You are viewing CASS 17.5 Records of cryptoassets and reconciliations as it appeared on 25/10/2027. The current version of CASS 17.5 Records of cryptoassets and reconciliations was last updated on 25/10/2027.

CASS 17.5 Records of cryptoassets and reconciliations

25/10/2027R

This section applies to a firm when it is safeguarding cryptoassets which are client cryptoassets.

General requirements

25/10/2027R

A firm must keep such records as necessary to enable it at any time and without delay to distinguish client cryptoassets in respect of which the firm is safeguarding cryptoassets on behalf of one client from client cryptoassets in respect of which the firm is safeguarding cryptoassets on behalf of any other client, and from any cryptoassets which are not client cryptoassets.

25/10/2027R

A firm must maintain its records in a way that ensures their accuracy, having regard to the business model of the firm and in particular the risks of:

  1. (1) records becoming unreliable due to the nature of the firm’s services and the networks relevant to the client cryptoassets; and
  2. (2) the firm breaching the rule at CASS 17.3.3R.
25/10/2027R
  1. (1) A firm must establish and maintain systems and controls so that it can accurately determine the following and promptly identify and resolve any discrepancies in accordance with the rules in this section:
    1. (a) for each trust that the firm has created under CASS 17.3.3R and in accordance with CASS 17.5.6R, the number of client cryptoassets of a particular cryptoasset safeguarding class in respect of which it is required to be safeguarding cryptoassets for a particular client (the per-trust/client/class cryptoasset requirement), taking into account its agreements with that client and any services that have been provided or are being provided to that client; and
    2. (b) for each trust that the firm has created under CASS 17.3.3R and in accordance with CASS 17.5.7R, how many client cryptoassets of a particular cryptoasset safeguarding class it is safeguarding cryptoassets in relation to (the per-trust/class cryptoasset resource), whether itself or through the appointment of a third party under CASS 17.6.
  2. (2) A firm’s systems and controls under (1) must be designed to minimise the risks of inaccuracy, taking into account in particular:
    1. (a) the time of day at which any processes to comply with CASS 17.5.6R to CASS 17.5.10R are run; and
    2. (b) its arrangements for obtaining information from any third party appointed under CASS 17.6 in order to comply with CASS 17.5.7R.
  3. (3) A firm must create, retain and maintain a reconciliations policy document and a reconciliations procedures document which, taken together, explain and set out:
    1. (a) the firm’s rationale for its procedures to comply with the rules in this section in clear and non-technical terms; and
    2. (b) those procedures.
  4. (4) A firm must review the documents under (3) at least once every year and make any necessary changes.
  5. (5) A firm must retain each version of the documents required under (2) for a period of 5 years until after that version has been superseded by a new version.
25/10/2027G
  1. (1) Depending on the way a firm has complied with the rules in CASS 17.3, it may be necessary for the firm, when complying with the rules in this section, to make distinctions between different trusts that it has created under CASS 17.3.3R, and between different aspects of those trusts (such as whether or not it has decided for a particular trust to include an operational surplus under CASS 17.3.20R).
  2. (2) When maintaining its records under the rules in this section, a firm should be making the distinctions referred to in (1) on the basis of its client cryptoasset trust records, which are required to be kept up to date under CASS 17.3.19R(2).

