Home FCA Handbook PERG PERG 18 PERG 18.6 Activity: safeguarding qualifying cryptoassets and relevant specified investment cryptoassets
You are viewing PERG 18.6 Activity: safeguarding qualifying cryptoassets and relevant specified investment cryptoassets as of . PERG 18.6 Activity: safeguarding qualifying cryptoassets and relevant specified investment cryptoassets was last updated on 16/09/2026.

PERG 18.6 Activity: safeguarding qualifying cryptoassets and relevant specified investment cryptoassets

16/09/2026

Question 6.1: To what extent does the carrying on of the activity of safeguarding cryptoassets depend on who owns the cryptoasset?

PERG 2.7.10G explains that, for the regulated activity of safeguarding and administering investments, the safeguarded property must belong beneficially to another person.

This requirement does not apply to the regulated activity of safeguarding cryptoassets. Safeguarding cryptoassets may be carried on regardless of whether the cryptoasset is owned by the customer or the firm, provided the activity is carried out on behalf of another person and the firm has the requisite degree of control over the cryptoasset.

As a result, determining whether a person is carrying on the activity of safeguarding cryptoassets involves less emphasis on establishing ownership. This is particularly relevant where anonymous transaction ledgers are not designed to identify ownership of a cryptoasset.

Where a firm acting on behalf of another has sufficient control and the customer has a right against the firm for the return of the cryptoasset (but does not own it themselves), the arrangement can still be within scope of safeguarding cryptoassets. (This is not the case where the right arises from certain types of transactions which do not involve a consumer – see PERG 18.6.4.)

In the FCA’s view, because the definition of qualifying cryptoasset includes the quality of being fungible, and this is also therefore a component of the definition of specified investment cryptoasset, it will be immaterial if the right for the return is for the particular cryptoasset that was given by the customer, or for a fungible substitute. However, the concept of a right for return does not include a debt owed by the firm to the customer where the customer had not placed a cryptoasset in the firm’s control in the first place.

16/09/2026

Question 6.2: How does the concept of ‘control’ relate to the regulated activity of safeguarding cryptoassets?

A firm will only be safeguarding cryptoassets if it has the requisite degree of control, which is the ability (through any means) to bring about the transfer of the benefit of the cryptoasset to another person, including to the firm itself.

This requisite degree of control may arise in various ways and the words ‘through any means’ signify a broad scope. Article 9N(4) of the Regulated Activities Order highlights 2 common examples: holding or storing the means of access to the cryptoasset (often the private cryptographic key), and operating an arrangement in which others are appointed to hold or store the means of access or any part of it. The latter includes arrangements where the firm engages other persons to hold ‘shards’ (or sections) of a private cryptographic key.

The requisite degree of control will not be satisfied if a person merely has the ability to prevent a transfer of the benefit of the cryptoasset to another person (sometimes referred to as ‘negative control’). This may be the case if the firm merely holds a single ‘shard’ of a private cryptographic key, which is below a threshold that would be needed to bring about the transfer of the benefit of the cryptoasset to another person; although if such a firm has the ability to meet the relevant threshold through other additional means – for example, by requiring other parties to carry out acts in relation to ‘shards’ which they control – it will have the requisite degree of control. The relevant threshold in that situation will be a case-specific matter.

As technology evolves, new methods of obtaining such control will likely emerge. It seems unlikely that the facts of whether a service has an ‘online’ element, or is entirely ‘offline’, will, purely of itself, be conclusive to the question of whether there is the requisite degree of control. However, the central question will remain whether the firm is, or could put itself, in a position to initiate a transfer that could prejudice a person with a claim to the cryptoasset. Addressing this potential harm is the core purpose of regulating the activity.

Readers considering the control test in the context of services which involve more than one party may find it helpful to consider the table of examples on page 65 of ‘Crypto Regime: Regulated Cryptoasset Activities’ (PS26/11).

Persons who consider themselves to merely provide technical, infrastructure, connectivity or security services should note that there is no exclusion from safeguarding cryptoassets which has been expressly made for those types of services. Therefore, such persons are likely to need to consider whether, in the course of providing such services, they have the requisite degree of control. The holding out exclusion at article 9R(2) (Article 9N exclusion: other exclusions) of the Regulated Activities Order may be available to them where the conditions for that exclusion are met (see PERG 18.6.9).

