CIRO publishes digital asset custody framework for crypto
CIRO has established a digital asset custody framework in 2026 to enhance operational standards for registered crypto trading platforms in Canada.
Custody is the least glamorous part of crypto and, when it goes wrong, the most expensive. Where a platform actually keeps client coins, how it proves they are there, and what happens if they go missing are questions that sit underneath every other feature a trading app advertises. Canadian regulation has been working through those questions steadily rather than dramatically, and in 2026 it produced another piece: the Canadian Investment Regulatory Organization published a Digital Asset Custody Framework aimed at strengthening operational standards for registered digital asset trading platforms operating in Canada.
Who CIRO regulates
CIRO is Canada’s national self-regulatory organization. It oversees investment dealers and trading activity in Canada’s capital markets, working under the authority of the provincial and territorial securities commissions. Its traditional membership is the brokerage industry, but as crypto platforms in Canada moved into the securities-regulation perimeter, CIRO’s remit followed them. Platforms that have obtained Investment Dealer or Restricted Dealer registration sit inside that perimeter, which means CIRO rules, CIRO examinations and CIRO enforcement apply to them in a way that does not apply to a venue registered only as a money services business.
That population is no longer small. By 2026 a growing list of CIRO-registered platforms serves Canadian retail customers, including names Canadians will recognize from their app stores. The custody framework is written for that group.
What a custody framework is for
Custody rules answer a narrow but critical question: when a customer’s coins sit on a platform, what obligations does the platform carry with respect to those coins? In regulated finance, frameworks of this kind typically address matters such as the segregation of client assets from the firm’s own assets, requirements around cold storage and key management, insurance coverage against loss or theft, and audit and reporting obligations that allow a regulator or an independent examiner to verify that the assets are actually there.
It is worth being precise about what has and has not been established publicly. CIRO’s framework is directed at operational standards for registered platforms; the specific thresholds, percentages and coverage minimums it sets are matters for the framework’s own text and CIRO’s published guidance rather than for inference. Readers who need the operative detail (a compliance officer at a registered firm, or an investor trying to understand a specific platform’s obligations) should work from CIRO’s own publications rather than from secondary summaries, this one included.
Why custody failures are the industry’s defining risk
The reason regulators keep returning to custody, rather than treating it as one item among many, is that it is where crypto’s worst failures have historically originated. When a major exchange has collapsed, the proximate cause has rarely been a bad trade or a market downturn on its own; it has been a gap between what the platform told customers it held and what it actually held, often because customer assets were commingled with the firm’s own funds, rehypothecated to fund other activities, or simply never segregated in the first place. A custody framework is regulation’s answer to that specific failure mode. Segregation rules exist so that a platform cannot quietly use client coins for its own purposes. Cold-storage requirements exist because coins held in an internet-connected “hot” wallet are exposed to a different, larger category of theft risk than coins held offline. Insurance and audit requirements exist so that a claim of solvency can be checked against something other than the platform’s own word.
None of this is unique to crypto. Custody obligations of a similar shape have existed for decades in traditional securities dealing, where a brokerage holding a client’s stocks or bonds is bound by rules that keep those assets legally distinct from the firm’s own balance sheet. What CIRO’s framework represents is that same logic being written specifically for the operational realities of digital assets, where “segregation” has to account for practices, like commingled omnibus wallets and multi-signature key arrangements, that do not have a direct analogue in traditional custody.
Why the distinction between platforms matters
For a Canadian choosing where to hold crypto, the practical upshot is that not all platforms carry the same duties. A CIRO-registered dealer operates under a rulebook that covers capital adequacy, books and records, know-your-client standards and now an articulated custody framework. A platform without that registration does not, regardless of what its marketing says about security. The gap is not a matter of degree in the way that two brands of safe might differ; it is a difference in whether an external body has the standing to inspect, demand records and impose consequences.
It is also worth distinguishing custody regulation from the custodial-versus-non-custodial choice an individual user makes. A CIRO custody framework governs how a registered platform must handle assets it holds on a customer’s behalf; it says nothing about the separate question of whether holding crypto on any platform, however well-regulated, versus in a wallet the user controls directly, is the right choice for a given amount of money. A strong custody framework reduces the risk of a specific kind of failure at registered platforms. It does not eliminate the more basic distinction between a balance a company promises to honour and a balance the user’s own keys control outright.
How this compares with the pre-CIRO era
It is worth remembering how recently registered crypto platforms in Canada operated with none of this structure. Before the Canadian Securities Administrators began drawing crypto trading platforms into the securities-registration perimeter, a platform serving Canadian customers might have held only a FINTRAC registration as a money services business, a designation focused on anti-money-laundering and know-your-client obligations rather than on custody, capital adequacy or client-asset segregation in the way a securities-dealer rulebook addresses those areas. That earlier regime said very little about what happened to client coins if the platform itself ran into trouble, since it was never designed to answer that question in the first place. The move to Investment Dealer and Restricted Dealer registration, and now to an explicit custody framework layered on top of it, represents Canadian regulators closing that gap incrementally, category by category, rather than through a single comprehensive crypto law passed all at once.
The direction of travel
The custody framework fits a pattern that has been visible in Canadian crypto regulation for several years: rather than writing a bespoke crypto statute, regulators have been extending existing securities and dealer machinery to cover crypto activity, and then filling in the operational specifics as the sector’s particular risks become clear. Custody is one of those specifics. It is likely not the last.
For Canadians, the useful habit is to check a platform’s actual registration status before depositing, and to treat “regulated” as a claim to be verified rather than a description to be accepted. CIRO maintains public records of the dealers it oversees, and its newsroom is where framework publications and related guidance appear.