Bank custody changes the compliance model because cryptocurrency transfers are recorded on a public ledger, which makes monitoring and screening more observable than many fiat payment flows. That transparency can improve transaction oversight, but only if institutions have strong controls, real-time monitoring, and clear risk thresholds. Without those controls, visibility alone does not reduce exposure.
Why custody changes the compliance posture, not just the storage model
When a bank holds cryptocurrency, the service is no longer just about safekeeping an asset. It becomes a supervised financial control point where transaction oversight, customer screening, sanctions checks, and auditability all matter at the point of control. That shifts the operating model toward evidence, traceability, and policy enforcement rather than passive asset possession.
For banks, that means compliance has to be designed around how custody changes visibility into the asset flow. On-chain movement can be easier to observe than some off-chain payment paths, but the institution still needs controls that translate visibility into action, especially when custody interacts with customer onboarding, wallet ownership, and transfer approvals.
Public ledger transparency can support FATF Recommendations, AML and KYC Framework style obligations because the institution can monitor transfers, link activity to customer risk, and retain a clearer audit trail. The compliance model changes because the bank is expected to demonstrate not only that it can see movement, but that it can explain and govern it.
What controls become decisive in a bank custody model
The practical change is that compliance depends less on abstract policy and more on operational controls that can keep pace with transfers. Banks need real-time monitoring, thresholds for escalation, screening logic that is tuned to the asset and counterparty risk, and a defined exception process for unusual movement. Visibility without response capability creates a false sense of control.
That is why custody programs should treat transaction surveillance as a control system, not a reporting function. The questions become whether the institution can identify suspicious patterns quickly, preserve evidence, and route cases through the right compliance and operations teams before risk propagates.
For broader control design, ISO/IEC 27001:2022 Information Security Management and ISO/IEC 27002:2022 Information Security Controls are useful because they frame access control, logging, and governance as measurable obligations. In a custody setting, those control themes need to extend to transaction monitoring, approval workflows, and evidentiary retention.
Where institutions want a more operational control lens, CIS Controls v8 helps anchor account management, audit logging, and data protection as implementation priorities. Those are the controls that make custody oversight defensible when regulators or auditors ask how the bank detected and handled unusual activity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | Information Security Management | Custody compliance depends on governed logging, access control, and traceable operations. |
| Recommendation — Document custody controls, monitoring, and evidence retention inside the ISMS. | ||
| CIS Controls v8 | CIS Controls v8 | Prescriptive safeguards help operationalise custody monitoring and account control. |
| Recommendation — Prioritise account management, audit logging, and data protection for custody operations. | ||
Practitioner Guidance
What to verify: The custody model should prove that screening and monitoring occur at the point where the bank can actually intervene, not only after the fact. If alerts are delayed, manual, or detached from wallet and customer context, the compliance model is weaker than the ledger transparency suggests.
What practitioners underestimate: Public visibility does not remove the need for governance around thresholds. The harder problem is deciding which patterns require escalation, freezing, enhanced due diligence, or exit, and then documenting those decisions consistently enough for audit and supervisory review.
Decision rule: If the institution cannot show how it converts on-chain visibility into timely compliance action, treat the custody function as a higher-risk operating model rather than a better-monitored one.
Practitioner takeaway: Bank custody changes compliance most when it turns crypto handling into an evidence-driven control problem, where monitoring quality, escalation speed, and auditability matter more than simple ledger transparency.
Related resources from NHI Mgmt Group
- Why do digital asset firms need the same compliance rigour as traditional finance, even if the operating model is faster?
- How should security teams govern digital-asset custody when third parties are involved?
- Why do digital identity wallets change the age verification model?
- Why do organisations rely on TLS for compliance and customer trust in digital services?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 20, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org