Quick Answer
There is no single “right” custody model for tokenized securities — there is a right model for your specific combination of regulatory status, client type, and key-management risk tolerance. A registered investment adviser holding client assets almost always needs a qualified custodian, which in practice means an OCC-chartered or state-chartered trust bank, a NYDFS limited-purpose trust company, or an SEC special purpose broker-dealer, not a self-hosted multisig wallet. An issuer running its own permissioned cap table on a standard like ERC-3643 can pair a transfer-agent-embedded model with a custodian of record for the underlying shares. A crypto-native fund with sophisticated internal security operations may reasonably choose a sub-custody arrangement built on MPC technology from a provider like Fireblocks or Copper, trading a lower fee for a smaller insurance backstop. The decision hinges on four questions: is the token legally a security requiring Advisers Act compliance, who holds the private keys, how much commercial insurance sits behind a loss, and whether the custodian is bankruptcy-remote from its own parent company’s balance sheet.
Why Custody Became the First Question, Not an Afterthought
Ask ten people building a tokenized securities platform in 2026 what keeps them up at night, and most will not say blockchain scalability or smart contract audits. They will say custody. That is a change from five years ago, when custody was treated as a plumbing detail to be sorted out after the product roadmap was locked. The reason for the shift is straightforward: a tokenized security is still a security under the law, and the SEC’s long-standing Investment Advisers Act Custody Rule — formally Rule 206(4)-2 — requires a registered adviser with custody of client funds or securities to place them with a “qualified custodian.” That rule was written for stock certificates and bank accounts, but its logic transferred directly to digital assets once regulators made clear that a token wrapping a real-world security does not escape securities regulation just because it moves on a blockchain.
The practical result is that the custody decision now shapes almost everything downstream — which chains an issuer can realistically use, which broker-dealers will clear trades in the token, and which institutional allocators are even allowed to buy it. A fund that picks the wrong custody model does not just take on operational risk; it can find itself unable to onboard the exact clients it built the product for, because their compliance departments will not sign off on an arrangement that fails the qualified-custodian test. Understanding the landscape starts with recognizing that “custody” in this context covers at least three separate legal questions that often get collapsed into one conversation: who has legal title to the underlying asset, who controls the cryptographic keys that can move the token, and who is contractually and financially on the hook if something goes wrong.
The Custody Decision Framework: Four Questions Before You Choose a Model
Before comparing vendors, it helps to answer four questions in order. Each one narrows the field of viable custody models considerably, and skipping a question is the single most common reason firms end up re-papering a custody agreement eighteen months after signing it.
1. Does a regulated intermediary have custody of the asset?
If a registered investment adviser, broker-dealer, or bank trust department has custody of the tokenized security on behalf of a client, the Custody Rule and its bank, broker-dealer, and (as proposed) digital-asset-specific safeguarding requirements apply. If the token sits directly in an individual investor’s own wallet with no intermediary ever taking possession, the Custody Rule’s adviser-facing obligations do not apply in the same way — though the issuer’s own transfer-agent and recordkeeping obligations still do.
2. Is the token a security under U.S. law, and if so, under what exemption was it issued?
A token issued under Regulation D, Regulation S, or Regulation A+ carries transfer restrictions that the custody model must be able to enforce. This matters because a custodian that cannot check accredited-investor status or holding-period lockups before releasing a token is not just an operational inconvenience — it is a compliance failure waiting to happen.
3. Who physically controls the private keys, and how many parties have to agree to move funds?
This is the operational security question. A single-signer hot wallet, a multi-party computation (MPC) threshold-signature scheme, and an air-gapped hardware security module (HSM) with a formal key ceremony each carry very different breach profiles, recovery timelines, and insurance eligibility.
4. What happens to the asset if the custodian itself fails?
Bankruptcy remoteness is the question that separates a real qualified custodian from a wrapper. Client assets held by a chartered trust company in a segregated, off-balance-sheet account should not become part of a bankruptcy estate if the custodian’s parent company collapses. Client assets held on an exchange’s general balance sheet, by contrast, have repeatedly become entangled in creditor claims during past insolvencies — a pattern regulators cite explicitly when justifying stricter segregation rules for digital asset custodians.
Evaluation Criteria That Separate a Real Custodian From a Wrapper
Once the four framework questions point you toward a category of provider, the following criteria do the actual vendor comparison. Treat any provider that cannot answer all seven with specifics, rather than marketing language, as a red flag.
- Charter and regulatory status. Is the entity an OCC-chartered national trust bank, a state-chartered trust company (South Dakota, Wyoming, and New York are the most common domiciles), a registered broker-dealer operating under the SEC’s special purpose custody framework, or an unregulated technology vendor licensing its software to a regulated entity above it?
