- (1) Where a firm carries on the activity of safeguarding cryptoassets, it may be necessary for the firm to appoint a third party to carry on the activity of safeguarding cryptoassets under the firm’s direction in relation to a particular client cryptoasset or client cryptoassets of one or more cryptoasset safeguarding classses.
- (2) That third party appointed by the firm may itself be a firm or may, for example, be a person who is overseas and who is not required to be authorised to carry on the activity of safeguarding cryptoassets in these circumstances.
- (3) This section sets out the rules that apply to such an appointment by a firm of a third party to carry on that activity in order to address the risk of harm to the firm’s clients that might result from that appointment, particularly in cases where the third party is not itself authorised.
- (4) In the FCA’s view, where a firm appoints a third party to carry on the activity of safeguarding cryptoassets in relation to any client cryptoasset, the firm will be carrying on the activities of both safeguarding cryptoassets and arranging cryptoasset safeguarding. In that situation, the firm, while remaining a trustee who is safeguarding cryptoassets, arranges for another person to safeguard cryptoassets under the firm’s direction.
- (5) The scenario described in (4) is different to one in which a firm only carries on arranging cryptoasset safeguarding and does not itself carry on safeguarding cryptoassets. In that situation, in making the arrangements which will result in the client receiving the service of safeguarding cryptoassets from another person, the firm is not itself a trustee of the cryptoassets.
- (6) This section would not apply to the scenario described in (5) in which a firm only carries on arranging cryptoasset safeguarding. The rules in CASS 17.7 apply to a firm that only carries on arranging cryptoasset safeguarding.
- (7) This section would not apply where the firm appoints a third party to hold part of a means of access where the third party would not be safeguarding cryptoassets because it lacks the requisite degree of ‘control’. An example of this is where the firm appoints a third party to hold a shard of a private cryptographic key, but possession or knowledge of that shard, by itself, would not put the third party in a position to be able to transfer the benefit of the relevant client cryptoasset.
CASS 17.6 Appointing third parties to safeguard cryptoassets
You are viewing CASS 17.6 Appointing third parties to safeguard cryptoassets as it appeared on 25/10/2027. The current version of CASS 17.6 Appointing third parties to safeguard cryptoassets was last updated on 25/10/2027.
CASS 17.6 Appointing third parties to safeguard cryptoassets
25/10/2027R
This section applies to a firm when it safeguards cryptoassets which are client cryptoassets and, in the course of carrying on that activity, it arranges cryptoasset safeguarding.
Purpose of this section
25/10/2027G
The conditions for appointing third parties to safeguard cryptoassets
25/10/2027R
- (1) A firm may appoint and retain another person (a ‘third party’) to carry on the activity of safeguarding cryptoassets in respect of which the firm has undertaken to its client to carry on safeguarding cryptoassets, but only if the following conditions are met:
- (a) the third party operates in a jurisdiction which specifically regulates the safeguarding of cryptoassets through mandatory requirements concerning financial and operational resilience, security of the means of access to cryptoassets, and record-keeping, and the activities of the third party pursuant to the appointment by the firm are supervised in that jurisdiction;
- (b) the firm has concluded, having completed the due diligence and any periodic review required under CASS 17.6.5R, that the appointment of the third party would not increase the risk of loss or diminution of any client cryptoassets which are subject to the arrangement, having regard to the firm’s compliance with CASS 17.2.2R;
- (c) in relation to a firm’s retail market business, the appointment of the third party is compatible with the Consumer Duty;
- (d) prior to the appointment commencing, the firm has entered into an agreement with the third party in the form required at CASS 17.6.6R; and
- (e) the firm has met the governance requirements at CASS 17.6.9R.
- (2) A contravention of (1)(c) does not give rise to a right of action by a private person under section 138D of the Act (and CASS 17.6.3R(1)(c) is specified under section 138D(3) of the Act as a provision giving rise to no such right of action).
- (3) A contravention of any other aspect of this rule is not affected by (2).
25/10/2027G
- (1) Where a client has instructed a firm to appoint a particular third party, the firm should still ensure that the conditions for the appointment at CASS 17.6.3R are met.
