Informal practices usually fail at the points regulators care about most: identity verification, suspicious activity reporting, recordkeeping, and licensing. Without documented controls, firms struggle to prove intent, demonstrate oversight, or respond to audits and enforcement actions. That weakness becomes more serious when a single platform touches trading, custody, tax reporting, and customer onboarding.
Why This Matters for Security Teams
Informal compliance practices look efficient until a regulator, auditor, or examiner asks for evidence. In crypto firms, the gap is usually not the absence of good intent, but the absence of controls that are repeatable, testable, and attributable. That becomes a problem across onboarding, transaction monitoring, custody, sanctions screening, and record retention, where a policy statement is not the same as a demonstrable control set. Current guidance from the NIST Cybersecurity Framework 2.0 and FATF Recommendations both point toward governance, traceability, and accountable execution rather than ad hoc judgment.
This is where informal practice becomes a liability. If customer risk decisions are made in chat threads, exceptions are handled by memory, or suspicious activity reviews are not logged in a way that survives scrutiny, the firm cannot reliably prove what happened, when it happened, or who approved it. That weakens both operational resilience and defensibility during enforcement. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives shows how quickly undocumented access and weak lifecycle controls turn into audit exposure, especially when secrets and service accounts are spread across multiple systems. In practice, many crypto firms discover the control gap only after an examiner requests evidence that never existed in the first place.
How It Works in Practice
Formal controls turn compliance from a habit into an evidence-producing system. That means defining owners, approvals, thresholds, exception paths, retention periods, and review cadence for each obligation, then mapping those requirements to technical and operational controls. For crypto businesses, this usually spans identity verification, anti-money-laundering monitoring, chain analysis, custody controls, and change management. The relevant standard is not whether staff “usually” do the right thing, but whether the firm can show that the right thing is required, recorded, and reviewable.
In practice, strong programs use documented workflows, system-enforced approvals, immutable logs, periodic attestations, and control testing. A suspicious activity process should show who flagged the case, what data supported the decision, when escalation occurred, and whether the report was filed on time. A licensing control should show jurisdiction mapping, product approvals, and the conditions under which a business line may not launch. This is consistent with NIST SP 800-53 Rev. 5 Security and Privacy Controls, which treats accountability, auditability, and access restriction as core control outcomes, not optional paperwork.
Formalisation also matters for non-human identities. Crypto platforms rely on API keys, service accounts, bots, and workflow credentials that can outlive the humans who created them. NHIMG’s Top 10 NHI Issues and Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs both stress that undocumented credentials and unclear ownership are classic failure points. One directly relevant NHIMG stat: only 20% of organisations have formal processes for offboarding and revoking API keys, which shows how often informal handling leaves standing access behind. These controls tend to break down when the firm operates across multiple jurisdictions because local regulatory triggers, evidence retention rules, and approval chains diverge faster than the informal process can adapt.
Common Variations and Edge Cases
Tighter compliance controls often increase operating overhead, requiring organisations to balance speed against defensibility. That tradeoff becomes visible in fast-moving crypto environments where product launches, token listings, or custody changes are time-sensitive and business teams want exceptions handled informally. Current guidance suggests that exceptions can be allowed, but only inside a documented risk-acceptance process with clear expiry, approver authority, and retrospective review. Without that, “temporary” workarounds become permanent control gaps.
There is no universal standard for exactly how much evidence every crypto firm must retain for every jurisdiction, so the control design has to reflect the applicable regime rather than a generic template. Some firms need stronger segregation between trading, custody, and compliance functions; others need more explicit jurisdictional mapping or recordkeeping controls. The important point is that undocumented judgment does not scale across regulators, acquisitions, or platform integrations. Where informal practice is especially dangerous is in firms that outsource onboarding, monitoring, or wallet operations but fail to retain oversight artifacts, because the third party’s action still lands on the firm’s control environment.
For a broader lifecycle view, NHIMG’s Ultimate Guide to NHIs — Standards is useful when compliance processes depend on machine identities, workflows, or automation. The practical lesson is simple: if a control cannot be evidenced, reproduced, and assigned to a responsible owner, it is not yet a control. In crypto, that usually becomes visible only when reporting is late, records are incomplete, or an examiner asks for proof that informal practice cannot supply.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC, GV.RM | Governance and risk management require documented, accountable compliance controls. |
| NIST SP 800-63 | IAL, AAL | Identity proofing and authentication are central to crypto onboarding and access decisions. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Undocumented API keys and service accounts are common compliance and audit gaps. |
| NIST AI RMF | GOVERN | AI RMF governance supports traceable decisions and accountable oversight. |
| CSA MAESTRO | GOV | Agentic or automated compliance processes need explicit oversight and control boundaries. |
Assign owners, approvals, and monitoring for every automation that affects compliance outcomes.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on informal evidence instead of a formal compliance report?
- What breaks when crypto firms treat compliance as a simple approval layer instead of a risk management function?
- What breaks when identity teams rely on logs instead of rollback for tenant recovery?
- What breaks when crypto platforms rely on onboarding checks but do not monitor transactions afterward?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org