Treasury’s Role in Digital Asset Custody: A 2026 Guide

Professional reviewing digital asset custody policy documents

Treasury owns the digital asset custody decision. Not IT, not legal, not the CFO’s office acting alone. The treasury function sets the custody strategy, selects the model that fits the organization’s risk tolerance and regulatory environment, and maintains the governance controls that keep auditors and regulators satisfied. For most corporate treasury functions, qualified custodians are the default starting point: they provide legal segregation, regulatory oversight, and insurance coverage that no internal arrangement can replicate without significant operational investment. Treasury’s job is to make that choice deliberately, document it thoroughly, and build the control environment around it.

The core responsibilities break down like this:

  • Custody model selection: Evaluate qualified custodians, self-custody, and hybrid arrangements against jurisdiction, liquidity needs, and counterparty risk.
  • Governance and controls: Establish approval matrices, key management rules, and segregation of duties across the custody lifecycle.
  • Risk oversight: Monitor custodian attestation reports, issuer reserve composition, and wallet inventories on a defined schedule.
  • System integration: Connect custody data into the treasury management system (TMS) for real-time exposure visibility alongside traditional assets.
  • Compliance readiness: Align controls with recognized standards such as NIST SP 800-57 for key lifecycles and FIPS 140-3 for cryptographic modules.
  • Incident response: Maintain tested recovery procedures and documented escalation paths before an incident occurs.

Pro Tip: Before selecting any custody solution, map your organization’s liquidity requirements first. A custody model that locks assets in cold storage for 48 hours may be fine for strategic reserves but unworkable for daily settlement flows.


How treasury evaluates and selects custody models

The custody architecture decision is, at its core, a legal structure decision, not a technology one. Treasury professionals who treat it primarily as a vendor selection miss the point. The question is whether your organization’s assets are genuinely segregated from the custodian’s balance sheet, and whether that segregation survives the custodian’s insolvency.

Treasury officer selecting custody model

Qualified custodians are regulated trust companies or bank subsidiaries that hold digital assets under fiduciary standards. They provide SOC 2 Type II attestation, crime and cyber insurance, and clearly titled segregated accounts. The SEC’s rescission of SAB 121 removed the on-balance-sheet liability that had kept banks out of crypto custody, which has widened the pool of institutions willing to offer these services. For most corporate treasury functions, a qualified custodian is the right starting point precisely because it is the only model that combines institutional-grade controls, insurance, regulatory oversight, and legal segregation in a single arrangement a bank or auditor will recognize.

Infographic illustrating digital asset custody process steps

Self-custody gives treasury direct control of private keys, with no counterparty that can freeze assets or fail. The tradeoff is that every operational risk sits entirely on internal governance. Key ceremony procedures, signing role segregation, secure key storage, tested recovery processes, and audit trails all become internal responsibilities. Getting any one of them wrong can result in permanent asset loss.

Hybrid custody is increasingly the preferred model among treasury professionals. Bulk reserves sit with a qualified custodian for security and audit readiness; working balances move to a tightly governed self-custody tier for operational liquidity. This approach balances counterparty risk against the need for fast settlement.

Treasury’s selection criteria should cover:

  • Legal segregation documented in the custody agreement, not just asserted in marketing materials.
  • Bankruptcy remoteness, meaning customer assets are not available to the custodian’s creditors.
  • Regulatory oversight by the OCC, a state banking authority, or a recognized foreign equivalent.
  • SOC 2 Type II reports, financial audits, and proof-of-reserves attestation.
  • Insurance coverage with clearly defined scope, limits, and exclusions.
  • Jurisdiction compatibility with the organization’s operating footprint and applicable law.

Governance frameworks and the control environment treasury must build

Governance in digital asset custody is not a separate workstream from traditional treasury governance. It is an extension of it, applied to an asset class with different technical characteristics and higher operational risk if controls fail.

Treasury team discussing governance frameworks

Treasury’s governance responsibilities center on three areas. First, policy ownership: treasury writes and maintains the board-approved custody policy that defines permissible assets, wallet tiers, transaction limits, approver roles, and how policy changes are documented. Second, control design: treasury enforces segregation of duties, multi-signature wallet requirements, and transaction approval matrices that prevent any single individual from initiating and approving a transfer. Third, audit readiness: treasury maintains the documentation trail that auditors and regulators need, including SOC 2 attestation reports from custodians, periodic internal audits, and evidence of ongoing monitoring.