- (2) To meet the condition at CASS 17.6.3R(1)(a) it is not essential that the mandatory requirements of the other jurisdiction refer to the specific terms mentioned in that requirement (e.g. ‘financial and operational resilience’, ‘security of the means of access to cryptoassets’, and ‘record-keeping’) provided that they focus on all of those aspects in substance.
Mandatory due diligence
25/10/2027R
- (1) A firm must exercise all due skill, care and diligence in the selection, appointment and periodic review of the third party and of the arrangements for the safeguarding of the relevant client cryptoassets, in order to conclude that the appointment of the third party would not increase the risk of loss or diminution of any client cryptoassets which are subject to the arrangement.
- (2) When a firm makes the selection and appointment and conducts the periodic review referred to under this rule, it must take into account:
- (a) whether the third party has the appropriate regulatory permissions to carry out the appointment;
- (b) the arrangements that the third party has in place for safeguarding cryptoassets;
- (c) the capacity and capability of the third party to provide the contracted services;
- (d) the capital or financial resources of the third party;
- (e) the creditworthiness of the third party;
- (f) the potential impact on the contracted services of any other activities undertaken by the third party and, if relevant, any affiliated company;
- (g) the expertise and market reputation of the third party;
- (h) any legal requirements relating to the carrying on of safeguarding cryptoassets in respect of the relevant cryptoassets that could adversely affect the firm’s clients’ rights;
- (i) market practices relating to the carrying on of safeguarding cryptoassets in respect of the cryptoassets that could adversely affect the firm’s clients’ rights;
- (j) any relevant industry standard reports, including in relation to security; and
- (k) where the third party appointed by the firm has appointed a further third party with the firm’s consent under CASS 17.6.9R, all the factors set out above in relation to that further third party.
- (3) The firm must conduct the periodic review required under this rule at least once each year.
The agreement condition
25/10/2027R
A firm must have entered into a written agreement with any third party that it appoints to carry on the activity of safeguarding cryptoassets under CASS 17.6.3R. This agreement must, at minimum:
- (1) set out the binding terms of the arrangement between the firm and the third party;
- (2) be in force for the duration of the appointment;
- (3) clearly set out the service(s) that the third party is contracted to provide;
- (4) require the third party to seek and obtain the firm’s written consent prior to the third party being able to appoint a further, different third party to carry on the activity of safeguarding cryptoassets;
- (5) in recognition that the firm is acting as a trustee in relation to the client cryptoassets that are subject to the appointment:
- (a) require that any client cryptoassets that are subject to the appointment are not co-mingled with, and are identifiable separately from, any assets belonging to the third party;
- (b) require that any client cryptoassets that are subject to the appointment are not co-mingled with, and are identifiable separately from, any assets belonging to the firm for which it is not acting as a trustee;
- (c) require that any client cryptoassets that are subject to the appointment are not co-mingled with, and are identifiable separately from, any assets pertaining to any other appointment;
- (d) require the third party to recognise that the firm acts for its clients as trustee over the client cryptoassets; and
- (e) exclude any rights of the third party to exercise set-off or counterclaim against the client cryptoassets in respect of any debt owed to it or to any other person;
- (6) require the third party to notify the firm whenever cryptoassets are no longer subject to the terms of the agreement for any reason;
- (7) include provisions detailing the extent of the third party’s liability in the event of the loss of a client cryptoassets caused by the fraud, wilful default or negligence of the third party or an agent appointed by the third party; and
- (8) set out the procedures and authorities for the passing of instructions to, or by, the firm.
25/10/2027R
A firm must take the necessary steps to ensure that both it and the third party adhere to the agreement referred to at CASS 17.6.6R at all times.
Consenting to safeguarding chains
25/10/2027R
- (1) This rule applies where, under the mandatory term described at CASS 17.6.6R(4), a third party appointed by the firm seeks the firm’s consent to itself appoint a further, different third party to carry on the activity of safeguarding cryptoassets in relation to client cryptoassets which the firm has undertaken to its client to safeguard.