16/09/2026

Question 6.3: What about ‘self-custody’ arrangements?

Two of the key components of carrying on the regulated activity of safeguarding cryptoassets are that the firm’s safeguarding is on behalf of another person and that the firm has the requisite degree of control. This means that where a firm supplies a customer with a solution for the customer to keep their own cryptoasset secure by exercising control themselves, and the firm itself has no means to bring about the transfer of the benefit of the cryptoasset to another person, the firm will not be carrying on the activity of safeguarding cryptoassets.

But in cases where the firm promises (eg, under a contract) not to exercise control but does actually have the requisite control (eg, because it can override a customer’s authority through its own systems, including by devising a way to do that), the control element of the activity is likely to be met because of the broad scope signified by the words ‘through any means’.

Therefore, in order for a firm that purports to provide customers with a ‘self-custody’ solution to be confident that it is not carrying on the regulated activity of safeguarding cryptoassets, it would need to be able to demonstrate that it genuinely does not have ‘any means’ to itself bring about the transfer of the benefit of the cryptoasset. This is likely to involve examining how the solution is engineered in technical detail.

16/09/2026

Question 6.4: What about title transfer collateral arrangements and transactions in which the customer is contracted to buy back the asset from the firm?

Where a firm acting on behalf of another has the requisite degree of control over a cryptoasset, and that other person – who is not a ‘consumer’ (meaning an individual who is acting for a purpose other than for any trade, business or profession carried on by that individual) – has a right against the firm for the return of the cryptoasset, the firm will not be safeguarding cryptoassets if the other person’s right arises in either one of the following ways:

  1. (1) from a title transfer collateral arrangement (as defined at article 9N(5)(c) of the Regulated Activities Order); or
  2. (2) from a transaction as described at article 9N(2)(c)(ii) (ie, a transaction under which the other person is contracted to buy the cryptoasset back from the firm).
16/09/2026

Question 6.5: Are the activities of group companies excluded?

The group activity exclusion at article 9O (Article 9N exclusion: group activity) of the Regulated Activities Order excludes any safeguarding conducted for a customer under arrangements operated by another group entity that is authorised to safeguard cryptoassets and has accepted responsibility towards that customer for meeting the safeguarding requirements. For example, a bare nominee company owned by an authorised cryptoasset safeguarding firm could benefit from this exclusion.

16/09/2026

Question 6.6: What if the safeguarding is merely temporary and only to facilitate the settlement of a transaction?

The exclusion for temporary settlement arrangements at article 9Q (Article 9N exclusion: temporary settlement arrangements) of the Regulated Activities Order concerns arrangements whereby a qualifying cryptoasset or a relevant specified investment cryptoasset is held temporarily to facilitate the settlement of a transaction. Any such arrangements are removed from the scope of safeguarding cryptoassets or arranging cryptoasset safeguarding.

It does not, however, exclude such arrangements from any other activities, such as dealing in qualifying cryptoassets as principal or operating a qualifying CATP, which may also be relevant for the settlement of transactions. But, depending on whether the conditions are met, it may be relied on by persons carrying on those other activities who might otherwise be safeguarding cryptoassets or arranging cryptoasset safeguarding.

Although not defined, ‘settlement’ is likely to cover actions required for the parties to fulfil their obligations under a transaction, such as delivering cryptoassets to a designated party or wallet. ‘Facilitate’ is intended to link the safeguarding cryptoassets activity or the arranging cryptoasset safeguarding activity directly to the settlement process.

‘Temporarily’ is also undefined but is likely to mean that the safeguarding lasts only as long as necessary to facilitate settlement. In practice, the FCA considers that this is unlikely to require longer than 24 hours from the point at which the requisite degree of control exists.

The term ‘transaction’ is similarly undefined, though the exclusion is aimed at transactions involving one or more cryptoassets as part of their settlement obligations. This may include, for example, cryptoassets being transferred as collateral security for a loan, as well as cryptoassets being exchanged for other cryptoassets or for money. The way in which the transaction to be settled is brought about is immaterial (for example, it may have been executed on a QCATP or entered into ‘over the counter’ between investors). 

16/09/2026

Question 6.7: What about having a power of attorney or investment management mandate over another person’s cryptoasset?

