FCA Cryptoasset Custody: What PS26/11 Says About CASS 17 Safeguarding


This is general public information, not investment, financial, legal, tax, regulatory, compliance or personal advice.
No individual custodian, wallet, service, client holding, custody arrangement or outcome is assessed in this article. The content summarises and reports on material published by the Financial Conduct Authority (FCA) and does not evaluate, rank or recommend any firm, model, product or practice.
FCA cryptoasset custody: scope of this explainer and the published record
This CASS 17 public-information explainer summarises and quotes material published by the Financial Conduct Authority (FCA) in connection with its cryptoasset regime, specifically Policy Statement PS26/11 and the FCA’s online summary of the regime. It does not introduce statements or conclusions beyond the text of those FCA publications. The paragraphs below follow the content of PS26/11 and the FCA’s accompanying web publication dated 30 June 2026 and reflect the language those sources use when describing safeguarding and the application of CASS 17 to cryptoasset custodians.
Source boundary: which FCA publications are summarised
The CASS 17 source boundary in this article is limited to the FCA’s public web summary of the cryptoasset regime and the policy statement entitled “PS26/11: Crypto Regime: Regulated Cryptoasset Activities” (June 2026). PS26/11 sets out the final rules and guidance for regulated cryptoasset activities defined by the Regulated Activities Order, including safeguarding. The article does not draw on or paraphrase other FCA publications.
PS26/11 as a final policy statement
PS26/11 is presented by the FCA as a final policy statement. The FCA’s published materials state that PS26/11 “covers final rules and guidance for regulated cryptoasset activities, including cryptoasset custodians” and that it “sets out final rules and guidance for regulated cryptoasset activities defined by the Regulated Activities Order, including safeguarding.” Those are the formulations used by the FCA to describe the status of PS26/11 in relation to the cryptoasset regime.
What ‘safeguarding’ means in the FCA material
The FCA overview refers to safeguarding in the context of cryptoasset custody. Its safeguarding summary describes “enhanced protections around ownership rights, record-keeping, reconciliation and private-key management.” The overview lists those four areas when describing safeguarding in its published account of the cryptoasset regime policy statements.
CASS 17: contextual statement in PS26/11
Both the web summary and PS26/11 confirm that safeguarding requirements under CASS 17 are being applied to cryptoasset custodians with adjustments. PS26/11 “confirms the application of safeguarding requirements under CASS 17 with adjustments to reflect cryptoasset custody.” The FCA’s publications present CASS 17 as the chapter of the Client Assets Sourcebook that the policy statement addresses in its final rules and guidance for cryptoasset custodians.
Ownership-rights language in the FCA overview
In its overview of safeguarding, the FCA highlights ownership rights as one of the protections to be enhanced in the rules and guidance. The regulator’s published summary uses the phrase “ownership rights” when listing the areas of enhanced protection and explicitly includes ownership rights alongside record-keeping, reconciliation and private-key management in its safeguarding summary. That is the specific terminology used by the FCA in the excerpts cited from the published material.
Record-keeping as described in the safeguarding summary
The FCA’s safeguarding summary explicitly lists record-keeping among the areas for enhanced protections. The FCA overview identifies record-keeping as one of the named areas in that safeguarding summary. PS26/11 confirms that safeguarding requirements under CASS 17 apply with adjustments to reflect cryptoasset custody.
Reconciliation as described in the safeguarding summary
Reconciliation appears in the FCA overview’s safeguarding summary as one of the named areas for enhanced protections. The overview identifies reconciliation alongside ownership rights, record-keeping and private-key management. PS26/11 confirms that safeguarding requirements under CASS 17 apply with adjustments to reflect cryptoasset custody.
Private-key management: the FCA’s framing
The FCA overview’s safeguarding summary includes private-key management among the areas for enhanced protections. The overview identifies private-key management alongside ownership rights, record-keeping and reconciliation. PS26/11 confirms that safeguarding requirements under CASS 17 apply with adjustments to reflect cryptoasset custody.
Technology-agnostic approach to private-key management
The FCA overview states that the FCA “adopted a technology-agnostic approach to private-key management.” This is the description used in the overview’s published safeguarding account.