- (2) The firm must withhold the consent referred to in (1) unless it is satisfied that:
- (a) the further appointee operates in a jurisdiction which specifically regulates the safeguarding of cryptoassets through mandatory requirements concerning financial and operational resilience, security of the means of access to cryptoassets, and record-keeping, and the activities of the further appointee are supervised in that jurisdiction;
- (b) the firm has concluded, having completed due diligence on the further appointee in line with the requirements under CASS 17.6.5R, that the further appointment would not increase the risk of loss or diminution of any client cryptoassets which are subject to the arrangement, having regard to the firm’s compliance with CASS 17.2.2R;
- (c) in relation to a firm’s retail market business, the further appointment is compatible with the Consumer Duty; and
- (d) the agreement under which the further appointment will be governed (as between the third party appointed directly by the firm and the further third party) contains terms which provide equivalent safeguards to those set out at CASS 17.6.6R(1) to (8).
- (3) (a) The firm may approach its assessment under (2)(b) by requiring the third party it has appointed under CASS 17.6.3R to apply the factors set out at CASS 17.6.5R(2) in relation to the further appointee and to report its conclusions to the firm.
- (4) Any consent given by the firm under this rule must be periodically reviewed, at least once each year.
- (5) A contravention of (2)(c) does not give rise to a right of action by a private person under section 138D of the Act (and CASS 17.6.8R(2)(c) is specified under section 138D(3) of the Act as a provision giving rise to no such right of action).
- (6) A contravention of any other aspect of this rule is not affected by (5).
The governance condition
25/10/2027R
- (1) Each proposed appointment by the firm of a third party under CASS 17.6.3R and each proposed consent under CASS 17.6.8R, together with the firm’s considerations and conclusions to support that proposal, must be approved by the firm’s governing body before the appointment is made or the consent is given, or by a person or persons within the firm to whom the firm’s governing body has delegated that role (the ‘governing body’s delegate’).
- (2) Where the governing body has delegated one or more persons for the purposes of the approval under (1), that delegation must include the SMF manager to whom the firm has appointed the FCA-prescribed senior management responsibility (Reference letter (z)) in the table in SYSC 24.2.6R (functions in relation to CASS).
- (3) The outcome of each periodic review of a firm’s selection and appointment of a third party that it conducts under CASS 17.6.5R, together with the firm’s considerations and conclusions, must be approved by the firm’s governing body or the governing body’s delegate within 3 months of the review being concluded.
Policy on appointing third parties
25/10/2027R
- (1) A firm must produce and maintain a written policy that sets out its methodology for any selections, appointments, periodic reviews and consents that are required under CASS 17.6.3R, CASS 17.6.5R and CASS 17.6.8R.
- (2) A firm must retain the written policy under (1) until 5 years after it has been superseded by any new version of the written policy, or otherwise indefinitely.
Records
25/10/2027R
- (1) A firm must make a record of how the requirements of CASS 17.6.3R(1) or CASS 17.6.8R(2) are met in relation to any appointment of a third party under CASS 17.6.3R or consent to a further appointment of a third party under CASS 17.6.8R. That record must include the conclusions of any due diligence exercise carried out in accordance with those rules, making explicit reference to the factors set out at CASS 17.6.5R(2)(a) to CASS 17.6.5R(2)(j) (a ‘client cryptoasset third party due diligence record’).
- (2) A firm must make the record under (1) prior to the relevant appointment commencing or the relevant consent being given.
- (3) Whenever a firm undertakes a periodic review of its selection and appointment of a third party under CASS 17.6.5R or of the firm’s consent to an appointment under CASS 17.6.8R(4), the firm must make a record of the conclusions of its review, making explicit reference to the factors set out at CASS 17.6.5R(2)(a) to CASS 17.6.5R(2)(j) (a ‘client cryptoasset third party review record’).
- (4) A firm must make the record under (3) on the date it completes the review.
- (5) A firm must make a record of each approval given by its governing body or its governing body’s delegate under CASS 17.6.9R(1) or (3) (a ‘client cryptoasset third party governance record’).
- (6) A firm must make the record under (5) on the date of the governing body’s or its governing body’s delegate’s approval.
- (7) A firm must retain the records under (1), (3) and (5) until 5 years after the relevant appointment ceases.
Point In Time
25/10/2027
