All posts
Compliance·· 10 min read

FINRA Crypto Broker-Dealer Rules: SPBD Guide 2027

FINRA's special purpose broker-dealer rules have teeth in 2027. Here's what the application process actually looks like — and where most firms stumble.

By AtlasForge Financial Editorial
FINRA Crypto Broker-Dealer Rules: SPBD Guide 2027

The regulatory window for crypto broker-dealers is no longer wide open. Since FINRA published its updated guidance on Special Purpose Broker-Dealers in late 2025 and the SEC formalized complementary custody rules in Q1 2026, the path to operating a compliant crypto trading desk has become both clearer and considerably narrower. Firms that moved fast and filed loose applications in 2022 and 2023 are now facing deferred approvals, corrective filings, and in several cases, full withdrawal and refiling.

If you are in-house counsel, a compliance officer, or a founder preparing an SPBD application in 2027, this guide cuts through the regulatory boilerplate. We focus on what FINRA is actually reviewing, where the custody carve-outs apply (and where they do not), and the two disclosure items that appear on nearly every first-submission deficiency letter.

What Is a Special Purpose Broker-Dealer — and Why Does It Exist?

The SPBD designation was born from a practical problem: the SEC's customer protection rule (Rule 15c3-3) was written for securities held at DTC-eligible custodians. Digital assets sitting on a blockchain do not fit that architecture. Forcing a crypto trading firm into the standard broker-dealer box would have required either impossible custody arrangements or blanket exemptions — neither of which the SEC was willing to grant at scale.

The SPBD framework, first articulated in the SEC's 2020 no-action letter and progressively hardened since, carves out a specific license category for broker-dealers whose business is exclusively digital asset securities. The trade-off is structural: SPBDs accept heightened operational restrictions in exchange for modified compliance with Rule 15c3-3. As of 2027, there are 34 active SPBD registrations, according to FINRA's member roster — a number that has grown from 11 in 2024 but remains far below the volume of firms that initially expressed interest.

The Anatomy of an SPBD Application in 2027

FINRA processes SPBD applications through its New Member Application (NMA) portal, with a dedicated review track for digital asset securities firms. The standard review window is 180 days, though complex applications — those involving proprietary custody technology or offshore digital asset affiliates — routinely run to 270 days.

The core documents you will file include:

  • Form BD with business description specifically delineating digital asset securities vs. non-security digital assets
  • Supervisory and Compliance Procedures Manual (the SCPM) tailored to FINRA Rule 3110 and the specific SPBD operating conditions
  • Business Continuity and Disaster Recovery Plan addressing private key loss scenarios
  • Anti-Money Laundering Program that satisfies FinCEN's 2024 final rule on digital asset reporting
  • Cybersecurity Policy referencing NIST CSF 2.0 controls, which FINRA examiners began citing explicitly in review correspondence as of February 2026
  • Financial projections and capital computations demonstrating net capital compliance under Rule 15c3-1
  • Custody framework memorandum — the document most firms underweight

The custody framework memorandum deserves its own section, because it is where applications live or die.

Custody Carve-Outs: What FINRA Actually Allows

The modified Rule 15c3-3 compliance for SPBDs rests on four permissible custody arrangements. An SPBD may hold customer digital asset securities in:

  1. Cold storage controlled exclusively by the SPBD, subject to multi-signature key controls with at least two of three key shards held offline
  2. A qualified custodian that meets the SEC's February 2026 definition — notably, this now requires the custodian itself to be a bank, trust company, or registered investment adviser with a specific digital asset custody designation
  3. A smart-contract-based escrow approved on a case-by-case basis by FINRA's Office of General Counsel — only three such approvals have been issued as of April 2027
  4. A combination arrangement where the SPBD controls keys but settles through a qualified intermediary within T+1

Critical distinction: The carve-outs apply only to digital asset securities — tokens that meet the Howey test. Non-security digital assets (Bitcoin, Ether post-Merge, and assets on FINRA's evolving safe harbor list) held in the same wallet infrastructure must be operationally segregated. Commingling them in a unified custody system is the single most common technical deficiency cited in FINRA's 2026 annual examination findings report.

