- (1) The scope of the regulated activity of safeguarding cryptoassets covers a range of legal relationships between the firm and the client in relation to a qualifying cryptoasset or relevant specified investment cryptoasset. It does not only apply where a cryptoasset that is controlled by a firm belongs to a client.
- (2) Where the other conditions of the scope of the activity are met, the regulated activity of safeguarding cryptoassets is carried on in cases where the person on whose behalf the firm is safeguarding is the beneficial owner of the cryptoasset, and also in certain cases where that person has a right against the firm for return of a cryptoasset. The scope of the regulated activity for the latter type of case (where that person has a right for return) depends on whether the firm and that person have entered into a ‘title transfer collateral arrangement’ or repurchase agreement and on whether that person is a ‘consumer’ (as those terms are defined at Article 9N(5) of the RAO).
- (3) The purpose of this section is to:
- (a) set out a general requirement which would prohibit a firm from carrying on the regulated activity of safeguarding cryptoassets under any of those sorts of legal relationships that are within the scope of that regulated activity other than as a trustee;
- (b) provide certain exemptions to that requirement to act as a trustee, subject to particular conditions being met; and
- (c) set out other more specific requirements which a firm must meet when that requirement to act as a trustee applies.
- (4)
- (a) In the following guidance, the FCA sets out its policy rationale for the requirements and exemptions in this section concerning trusts.
- (b) It is important that, in line with the requirements in CASS 17.2, clients’ rights to cryptoassets which are being safeguarded are adequately protected through the use of trusts which can withstand competing claims to those cryptoassets, for example in case of the insolvency of the firm which is carrying on the regulated activity of safeguarding cryptoassets. In the FCA’s view, this has market integrity advantages in the context of section 1D of the Act.
- (c) Furthermore, in the FCA’s view, taking account of potential difficulties that a client may have in evidencing and asserting ownership claims to cryptoassets (particularly where the firm has full control over those cryptoassets), a trust arrangement has consumer protection advantages over other legal arrangements that might exist between a client and firm in the context of safeguarding cryptoassets (such as an absolute title transfer or an agency arrangement), in the context of section 1C of the Act.
- (d) This general requirement to safeguard cryptoassets as a trustee is set out at CASS 17.3.3R.
- (i) That rule requires a firm to agree with its client that the firm will act as a trustee, so that this should clear to the client.
- (ii) That rule does not create a statutory trust; the FCA is of the view that firms to which that requirement applies should have some flexibility around how they create private trusts, subject to certain conditions being met (see CASS 17.3.14R to CASS 17.3.18G).
- (iii) Detailed and up-to-date records are also mandatory (see CASS 17.3.19R).
- (e) However, certain other services which clients may engage a firm which is carrying on the regulated activity of safeguarding cryptoassets to provide in relation to cryptoassets would not be compatible with cryptoassets being safeguarded on trust. This is provided for at:
- (i) CASS 17.3.4R in relation to qualifying cryptoasset lending;
- (ii) CASS 17.3.5R in relation to the settlement of transactions executed on a UK QCATP; and
- (iii) CASS 17.3.6 in relation to other services.
- (f) In addition, a firm may be released from the requirement to act as a trustee where its dealings with the relevant client would require that. This is provided for at:
- (i) CASS 17.3.8R in relation to a client’s instructions to transfer a cryptoasset to another person (including the firm); and
- (ii) CASS 17.3.10R in relation to a client’s indebtedness to the firm.
- (g) Furthermore, the FCA is of the view that it is disproportionate to require a firm to be a trustee where it is engaged to only provide a backup solution where its client contemporaneously retains full control of the cryptoasset in question. This is provided for at CASS 17.3.12R.
- (h) Firms should note that each of the exemptions referred to above are subject to conditions set out within those rules.
- (i) Finally, and again provided certain conditions are met including that this is necessary in order to service clients, a firm may co-mingle ‘house’ cryptoassets in the same trust as client cryptoassets. See CASS 17.3.20R on operational surpluses.
