Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What signals show a regulated crypto business is…
Governance, Ownership & Risk

What signals show a regulated crypto business is not ready for transition?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Warning signs include no tested wind-down plan, no clear transfer path for customer assets, and no mapping between authorisation status and service access. If the organisation cannot explain what happens to each critical workflow after approval expires, the transition plan is incomplete.

What a stalled transition actually looks like

A regulated crypto business is not ready when approval, asset movement, operations, and customer servicing are treated as separate workstreams rather than one controlled handover. Readiness means the firm can prove how authority, custody, and operational access change on the day of transition. If those dependencies are still being reconciled, the plan is still aspirational.

The practical test is whether the business can describe the end state for each critical workflow without hand-waving. That includes who can move assets, who can approve changes, which systems remain live, and what gets frozen if the authorisation boundary shifts. A strong transition plan is operational, not just legal or policy-based.

Where businesses miss this most often is in the gap between control ownership and service ownership. ISO/IEC 27001:2022 Information Security Management is useful here because it forces teams to think in terms of accountable controls, not just documents, and that mindset maps well to transition planning for regulated services.

Where transition plans break down

The first failure mode is a missing or untested wind-down path. If a firm cannot stop, pause, or re-route activity without losing custody, auditability, or customer access, then the transition is not operationally safe. This is especially important where regulated duties continue even if commercial arrangements change.

The second failure mode is unclear asset transfer. For a crypto business, customer assets, keys, and approvals are not abstract records, they are live control points. A transition plan must show exactly how assets are transferred, what evidence proves the transfer, and what prevents parallel control by two parties at once.

The third failure mode is access drift, where system access remains broader than the current authorisation state. In practice, the business should be able to show that service access shrinks or changes when approval status changes, instead of assuming that downstream teams will notice. NIST SP 800-53 Rev 5 Security and Privacy Controls supports this kind of control thinking through access control, identification and authentication, audit, and configuration management.

For crypto-specific custody and transfer mechanics, PCI DSS v4.0 is relevant because it reflects the broader security principle that access should be limited by business need and that interactive access for system accounts should be tightly controlled.

What transition readiness should prove before approval expires

Before a transition is considered ready, the business should be able to prove three things: the wind-down plan has been tested, asset transfer is unambiguous, and every critical workflow has a defined post-approval state. If any one of those is missing, the organisation may have a paper plan but not an executable one.

Readiness also means that the business knows what happens to exceptions. Temporary manual workarounds, emergency access, and delegated approvals need a defined expiry condition, not an informal promise to tidy them up later. That matters because regulated transitions often fail at the exception layer, not in the ideal path.

Where custody, access, and approval status intersect, the most useful control question is not “is the document complete?” but “can operations continue safely under the new authority model?” If the answer depends on unresolved assumptions about keys, permissions, or handover timing, the transition is not ready.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
ISO/IEC 27001:2022A.5.15 — Access controlTransition readiness depends on controlled access changes when authorisation status changes.
Recommendation — Define and enforce access changes for each workflow before approval expires.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccount lifecycle control is central when service access must change with transition status.
AC-6 — Least PrivilegeReadiness requires proving no excess access remains during handover or wind-down.
Recommendation — Reconcile and disable accounts that should not survive the transition. Limit transitional access to the minimum needed for each critical workflow.
CIS Controls v8CIS-5 — Account ManagementAccount governance is essential to prevent lingering access after approval changes.
Recommendation — Review and remove accounts that no longer match the approved operating state.

Practitioner Guidance

What to verify: Confirm that the business can produce an end-to-end walkthrough for each critical workflow, from approval expiry through asset transfer to service shutdown or continuation. If the team cannot show that sequence without relying on future decisions, the plan is not mature enough for transition.

Decision rule: If customer assets or privileged access would remain effective after the approval boundary changes, treat that as a blocking issue rather than an operational inconvenience. The safest transition plans remove ambiguity before go-live, not after the regulator or counterparty asks for evidence.

Practitioner takeaway: The key signal is not whether transition artefacts exist, but whether the business can prove control handover, custody transfer, and service access changes as one coherent operational state.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org