Firms using third-party custody platforms should verify the platform's designation status quarterly. Several custody providers that were qualified under the pre-2026 standards lost that status when the SEC's updated rule took effect on March 15, 2026, creating a gap period that caught at least seven SPBD applicants mid-filing.

The Two Disclosures Every Crypto Issuer Misses on First Submission

FINRA publishes aggregated deficiency data annually. The 2026 report, released in January 2027, identified disclosure omissions as the leading cause of deferred NMA decisions for digital asset securities firms — ahead of even capital computation errors. Two specific disclosure items appear in over 60% of first-submission deficiency letters.

Disclosure 1: The Token Issuance Conflict-of-Interest Statement

If your firm has any affiliate, parent, or controlling person that issued, co-issued, or received allocation rights to any digital asset security your SPBD intends to trade or custody, FINRA requires a standalone conflict-of-interest disclosure as an exhibit to Form BD. This is separate from the standard disciplinary history questions.

The disclosure must include: the name of the affiliated issuer, the token ticker and contract address, the percentage of total supply held by the affiliate as of the application date, and a description of the policies preventing preferential trade execution. Firms routinely include this information somewhere in their SCPM but fail to extract it into the required standalone exhibit format. The result is a deficiency letter requesting the exhibit, a 30-day response clock, and an effective 45-to-60-day delay in the review timeline.

Disclosure 2: The Qualified Purchaser Limitation Notice

SPBDs operating under the modified 15c3-3 regime must restrict their customer base to qualified purchasers as defined under Section 2(a)(51) of the Investment Company Act — generally, individuals with $5 million or more in investments, or institutions with $25 million or more. The application must include a customer onboarding flow diagram demonstrating exactly how the SPBD verifies qualified purchaser status at account opening, and a sample of the customer-facing disclosure language.

Most first-time applicants attach a legal memo asserting that their onboarding process satisfies the standard but omit the actual flow diagram and the verbatim customer disclosure language. FINRA's review staff treat these as separate required items. Submit both. Use plain language in the customer disclosure — FINRA's examiners have been explicitly critical of legalese that a retail-adjacent customer cannot parse, even if technically your customer base is restricted to institutions.

Net Capital and Recordkeeping: The 2027 Baseline

SPBDs must maintain minimum net capital of $250,000 under Rule 15c3-1. In practice, FINRA has been conditioning approvals on higher initial capital levels — typically $1 million to $2 million — for firms with proprietary custody technology, on the grounds that operational risk justifies a buffer above the regulatory floor. This is not yet codified in a formal rule but has appeared consistently in membership agreements since mid-2026.

Recordkeeping requirements under Rule 17a-3 and 17a-4 apply in full. The wrinkle for digital asset firms is blockchain transaction data: FINRA's position, confirmed in a staff interpretive letter dated September 2026, is that on-chain transaction hashes constitute records that must be preserved in WORM (write once, read many) format — the same standard as traditional trade confirmations. Your compliance infrastructure needs to pipe blockchain explorer data into a compliant archival system. Firms using AtlasForge Financial's API have found it straightforward to integrate on-chain data feeds with WORM-compliant storage partners, but this is an engineering task that requires lead time regardless of the toolchain you choose.