Clarification on control-based application
The FCA overview states that the FCA “clarified control-based application.” This wording appears in the overview’s published safeguarding account.
Targeted exceptions to trust requirements
The FCA overview states that the FCA “introduced targeted exceptions to trust requirements.” This wording appears in the overview’s published safeguarding account.
Settlement-float model percentage increased to 2%
The FCA overview states that the FCA “increased the settlement-float model percentage limit to 2%.” The 2% figure appears in the overview’s published safeguarding account.
Planned further engagement and future work
The FCA’s web summary indicates that the regulator “plans further engagement on tokenised asset custody and potential future CASS amendments, and future consultation on resolution of crypto custodians.” Those are the terms the FCA uses in its public summary of PS26/11 to describe future work and engagement it intends to undertake following the publication of the final policy statement.
Tokenised asset custody: planned further engagement
In the FCA’s public description of PS26/11, tokenised asset custody is identified as an area on which the FCA plans further engagement. The policy statement and the accompanying web summary refer to “further engagement on tokenised asset custody and potential future CASS amendments.” The FCA’s language sets out planned engagement separate from the final rules summarised in PS26/11 rather than describing any new final CASS text concerning tokenised asset custody in the documents themselves.
Non-application of CASS 17 to relevant specified investment cryptoasset custody at the outset
The FCA overview states that “CASS 17 is not being applied to relevant specified investment cryptoasset custody at the outset.” This is the wording used in the overview’s published account of the cryptoasset regime policy statements.
CASS 6 applied temporarily for RSIC custody at the outset
The FCA’s web summary explains the immediate regulatory position for firms seeking authorisation to provide custody for relevant specified investment cryptoassets. The summary states that such firms “need to do so as cryptoasset custodians and need to apply CASS 6 when safeguarding those assets for the time being.” That is the precise wording the FCA uses to describe the interim application of the CASS chapters for the specific custody activity referred to in PS26/11.
CASS 7 and client money arising in connection with safeguarding client cryptoassets
The FCA’s published material states that “CASS 7 applies to client money arising in connection with safeguarding client cryptoassets, with targeted adjustments.” That sentence is used in the FCA’s overview of PS26/11 to describe which parts of the Client Assets Sourcebook apply to client money linked to safeguarding activities for cryptoassets and to flag that the application includes targeted adjustments in the FCA’s final rules and guidance.
Stablecoin issuing firms and CASS 7
The FCA overview states that “firms issuing qualifying stablecoins will not be subject to CASS 7.” This is the wording used in the overview’s account of the cryptoasset regime policy statements.
What the final rules do not establish about a firm
The FCA’s policy statement is presented as a set of final rules and guidance for regulated cryptoasset activities. The policy statement and the web summary do not, within the material cited here, make firm-specific determinations or conclusions about particular firms, custodians, wallets or specific client arrangements. The published texts set out regulatory requirements and clarifications; they do not operate as assessments of individual firms within the scope of this article.
No operational-custody instruction in this article
The FCA’s published materials describe regulatory requirements, rule applications and the adjustments the regulator has made in PS26/11. This article does not provide operational instructions for custody, nor does PS26/11 itself, as presented in the cited extracts, prescribe operational procedures in place of the rule and guidance descriptions. The FCA’s published text is the primary source for the regulatory formulations summarised here.
No explanation of wallet or private-key procedures
The FCA overview includes the statement that the FCA adopted a “technology-agnostic approach to private-key management.” This article reports that published wording and does not assess an individual custodian, wallet, service, client holding or custody arrangement.
No conclusion about consumer protection outcomes
The FCA’s published statements explain regulatory frameworks, rule changes and planned engagement. The material summarised in PS26/11 and the web summary does not itself provide an evaluative statement about individual consumer outcomes in particular cases. The FCA sets regulatory requirements and indicates areas of future engagement; this article reproduces those statements and does not draw firm-level or consumer-level conclusions beyond the text of the publications.
Official-source recap
The reporting in this article uses two primary FCA sources: PS26/11 and the FCA’s web overview of the cryptoasset regime policy statements. The article does not summarise or rely on other FCA publications.
