- (1) safeguarding cryptoassets which are client cryptoassets; or
- (2) safeguarding cryptoassets which would be client cryptoassets but are not being treated by the firm as client cryptoassets in reliance upon CASS 17.3.12R.
CASS 17.4 Means of access
CASS 17.4 Means of access
This section applies to a firm when it is:
The rules in this section apply where a firm undertakes any of the following activities in relation to the means of access to a cryptoasset in respect of which the firm is safeguarding cryptoassets:
- (1) generating or creating the means of access, or any similar process;
- (2) storing the means of access, in any form or medium of storage;
- (3) exercising any form of control over the means of access;
- (4) subjecting the means of access to any type of process; and
- (5) destroying the means of access.
- (1) Because the rules in this section apply where a firm is safeguarding cryptoassets, this means that they do not apply where the firm does not have the requisite degree of ‘control’ as described at article 9N(4) of the Regulated Activities Order.
- (2) The definition of means of access includes any means of which a person would need possession or knowledge to bring about a transfer of the benefit of a cryptoasset to another person.
- (3) The scope of CASS 17.4.2R is broad and therefore the provisions in this section will apply to a range of activities and aspects of safeguarding cryptoassets, for example:
- (a) using ‘hot’ or ‘cold’ devices or facilities to store the means of access;
- (b) making and storing written records of the means of access; and
- (c) processing the means of access by dividing a private cryptographic key into parts (‘shards’), and (if relevant) distributing the shards amongst the firm’s staff or other persons outside of the firm.
- (4)
- (a) If a person is, at a particular point in time, safeguarding only a single part of a private cryptographic key (eg, a ‘shard’) then, as a consequence of that fact by itself, they may be unlikely to have the requisite degree of ‘control’ as described at article 9N(4) of the Regulated Activities Order (assuming safeguarding just that one shard does not afford them the requisite degree of ‘control’ as described at article 9N(4)).
- (b) However, if that person was previously in the position to create that shard and all the other shards from a private cryptographic key, then at that point they would have had the requisite degree of ‘control’ – even if after sharding the key they proceeded to distribute the other shards to other persons. Because they would have subjected the means of access to a process (the ‘sharding’ process), then as a result of CASS 17.4.2R(4) and the fact that they had the requisite degree of control at the time of the sharding, and assuming they are a firm, the requirements of this section would apply to that firm.
- (c) Continuing from the example in (b) of a firm sharding a private cryptographic key and distributing it: if, after distributing the shards to other persons the firm can still require those other persons to return their shards under a binding agreement (or require their assistance to convene sufficient shards in order to digitally sign a transaction), then also as a result of CASS 17.4.2R(3), this section would apply to that firm.
- (d) If any of the recipients of the shards had sufficient shards to themselves have the requisite degree of ‘control’ as described at article 9N(4) of the Regulated Activities Order then, assuming they are firms, as a result of CASS 17.4.2R(2), this section would apply to them also.
- (5) In scenarios involving shards, the record required at CASS 17.4.8R(1)(d) should explain how the firm can exercise ‘control’, for example by setting out any relevant technical criteria which the firm is able to meet in order to digitally sign a transaction (such as a reconstruction or confirmation threshold), as well as how the firm is able to meet those criteria (for example, by a combination of retrieval from cold storage and requiring an appointed shard-holder to take certain steps).
A firm must have robust security and organisational arrangements to ensure that, throughout the entire life cycle of any means of access to a client cryptoasset, the means of access are protected against the risks of inoperability, inaccessibility, loss, fraud and irrecoverability.
A firm must promptly identify incidents of inoperability, inaccessibility, loss, fraud and irrecoverability to any means of access to a client cryptoasset.
A firm must promptly resolve any incidents of inoperability, inaccessibility, loss, fraud and irrecoverability to any means of access to a client cryptoasset.
In complying with CASS 17.4.4R to CASS 17.4.6R, a firm should, for example, consider whether, as relevant:
- (1) its security and organisational arrangements adhere to any relevant international and industry standard practices;
- (2) it is addressing any vulnerabilities to hacking and other risks of fraud and theft, including risks which originate from among the firm’s own staff;
- (3) it has a culture of detecting and acting on suspicious activity, including appropriate whistleblowing systems;
- (4) it is addressing any:
- (a) risks of ‘single point of failure’ (for example, as a result of a concentration of means of access with too few members of staff or on too few devices); and
- (b) ‘dependency risk’ (for example as a result of distribution among too many members of staff or devices, or too much reliance on other persons);
- (5) it has appropriate back-up and recovery systems;
- (6) it has appropriate checks to ensure that the means of access remain accessible and operable, which themselves do not add undue security risks; and
- (7) it employs random and non-deterministic methods as part of its security arrangements to minimise the risk of irreproducibility of any important data.
- (1) For each means of access that a firm controls at any particular point in time, and from the point at which the firm has such control, the firm must make and maintain a record which sets out the following information (the ‘cryptoasset means of access record’):
- (a) the location (whether digital or physical) at which that means of access is being held including, where relevant, the virtual address for that means of access;
- (b) a summary of the security measures which the firm has deployed for that means of access in accordance with CASS 17.4.4R, which must include the name of any other persons involved;
- (c) the name of any natural person, such as a member of staff of the firm, who, to the firm’s knowledge, is in a position to use that means of access;
- (d) the way in which the means of access, whether by itself or in combination with other means of access, affords the firm ‘control’ over the relevant cryptoasset or cryptoassets in respect of which it is safeguarding cryptoassets; and
- (e) whether the means of access has been destroyed (and, if so, when and the reason why it was destroyed).
- (2) The cryptoasset means of access record under (1) must not contain or reproduce the means of access itself.
- (3) The components of the cryptoasset means of access record under (1)(b) and (c) do not have to include the actual name of a person if doing so would compromise the firm’s ability to comply with CASS 17.4.4R, provided that the record includes sufficient information from which the person can be identified using other records maintained by the firm.
A firm must promptly update its cryptoasset means of access records required under CASS 17.4.8R as often as is necessary for the details within them to remain accurate.
A firm must ensure that each cryptoasset means of access record is retained for a period of 5 years starting from whichever is the later of:
- (1) the date it was created; or
- (2) the date it was most recently modified.
- (1) A firm must create, retain and maintain a means of access policy document and a means of access procedures document which, taken together, explain the firm’s means of complying with the requirements in CASS 17.4.4R to CASS 17.4.6R and CASS 17.4.8R to CASS 17.4.10R in clear and non-technical terms.
- (2) A firm must review the documents under (1) at least once every year and make any necessary changes.
- (3) A firm must retain each version of the documents required under (1) for a period of 5 years until after that version has been superseded by a new version.
