Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Third-Party Custodianship
Governance, Ownership & Risk

Third-Party Custodianship

← Back to Glossary
By NHI Mgmt Group Updated September 23, 2026 Domain: Governance, Ownership & Risk

Third-party custodianship is an arrangement where an independent custodian holds client assets instead of the trading platform itself. In crypto markets, it helps separate exchange operations from asset control, reduces commingling risk, and creates a clearer accountability model for safeguarding customer funds and executing withdrawals under defined rules.

What Third-Party Custodianship Actually Changes

Third-party custodianship changes who controls assets, not just who operates the trading venue. The custodian becomes the party responsible for safekeeping, settlement permissions, and release conditions, which helps separate operational execution from direct asset control and reduces the temptation or ability to commingle client funds.

That separation is meaningful in crypto because the custody layer is often where withdrawal authority, key handling, and asset segregation are enforced. If the custodial role is clear, the platform can still provide trading or brokerage functions without having unilateral control over client holdings.

In practice, custodianship also creates an accountability boundary. Clients, auditors, and regulators can ask who holds the assets, under what legal or contractual rules, and what controls govern movement, recovery, and exception handling.

How It Supports Safeguarding and Control Separation

The core benefit is structural. A third party holding the assets can reduce the chance that trading operations, treasury functions, and client safekeeping blur together. That separation makes it easier to enforce approval rules, reconcile balances, and demonstrate that customer assets are not being used as working capital.

This model is especially relevant when assets are represented by keys, accounts, or wallet authority rather than physical possession. Control over the mechanism that can move funds is what matters, so custodianship is really about governance over authorization paths and the rules that govern those paths.

It also supports clearer oversight for high-value or sensitive assets because the custodian can impose independent controls around access, transfer thresholds, segregation, and reporting. When those controls are independent of the platform operator, a failure in one layer does not automatically eliminate control in the other.

  • Independent custody helps keep customer assets separate from exchange operations.
  • Defined custody rules reduce ambiguity around withdrawals and recovery.
  • Clear role separation supports auditability and dispute resolution.

For a broader view of why control over credentials and transfer authority matters, NHIMG’s Ultimate Guide to NHIs is useful context, because the same governance logic applies wherever access authority and asset movement must be tightly controlled.

What Can Go Wrong When Custody Is Weak

Third-party custodianship reduces some risks, but it also introduces dependency risk. If the custodian has poor controls, weak segregation, or unclear procedures, the client inherits that failure path even if the trading platform itself is well run.

The most common failure mode is a breakdown in segregation or approval discipline, where assets become commingled, movements are poorly documented, or withdrawal authority is broader than intended. In a crypto setting, that can turn a custody problem into an immediate loss event because the asset transfer mechanism is the security boundary.

Industry evidence shows why this matters: 92% of organisations expose NHIs to third parties, raising supply chain security concerns. That is relevant here because custodial and integration relationships often depend on tokenized or delegated access patterns, and those relationships become a direct part of the control surface.

Operationally, a custodian can also become a concentration point. If the same third party serves many clients, a single process failure, incident, or compromise can affect multiple accounts at once, which makes governance and resiliency more important than simple convenience.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Identity Management, Authentication and Access ControlCustodianship depends on who can authorize asset movement and access.
GV.SC — Supply Chain Risk ManagementThird-party custody is an outsourcing and dependency relationship with direct risk exposure.
Recommendation — Define and enforce access boundaries for custody operations and transfer authority. Assess and govern third-party custody dependencies and contractual control requirements.
CIS Controls v86 — Access Control ManagementCustodial control relies on restricting and reviewing who can move or release assets.
15 — Service Provider ManagementA custodian is a service provider whose control environment affects client asset safety.
Recommendation — Restrict custody access paths and review them regularly for excess privilege. Evaluate custodian controls, responsibilities, and incident obligations before entrusting assets.
DORAICT third-party risk management — ICT Third-Party Risk ManagementFinancial entities must manage third-party dependencies that can affect critical asset control.
Recommendation — Govern custody providers as critical third-party ICT dependencies and test their resilience.

Practitioner Guidance

Governance implication: Treat custodianship as a control relationship, not just a vendor relationship. The operating question is whether the custodian can demonstrate independent safekeeping, clear withdrawal rules, and verifiable segregation of client assets from platform funds.

What to watch for: Look for ambiguous ownership of keys, unclear exception handling, weak reconciliation, or service terms that let the platform regain practical control over customer assets without equivalent oversight. Those conditions usually indicate that the custody boundary is thinner than the marketing suggests.

Practitioner takeaway: The strongest custodial model is the one that can prove who controls assets, who can move them, and under what conditions, without relying on trust in the trading venue alone.

Risk and Threat Considerations

Third-party custodianship can reduce commingling risk, but it also creates a concentration point for access, transfer authority, and operational dependency. If the custodian, its integrations, or its approval workflows are compromised, attackers may target the custody layer to move assets or interrupt withdrawals.

Failure mechanism: Weak segregation, overbroad delegated authority, or compromised third-party access can collapse the separation between platform operations and asset control, turning a governance model into a direct loss pathway.

Impact: The result can be unauthorized transfers, frozen withdrawals, customer restitution disputes, and broader loss of trust in the custody chain.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org