CASS 17.3 Cryptoasset safeguarding trusts
CASS 17.3 Cryptoasset safeguarding trusts
This section applies to a firm when it is safeguarding cryptoassets.
Context and purpose
Requirement to safeguard as a trustee
- (1) Unless otherwise permitted in this section, a firm must ensure that wherever it carries on the regulated activity of safeguarding cryptoassets, it does so as a trustee of the relevant cryptoasset under trust arrangements which comply with CASS 17.3.14R.
- (2) In so far as the requirement in (1) applies, a firm must ensure that its client on behalf of whom it is safeguarding cryptoassets has agreed to the firm safeguarding cryptoassets as a trustee (for example in any written agreement required under COBS 8.1 (Client agreements: non-MiFID designated investment business)).
- (3) A firm must ensure that its client’s agreement under (2) addresses how the trust is to be established (for example in relation to legal title transferring to the firm pursuant to a transfer of the cryptoasset to the firm’s control).
Exemption from acting as a trustee for cryptoasset lending
- (1) A firm is not required to safeguard cryptoassets as a trustee under CASS 17.3.3R or, if it is already carrying on safeguarding cryptoassets in respect of a client cryptoasset as a trustee under CASS 17.3.3R, the firm may cease to treat a cryptoasset as a client cryptoasset, where the client on behalf of whom the firm is carrying on safeguarding cryptoassets has engaged the firm to provide a qualifying cryptoasset lending service in relation to a cryptoasset.
- (2) The exemption in (1) only applies during the period for which the qualifying cryptoasset lending service is being provided in relation to that cryptoasset.
- (3) Once that qualifying cryptoasset lending service in relation to a cryptoasset has ended for any reason, including by prior agreement or if the client has exercised any right to require that service to cease in relation to a cryptoasset, the exemption in (1) no longer applies.
- (4) A firm may not use the exemption in (1) in relation to any cryptoasset which represents qualifying cryptoasset borrowing collateral, whether the obligations which the cryptoasset secures are owed to the firm itself or to another authorised person who has, under CRYPTO 9.6.8R(1)(b), arranged for the firm to carry on the regulated activity of safeguarding cryptoassets.
Exemption from acting as a trustee for qualifying cryptoasset trading platforms
A firm may cease to treat a qualifying cryptoasset as a client cryptoasset (and therefore cease to carry on safeguarding cryptoassets as a trustee of the cryptoasset) where:
- (1) the client on behalf of whom the firm is safeguarding the qualifying cryptoasset is also a user of a UK QCATP operated by the firm itself or another person in the firm’s group;
- (2) that client is trading, or has made it clear to the firm that they intend to trade, with qualifying cryptoassets of that cryptoasset safeguarding class using that UK QCATP;
- (3) as part of the day-to-day operation of that UK QCATP, the UK QCATP operator needs to take control of qualifying cryptoassets to facilitate the settlement of transactions executed on that UK QCATP;
- (4) the firm has obtained the client’s prior informed consent, in accordance with CASS 17.3.11R, to the qualifying cryptoasset ceasing to be a client cryptoasset in order for transactions executed on the UK QCATP in that cryptoasset safeguarding class to settle; and
- (5) at all times, the amount of cryptoassets of a particular cryptoasset safeguarding class which the firm is not treating as client cryptoassets under this rule for the client does not exceed 2% of the total amount of cryptoassets of that particular cryptoasset safeguarding class which remain in the firm’s trusteeship for that client under CASS 17.3.3R.
Exemption from acting as a trustee where necessary for other services
- (1) A firm is not required to safeguard cryptoassets as a trustee under CASS 17.3.3R or, if it is already carrying on safeguarding cryptoassets in respect of a client cryptoasset as a trustee under CASS 17.3.3R, the firm may cease to treat that cryptoasset as a client cryptoasset, where:
- (a) the client on behalf of whom the firm is carrying on safeguarding cryptoassets has engaged the firm to provide a service (other than services described in CASS 17.3.4R or CASS 17.3.5R);
- (b) in order to provide that service to the client, the firm has concluded that it is necessary:
- (i) for the firm to have ownership of the cryptoasset; and/or
- (ii) for the firm to effect a transfer of ownership of the cryptoasset to another person; and
- (c) the firm has obtained the client’s prior informed consent, in accordance with CASS 17.3.11R, to that transfer of ownership in order for the service to be provided.