- Key management architecture. MPC threshold signatures, HSM-based cold storage with a documented key ceremony, or a simple multisig smart contract — each has a different recovery process and a different attack surface.
- Asset segregation and bankruptcy remoteness. Are client tokens held in individually addressed, segregated wallets recorded on the custodian’s books as client property, or commingled in an omnibus wallet where reconciliation depends entirely on internal ledgers?
- Insurance coverage and its actual scope. A headline insurance number is close to meaningless without knowing the per-incident cap, whether it covers internal theft as well as external hacking, and whether cold-storage assets are covered at a different (usually lower) rate than hot-wallet assets.
- Audit cadence and report type. A SOC 2 Type II report, which tests controls over a period of months, is materially stronger evidence than a SOC 2 Type I report, which only confirms controls were designed correctly on a single date. Ask which one you are actually being shown.
- Transfer-restriction enforcement. For a Reg D or Reg S token, does the custody layer integrate with an on-chain whitelist (commonly built on the ERC-3643 permissioned token standard) so restricted transfers are blocked automatically, or does enforcement rely on manual compliance review after the fact?
- Fee structure and its alignment with your holding size. Basis-point fees on assets under custody make sense for larger books; flat monthly platform fees often work out cheaper for smaller allocations, but can include hidden minimums that erase the advantage.
Six Custody Models for Tokenized Securities, Compared
The market has settled into roughly six recognizable models, each with a distinct regulatory posture and cost profile. Very few real deployments use exactly one in isolation — a transfer-agent-embedded structure, for example, almost always sits on top of a trust-company custodian for the underlying asset — but understanding each as a discrete building block makes it easier to see what you are actually buying.
| Custody Model | Regulatory Status | Key Management | Bankruptcy Remoteness | Best Fit |
|---|---|---|---|---|
| OCC-chartered / state trust bank e.g. Anchorage Digital Bank, BNY Digital Assets, Zodia Custody | Federally or state-chartered trust bank; qualified custodian under the Custody Rule | HSM cold storage with formal multi-person key ceremonies | Strong — assets held off balance sheet as fiduciary property | RIAs and institutions that must satisfy the Custody Rule |
| NYDFS / state limited-purpose trust e.g. Coinbase Custody Trust, BitGo Trust, Gemini Trust | State-chartered limited-purpose trust company under a virtual-currency framework | MPC and HSM hybrid, largely cold storage | Strong — statutory trust obligations require segregation | Crypto-native funds needing a regulated but faster-onboarding option |
| SEC special purpose broker-dealer custody | Registered broker-dealer operating under the SEC’s digital asset securities custody framework | Varies by firm; typically HSM cold storage | Moderate — subject to broker-dealer net capital and segregation rules | Issuers pairing custody with in-house secondary trading |
| Sub-custody via MPC technology platform e.g. a trust company running Fireblocks or Copper infrastructure | The regulated entity above the platform (usually a trust company) holds the license; the technology vendor itself is typically unregulated | MPC threshold signatures across distributed key shares | Depends entirely on the licensed entity’s own segregation practices | Firms needing fast transaction throughput alongside institutional controls |
| Transfer-agent-embedded custody permissioned token, e.g. ERC-3643, plus custodian of record | Custody sits with an underlying trust company; the token layer enforces transfer restrictions on-chain | Whichever model the underlying custodian uses, plus an on-chain identity whitelist | As strong as the underlying custodian | Reg D / Reg S / Reg A+ issuers needing automated lockup enforcement |
| Self-custody / on-chain multisig e.g. a Gnosis Safe-style contract controlled by internal signers | Not a qualified custodian under the Custody Rule; generally unsuitable for RIAs holding client assets | N-of-M multisig held by internal or founder-controlled keys | None — no independent trust or bankruptcy shield | DAOs and unregistered issuers holding only their own treasury |
Insurance Coverage by Custody Model, and Why the Gap Is So Wide
Nothing separates these six models more starkly than the commercial insurance sitting behind them. A chartered trust bank negotiates crime and specie policies, often syndicated through Lloyd’s of London, that scale with assets under custody and explicitly name internal theft and external hacking as covered perils. A self-hosted multisig, by contrast, is not insurable in any conventional sense — no underwriter will write a policy against a founder losing a hardware key, because there is no independently verifiable control environment to underwrite against.
Typical Commercial Insurance Coverage by Custody Model ($ Millions per Incident)
No commercial coverage available
$320M
$150M
$60M
$35M
$0
Figures are representative ranges compiled from publicly disclosed custodian insurance program sizes as of mid-2026, not a quote for any specific account or policy.
