Digital Asset Custody

Safekeeping, signing authority and the customer's legal entitlement

What custody must protect

Digital asset custody combines two distinct duties. One is protecting the customer's legal entitlement to an asset or claim. The other is controlling the credentials and systems that can move or change its digital record. A cryptographic key may authorise a transfer, but possession of that key does not alone answer who legally owns the asset, whether a custodian may use it, or how the customer is protected if the provider fails.

A bank should describe the custody arrangement in plain language: the asset held, the legal holder, the custodian entity, whether assets are segregated, who controls signing, whether the asset may be lent or pledged, and what recovery is possible. The answer depends on the asset and contract. “Cold storage” is a security control, not a complete legal custody model.

IOSCO's recommendations for crypto and digital asset markets focus on segregation and handling of client assets, disclosures, reconciliation, independent assurance and secure transfer. These are international policy recommendations; the binding rules for a particular custodian depend on its jurisdiction and authorisation.

Three records that must agree

The client entitlement record says what each customer owns or is owed. The custody inventory says what assets or keys the custodian controls, including any pooled positions. The network or issuer record says what the external system recognises. The bank should reconcile them and explain any difference promptly. A matching aggregate token balance does not prove that each customer has the right amount.

Client entitlements, custody inventory and external records must reconcile in a digital asset custody model.

Segregation can be legal, operational and technical. Separate wallet addresses may help, but they do not by themselves settle insolvency rights. Conversely, an omnibus wallet can be workable only where the legal and record-keeping arrangements preserve identifiable customer entitlements. Product teams must obtain legal analysis of the actual structure and avoid presenting a wallet layout as a guarantee of bankruptcy remoteness.

Signing control, storage and recovery

A private key or signing credential can permit an irreversible or difficult-to-reverse transfer. The bank needs a controlled life cycle: generation, approval, storage, use, rotation, backup, recovery and destruction. No single operator should be able to create and approve a high-value transfer without the controls the bank has set for that risk. Device, quorum, destination and override evidence should be retained.

“Hot,” “warm” and “cold” describe differing levels of online access, not a universal risk ranking. A hot wallet can support timely customer withdrawals but increases exposure to online compromise. A cold arrangement can reduce online exposure while increasing recovery time and manual-process risk. Hardware security modules, multiparty computation and multisignature arrangements distribute or protect signing authority in different ways; none removes the need for governance, testing and incident response.

Recovery must be rehearsed. The custodian should know what happens if a key is lost, an approver leaves, a provider fails, an address is wrong or a customer dies. Some network transfers cannot be undone. Customer terms should not promise universal reversibility. The bank needs a credible way to prove entitlement and restore service, or a clear statement where restoration is impossible.

A transfer from instruction to final customer state

A customer requests a withdrawal. The bank confirms identity and entitlement, checks the destination and applies applicable fraud, sanctions and other controls. A controlled signing process authorises the transaction. The system records the network reference and waits for the arrangement's finality rule. The client entitlement record, custody inventory and customer-visible state update together under a defined posting process.

If the network transaction is delayed, replaced or rejected, the customer should see a pending or failed state rather than an invented completion. If the external record changes while the bank book does not, operations needs a case that joins the original instruction, approvals, network events and book entries. Reconciliation must identify both missing assets and assets held without a matched customer entitlement.

Worked example: a custodian outage

A bank's custody provider becomes unavailable during a market move. Customers can see balances in the bank app but cannot withdraw. The bank should be able to distinguish assets legally held for customers from positions merely shown by a provider API. It needs an independent inventory or retrievable evidence, the latest reconciled client entitlements, an incident owner, a customer message and a tested route to recover or transfer the service.

The provider contract should give the bank access to records and assistance on exit. It should define how keys, wallets, transaction history and customer rights are handled. A service-level credit cannot repair a missing asset or prove which customer owns it.

Measures and review questions

Useful custody measures include unmatched client entitlements, aged inventory breaks, failed or overridden signing approvals, time to recover access, withdrawal failures, concentration by provider and the completeness of independent assurance. Test these with sampled customer files, not only aggregate dashboards.

Before launch, the bank should answer:

  1. Which entity is the custodian and what exact right does the customer have against it?
  2. Can the custodian reuse, lend or pledge the asset under the terms?
  3. What records prove each customer's entitlement if the provider fails?
  4. Who can sign or change destinations, and how is that authority revoked?
  5. How are network positions reconciled to customer and general-ledger records?
  6. What recovery and dispute paths work when a transfer is final or a key is lost?

Takeaway

Custody is more than keeping keys offline. It is a legal entitlement, a controlled ability to move the asset, and a reconciliation that survives provider failure. A bank should promise safety only to the extent that its contracts, records and tested operations support it.

Sources and review scope

This chapter gives general operating principles. Local custody, client-asset and insolvency rules must be checked for the exact asset, entity and jurisdiction.