2025-06-12
The Canadian securities regulatory authorities amended Policy Statement to Regulation 81-102 to clarify the definition of crypto assets and update French terminology from 'garantie' to 'sûreté'. The amendments permit mutual funds to invest in crypto assets listed on recognized exchanges or derivatives while establishing specific custody requirements for private key storage, cybersecurity, and insurance. Additionally, the regulators specified that SOC-2 Type II reports satisfy the internal control assessment requirements for custodians holding crypto assets.
CHANGES TO POLICY STATEMENT TO REGULATION 81-102 RESPECTING INVESTMENT FUNDS
2 (1) by inserting, at the beginning of first paragraph, “(1)”; (2) by adding, after the first paragraph, the following paragraphs: “(2) The Canadian securities regulatory authorities expect that custodians and sub-custodians responsible for the custody of portfolio assets that are crypto assets implement policies and procedures that address the unique risks concerning safeguarding of crypto assets compared to other asset types. We also expect that investment fund managers take note of these policies and procedures in conducting their due diligence on custodians or sub-custodians to hold crypto assets for an investment fund, consistent with their fiduciary obligations. Examples of what we understand to be industry best practices may include, but are not limited to: (a) having specialist expertise and infrastructure relating to the custody of crypto assets; (b) storing private cryptographic keys to the investment fund’s crypto assets in segregated wallets separate from wallets the custodian or sub-custodian uses for its other customers so that unique public and private keys are maintained on behalf of an investment fund and visible on the blockchain; (c) maintaining books and records in a way that enables the investment fund, at any time, to confirm its transactions and ownership of the crypto assets it holds. Custody and record-keeping controls (e.g., reconciliation to the blockchain) that ensure investors’ crypto assets exist, are appropriately segregated and protected, and that ensure transactions with respect to those assets are verifiable, should be maintained; (d) using hardware devices to hold private cryptographic keys that are subject to robust physical security practices, with effective systems and processes for private key backup and recovery; (e) using effective cybersecurity solutions that minimise single point of failure risk, such as the use of multi-signature wallets; (f) maintaining robust systems and practices for the receipt, validation, review, reporting and execution of instructions from the investment fund; (g) maintaining website security measures that include two-factor authentication, strong password requirements that are cryptographically hashed, encryption of user information and other state-of-the-art measures to secure client information and protect the custodian and sub-custodian’s website from hacking attempts; (h) maintaining robust cyber and physical security practices for their operations, including appropriate internal governance and controls, risk management and business continuity practices; (i) maintaining insurance with respect to the crypto assets in their custody that is reasonable and appropriate. The Canadian securities regulatory authorities expect investment fund managers to use their best judgment, consistent with their fiduciary obligation to the investment fund, to determine whether the insurance maintained by the custodian or subcustodian is satisfactory in the circumstances, which would include a consideration of whether the amount and nature of the insurance is consistent with standard industry practices where applicable. “(3) For the purposes of section 6.5.1, the Canadian securities regulatory authorities generally consider offline storage to mean the storage of private cryptographic keys in a manner that prevents any connection to the internet.”. 6. Section 8.3 of the Policy Statement is changed: (1) by inserting, at the beginning of the first paragraph, “(1)”; (2) by adding, after the first paragraph, the following paragraphs:
3 “(2) Subsection 6.7(1.1) requires a custodian or sub-custodian of an investment fund that holds portfolio assets of that investment fund that are crypto assets to obtain a report prepared by a public accountant to assess its internal management and controls. The Canadian securities regulatory authorities would consider obtaining a System and Organization Controls 2 Type II report, generally referred to as a “SOC-2 Type II” report, prepared in accordance with the framework developed by the American Institute of Certified Public Accountants, to satisfy this requirement. “(3) We are not prescribing a specific 12-month period the report required under subsection 6.7(1.1) must refer to. However, we expect that report will generally refer to the same 12- month period each year, similar to how other types of annual reporting, such as financial reporting is provided.”.