- (2) Where a service for which the firm has relied on (1) ends, or where it is no longer necessary for the firm or another person to have ownership of cryptoassets, the exemption in (1) no longer applies.
- (3) For each distinct service for which the firm intends to rely on (1), and prior to providing that service to any client, the firm must make a record of the reasons for concluding that it is necessary for the firm to have ownership of cryptoassets, or to effect a transfer of ownership of cryptoassets to another person, in order to provide that service (the ‘client cryptoasset trust exemption record’).
- (4) For the purposes of (3), a service must be considered ‘distinct’ if it has different technical features, a different purpose, or a different type of risk to the client to a service which has already been assessed by the firm.
- (5) The firm must retain each client cryptoasset trust exemption record made under (3) for a period of 5 years after it has stopped providing the relevant service.
- (6) A firm may not use the exemption in (1) in relation to any cryptoasset which represents qualifying cryptoasset borrowing collateral, whether the obligations which the cryptoasset secures are owed to the firm itself or to another authorised person who has, under CRYPTO 9.6.8R(1)(b), arranged for the firm to carry on the regulated activity of safeguarding cryptoassets.
- (1) The reference to ‘distinct’ service in CASS 17.3.6R(3) should be interpreted on a granular basis, meaning that a firm should investigate and conclude that a transfer of ownership is necessary in relation to the specific features of the service. For example, if a firm intends to rely on CASS 17.3.6R(1) in order to carry on the activity of arranging qualifying cryptoasset staking, it should make a record under CASS 17.3.6R(3) for each staking protocol in relation to which it will provide services.
- (2) For the purposes of CASS 17.3.6R(1), the term ‘service’ should not be limited to services which only comprise regulated activities.
Exemption from acting as a trustee to act on client instructions to transfer
A firm may cease to treat a cryptoasset as a client cryptoasset where:
- (1) The reference to an ‘express and specific instruction’ at CASS 17.3.8R(1) means that the rule cannot be relied on where the client has given the firm a mandate in relation to their client cryptoassets without any specific instruction for any particular transfer (for example, a discretionary investment mandate). For such a service where there is no express and specific client instruction, a firm may be able to rely on CASS 17.3.6R provided that the conditions in that rule are met.
- (2) Following a transfer under CASS 17.3.8R to another person (the ‘transferee’), the firm would be required to continue to safeguard cryptoassets in accordance with the requirements in this section if it is carrying on the regulated activity of safeguarding cryptoassets on behalf of the transferee in relation to that cryptoasset. This may mean that the firm will be required to safeguard cryptoassets as a trustee on behalf of the transferee.
Exemption from acting as a trustee where the client is indebted to the firm
A firm may cease to treat a cryptoasset as a client cryptoasset where:
- (1) the relevant client has given the firm a right, through a written binding agreement, to take ownership of their cryptoassets in order to discharge an obligation that the client owes to the firm; and
- (2) the firm has exercised that right in accordance with the terms of that written agreement in relation to those client cryptoassets.
Obtaining a client’s consent
- (1) This rule sets out steps which a firm must take in the course of obtaining a client’s prior informed consent under CASS 17.3.5R(4) or CASS 17.3.6R(1)(c).
- (2) For any retail market business, the firm’s process for obtaining prior informed consent must be compatible with the Consumer Duty.
- (3) In the course of seeking consent, the firm must specifically and clearly explain to the client the risks to the client of the cryptoasset not being within a trust, including in the event of the firm’s failure.
- (4) Any consent provided by a client must be obtained in writing and a record of it (the ‘client cryptoasset trust exemption consent record’) must be retained for a period of 5 years after the firm has stopped relying on the consent to use the exemption at CASS 17.3.5R(1) or CASS 17.3.6R(1), as applicable.