Related OGM reporting is available in the Crypto section.
Final public-information boundary
This CASS 17 article is confined to reporting and quoting from the FCA’s June 2026 policy statement PS26/11 and the FCA’s public web summary dated 30 June 2026. It does not extend to operational advice, steps for market participants, or analysis that relies on independent assumptions beyond the text of those two FCA sources. The FCA’s publications that are summarised here include the regulator’s description of safeguarding, the application of CASS 17 with adjustments, the interim application of other CASS chapters in specified circumstances, and the areas of intended future engagement.
The two primary sources used in the article are listed in the Official sources section below. Related OGM reporting is available in the Crypto section.
Chapter 7 as the detailed CASS 17 source
PS26/11 states that Chapter 7 sets out the FCA’s final rules for firms that safeguard client cryptoassets under the client assets regime (CASS). The policy statement describes Chapter 7 as building on previous work (DP23/4, CP25/14 and CP26/4), and as focused on ensuring firms take appropriate measures to protect client cryptoassets when they are responsible for them and to facilitate the return of client cryptoassets “as quickly and as whole as possible” in the event of firm insolvency.
The policy statement describes these rules as an extension and adaptation of the existing CASS framework, intended to support the FCA’s statutory objectives and Principle 10 of the Principles for Businesses. Chapter 7 is the FCA’s articulated source for the detail in this article: it contains the final rules, the FCA’s summary of consultation feedback, and the FCA’s responses and clarifications on scope, trusts, exceptions, record‑keeping, reconciliations, means of access, third‑party appointments, operational surplus and other topics that the FCA considered material to safeguarding client cryptoassets.
FCA says it uses custody and safeguarding interchangeably in Chapter 7
The policy statement describes that, in Chapter 7, the FCA uses the terms “custody” and “safeguarding” interchangeably. PS26/11 states this usage at the outset of the chapter, noting that the chapter “details our final rules for firms that safeguard client cryptoassets” and explicitly that “we refer to custody and safeguarding interchangeably in this chapter.” This lexical clarification is presented as part of the chapter’s framing, reflecting the FCA’s approach to terminology within these rules.
Chapter 7 stated outcomes (the FCA’s list)
PS26/11 states that, in developing the CASS cryptoasset custody regime, the FCA sought to achieve the following outcomes (set out in paragraph 7.3 of Chapter 7):
- “Have adequate arrangements to protect clients’ ownership rights to their cryptoassets.”
- “Have adequate organisational arrangements to minimise risk of loss or diminution of client cryptoassets or the rights in connection with those cryptoassets.”
- “Maintain accurate books and records of client cryptoassets.”
- “Have adequate controls and governance to protect client cryptoassets, including the means of access. This can include a private cryptographic key, parts of a private cryptographic key (a shard), or some other means which enables a transfer of the benefit of the cryptoasset to another person.”
The policy statement describes these four outcomes as the FCA’s intended regulatory objectives for firms subject to CASS in the context of safeguarding client cryptoassets; this list is presented as the FCA’s objectives rather than as an evaluation of any firm’s practices.
Article 9N scope and control concepts (final‑rule framing)
PS26/11 states that the application of CASS 17 is aligned with the Article 9N definition of safeguarding in the Cryptoassets Regulations. The policy statement describes that CASS 17 applies to firms that have “control” of cryptoassets within the meaning of Article 9N—specifically, the FCA’s focus is on whether a firm has the ability to bring about a transfer of the benefit of cryptoassets to another person. The policy statement sets out that control can occur by various means and that these concepts underpin the final‑rule scope.
The policy statement describes the dual concept of control in Article 9N and clarifies how that maps to the CASS 17 perimeter. PS26/11 states that control may arise from a firm holding or storing the means of access (for example, a private cryptographic key or part of it), or from the firm appointing a person to hold or store the means of access under an arrangement operated by the firm, or a combination of both. The policy statement emphasises that CASS 17 will apply where those conditions of control—ie the practical ability to bring about a transfer of benefit—are met, subject to the limited exceptions the FCA sets out in the chapter.
