Annex - Updated Guidance on Expected Standards on Provision of Custodial Services for Digital Assets by Authorized Institutions

Annex Email: HKMA E-mail Alert of 28 May 2026 (05:00 p.m. HKT)

Document Information

Title: Annex - Updated Guidance on Expected Standards on Provision of Custodial Services for Digital Assets by Authorized Institutions

Type: Annex

URL: https://brdr.hkma.gov.hk/eng/doc-ldg/docId/20260527-7-EN

Email Received: 2026-05-28 19:24

Summary Created: 2026-05-28 14:03

English Summary (4413 chars)
Quick section switch
Management Summary
  • Purpose / Background: This guidance sets out the expected standards for Authorized Institutions (AIs) providing custodial services for digital assets (e.g., Virtual Assets, tokenized securities). It ensures AIs manage the unique risks—technological, security, and operational—inherent in holding client assets on distributed ledger technology (DLT).
  • One-line conclusion: AIs must implement robust, risk-based custodial frameworks featuring strict asset segregation, cold storage mandates, secure key management, and rigorous third-party oversight to ensure client protection.
  • Key Changes:
  • Mandated 98% cold storage requirement for Virtual Assets (VAs).
  • Strict prohibition on using client assets for an AI’s own account (lending/pledging) without explicit consent.
  • Requirement to store seeds and private keys in secure environments (e.g., HSMs) within Hong Kong.
  • Implementation of multi-factor authentication and "no single point of failure" key management (e.g., sharding).
  • Formalized due diligence requirements for delegation and outsourcing arrangements.
  • Obligation to maintain 24/7 security monitoring and conduct regular independent audits.
  • Key Dates / Deadlines: Effective immediately for all AIs engaging in custodial activities for client digital assets.
  • Applicability / Impact scope: All locally incorporated AIs and their subsidiaries providing digital asset custody for clients. Excludes custody of an AI's proprietary assets.
  • Recommended management actions:
  • Conduct a gap analysis of existing digital asset custodial infrastructure against the new security requirements.
  • Review and update client service agreements to ensure transparent disclosure of risks and custodial arrangements.
  • Formalize "cold wallet" operational procedures, including key generation, destruction, and multi-signature/shard approval flows.
  • Establish a 24/7 incident response protocol for custodial wallet infrastructure.
  • Conduct due diligence on third-party vendors/delegates to ensure their compliance with HKMA expectations.
  • Perform a comprehensive internal audit of current segregation and reconciliation processes.
Detailed Summary
  1. Document overview: Provides regulatory standards for AIs handling client digital assets (VAs, tokenized securities/real-world assets). It emphasizes protecting client assets from institutional insolvency and security breaches.
  2. Main requirements:
  • Governance: Boards must oversee risk assessment, resource allocation, and ongoing training for staff (especially transaction signers).
  • Segregation: Assets must be held in accounts (wallets) strictly separated from the AI’s own, shielded from AI creditor claims.
  • Safeguarding: Use a risk-based approach for DLT networks. Implement cold storage, HSMs for key management, and air-gapped devices for transaction approval.
  • Outsourcing: Delegation is limited to other AIs, SFC-licensed VA platforms, or licensed stablecoin issuers. AI retains ultimate accountability.
  • Disclosure: Clear, comprehensive terms provided to clients regarding ownership, insurance, and conflict of interest.
  1. Key changes: Increased rigor in "cold storage" (98% for VAs), mandatory local storage of keys, and strict constraints on "single points of failure" via key sharding and multi-signature authorization.
  2. Important dates & transition: Immediate compliance expected. AIs must align existing services with these updated standards.
  3. Impact and risks: High operational impact on IT security (wallet management, 24/7 monitoring) and legal/compliance (disclosure requirements, third-party oversight).
  4. Compliance action checklist:
  • Perform gap analysis on security controls (e.g., HSM, key sharding).
  • Implement independent code review for custody software.
  • Establish reconciliation frequency protocols (off-chain vs. on-chain).
  • Document "Need-to-know" access rights for cryptographic keys.
  • Draft/Update client disclosures.
  1. Appendices/attachments summary:
  • The document does not contain formal appendices; however, the "Footnotes" clarify the definitions of "limited purpose digital tokens" (AMLO), "tokenized securities," and the specific requirements for delegated custodial services by stablecoin issuers.
中文摘要 (2040 chars)
快速切換摘要區塊
管理層摘要
  • 目的/背景 針對認可機構(AI)提供數碼資產託管服務制定更新指引,確保在快速發展的數碼資產市場中,AI 能有效管理風險並保障客戶資產安全。
  • 一句話結論 AI 必須建立嚴謹的治理架構、實施資產隔離,並採取基於風險的技術防禦措施,確保私鑰安全、系統穩定及合規記錄,同時對外包託管保持最終責任。
  • 關鍵變更
  1. 明確資產隔離要求 必須將客戶資產與 AI 自有資產完全隔離,防範破產清算風險。
  2. 嚴格的私鑰與錢包管理 針對虛擬資產(VA),要求 98% 存入離線冷錢包,並實施硬件安全模組(HSM)及多重驗證。
  3. 外包監管強化 嚴格限制託管業務委外對象(限 AI、持牌虛擬資產交易平台或合規穩定幣發行人),且必須保留最終責任。
  4. 強制性賠償責任 因 AI 過失導致的資產損失,AI 必須承擔賠償責任,且需備有充足財務資源(含保險)。
  5. 營運與監控韌性 要求 24/7 安全監控、定期災難復原演習及針對外包服務商進行持續合規評估。
  • 重要日期 / 截止日 即日起適用(請留意文件中提及的 2025/2026 年相關穩定幣及 Staking 服務配套指引)。
  • 適用對象 / 影響範圍 香港認可機構(AI)及其本地註冊子機構(提供數碼資產託管服務者)。
  • 管理層建議行動
  1. 風險評估 立即審視並開展針對現有託管架構的全面風險評估。
  2. 政策修訂 更新內部政策,明確責任歸屬、利益衝突管理及外包審核機制。
  3. 技術升級 檢視冷錢包佔比、HSM 合規性及私鑰分片存儲方案,確保無單點失效(Single Point of Failure)。
  4. 合約條款檢視 調整客戶服務協議,確保披露內容涵蓋資產所有權、風險及賠償安排。
  5. 定期測試 建立針對災難復原及系統漏洞的常態化測試機制(含代碼審計)。
詳細摘要

