Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What are the signs that a bank is…
Governance, Ownership & Risk

What are the signs that a bank is not ready to operate digital asset custody at scale?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Governance, Ownership & Risk

A bank is not ready when the custody plan exists without supporting controls, staff training, and cross-functional ownership. Warning signs include limited understanding of digital asset risks, weak internal education, unclear procedures for client protection, and an inability to align technology, business, and control teams around the same operating model. Those gaps usually surface before launch, not after volume grows.

What readiness looks like before launch, not after volume arrives

For digital asset custody, readiness is less about whether the bank has a strategy deck and more about whether the operating model can survive real client assets, real exceptions, and real supervision. The main warning signs are practical: control design exists on paper, but the people, process, and accountability needed to run it at scale are still missing.

A bank that is ready can explain who owns custody risk, how exceptions are approved, how client assets are protected, and how control failures are escalated. If those answers depend on informal knowledge, one-off workarounds, or a single specialist team, the launch risk is not theoretical, it is structural.

That is why cross-functional alignment matters so much. Custody combines technology operations, client service, finance, legal, compliance, and security decisions, so a weak answer in any one of those areas can undermine the whole model. The bank should be able to show that policy, workflow, and tooling all describe the same custody process instead of three different versions of it.

  • Ultimate Guide to NHIs is useful here because the custody operating model often depends on secrets, credentials, and lifecycle discipline that must be governed consistently.
  • The 2025 State of NHIs and Secrets in Cybersecurity adds a useful lens on lifecycle, offboarding, rotation, and third-party exposure when custody operations rely on machine access and privileged workflows.

Common readiness gaps that show up early

The most reliable indicator of immaturity is a gap between ambition and operating discipline. If teams cannot describe the custody lifecycle in plain language, train frontline staff on incident handling, or prove that controls were tested under realistic conditions, the institution is still in build-out mode even if the launch date is fixed.

Another sign is weak internal education. Digital asset custody introduces unfamiliar asset behaviors, irreversibility, wallet governance, key management, and reconciliation issues that are easy to underestimate if the bank tries to treat them like a standard product launch. When knowledge sits only with a small technical team, the bank usually cannot scale safely.

The same is true when client-protection procedures are vague. Custody at scale requires explicit rules for segregation, approvals, recovery, exception handling, and loss scenarios. If those procedures are not documented, rehearsed, and understood outside the project team, the bank is relying on optimism instead of control maturity.

  • CIS Controls v8 supports the practical control foundations behind account management, audit logging, and secure configuration that a custody program needs before scale.
  • NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant where the bank needs formal control expectations for access, monitoring, integrity, and configuration discipline.
  • OWASP Non-Human Identity Top 10 is especially relevant if custody workflows rely on service accounts, API keys, or automated control paths that must be governed like production identities.

Risk and Threat Considerations

Digital asset custody at scale concentrates operational, financial, and trust risk in a way that ordinary product launches do not. If controls are immature, the bank may expose client assets, create weak points in wallet or key handling, or leave itself unable to detect or contain abuse before the impact spreads across accounts or platforms.

Failure mechanism: The bank treats custody as a product launch rather than a control-intensive operating model, so gaps in training, approvals, monitoring, segregation, or recovery remain hidden until transaction volume or exception rates expose them.

Impact: Those gaps can lead to client loss exposure, unrecoverable transfers, delayed incident response, broken reconciliation, and supervisory concern, especially if the bank cannot demonstrate that staff and systems can operate safely under pressure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 5 — Account ManagementCustody scale depends on disciplined ownership of accounts and access paths.
Recommendation — Standardise account ownership, review access regularly, and remove stale custody access paths.
NIST SP 800-53 Rev 5AC — Access ControlCustody readiness hinges on enforced access boundaries and approval discipline.
AU — Audit and AccountabilityThe bank must be able to evidence custody actions, exceptions, and escalation handling.
Recommendation — Enforce least privilege and approval controls across custody operations. Log custody actions and retain audit evidence for review and incident response.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementCustody workflows often rely on service credentials and keys that must be governed tightly.
NHI-06 — Privilege and Entitlement ManagementOverprivileged automation or service access can break custody containment.
NHI-08 — Lifecycle and OffboardingCustody readiness requires predictable retirement of access, keys, and workflows.
Recommendation — Rotate and inventory custody secrets, API keys, and automation credentials. Reduce custody privileges to the minimum required for each workflow. Define offboarding and expiry rules for custody access and credentials.

Practitioner Guidance

What to verify: Before approving scale-up, verify that the bank can show named owners for custody risk, documented escalation paths, and evidence that staff outside the core build team understand the operating model. If only the project team can explain how the service works, the control environment is not ready.

What good looks like: The custody service should have tested procedures for onboarding, transaction approval, exception handling, recovery, and client protection, with business, technology, and control functions all working from the same playbook. At scale, readiness is proven by repeatability, not by a successful pilot.

Practitioner takeaway: The critical question is not whether digital asset custody can be launched, but whether the bank can run it safely when exceptions, staffing gaps, and operational stress arrive together.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org