The per-trust/client/class cryptoasset requirement

25/10/2027R
  1. (1) A firm must calculate the per-trust/client/class cryptoasset requirement using the formula in (2) at least once each business day, with the result that, for each trust that the firm has created under CASS 17.3.3R, it produces, separately for each client that has an interest in that trust, the quantity of each client cryptoasset of each particular cryptoasset safeguarding class that the firm is required to hold for that client under that trust in accordance with the rules in CASS 17.3 (Cryptoasset safeguarding trusts).
  2. (2) The per-trust/client/class cryptoasset requirement in (1) is calculated as (a) minus (b), where (a) and (b) are as follows:
    1. (a) the sum of:
      1. (i) the firm’s previous per-trust/client/class cryptoasset requirement for the relevant trust, client and cryptoasset safeguarding class; and
      2. (ii) the total of the following, each for the relevant trust:
        1. (A) the number of client cryptoassets of the relevant cryptoasset safeguarding class which the firm has received from the client since the previous calculation;
        2. (B) the number of client cryptoassets of the relevant cryptoasset safeguarding class which the firm has received on behalf of that client from any other person since the previous calculation;
        3. (C) (to the extent not covered by (B)) the number of client cryptoassets of the relevant cryptoasset safeguarding class which have become due to the client, whether from the firm or earned in some other way, since the previous calculation; and
        4. (D) (to the extent not covered by (B) or (C)) the number of client cryptoassets of the relevant cryptoasset safeguarding class which were required to be reinstated into the trust since the previous calculation under the rules at CASS 17.3 (Cryptoasset safeguarding trusts), including because of the end of a particular service; and
    2. (b) the total of the following, each for the relevant trust:
      1. (i) the number of client cryptoassets of the relevant cryptoasset safeguarding class which the client has withdrawn from the firm since the previous calculation;
      2. (ii) the number of client cryptoassets of the relevant cryptoasset safeguarding class which the firm has transferred to another person on the client’s instruction since the previous calculation;
      3. (iii) the number of client cryptoassets of the relevant cryptoasset safeguarding class which have become due to the firm since the previous calculation, in respect of which the firm has a right to take ownership of the cryptoasset under CASS 17.3.10R;
      4. (iv) the number of client cryptoassets of the relevant cryptoasset safeguarding class in respect of which the firm has relied on an exemption under CASS 17.3.4R, CASS 17.3.5R or CASS 17.3.6R to not hold the cryptoassets under the trust since the previous calculation;
      5. (v) (to the extent not covered by (iii) or (iv)) the number of client cryptoassets of the relevant cryptoasset safeguarding class which, since the previous calculation and as a result of services being provided by the firm, the client has been required to surrender; and
      6. (vi) the number of client cryptoassets of the relevant cryptoasset safeguarding class in respect of which, following an unresolved shortfall, the firm has agreed with its client that it will no longer have to carry on safeguarding cryptoassets.
  3. (3) A firm must use its internal records of client instructions, transactions and services to calculate any per-trust/client/class cryptoasset requirement under this rule, and must not use information from an external source (such as information contained on a blockchain or distributed ledger technology).

The per-trust/class cryptoasset resource

25/10/2027R
  1. (1) For each trust that a firm has created under CASS 17.3.3R, the firm must confirm the quantity of client cryptoassets of a particular cryptoasset safeguarding class in respect of which it is safeguarding cryptoassets under that trust at least once each business day (the ‘per-trust/class cryptoasset resource’).
  2. (2) The confirmation required under (1) must take account of both:
    1. (a) the client cryptoassets of that particular cryptoasset safeguarding class which the firm can access in virtual addresses or devices; and
    2. (b) where the firm has, under CASS 17.6, appointed a third party to carry on the activity of safeguarding cryptoassets, the client cryptoassets for which either:
      1. (i) the third party has confirmed to the firm that it has the means of access to itself; or
      2. (ii) in cases where that third party has appointed a further third party with the firm’s consent under CASS 17.6.9R, the third party appointed by the firm has confirmed to the firm that the further third party has the means of access to.
  3. (3) A firm must use external sources of information to confirm any per-trust/class cryptoasset resource under this rule, and must not use any internal source of information which the firm uses to calculate any per-trust/client/class cryptoasset requirement under CASS 17.5.6R
25/10/2027G
  1. (1) The requirements at CASS 17.5.6R(3) and at CASS 17.5.7R(3) are to ensure that a firm’s client cryptoasset reconciliations use independent sources of information, with the effect that the client cryptoasset reconciliations will be effective in their purpose of identifying discrepancies.
  2. (2) A firm may use information from an external source such as information contained on the appropriate distributed ledger technology network to confirm the information described at CASS 17.5.7R(2)(a).
  3. (3) Although information contained on a blockchain or distributed ledger technology may give an indication as to the information described at CASS 17.5.7R(2)(b), a firm should only use information provided from a third party appointed under CASS 17.6 in order to confirm that information.
  4. (4) The requirements at CASS 17.5.6R(3) and at CASS 17.5.7R(3) should not prevent a firm from investigating and resolving any discrepancy under CASS 17.5.10R(3) or CASS 17.5.11R(1).
  5. (5) When a firm is ascertaining the quantity for the per-trust/class cryptoasset resource under CASS 17.5.7R, it should not make any adjustment or allowance for cryptoassets in the relevant trust environment that may be part of an operational surplus which the firm has decided to include under CASS 17.3.20R.
25/10/2027R
  1. (1) Each time a firm calculates a per-trust/client/class cryptoasset requirement or confirms a per-trust/class cryptoasset resource, it must make a record of:
    1. (a) the date and time it carried out that calculation or confirmation, as appropriate;
    2. (b) the actions it took in order to carry out that calculation or confirmation, as appropriate; and
    3. (c) the calculation result or confirmation outcome, as appropriate.
  2. (2) A firm must retain each record made under (1) for a period of 5 years.

