Institutional custody is frequently discussed as a technology question, and the substance of it is operational controls that would be familiar to anyone from traditional finance.

Segregation of duties

No single person can initiate, approve and execute a transfer.

Which is the foundational control and predates digital assets by a very long time.

Implementations use multiple signers with defined roles rather than technical measures alone.

Key ceremonies

Generating and distributing key material under witnessed, documented procedures.

Which typically occurs in a secure facility with recorded video, multiple participants and a written script.

The ceremony record becomes an audit artefact demonstrating that no single party could have retained the material.

Cold and warm storage

The large majority of assets held offline, with a smaller operational balance available for withdrawals.

Which is a liquidity management decision as much as a security one.

Ratios are policy decisions and are documented, monitored and reported.

Withdrawal workflow

Requests pass through verification, approval and execution stages with defined authorisations at each.

Which introduces delay deliberately.

Allowlisted destinations with waiting periods before new addresses become usable are standard.

Reconciliation

Comparing internal records against on-chain balances continuously.

Which is where discrepancies surface early rather than at audit.

Automated reconciliation with alerting is now expected rather than exceptional.

Disaster recovery

Geographic distribution of key material and tested recovery procedures.

Which must handle the loss of a facility, of personnel and of individual key shares.

Recovery testing is periodic and is a requirement in several regulatory regimes.

Audit and attestation

Independent examination of controls under established assurance standards.

Which produces reports that clients and regulators can rely on.

The distinction between a controls report and a point-in-time balance attestation is substantive and frequently blurred in marketing.

Insurance

Coverage for specified loss events up to defined limits.

Which generally excludes losses arising from client credential compromise.

Reading the exclusions determines what the cover actually means, and the headline figure rarely does.

What clients should ask

Who holds keys, what the approval workflow is, what the assurance report covers, and what happens in insolvency.

Multi-party computation

Splitting a key across parties so no complete key ever exists in one place.

Which produces an ordinary transaction indistinguishable from a single-signer one.

Implementation quality is not visible externally, which is why independent review of the cryptographic implementation matters.

Hardware security modules

Certified devices holding key material with tamper resistance and controlled access.

Which provides physical assurance alongside procedural controls.

Certification standards specify the assurance level, and these are published and comparable.

Personnel controls

Background checks, role separation and access review.

Which addresses insider risk, historically a significant cause of losses in custody businesses.

No two employees with sufficient combined access should be able to collude without detection, which is a design requirement rather than an aspiration.

Client onboarding

Identity verification, source of funds and ongoing due diligence.

Which is required by regulation and is substantial work for institutional clients.

Onboarding timelines of weeks are normal rather than exceptional.

Staking and asset services

Custodians increasingly offer participation in network consensus on behalf of clients.

Which introduces slashing risk into a custody relationship.

How that risk is allocated between custodian and client is a contractual matter worth establishing explicitly.

Sub-custody arrangements

Custodians frequently use other custodians for specific assets or jurisdictions.

Which creates a chain that clients should understand, since risk passes down it.

Disclosure of sub-custody relationships is required under several regulatory frameworks.

Bankruptcy remoteness

Structuring so that client assets are not available to the custodian's creditors on insolvency.

Which requires specific legal arrangements rather than merely stating an intention.

Trust structures and statutory segregation are the mechanisms used, and their effectiveness varies by jurisdiction.

Fork and airdrop handling

Networks split and distribute new assets, and custodians must decide what to support.

Which is a contractual matter that clients should establish in advance.

Unsupported distributions may be unrecoverable, which has caused disputes.

Reporting to clients

Statements, transaction records and tax reporting.

Which institutional clients require in formats their existing systems can consume.

Integration with fund administration systems is a practical selection criterion.

Service level commitments

Withdrawal processing times, support availability and incident notification.

Which are contractual and are worth negotiating explicitly rather than accepting defaults.

Selection criteria

Regulatory status, assurance reports, insurance terms, supported assets, integration capability and insolvency treatment.

Which are the questions institutional clients actually ask.

Marketing material addresses few of them, and the answers are generally available on request.

Where the failures have come from

Historical custody losses have arisen from insider access, poor procedural discipline and commingling far more often than from cryptographic weakness.

Which is why the controls described here matter more than the technology selected.

Any assessment weighted toward the cryptography and light on the operational controls is looking in the wrong place.

The operational discipline is unglamorous and is what actually keeps assets where they are supposed to be.