The Basel Committee's cryptoasset standard, SCO60, took its first step on January 1, 2025, when the disclosure framework for banks holding Group 1b and Group 2 cryptoassets began applying, with the capital and liquidity requirements following into 2026 — a calendar that binds internationally active banks wherever jurisdictions implemented on schedule, while the US banking agencies, having issued successive statements but not a final capital rule, left American banks operating to supervisory expectations rather than codified risk weights. The consequence for custody design and vendor architecture is a two-map world.
3G Times publishes information, not legal advice; capital treatment questions belong with prudential counsel and each institution's supervisor.
What does the standard actually divide?
SCO60 sorts cryptoassets by the credibility of their stabilization. Group 1a is tokenized traditional assets — capital treatment follows the underlying exposure. Group 1b covers stablecoins and similar instruments that pass a stabilization test: segregated reserve assets, redeemable at par on demand, and a rights-and-redemption analysis that survives stress. Group 1b holdings get modified treatment — additional infrastructure risk add-ons — but nothing like the alternative. Group 2 is everything else, and it carries the regime's famous arithmetic: a 1,250 percent risk weight (or full deduction), plus, under the amended framework, a conservative floor applied even to hedged positions and an outright zero-weights prohibition for the riskiest subgroup.
What do the disclosures require?
Since January 1, 2025, banks with Group 1b or Group 2 exposures report them in a dedicated disclosure table: amounts of each class, direct versus indirect holdings, the capital impact, and the classification basis. The table is short and its existence is the point — supervisors wanted a quarterly, comparable, public picture of banking-sector crypto exposure before the capital weights bit. The second-order effect matters more for fintechs than the numbers: the disclosed classification of each instrument is now an audited, published statement of how a bank reads its stabilization mechanics, which counterparties can and do read when pricing custody and settlement relationships.
| Classification | Definition core | Capital consequence |
|---|---|---|
| Group 1a | Tokenized traditional assets | Follows the underlying exposure |
| Group 1b | Stablecoins passing the stabilization test | Modified treatment with infrastructure add-on |
| Group 2 (hedged allowed) | Other cryptoassets meeting conditions | Conservative floor on hedge recognition |
| Group 2 (prohibited) | Fail conditions, e.g., non-compliant stablecoins | Zero risk weight relief unavailable |
The audit interaction deserves planning: external auditors test classification judgments against the standard's criteria and the bank's methodology, and the disclosed tables give them a public anchor. Institutions that maintain a standing classification file — instrument, documents reviewed, analysis, approver — experience the audit as confirmation; institutions that re-derive classifications each cycle pay the analysis twice and risk the answer changing without the position changing.
What does the classification test turn on?
The Group 1b gate is a legal analysis wearing a risk costume: reserve segregation (who holds what, bankruptcy-remote or not), redemption at par (contractual right, operational capability, and the issuer's incentive to honor it at stress), and the completeness of the rights the holder actually holds. A stablecoin whose reserves sit in the issuing entity's own balance sheet, or whose redemption right is discretionary, is not a Group 1b instrument no matter how stable its price history — which is why classification memos cite the instrument's offering documents and the issuer's insolvency analysis, and why the same instrument can classify differently when issued through different structures. The EU's MiCA authorization regime interacts here predictably: authorized issuance under an e-money or credit-institution wrapper speaks directly to the redemption and segregation elements.
How does custody architecture inherit the regime?
Custody is where the capital arithmetic meets product design. A bank holding cryptoassets for clients faces the exposure classification of its own positions and, separately, the treatment of custody services themselves — fee-generating, operational-risk-bearing, and dependent on where the keys sit and whose balance sheet bears loss. Cold-storage-as-a-service, MPC arrangements, and tri-party structures change the bankruptcy and control analysis that both capital classification and client contracts turn on. Fintech custodians selling into banks therefore field a diligence package that is now Basel-literate: key-management architecture, segregation of client assets, sub-custodian chains, and the classification memo for every instrument the platform can hold — because the bank's disclosure table will name the numbers its custody vendor enabled.
What is the US gap, concretely?
The Federal Reserve, OCC, and FDIC supervised crypto activity through 2023-2025 via interagency statements, supervisory non-objection processes, and case-by-case capital treatment, without adopting SCO60 as a final rule. Banks in other jurisdictions — the EU's CRR3 package carried the standard's logic, the UK consulted on adoption, Switzerland and others implemented with local variations — answer to codified weights and disclosed tables. The operational consequence for a multinational custody or settlement program: the same position can be a disclosed, risk-weighted exposure in one subsidiary and a supervisory-conversation item in another, and group-level reporting must reconcile the maps rather than average them. The US posture shifted direction repeatedly across administrations; architecture decisions that survive the shifts are the ones that assume the stricter map applies to any entity that can hold the position.
What does this mean in practice?
- Write the classification memo per instrument, citing documents. Stabilization analysis is a legal artifact; the memo is what auditors and counterparties read.
- Design custody for the disclosure table. Key architecture and sub-custody chains should produce clean answers to "whose balance sheet" — the question both SCO60 and client contracts ask.
- Track the US rulemaking and the statements separately. Supervisory expectations bind behavior before capital rules bind arithmetic; the gap between them is where programs stall.
- Reconcile group reporting across regimes. Multi-entity programs need one position, two maps, and a reconciliation that names which map each number answers to.
SCO60's quiet achievement is that bank crypto exposure became a table anyone can read. The institutions that treat classification as legal work, custody design as balance-sheet work, and disclosure as architecture — rather than as compliance tail — are the ones the table shows flourishing.
A reporting note for groups with EU subsidiaries: the disclosure table's classification lines feed group-level capital and risk reporting, so classification changes — a stablecoin restructured toward authorization, a custody arrangement re-papered — propagate into published numbers on the next quarter. Treasury and legal share the maintenance duty: the memo that reclassifies an instrument is a capital event, and treating it as one keeps the disclosure and the balance sheet telling the same story.
How do US fintechs operate inside the gap day to day?
Through partners and contracts: the bank partner's supervisory expectations arrive as diligence questions and flow-down clauses, and the fintech answers with the Basel-literate package — classification memos, key-management architecture, sub-custody chains — regardless of which map governs the underlying positions. The gap is a US banking question; the paperwork it generates is everyone's.
Frequently asked questions
Does SCO60 apply to non-bank fintechs?
Not directly — it is bank capital regulation. It reaches fintechs through their bank clients' diligence, custody contracts, and the classification memos banks demand for any instrument a platform can hold.
Why does a stablecoin's price stability not decide classification?
Because the test reads stabilization mechanics — reserve segregation, par redemption rights, and issuer incentives — not market history. Price discipline without those elements is exactly what the 1250 percent bucket exists for.
What changed for tokenized bonds and funds (Group 1a)?
Least changed: capital follows the underlying asset. The compliance work is evidentiary — proving the token's legal claim on the traditional asset is complete, which is a documentation and settlement-law question, not a capital one.
For more context, read Consent Receipts and Audit Logs: Designing Exam-Ready Evidence for Open-Banking Authorization.
For more context, read post-quantum cryptography migration finance.
For more context, read remote online notarization requirements.