Client cryptoasset reconciliations

25/10/2027R
  1. (1) For each trust that a firm has created under CASS 17.3.3R, a firm must perform a client cryptoasset reconciliation under this rule at least once each business day, to check whether it has breached the rules in CASS 17.3 to hold client cryptoassets on trust.
  2. (2) For each cryptoasset safeguarding class in respect of which the firm is required to be safeguarding cryptoassets within the relevant trust, the firm must compare the total of the per-trust/client/class cryptoasset requirements for all clients who have an interest in that trust with the per-trust/class cryptoasset resource for that trust at the same point in time.
  3. (3) If the firm identifies a discrepancy as a result of carrying out a client cryptoasset reconciliation, it must promptly investigate the reason for the discrepancy and resolve it without delay or, where there is a shortfall, in accordance with CASS 17.5.13R.
  4. (4) Each time a firm performs a client cryptoasset reconciliation, it must make a record (a ‘client cryptoasset reconciliation record’) of:
    1. (a) the date and time of the client cryptoasset reconciliation;
    2. (b) whether or not the client cryptoasset reconciliation identified any discrepancies and, if so:
      1. (i) the extent of them; and
      2. (ii) the reasons for them; and
    3. (c) any actions taken or attempted by the firm in relation to those discrepancies, including under CASS 17.5.12R and CASS 17.5.13R.
  5. (5) A firm must retain each client cryptoasset reconciliation record made under (4) for a period of 5 years.

Other discrepancies

25/10/2027R
  1. (1) If a firm identifies a discrepancy related to its safeguarding of client cryptoassets outside of its processes for a client cryptoasset reconciliation, it must promptly investigate the reason for the discrepancy and resolve it without delay or, where there is a shortfall, in accordance with CASS 17.5.13R.
  2. (2) Each time a firm identifies a discrepancy under (1), it must make a record (a ‘client cryptoasset discrepancy record’) of:
    1. (a) the date and time the discrepancy was identified;
    2. (b) the reasons for the discrepancy and the extent of it; and
    3. (c) any actions taken or attempted by the firm in relation to the discrepancy, including under CASS 17.5.12R and CASS 17.5.13R.
  3. (3) A firm must retain each client cryptoasset discrepancy record made under (2) for a period of 5 years.

Client cryptoasset reconciliation excesses

25/10/2027R
  1. (1) This rule applies where a firm’s client cryptoasset reconciliation for a particular trust shows that the firm, having investigated any discrepancies under CASS 17.5.10R(3) or CASS 17.5.11R(1), has confirmed there to be a greater amount of cryptoassets within that trust for a particular cryptoasset safeguarding class than the total of the per-trust/client/class cryptoasset requirements for all clients who have an interest in that trust for that cryptoasset safeguarding class.
  2. (2) Subject to (3), the firm must, before its next client cryptoasset reconciliation for that trust, remove all the excess cryptoassets of that particular cryptoasset safeguarding class from that trust.
  3. (3) The firm may only retain excess cryptoassets of that particular cryptoasset safeguarding class within that trust if:
    1. (a) it had previously decided to use an operational surplus in that trust and in that cryptoasset safeguarding class of cryptoasset in accordance with CASS 17.3.20R;
    2. (b) the firm’s retention of the excess does not cause the firm to be in breach of CASS 17.3.20R(2) or (3); and
    3. (c) the amount of any excess that is withdrawn under this rule, and the amount of any excess that is retained under this rule, are recorded in the relevant client cryptoasset reconciliation record under CASS 17.5.10R(4)(c) or the relevant client cryptoasset discrepancy record under CASS 17.5.11R(2)(c), as appropriate.

