Operational Custody Risk
Pronunciation: ah-pur-AY-shuh-nul KUS-tuh-dee RISK
Definition
Operational custody risk is the possibility that procedures, people, systems, or records fail while safeguarding, signing, moving, or recovering assets. A score for Operational Custody Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions. Operational Custody Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner.
Overview
Operational custody risk covers day-to-day failures in asset control even when legal ownership and cryptography are sound. Examples include incorrect approvals, lost backups, address substitution, reconciliation errors, unavailable signers, insider misuse, and failed withdrawal infrastructure.
Cold storage can reduce remote attack exposure while increasing ceremony, logistics, and recovery complexity. Automated custody can improve speed but magnify software, integration, credential, and change-management failures across many assets.
Organizations should separate duties, verify destinations independently, monitor access, reconcile records, limit transactions, and test backup, failover, and key-replacement procedures. Runbooks must cover staff absence, vendor outage, chain disruption, and suspected key compromise. Metrics should include failed ceremonies, reconciliation breaks, and delayed withdrawal completion.
Operational custody risk is the possibility that procedures, people, systems, or records fail while safeguarding, signing, moving, or recovering assets. Custody operations must make both unauthorized movement and permanent inaccessibility unlikely through verified procedures, segregation, monitoring, and tested recovery.
For Operational Custody Risk, the assessment should evaluate the possibility that procedures, people, systems, or records fail while safeguarding, signing, moving, or recovering assets. The assessment record should separate observed evidence supporting the possibility that procedures, people, systems, or records fail while safeguarding, signing, moving, or recovering assets from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the possibility that procedures, people, systems, or records fail while safeguarding, signing, moving, or recovering assets have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about the possibility that procedures, people, systems, or records fail while safeguarding, signing, moving, or recovering assets to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
Custody operations must make both unauthorized movement and permanent inaccessibility unlikely through verified procedures, segregation, monitoring, and tested recovery.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)