Accountability is shared across the investigative chain. Law enforcement needs lawful access and coordination, exchanges need accurate KYC and timely response processes, and compliance teams need controls for suspicious activity review and preservation of records. When those pieces align, investigators can connect wallet activity to identity and support enforcement action with defensible evidence.
Why This Matters for Security Teams
When exchanges hold identity records, they become a critical control point between pseudonymous blockchain activity and a real-world person. That makes the question less about who “owns” the data and more about who can preserve, validate, and lawfully disclose it when an investigation is active. In practice, accountability spans the exchange, compliance, and law enforcement, with each party responsible for a different part of the evidence chain.
The operational risk is not only delay. Poor record quality, weak retention, or incomplete KYC can make suspicious activity impossible to tie back to a subject with defensible confidence. Current guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls reinforces that auditability, retention, and access controls are core security functions, not after-the-fact legal tasks. NHIMG research shows why this matters in adjacent identity environments: the Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, which is a useful reminder that identity blind spots often surface only when records are already needed.
In practice, many security teams encounter identity-linking failures only after investigators ask for records that were never retained cleanly or were not indexed for timely disclosure.
How It Works in Practice
The workable model is chain-of-custody plus lawful process. Exchanges are expected to know their customers, preserve relevant logs, and respond to validated requests through compliance and legal workflows. Law enforcement supplies the lawful basis, scope, and timing. Compliance teams ensure the response is accurate, limited to the request, and documentable. Without that structure, identity data may exist but still be unusable.
Security teams should treat the records as an evidentiary asset. That means aligning retention, access logging, escalation paths, and preservation holds with the exchange’s suspicious activity review process. 52 NHI Breaches Analysis illustrates a broader identity lesson: when identity evidence is fragmented or poorly governed, remediation becomes much harder after the fact. The same logic applies to exchange identity records, even though the subject matter is human identity rather than NHI.
- Preserve KYC and transaction-linked records as soon as suspicion is raised.
- Restrict disclosure to lawful requests with documented scope and approval.
- Maintain immutable logs showing who accessed or exported records.
- Separate operational monitoring from investigative disclosure decisions.
- Validate that identity fields are complete enough to support attribution.
For control mapping, NIST SP 800-53 Rev 5 Security and Privacy Controls is most relevant where retention, audit logging, and media protection are concerned, while NHIMG’s Top 10 NHI Issues helps teams think about record integrity, visibility, and timely response as identity governance problems, not just compliance tasks. These controls tend to break down when exchanges outsource onboarding and recordkeeping across multiple vendors because attribution becomes inconsistent across systems.
Common Variations and Edge Cases
Tighter identity controls often increase operational overhead, requiring organisations to balance investigative readiness against user friction and regulatory complexity. There is no universal standard for this yet, especially across jurisdictions where privacy law, AML obligations, and disclosure rules differ.
One common edge case is incomplete or outdated KYC. If the exchange collected weak identity data at onboarding, accountability may still rest with the exchange for poor controls, but investigators may not be able to reach a real person with confidence. Another issue is cross-border requests: a lawful order in one jurisdiction may not be enough for a foreign exchange without additional legal process. Best practice is evolving toward stronger record validation, but current guidance suggests that legal process, retention discipline, and clear internal ownership matter more than any single technology.
For teams building policies, the practical question is not only “who is accountable” but “who can prove the answer.” That is why the identity record must be accurate, time-stamped, and retrievable when needed, not merely collected at onboarding.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity proofing and access control are central to linking records to a real person. |
| NIST SP 800-63 | IAL2 | Exchange KYC quality depends on identity proofing assurance level. |
| OWASP Non-Human Identity Top 10 | NHI-06 | Record integrity and lifecycle controls mirror identity evidence governance needs. |
| NIST AI RMF | Governance and accountability map to the AI RMF govern function for decision traceability. | |
| NIS2 | Incident handling and record preservation expectations align with regulated response duties. |
Assign owners, document decision workflows, and preserve evidence for audits and investigations.
Related resources from NHI Mgmt Group
- Who is accountable when an identity management API exposes user records through a sibling endpoint?
- Who is accountable for auditability and consent records in cross border identity verification flows?
- Who is accountable when a third-party notices suspicious identity activity first?
- Who is accountable when suspicious identity activity is detected late?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org