- (5) If a client withdraws their consent, the firm can no longer rely on the exemption at CASS 17.3.5R(1) or CASS 17.3.6R(1), as applicable, from the time at which the client’s withdrawal of consent takes effect (taking into account any agreed notice period).
- (6) A contravention of (2) does not give rise to a right of action by a private person under section 138D of the Act (and CASS 17.3.11R(2) is specified under section 138D(3) of the Act as a provision giving rise to no such right of action).
- (7) A contravention of any other aspect of this rule is not affected by (6).
Exemption from acting as a trustee where providing a backup solution
A firm is not required to safeguard cryptoassets as a trustee under CASS 17.3.3R where all the following conditions are met:
- (1) the firm has good reason to believe that the client on whose behalf the firm is carrying on safeguarding cryptoassets in respect of a particular cryptoasset has its own means of access which would enable the client to transact using the cryptoasset without relying on the firm;
- (2) where that client is a firm that is itself also carrying on safeguarding cryptoassets in relation to that cryptoasset, that client has confirmed to the firm to which this rule applies that it is itself carrying on safeguarding cryptoassets in respect of that cryptoasset as a trustee under CASS 17.3.3R (as it applies to that client);
- (3) the firm has not been appointed to provide any service in relation to that cryptoasset other than:
- (a) undertaking one or more of the activities set out at CASS 17.4.2R in relation to the relevant means of access to the cryptoasset for which it is carrying on safeguarding cryptoassets; and
- (b) undertaking those activities at CASS 17.4.2R only for the purposes of assisting the client in the event that the client’s own means of access becomes lost, inoperable, inaccessible or irrecoverable; and
- (4) when carrying on that limited safeguarding cryptoassets service, the firm does not also carry on the activity of arranging cryptoasset safeguarding in relation to that cryptoasset.
- (1) It may be possible for a firm to rely on the exemption at CASS 17.3.12R where it has been appointed to provide a backup and recovery solution for a client (and no other service).
- (2) The client in the situation described in (1) may itself be another firm (or an unauthorised cryptoasset service provider) which has engaged the firm to provide that backup and recovery solution in order to make its own service more robust. The condition at CASS 17.3.12R(2) is only relevant where the client is a is another firm which is itself carrying on safeguarding cryptoassets in respect of the relevant cryptoasset.
- (3) Where the client is another firm which is not carrying on safeguarding cryptoassets in respect of the relevant cryptoasset (for example, because it owns the cryptoasset outright for the purposes of dealing in qualifying cryptoassets as principal, and no other person has a right for the return of it) then the condition at CASS 17.3.12R(2) would not be relevant.
- (4) Likewise, where the client is simply the investor in the cryptoasset (and provides no service to any other person) then the condition at CASS 17.3.12R(2) would not be relevant.
- (5) To meet the condition at CASS 17.3.12R(1), it should not be necessary for the firm to prove (cryptographically or otherwise) that the client has their own means of access, but the firm should be able to explain the basis of its belief that the client is in that position. For example, this may be a point which is addressed in the firm’s agreement with the client.
- (6) The client’s own means of access referred to at CASS 17.3.12R(1) may be a duplicate copy of the firm’s means of access or may be an alternative means of access which co-exists with the firm’s means of access.
Setting up and operating client cryptoasset trusts
For any client cryptoasset, the firm must ensure that:
- (1) the trust that is required under CASS 17.3.3R is created and operated by the firm in accordance with applicable legal requirements for trusts in the UK;
- (2) the terms of any such trust are clearly documented with the effect that it is clear the trust is intended and it is clear what the terms are; and
- (3) the terms and operation of the trust by the firm deliver the objectives and include the provisions set out in CASS 17.3.17R.
To comply with CASS 17.3.14R(2) a firm may, for example, execute a deed or similar formal instrument.
