Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Custody Rule

← Back to Glossary
By NHI Mgmt Group Updated September 27, 2026 Domain: Governance, Ownership & Risk

A regulatory requirement governing how client assets are safeguarded and accounted for. In crypto, custody rules matter because control over private keys, wallet access, and asset movement can create distinct compliance obligations and risk exposure.

What custody means in practice

Custody is the point where a firm takes responsibility for safeguarding client assets and proving those assets are still present, segregated, and controllable. The term matters because the custody relationship creates legal, operational, and security duties that go well beyond simple storage.

In financial services, custody is not just about holding an asset, it is about who has authority to move it, how that authority is evidenced, and what records show at every step. That distinction is central in crypto, where control of private keys can be tantamount to control of the asset itself.

Why custody rules exist

Custody rules exist to reduce the chance that client assets are lost, misused, commingled, or unavailable when they are needed. They also establish accountability so a firm cannot blur the line between client property and firm property.

The practical security issue is that custody arrangements create a trust boundary: if access, signing authority, or settlement controls are weak, the firm may still appear compliant while client assets are exposed to theft, error, or insolvency risk. Good custody rules therefore govern both protection and proof.

For digital assets, the control problem is especially sharp because wallet access, signing workflows, and key management can determine whether the custodian truly has exclusive or delegated control over the asset movement path.

Custody in crypto and digital asset operations

In crypto, custody typically covers private keys, wallet infrastructure, transaction approval, and the policy rules that determine when assets can move. A firm may act as a custodian, sub-custodian, or technology provider, but the compliance and operational obligations depend on who can initiate, approve, and finalize transfers.

That is why custody concepts often intersect with key management, segregation of duties, authorization, and recovery planning. NIST SP 800-57 Key Management is useful here because custody depends on disciplined control over the lifecycle of cryptographic keys that can move or protect assets.

Where custodial control is implemented through service accounts, wallets, APIs, or automation, the practical issue becomes not only who owns the asset but who can exercise effective control over it. For that reason, operational custody often has an identity and access dimension even when the legal term sounds purely financial.

Common custody failure modes

Custody failures usually arise when records and real control drift apart. A firm may have asset records but inadequate reconciliation, strong policy language but weak technical enforcement, or separation on paper but shared operational access in practice.

In digital asset environments, the most serious failure modes are unauthorized signing, poor key segregation, weak recovery procedures, and inconsistent transaction approval. These failures can turn a custodial process into a single point of compromise or an evidence problem when regulators or auditors ask who controlled what, when, and under which authority.

Crypto custody also introduces concentration risk: if one wallet architecture, one provider, or one approval workflow holds too much of the asset base, a local control failure can become a portfolio-wide incident.

How the term is used across regulation and operations

Different regimes use custody language differently, but the shared idea is the same: the party with custody must protect the asset and account for it. In practice, that means documenting ownership boundaries, maintaining reconciliations, and showing that client assets are not being used as if they were the firm’s own.

For practitioners, the useful lens is to ask whether the custody model matches the actual control path. If the custody arrangement relies on shared keys, informal approvals, or unclear delegation, the legal label may be weaker than the operational reality.

In crypto and tokenized markets, that operational reality is often determined by how wallets, keys, and transfer permissions are governed. OWASP Non-Human Identity Top 10 is relevant where custody depends on machine-controlled credentials and long-lived access paths, because those credentials can become the practical mechanism through which asset control is exercised.

Risk and Threat Considerations

Custody rules fail most visibly when asset control and recordkeeping drift apart, or when a single set of credentials, wallets, or approvals becomes the easiest way to move client assets. In crypto, that creates exposure to theft, unauthorized transfer, commingling, and loss of proof about who controlled the asset at the time of movement.

Failure mechanism: Weak segregation of duties, overbroad signing authority, compromised keys, or poor reconciliation can let an attacker or insider move assets while records still appear plausible.

Impact: The result can be direct asset loss, regulatory breach, client harm, and an inability to demonstrate custody, ownership, or lawful control after an incident.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-57 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-57Recommendation for Key Management Part 1Custody of crypto assets depends on controlling the keys that can move or protect them.
Recommendation — Apply key lifecycle controls to protect, rotate, and retire keys that govern asset movement.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCustody operations rely on secure handling of credentials and signing material that authorize asset control.
Recommendation — Enforce strict lifecycle management for credentials and signing material used in custodial workflows.
OWASP Non-Human Identity Top 10NHI-07 — Long-Lived SecretsCustodial systems often depend on long-lived keys or tokens that can expose asset control.
Recommendation — Replace long-lived custodial secrets with shorter-lived, tightly governed credentials.

Practitioner Guidance

Why practitioners should care: Custody is only as strong as the control path behind it. If the signing process, reconciliation process, and access model do not line up, the firm may have a legal custody position but not a defensible operational one.

Practitioner note: In crypto custody, treat wallet authority, approval workflows, and recovery controls as the evidence of custody, not just the policy document. Where control is delegated to infrastructure or automation, verify that the delegation is explicit, limited, and auditable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org