KYC Challenges became a sharper operational issue after the SEC published its crypto custody rule proposal on October 1, 2026. The proposal addressed custody of crypto securities and similar investments by regulated funds and registered investment advisers, including conditions for self-custody, custodian oversight, identity theft controls, and recordkeeping around client assets. The rule was not final as of October 7, 2026, so firms should treat the text as a proposal, not settled law.
The core compliance issue is not just collecting a client name at onboarding. Crypto custody can involve private keys, omnibus wallets, smart-contract controls, staking, bridging, governance rights, and reconciliation records that do not map neatly to traditional account structures. That makes identity verification a technical control problem as much as a paperwork problem.
KYC Challenges In The Proposal
What Changed On October 1, 2026
The SEC proposal sought to modernize custody rules for advisers and regulated funds that hold crypto securities and similar investments, according to the agency’s rule page for File No. S7-2026-35. Its identity-related impact comes from several connected duties: determining whether a permitted custodian is available, applying stricter guardrails if self-custody is used, documenting controls, and maintaining records that connect assets to the right client or fund.
These KYC Challenges are sharper for crypto assets because possession and control may be expressed through private keys, wallet policies, or smart-contract arrangements rather than a conventional securities account. A regulated adviser may know the legal client, but still need a defensible process for proving which wallet activity belongs to that client, which personnel or systems can authorize transfers, and how errors or losses would be traced.
KYC Challenges For Wallet Identity
Wallet identity is not the same as human identity. A blockchain address can show transaction history, but it does not, by itself, prove who controls the private key, who approved a transaction, or whether multiple clients’ assets are pooled behind one operational wallet. The proposal’s custody focus pushes advisers toward stronger internal mapping between client records, wallet records, authorization workflows, and reconciliation evidence.
That mapping becomes harder where crypto assets involve staking, bridging, on-chain governance, or nonstandard smart-contract custody. The research record for the proposal described token-specific technical challenges that may require specialized attestation expertise for verification and reconciliation. That is a cost issue, but it is also a security issue: weak identity mapping can hide unauthorized transfers, client-allocation errors, or gaps in access controls.
Self-Custody Identity Controls
Red Flags Programs
The proposal allowed adviser self-custody only under conditions, including a determination before self-custody and quarterly afterward that no permitted custodian is available for the relevant asset. For advisers using self-custody, the identity layer is not optional. The Federal Register version stated that advisers holding crypto assets in self-custody would be required to comply with Regulation S-ID and establish a red flags identity theft detection program if they are financial institutions or creditors with covered accounts, as described in the Federal Register proposal.
For advisers, KYC Challenges under this structure include verifying the individuals and systems that can initiate transactions, reviewing changes to key custody procedures, and detecting account-takeover patterns before they become asset losses. The proposal also referenced at least annual written assessments of cybersecurity risks for self-custody operations and safeguarding systems, with attention to the technical attributes of the crypto assets involved.
Control Reports And Loss Reporting
Self-custody also introduced audit-style evidence needs. Advisers that self-custody would need a written internal control report by an independent public accountant within six months of adopting self-custody, and annually afterward. The proposal also required reporting losses of client crypto assets held in self-custody within a specified timeframe.
Those duties affect identity verification because a control report is only useful if the firm can show who had authority, how approvals were logged, how wallet access was limited, and how client ownership records were reconciled. This is where general endpoint hygiene still matters. Compromised workstations, weak authentication, or unmanaged devices can undermine otherwise sound custody records; for related device-security reading, see these antivirus and endpoint security resources.
- Client identity records: legal identity, account ownership, and authorization rights should align with custody records.
- Wallet control records: firms need evidence of who or what can approve movements from operational wallets.
- Reconciliation records: client allocations should be traceable even when assets move through pooled infrastructure.
- Incident records: loss reporting depends on timestamps, approvals, wallet addresses, and internal investigation notes.
Custodian Oversight And Omnibus Records

State Trust Companies
The proposal recognized state-chartered trust companies as qualified custodians for crypto assets, subject to checks. Advisers would need to verify the trust company’s state authority, safeguarding policies, and procedures intended to prevent theft, loss, misuse, and misappropriation. That shifts part of the identity problem from direct wallet control to third-party oversight.
For a registered adviser, relying on a custodian does not remove KYC Challenges. It changes the evidence set. The adviser still needs to understand whether custodian records can identify client ownership, support account statements, document asset movements, and distinguish client assets from operational balances. If the custodian uses technical structures the adviser cannot review or reconcile, the adviser may face gaps in supervision.
Omnibus Wallet Reconciliation
Omnibus wallets are a practical pressure point. Pooled wallet structures can improve operational efficiency, but they complicate beneficial ownership tracing. If multiple clients’ assets are represented in one or more shared wallets, the on-chain record may not show which client owns which asset. The adviser’s off-chain records then become the main evidence of beneficial ownership.
This is where custody and compliance teams need a shared data model. A wallet operations team may track addresses, transaction hashes, and signer policies. A compliance team may track client files, account approvals, and restrictions. If those systems do not agree, the firm may struggle to prove asset allocation after a transfer, smart-contract interaction, or loss event. The related compliance issues overlap with broader SEC crypto asset oversight discussed in crypto asset compliance risks.
KYC Challenges For SEC Crypto Custody
The proposal’s practical message is cautious but clear: identity controls for crypto custody must reach beyond onboarding forms. They need to connect legal ownership, wallet control, transaction approval, custody records, cybersecurity assessments, and third-party custodian oversight.
KYC Challenges under the SEC proposal are likely to be most difficult for advisers using self-custody, pooled wallet structures, or assets with staking, bridging, governance, or unusual smart-contract custody features. Because the rule remained proposed as of October 7, 2026, firms should avoid assuming the final version will be identical. Still, the direction of travel in the proposal is evidence-heavy: if an adviser cannot show who owns the asset, who can move it, how controls were tested, and how losses would be reported, its custody process may be difficult to defend.



