Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Custody Risk

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Governance, Ownership & Risk

Custody risk is the chance that assets become vulnerable because of weak control over where they are held, who can access them, or how they are transferred. For crypto programmes, custody risk often changes when regulatory expectations, third-party dependencies, or access rules shift faster than operational controls.

What custody risk means in practice

Custody risk is not just about theft. It describes the security exposure created when control over an asset’s location, access path, or transfer process is weak, inconsistent, or delegated to parties and systems that the owner cannot fully govern.

In practice, custody risk appears whenever the holder of record, the technical custodian, and the operational approver are not the same entity, or when transfer rules change faster than the controls that enforce them. That gap can be small in traditional asset programmes and much larger in crypto environments where settlement, signing, storage, and release may be split across platforms, teams, and jurisdictions.

Where custody risk comes from

The risk usually emerges from a few recurring conditions: unclear ownership, excessive access, weak segregation of duties, fragile transfer approvals, and dependence on third parties or infrastructure that can fail or be compromised. For digital assets, the same problem can arise when a private key, wallet policy, or signing workflow is treated as “secure enough” even though the surrounding operational process is not.

Custody risk also grows when the trust boundary is blurry. If an organisation cannot clearly answer who can move the asset, under what conditions, and how that action is logged or reversed, then the asset may be protected in storage but exposed in motion. That is why custody is a control problem as much as it is a storage problem.

Why custody risk is harder in crypto programmes

Crypto custody often concentrates value into a small number of signing paths, admin roles, and recovery procedures. That creates a high-impact failure mode: a single weak approval rule, compromised operator, or dependency on a third-party platform can turn a procedural lapse into direct asset loss.

It is also a moving target. Regulatory expectations, transfer permissions, and provider relationships can change quickly, while operational controls, auditability, and incident response lag behind. When the asset can be transferred instantly but the control model changes slowly, the custody function becomes vulnerable to both abuse and error.

What good custody control is trying to preserve

Good custody control preserves three things at once: exclusive control by the right party, trustworthy transfer authority, and evidence that movement was intentional. That usually means the ownership model, approval model, and transfer mechanics all need to line up, not just the storage layer.

For readers evaluating a custody design, the key question is whether the control environment can still resist loss, fraud, coercion, and operational mistakes under stress. A custody setup that depends on informal approvals, shared access, or undocumented exception handling may function normally until the first real disruption exposes how much trust was assumed rather than enforced.

Risk and Threat Considerations

Custody risk matters because a weak custody model can convert a contained asset into an exposed one, especially when attackers target signing paths, recovery procedures, third-party operators, or transfer approvals. In high-value digital environments, the threat is often less about breaking the asset itself and more about exploiting the process that authorises movement.

Failure mechanism: Weak segregation of duties, overbroad access, or poor transfer governance lets an attacker, insider, or compromised vendor move assets without strong challenge, traceability, or recovery options.

Impact: The result can be direct asset loss, irreversible transfer, prolonged operational disruption, or a governance failure that undermines the organisation’s ability to prove control over the asset.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST SP 800-57 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeCustody risk depends on limiting who can move or release assets.
IA-5 — Authenticator ManagementCustody processes often rely on keys, secrets, and signing access that must be controlled.
AU-2 — Event LoggingCustody control requires traceable evidence of who authorised and executed transfers.
Recommendation — Apply least privilege to custody workflows so only approved roles can transfer or release assets. Manage custodial credentials and signing secrets with strict issuance, rotation, and revocation. Log custody approvals and transfer events so asset movement is auditable.
NIST CSF 2.0PR.AA-05 — Least Privilege Access RightsCustody risk is reduced when access to transfer and control functions is tightly limited.
GV.SC-01 — Cyber Supply Chain Risk Management StrategyThird-party custodians and transfer dependencies are central to custody risk.
Recommendation — Restrict custody operations to the minimum access rights needed for the role. Set a supply-chain risk strategy for custodians, brokers, and transfer providers.
ISO/IEC 27001:2022A.5.15 — Access controlCustody risk directly involves controlling who can access and move assets.
A.5.19 — Information security in supplier relationshipsThird-party custody dependencies can materially change asset exposure.
Recommendation — Define custody access rules that limit who can approve, sign, or transfer assets. Assess supplier custody responsibilities and enforce security requirements in contracts.
NIST SP 800-57Key managementDigital custody risk often hinges on the lifecycle of signing keys and related secret material.
Recommendation — Govern key generation, storage, rotation, and destruction as core custody controls.

Practitioner Guidance

Why practitioners should care: Custody risk is a control-design issue, not a documentation issue. If control over transfer, approval, and recovery is not explicit, the organisation may believe an asset is protected when it is only well stored.

What to watch for: The highest-risk signals are shared signing authority, informal exception handling, unclear vendor responsibility, and custody processes that differ between normal operations and emergency recovery.

Practitioner takeaway: Treat custody as a governed chain of control, from entitlement to transfer execution, and assume the weakest handoff will define the real risk posture.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org