← Institute Insights
Deep dive · Research · 9 JULY 2026 · 3 MIN READ

What a Robust Digital Asset Custody Set-Up Looks Like

A reference architecture for institutional-grade digital asset custody: five layers, from access channels to settlement, wrapped in governance and cross-cutting security controls.

Institutions evaluating custody solutions often compare feature lists. A more useful exercise is to compare architectures, because institutional-grade custody is not a product feature. It is a system with a recognisable shape. This article describes that shape: an illustrative reference architecture for institutional digital asset custody, layer by layer.

The frame: governance above, controls below

Two horizontal bands frame everything. On top sits governance, risk and oversight: the operating model and roles, policies and the approval matrix, regulatory compliance, audit trail and reporting, and third-party risk management. Below runs a band of cross-cutting security and resilience controls: IAM/PAM and segregation of duties, 24/7 SOC and SIEM monitoring, on-chain monitoring and anomaly detection, incident response with kill-switch and containment, backup, disaster recovery and business continuity, and pen-testing, code review and change management.

The placement is the point. Governance is not a document that sits beside the infrastructure; it is the layer that shapes it. And the security controls are not attached to one component; they cut across all of them.

Layer 1: Business and access channels

Clients and institutional users, front office and treasury, operations and back office, APIs, OMS and external applications. This layer defines who can ask the custody system to do anything at all, and it is where identity, entitlements and channel security begin.

Layer 2: Custody control plane

Wallet orchestration, the policy engine, transaction workflow, dual and multi-approval controls. This is the brain of the system: every transaction passes through policy evaluation and approval routing before any cryptography happens. In a robust set-up, the policy engine enforces what the governance layer decides. The two are the same rules, expressed once on paper and once in code.

Layer 3: Cryptographic trust layer

The MPC signing quorum, HSM root of trust, key shards and secure storage, key rotation and recovery procedures. This layer holds the core principle of the whole architecture: control of assets equals control of keys. Its design goal is equally clear: no single point of compromise. No single machine, person or site whose failure or corruption moves assets.

Layer 4: Wallet and asset storage tiers

Three tiers with controlled flows between them: a hot wallet with limited liquidity for rapid settlement; a warm wallet holding controlled operational liquidity; and a cold vault for deep storage with the highest protection. Assets sweep down and top up between tiers under policy, not ad hoc. The tiering is a liquidity risk decision expressed in infrastructure.

Layer 5: Connectivity and settlement

Blockchain nodes and RPC, smart contracts and tokenization rails, exchanges, counterparties and banks, bridges and external protocols. This is the outward-facing layer and a major part of the attack surface. Node strategy, counterparty connectivity and bridge exposure deserve the same scrutiny as key management, because in practice this is where many incidents start.

The design objectives that tie it together

Across all five layers, a robust set-up pursues five objectives simultaneously: security of key material; policy-enforced transaction control; operational resilience; traceability and auditability; and real-time detection and response. Technology, governance and operations must align. An architecture that scores well on one objective by sacrificing the others is not robust; it is lopsided.

Using the reference honestly

A reference architecture is a benchmark, not a template. Real institutions differ in asset mix, regulatory perimeter, volumes and team shape. So the right question is not "do we have all the boxes?" but "where does our current state deviate from this shape, and is each deviation a decision or an accident?"

That gap analysis is exactly what our Advisory Program produces. Over four to six weeks we map your current architecture against your actual requirements and deliver The Vault Blueprint: deployment diagram, specifications, current-to-target mapping and a phased roadmap, with a gap and risk register compiled by our partner Halborn as independent validation.

The Vault Advisory Program

Turn the thinking into a plan for your business

Our advisory practice produces The Vault Blueprint: an infrastructure plan built around your specific business, delivered in partnership with Halborn as independent validator.

Talk to an expert

Ready to take control of your digital asset operations?