A firm must retain any document required under CASS 17.3.14R(2) setting out the terms of a trust, and details of any amendments which were made to the terms after the trust was first created, from the point at which the trust is created or the terms of the trust amended, and until 5 years after the trust has been brought to an end.
A firm must ensure that the terms and operation of any trust that is required under CASS 17.3.3R deliver the objectives at (1) and (2) and include the provisions at (3) and (4):
- (1) The firm must act as a trustee in relation to the client cryptoassets as well as in relation to any rights which can be exercised by virtue of the firm safeguarding cryptoassets, and in particular:
- (a) the firm must be required to respond to the lawful instructions of the relevant client in relation to the client cryptoassets; and
- (b) save for having the necessary powers to comply with any applicable rules or legal requirements, or unless otherwise agreed with the client, the firm must not have any discretion in applying, investing or otherwise using any client cryptoassets which are trust property.
- (2) Subject to CASS 17.3.20R, the firm’s operation of the trust ensures that the client cryptoassets within the trust are not co-mingled with, and are identifiable separately from, any other assets (for example, any assets for which the firm is not carrying on safeguarding cryptoassets, any assets for which the firm is relying on an exemption to act as a trustee under this section, and any assets which pertain to any other separate trust that is created to meet CASS 17.3.3R).
- (3) Where there is, or is intended to be, more than one client on whose behalf the firm is safeguarding cryptoassets within a single trust, the terms of that trust must set out how any shortfalls in the trust, whether within a particular cryptoasset safeguarding class or across all cryptoasset safeguarding classes of client cryptoassets within the trust, are to be allocated between the clients.
- (4) The terms of the trust must set out whether or not the client cryptoassets within the trust may be applied towards funding the distribution costs of the trust on the failure of the trustee and, if the terms do provide for this, the basis on which that funding will be deducted from the entitlements of the clients.
- (1) A firm should decide on an approach to settling and operating trusts under the rules in this section which is suitable for its business model, its client base and the types of client cryptoassets in respect of which it will be safeguarding cryptoassets. In particular:
- (a) a firm may decide whether to operate separate trusts for each client or one or more ‘omnibus’ trusts for a particular class of clients (which may include all clients);
- (b) a firm may decide whether to operate separate trusts for different cryptoasset safeguarding classes; and
- (c) a firm may decide whether to operate separate trusts distinctly, using separate virtual addresses or devices, or to combine client cryptoassets at different virtual addresses or devices into the same trust.
- (2) (a) A firm should consider whether the objective in CASS 17.3.17R(2) can be achieved through the use of different virtual addresses, with regard to the operation of the relevant network.
- (b) A particular network relevant to a type of client cryptoasset may affect the choices available to a firm in deciding how to implement a trust which complies with the rules in this section.
- (c) Where the network relies on another network for its functioning, a firm should ensure that the ownership of the client cryptoassets cannot be challenged or reversed through the operation of technology.
- (d) Allocating client cryptoassets which exist at the same single virtual addresses or on the same single device into different trusts would not meet the requirement at CASS 17.3.17R(2) in relation to co-mingling.
- (3) (a) A firm may decide how any shortfall in a trust should be allocated between clients, but in doing so, a firm should consider the requirement at CASS 17.1.6R.
- (b) The FCA would generally expect a shortfall in a particular cryptoasset safeguarding class within a trust to be borne ‘pro rata’ by all clients for whom the firm is safeguarding cryptoassets of that particular cryptoasset safeguarding class in that particular trust, in proportion to their respective interests in those cryptoassets.
- (4) The way in which a firm decides to set up its trust environment and the way in which it achieves the required segregation should be recorded in the firm’s client cryptoasset trust records.