Notice that the gap between the top model and the bottom is not a matter of degree — it is a difference between having a financial backstop and having none at all. That gap is exactly why compliance departments at institutional allocators will not approve a self-custody arrangement for anything beyond a firm’s own risk capital, no matter how technically elegant the multisig setup is.
Worked Example: Picking a Custodian for a $40 Million Tokenized Private Credit Allocation
Consider a mid-sized RIA that has committed $40,000,000 of client capital to a tokenized private credit fund structured under Regulation D, with tokens issued on a permissioned ERC-3643 rail. The firm’s compliance officer has to select a custody arrangement that will pass an SEC examination and satisfy the fund sponsor’s own diligence requirements.
- Confirm the Custody Rule applies. Because the RIA has discretionary authority over client accounts holding the tokens, it has “custody” under Rule 206(4)-2 and must use a qualified custodian — this immediately rules out the self-custody multisig model and the unregulated MPC vendor operating without a chartered entity above it.
- Shortlist qualified candidates. The firm narrows the field to an OCC-chartered trust bank quoting 18 basis points annually, and a NYDFS limited-purpose trust company quoting 12 basis points annually plus a $15,000 flat onboarding fee.
- Price each option against the allocation. At 18 basis points, annual custody cost is $40,000,000 × 0.0018 = $72,000. At 12 basis points plus onboarding, the first-year cost is ($40,000,000 × 0.0012) + $15,000 = $48,000 + $15,000 = $63,000, dropping to $48,000 in year two.
- Weigh the insurance and remoteness difference. The trust bank’s insurance program covers up to $320,000,000 per incident and includes internal theft; the limited-purpose trust’s program covers up to $150,000,000 and carries a narrower internal-theft sublimit of $25,000,000. Given the fund’s size, both comfortably exceed the $40,000,000 exposure, so this factor does not decide the vote on its own.
- Check transfer-restriction enforcement. The RIA confirms which custodian’s platform natively integrates with the ERC-3643 whitelist used by the fund’s transfer agent, since manual enforcement would create a real risk of an inadvertent transfer to a non-accredited wallet.
- Make the call. The limited-purpose trust company wins on cost and matches on whitelist integration, so the RIA selects it, documents the decision rationale in its compliance file, and schedules an annual re-review tied to the fund’s insurance renewal date.
The arithmetic in this example is simple by design — the hard part of a real custody decision is almost never the fee calculation. It is confirming, in writing, that the custodian’s segregation and insurance actually hold up the way the sales deck says they do, which is why the checklist further down asks for documents, not assurances.
Common Mistakes That Blow Up a Custody Decision
- Treating an MPC technology vendor as if it were the custodian. Fireblocks, Copper, and similar platforms provide key-management infrastructure that a licensed trust company or bank uses. The technology vendor itself typically holds no banking or trust charter, so the actual qualified custodian is whichever regulated entity sits above the software — confirm that entity’s charter directly, not the software brand name on the marketing page.
- Assuming a multisig wallet satisfies the Custody Rule because “no single person can move funds.” Distributing signer authority reduces one kind of internal risk, but it does not create bankruptcy remoteness, does not produce an audited segregation record, and is not a qualified custodian in the eyes of the SEC, regardless of how many signers are required.
- Confusing a SOC 2 Type I report with a SOC 2 Type II report. A Type I report only confirms that controls were designed appropriately as of one date; a Type II report tests whether those controls actually operated effectively over a period, typically six to twelve months. Custodians sometimes lead with the Type I because it is easier to obtain — always ask which one you are looking at.
- Concentrating multisig or MPC key shares with people who all report to the same manager. Threshold signature schemes only reduce risk if the parties holding separate key shares are genuinely independent. A “3-of-5” scheme where four of the five signers sit on the same trading desk offers far less protection than the number implies.
- Skipping the whitelist-integration check for restricted securities. A custodian that can hold the token but cannot enforce Reg D accredited-investor whitelisting or Reg S offshore-transfer restrictions pushes that compliance burden back onto manual review, which is exactly the kind of process a permissioned token was supposed to eliminate.
- Reading the insurance headline number without checking sublimits. A $300,000,000 program that carries a $10,000,000 sublimit specifically for internal theft or key-management failure offers much less protection against the most common real-world loss scenario than the top-line figure suggests.
A Practical Checklist Before You Sign a Custody Agreement
- Obtain the custodian’s actual charter document or license number and confirm it independently with the issuing regulator (OCC, the relevant state banking department, or the SEC’s broker-dealer registration database).
- Request the current SOC 2 Type II report — not a Type I, not a summary letter — and read the exceptions section, not just the auditor’s opinion paragraph.
- Get the insurance certificate directly from the carrier or broker, and ask specifically for the internal-theft sublimit and the hot-wallet-versus-cold-storage coverage split.