Multi-signature (multi-sig) and multi-party computation (MPC) controls are the technical mechanisms that enforce dual control at the transaction level. Multi-sig requires multiple on-chain signers to authorize a transfer; MPC distributes key material across participants so no single party ever holds a complete private key. Neither is universally superior. The right choice depends on the threat model, the asset types held, and what the organization’s auditors expect to see.

Treasury should also align its control environment with recognized security standards such as NIST SP 800-57 for cryptographic key lifecycle management and FIPS 140-3 for the hardware security modules used in key storage. These standards give auditors a reference point and give treasury a structured framework for evaluating whether controls are adequate.

Key governance controls to implement:

  • Board-approved custody policy with defined review cadence (at minimum annual).
  • Approval matrices specifying transaction limits by wallet tier, asset type, and counterparty.
  • Segregation of duties between transaction initiators, approvers, and reconcilers.
  • Multi-sig or MPC controls with signer independence across geographic or legal entity boundaries.
  • Periodic SOC 2 Type II review of custodian controls.
  • Regular internal audits with documented findings and remediation tracking.

Risk management in treasury digital asset custody

Risk management for digital assets follows the same four-step process treasury applies to any asset class: identify, assess, mitigate, and report. The difference is the risk categories themselves, several of which have no direct analog in traditional treasury.

Custody risk is the risk that the custodian fails, misappropriates assets, or cannot fulfill a transfer instruction. Treasury mitigates this through custodian due diligence, legal segregation requirements, and concentration limits at the custodian level. Issuer risk is distinct and often underweighted. A qualified custodian holding a stablecoin on your behalf does not protect you if the stablecoin issuer’s reserves are insufficient. Issuer diligence must cover reserve composition, attestation frequency, direct redemption rights, and regulatory status independently of custodian selection.

Liquidity risk arises when assets held in cold storage or with a custodian cannot be accessed quickly enough to meet operational needs. Treasury addresses this through wallet tiering: hot wallets for immediate operational flows, warm wallets for regular settlements within policy caps, and cold vaults for long-term reserves. Concentration risk applies at both the custodian level and the issuer level. Policy should set explicit limits on how much of the digital asset portfolio sits with any single custodian or in any single issuer’s token.

Ongoing monitoring is where many treasury functions fall short. Best practice requires regular review of custodian attestation reports, a complete and accurate inventory of wallet addresses, and periodic reconciliation of on-chain balances against internal records. Treasury should also review the risk frameworks that apply to its specific digital asset mix, since stablecoin risk, Bitcoin reserve risk, and tokenized asset risk each carry different monitoring requirements.

Risk reporting to management and the board should cover:

  • Custodian exposure by institution and asset type.
  • Issuer concentration and attestation status.
  • Liquidity coverage across wallet tiers.
  • Open audit findings and remediation status.
  • Incident log with resolution timelines.

How treasury integrates digital asset custody with management systems

Digital assets operate 24 hours a day, seven days a week. Traditional treasury management systems were not built for that. The gap between continuous on-chain activity and batch-processing TMS infrastructure is where control failures tend to accumulate, particularly when treasury teams rely on manual spreadsheets to bridge the two.

The solution is automated approval workflows and real-time data integration that bring digital asset custody positions into the same normalized view as traditional bank and treasury data. A unified TMS that consolidates digital and traditional assets gives treasury real-time exposure visibility, supports concentration limit monitoring, and makes counterparty risk management a continuous process rather than a monthly exercise.

Integration requirements for treasury teams include:

  • Real-time balance feeds from custodians and self-custody wallets into the TMS.
  • Automated reconciliation between on-chain transaction data and internal general ledger entries.
  • Policy-based approval workflows that enforce transaction limits and dual control without manual intervention.
  • Exception alerting for transactions that breach velocity limits, allowlists, or approval thresholds.
  • Audit trail generation that links every on-chain transaction to its internal approval record and GL mapping.

The reconciliation requirement deserves particular attention. Lack of tie-out between on-chain data and internal books is one of the most common causes of audit failure in digital asset treasury. A subledger solution that reconciles on-chain activity with the general ledger and approval workflows on at least a weekly basis is the minimum standard; daily reconciliation is preferable for active trading or settlement operations.

Pro Tip: When evaluating TMS vendors for digital asset integration, ask specifically whether their reconciliation engine handles on-chain transaction data natively or requires a manual export step. The manual export step is where errors and delays concentrate.


Cybersecurity and operational controls treasury must enforce

Cybersecurity in digital asset custody is not the information security team’s problem alone. Treasury owns the operational controls that determine whether a cyberattack results in asset loss or a contained incident. The two functions need to work from a shared control framework.

