Indirect Custody
Pronunciation: ihn-dur-EHKT KUS-tuh-dee
Definition
Indirect custody is an arrangement in which an organization relies on an intermediary that uses another custodian or custody layer to safeguard assets. Reliable operation of Indirect Custody requires clear authority, segregation, controlled withdrawals, provider continuity, and reconciliation between external assets and internal entitlements. A production model for Indirect Custody should state beneficial ownership, signing control, segregation, withdrawal rights, provider dependencies, and reconciliation responsibilities.
Overview
In indirect custody, the customer relationship and the underlying asset-control relationship are not held by the same party. A platform, broker, exchange, fund, or service provider may maintain the customer account while assets are stored with a sub-custodian or pooled through additional intermediaries.
Extra layers can improve market access or specialist security but create dependency, opacity, and legal complexity. The customer may lack direct rights against the underlying custodian. Reconciliation delays, omnibus structures, insolvency, jurisdiction, and contract differences can affect recovery.
Due diligence should identify every custody layer, legal owner, account structure, asset location, control right, and termination process. Agreements should address segregation, sub-custodian changes, reporting, liability, and access during failure. Independent records must reconcile customer obligations to intermediary statements and underlying custody evidence where available.
Records for Indirect Custody should reconcile on-chain or provider balances with customer entitlements and the internal ledger by asset, network, account, and cutoff. For Indirect Custody, pending deposits, locked assets, staking, fees, conversions, forks, unsupported transfers, and manual adjustments require separate treatment and review.
Indirect Custody should be distinguished from investment ownership and from a software interface. For example, a provider may display an asset balance while holding pooled assets through another custodian; operations must verify contractual rights, segregation, withdrawal capability, and external evidence rather than rely on the screen alone.
For Indirect Custody, risks include key compromise, insider abuse, commingling, inaccurate books, unsupported tokens, provider insolvency, sub-custodian failure, blocked withdrawals, lost recovery material, and ambiguous liability. For Indirect Custody, controls should combine least privilege, separation of duties, verified destinations, asset segregation, limits, monitoring, and continuity tests.
Key Takeaway
Indirect custody adds intermediary layers, making sub-custodian identity, legal rights, segregation, and failure recovery especially important.
Sources
- Bitcoin.org Documentation: Wallets — Bitcoin.org (2026-07-30)
- NIST Documentation: Key Management — NIST (2026-07-30)