As digital assets become an increasingly important part of the financial services landscape, businesses are facing growing pressure to ensure that their custody, governance and risk management arrangements are fit for purpose. Whether holding cryptocurrencies, stablecoins, tokenised assets or other forms of digital value, organisations must carefully consider how assets are safeguarded and how operational risks are managed.
For fintechs, investment firms, exchanges, custody providers and institutional investors, security is no longer simply a technical issue. It is a legal, regulatory and commercial consideration that can directly affect investor confidence, business resilience and long-term growth.
A robust governance framework, combined with appropriate custody arrangements and cybersecurity measures, can help businesses reduce risk while demonstrating a commitment to responsible digital asset management.
Understanding Digital Asset Custody Models
One of the first decisions any business must make is how its digital assets will be held and protected.
Unlike traditional assets, digital assets are controlled through cryptographic keys. Whoever controls the relevant private keys will usually have effective control over the assets themselves. As a result, custody arrangements sit at the centre of risk management.
There are several common custody models available:
- Non-custodial, where the individual or business retains direct control of private keys. Metamask is an example of a non-custodial wallet that offers self-custody.
- Custodial, where assets are held by a specialist custodian. Usually a third-party like an exchange controls the private keys to the wallet. Binance is an example of a third-party exchange with control over private keys of an individual’s account.
- Hybrid custody models, combining internal controls with external support.
- Multi-signature arrangements, requiring approval from multiple parties before transactions can be completed.
Each model offers different advantages and risks. Non-custodial models may provide greater control and flexibility, but it also places full responsibility for security and operational management on the organisation and/or individual. Custodial models can offer specialist expertise and infrastructure, but businesses should ensure they fully understand the contractual and operational implications of relying on an external provider to manage their private keys.
When selecting a custody solution, businesses should consider not only security requirements but also operational resilience, governance standards, scalability and future regulatory developments.
Legal Risks Associated with Custody Arrangements
Whilst technology plays a significant role in digital asset custody, the legal framework surrounding those arrangements is equally important.
Many businesses focus heavily on technical security but overlook critical questions relating to ownership, control and liability. In practice, these issues often become particularly important when disputes arise or where assets are lost, compromised or become inaccessible.
Organisations should carefully review:
- Ownership rights over digital assets.
- Contractual obligations between custody providers and customers.
- Liability provisions and limitations.
- Insolvency and asset segregation arrangements.
- Recovery procedures in the event of a security incident.
- Jurisdiction and dispute resolution provisions.
Particular consideration should be given to understanding how customer assets are held and whether they are appropriately segregated from business assets. Clear contractual documentation can help minimise uncertainty and provide greater protection if issues arise in the future.
Businesses should also consider how legal obligations interact with their wider regulatory responsibilities, particularly where client assets are involved.
Governance and Internal Controls
Effective governance is essential to reducing the operational risks associated with digital assets.
As organisations scale, informal decision-making processes can quickly become a source of vulnerability. A strong governance framework helps ensure that responsibilities are clearly defined, risks are monitored and appropriate oversight is maintained.
Businesses should establish clear policies governing:
- Asset transfers and approvals.
- Authority levels and delegated responsibilities.
- Wallet creation and management.
- Incident response procedures.
- Access controls and permissions.
- Third-party provider oversight.
Governance arrangements should not be viewed solely as a compliance exercise. They play a crucial role in protecting assets, preventing internal errors and providing stakeholders with confidence that risks are being appropriately managed.
Regular reviews of governance structures can help ensure controls remain effective as technology, regulatory expectations and business operations evolve.
Cybersecurity and Asset Protection Measures
Cybersecurity remains one of the most significant risks facing businesses operating within the digital asset sector.
Threat actors continue to target digital asset platforms, exchanges, custodians and fintech businesses due to the potentially high value of assets being held. Security incidents can lead not only to financial loss but also substantial reputational damage and regulatory scrutiny.
An effective cybersecurity strategy should combine technology, processes and employee awareness.
Key measures often include:
- Multi-factor authentication.
- Encryption of sensitive information.
- Secure key management procedures.
- Regular penetration testing.
- Network monitoring and threat detection.
- Employee cybersecurity training.
- Business continuity and disaster recovery planning.
Technology alone is rarely sufficient. Many security incidents originate from human error, inadequate processes or weaknesses within third-party supply chains. A comprehensive security programme should therefore consider the broader operational environment rather than focusing solely on technical controls.
Businesses should also regularly test their incident response capabilities to ensure they can react effectively in the event of a cyberattack or security breach.
Developing a Robust Digital Asset Risk Framework
A successful digital asset strategy requires more than secure technology and strong governance. Businesses should adopt a comprehensive risk framework that identifies, assesses and manages risks on an ongoing basis.
Risk management should be embedded throughout the organisation and supported by regular review at both operational and senior management level.
Areas commonly covered by a digital asset risk framework include:
- Operational risk management.
- Custody and safeguarding arrangements.
- Cybersecurity and information security.
- Regulatory and legal compliance.
- Third-party and supplier risk.
- Business continuity planning.
- Financial crime and fraud prevention.
The framework should be proportionate to the nature, scale and complexity of the business. As digital asset markets continue to evolve, organisations should regularly reassess their risk profile and ensure controls keep pace with emerging threats.
Importantly, risk management should not be seen as an obstacle to innovation. Businesses that implement robust governance and control frameworks are often better positioned to attract investors, establish strategic partnerships and support sustainable growth.
Building Confidence in a Rapidly Evolving Market
Digital assets continue to create significant opportunities for businesses across the financial services and technology sectors. However, the increasing value of these assets, coupled with evolving regulatory expectations and cybersecurity threats, means that effective risk management has never been more important.
By implementing appropriate custody arrangements, strengthening governance structures and adopting a proactive approach to cybersecurity and operational risk, organisations can better protect their assets while positioning themselves for long-term success.
At Herrington Carmichael, our Financial Services and Commercial teams advise fintechs, investment firms, digital asset businesses and emerging technology companies on governance, risk management, commercial arrangements and regulatory considerations. If your organisation is reviewing its digital asset strategy or custody arrangements, our team can help ensure your legal and operational framework remains fit for purpose in a rapidly developing market. Contact us now to get it touch with a member of our team.



