Regulatory explainer · Draft

Bitcoin custody for banks: what the OCC, BaFin, and MAS expect

Banks can custody Bitcoin. They have to do it under their prudential regulators' expectations, and the common thread across jurisdictions is control, segregation, and demonstrable solvency.

First draftTarget: “bitcoin custody for banks” · 30 global/mo · KD low~950 wordsMaps to: For Banks

Banks can custody Bitcoin. What they cannot do is treat it like any other operational system. Holding crypto assets for clients sits squarely inside prudential supervision, and a bank has to meet the same standards of safety and soundness it meets for everything else on its balance sheet.

The frameworks differ by jurisdiction, but the substance converges. Regulators want to see three things: that the bank controls the assets, that client assets are segregated and protected, and that the bank can demonstrate it actually holds what it claims.

This post walks through the regulatory posture in the US, Germany, and Singapore, what a bank has to satisfy operationally, and how Bitcoin-native infrastructure maps to those expectations.

The regulatory frame, by jurisdiction

Three supervisors set the tone for much of the institutional market. The details evolve, so treat these as the posture rather than a fixed rulebook, and check current guidance before you build.

United States — OCC

The Office of the Comptroller of the Currency supervises national banks. Through a series of interpretive guidance, the OCC has taken the position that national banks may provide crypto-asset custody services, provided they do so under their existing safety-and-soundness obligations. The emphasis is on sound risk management, robust controls, and the same standard of care expected for any custody activity. Custody is permitted; it is not unsupervised.

Germany and the EU — BaFin

In Germany, crypto custody is a licensed activity. BaFin supervises crypto-custody business as a regulated financial service, and a bank or institution providing it operates under authorization and ongoing oversight. Across the EU, the MiCA framework now sets common rules for crypto-asset service providers, including custody, which raises the baseline for licensing and client-asset protection.

Singapore — MAS

The Monetary Authority of Singapore regulates digital-payment-token services, including custody, under its payment-services regime. Providers operate under licensing and conduct expectations, with a clear focus on segregation and protection of customer assets. MAS has been explicit that customer assets must be safeguarded and kept distinct from the provider’s own.

The vocabulary differs across these three, but the requirements rhyme: licensed or authorized activity, strong controls, segregated client assets, and the ability to prove the position.

What a bank must satisfy operationally

Strip away the jurisdiction-specific language and the operating requirements look like this.

  • Segregation.Client assets must be distinct from the bank’s own and, ideally, from each other. Commingling into one pool undermines both legal protection and provability.
  • Key management. Signing keys held under strong controls, typically hardware or HSM-based, with no single point of failure or unilateral movement.
  • Audit and reporting. The bank must be able to evidence holdings and activity to internal audit, external auditors, and its regulator on demand.
  • Qualified-custody treatment. Where a mandate or rule requires assets to sit with a qualified custodian, the arrangement must meet that bar.
Across every jurisdiction, the question a supervisor asks is the same: can you prove you control these assets, and can you prove they are still there?

How Bitcoin-native infrastructure meets it

These expectations map cleanly onto open Bitcoin infrastructure. On the Liquid Network, an open-source Bitcoin sidechain run by a federation of more than 80 members, custody can be built so the controls regulators ask for are properties of the system rather than manual processes.

  • HSM policy engine. Signing is enforced by 2-of-2 HSM cosigning with per-asset rules, so movements require the right keys and cannot happen unilaterally.
  • On-chain proof of reserves.Holdings can be confirmed directly on the ledger rather than asserted in a report, which satisfies the “prove they are still there” question.
  • Per-client segregation.Assets sit in segregated per-client UTXOs, not an omnibus pool, so each client’s position is distinct and individually verifiable.
  • Regulator view-key. Confidential Transactions keep amounts private by default, while a selective blinding-key disclosure lets a regulator or auditor verify positions without public exposure.
  • Open, inspectable foundations.The underlying infrastructure is open-source, so the bank’s own engineers and examiners can review the security model rather than trust a black box.

Blockstream Enterprise is the HSM-based custody platform built on this foundation, supporting full-custody, hybrid, and self-custody arrangements depending on where the bank needs the trust boundary.

Build vs. buy

A bank can build custody infrastructure in-house or adopt a platform. Building gives maximum control and deep integration, at the cost of carrying key management, HSM operations, and ongoing security entirely yourself. Buying or partnering shortens the path to a supervised, examinable setup and lets you start from infrastructure that already embodies segregation, proof of reserves, and HSM policy. For most banks the practical answer is hybrid: adopt proven, open infrastructure and integrate it into existing controls rather than reinvent custody from scratch.

The bottom line

Bitcoin custody is open to banks, under supervision. Whichever regulator you answer to, build for control, segregation, and demonstrable solvency, and prefer infrastructure where those properties can be proven rather than promised.

Where this points

See the digital-asset infrastructure banks build custody on. For Banks →