Self‑custody boundary under Article 9N (the FCA’s description)
PS26/11 states that, as articulated in Chapter 7, self‑custody models fall outside Article 9N and CASS 17 where the firm does not have the ability to bring about a transfer of the benefit of the cryptoasset. The policy statement describes that “self‑custody models, where clients safeguard their cryptoassets themselves and firms do not have the ability to bring about a transfer, are not in scope of Article 9N and therefore the CASS rules do not apply.”
The policy statement frames this as a perimeter boundary: where the client alone retains the practical ability to transfer the asset (the firm cannot bring about a transfer), the Article 9N safeguarding definition is not engaged, and the CASS 17 trust‑based safeguarding obligations are not applied under the final rules described in Chapter 7.
Distributed/shared control: FCA explanation and stance
The policy statement describes that the FCA recognises custody models in which control is distributed or shared—such as architectures where private key material is split across multiple parties or systems—are common in the market and can offer robust security characteristics. PS26/11 states that the FCA “recognise[s] that safeguarding models involving distributed or shared control are common and can provide more robust security arrangements to clients,” and that it “does not want to prevent or deter firms from doing so.”
PS26/11 states the FCA’s focus remains on protecting the cryptoasset owner where a safeguarding firm has the Article 9N control described in the Cryptoassets Regulations. The policy statement explains that distributed or shared control arrangements (examples referenced include sharded keys and MPC‑type constructs) were considered during consultation and that the FCA addressed such models in Chapter 7 by mapping control concepts to the Article 9N definition and by illustrating scenarios in an explanatory diagram. The FCA’s explanation includes the view that a firm may meet the Article 9N control threshold even where it does not itself physically hold all means of access, noting there is not a tension between meeting Article 9N control and not physically holding cryptoassets or all key material.
Backup‑key exception described for clients retaining full control
PS26/11 states that the FCA introduced an additional exception to the requirement to safeguard client cryptoassets on trust in the specific circumstance where a firm holds a back‑up key on behalf of a client but the client retains full control and can act independently. The policy statement describes this exception as applying where the firm holds a back‑up key and the client retains the ability to act independently; it may also apply where the client is another safeguarding firm acting as trustee for its own clients.
The policy statement describes the FCA’s rationale: the principal insolvency protection objective of the trust (protecting clients against competing creditor claims) is less relevant where the client already retains independent control. PS26/11 states that this exception is proportionate to the risk in that scenario. The policy statement also explains that firms that rely on this back‑up key exception will remain subject to certain CASS rules (the chapter identifies applicable rules such as CASS 17.2 and 17.4), but that firms in this exception will not be permitted to appoint third parties under the CASS 17.6 rule to mitigate additional risk. This description is presented as the FCA’s final‑rule position on that narrow exception; it is not an operational guide.
RSIC (relevant specified investment cryptoassets) staged position
PS26/11 states that the FCA is not proceeding to apply CASS 17 to RSIC custody at this stage. The policy statement explains that, at the commencement of the new cryptoasset regime, firms seeking to provide RSIC custody will need to be authorised as a cryptoasset custodian and will be required, for the time being, to apply the CASS 6 requirements when safeguarding RSICs.
The policy statement describes the FCA’s intention to engage further on whether and how tailored CASS requirements for RSIC custody should apply in the longer term. PS26/11 states the FCA will consult on any further changes once it has engaged further, noting issues the FCA considers relevant for future work such as whether requirements should differ by RSIC type and how ownership rights can be protected in the absence of traditional registrars or CSDs. The policy statement presents this as a staged position: RSIC custodians are subject to finalised non‑CASS cryptoasset rules (eg parts of COBS, SUP and SM&CR) while CASS 6 remains the safeguard framework in the first phase for RSICs, with further FCA engagement planned.
Settlement float: final position and constraints
PS26/11 states the FCA amended its consulted proposal on settlement float for qualifying cryptoasset trading platforms (QCATPs). The policy statement describes the final position as permitting QCATPs to hold up to 2% of each client’s cryptoassets, calculated per client and per cryptoasset class, outside the trust in a global settlement wallet for settlement purposes. The policy statement explains this change was made in response to consultation feedback that a 1% limit would be insufficient for typical customer trading volumes.