- Confirm in writing how client assets are recorded on the custodian’s books — individually segregated wallets versus an omnibus wallet with internal ledger allocation — and how a bankruptcy trustee would be expected to treat those records.
- Test the whitelist and transfer-restriction integration with a sample transaction in a sandbox environment before go-live, rather than taking the integration claim on faith.
- Map out the key-recovery procedure end to end, including who has to be reachable and how long a worst-case recovery would realistically take, not the marketing-stated best case.
- Document the custody decision rationale, including the alternatives considered and why they were rejected, in a form that would satisfy a regulatory examination two years from now.
- Set a calendar reminder to re-verify the custodian’s insurance renewal and SOC 2 report at least once a year, since both can lapse or narrow in scope without an active notice to clients.
Key Takeaways
- The custody model you need is determined first by regulatory status — whether a registered adviser, broker-dealer, or bank has custody of the asset — not by which technology looks most modern.
- Qualified custodians for tokenized securities cluster into three regulated categories: OCC-chartered or state trust banks, NYDFS-style limited-purpose trust companies, and SEC special purpose broker-dealers. Self-custody multisig arrangements do not qualify for RIA client assets.
- Insurance coverage varies by roughly two orders of magnitude across models, from several hundred million dollars at a chartered trust bank down to zero for a self-hosted multisig — a gap that reflects insurability, not just marketing positioning.
- For Reg D, Reg S, and Reg A+ tokens, custody and transfer-restriction enforcement should be evaluated together; a custodian that cannot integrate with an on-chain whitelist standard like ERC-3643 pushes compliance risk back onto manual review.
- A SOC 2 Type II report and a verified insurance certificate with clear sublimits are the two documents that most reliably separate a genuine custody program from one that only sounds like one in a pitch deck.
Frequently Asked Questions
Does a tokenized security need to sit with a qualified custodian?
Yes, if a registered investment adviser, broker-dealer, or bank has custody of it on a client’s behalf. The Investment Advisers Act Custody Rule requires client funds and securities — including tokenized securities — to be held with a qualified custodian, generally a bank, a registered broker-dealer, or a chartered trust company, rather than in a self-hosted wallet controlled by the adviser.
Can an RIA self-custody a client’s tokenized securities in a multisig wallet?
No. A self-hosted multisig arrangement, no matter how many signers are required to approve a transaction, is not a qualified custodian under the Custody Rule. It lacks the chartered status, independent audit regime, and bankruptcy-remote segregation that regulators require for client assets held by a registered adviser.
What’s the difference between a trust company custodian and a sub-custody technology platform?
A trust company custodian is a chartered, regulated entity that holds legal and fiduciary responsibility for client assets. A sub-custody technology platform, such as an MPC key-management vendor, typically provides the software infrastructure that a chartered custodian uses internally — the technology vendor itself usually holds no banking or trust license, so the actual regulated custodian is the entity above it.
How much insurance coverage should a tokenized securities custodian carry?
There is no fixed legal minimum, but institutional allocators generally expect coverage that comfortably exceeds the largest single account the custodian holds, with explicit sublimits for internal theft as well as external hacking. Programs at established trust banks have run into the hundreds of millions of dollars, while self-custody arrangements carry no commercial coverage at all.
Does MiCA require different custody rules than the SEC’s Custody Rule?
Broadly similar in intent but different in mechanics. The EU’s Markets in Crypto-Assets Regulation requires crypto-asset service providers to segregate client assets, maintain daily reconciliation, and accept liability for losses caused by an incident attributable to the provider, while the SEC’s framework centers on the qualified-custodian requirement under the Investment Advisers Act. A firm operating in both jurisdictions typically needs a custody arrangement built to satisfy the stricter of the two sets of requirements rather than treating them as interchangeable.
References
- Securities and Exchange Commission — Investment Advisers Act Rule 206(4)-2 (the Custody Rule) and related safeguarding proposals.
- Office of the Comptroller of the Currency — Interpretive Letters 1170 and 1172 on national bank custody of crypto assets and stablecoin reserves.
- New York State Department of Financial Services — virtual currency business activity and limited-purpose trust company chartering framework.
- European Parliament and Council — Regulation on Markets in Crypto-Assets (MiCA), custody and segregation provisions for crypto-asset service providers.
- Public disclosures from Anchorage Digital Bank, BNY Digital Assets, Coinbase Custody Trust Company, and BitGo Trust Company regarding charter status, key-management architecture, and insurance programs.
- ERC-3643 Association — technical documentation on the permissioned token standard used for identity-gated transfer restrictions.
Anyone still mapping the basics of how an asset gets wrapped into a token in the first place will find useful grounding in this real-world asset tokenization guide, which covers the legal wrapping and SPV structures that sit underneath most of the custody arrangements described above.






