Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why do institutional investors need stronger due diligence…
Cyber Security

Why do institutional investors need stronger due diligence when buying indexed cryptocurrency products?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Cyber Security

Institutional investors face higher expectations around provenance, counterparties, and regulatory scrutiny. Indexed crypto products can look familiar operationally, but the underlying assets still move across public blockchains where tainted funds, sanctions exposure, or suspicious activity may exist. Stronger due diligence helps firms reduce reputational risk, support compliance, and make access decisions with better evidence.

Why indexed crypto products still require institutional-grade provenance checks

Indexed products can simplify trading and custody, but they do not remove the provenance problem. The underlying tokens still come from public blockchain activity, where source-of-funds, sanctions exposure, and chain-history contamination can exist. For institutional buyers, the question is not only whether the wrapper is familiar, but whether the assets, counterparties, and control points are defensible under heightened review.

That means due diligence has to reach beyond the product label. Investors need to understand how the index is constructed, which venues or custodians touch the assets, how rebalancing occurs, and what screening is performed before exposure is packaged into a seemingly standard instrument. A product can be operationally elegant and still carry embedded compliance and reputational risk if those checks are shallow.

One practical way to think about the issue is that the wrapper may behave like a conventional fund, while the exposure behaves like public-chain crypto. EBA AML/CFT Guidance is relevant here because institutional investors often need stronger evidence that the product’s controls align with AML and counter-terrorism-financing expectations, not just trading convenience.

What stronger due diligence should actually test

Institutions should ask how the product provider identifies tainted assets, whether sanctions screening is continuous or point-in-time, and how exceptions are handled when coins or counterparties present elevated risk. They should also test whether the index methodology can exclude problematic assets quickly enough to matter, or whether it only reacts after exposure has already been admitted.

This is also where provenance and counterparties matter more than in many traditional index products. If the product relies on exchanges, custodians, administrators, or data providers with weak disclosure, the buyer inherits a chain of trust that can be hard to verify after the fact. Strong due diligence should therefore treat the control stack as part of the investment thesis.

For teams that already run onboarding and customer review controls, the relevant benchmark is not generic comfort, but evidence quality. FATF Recommendations, AML and KYC Framework is a useful reference point because it reinforces the need for customer due diligence, beneficial ownership awareness, and suspicious-activity sensitivity when exposure touches virtual assets.

When the product includes operational or technical exposure to wallets, key management, or blockchain handling, due diligence should also ask whether the provider can explain those controls at a depth suitable for an institutional allocator. NIST SP 800-57 Key Management is useful as a benchmark for judging whether cryptographic lifecycle discipline is strong enough to support institutional assurance.

Why the risk is larger for institutions than for retail buyers

Institutions face a higher bar because their exposure can trigger regulatory review, client scrutiny, and internal governance escalation even when the economic product looks ordinary. The same underlying asset can create very different consequences depending on who owns it, how it is booked, and what promises were made to clients, boards, or regulators.

The main failure mode is false familiarity. A product that resembles a traditional index vehicle can cause buyers to underweight the fact that the underlying exposure may contain tainted flow, sanctions adjacency, or weakly governed counterparties. If that happens, the institution may discover too late that the product was easier to buy than it is to defend.

For firms that want a broader control lens, NIST Cybersecurity Framework 2.0 provides a useful governance frame for managing third-party risk, asset visibility, and response discipline around the product lifecycle.

Risk and Threat Considerations

Indexed crypto products can concentrate hidden exposure, because a single purchase can bundle assets with uneven provenance, opaque counterparties, or sanctions-adjacent flow. The risk is not only price volatility, but also regulatory, reputational, and operational fallout if the institution cannot explain why the exposure was acceptable.

Failure mechanism: weak screening, shallow source-of-funds review, or opaque index methodology allows questionable assets to enter the product unchallenged, and the investor inherits that exposure through the wrapper.

Impact: the institution may face remediation work, client questions, compliance findings, or forced divestment, even if no direct fraud or sanctions breach is proven.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeControls access paths for product and custody operations tied to crypto exposure.
IA-5 — Authenticator ManagementSupports strong management of credentials used by providers, custodians, and screeners.
Recommendation — Limit operational access to product, custody, and screening systems to the minimum required. Enforce lifecycle controls for credentials that can move or approve digital assets.
CIS Controls v8CIS-15 — Service Provider ManagementApplies because institutional buyers depend on third parties for custody, screening, and execution.
Recommendation — Vet and monitor service providers that handle custody, screening, and asset movement.
NIST CSF 2.0GV.SC-01 — Supply Chain Risk Management ProcessFits the need to govern counterparties and third-party dependencies in indexed crypto products.
ID.RA-01 — Asset Inventory and ContextRelevant because buyers need visibility into assets, counterparties, and exposure paths.
Recommendation — Establish a process to evaluate third-party risk before approving the product. Identify the assets, counterparties, and exposure routes embedded in the product.

Practitioner Guidance

What to verify: Require the provider to show how assets are screened, how frequently sanctions and taint checks run, and what triggers exclusion or redemption. If those answers are vague, treat the product as higher risk than its packaging suggests.

What to prioritise: Focus first on provenance, counterparties, and control evidence, then on performance and index design. In institutional settings, a cheap or liquid product is not enough if the governance trail cannot withstand scrutiny.

Practitioner takeaway: The key judgement is whether the wrapper creates genuine risk reduction or merely hides the crypto-specific exposure inside a familiar investment format.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org