The exclusion at article 9R(1) of the Regulated Activities Order applies where a person who would otherwise have the requisite degree of control is acting solely as an agent, appointed to give instructions on the principal’s behalf to a person who has undertaken to safeguard the cryptoasset for that principal. This exclusion may, for example, apply to an investment manager appointed under a power of attorney (but see PERG 18.8.9 on the scope of managing investments in relation to qualifying cryptoassets and relevant specified investment cryptoassets). The effect of the exclusion is that, although such a person would otherwise have the requisite ‘control’ by having the means to bring about a transfer, that control would be excluded from safeguarding, provided the conditions of the exclusion are met.

16/09/2026

Question 6.8: Is it a necessary element of safeguarding cryptoassets to be ‘holding out’ as providing that service?

No, in the sense that there is no exclusion for safeguarding cryptoassets which is available where there simply is an absence of holding out. But see PERG 18.6.9 regarding the exclusion at article 9R(2) of the Regulated Activities Order.

16/09/2026

Question 6.9: What does the holding out exclusion at article 9R(2) of the Regulated Activities Order achieve?

This exclusion applies where a person does not hold themselves out as engaging in the business of providing a service that is in relation to qualifying cryptoassets or relevant specified investment cryptoassets.

For example, a safety deposit box provider or a generic data storage provider may, in the ordinary course of business, have the requisite degree of control to be safeguarding cryptoassets on behalf of a customer. In those scenarios, the customer may place a device which contains a private cryptographic key into the safety deposit box or may upload data consisting of a private cryptographic key onto the provider’s cloud storage facility. If the safety deposit box provider or data storage provider can access, and is in a position to use, the relevant device or data, they would have the requisite degree of control. However, if they do not hold themselves out as engaging in the business of providing a service in relation to cryptoassets (rather, they held themselves out as engaging in the business of providing generic safe storage for physical items or data), they would be able to rely on this exclusion.

16/09/2026

Question 6.10: Is arranging cryptoasset safeguarding a regulated activity?

Yes. Arranging cryptoasset safeguarding is specified at article 9N(1)(b) of the Regulated Activities Order.

Arranging cryptoasset safeguarding is carried on by a person (the arranger) who arranges for another person to carry on safeguarding cryptoassets. It is possible for a firm to carry on both the activities of safeguarding cryptoassets and arranging cryptoasset safeguarding in relation to the same cryptoasset. For example, this can occur where, in the course of safeguarding cryptoassets on behalf of a customer, a firm appoints a third party to carry on day-to-day safeguarding. If the third party has the requisite degree of control, by making the appointment, the firm will be arranging cryptoasset safeguarding; but if the arrangement is structured so that the firm also retains the requisite degree of control (see article 9N(4)(b) of the Regulated Activities Order), the firm will also be safeguarding cryptoassets. Such a situation can also arise where a firm appoints another person to securely store ‘shards’ of a private cryptographic key which the firm can ‘call back’ on demand, and where the other person has the requisite degree of control by virtue of the number of ‘shards’ that they are storing.

It is also possible for a firm to carry on arranging cryptoasset safeguarding without also carrying on safeguarding cryptoassets. This can occur where the firm merely arranges for a third party to carry on safeguarding cryptoassets for a customer but the firm making that arrangement does not have the requisite degree of control itself. The customer would then have received an arranging cryptoasset safeguarding service from the firm but would rely entirely on the third party for the safeguarding cryptoassets service.

16/09/2026

Question 6.11: What about introducing a person to a firm which is authorised to carry on safeguarding cryptoassets?

Mere introductions are excluded from the regulated activity of arranging cryptoasset safeguarding under article 9P (Article 9N exclusion: introductions) of the Regulated Activities Order, provided the introducer and the authorised safeguarding firm are not in the same group and the introducer is not remunerated by that firm.

16/09/2026

Question 6.12: Can firms acting as depositaries of UK UCITS or AIFs carry on the regulated cryptoasset activities of safeguarding cryptoassets or arranging cryptoasset safeguarding?

No. The exclusion at article 42A (Depositaries of UK UCITS and AIFs) of the Regulated Activities Order covers the carrying on of these regulated activities in the same way as it does for the regulated activity of safeguarding and administering investments.