PS26/11 states that the FCA clarified that the settlement‑wallet exception is conditional on client consent and that, if a client withdraws consent, firms can no longer use the exemption for that client. The policy statement describes the FCA’s intent that the settlement float operates as a narrow exception for settlement purposes only, not as a general liquidity buffer, and that the FCA has not changed the method of calculation (ie the per client/per asset class approach) or adopted a dynamic or portfolio-wide calculation at this stage. The policy statement indicates the FCA will monitor the settlement float as the market evolves.
Trust terms, separate identifiability and virtual address statements
PS26/11 states that the FCA is proceeding with a requirement for firms subject to Article 9N to safeguard client cryptoassets on trust, subject to the specified exceptions. The policy statement describes detailed expectations for the design and operation of the trust in the rules and guidance: the terms and operations of the trust must make sure client cryptoassets are not co‑mingled with, and are separately identifiable to, any other assets.
The policy statement describes that firms may operate separate trusts through separate virtual addresses or combine client cryptoassets at different virtual addresses into the same trust, but firms will not be permitted to allocate the same single virtual address to different trusts because this would not meet the FCA’s co‑mingling/identifiability requirement. PS26/11 also states that firms must ensure any appointed third parties for safeguarding keep client cryptoassets separately identifiable and not co‑mingled with assets belonging to the firm or to any other appointment. These statements are presented as the FCA’s final wording and operational boundary for trust terms and identifiability within CASS 17.
Operational surplus: factual final‑rule description
PS26/11 states that the FCA is proceeding with allowing a limited operational surplus within the trust in circumstances where it is necessary to deliver additional services. The policy statement describes examples of services where an operational surplus may be necessary, including reduced gas fees from settling transactions and staking where the firm may need to deposit its own assets to meet protocol minimum denominators.
The policy statement states that the surplus will be subject to the same conditions consulted on, but that the FCA amended one earlier condition: firms may now use a different cryptoasset class for the operational surplus where necessary (for example, where gas fees are paid in a blockchain’s native asset different from the transacted token class). PS26/11 states that the FCA will not set a quantitative limit on the operational surplus at this stage, describing this as a proportionate approach to provide flexibility given the range of services firms may provide. The policy statement presents these points as the FCA’s final‑rule description of the operational surplus boundary; it does not provide operational instructions.
Third‑party appointment context and related constraints
PS26/11 states that the FCA is proceeding with requirements for firms that appoint third parties to safeguard client cryptoassets on trust, and that these requirements apply in addition to the SYSC outsourcing and oversight framework. The policy statement explains that SYSC 8’s definition of outsourcing is applicable and that examples of outsourced custody infrastructure cited include MPC and HSM providers, node operators and transaction‑signing infrastructure.
The policy statement describes a number of related points in the FCA’s final position: firms appointing third parties must ensure such appointments would not increase the risk of loss or diminution to client cryptoassets and must evidence their assessment; firms may rely on an appointee to conduct due diligence on subsequent third parties in a safeguarding chain; firms may delegate board approval for appointment of a third party to the person performing the safeguarding PRz or to a committee that includes that individual; and the FCA’s final rules do not permit firms to grant a security interest, lien or right of set‑off over client cryptoassets to a third party. PS26/11 also states that firms providing back‑up solutions relying on the back‑up key exception will not be permitted to appoint third parties under CASS 17.6, and that these points are part of the FCA’s final‑rule approach.
Books, records and reconciliation: Chapter 7 final‑rule context
PS26/11 states that firms safeguarding client cryptoassets as trustee must keep records that enable them to identify, for each client, the type, quantity and location of cryptoassets held and any other persons with the capacity or control to effect a transfer. The policy statement describes that cryptoassets safeguarded outside the trust are not subject to the CASS 17 record‑keeping rules and that other record regimes may apply depending on the activity (for example, staking or lending/borrowing rules in CRYPTO chapters).
The policy statement states the FCA’s approach to DLT and independence of sources of information: firms may use distributed ledger technology as an external source of information to confirm the per‑trust/class cryptoasset resource where they have not appointed third parties for safeguarding, but the same DLT source cannot be used to calculate the per‑trust/client/class requirement. PS26/11 describes the FCA’s rationale that calculation and confirmation must be independent to ensure reconciliations can identify discrepancies.
