relationship that is lost, but the underlying asset itself, and the loss may be irreparable.
The Federal Reserve's guidance for community banks is also built around supplier failure models that cannot clearly map to the risks of crypto-assets. This is not a theoretical difference. A bank that outsources loan services to a bankrupt provider can transfer services to other providers without the underlying loan disappearing; but a bank that outsources the custody of crypto assets to a provider that has failed in key management may directly lose the assets themselves, and there is no equivalent path to recovery.
This difference in the meaning of "failure" is why existing guidelines, which focus on business continuity and data security, fail to fully cover what regulators need banks to actually verify before signing custody agreements with professional providers of crypto assets.
What the updated framework actually needs to cover
Meaningful updates cannot just stop at the standard due diligence list, but must also address specific issues related to the actual security of digital assets: Examples include how private keys are generated, stored and backed up, whether custodians use multi-party computing or traditional cold storage, how customer assets are handled when custodians go bankrupt under existing laws, and how quickly banks can actually verify the integrity of their positions, rather than just relying on the custodians 'verbal assurances.
None of the existing cross-agency guidelines directly answer these questions, which is the gap regulators are currently being pushed to fill. This gap has become increasingly apparent as banks 'participation in crypto asset custody has gradually expanded from a niche market among a few institutions.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC