Join our Newsletter — 33% off our NHI Course

Custodial Model

A custodial model is an arrangement in which a platform holds or controls digital assets, keys, or both on behalf of the user. It simplifies the user experience, but it concentrates operational, compliance, and security responsibility with the provider and increases the importance of governance and reserve transparency.

What the custodial model actually changes

A custodial model shifts control of digital assets, keys, or both from the user to the platform. That design can reduce user friction, but it also changes the trust boundary: the provider becomes the operational gatekeeper for access, recovery, safeguarding, and transaction handling.

That shift is not just a business model detail. It affects who can enforce policy, who can recover lost access, and who must prove that assets are segregated, monitored, and protected. In practice, the custodian’s internal controls become part of the user’s security posture.

Because custody concentrates control, it also concentrates failure impact. If the platform’s signing environment, key management process, or administrative access is compromised, the user’s assets may be exposed even when the user has done nothing wrong.

Security implications of custodial control

The main security issue is concentration of authority. A custodial platform typically holds the secrets or signing capability needed to move assets, so compromise of that platform can become compromise of many users at once. This is why custody models are closely tied to control design, auditability, and segregation of duties.

Governance matters as much as technical hardening. Users and counterparties need evidence that the custodian can account for holdings, manage operational access, and keep customer assets separated from house funds or internal use. The term therefore sits at the intersection of security, operational resilience, and financial trust.

Controls that reduce exposure usually include stronger internal access control, monitored key handling, audited transaction workflows, and transparency around reserves and reconciliation. The OWASP Non-Human Identity Top 10 is relevant here because custodial operations often depend on privileged systems, service credentials, and secret handling rather than only human logins.

Custody versus self-custody

Custody is best understood by contrast with self-custody. In self-custody, the user retains the private keys and therefore the direct ability to move assets. In custody, the provider performs that function on the user’s behalf, which simplifies onboarding and recovery but removes direct user control over the signing authority.

That trade-off affects both usability and risk tolerance. Users who prefer convenience, institutional support, or recovery assistance often accept custody. Users who prioritize direct control, minimised counterparty dependence, or reduced platform trust usually prefer self-custody.

The right choice depends on whether the user wants operational convenience or direct control of the secret material that authorises transfers. A custodial model does not eliminate risk, it relocates it to the provider’s controls and governance.

Why transparency and reserve assurance matter

For custodial services, transparency is part of security. Customers need to know how assets are recorded, how liabilities are matched, and whether internal controls support accurate reporting. Without that visibility, users must trust assertions that may not be independently testable.

This is why reserve transparency, reconciliation, and independent assurance are so important. They do not just address accounting concerns, they help answer whether the custodian truly controls what it claims to control and whether customer assets remain available when needed.

In practice, a custodial model is only as strong as the provider’s ability to demonstrate custody integrity over time. The NIST SP 800-53 Rev 5 Security and Privacy Controls provides a useful control lens for access control, auditability, configuration management, and system integrity, while the SOC 2 Trust Services Criteria is often used to evaluate the reliability, availability, and confidentiality posture of providers that hold customer assets.

Risk and Threat Considerations

A custodial model concentrates both trust and attack surface. If the custodian is breached, coerced, misconfigured, or operationally unstable, a single failure can affect many users at once. The main risks are asset loss, unauthorised transfer, insider abuse, and inability to prove that holdings are properly safeguarded.

Failure mechanism: Centralised key control, privileged operational access, or weak internal segregation can let an attacker or insider move assets at scale, or prevent the provider from proving that customer balances are fully backed and segregated.

Impact: The result can be direct financial loss, frozen withdrawals, regulatory exposure, litigation, and a long-lived trust failure that extends well beyond the initial incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.SC — Cyber Supply Chain Risk Management Custody depends on a provider trust relationship and operational control chain.
PR.AA — Identity Management, Authentication, and Access Control Custodial services rely on strict control of privileged access to assets and signing capability.
RS.AN — Analysis Custody failures require analysis of control gaps, compromise paths, and customer impact.
Recommendation — Assess custodian dependencies and require assurance over the third-party control environment. Enforce tightly governed access to key-handling and asset-movement functions. Investigate custody incidents for control failure, scope of exposure, and recovery actions.
CIS Controls v8 6 — Access Control Management Custodial platforms concentrate privileged access to high-value assets and signing systems.
8 — Audit Log Management Custody needs traceability for transfers, admin actions, and reconciliation events.
5 — Account Management Custodial environments rely on tightly governed operator accounts and service accounts.
Recommendation — Restrict and review access to custody operations, secrets, and transfer workflows. Log and retain custody actions so asset movements and privileged changes are auditable. Remove stale operator access and tightly govern accounts that can affect customer assets.
NIST SP 800-53 Rev 5 AC — Access Control Custodial control depends on limiting who can initiate, approve, or alter asset handling.
AU — Audit and Accountability Custody requires evidence of transfers, approvals, and reconciliation activity.
SC — System and Communications Protection Custodial systems protect secret material and transfer channels that enable asset movement.
Recommendation — Apply least-privilege access to custody operations and administrative functions. Record custody events so asset handling can be traced and investigated. Protect custody systems and transfer paths against interception and manipulation.

Practitioner Guidance

Why practitioners should care: For providers, custody is not just about storing assets, it is about proving that control is bounded, monitored, and recoverable. For users, the practical question is whether the custodian’s controls are strong enough to justify the trust being placed in them.

Governance implication: Treat custody as a control obligation with clear ownership for key handling, reconciliation, incident response, and customer disclosure. The arrangement should be understandable to auditors, customers, and internal security teams, not only to product teams.

Practitioner takeaway: If a service holds assets on behalf of others, its security posture must be measured by the integrity of its control environment, not just by the convenience it offers.