Insights on Crypto Payments, Infrastructure, and Operations

Custody Risk

Pronunciation: KUS-tuh-dee RISK

Definition

Custody risk is the possibility of losing assets or access because of failures in key control, safeguarding, records, governance, or legal arrangements. A score for Custody Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions. Custody Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner.

Overview

Custody risk covers exposures created when assets are held directly or through a third party. It includes key theft, key loss, unauthorized signing, inadequate segregation, inaccurate records, insider misuse, insolvency, legal seizure, and unavailable withdrawal infrastructure.

Self-custody removes some counterparty dependencies but increases responsibility for devices, backups, recovery, inheritance, and transaction verification. Third-party custody may add institutional controls while creating exposure to contracts, operators, jurisdictions, and financial condition.

A custody model should match asset value, transaction needs, governance, and recovery capability. Controls include multisignature approval, hardware protection, reconciliation, access reviews, independent oversight, diversified storage, and tested business-continuity procedures. Legal ownership, operational access, and technical control should each be tested under realistic stress scenarios.

For Custody Risk, production scope should name the relevant keys, signing policies, accounts, addresses, transactions, recovery paths, and custody boundaries, the decision being supported, the accountable owner, and the time and jurisdiction boundaries.

An auditable record of Custody Risk should link enrollment, signing, approval, broadcast, confirmation, revocation, and recovery events to the governing policy or model version, source evidence, decision, approver, exception, action, and final outcome.

Custody risk is the possibility of losing assets or access because of failures in key control, safeguarding, records, governance, or legal arrangements. Every custody model shifts rather than eliminates risk, balancing direct key responsibility against external operational, legal, and solvency dependencies.

For Custody Risk, the assessment should evaluate the use of of failures in key control, safeguarding, records, governance, or legal arrangements. The assessment record should separate observed evidence supporting the use of of failures in key control, safeguarding, records, governance, or legal arrangements from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the use of of failures in key control, safeguarding, records, governance, or legal arrangements have changed enough to require a new rating, treatment, or approval.

Key Takeaway

Every custody model shifts rather than eliminates risk, balancing direct key responsibility against external operational, legal, and solvency dependencies.

Sources

  1. NIST Documentation: Cyberframework — NIST (2026-07-30)
  2. FATF Documentation: Virtual Assets — FATF (2026-07-30)