BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

US Regulators Revisit Bank Third-Party Risk Rules as Crypto Custody Grows

Key Facts Federal banking regulators maintain interagency guidance on how banks must oversee third-party vendors. More banks are outsourcing crypto custody to specialist providers rather than

AnonymousCryptoCompass newsroom
September 13, 2026
3 min read
NEWS
US Regulators Revisit Bank Third-Party Risk Rules as Crypto Custody Grows
CryptoCompass editorial visual for policy coverage.

Key Facts

  • Federal banking regulators maintain interagency guidance on how banks must oversee third-party vendors.
  • More banks are outsourcing crypto custody to specialist providers rather than building it in-house.
  • Existing guidance predates most banks’ crypto custody arrangements and was written with traditional vendors in mind.

The core rulebook governing how a bank must supervise the outside vendors it relies on, the Interagency Guidance on Third-Party Relationships issued jointly by the Federal Reserve, the OCC and the FDIC, is facing renewed scrutiny as more banks push into crypto custody by outsourcing it to specialist providers rather than building the capability internally. The guidance itself was not written with digital assets in mind, and that gap is becoming harder to ignore as the number of banks relying on outside custodians for crypto grows.

Why Crypto Custody Strains an Old Framework

Traditional third-party risk guidance assumes a vendor relationship looks like outsourcing payment processing or core banking software, arrangements where the bank can audit the vendor’s operations, demand contractual remedies, and reasonably assume the underlying asset, a customer’s deposit, still legally exists regardless of what happens to the vendor. Crypto custody breaks that assumption in a specific way: if a custodian holding private keys on a bank’s behalf is compromised or insolvent, the underlying asset itself, not just the servicing relationship, can be irrecoverably lost. The Fed’s own guide for community banks was built around vendor failure modes that simply do not map cleanly onto that risk.

This is not a hypothetical distinction. A bank that outsources loan servicing to a vendor that goes bankrupt can transfer servicing to another provider without the underlying loans disappearing. A bank that outsources crypto custody to a provider that suffers a key-management failure can lose the assets themselves, with no equivalent recovery path. That difference in what failure actually means is the reason existing guidance, built around operational continuity and data security, does not fully capture what regulators need banks to actually verify before they sign a custody agreement with a crypto specialist.

What an Updated Framework Would Actually Need to Cover

A meaningful update would need to go beyond the standard due-diligence checklist and address questions specific to how digital assets are actually secured: how private keys are generated, stored and backed up, whether the custodian uses multi-party computation or traditional cold storage, what happens to client assets in a custodian bankruptcy under existing law, and how quickly a bank could actually verify its holdings are intact rather than taking a custodian’s word for it. None of the existing interagency guidance answers these questions directly, which is exactly the gap regulators are now being pushed to close as bank involvement in crypto custody continues to grow rather than staying a niche activity at a handful of institutions.

This post first appeared in US Regulators Revisit Bank Third-Party Risk Rules as Crypto Custody Grows