The control stack treasury should enforce covers multiple layers. Device hardening for any machine used in key ceremonies or transaction signing: remove unnecessary network radios, restrict installed software, and use allowlists to limit which applications can execute. Velocity limits and time locks on warm and hot wallets cap the damage from a compromised credential. Immutable logs of every approval and signing event create the evidence base for SOC reporting and forensic investigation if an incident occurs.

Key operational controls:

  • Hardened, dedicated devices for signing operations with no shared use for general computing.
  • Allowlists restricting transaction destinations to pre-approved wallet addresses.
  • Velocity limits by wallet tier, asset type, and time window.
  • Dual control requirements for all transfers above defined thresholds.
  • Immutable audit logs aligned to SOC reporting expectations for design and operating effectiveness.
  • Continuous monitoring with automated alerts for anomalous transaction patterns.
  • Tested backup and recovery procedures for key material, with documented recovery time objectives.

The 24/7 nature of digital asset operations means monitoring cannot be a business-hours function. Treasury should define escalation paths and on-call responsibilities for after-hours alerts, and test those paths at least quarterly. An incident response plan that has never been rehearsed is not a plan.


Best practices and certification frameworks for treasury custody governance

The governance gap in enterprise digital asset operations is well-documented. Organizations that hold digital assets without board-approved policies, documented controls, and regular audits face material audit and regulatory risk, regardless of how good their custodian is. Certification frameworks exist precisely to close that gap.

The Digital Asset Readiness Evaluation (DARE), offered through Wush, provides a structured certification framework that covers custody governance, regulatory compliance, risk management, legal controls, and operational procedures. For treasury teams, DARE certification serves two practical purposes: it gives internal stakeholders a structured path to build governance maturity, and it gives external auditors and regulators a recognized credential that demonstrates the organization has assessed and documented its digital asset controls against an independent standard.

Board-approved custody policies should align with the organization’s risk appetite and jurisdiction, and should be reviewed at least annually or when material regulatory changes occur. The OCC’s March 2025 guidance (Interpretive Letter 1183) rescinding the supervisory non-objection requirement for crypto custody is one example of a regulatory shift that should trigger a policy review.

Treasury best practices for governance and certification readiness:

  • Maintain a board-approved custody policy with documented review history.
  • Conduct annual governance assessments against recognized frameworks.
  • Pursue DARE certification to demonstrate governance maturity to auditors and regulators.
  • Document all control design decisions with rationale tied to specific risk categories.
  • Track regulatory developments in operating jurisdictions and update policies accordingly.
  • Build certification readiness into the annual treasury planning cycle, not as a one-time project.

Pro Tip: Treat DARE certification as an ongoing governance discipline, not a one-time credential. The annual renewal process is where the real value accumulates, because it forces a structured review of whether controls have kept pace with regulatory and operational changes.


Treasury policies and procedures specific to digital assets

A digital asset treasury policy is not a modified version of the cash management policy. It needs to address asset categories, wallet architecture, key management, and counterparty rules that have no equivalent in traditional treasury documentation.

The policy should define permissible asset types (Bitcoin, Ether, regulated stablecoins, tokenized securities) and explicitly list prohibited activities. It should specify wallet tiers, the controls that apply to each tier, and the approval requirements for moving assets between tiers. Transaction limits should be set by wallet, role, asset type, and counterparty, with step-up approval requirements for high-value or high-risk transactions.

Key management procedures deserve their own documented section. This covers key generation ceremonies, storage requirements (hardware security modules meeting FIPS 140-3), backup procedures, rotation schedules, and the process for revoking access when personnel change. Many organizations treat key management as an IT procedure. Treasury should own the policy framework even when IT executes the technical steps.

Procedures should also address the compliance obligations that apply to digital asset transactions: sanctions screening, Travel Rule compliance for transfers above applicable thresholds, and counterparty onboarding requirements. These are not optional additions; they are baseline requirements for any organization operating in the US market under current regulatory expectations.


Liquidity management and digital asset portfolio optimization

Liquidity management for digital assets requires treasury to think in tiers. Not all digital assets are equally liquid, and the custody model affects how quickly assets can be accessed and converted.

Hot wallets hold small balances for immediate operational needs: vendor payments, on-chain settlements, and product functionality where applicable. Warm wallets hold working balances for regular settlements within defined policy caps, with quorum approval requirements and allowlist controls. Cold vaults hold strategic reserves and long-term positions, with access requiring multi-person ceremonies and documented procedures. The allocation across tiers should reflect actual operational cash flow requirements, not a theoretical preference for security.

