When assets are not segregated, customer protection weakens immediately because client claims can become entangled with the provider’s own liabilities. That creates commingling risk, increases bankruptcy exposure, and makes recovery far less predictable. The practical failure is not only technical custody, but also the inability to prove ownership and priority if the institution enters insolvency.
Why Segregation Matters in Crypto Custody
Clear segregation is what turns custody from a general balance-sheet promise into an enforceable ownership structure. Client assets should be ring-fenced from firm assets so that records, controls, and legal treatment all point to the same conclusion: whose property is it, who can move it, and what happens if the custodian fails.
When that separation is blurred, the custody model stops being just an operational control problem and becomes a recovery problem. The key issue is not only whether the wallet infrastructure works, but whether the institution can demonstrate title, priority, and control under stress. In practice, that is what makes the difference between orderly return and disputed claims.
Segregation also affects how exposures cascade across the broader control environment. If the same holdings, accounts, or transaction records are used to support both client and firm positions, a single error can distort reporting, legal ownership, and insolvency treatment at the same time. That is why segregation is not a bookkeeping preference, it is a core custody assurance control.
- Strong segregation means client assets are operationally distinct, legally distinct, and auditable as such.
- Weak segregation creates ambiguity even when the underlying blockchain asset is technically movable.
- Recovery depends on the custodian being able to evidence ownership, not just possession.
How Commingling Creates Insolvency and Recovery Problems
Commingling is dangerous because it collapses the boundary between fiduciary custody and proprietary exposure. If a firm becomes insolvent, mixed records can leave customers arguing that their assets are part of the bankruptcy estate, or that they must wait alongside unsecured creditors rather than receiving prompt return. The failure mode is a breakdown in traceability, not just a failure of software.
This is especially acute in crypto because control can be split across wallets, addresses, sub-accounts, ledgers, and off-chain reconciliation systems. If those layers are not aligned, the institution may hold the private keys but still be unable to prove which holdings belong to whom. For customers, that increases uncertainty; for the firm, it increases legal and operational remediation cost.
Good segregation also reduces the blast radius of operational mistakes. A mistaken transfer, an internal authorization error, or an accounting mismatch is far more damaging when assets are pooled, because the error can affect multiple customer claims at once. In a stressed event, that makes disputes slower to resolve and more expensive to unwind.
For custody models that use omnibus structures, the burden shifts to reconciliation discipline, legal documentation, and clear sub-ledger accuracy. Without that, the institution may still have a technically functioning wallet stack while the customer protection model has already failed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorizations | Segregated custody depends on tightly controlled access to distinct client and firm asset pools. |
| GV.PO-1 — Cybersecurity Policy | Custody segregation requires policy-defined ownership boundaries and recovery expectations. | |
| RC.RP-1 — Recovery Plan Execution | Asset segregation directly affects the ability to execute orderly recovery after a failure. | |
| Recommendation — Enforce separate access paths for client and firm custody records and wallets. Define and enforce policy for client asset segregation and insolvency handling. Test recovery procedures that preserve client ownership and priority under distress. | ||
| CIS Controls v8 | 6.1 — Establish Access Control Processes | Custody segregation is enforced through distinct authorization and access processes. |
| 3.3 — Data Classification and Handling | Client asset records need distinct handling to preserve ownership and recovery evidence. | |
| Recommendation — Separate client and firm custody authorities and review them regularly. Classify custody records so client holdings are handled as separately controlled assets. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | Asset ownership claims must be backed by reliable identity proofing for recovery and disputes. |
| Recommendation — Require strong identity evidence for any recovery action affecting client assets. | ||
| PCI DSS v4.0 | 7.2.5 — Access Control Model | Segregated asset control mirrors the principle of limiting access to only what is necessary. |
| Recommendation — Restrict custody access so client asset controls are separated from firm operational access. | ||
Practitioner Guidance
What to verify: Confirm that legal ownership, wallet control, and sub-ledger records all support the same segregation model. If any one of those layers is ambiguous, treat the custody design as materially weaker than it appears from the wallet architecture alone.
Decision rule: If client and firm assets share the same recovery path, the same insolvency analysis, or the same reconciliation record without a hard legal separation, treat that as a custody risk requiring immediate redesign or documented exception handling.
What good looks like: A practitioner should be able to trace a client asset from entitlement to wallet control to ledger entry to recovery process without relying on inferred ownership or manual reconstruction after the fact.
Practitioner takeaway: The real test is not whether assets can be stored, but whether they can be returned under dispute, and segregation is what makes that proof possible.
Related resources from NHI Mgmt Group
- What breaks when seized crypto assets are not placed under formal custody controls?
- What breaks when private keys are exposed in seized crypto assets?
- What breaks when crypto asset control is not tied to a verified identity or custody record?
- What breaks when crypto fraud investigators cannot act fast enough to freeze suspect assets?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org