top of page
Search

Recent SEC Guidance on Crypto: What It Means for Building a Defensible Compliance Program

  • Writer: Susan Kim
    Susan Kim
  • Apr 12
  • 4 min read

Regulatory expectations for crypto firms have not emerged through a single rulemaking. Instead, the U.S. Securities and Exchange Commission has articulated its position through a combination of staff guidance, enforcement actions, and examination priorities.


Across these developments, a consistent message has emerged: crypto firms operating in or accessing the U.S. market are expected to apply existing securities law frameworks with full rigor, not modified or informal interpretations.



Depiction of various cryptocurrencies in coin form
Depiction of various cryptocurrencies in coin form


What the SEC Is Really Signaling


Recent actions and guidance suggest that the SEC’s approach to crypto is not evolving toward accommodation—it is converging toward full alignment with traditional regulatory expectations.


In practical terms, that means:


  • The SEC is not waiting for industry consensus or new rulemaking

  • Business models common in crypto will be evaluated against existing regulatory standards

  • Firms will be judged based on how their compliance programs operate in practice—not how they are described


Enforcement actions involving firms such as Coinbase and Kraken reinforce this point: the absence of bespoke crypto rules does not limit the SEC’s willingness to apply existing frameworks.

For firms, the implication is straightforward: compliance programs must be built to withstand scrutiny today, not at some future point of regulatory clarity.

1. The SEC Is Not Waiting for New Rules


Recent SEC statements and actions reinforce that existing laws - particularly under the Investment Advisers Act—already apply to many crypto-related activities.


What this means in practice:

  • Firms should not delay building compliance frameworks while waiting for bespoke crypto regulation

  • Legal uncertainty does not reduce regulatory expectations

  • Compliance programs should be designed as if traditional regulatory standards fully apply


Implication: A “we’re still figuring it out” approach is unlikely to be defensible.


2. Asset Classification Must Be Documented and Consistent


The SEC continues to emphasize that digital asset classification is a facts-and-circumstances analysis.


What this means for compliance programs:


  • Maintain a documented classification framework

  • Record and support conclusions

  • Reassess classifications as facts evolve


Enforcement context: A recurring theme in SEC actions is inconsistency between how assets are described, marketed, and internally evaluated—creating exposure across both disclosure and compliance obligations.


Implication: Undocumented or inconsistent classification decisions are a primary vulnerability.


3. Custody Is a Regulatory Fault Line


Recent SEC guidance and proposals reflect a strict and expanding view of custody.


What this means for crypto firms:


  • Clearly identify custody relationships

  • Ensure segregation of client assets

  • Evaluate whether custodians meet regulatory expectations

  • Implement controls around access and transfer


Enforcement context: Custody failures and control gaps have been central to SEC scrutiny, particularly where firms relied on operational or technological safeguards without corresponding governance and oversight.


Implication: Many common crypto custody models may not align with SEC expectations.


4. Marketing Is Being Evaluated Under Traditional Standards


The SEC’s Marketing Rule is being applied to crypto-related communications with increasing scrutiny.


What this means:


  • Marketing must be fair, balanced, and substantiated

  • Performance claims must be supportable

  • Risk disclosures must be prominent and specific


Enforcement context: In actions involving firms such as Coinbase, the SEC has scrutinized how products and services are described relative to their actual regulatory status and risk profile.


Implication: Crypto marketing is not being evaluated as a new category—it is being held to existing standards, often with heightened skepticism.


5. Conflicts of Interest Are a Primary Focus


Crypto business models often involve embedded conflicts.


What this means for firms:


  • Identify and document conflicts

  • Implement mitigation or control measures

  • Ensure disclosures accurately reflect how conflicts are managed


Enforcement context: The SEC has repeatedly focused on situations where firms operated in multiple roles (e.g., trading, custody, and platform operation) without adequately addressing resulting conflicts.

Implication: Conflicts are being treated as governance failures—not just disclosure issues.


6. Governance and Accountability Expectations Are Increasing


The SEC expects compliance to be a senior-level function.


What this means:


  • Clearly defined compliance leadership

  • Documented decision-making processes

  • Active involvement from senior management


Enforcement context: In multiple actions, deficiencies were tied to the absence of clear oversight structures or accountability at the senior level.


Implication: Informal or decentralized compliance models are increasingly difficult to defend.


7. Disclosure Alone Is Not Enough


A consistent theme across SEC guidance and enforcement is that disclosure cannot compensate for weak controls.


What this means:


  • Disclosures must reflect actual practices

  • Controls must exist independently of disclosures

  • Policies must be implemented and tested


Implication: Firms that rely heavily on disclaimers without corresponding controls face heightened risk.


8. Documentation Is Critical


Documentation is often the determining factor in how issues are evaluated.


What this means:


  • Maintain records of key decisions and reviews

  • Document compliance processes and testing

  • Ensure audit trails are complete and accessible


Implication: If it is not documented, it is difficult to demonstrate that it occurred.


Conclusion: What Firms Should Do Now


Recent SEC guidance reinforces a clear direction: crypto firms are expected to meet the same regulatory standards as traditional market participants.


For firms, the practical takeaway is:


  • Build compliance programs aligned with existing regulatory frameworks

  • Focus on governance, documentation, and consistency

  • Address high-risk areas—custody, conflicts, and marketing—proactively

  • Ensure controls operate in practice, not just on paper


In the current environment, the question is not whether a crypto firm will be evaluated against these standards—but when.



 
 
 

Comments


bottom of page