PS26/11 states that the FCA removed references to records being accurate “at all times” to be proportionate, but that reconciliations will be required per business day. The policy statement describes the reconciliation and shortfall handling rules in Chapter 7: firms must perform daily reconciliations to calculate what they are required to safeguard per client/per trust/per cryptoasset class and to confirm what they are safeguarding; firms must investigate discrepancies and remove excesses; firms must top up shortfalls in the relevant cryptoasset class or, in cases of illiquidity, may set aside or transfer an alternative asset of equivalent value with client agreement; firms must notify the FCA if a shortfall is not topped up by the next reconciliation and must immediately notify affected clients. PS26/11 states that trust records must be kept for five years after the relevant trust is brought to an end and that the FCA introduced a defined term for “safeguarding cryptoasset class” to be blockchain sensitive (permitting reference to token identifiers where relevant).
Future audit, RSIC engagement and monitoring (FCA intentions)
PS26/11 states that the FCA will revisit client cryptoasset audit requirements in a subsequent consultation and intends to finalise client cryptoasset audit requirements as part of that future work. The policy statement describes that the FCA’s policy intention remains that cryptoasset firms subject to CASS will be required to obtain an audit which checks their compliance with CASS, but that the audit details and timing will be consulted on later.
PS26/11 states that the FCA will engage further on the application of safeguarding requirements to RSIC custody and that it will consult on any further changes after that engagement. The policy statement also states that the FCA will monitor aspects of the framework (for example, the settlement float and the policy position on the trust) and that the FCA’s monitoring and future consultations are part of its intended regulatory approach as the market and relevant law develop. These statements are described by the FCA in Chapter 7 as future work and ongoing engagement rather than final changes to the rules described there.
Public‑information limit restated: no advice and no firm‑level conclusions
The policy statement describes the rules and clarifications in Chapter 7 but does not evaluate any specific firm or arrangement. PS26/11 states the FCA’s final positions and the consultation feedback it received, and the policy statement describes these as regulator‑level rules, guidance and intentions.
This article does not offer regulatory, legal, financial, investment or operational advice. The material above reproduces, summarises and attributes content from PS26/11 Chapter 7 as described in the source. No statement in this article should be read as asserting that any named or unnamed firm, wallet, service, arrangement, key, product or token is compliant, protected, safe, suitable, authorised or eligible under the FCA’s rules. The policy statement’s descriptions of exceptions, rights, record‑keeping, reconciliation, trust terms, means of access and other matters are presented as the FCA’s final rules, clarifications and future intentions set out in Chapter 7 and not as guidance for operational practice or as an assessment of any entity’s conduct.
Independent sources of information in the final record-keeping position
PS26/11 records that the FCA has modified its consultation position on record‑keeping and the sources of information firms may rely upon. The consultation (CP25/14 and CP26/4) had proposed that firms must maintain records independently from the distributed ledger technology (DLT) used and could not rely on records kept by third parties; PS26/11 states the FCA’s final position allows limited use of DLT as an external source of information, but only in specific circumstances. PS26/11 explains that firms safeguarding client cryptoassets on trust may use DLT to confirm the per‑trust/class cryptoasset resource (that is, the amount and class of cryptoasset they are safeguarding on trust) provided the firm has not appointed third parties for safeguarding.
PS26/11 distinguishes the regulatory function of a requirement from the evidential function of a resource: the FCA’s final rules, as set out in PS26/11, do not permit the same source (for example, the same on‑chain DLT data) to be used to calculate the per‑trust/client/class cryptoasset requirement and simultaneously to confirm the per‑trust/class resource. PS26/11 states the FCA’s rationale is that independence of sources is necessary for reconciliations to be effective at identifying discrepancies.
PS26/11 states further that where a firm has appointed a third party to safeguard client cryptoassets on trust, the resource confirmation must come from information provided by that third party rather than relying on the same DLT source the firm uses to calculate the requirement. PS26/11 records that this final rule prevents a situation where both the calculation and the confirmation rely on a single common information source, which the FCA says would undermine the purpose of reconciliations.
