Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should institutions evaluate custody and protection controls…
Governance, Ownership & Risk

How should institutions evaluate custody and protection controls before entering crypto markets?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Governance, Ownership & Risk

Institutions should treat custody as a governance and risk decision, not just an execution choice. The core questions are whether client assets are clearly segregated, whether the custody model supports bankruptcy protection, and whether operational controls reduce commingling risk. Teams should also verify oversight, contractual protections, and how assets are ring-fenced if the provider fails.

What institutions should assess before treating custody as a safe market entry decision

Institutions should evaluate custody through the lens of legal protection, operational resilience, and control design, not simply as a vendor selection exercise. The key issue is whether the custody structure preserves client ownership, limits balance-sheet contamination, and gives the institution credible evidence that assets remain identifiable, segregated, and recoverable if the provider is disrupted.

That means looking beyond product features to the full control environment: account structure, asset segregation, contractual rights, third-party dependencies, and the operational processes that keep client assets separated in practice. A custody model can look acceptable on paper while still creating commingling, transfer, or recovery risk if those controls are weak.

Controls that matter most when evaluating custody and protection

Practitioners should focus on whether the custody arrangement supports segregation, ring-fencing, and enforceable protection if the provider fails. If assets can be mixed with proprietary assets, rehypothecated, or moved through opaque operational chains, the institution may inherit legal and recovery uncertainty even when the market exposure itself is intentional.

Operational control quality is equally important. Institutions should verify how access is approved, who can move assets, how exceptions are handled, and whether controls are strong enough to prevent unauthorized transfers or mistaken commingling. This is where custody becomes a governance question, because weak processes can defeat otherwise sound legal terms.

  • Confirm that client assets are held in a structure that is separately identifiable and operationally isolated.
  • Test the contractual right to recover assets under provider insolvency or disruption scenarios.
  • Review who can authorize movement, under what conditions, and with what audit evidence.
  • Check whether third-party dependencies could delay access, recovery, or reconciliation.

The most useful evaluation question is not whether the provider is reputable, but whether the institution can prove where assets sit, who controls them, and what happens if the provider cannot operate normally. That proof should be stronger than marketing claims and should be supportable by contract, process, and audit trail.

Why protection controls fail in practice, and what good looks like

Failures usually come from control gaps rather than from the asset class itself. Commingling, unclear entitlement to assets, weak change control, and poor oversight of operational transfers can all turn a custody relationship into a recovery problem after a provider failure or internal incident. Institutions should therefore treat the custody stack as a chain of dependencies, not a single control.

Good custody design makes the control objective observable. The institution should be able to reconcile holdings, demonstrate segregation, understand the provider’s failure handling, and show that transfer rights are bounded by policy and contract. When those conditions are absent, the apparent convenience of the model is usually masking legal and operational exposure.

  • Ultimate Guide to NHIs notes that 97% of NHIs carry excessive privileges, a reminder that overbroad access is usually the control failure that turns a protection problem into an asset-loss problem.
  • JumpCloud Breach shows how compromise of access material can cascade into downstream customer impact when third-party controls and trust assumptions fail.
  • ISO/IEC 27001:2022 Information Security Management supports the need to evaluate access control, privileged access, authentication, and cloud security as part of the custody control environment.
  • CIS Controls v8 is useful for checking whether account management, access control, logging, and data protection controls are operating with enough discipline to support custody assurances.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS Control 6 — Access Control ManagementCustody evaluation depends on bounded access and transfer authority.
CIS Control 8 — Audit Log ManagementCustody protection needs evidence of who moved assets and when.
CIS Control 3 — Data ProtectionSegregation and ring-fencing rely on protecting asset records and sensitive holdings data.
Recommendation — Enforce account and access control limits for asset movement and recovery paths. Collect and review logs for custody actions, exceptions, and privileged transfers. Protect custody records and sensitive asset data with strong controls and segregation.
NIST CSF 2.0PR.AC — Protective Technology and Access ControlCustody risk is driven by who can access, transfer, and segregate client assets.
GV.RM — Risk Management StrategyInstitutional custody selection is a governance and risk decision before market entry.
Recommendation — Apply access controls that keep custody functions bounded and separately authorized. Assess custody as a governed risk decision with explicit tolerance and ownership.
ISO/IEC 42001:20234.1 — Understanding the organization and its contextInstitutions must assess legal, operational, and third-party context before adopting custody models.
Recommendation — Define custody context, dependencies, and failure conditions before approving use.

Practitioner Guidance

What to prioritise: Put segregation, insolvency treatment, and transfer authority ahead of commercial terms or fee comparisons. If those three are weak, the custody model is not yet fit for institutional use, even if the provider is otherwise credible.

What to verify: Ask for evidence that holdings can be reconciled to named client accounts, that operational access is limited, and that recovery rights are documented in a way legal and operations teams both accept. The practical test is whether the institution could explain its position to auditors, counsel, and the investment committee without relying on vendor assurances.

Practitioner takeaway: Custody should be accepted only when the institution can show both legal separation and operational control, because protection fails when either the contract or the control plane is too weak to survive provider distress.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org