Custody protects and safekeps client assets, while an exchange matches buyers and sellers and facilitates trading. In a mature market, these functions are better separated because they create different risk profiles, governance needs, and client expectations. Separation can also support better continuity, clearer accountability, and more specialized services such as reporting, inheritance handling, and tax support.
Why custody and exchange are different functions
Custody and exchange sit on different sides of the market stack. Custody is about safeguarding client assets, controlling access, and preserving continuity over time. Exchange is about price discovery, order matching, market access, and execution quality. In a mature market, separating them reduces role confusion and lets each function be governed to its own risk and service model.
The distinction matters because the failure modes are not the same. A custody control failure can expose assets, settlement records, or keys; an exchange failure can distort market access, matching integrity, or client execution. Keeping the functions separate makes it easier to define accountability, operating limits, and client expectations around what is being protected versus what is being traded.
That separation also supports specialized service design. Custody can optimise for reporting, inheritance handling, treasury workflows, and controls around asset safekeeping, while exchange can optimise for liquidity, order routing, and trading operations. When one firm tries to collapse both into one undifferentiated service, governance often becomes harder to test and harder to explain to clients.
Where separation improves governance and client protection
A mature market usually separates custody from exchange because the two functions imply different trust boundaries. Custody needs strong control over asset movement, recordkeeping, and authorisation. Exchange needs controls for trade integrity, conflict management, and fair access to market infrastructure. Those are related, but they are not interchangeable.
From a governance perspective, separation can reduce concentration risk. If the same entity both holds the assets and runs the venue, a failure in one layer can propagate into the other. Independent custody can also make audits, reconciliations, and incident review clearer because the institution handling safekeeping is not also the one operating the trading venue.
For clients, the practical benefit is clearer accountability. They can distinguish who is responsible for asset protection, who is responsible for execution, and what happens if one service is disrupted. That clarity becomes especially important in institutional settings where reporting, transfer controls, and legal ownership treatment matter as much as trading convenience.
For general security governance, mature separation aligns with baseline control thinking in NIST Cybersecurity Framework 2.0 and the access-control emphasis in CIS Controls v8, while market-surveillance and trading integrity issues often sit alongside AML and KYC obligations reflected in FATF Recommendations.
How mature firms operationalise the split
In practice, maturity shows up in the details. Custody functions usually emphasise segregated asset records, approval workflows, key or secret protection, and robust reporting. Exchange functions usually emphasise matching reliability, surveillance, market abuse detection, and availability under load. The deeper the market grows, the more important it becomes to keep those operational concerns distinct.
One useful test is whether the organisation can explain the control objective without using vague language. If the answer is “we keep assets safe,” that points to custody. If the answer is “we match orders fairly and efficiently,” that points to exchange. When those answers blur, the organisation often has unresolved conflicts between safekeeping, trading, and customer service priorities.
Another test is continuity. A mature custody model should remain understandable even if the trading venue is offline, and a mature exchange model should still be understandable even if a client uses an independent custodian. That separation improves resilience because it prevents a single operating failure from automatically becoming an asset-loss event and a market-access event at the same time.
Where digital asset operations rely on technical controls such as secret handling or cryptographic keys, the custody side has the stronger alignment with lifecycle governance and key management discipline. That is why custody often benefits from control frameworks focused on identity and key stewardship, including Ultimate Guide to NHIs, What are Non-Human Identities and NIST SP 800-57 Key Management, while exchange operations lean more toward market-access and transaction-integrity controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST SP 800-53 Rev 5 and NIST SP 800-57 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV — Govern | Custody-exchange separation is a governance and accountability design decision. |
| Recommendation — Define ownership, decision rights, and oversight boundaries for custody and exchange functions. | ||
| CIS Controls v8 | 6 — Access Control Management | Custody depends on tightly controlled access to assets and sensitive operational functions. |
| 8 — Audit Log Management | Exchange and custody need distinct records for execution, transfers, and safekeeping accountability. | |
| Recommendation — Restrict and review who can move assets or alter safekeeping controls. Log and retain custody and trading actions separately for reconciliation and investigation. | ||
| NIST SP 800-53 Rev 5 | AC — Access Control | The split changes who may approve transfers versus who may execute trades. |
| AU — Audit and Accountability | Independent custody and exchange functions require clear evidence trails. | |
| Recommendation — Separate authorization for asset movement from authorization for market execution. Preserve distinct audit evidence for safekeeping actions and exchange activity. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Custody relies on protecting credentials, keys, and other identity-enabling material. |
| Recommendation — Protect custody credentials and keys with strong lifecycle and rotation controls. | ||
| NIST SP 800-57 | 1 — General Guidance | Custody commonly depends on cryptographic key lifecycle governance. |
| Recommendation — Manage key generation, storage, rotation, and destruction as a custody control. | ||
Practitioner Guidance
What to verify: Treat custody and exchange as separate control planes unless the business case explicitly requires otherwise. Verify which entity is legally and operationally responsible for asset safekeeping, which entity controls trade execution, and whether clients can independently evidence those responsibilities.
Common mistake: Do not assume that a single platform can be equally good at safekeeping and execution without introducing control trade-offs. If the same operating team can move assets and run the market venue without clear segregation, the organisation should expect harder audits, weaker accountability, and more complex incident recovery.
Practitioner takeaway: The key judgement is not whether both functions are “in one ecosystem,” but whether each function has a separate risk model, separate accountability, and controls that match its job.
Related resources from NHI Mgmt Group
- What is the difference between direct access and effective access in Active Directory?
- What is the difference between managing human identities and non-human identities?
- What is the difference between owning a digital asset outright and controlling it through a marketplace or game platform?
- What is the difference between incident response tooling and cyber asset management in a mature security programme?