Insights on Crypto Payments, Infrastructure, and Operations

Legal Custody Risk

Pronunciation: LEE-gul KUS-tuh-dee RISK

Definition

Legal custody risk is the possibility that ownership, segregation, recovery, or access rights over safeguarded assets fail under applicable law or contract. Legal Custody Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner. Decision-makers use Legal Custody Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified.

Overview

Legal custody risk arises when the legal status of assets held by a custodian is uncertain or differs from operational expectations. Issues include beneficial ownership, segregation, insolvency treatment, liens, rehypothecation, jurisdiction, subcustody, and enforceability of withdrawal rights.

Technical control of private keys does not by itself determine legal ownership, and on-chain balances may not show client liabilities or encumbrances. Contract language can also conflict with mandatory insolvency, property, sanctions, or court rules.

Organizations should review custody agreements, governing law, asset segregation, client claims, subcustodian terms, insolvency opinions, and dispute procedures. Exposure limits and diversified arrangements can reduce dependence, while records must reconcile legal entitlements with controlled assets.

Legal custody risk is the possibility that ownership, segregation, recovery, or access rights over safeguarded assets fail under applicable law or contract. Custody safety depends on enforceable ownership and recovery rights as well as technical key control and accurate asset records.

For Legal Custody Risk, the assessment should evaluate the possibility that ownership, segregation, recovery, or access rights over safeguarded assets fail under applicable law or contract. The assessment record should separate observed evidence supporting the possibility that ownership, segregation, recovery, or access rights over safeguarded assets fail under applicable law or contract from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that ownership, segregation, recovery, or access rights over safeguarded assets fail under applicable law or contract have changed enough to require a new rating, treatment, or approval.

Decision-makers should use findings about the possibility that ownership, segregation, recovery, or access rights over safeguarded assets fail under applicable law or contract to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.

Key Takeaway

Custody safety depends on enforceable ownership and recovery rights as well as technical key control and accurate asset records.

Sources

  1. NIST Documentation: Cyberframework — NIST (2026-07-30)
  2. FATF Documentation: Virtual Assets — FATF (2026-07-30)