Insights on Crypto Payments, Infrastructure, and Operations

Commingling Risk

Pronunciation: kuh-MING-gling RISK

Definition

Commingling Risk is the risk that customer, corporate, or separately owned assets are combined without adequate legal, accounting, operational, or technical separation. Pooling can be legitimate when rights and records remain clear, but undisclosed or poorly controlled commingling can create loss allocation, reconciliation, insolvency, and misuse problems. Controls include designated accounts or wallets, subledger accuracy, ownership records, daily reconciliation, transfer restrictions, segregation of operating funds, exception review, contractual disclosure, and independent assurance.

Overview

Commingling Risk is the risk that customer, corporate, or separately owned assets are combined without adequate legal, accounting, operational, or technical separation. The control exists to protect customer or beneficial-owner assets and maintain clear legal, accounting, operational, and technical separation from unauthorized use or provider failure. Pooling can be legitimate when rights and records remain clear, but undisclosed or poorly controlled commingling can create loss allocation, reconciliation, insolvency, and misuse problems. It should be interpreted alongside Client Asset Safeguarding because the concepts can affect the same decision without representing the same control, event, or risk.

The workflow identifies ownership, custody structure, wallets or accounts, subledger records, transfer authority, key controls, third parties, fees, and reconciliation. Movements require authenticated instructions, appropriate approval, policy checks, and confirmation in both custody and accounting records. In this context, controls include designated accounts or wallets, subledger accuracy, ownership records, daily reconciliation, transfer restrictions, segregation of operating funds, exception review, contractual disclosure, and independent assurance.

It should connect the term to Custody Segregation where that relationship changes access, transaction treatment, investigation, communication, or recovery.

Records should preserve beneficial ownership, addresses or account identifiers, balances, movements, approvals, key or access events, reconciliations, breaks, fee deductions, third-party statements, disclosures, and remediation. Insolvency and return procedures should be documented and tested.

Useful measures include reconciliation breaks, unexplained movements, segregation exceptions, stale balances, concentration, unauthorized attempts, return time, third-party findings, key-control failures, and unresolved customer claims.

The relationship with Cross-Provider Reconciliation should be documented where it affects residual risk or control ownership.

For Commingling Risk, the assessment should evaluate the possibility that customer, corporate, or separately owned assets are combined without adequate legal, accounting, operational, or technical separation. The assessment record should separate observed evidence supporting the possibility that customer, corporate, or separately owned assets are combined without adequate legal, accounting, operational, or technical separation from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that customer, corporate, or separately owned assets are combined without adequate legal, accounting, operational, or technical separation have changed enough to require a new rating, treatment, or approval.

Key Takeaway

Controls include designated accounts or wallets, subledger accuracy, ownership records, daily reconciliation, transfer restrictions, segregation of operating funds, exception review, contractual disclosure, and independent assurance.

Sources

  1. Policy Recommendations for Crypto and Digital Asset Markets — International Organization of Securities Commissions (2026-08-03)
  2. Client Assets Sourcebook — Financial Conduct Authority (2026-08-03)
  3. Regulation (EU) 2023/1114 on Markets in Crypto-assets — European Union (2026-08-03)