Permissionless networks shift trust from a central operator to a distributed set of participants, which changes accountability, control, and cost structures. For regulated organisations, that can create challenges around transaction finality, operational oversight, identity assurance, and policy enforcement. Teams should evaluate whether the business benefit of decentralisation outweighs the added complexity in compliance, security governance, and incident response.
Why This Matters for Security Teams
Permissionless blockchain changes the control plane itself: the organisation does not own the network, the validators, or the transaction lifecycle in the way it would with a conventional system. That creates a governance tradeoff for regulated firms, because accountability, evidence collection, and policy enforcement become distributed across parties that may not share the same risk appetite or jurisdiction. Current guidance suggests treating this as a technology risk decision, not just an architecture choice, aligned with the NIST Cybersecurity Framework 2.0.
The practical issue is that regulated organisations still need auditability, access governance, incident response, and data handling controls even when the underlying network is permissionless. That is why NHIMG’s Top 10 NHI Issues is relevant here: once identities, keys, or signing permissions are not tightly governed, blockchain decentralisation can amplify operational risk rather than reduce it. In practice, many security teams encounter those gaps only after transaction disputes, key compromise, or compliance review findings have already exposed the weakness.
How It Works in Practice
On permissionless networks, anyone can usually read the chain, submit transactions, and participate in validation under the protocol rules. That creates three governance implications. First, the organisation cannot assume a trusted operator will mediate abuse or reverse mistakes. Second, policy controls must often sit at the application layer, wallet layer, or custody layer rather than in the chain itself. Third, evidence and reconciliation need to be designed around immutable records that may not map neatly to internal retention or deletion rules.
For regulated organisations, the question becomes where identity, authorisation, and approval live. Best practice is evolving toward stronger custody controls, segregation of duties, transaction review workflows, and explicit key management policies. The OWASP Non-Human Identity Top 10 is a useful analogue because blockchain wallets, node credentials, signer services, and automation keys behave like high-value non-human identities: if they are over-privileged, long-lived, or poorly monitored, compromise can translate directly into loss of control.
NHIMG’s Regulatory and Audit Perspectives section is especially relevant because auditors will usually ask who approved the transaction, how the signing key was protected, and whether the organisation can prove policy compliance after the fact. One useful operational pattern is to separate business approval from cryptographic signing, then log both in a way that supports reconstruction during incident response. These controls tend to break down when the organisation relies on a single shared wallet or when off-chain approvals are not retained with enough fidelity to satisfy audit or dispute resolution.
Common Variations and Edge Cases
Tighter governance often increases friction, requiring organisations to balance decentralisation benefits against approval latency, custody overhead, and user experience. That tradeoff is especially sharp when multiple jurisdictions are involved, because a permissionless network can make data residency, sanction screening, and records retention harder to evidence even when the business process is legitimate.
There is no universal standard for this yet, but current guidance suggests that regulated firms should distinguish between using blockchain as a recordkeeping tool, a settlement mechanism, or a shared-state coordination layer. Each use case changes the risk profile. For example, tokenised assets may require stronger controls around finality and transfer restrictions, while internal reconciliation workflows may be better served by a permissioned or hybrid design. NHIMG’s Lifecycle Processes for Managing NHIs helps frame the same discipline for keys and signing services: creation, approval, rotation, monitoring, and revocation need explicit ownership.
For organisations evaluating decentralised systems, the deciding factor is often not whether the network is secure in the abstract, but whether the governance model can survive a real audit, dispute, or compromise event. The Key Challenges and Risks guidance is a practical reminder that immutability and decentralisation can strengthen integrity while simultaneously making exception handling, recovery, and accountability more difficult.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Permissionless chain adoption is a governance and oversight decision. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Blockchain keys are long-lived NHI credentials if poorly managed. |
| NIST SP 800-63 | IAL2 | High-impact transactions need stronger identity assurance for approvers. |
| NIST AI RMF | AI RMF helps govern opaque, distributed decision and evidence risks. |
Define oversight criteria, risk appetite, and exception handling before approving blockchain use.
Related resources from NHI Mgmt Group
- Why do AI systems with weak inventory and impact assessments create more governance risk for organisations?
- Why do cross-border data transfers create governance risk when organisations store government or regulated data in cloud services?
- Why do opaque AI systems create governance and accountability risk in regulated workflows?
- Why do traditional identity systems create more risk as credentials spread across cloud and app environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org