Choosing a digital asset custodian is one of the highest-stakes decisions a UHNW investor or family office will make. The wrong choice does not merely result in poor service — it results in permanent, irrecoverable loss. The history of digital asset custody is littered with institutions that sounded credible, held proper licences, used the right language, and then failed catastrophically. This framework gives institutional clients the tools to evaluate custodians with the rigour the decision demands.
Why Standard Due Diligence Is Insufficient
Due diligence frameworks developed for traditional financial counterparties — examining balance sheets, regulatory status, professional indemnity insurance, and key-person risk — are necessary but materially insufficient when applied to digital asset custodians. Traditional financial custody involves a custodian holding a legal claim to assets on your behalf, with a regulatory and legal enforcement apparatus behind it. Digital asset custody, at its core, involves the control of cryptographic keys. When those keys are lost or compromised, no court order, no insurance policy, and no regulatory intervention recovers the assets.
This changes the due diligence question fundamentally. You are not evaluating whether a counterparty is creditworthy or whether the legal system will enforce your claim. You are evaluating whether the cryptographic and operational infrastructure protecting your keys is sound — and whether it will remain sound across a range of stress scenarios that the institution may never have anticipated.
The 12 Questions
1. How are the private keys generated, stored, and accessed?
Key generation must occur in a hardware security module (HSM) or dedicated hardware wallet that never exposes the private key to an internet-connected environment. Ask for a specific answer: which hardware? What is the air-gap protocol? What happens during signing operations? A credible custodian provides a detailed, technical answer. A non-answer or marketing language is disqualifying.
2. What multi-signature architecture is in use?
Single-key custody — where one key controls the assets — is appropriate for transactional amounts only. Institutional holdings require multi-signature schemes (2-of-3, 3-of-5, or more) where multiple independent keys, held in geographically separated locations, must cooperate to authorise any transaction. Ask for the specific threshold scheme, the distribution of key custody across people and locations, and the conditions under which any single keyholder could be compelled to act alone.
3. Are client assets segregated from the custodian’s proprietary assets?
Commingling client assets with the custodian’s own holdings creates counterparty risk that institutional investors should not accept. In any insolvency proceeding, commingled assets become part of the general estate. Segregated custody keeps your assets identifiable and separate regardless of what happens to the custodian’s financial position. Ask for documentary evidence of the segregation architecture, not just an assertion that it exists.
4. What happens if the custodian fails?
This question should be asked bluntly, and the answer should be specific. Who holds the keys? Under what legal structure? What is the recovery mechanism for clients? Is there a documented business continuity and wind-down plan? The Celsius, BlockFi, and Voyager failures demonstrated that clients of commingled custodians may wait years for partial recoveries in bankruptcy proceedings. Institutional custodians serving high-net-worth clients should have documented recovery procedures that do not depend on their own solvency.
5. What insurance is in place and what does it actually cover?
Crime insurance and cold storage coverage are not the same thing. Most digital asset insurance policies cover a narrow subset of loss scenarios — typically theft by external actors — and exclude loss due to internal fraud, software vulnerabilities, or operational error. Ask for the policy schedule, the coverage limit as a percentage of assets under custody, and the named exclusions. Compare the coverage to the actual risk scenarios relevant to your holdings.
6. What is the regulatory status in each operating jurisdiction?
Regulatory licences create accountability mechanisms and compliance standards that unregulated entities are not subject to. In Australia, digital asset custodians holding assets on behalf of clients are now required to hold an AFSL under the Corporations Amendment (Digital Assets Framework) Act 2026. In Singapore, they require a Major Payment Institution licence or capital markets services licence. In the UAE, they require ADGM or VARA authorisation. Ask for specific licence numbers and verify them directly with the relevant regulator.
7. Who are the key personnel and what is their background?
Digital asset custody requires deep expertise in cryptography, operational security, and key management. Ask for the professional backgrounds of the team responsible for custody operations. Tenure matters — a new team working with unfamiliar systems presents risks that a seasoned team does not. Ask about key-person risk: what happens if the primary technical lead leaves?
8. Has the custody infrastructure been independently audited?
SOC 2 Type II reports, independent security audits, and penetration testing results are the documentary evidence that an institution’s security claims have been tested by an adversarial third party. Ask for the most recent audit report, the auditor’s credentials, and how findings were remediated. A custodian that has never had its infrastructure independently audited is asking you to trust assertions rather than evidence.
9. What is the transaction authorisation process?
How does the custodian verify that a withdrawal instruction is legitimate? How many people need to approve a transaction? What out-of-band verification is in place? The Bybit hack — in which $1.5 billion was stolen by compromising the software interface between authorised signatories and hardware devices — illustrates that the weakest point in custody infrastructure is often the authorisation layer, not the key storage itself. Multi-party authorisation with out-of-band verification is the minimum acceptable standard for institutional holdings.
10. What is the succession and estate access protocol?
If you die or become incapacitated, can your estate access the assets? Under what conditions, with what documentation, and on what timeline? A custodian that cannot provide a clear, tested answer to this question is not suitable for long-term wealth preservation. Succession access should be built into the custody architecture, not treated as an afterthought.
11. How are assets reported and reconciled?
Institutional clients require regular, auditable reporting of their holdings. Ask for sample reports, the frequency of reconciliation, and the format in which data is provided to external accountants and auditors. For family offices with complex reporting obligations, compatibility with portfolio management systems and accounting software is a practical requirement, not a luxury.
12. What is the fee structure and what conflicts of interest exist?
Custodians who earn revenue from lending client assets, staking yields, or trading fees have interests that may not align with yours. A pure custody model — where the custodian’s fee is paid for the service of safeguarding assets, and nothing else — eliminates the conflict of interest that contributed to the failures of several high-profile custodians who chose yield over safety. Understand precisely how the custodian makes money and what that incentivises.
The Verification Process
Answers to these questions are only as valuable as your ability to verify them. Request primary documentation rather than summaries: the actual policy schedule, the actual audit report, the actual licence registration. Engage an independent technical adviser to review the custody architecture documentation. Verify regulatory status directly with the relevant regulatory authority rather than relying on certificates provided by the custodian itself.
For holdings above material thresholds, an on-site assessment of custody operations — conducted by a qualified independent reviewer — provides assurance that no amount of documentation can substitute for.
Red Flags
The following responses to these questions should be treated as disqualifying: vague answers about “institutional-grade” infrastructure without specifics; refusal to provide regulatory licence numbers; insurance coverage limited to a small fraction of assets under custody; no documented succession access protocol; no independent audit history; and any arrangement where the custodian commingles client assets with its own holdings or those of other clients.
The history of digital asset custody failures has not been characterised by unsophisticated operators. It has been characterised by credible-sounding institutions that failed on precisely the dimensions that rigorous due diligence would have identified in advance.
CryptoVault provides detailed due diligence documentation to prospective institutional clients, including custody architecture specifications, audit reports, and regulatory licence details.
Request Due Diligence Package