Skip to main content

Month: October 2026

SEC Proposed Custody Rule Amendments: Modernizing Custody for an Evolving Financial Landscape

Business professionals point at chart on board.

Safeguarding client assets is a fundamental investor protection within the regulatory framework governing investment advisers. At the same time, regulations must provide both meaningful investor protection and operational practicality. As technology, asset classes, and the infrastructure supporting financial markets continue to evolve, the regulatory framework must evolve with them.

That theme is at the center of the Securities and Exchange Commission’s October 1, 2026 proposal to amend the custody rules applicable to registered investment advisers and regulated funds.

In his statement regarding the proposal, SEC Commissioner Mark T. Uyeda highlighted the need to revisit the custody framework as new asset classes emerge and technology continues to develop. While the core principles of custody—including asset separation and appropriate controls—remain important, the way those principles are applied may look different as technology changes.

Safeguarding a paper certificate held in a bank vault and safeguarding an asset recorded on a distributed ledger may require very different processes and controls, even though the underlying objective is the same: protecting client assets.

Modernizing Compliance Alongside Technology

The proposal provides an important reminder that modernization is not simply about adopting new technology. It is also about ensuring that compliance frameworks remain relevant as financial services change.

Investment advisers are increasingly evaluating artificial intelligence tools, automated workflows, cloud-based platforms, and other third-party technology solutions to make day-to-day operations more efficient. These technologies create opportunities, but they also bring additional compliance considerations.

As more information moves through technology platforms and third-party providers, firms must consider how confidential and sensitive information is collected, accessed, transmitted, stored, and protected. Privacy, cybersecurity, data governance, vendor oversight, and access controls therefore remain important components of a modern compliance program.

While the proposed custody amendments do not specifically address artificial intelligence, the broader modernization principles reflected in the proposal are relevant as firms evaluate how emerging technologies fit within their existing compliance and risk-management frameworks.

Crypto Assets and Self-Custody

The proposal also addresses one of the areas where traditional custody concepts have faced some of their biggest challenges: crypto assets.

The SEC proposes a framework for the custody of certain crypto assets, including permitting certain state-chartered trust companies to serve as custodians, subject to specified conditions.

The proposal also recognizes that, for certain “novel crypto assets”, a qualified custodian may not be available or willing to hold the assets. In those circumstances, the proposal would permit self-custody in certain situations, subject to safeguards involving areas such as safeguarding expertise, cybersecurity, annual reviews, internal reporting, account statements, and client disclosures.

Self-custody creates an additional compliance consideration because an adviser holding client crypto assets may face a different conflict-of-interest analysis than it would when assets are held by an independent custodian. Importantly, an adviser’s fiduciary obligations continue to apply when it holds client crypto assets.

For firms considering digital assets, this could require careful consideration of policies and procedures, cybersecurity controls, supervision, disclosures, documentation, and conflicts of interest.

Other Areas of Modernization

Beyond crypto custody, the proposal also raises questions about how other aspects of the custody framework may evolve, including the role of broker-dealers as custodians, certain authorized discretionary trading arrangements, and independent verification requirements.

While these provisions are more technical, they reflect the same broader issue: the way advisers operate today is not necessarily the way they operated when the existing custody framework was developed.

The goal should not be to move away from strong controls or investor protections. Rather, those protections need to remain effective as technology, business practices, and the financial markets change.

For compliance professionals, this raises an important question: how do we preserve the protections that have always mattered while ensuring that the regulatory framework remains practical and relevant to the way the industry operates today?

What This Could Mean for Compliance Programs

As firms adopt AI tools, work with additional third-party providers, and consider digital assets and other emerging technologies, compliance programs may need to evolve alongside those developments.

That may mean revisiting areas such as:

  • Third-party due diligence and oversight;
  • Data privacy and information security;
  • Cybersecurity and incident response;
  • Policies governing AI and other emerging technologies;
  • Custody and asset-safeguarding procedures;
  • Conflict-of-interest assessments;
  • Supervisory procedures; and
  • Client disclosures and recordkeeping.

The objective is not simply to accommodate new technology or asset classes. It is to ensure that the appropriate controls and protections continue to work as the underlying technology and business processes change.

Looking Ahead

The SEC’s proposal is not yet a final rule, and the public comment period will remain open for 60 days following publication of the proposing release in the Federal Register.

As the rulemaking process moves forward, advisers, funds, custodians, and compliance professionals will have an opportunity to evaluate how the proposed changes could affect their existing custody arrangements and compliance programs.

Commissioner Uyeda summarized the proposal’s objective by stating:

“Today’s proposal presents a workable path to compliance without compromising the protections the custody rules are designed to provide.”

That balance between investor protection and operational practicality is one of the most important themes of the proposal.

As the financial services industry continues to incorporate digital assets, artificial intelligence, distributed ledger technology, and an expanding network of technology and service providers, the compliance framework supporting those activities will need to evolve as well.

As technology changes, effective compliance must change with it.

Source

SEC.gov | Statement on Proposed Amendments to the Custody Rules (October 1, 2026).

Note: The proposed Custody Rule Amendment reflects SEC staff views, has no legal force or effect, and does not create new obligations.

