READ NOWH1 2026, State of Advisor Movement

Winthrop & Co.
Market Insights
GuideFiled August 20, 20267 min read

Does Managing Held-Away 401(k) Accounts Create Custody?

Advising on a client's workplace retirement plan is one of the most requested things an adviser does and one of the least settled. The moment a client's username and password enters the arrangement, the question stops being about service and becomes a custody question, and several state regulators have now answered it in a way that surprised the firms relying on the technology.

Filed by Tyler Noe

GuideDoes Managing Held-Away 401(k) Accounts Create Custody? An Adviser's Guide

A client has half their retirement savings in a workplace plan you cannot see and cannot touch, and they keep asking you what to do with it. It is one of the most common requests an adviser gets, and until fairly recently the industry had a comfortable answer: technology solved it.

That answer has been getting less comfortable.

This is a compliance question rather than a transition question, and we are a transition consultancy rather than a compliance firm. It ends up in our conversations anyway, because advisers evaluating a move to independence discover that the arrangement their current firm permitted may not be the arrangement their next structure permits, and because the answer changes depending on who supervises you. So it is worth laying out plainly.

Advice is not the problem. Access is.

Start with the distinction everything else rests on.

If a client emails you their plan menu and their current allocation, and you tell them which funds to select and in what proportion, and they log in and do it, you have given advice. No custody question arises. You are doing the thing advisers are for.

If you hold their username and password, or if you have directed them to enter those credentials into a service that acts on your instruction, you now have the ability to reach an account holding their money. Custody under the Commission's rule turns on exactly that: the ability to access or take possession of client funds or securities. Not whether you moved anything. Whether you could.

That is the whole analysis in two paragraphs, and most of the difficulty people have with this topic comes from wanting the answer to depend on intent.

What the regulators have actually said

The Securities and Exchange Commission's 2017 guidance on inadvertent custody put advisers on notice that possessing a client's online credentials is a problem where those credentials permit withdrawal or transfer of funds. That was framed as guidance and it was aimed at a broad set of arrangements.

The state regulators have been more direct, and more recent.

Washington's Department of Financial Institutions issued a notice in March 2025 addressing state-registered advisers who use third-party platforms to manage held-away accounts. Its conclusion was that the practice is likely a dishonest or unethical business practice, citing a rule that prohibits accessing a client's account using the client's own unique identifying information. Missouri issued a similar warning to its registrants in May 2024.

Two details in the Washington notice are worth reading closely because they close doors firms assume are open.

The first is that going through a vendor is not a cure. The notice addresses the case where an adviser instructs a client to share login information with a third party in a way that enables the adviser to act on the account, and treats that as the adviser obtaining access indirectly. The intermediary does not change who ends up with the ability to trade.

The second is the plan custodian's position. The notice observes that these platforms typically have no agreement with the major plan recordkeepers, and that recordkeepers are frequently unaware of the access or have actively tried to block it. That matters beyond the custody rule, because a plan's own terms of service usually govern credential sharing, and a client who shares credentials may forfeit fraud protections they assume they have.

The other version, which almost nobody prices

Everything above concerns trading. There is a quieter version of the same exposure that involves no trading at all.

Account aggregation, the feature that lets a client see their whole balance sheet in one place, frequently works by collecting client-level usernames and passwords and signing in on the client's behalf. Stored in a credential vault, or used by a screen-scraping routine, those credentials give the firm the ability to sign in to every account they cover.

A firm with three hundred clients and full aggregation turned on may have created a custody footprint across several hundred accounts without a single trade and without anyone in the firm thinking of it as a custody decision. Form ADV Item 9 will not reflect it, because nobody filled out Item 9 with the aggregation tool in mind.

What it costs to be wrong

Custody is not a label. It attaches obligations.

Assets must sit with a qualified custodian. Clients must receive written notice of the arrangement. The custodian must send statements directly to clients at least quarterly. Item 9 of Form ADV must be accurate, which is the disclosure examiners check first.

And unless an exemption applies, the firm needs an annual surprise examination by an accountant registered with the Public Company Accounting Oversight Board, with Form ADV-E filed within 120 days and any material discrepancy reported to the Commission within one business day. That examination commonly runs $15,000 to $50,000 a year.

For a firm that adopted a held-away tool to serve clients better, discovering that the tool carries a five-figure annual compliance obligation is a genuinely unwelcome surprise, and it is the sort of thing that is much cheaper to find out before adoption than during an examination.

How to think about it if you are evaluating a tool

Four questions, in order, and none of them is the vendor's compliance memo.

What does it need in order to trade? If the answer involves the client's credentials in any form, at any point, you are in the analysis above rather than outside it.