Ongoing FINRA Examination Priorities for SPBDs

Registration is the start, not the finish. FINRA's 2027 examination priorities letter, published in February 2027, lists digital asset securities firms as a Tier 1 examination priority for the third consecutive year. Examiners are specifically focused on:

  • Key management controls: Whether multi-signature procedures are actually followed in practice vs. documented on paper
  • Token classification consistency: Whether the firm's internal classification of specific tokens as securities or non-securities aligns with current SEC guidance and is reviewed on a regular cadence
  • Customer asset segregation: Whether customer digital asset securities are truly segregated from firm assets at the wallet level, not just at the ledger level
  • AML transaction monitoring: Whether the firm's blockchain analytics vendor (Chainalysis, Elliptic, TRM Labs, or comparable) is configured to flag the specific risk typologies FINRA cited in its 2026 AML findings
  • Supervision of associated persons: Whether registered representatives discussing digital asset securities on social media are captured in the firm's communications surveillance program

The examination cycle for SPBDs has compressed. Firms that registered in 2024 or later should expect their first cycle examination within 18 months of approval — shorter than the historical 24-to-36-month window for traditional broker-dealers.

What the Horizon Looks Like: FINRA Rulemaking in Progress

Two FINRA rulemaking proceedings are directly relevant to SPBDs and are expected to reach final rule status by Q4 2027.

The first is a proposed amendment to FINRA Rule 4370 (Business Continuity Plans) that would require SPBDs to maintain a documented "key ceremony" recovery protocol — a step-by-step procedure for reconstituting private key access after a catastrophic event, independently verifiable by a third party. The comment period closed in March 2027, and the proposed rule drew 214 comment letters, the majority from industry groups arguing the third-party verification requirement creates its own security risk.

The second is a proposed consolidated disclosure form for digital asset securities — essentially a crypto-specific version of the existing customer account agreement. If adopted as proposed, it would supersede the patchwork of state-level disclosure requirements that SPBDs currently have to navigate in jurisdictions like New York (BitLicense holders), Texas, and Wyoming. The SEC's investor protection framework and the Federal Reserve's guidance on bank-crypto interactions are both shaping the contours of this proposal.

For a deeper dive into the operational side of crypto compliance infrastructure, the CFPB's 2026 supervisory highlights on digital payments provide useful parallel context, particularly on the consumer-disclosure expectations that are bleeding into the institutional space.

Practical Checklist Before You File

Before submitting your NMA, run through these ten items:

  1. Confirm every digital asset your firm will touch has been individually classified as a security or non-security, with written legal analysis on file
  2. Verify your custody provider's qualified custodian status under the SEC's March 2026 definition — call them directly, do not rely on their marketing materials
  3. Draft the standalone conflict-of-interest exhibit as a separate document, not an SCPM appendix
  4. Prepare the customer onboarding flow diagram as a visual, not a prose description
  5. Include verbatim customer-facing disclosure language for the qualified purchaser limitation
  6. Confirm your net capital buffer strategy with a FINRA-experienced accountant before submission
  7. Map your blockchain transaction data archival process to WORM requirements
  8. Confirm your AML vendor's configuration against FINRA's 2026 AML findings typologies
  9. Document your social media surveillance program for associated persons
  10. Build a realistic 270-day timeline assumption into your board and investor communications

Getting Your Infrastructure Ready Before Approval

The SPBD approval process is long, but the compliance infrastructure you build during the application period will define your examination experience for years afterward. Firms that invest in automated transaction monitoring, structured data archival, and real-time net capital computation before their first examination consistently fare better than those that retrofit systems post-approval under examiner pressure.

The AtlasForge Financial API is built for exactly this pre-approval infrastructure phase — supporting compliant data ingestion from multiple blockchain networks, structured recordkeeping outputs, and audit-trail generation that aligns with Rule 17a-4 standards. Our Safe to Spend 365 compliance dashboard also gives compliance officers a live view of capital cushion against dynamic net capital computations, reducing the manual spreadsheet work that creates errors during examination. If you are evaluating how to structure your firm's data layer before your FINRA submission, reach out to our team — we work with a number of firms in the SPBD pipeline and can share what infrastructure choices have held up under examiner scrutiny.

Further reading

Ready to build on AtlasForge?

Get sandbox API keys in 60 seconds — or install the Safe to Spend 365 app.