1) 文檔概述
本指引適用於 AI 為客戶代管之數碼資產(加密技術及 DLT 技術資產),包括虛擬資產(VA)、代幣化證券及資產。旨在確保機構託管過程中的治理、隔離、保管及外包合規。

2) 主要要求

  • 治理與風險 董事會需負責監管;需分配足夠人才與資源;建立衝突管理及業務連續性計劃(BCP)。
  • 資產隔離 客戶資產與自有資產必須在錢包地址層面分離,防止債權人追索。
  • 託管安全
  • 私鑰/種子短語須加密存於香港;使用 HSM 等抗篡改裝置。
  • 實施白名單機制防止未經授權轉移;實施多重簽名或私鑰分片技術避免單點失效。
  • VA 託管中 98% 必須為離線冷存儲。
  • 外包管理 僅限委託給 AI、持牌 VA 平台或獲授權之穩定幣發行人;AI 需進行嚴格盡職調查並保持監控。
  • 披露責任 須向客戶完整披露資產權利、隔離方式、保險安排及利潤回饋處理(如空投/分叉)。

3) 關鍵變更
對比以往,本指引更細化了技術防禦標準,如禁止冷錢包使用公鏈智能合約、強調離線環境生成私鑰、並明確要求對託管服務商的持續評估(包括漏洞掃描與測試)。

4) 重要日期與過渡安排
本指引已更新並持續生效。AI 應根據自身託管資產類別(特別是 VA 與代幣化證券)調整風險框架。若涉及穩定幣或 Staking 服務,需同時參考 HKMA 於 2025 年 4 月發布的相關指引。

5) 對機構的影響與風險

  • 合規成本 硬體安全設施(HSM)、24/7 監控人員及第三方代碼審計成本增加。
  • 法律風險 若未能確保資產安全,AI 需承擔全額賠償責任,且需確保保險覆蓋有效。
  • 營運壓力 需具備高階技術能力來審查委外廠商的軟體開發與部署流程。

6) 合規動作清單 (Checklist)

  • [ ] 完成託管資產的全面風險評估(RBA)。
  • [ ] 確認 VA 託管冷錢包比例達 98%。
  • [ ] 審查並更新外包合約與盡職調查報告。
  • [ ] 執行系統安全性漏洞及壓力測試。
  • [ ] 更新客戶披露聲明文件。
  • [ ] 建立客戶資產定期對賬(Off-chain 與 On-chain 同步)流程。

7) 附件/附錄摘要
本文件本身即為 Annex,詳細指引內容包含在各小標題中(治理、隔離、保管、委外、披露、記錄、監控、Staking)。文中引用的其他法規(如《打擊洗錢條例》AMLO、穩定幣條例、SFC 相關指引)作為法律基礎,要求 AI 在處理跨業務(如既託管又交易)時須一併合規。