Maëlle Vautrin
Paris, France
Oct 5, 2026

Crypto custody creates a division of responsibilities that investment funds cannot resolve simply by appointing an authorised provider. A crypto-asset service provider may safeguard digital assets, but the fund’s depositary still has its own duties—and needs the information necessary to perform them.

An update to France’s depositary guidance, described in the materials supplied for this article, addresses that interface between depositaries, portfolio management companies and crypto-asset service providers. The central operational question is whether the depositary can maintain a reliable view of fund assets when a specialist provider operates the custody infrastructure.

Verification note: The supplied materials date the AMF announcement to 24 September 2026 and the associated instruction revisions to 23 September 2026. Those dates and the contents of the updated documents have not been independently verified. The account of the update below is therefore attributed to the supplied summary; the broader legal context is linked separately.

What the update addresses

According to that summary, the Autorité des Marchés Financiers’ update to its doctrine for UCITS and AIF depositaries covers relationships with authorised crypto-asset service providers, custody interfaces, fund flows, escalation procedures and quarterly anomaly reporting to the regulator. It also addresses safekeeping arrangements for alternative investment funds with crypto-asset exposure.

The accompanying changes concern Instruction DOC-2016-01, which deals with depositary authorisation procedures and reporting. These are operational and supervisory matters: how firms organise their responsibilities, obtain information and bring problems to the regulator’s attention.

The supplied summary does not establish a new, general permission for funds to invest in crypto-assets. Nor should depositary guidance be read as doing so.

CASP authorisation is not fund eligibility

Three questions need to remain separate: whether a provider is authorised to offer a crypto service, whether a fund may hold a particular asset, and how the fund’s depositary must treat that holding.

The EU’s Markets in Crypto-Assets Regulation, or MiCA, establishes a framework for crypto-asset service providers, including custody and administration services. It does not replace the investment restrictions and depositary requirements applicable to investment funds.

Those requirements arise under separate regimes, including the UCITS Directive and the Alternative Investment Fund Managers Directive. The distinction matters particularly for UCITS, where eligible-asset rules cannot be inferred from an AIF’s ability to obtain crypto exposure.

MiCA also excludes crypto-assets that qualify as financial instruments from its scope. A token’s legal classification therefore matters before firms decide which provider authorisation and safekeeping framework apply.

The depositary needs visibility, not just a provider’s licence

Under the fund regimes, safekeeping distinguishes between financial instruments held in custody and other assets subject to ownership verification and record-keeping. Applying that distinction requires an assessment of the asset and the arrangement—not merely the label “crypto”.

A CASP’s authorisation is relevant, but it does not explain how a particular fund’s assets are controlled or how the depositary receives evidence of holdings and transactions.

For managers and depositaries, the practical work starts with mapping the arrangement: who can issue instructions, which entity maintains the relevant records, how transactions are reconciled, and what information reaches the depositary. Where additional providers or technical dependencies are involved, those links also need to be understood.

These are practical implications of effective oversight, not a claim that the described AMF update prescribes a single technical model.

Anomaly reporting depends on clear escalation

The supplied summary also identifies quarterly anomaly reporting to the AMF. Its precise scope, reporting triggers and implementation requirements would need to be checked against the instruction itself.

A reporting timetable should not be confused with permission to leave an urgent incident unresolved until quarter-end. Effective arrangements need to distinguish routine reporting from immediate operational escalation and any other applicable notification duties.

That requires clarity about who detects discrepancies, who investigates them, what evidence is retained and when the manager, depositary or provider must notify the other parties. A contractual promise to cooperate is useful only if information can actually be obtained when a problem occurs.

The implementation test

For fund managers, the implication is to involve the depositary while designing a crypto-asset arrangement, rather than after selecting a custody provider. For depositaries, it is to establish whether their information access and controls are adequate for the proposed structure.

The regulatory objective is sound: specialist crypto infrastructure should not create a blind spot in fund oversight. But clarity matters as much as coverage. Firms need predictable expectations about evidence, responsibility and escalation—not overlapping processes that obscure who must act.

The decisive test is therefore not whether a custody chain contains an authorised CASP. It is whether the manager, provider and depositary can demonstrate that their distinct responsibilities work together in practice.