Top Five AML Testing Failures – The Penny Stock Edition

Business professionals engaging in meeting.

Findings related to penny stocks—more commonly referred to as low‑priced securities—are not new. Regulators have consistently highlighted the elevated risk these securities present, particularly in the context of market manipulation and money laundering. However, recent enforcement activity suggests that these issues are not only persisting, but may be increasing in frequency and severity, particularly where firms’ AML programs are not adequately aligned with the underlying risk.

For purposes of regulatory analysis, a “penny stock” generally refers to equity securities trading at low prices, typically over‑the‑counter and often lacking robust public disclosure. These securities are also commonly referred to as low‑priced securities, microcap securities, OTC securities, or thinly traded securities. Regardless of terminology, they share common characteristics—limited liquidity, price volatility, and reduced transparency—that make them particularly susceptible to manipulative or illicit activity. Against that backdrop, recent AML testing and enforcement observations reveal several recurring failure points.

1. Surveillance That Doesn’t Capture the Risk

A consistent issue is the presence of surveillance systems that technically exist, but are not designed to capture the firm’s actual risk exposure.

In many cases, firms relied on reports or exception monitoring that:

  • Excluded key account types (e.g., omnibus, DVP/RVP, or certain institutional accounts)
  • Filtered out lower‑value or segmented transactions
  • Failed to aggregate activity across accounts or time periods

The result is a control environment where the highest‑risk activity is effectively outside the scope of monitoring. From a testing perspective, this is not a gap in execution—it is a design failure. Surveillance that cannot identify relevant activity cannot be considered “reasonably designed” under Rule 3310.

2. Lack of Risk Alignment with the Firm’s Business Model

Another recurring theme is the failure to tailor AML programs to the firm’s specific business activities involving low‑priced securities.

This commonly arises where firms:

  • Facilitate trading through correspondent, omnibus, or foreign financial institution accounts
  • Operate in execution‑only environments with limited insight into underlying customers
  • Engage in high‑velocity or high‑volume trading in thinly traded securities

Despite these risk factors, AML programs often remain generic and do not reflect the firm’s actual operational exposure.

From a testing perspective, the key question is not whether a firm has an AML program—it is whether the program reflects the actual risks presented by the firm’s activities. Where low‑priced securities are a meaningful part of the business, regulators expect enhanced, targeted controls.

3. Red Flags Identified—But Not Operationalized

Many firms appropriately identify red flags associated with low‑priced securities in their written procedures. However, a common failure is the absence of operational guidance around those red flags.

Specifically:

  • Red flags are listed, but not linked to specific surveillance scenarios
  • There is no defined process for how alerts are generated or identified
  • Escalation thresholds and investigative expectations are unclear or undefined

In practice, this creates a disconnect between policy and execution. Staff may recognize that certain activity is risky in theory, but lack the tools or direction to detect and act on that risk.

Effective AML programs require that red flags are not only documented—but translated into actionable surveillance, investigation, and escalation procedures.

4. Failure to Investigate and Escalate Suspicious Activity

Even where potentially suspicious activity is identified, firms frequently fail to conduct reasonable investigations or escalate concerns appropriately.

Testing observations often include:

  • Acceptance of customer explanations without independent verification
  • Lack of documented investigative steps or conclusions
  • Failure to consider whether activity warrants SAR filing

This issue is particularly pronounced in low‑priced securities activity involving:

  • Significant liquidations relative to market volume
  • One‑sided trading patterns (e.g., repeated sell orders with no corresponding buys)
  • Rapid movement of proceeds following transactions

From a regulatory perspective, detecting activity is only the first step. Firms must demonstrate a structured, documented, and defensible investigative process, including clear rationale for escalation or non‑escalation decisions.

4. Failure to Investigate and Escalate Suspicious Activity

Even where potentially suspicious activity is identified, firms frequently fail to conduct reasonable investigations or escalate concerns appropriately.

Testing observations often include:

  • Acceptance of customer explanations without independent verification
  • Lack of documented investigative steps or conclusions
  • Failure to consider whether activity warrants SAR filing

This issue is particularly pronounced in low‑priced securities activity involving:

  • Significant liquidations relative to market volume
  • One‑sided trading patterns (e.g., repeated sell orders with no corresponding buys)
  • Rapid movement of proceeds following transactions

From a regulatory perspective, detecting activity is only the first step. Firms must demonstrate a structured, documented, and defensible investigative process, including clear rationale for escalation or non‑escalation decisions.

The common thread across these findings is not the absence of AML programs—but the absence of operational, risk‑aligned controls that reflect the realities of low‑priced securities trading.

For firms that engage in or facilitate this activity, the regulatory expectation is clear: AML programs must move beyond generic frameworks and demonstrate a practical, working ability to detect, investigate, and escalate suspicious activity in higher‑risk areas of the business.

Firms that proactively address these gaps through targeted AML program testing, surveillance design reviews, and risk‑based control enhancements are better positioned to identify vulnerabilities before regulators do.

Renaissance Regulatory Services works with broker-dealers and other financial institutions to operationalize these expectations—supporting firms through independent AML testing, control framework assessments, and tailored remediation strategies designed to align programs with real-world regulatory scrutiny.