Client cryptoasset reconciliation shortfalls

25/10/2027R
  1. (1) This rule applies where a firm’s client cryptoasset reconciliation for a particular trust identifies a discrepancy as a result of, or that reveals, a shortfall which the firm has not yet resolved.
  2. (2) A shortfall for the purposes of this rule is a situation for a particular trust under CASS 17.3.3R in which the firm’s per-trust/class cryptoasset resource shows that there is a lesser amount of cryptoassets within that trust for a particular cryptoasset safeguarding class than the total of the per-trust/client/class cryptoasset requirements for all clients who have an interest in that trust in relation to that cryptoasset safeguarding class.
  3. (3) This rule also applies where, outside of its processes for client cryptoasset reconciliations, a firm identifies a discrepancy as a result of, or that reveals, a shortfall which the firm has not yet resolved.
  4. (4) The firm must address the shortfall by ensuring that, no later than 24 hours after identifying the discrepancy, the firm has the correct number of client cryptoassets on trust.
  5. (5) Where necessary to comply with the requirement at (4), the firm must:
    1. (a) appropriate its own cryptoassets in the relevant cryptoasset safeguarding class;
    2. (b) acquire cryptoassets in the relevant cryptoasset safeguarding class using its own resources; or
    3. (c) procure a third party appointed under CASS 17.6 to apply or acquire its own cryptoassets in the relevant cryptoasset safeguarding class to resolve the shortfall.
  6. (6) Each measure taken by a firm to comply with (4) must be recorded in the relevant client cryptoasset reconciliation record under CASS 17.5.10R(4)(c) or the relevant client cryptoasset discrepancy record under CASS 17.5.11R(2)(c), as appropriate.
  7. (7) A shortfall will not be considered to be addressed under (4) if cryptoassets of another cryptoasset safeguarding class, or some other type of asset (e.g. money), are placed in the trust.
25/10/2027G
  1. (1) CASS 17.5.13R does not prevent a firm from setting aside an alternative asset for the relevant client(s), or paying/transferring an alternative asset to them, in an amount which would match any claim that they might have against the firm for the shortfall – for example, where doing so is required under the firm’s agreement with the client(s), is required by the FCA, or is considered by the firm to be required for another reason.
  2. (2) Where a firm takes the action described in (1) involving an alternative asset, this does not have the automatic consequence that the firm will have addressed the shortfall as required under CASS 17.5.13R(4).
  3. (3) However, it may put the firm and client in a position to agree that the firm need no longer carry on the activity of safeguarding cryptoassets in relation to the cryptoassets in shortfall, which may then be reflected in the per-trust/client/class cryptoasset requirement (see CASS 17.5.6R(2)(b)(vi)).
  4. (4) In making any such agreement with a client in the course of retail market business, whether in advance or at the time of the shortfall, a firm should act compatibly with its obligations under the Consumer Duty.
25/10/2027R

Where a firm fails to address a shortfall as required by CASS 17.5.13R, it must immediately:

  1. (1) notify each affected client in writing (including those who are affected because they have an interest in the relevant trust which has, under the terms of that trust, reduced); and
  2. (2) notify the FCA in writing, setting out:
    1. (a) the reasons for the shortfall and the reasons for the firm failing to address it;
    2. (b) the name of each cryptoasset safeguarding class of cryptoasset for which there is a shortfall, identified using the name of the cryptoasset or an identification code, in either case from which the relevant cryptoasset safeguarding class can be precisely distinguished, and the amount of that shortfall in that cryptoasset safeguarding class;
    3. (c) the number of clients in the relevant trust affected by the shortfall and by how much each affected client is affected;
    4. (d) the firm’s expected timeframe for resolution of the shortfall, including detail on the steps which the firm and any third parties intend to follow to achieve resolution; and
    5. (e) the approach the firm is taking in relation to client notifications under (1).

Other notification requirements

25/10/2027R

A firm must notify the FCA in writing without delay if either of the following apply:

  1. (1) its internal records relating to safeguarding cryptoassets are materially out of date, or materially inaccurate or invalid; or
  2. (2) it will be unable, or materially fails, to comply with CASS 17.5.6R, CASS 17.5.7R or CASS 17.5.10R.
Point In Time
25/10/2027