Institutions should treat custody as a governance and risk decision, not just an execution choice. The core questions are whether client assets are clearly segregated, whether the custody model supports bankruptcy protection, and whether operational controls reduce commingling risk. Teams should also verify oversight, contractual protections, and how assets are ring-fenced if the provider fails.
What institutions should assess before treating custody as a safe market entry decision
Institutions should evaluate custody through the lens of legal protection, operational resilience, and control design, not simply as a vendor selection exercise. The key issue is whether the custody structure preserves client ownership, limits balance-sheet contamination, and gives the institution credible evidence that assets remain identifiable, segregated, and recoverable if the provider is disrupted.
That means looking beyond product features to the full control environment: account structure, asset segregation, contractual rights, third-party dependencies, and the operational processes that keep client assets separated in practice. A custody model can look acceptable on paper while still creating commingling, transfer, or recovery risk if those controls are weak.
Controls that matter most when evaluating custody and protection
Practitioners should focus on whether the custody arrangement supports segregation, ring-fencing, and enforceable protection if the provider fails. If assets can be mixed with proprietary assets, rehypothecated, or moved through opaque operational chains, the institution may inherit legal and recovery uncertainty even when the market exposure itself is intentional.
Operational control quality is equally important. Institutions should verify how access is approved, who can move assets, how exceptions are handled, and whether controls are strong enough to prevent unauthorized transfers or mistaken commingling. This is where custody becomes a governance question, because weak processes can defeat otherwise sound legal terms.
- Confirm that client assets are held in a structure that is separately identifiable and operationally isolated.
- Test the contractual right to recover assets under provider insolvency or disruption scenarios.
- Review who can authorize movement, under what conditions, and with what audit evidence.
- Check whether third-party dependencies could delay access, recovery, or reconciliation.
The most useful evaluation question is not whether the provider is reputable, but whether the institution can prove where assets sit, who controls them, and what happens if the provider cannot operate normally. That proof should be stronger than marketing claims and should be supportable by contract, process, and audit trail.
Why protection controls fail in practice, and what good looks like
Failures usually come from control gaps rather than from the asset class itself. Commingling, unclear entitlement to assets, weak change control, and poor oversight of operational transfers can all turn a custody relationship into a recovery problem after a provider failure or internal incident. Institutions should therefore treat the custody stack as a chain of dependencies, not a single control.
Good custody design makes the control objective observable. The institution should be able to reconcile holdings, demonstrate segregation, understand the provider’s failure handling, and show that transfer rights are bounded by policy and contract. When those conditions are absent, the apparent convenience of the model is usually masking legal and operational exposure.
- Ultimate Guide to NHIs notes that 97% of NHIs carry excessive privileges, a reminder that overbroad access is usually the control failure that turns a protection problem into an asset-loss problem.
- JumpCloud Breach shows how compromise of access material can cascade into downstream customer impact when third-party controls and trust assumptions fail.
- ISO/IEC 27001:2022 Information Security Management supports the need to evaluate access control, privileged access, authentication, and cloud security as part of the custody control environment.
- CIS Controls v8 is useful for checking whether account management, access control, logging, and data protection controls are operating with enough discipline to support custody assurances.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 6 — Access Control Management | Custody evaluation depends on bounded access and transfer authority. |
| CIS Control 8 — Audit Log Management | Custody protection needs evidence of who moved assets and when. | |
| CIS Control 3 — Data Protection | Segregation and ring-fencing rely on protecting asset records and sensitive holdings data. | |
| Recommendation — Enforce account and access control limits for asset movement and recovery paths. Collect and review logs for custody actions, exceptions, and privileged transfers. Protect custody records and sensitive asset data with strong controls and segregation. | ||
| NIST CSF 2.0 | PR.AC — Protective Technology and Access Control | Custody risk is driven by who can access, transfer, and segregate client assets. |
| GV.RM — Risk Management Strategy | Institutional custody selection is a governance and risk decision before market entry. | |
| Recommendation — Apply access controls that keep custody functions bounded and separately authorized. Assess custody as a governed risk decision with explicit tolerance and ownership. | ||
| ISO/IEC 42001:2023 | 4.1 — Understanding the organization and its context | Institutions must assess legal, operational, and third-party context before adopting custody models. |
| Recommendation — Define custody context, dependencies, and failure conditions before approving use. | ||
Practitioner Guidance
What to prioritise: Put segregation, insolvency treatment, and transfer authority ahead of commercial terms or fee comparisons. If those three are weak, the custody model is not yet fit for institutional use, even if the provider is otherwise credible.
What to verify: Ask for evidence that holdings can be reconciled to named client accounts, that operational access is limited, and that recovery rights are documented in a way legal and operations teams both accept. The practical test is whether the institution could explain its position to auditors, counsel, and the investment committee without relying on vendor assurances.
Practitioner takeaway: Custody should be accepted only when the institution can show both legal separation and operational control, because protection fails when either the contract or the control plane is too weak to survive provider distress.
Related resources from NHI Mgmt Group
- How should institutional investors evaluate custody and compliance controls before entering DeFi?
- How should financial institutions evaluate identity verification controls for e-KYC onboarding in regulated markets?
- What is the difference between human IAM controls and NHI governance?
- When should organizations review access controls?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org