PS26/11 also clarifies scope: the FCA’s final position in PS26/11 confirms that CASS record‑keeping requirements (CASS 17.5) apply only to firms safeguarding client cryptoassets as trustee; PS26/11 states cryptoassets held outside the trust will not be subject to CASS record‑keeping and instead will be subject to other applicable record‑keeping rules for the firm’s regulated activities (for example, staking or lending). PS26/11 records that the FCA removed the consultation wording that records must be accurate “at all times” and instead ties accuracy expectations to the reconciliation cadence and supervisory requirements.
Safeguarding cryptoasset class and the FCA’s stated identifier context
PS26/11 records that the FCA has introduced a defined term for “safeguarding cryptoasset class” in the final rules, describing it as blockchain‑sensitive and permitting reference to standardised digital token identifiers where relevant. PS26/11 states that this defined term is intended to reduce ambiguity when firms identify which assets they are required to safeguard and how shortfalls or excesses are allocated across assets.
PS26/11 records that the FCA amended its consultation position on the operational surplus held within a trust. The consultation had proposed requiring any operational surplus to be made up of the same cryptoasset class as the client cryptoassets in that trust; PS26/11 states the FCA’s final rule permits a different cryptoasset class for the operational surplus where necessary (PS26/11 gives the example that gas fees payable in a blockchain’s native asset may differ from the transacted asset class). PS26/11 states the FCA will not set a quantitative limit on the operational surplus at this stage and has amended the class requirement to allow technical or service‑feature driven differences in the surplus asset class.
PS26/11 also records the FCA’s explicit formulation that a firm safeguarding client cryptoassets “would need client agreement in order to return an equivalent asset to their client via a different blockchain than the one on which the safeguarding arrangement began.” PS26/11 attributes this requirement to the new safeguarding‑class definition and states it is intended to ensure clarity where token bridging, wrapping or cross‑chain equivalents are involved.
Reconciliation detail in PS26/11 Chapter 7
PS26/11 records the FCA’s final position to proceed with reconciliation requirements that were proposed in CP26/4 and to require firms to investigate discrepancies, remove excesses and top up any shortfalls. PS26/11 states the final rules require reconciliations on a per‑trust, per‑client and per‑cryptoasset‑class basis and indicates that reconciliations will be required per business day.
PS26/11 defines, for the purposes of the final rules, how shortfalls and resources are to be treated. PS26/11 states that a shortfall exists where the firm’s per‑trust/class cryptoasset resource is less than the total per‑trust/client/class cryptoasset requirement and that such shortfalls “must be topped up.” PS26/11 records the FCA’s final rule that firms must resolve shortfalls in the relevant class of cryptoasset.
PS26/11 records the FCA’s response to respondent feedback on illiquidity and practical challenges: the FCA’s final position, as set out in PS26/11, permits a firm to set aside or transfer an alternative asset of the same value to affected clients in instances where topping up in the same class is impracticable for less liquid assets, but PS26/11 states this requires client agreement. PS26/11 states that if clients do not agree, firms continue to be required to top up the shortfall in the relevant class.
PS26/11 states the FCA’s final notification requirements: firms must notify the FCA in writing if a shortfall has not been topped up by the next reconciliation, and PS26/11 states the FCA will require firms to immediately notify affected clients when a shortfall arises. PS26/11 records that the FCA does not distinguish treatment of shortfalls by cause (for example, timing differences, network congestion or protocol delays) for the purposes of CASS 17 shortfalls; PS26/11 explains the FCA’s view that the 24/7 nature of crypto markets makes the reconciliation approach different to CASS external reconciliation arrangements in traditional finance.
Third parties in the FCA’s Chapter 7 account
PS26/11 records the FCA’s final rules on appointing third parties to safeguard client cryptoassets on trust and clarifies the interaction with the outsourcing framework. PS26/11 states the rules for appointing third parties apply to all firms safeguarding client cryptoassets on trust and that these requirements operate alongside, and in addition to, the SYSC outsourcing and oversight framework.
