Custody is the responsibility for safeguarding the asset, while wallet administration is the operational control of the account-like container that can move it. In practice, they should not be the same control. Separating them reduces the risk that one compromised role can both hold and transfer value without independent oversight.
How custody differs from wallet administration
Custody is about safeguarding the asset itself, including who has the duty to protect it from loss, misappropriation, or misuse. Wallet administration is the operational control of the container or system that can move the asset. The distinction matters because the person who maintains the wallet should not automatically be the person who can approve transfers.
Why the separation is more than an accounting distinction
In practice, custody and wallet administration split the trust model. A custodian may be responsible for secure storage, policy enforcement, and recovery, while a wallet administrator may manage access, permissions, or transaction workflows. The point of separation is to reduce single-role control over both value protection and value movement, which is a core internal-control principle.
That separation is especially important when the wallet is a high-risk control point, because administrative access can often change limits, routes, signers, or recovery settings. The more power the wallet role has, the less it should overlap with the role that is charged with keeping the asset safe.
What practitioners should verify in a custody and wallet model
Look for clear role boundaries, explicit approval paths, and evidence that the wallet administrator cannot unilaterally move assets outside its intended authority. The custody function should have independent oversight over key actions such as onboarding, offboarding, access changes, and emergency recovery.
- Confirm whether the custody role can actually move value, or only safeguard it.
- Check whether wallet administration is limited to configuration, monitoring, and routine operations.
- Validate that transfer authority, recovery authority, and administrative authority are not all held by the same party.
Risk and Threat Considerations
When custody and wallet administration are combined, one compromise can become both an access compromise and a value-transfer compromise. That creates a much larger blast radius, especially where a privileged operator, vendor, or recovery process can change the control path without a separate check.
Failure mechanism: A compromised or overprivileged role can alter wallet settings, authorize transfers, or bypass intended oversight, turning administrative access into direct asset movement capability.
Impact: Loss, unauthorized transfer, or irreversible misuse of assets can follow, and the organisation may also lose the ability to prove who controlled the asset versus who operated the wallet at the time of the action.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Custody and wallet roles need constrained authority over asset movement. |
| AU-2 — Event Logging | Distinct custody and admin actions need traceable records for oversight. | |
| Recommendation — Limit wallet administration to the minimum permissions needed for operations. Log custody and wallet actions so transfers and configuration changes are attributable. | ||
| CIS Controls v8 | CIS-5 — Account Management | Role separation depends on managing who can administer versus move assets. |
| Recommendation — Separate and review wallet administrative accounts from custody-authority accounts. | ||
| NIST CSF 2.0 | PR.AA-05 — Least Privilege Access Rights Are Managed and Maintained | The model depends on keeping transfer authority distinct from safeguarding authority. |
| Recommendation — Maintain separate, least-privilege roles for custody and wallet administration. | ||
Practitioner Guidance
What to prioritise: Treat separation of duties as the default design, not an optional governance enhancement. If one role can both safeguard and transfer, you are relying on process discipline to compensate for a weak control model.
What to verify: Review whether the custody control and wallet control have different owners, different approval paths, and different failure modes. If the same operational team can modify permissions and execute movement, the model is too concentrated.
Practitioner takeaway: The safest design is one where custody limits loss exposure and wallet administration limits operational action, with independent oversight on the point where value can actually move.
Related resources from NHI Mgmt Group
- What is the difference between attack surface management and NHI governance?
- What is the difference between reviewing human access and reviewing NHIs?
- What is the difference between role-based access and API key governance for NHI security?
- What is the difference between human IAM controls and NHI governance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org