Counterparty Custody Risk
Pronunciation: KOWN-tur-pahr-tee KUS-tuh-dee RISK
Definition
Counterparty custody risk is the possibility that an external holder loses, freezes, misuses, or cannot return assets entrusted to its control. A score for Counterparty Custody Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions. Counterparty Custody Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner.
Overview
Counterparty custody risk arises when assets depend on another organization for safekeeping, key control, settlement, or withdrawal. Relevant counterparties include exchanges, custodians, banks, brokers, stablecoin issuers, wallet providers, and bridge operators.
Loss can result from theft, insolvency, weak segregation, fraud, operational failure, legal seizure, withdrawal restrictions, or inaccurate records. Proof of on-chain holdings does not by itself establish liabilities, client ownership, access to keys, or freedom from encumbrance.
Organizations should assess legal title, segregation, governance, security, insurance, audits, financial condition, withdrawal processes, and jurisdiction. Exposure limits, diversified custody, reconciliations, test withdrawals, and documented exit plans reduce dependence but cannot eliminate counterparty failure. Contingency access arrangements should also be verified.
The wallet and custody workflow for Counterparty Custody Risk should locate where evidence enters, where a rule or judgment is applied, what state changes, and which downstream service relies on the result.
An auditable record of Counterparty Custody Risk should link enrollment, signing, approval, broadcast, confirmation, revocation, and recovery events to the governing policy or model version, source evidence, decision, approver, exception, action, and final outcome.
For Counterparty Custody Risk, production scope should name the relevant keys, signing policies, accounts, addresses, transactions, recovery paths, and custody boundaries, the decision being supported, the accountable owner, and the time and jurisdiction boundaries.
Counterparty custody risk is the possibility that an external holder loses, freezes, misuses, or cannot return assets entrusted to its control. Entrusted assets remain exposed to the custodian’s security, solvency, legal structure, records, access controls, and ability to honor withdrawals.
For Counterparty Custody Risk, the assessment should evaluate the possibility that an external holder loses, freezes, misuses, or cannot return assets entrusted to its control. The assessment record should separate observed evidence supporting the possibility that an external holder loses, freezes, misuses, or cannot return assets entrusted to its control from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that an external holder loses, freezes, misuses, or cannot return assets entrusted to its control have changed enough to require a new rating, treatment, or approval.
Key Takeaway
Entrusted assets remain exposed to the custodian's security, solvency, legal structure, records, access controls, and ability to honor withdrawals.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)