Does the plan recordkeeper know? An integration the recordkeeper has agreed to is a different animal from access it has tried to block. Ask which one you are buying.

What has your regulator said? This is currently a state-by-state picture. A practice that draws no comment in one state has been called a dishonest or unethical business practice in another, and if you are state-registered, your state's view is the one that governs you.

What does your disclosure say? Whatever you conclude, Item 9 and your client agreements should describe what actually happens. Firms rarely get into trouble for the arrangement alone. They get into trouble for the arrangement plus a disclosure that does not match it.

Where this intersects with a move

The reason this reaches a transition desk at all is that supervision changes when structure changes.

An adviser inside a large employer operates under a compliance department that has already decided this question, usually by prohibiting the tool outright, and the adviser may never have had to think about it. The same adviser running their own registered investment adviser owns the decision, the disclosure and the surprise-examination bill. An adviser under an independent broker-dealer's umbrella sits somewhere in between, with the firm's compliance function making the call but the adviser carrying the client relationship that depends on the answer.

That shift, from operating inside someone else's compliance program to owning one, is one of the underappreciated costs of the last step to full independence, and it is part of why the sequencing argument in the order most advisors get wrong favours staying under an umbrella longer than forums suggest. The broader version of what that umbrella is actually buying you is in what an independent RIA platform actually costs, and the client-facing explanation of where assets sit is in how custody actually works.

The short version

Advising on a held-away plan is fine and always has been. Signing in to one is the question.

If you are weighing a structural move and want to understand which compliance obligations travel with you and which ones you would be taking on for the first time, that is part of what we model before anything is decided. The process is set out on financial advisor transition services, and if the independent path is the one you are pricing, going independent as a financial advisor compares what each structure puts on your desk.

Nothing here is legal or compliance advice. The only opinion that binds you is your own regulator's, and on this question it is worth asking them directly.

Sources (6)

Frequently asked

Does my advisor have custody of my 401(k) if they help manage it?
It depends entirely on how they reach the account. If they look at a statement you provide and tell you which funds to select, they have no custody and the arrangement raises no custody issue. If they hold your username and password, or have directed you to give those credentials to a service that trades on their instruction, most regulators treat that as the adviser having access to your assets, and access is what the custody rule turns on. The distinction from your side is simple: does anyone other than you sign in to that account?
Does managing held-away 401(k)s create custody?
Managing them through the client's login credentials generally does. Custody under Rule 206(4)-2 turns on the ability to access or take possession of client funds or securities, and the Securities and Exchange Commission's 2017 inadvertent custody guidance made clear that advisers should avoid possessing a client's online account credentials where those credentials permit withdrawal or transfer. Managing them by giving advice the client executes does not. The compliance question is therefore not whether you advise on the plan but whether you can sign in to it.
How should firms analyze custody implications of 401(k) management tools?
Start with the access question rather than the vendor's marketing. Ask what the tool needs in order to place a trade, whether client credentials are stored anywhere, whether the plan custodian has an agreement with the vendor or has instead tried to block it, and what the plan's own terms of service say about credential sharing. Then ask what your state regulator has said, because this is currently a state-by-state picture rather than a settled national one. Finally, price the downside: if the arrangement is deemed custody, the surprise examination and Form ADV Item 9 consequences follow automatically.
What does the custody rule actually require if I am deemed to have custody?
Client assets must be held with a qualified custodian. Clients must receive written notice of the custodial arrangement. The custodian must send account statements directly to clients at least quarterly. Form ADV Item 9 must disclose the custody accurately. And unless an exemption applies, an independent accountant registered with the Public Company Accounting Oversight Board must conduct an annual surprise examination, file Form ADV-E within 120 days, and report material discrepancies to the Commission within one business day. The surprise exam alone commonly costs $15,000 to $50,000 a year.
Is account aggregation a custody problem too?
It can be, and this is the version firms overlook because nothing is being traded. Many aggregation systems require client-level usernames and passwords to pull balances and transactions. Storing those in a credential vault, or using screen-scraping that depends on them, gives the firm the ability to sign in, and the ability to sign in is the thing regulators examine. A firm with a few hundred clients running full aggregation may have created a far broader custody footprint than its Form ADV reflects.
So how can an adviser help a client with their workplace plan without this problem?
The conservative path is advice the client executes. You analyze the plan menu, recommend an allocation, document the recommendation, and the client signs in and makes the changes. It is less elegant than discretionary management and it is where a great many firms have landed. Some firms also look for direct integrations between a plan provider and their technology, which avoids credential sharing entirely where it exists. The one thing worth avoiding is assuming a vendor's compliance conclusion is your regulator's.

Filed

August 20, 2026

More from Market Insights