The United States Monetary Supervisory Authority (OCC), the Federal Reserve Board (Fed) and the Federal Deposit Insurance Corporation (DFIC) issued a joint statement detailing how existing banking rules apply to institutions that provide encrypted money hosting services to customers. The guide emphasizes the practice of “custody” as holding a digital asset on behalf of a client and notes that this does not create new oversight requirements.

Risk Control Focus on Encryption Key

The regulator directs the board and executive level to view encrypted currency hosting as a service that relies on exclusive control of private key and other sensitive data. The Guide states that once an asset is in a custodial state, the bank must prove that no other party, even the customer itself, can move the asset unilaterally.

Management needs to assess how key generation tools, wallet types and contingency plans match the overall control environment of the agency and ensure that staff have the necessary technical skills to maintain these security measures.

In addition, when allocating capital and personnel to support hosting operations, banks should also take into account the volatility of the type of asset and the speed of technological change.

Compliance, governance and third-party oversight

The three institutions have reminded the agencies that the encryption of currency hosting services must comply with the provisions of the Bank Secrecy Act, the Anti-Money Laundering, Counter-Terrorism Financing and the Office of Foreign Assets Control, including the “travel rules” for transfers with identifying information.

The Board of Directors should involve BSA officials and senior management from the early days of any hosting service to assess the risk of illegal financial activity and document related controls.

If banks entrust storage tasks to secondary custodians, they remain responsible for the performance of these suppliers. The Guide recommends that an enterprise review the key management method of the secondary trustee, the separation of assets and insolvency protection measures before entering into a contract.

Enterprises are also required to establish a notification mechanism to inform in the event of any violation or operational incident. The same vendor risk control discipline is required for those agencies that purchase third-party software while maintaining assets in-house.

Finally, regulators require auditors to expand the scope of testing to include elements specific to encrypted currency, such as key generation, wallet security and chain clearance controls. When internal teams lacked expertise, management should employ independent experts to validate security measures and report directly to the Board of Auditors.

The joint statement concluded that existing fiduciary, custodial and information security regulations already provided a framework for banks wishing to secure their encrypted currency. However, these banks must demonstrate their ability to control keys in real time, manage suppliers and comply with federal financial crime laws.