Technology Custody Risk
Pronunciation: tehk-NAH-luh-jee KUS-tuh-dee RISK
Definition
Technology custody risk is exposure to asset loss or unavailability caused by the technical systems and dependencies used for custody. A score for Technology Custody Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions. Technology Custody Risk must specify the objective or asset exposed, causal scenario, threat or dependency, likelihood basis, impact dimensions, time horizon, existing controls, and accountable owner.
Overview
Technology custody risk covers key generation, wallets, signing systems, hardware modules, MPC services, access controls, transaction policies, networks, backups, monitoring, software updates, and integrations supporting safeguarded assets.
Strong legal agreements cannot prevent loss from compromised keys, flawed code, unavailable infrastructure, unsafe recovery, or incorrect transaction construction. Shared vendors, cloud concentration, and proprietary systems can create hidden single points of failure.
Custodians should use layered key controls, independent approvals, secure recovery, reconciled records, tested continuity, change management, and real-time monitoring. Assessments must include subcustodians, vendors, network dependencies, emergency authority, upgrade paths, and evidence that recovery works without exposing assets. Controls should be tested during vendor outages, network disruption, and key-holder unavailability.
Technology custody risk is exposure to asset loss or unavailability caused by the technical systems and dependencies used for custody. Technology custody risk requires end-to-end control of keys, signing, systems, vendors, recovery, monitoring, and change across the custody stack.
For Technology Custody Risk, the assessment should evaluate exposure to asset loss or unavailability caused by the technical systems and dependencies used for custody. The assessment record should separate observed evidence supporting exposure to asset loss or unavailability caused by the technical systems and dependencies used for custody from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in exposure to asset loss or unavailability caused by the technical systems and dependencies used for custody have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about exposure to asset loss or unavailability caused by the technical systems and dependencies used for custody to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
Technology custody risk requires end-to-end control of keys, signing, systems, vendors, recovery, monitoring, and change across the custody stack.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)