Canada’s top regulatory authority overseeing the investment sector has introduced new custody rules to enhance the security of cryptocurrencies. Announced on Tuesday, the regulation aims to prevent the recurrence of losses stemming from past hacking incidents, fraud, and management failures. The framework, prepared by the Canadian Investment Regulation Organization (CIRO), imposes clear obligations on crypto trading platforms operating within the country. This regulation will be applied through provisional membership conditions until permanent legislation is established.
The Core Elements of the New Custody Framework
The Digital Asset Custody Framework published by CIRO offers a comprehensive regulatory model for safeguarding cryptocurrencies. The regulation sets out detailed standards for member institutions operating on crypto trading platforms regarding how they should manage client assets. These standards encompass a broad range of areas, from technological infrastructure to legal responsibilities.
At the heart of the framework is a risk-based, four-tiered structure. Custody service providers are classified based on criteria such as capital adequacy, insurance coverage, regulatory oversight level, and operational resilience. Top-tier custodians can safeguard up to 100% of customer assets, while the limit is capped at 40% for the lowest category institutions.
Cryptocurrencies held directly by platforms are limited to a maximum of 20% of the total customer assets. Furthermore, comprehensive management policies for key management, cybersecurity, incident response plans, and third-party risks are made mandatory. The core elements of the framework also include insurance enforcement, independent audit reports, security compliance documentation, and regular penetration tests.
Past Crises and Regulatory Pressure
The preparation of new rules appears to be significantly influenced by Canada’s severe losses in the past. Notably, the collapse of the QuadrigaCX crypto exchange in 2019 resulted in thousands of investors losing their savings. CIRO emphasizes that the lessons learned from this incident form the foundation of the regulation.
The organization also mandates the clear definition of responsibilities for damages arising from negligence or preventable errors in custody agreements. This is intended to strengthen the legal rights of investors. Authorities assert that the developed system provides a balanced structure between investor safety and market competition.
There has been a noticeable increase in regulatory pressure on the Canadian crypto sector recently. In October last year, FINTRAC fined Cryptomus approximately $126 million for reporting deficiencies related to money laundering and illegal transactions. Within the same year, international platforms like KuCoin and Binance faced similar sanctions. CIRO holds the authority to conduct investigations over member firms, impose fines, and suspend activities.