PS26/11 states that the FCA has refined the consultation standard: rather than requiring appointments to be “necessary” for safeguarding, PS26/11 states the final rule requires firms to make sure any appointment “would not increase the risk of loss or diminution of client cryptoassets,” supported by due diligence, oversight and written evidence. PS26/11 records that firms may rely on an appointee to perform due diligence on subsequent sub‑appointed providers and to report findings in a safeguarding chain, subject to the firm’s ongoing responsibility.
PS26/11 records specific prohibitions and restrictions adopted as final rules: the FCA’s final rules do not permit firms to grant a security interest, lien or right of set‑off over client cryptoassets to third parties, PS26/11 states that the FCA considers such rights incompatible with ensuring appointments “do not increase the risk of loss or diminution.” PS26/11 also states that firms providing back‑up solutions under the trust exception (CASS 17.3.12) will not be permitted to appoint third parties, and PS26/11 explains this restriction is intended to mitigate the additional risks a third‑party appointment could introduce where the firm is not acting as trustee.
PS26/11 records the FCA’s guidance point that firms may appoint third parties in jurisdictions that use different regulatory terms for safeguarding so long as those regimes cover comparable aspects of financial and operational resilience, security of means of access and record‑keeping. PS26/11 states the FCA expects firms to consider jurisdictional risk as part of due diligence on third‑party appointments.
Source boundary after the Chapter 7 detail
PS26/11 draws a clear boundary between the calculation of what firms should safeguard and the confirmation of what they are safeguarding. PS26/11 states the FCA’s final rule requires the per‑trust/client/class requirement (the calculation of what must be safeguarded) to be determined by the firm’s own records and systems and not to be calculated using the same DLT source used to confirm the per‑trust/class resource. PS26/11 states this separation is central to ensuring reconciliations are a meaningful supervisory and internal control tool.
PS26/11 states the FCA’s final position on means‑of‑access records and dependency of sources: the FCA amended its consultation proposal that firms review each client’s means‑of‑access record daily and, as PS26/11 sets out, will instead require firms to promptly update those records “as often as necessary” so details remain accurate. PS26/11 states the FCA retains the requirement that means‑of‑access arrangements be documented and maintained in a way that supports effective supervision and that CASS 17.4 will apply to firms providing back‑up solutions as well as trustees.
PS26/11 records that the FCA will monitor the policy positions described in Chapter 7 and intends to revisit several aspects over time. PS26/11 states the FCA will monitor the settlement float limit and the market developments that informed the operational surplus treatment. PS26/11 also records that the FCA intends to revisit and finalise client cryptoasset audit requirements through a subsequent consultation — PS26/11 states the FCA’s policy intention remains that firms subject to CASS will be required to obtain an audit checking compliance with CASS once that work has concluded.
PS26/11 thus sets out a final‑rule architecture in which the independence and provenance of information sources are integral: PS26/11 states DLT may be used under specific, limited circumstances to confirm resources, third‑party confirmations are required where third parties are appointed, and firms must maintain separation between the calculation of requirements and the confirmation of resources to support the daily reconciliation regime and FCA supervision.
Official sources
- FCA web publication, Cryptoasset regime (published 30 June 2026)
- PS26/11: Crypto Regime: Regulated Cryptoasset Activities (Policy Statement, June 2026)
Official record may describe / This article does not conclude
| Official record may describe | This article does not conclude |
|---|---|
| PS26/11 sets out final rules and guidance for regulated cryptoasset activities, including safeguarding. | Any specific firm is compliant, authorised, safe, secure or suitable. |
| CASS 17 is applied to cryptoasset custodians with adjustments described in PS26/11. | Operational custody procedures or wallet/private-key steps for any firm. |
| The FCA describes enhanced protections around ownership rights, record-keeping, reconciliation and private-key management. | Assessment of customer outcomes or guarantees of protection in individual cases. |
| The FCA increased the settlement-float model percentage limit to 2% and adopted a technology-agnostic approach to private-key management. | Advice on custody operations, technical implementations or firm selection. |
End of article. The text above quotes and paraphrases material published by the Financial Conduct Authority in the two documents listed in the Official sources section and does not introduce independent factual assertions beyond those sources.