Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should crypto exchanges handle custody and fund…
Governance, Ownership & Risk

How should crypto exchanges handle custody and fund segregation in strict regulatory environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Governance, Ownership & Risk

Crypto exchanges should treat custody as a core control, not an afterthought. In strict regimes, operators need clear segregation between customer assets and business funds, independent custody arrangements, and controls that make asset movement auditable. The practical goal is to reduce counterparty misuse, protect consumers, and preserve regulatory confidence when markets experience stress or platform failures.

Custody is the control boundary, not just the storage layer

In strict regulatory environments, custody has to be treated as a governed control boundary with clear ownership, not simply as a technical wallet function. That means defining who can move assets, under what approval path, what evidence is retained, and how customer holdings remain separable from the exchange’s own operating capital. The control objective is legal, operational, and forensic clarity.

For exchanges, the core design choice is whether custody is structured to make beneficial ownership, ledger allocation, and movement authority provable at all times. If those elements are ambiguous, regulators will usually view the platform as carrying avoidable commingling risk even if the underlying wallets are technically secure.

This is where asset segregation becomes a governance requirement as much as a treasury requirement. Customer balances, corporate funds, fee revenue, and reserve assets need distinct accounting and movement rules so that stress events, reconciliations, and insolvency scenarios do not collapse into one another. Independent custody arrangements strengthen that separation when the regulatory model expects a hard barrier between the exchange and the asset holder.

Segregation only works when movement, reconciliation, and evidence line up

Effective segregation depends on more than wallet labels. The exchange has to align ledger treatment, custody permissions, transaction approvals, and reconciliation cadence so that what is shown to customers matches what is actually controlled on chain or through the custodian. The most common failure mode is a gap between internal books and operational access, especially when emergency liquidity actions are not tightly bounded.

That is why auditable movement matters. Regulators and auditors will look for a defensible trail that shows each transfer was authorised, attributable, and consistent with policy. A useful benchmark for the operational risk of weak control is that only 20% have formal processes for offboarding and revoking API keys, which illustrates how often access governance lags behind operational reality in high-control environments.

Strict regimes also tend to care about concentration and dependency risk. If a single wallet, signer, custodian, or internal approval chain can move both customer and house assets, then segregation exists in policy but not in practice. The safer design is to make the control path narrow enough that misuse, error, or compromise cannot silently cross the boundary between customer property and exchange property.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementSegregated custody depends on restricting who can move funds and approve transfers.
8 — Audit Log ManagementAuditable asset movement requires reliable logs for every transfer and approval.
Recommendation — Enforce least-privilege access and separate approval rights for customer and corporate assets. Collect and retain tamper-resistant logs for custody movements and administrator actions.
NIST CSF 2.0PR.AA-01 — Identity and Access ManagementCustody segregation relies on tightly governing which identities can authorize asset movement.
GV.OC-03 — Risk Management StrategyStrict regimes require custody and segregation to be treated as governed operational risk.
RC.RP-01 — Response Plan ExecutionFailure scenarios require the exchange to preserve segregation while operating under stress.
Recommendation — Limit custody movement authority to approved identities with documented business need. Define custody segregation as a formal risk-control objective with clear ownership. Test recovery procedures that preserve customer-asset separation during incidents and outages.
PCI DSS v4.07 — Restrict Access to System Components and Cardholder Data by Business Need to KnowLeast-privilege access is directly analogous to limiting custody and treasury movement authority.
10 — Log and Monitor All Access to System Components and Cardholder DataCustody controls need evidence of who moved what, when, and under which approval path.
Recommendation — Restrict custody and treasury access paths to verified business need and role separation. Log custody actions with sufficient detail to support reconciliation and audit review.

Practitioner Guidance

What to verify: Confirm that the exchange can produce separate, time-consistent records for customer balances, corporate treasury, and reserve holdings, and that those records reconcile to the actual custody model. If reconciliation depends on manual exceptions, treat that as a control weakness, not an operational inconvenience.

What good looks like: Customer assets remain identifiable through stress, insolvency, or incident response, and no routine business process can silently repurpose them for operating needs. Independent custody, clear signing authority, and an immutable audit trail should make that separation demonstrable rather than assumed.

Trade-off: Stronger segregation usually reduces liquidity flexibility and increases operational overhead, but that is the price of preserving customer trust and regulatory confidence in a high-scrutiny market.

Practitioner takeaway: The right question is not whether the exchange can move funds quickly, but whether it can prove that customer assets were never exposed to corporate discretion or cross-use during normal operations or failure conditions.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org