The client cryptoasset trust record
- (1) A firm must make and keep updated a record of each trust that it has created under CASS 17.3.3R which sets out the following details for that trust (the ‘client cryptoasset trust record’):
- (a) a unique identifier code for the trust;
- (b) the means by which the firm achieves the obligation at CASS 17.3.17R(2) including, where applicable:
- (i) each relevant virtual address or device controlled by the firm at which cryptoassets pertaining to the trust are being safeguarded by the firm;
- (ii) the name of each third party who has been appointed to safeguard cryptoassets pertaining to the trust under CASS 17.6; and
- (iii) the identifier of the relevant network for the trust property;
- (c) the name of each client who has an interest in the trust;
- (d) the cryptoasset safeguarding class(es) in the trust, identified using the name of the cryptoasset or an identification code, in either case from which the relevant cryptoasset safeguarding class can be precisely distinguished;
- (e) the location of the record of the terms of the trust required under CASS 17.3.16R;
- (f) whether or not the firm has decided for the trust to include an operational surplus under CASS 17.3.20R; and
- (g) if the trust has been brought to an end, the date of that occurring and the reason why it was brought to an end.
- (2) A client cryptoasset trust record must be made at the same time as the relevant trust is created, and it must be updated immediately:
- (a) upon making any changes to that trust; and
- (b) as necessary following any client cryptoasset reconciliation under CASS 17.5.
- (3) A client cryptoasset trust record must be retained for a period of 5 years after the relevant trust has been brought to an end.
Permitted operational surplus in trusts
A firm may include, within any trust required to be created under CASS 17.3.3R, an amount of additional qualifying cryptoassets or relevant specified investment cryptoassets funded from the firm’s own resources in order to meet the firm’s operational needs (an ‘operational surplus’), provided the following conditions are met:
- (1) An operational surplus in a trust is only permitted if it is necessary in order for the firm to provide services to one or more clients for whom the firm is safeguarding cryptoassets.
- (2) Subject to (3), the operational surplus must be in the same cryptoasset safeguarding class as that in relation to which the firm is providing the services that necessitate the operational surplus.
- (3) As an exception to (2), the operational surplus may be in a different cryptoasset safeguarding class where that would be necessary due to a technical limitation or feature of those services which the firm intends to provide.
- (4) The amount of cryptoassets which form the operational surplus in any trust must not exceed a level that would be reasonably expected to be necessary, taking into account those services.
- (5) The terms of the trust required under CASS 17.3.14R(2) and CASS 17.3.17R(3) must clearly set out that the firm’s claim in the trust to the operational surplus in a particular cryptoasset safeguarding class is always and unconditionally subordinated to the claims of clients to client cryptoassets of that cryptoasset safeguarding class in the trust.
- (6) When deciding to use a operational surplus in any trust that a firm operates under CASS 17.3.3R, the firm must make and retain a written record of the reason for the operational surplus to be necessary in order for the firm to provide services to one or more clients for whom the firm is safeguarding cryptoassets in the same trust (the ‘per-trust operational surplus record’).
- (7) The firm must not remove or reduce an operational surplus unless the amount removed represents an excess, and is removed following a client cryptoasset reconciliation, in accordance with CASS 17.5.12R.
A firm must retain any per-trust operational surplus record made under CASS 17.3.20R(4) for a period of 5 years until after the firm ceases to use the operational surplus in that particular trust.
- (1) An example of where a firm may wish to use an operational surplus under CASS 17.3.20R(1) includes where the firm’s service involves qualifying cryptoasset staking and, for example:
- (2) An example of where the exception at CASS 17.3.20R(3) may be relied on is to allow the firm to satisfy a requirement to pay transaction charges such as ‘gas fees’ in the cryptoasset safeguarding class that is required by the network when the transaction for which the firm is providing a service involves other cryptoasset safeguarding classes.
Guidance on trusts and appointing third parties
- (1) In cases where a firm appoints a third party to carry on the activity of safeguarding cryptoassets in accordance with CASS 17.6, the effect of CASS 17.3.3R and CASS 17.3.17R(1) means that the firm’s contractual rights against that third party in relation to the relevant client cryptoassets should be held on trust, because these are rights which can be exercised by virtue of the firm safeguarding cryptoassets.
- (2) A firm in the position referred to in (1) should also comply with the other requirements of CASS 17.6.