Concentration limits apply at the asset level as well as the custodian level. A treasury holding a large position in a single stablecoin issuer carries issuer credit risk that is independent of custody quality. Reserve transparency and attestation cadence are the primary monitoring tools for issuer-level concentration risk. Treasury should set explicit limits and review them as part of the regular risk reporting cycle.

Portfolio optimization for digital assets also means monitoring on-ramp and off-ramp efficiency. The ability to convert between digital and fiat assets quickly, at predictable cost, is a liquidity management requirement, not just an operational convenience. Treasury should document the conversion process, the counterparties involved, and the expected settlement timelines for each asset type held.


Accounting and reporting standards for digital assets within treasury

The accounting treatment for digital assets changed materially in 2025. FASB ASU 2023-08, effective for fiscal years beginning after December 15, 2024, requires in-scope crypto assets to be measured at fair value, with changes flowing through net income each period. For calendar-year companies, that treatment has been live since January 2025. The indefinite-lived intangible treatment that had discouraged corporate digital asset holdings is gone.

Treasury’s accounting responsibilities now include maintaining fair value measurements for each digital asset position, tracking unrealized gains and losses through the income statement, and providing the enhanced disclosures ASU 2023-08 requires. The digital asset accounting standards that apply to your specific holdings depend on asset type; not all digital assets fall within the scope of ASU 2023-08, and treasury should confirm the classification of each asset with the accounting team.

Reporting infrastructure needs to support this treatment. A subledger solution that reconciles on-chain activity with the general ledger provides the data foundation. The subledger should capture acquisition cost, fair value at each reporting date, realized and unrealized gains and losses, and the custody arrangement under which each asset is held. Digital asset disclosures in financial statements now carry more scrutiny from auditors and investors than they did two years ago, and the quality of the underlying data determines whether those disclosures hold up.


Incident response planning and disaster recovery in digital asset custody

An incident response plan for digital asset custody covers two distinct scenarios: a cybersecurity incident (unauthorized access, key compromise, fraudulent transaction) and an operational failure (custodian outage, key loss, system failure). Both require documented procedures, defined roles, and tested recovery processes before the incident occurs.

For cybersecurity incidents, the plan should define the detection triggers (anomalous transaction alerts, failed authentication attempts, custodian notifications), the immediate containment steps (wallet freezes, key rotation, custodian escalation), the investigation process, and the communication requirements to management, regulators, and affected counterparties. The operational risk framework should specify who has authority to freeze wallet activity and under what conditions.

Disaster recovery for key material is the scenario most treasury functions underinvest in. If the primary key storage location is unavailable, how does treasury access backup key material? Where is it stored, who has access, and what is the documented recovery procedure? These questions need answers before an incident, not during one. Recovery procedures should be tested at least annually, with results documented and reviewed by treasury leadership.

Business continuity planning should also address custodian failure. If the primary qualified custodian becomes unavailable, what is the timeline for accessing assets through a secondary arrangement, and what operational activities can continue in the interim? Treasury should maintain documented contingency arrangements and review them as part of the annual custody policy review cycle.


Key Takeaways

Treasury’s role in digital asset custody requires governance, risk oversight, and operational controls working together as a single integrated function, not three separate workstreams.

Point Details
Qualified custodians as default Legal segregation, regulatory oversight, and insurance make qualified custodians the right starting point for most corporate treasury functions.
Hybrid custody balances risk and liquidity Bulk reserves with a qualified custodian and working balances in governed self-custody addresses both security and operational flexibility.
Issuer risk is independent of custody risk Diligence on reserve composition and attestation cadence must cover the stablecoin issuer separately from the custodian holding the asset.
Fair value accounting is now required per FASB ASU 2023-08, mandating in-scope crypto assets be measured at fair value through net income for calendar-year companies.
DARE certification closes the governance gap Wush’s Digital Asset Readiness Evaluation provides a structured framework for demonstrating custody governance maturity to auditors and regulators.

Dare

Treasury teams that take digital asset custody seriously need more than good intentions. They need a documented governance framework, tested controls, and credentials that auditors and regulators recognize. Wush’s DARE certification gives treasury professionals a structured path to build and demonstrate that governance maturity, covering custody, compliance, risk management, and operational controls in a single annual program. If your organization holds digital assets and your custody policy predates 2025, the time to close that gap is now.

Get DARE certified

Validate your competency in enterprise digital asset governance with the DARE certification.

View certification
DARE - Digital Asset Readiness Evaluation logo

The global standard for evaluating and certifying enterprise digital asset readiness and governance.

PARTNERS

DARE is developed by Wush.co and co-issued with the Asia Blockchain Association


© 2026 DARE by Wush.co. All rights reserved.
Follow Us