Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What do organisations get wrong about digital asset…
Cyber Security

What do organisations get wrong about digital asset regulation and risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Cyber Security

They often assume regulation and risk move together everywhere, but they do not. A market can be highly active because of legitimate remittance or savings behaviour while still carrying elevated fraud and AML exposure. The mistake is using volume as proof of legitimacy instead of combining it with identity, provenance, and jurisdictional context.

Why Volume Is Not the Same as Low Regulatory Risk

Organisations often read digital asset activity through a single lens and miss the difference between usage intensity and regulatory exposure. High transaction volume can reflect legitimate payment corridors, treasury movement, or savings behaviour, yet still sit alongside fraud, sanctions, AML, and consumer harm concerns. The core mistake is treating aggregate activity as a proxy for trustworthiness instead of asking who is transacting, where value is moving, and under what jurisdictional obligations. For a broader governance lens, NIST Cybersecurity Framework 2.0 is useful because it frames risk as a cross-cutting management problem rather than a single control problem.

In practice, many organisations only discover this after their monitoring, onboarding, or reporting logic has already been tuned to the wrong signal.

How Digital Asset Regulation and Risk Diverge in Practice

digital asset regulation is not determined by asset class alone. It is shaped by activity type, counterparties, custody model, transfer pattern, geography, and the obligations that attach to the business model. A venue that facilitates remittances may have very different legal and supervisory expectations from one that supports speculative trading, even if both process similar volumes. Likewise, a wallet, exchange, broker, custodian, or payment flow can present different risk profiles depending on whether the organisation can identify beneficial ownership, trace provenance, and apply jurisdiction-specific restrictions.

The practical error is to assume that one metric can settle both compliance and risk. Volume can be a useful alerting input, but it cannot tell you whether funds are sanctioned, whether activity is structured to evade thresholds, or whether a customer profile matches the stated purpose of use. That is why regulators and risk teams usually care about context: identity assurance, source of funds, wallet clustering, transaction provenance, and whether controls are consistent across onboarding, screening, and ongoing monitoring.

  • Use identity and provenance checks to distinguish ordinary market activity from higher-risk movement patterns.
  • Treat jurisdiction as a control variable, not a footnote, because obligations can change materially by market.
  • Separate business growth signals from compliance signals so operational success does not mask exposure.

This guidance breaks down when an organisation lacks reliable customer data, cannot observe transfer paths, or operates through intermediaries that blur accountability.

Where Organisations Misread Context, Jurisdiction, and Control Boundaries

Tighter regulatory interpretation often increases operational overhead, requiring organisations to balance speed of growth against the cost of better evidence. The difficult edge case is that not every high-risk environment is obviously suspicious, and not every low-volume market is low-risk. A small set of transactions can create serious AML, fraud, or sanctions exposure if the provenance is weak or the jurisdictional route is opaque. By contrast, high activity in a legitimate corridor may be low concern if the organisation can explain source, destination, and customer purpose with confidence.

There is also a genuine consensus gap in parts of the market: some firms still treat digital asset risk as primarily a market-structure issue, while others treat it as primarily an identity, traceability, and obligations issue. In practice, the second view is usually more operationally useful because it forces teams to verify who controls the asset, how custody is delegated, and whether controls still hold when assets move across platforms or regions. The best programmes do not ask whether digital assets are “regulated” in the abstract; they ask which activity, actor, and jurisdiction create the obligation.

Another common mistake is assuming third-party infrastructure absorbs responsibility. Outsourcing custody, analytics, or onboarding does not outsource accountability. When the control boundary is unclear, regulatory gaps tend to appear first in exceptions, manual workarounds, and inconsistent escalation thresholds.

Risk and Threat Considerations

Digital asset environments create material exposure where identity, provenance, and jurisdictional controls are weak. The main risk is not simply non-compliance in the abstract, but the combination of fraud, sanctions breach, AML failure, and poor traceability that can accumulate when organisations rely on activity volume as a trust signal.

Failure mechanism: Abuse emerges when bad actors exploit weak onboarding, opaque wallet ownership, cross-border fragmentation, or inconsistent monitoring thresholds to make illicit flows look ordinary. If provenance data is incomplete, the organisation may be unable to distinguish legitimate movement from layering, structuring, or sanctioned exposure.

Impact: The organisation can misclassify risk, miss reportable activity, lose the ability to justify customer decisions, and face enforcement, account restrictions, or downstream counterparties refusing to transact.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyRegulatory and fraud exposure need enterprise risk framing, not a volume-only metric.
ID.BE-01 — Asset and Business EnvironmentDigital asset obligations depend on activity type, counterparties, and operating context.
PR.DS-01 — Data ManagementProvenance, screening, and monitoring depend on accurate data across systems and jurisdictions.
Recommendation — Define digital asset risk criteria around identity, provenance, and jurisdictional exposure. Classify each digital asset flow by business purpose, counterparties, and jurisdiction. Protect the integrity of customer, wallet, and transaction data used for risk decisions.
CIS Controls v86.3 — Data Protection and Lifecycle ManagementTraceability and evidence retention are central to proving transaction provenance and control.
5.1 — Establish and Maintain Asset InventoryDigital asset risk depends on knowing what assets, wallets, and control points exist.
Recommendation — Retain transaction and customer evidence needed to reconstruct provenance and decisions. Maintain an accurate inventory of wallets, custody points, and service dependencies.
NIST SP 800-63IAL2 — Identity Assurance Level 2Higher-risk digital asset activity depends on stronger identity proofing and attribution.
AAL2 — Authenticator Assurance Level 2Access to high-risk digital asset functions needs stronger authentication and accountability.
Recommendation — Raise identity assurance when transaction value, exposure, or regulatory obligation increases. Require stronger authentication for custody, withdrawal, and monitoring functions.

Practitioner Guidance

What to prioritise: Treat provenance, beneficial ownership, and jurisdictional routing as the primary evidence set, not optional enrichment. If those three are weak, volume-based comfort is unreliable.

Decision rule: If activity is high but the organisation cannot explain who controls the asset and why the flow is permissible in that market, classify the case as elevated risk until proven otherwise.

What to verify: Check whether onboarding, transaction monitoring, sanctions screening, and escalation criteria use the same risk model. Misalignment here is a common source of false comfort, because each team may think another control already covered the issue.

Practitioner takeaway: Digital asset regulation becomes actionable only when teams stop asking “how much moved?” and start asking “who, from where, under what authority, and with what traceable provenance?”

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org