Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should portfolio managers evaluate when comparing crypto…
Cyber Security

What should portfolio managers evaluate when comparing crypto risk management to traditional finance risk processes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Cyber Security

Portfolio managers should evaluate whether the same core disciplines apply, even if the asset class is new. They need integrated views of market risk, liquidity risk, operational and smart contract risk, and credit risk. The key question is whether the platform can support the decision-making expected in institutional finance, while adapting to tokenized assets and crypto market structure.

What portfolio managers are really comparing

Portfolio managers should start by comparing the underlying risk disciplines, not the label on the asset class. Crypto can still be assessed through market risk, liquidity, credit, operational risk, and control effectiveness, but the way those risks manifest is often less standardised than in traditional finance. That means the real test is whether the process produces decision-grade risk signals that can support institutional portfolio oversight.

In practice, this comparison is less about whether crypto is “riskier” in the abstract and more about whether the manager can see, measure, and govern the exposures with enough consistency to make allocation, hedging, custody, and counterparty decisions on a repeatable basis.

Traditional finance usually assumes mature pricing venues, established margining conventions, and clearer operational controls. Crypto market structure may be more fragmented, settlement and custody arrangements can vary materially, and tokenised assets may introduce dependencies that do not map neatly to standard fund risk reports. The question is whether the risk process can absorb those differences without losing comparability across the portfolio.

Where crypto risk processes diverge from conventional finance

The biggest divergence is usually not in the idea of risk management, but in the quality and stability of the inputs. Price discovery may be weaker across venues, liquidity can disappear quickly outside the most liquid pairs, and counterparty arrangements may depend on custodians, exchanges, prime brokers, or smart contract protocols that do not behave like traditional intermediaries.

Operational and smart contract risk also become part of the core comparison. A traditional risk process may assume controls around trade capture, reconciliation, corporate actions, and settlement. In crypto, the manager also has to evaluate wallet governance, key control, protocol dependency, contract upgradeability, chain-specific settlement finality, and the risk that an operational mistake becomes an irreversible loss event.

That does not mean traditional finance methods are obsolete. It means they need adaptation. A strong process will still ask the same questions about exposure, correlation, concentration, and stress, but it will add asset-specific controls for custody, on-chain settlement behaviour, venue concentration, and protocol-level failure modes. For institutional investors, NHI Mgmt Group’s Ultimate Guide to Non-Human Identities is useful for understanding how governance breaks down when control of credentials, keys, and lifecycle management is weak, which is directly relevant to crypto operational oversight.

Portfolio managers should also treat tokenised assets as a hybrid case. They may look like securities from a valuation standpoint, but operationally they can depend on blockchain rails, smart contract logic, and third-party infrastructure. That makes the comparison to traditional finance most useful when it is framed as a question of control maturity, not just asset design.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernGovernance is needed to define risk appetite and oversight for crypto exposures.
ID — IdentifyIdentify requires asset and dependency inventory across venues, custodians, and tokenised holdings.
PR — ProtectProtect covers controls for custody, access, and operational safeguards around crypto assets.
Recommendation — Set governance rules for crypto risk ownership, reporting, and exception approval. Inventory crypto exposures, dependencies, and counterparties before assigning risk. Apply protective controls to custody, access, and transaction workflows.
CIS Controls v86 — Access Control ManagementAccess control is central to protecting wallets, custody systems, and transaction authority.
8 — Audit Log ManagementAuditability is essential for reconciling trades, transfers, and control failures in crypto.
12 — Network Infrastructure ManagementCrypto platforms depend on exposed infrastructure and third-party connectivity that require segmentation and monitoring.
Recommendation — Restrict transaction and custody access to approved roles and workflows. Centralise logs for trades, transfers, and custody actions. Segment and monitor infrastructure that supports trading and custody operations.

Practitioner Guidance

What to verify: Confirm that the risk framework can separate market volatility from operational and custody-driven loss pathways. If those are blended together, the portfolio view will overstate some risks and miss others.

Decision rule: If the crypto strategy relies on venues, wallets, smart contracts, or token bridges that would materially change loss severity if they failed, require explicit control testing before treating the exposure as institutionally equivalent to a traditional instrument.

What good looks like: The manager can explain valuation, liquidity, counterparty, and operational dependencies in the same reporting pack, with clear escalation thresholds for venue stress, custody exceptions, and protocol events.

Practitioner takeaway: The most useful comparison is not “crypto versus traditional finance” in the abstract, but whether the risk process can preserve institutional discipline when market, custody, and protocol risk all move at different speeds.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org