← Institute Insights
Decision framework · Education · 11 JULY 2026 · 3 MIN READ

Four Institutional Custody Models Through the Agility-Cost-Security Lens

Sub-custody, licensed platform, hybrid, or fully in-house? A sharper view of how the four institutional custody models differ on agility, total cost and security, and how to choose.

Every institution entering digital assets faces the same structural question: how much of the custody stack to own. The market has converged on four operating models, and the honest way to compare them is through three variables at once: agility, total cost, and security. Each model is a different position on that frontier, not a different level of maturity.

Model 1: Third-party regulated custodian (sub-custody)

Assets sit with an external regulated custodian; the institution consumes custody as a service.

Agility: very high. Total costs: low. Security: low, in the specific sense of control over architecture, not the custodian's competence.

This is the fastest route to market and the cheapest to stand up. The trade is control: the institution inherits the custodian's architecture, policies, asset coverage and incident response, and has the least ability to differentiate or adapt. Counterparty and concentration risk sit outside the institution's perimeter.

Model 2: Licensed platform deployment

The institution deploys licensed custody technology, running the platform without building it.

Agility: high. Total costs: medium. Security: medium.

Balanced but not cheap. Stronger control than sub-custody: keys and policies can sit inside the institution's perimeter, workflows can be shaped to the business, and the platform vendor carries the engineering depth. The institution takes on real operational responsibility without the full burden of building from scratch.

Model 3: Hybrid front-bank / back-specialist

The institution owns the client relationship and front-end; a specialist runs the custody back-end under a shared-responsibility model.

Agility: medium. Total costs: high. Security: high.

Shared responsibility creates balance, with each party doing what it is best at, but it needs strong governance. The interface between front-bank and back-specialist is where this model succeeds or fails: unclear responsibility boundaries, undefined incident ownership or mismatched SLAs turn a sound structure into a risk multiplier.

Model 4: Fully in-house bank custody

The institution builds and operates the full custody stack: infrastructure, key management, operations, compliance.

Agility: low. Total costs: very high. Security: very high.

Maximum control and the highest ceiling on security, but slowest to launch and most expensive to run. This model demands permanent senior security engineering capacity, not a one-off build budget. For institutions with the scale and mandate to justify it, it is the strongest strategic position. For everyone else it is an aspiration that arrives too late.

Reading the spectrum honestly

As institutions move from Model 1 toward Model 4, control and security potential rise sharply, but so do cost, complexity and execution burden. Three implications follow:

  1. There is no universally right model. The right answer is the one aligned with the institution's scale, regulatory obligations and control appetite. A family office and a systemically important bank should not land in the same place.
  2. The models are positions, not stages. Institutions do migrate, typically from externalized toward internalized as volumes and strategic commitment grow, but each migration is a project with its own risks, not an automatic graduation.
  3. The decision is reversible only at a price. Re-platforming custody is expensive in every model. The cheapest migration is the one you designed for on day one, which is why the model choice deserves rigorous analysis before the first vendor conversation.

Choosing deliberately

The model question cannot be answered in the abstract: it depends on your asset mix, your client promises, your regulatory perimeter and your internal capabilities. Our Advisory Program exists to answer it with evidence. It is a four-to-six-week fixed-scope engagement that maps your organisation, evaluates the models against your actual constraints, and delivers The Vault Blueprint: a target architecture with alternatives at every major decision, independently validated for security and risk by our partner Halborn.

The Vault Advisory Program

Turn the thinking into a plan for your business

Our advisory practice produces The Vault Blueprint: an infrastructure plan built around your specific business, delivered in partnership with Halborn as independent validator.

Talk to an expert

Ready to take control of your digital asset operations?