Firms making genuine progress on integrating digital asset custody and settlement are those that treat digital assets as an extension of their standard operating model, not a separate build.

Institutions introducing digital asset workflows into existing systems face a variety of friction points. Most digital asset infrastructure was not built to sit inside a regulated institution. Running multi-chain custody and orchestration in-house is resource-intensive and diverts institutions from their core business.

Every capability from custody to settlement to tokenisation requires its own procurement and integration. “What institutions need is infrastructure that meets their governance requirements from the outset, deploys within their own environment and connects those capabilities through a single integration,” says Julian Sawyer, CEO of Zodia Solutions.

Traditional post-trade infrastructure assumes a single asset, a single venue and defined settlement windows. For digital assets, books don’t reconcile against chains that run 24/7 with reorganisations and native yield moving the numbers; funding sits trapped on venues to keep trading live; and the segregation of duties every auditor asks about doesn’t map onto a hot wallet.

“You can’t patch these issues with middleware,” says Giorgia Pellizzari, chief product officer and head of custody at Hex Trust. “They live in the custody rail or they don’t get solved.”

Institutions need custody, trading, settlement, financing, approvals and reporting to connect to their existing governance model, says Adam Sporn, head of prime brokerage and institutional sales at BitGo.

Technology integration into existing operating models is a major challenge. Most financial institutions have mature processes for risk, compliance, treasury, operations and custody that were designed around traditional market infrastructure. “Institutions need governance around who can initiate transactions, approve movements, recover access and manage cryptographic credentials,” adds Sabih Behzad, global head of digital assets & currencies transformation at Deutsche Bank. “Regulatory and control requirements are significantly higher than in many crypto-native environments.”

Separate rooms for trading and custody

Off-venue settlement is one of the most important developments in institutional digital assets. Traditional financial markets evolved to separate trading, custody and settlement because concentration of risk in a single venue is undesirable and institutions are increasingly asking for the same model in digital assets.

“Off-venue settlement allows firms to access liquidity on trading venues while keeping assets with independent custodians, significantly reducing exchange counterparty risk,” says Behzad. “Ultimately, it is helping digital asset markets mature from an exchange-centric model toward a market structure that more closely resembles traditional capital markets.”

Off-exchange settlement can be an important step in bringing more traditional market discipline to digital asset trading, agrees Sporn, noting that in traditional finance, asset managers generally do not expect to prefund every venue or leave assets at multiple execution venues simply to access liquidity.

For institutions, the objective is to access liquidity while maintaining custody controls and managing counterparty exposure. “Off-exchange settlement can support that objective by reducing the need to move assets onto trading venues before execution,” he says, adding that BitGo has focused on building a robust off-exchange settlement product based on its view that institutions want to mitigate exposure by holding assets at a qualified custodian while accessing liquidity from exchanges.

That is important for risk management, capital efficiency and operational control.

The fittings auditors already inspect

When asked what governance and control features managers expect to be built into the infrastructure, Pellizzari refers to controls their auditor already asks about, expressed natively on-chain. These include:

  • Transaction policies — maker-checker on every transaction (signed on hardware), whitelists, velocity limits, per-counterparty caps
  • Independent key recovery — smooth asset recovery via third party services to eliminate dependency on one centralised custodian counterparty
  • Entity segregation — one platform, multiple funds, no commingling
  • Regulator-grade reporting — SOC 2, ISAE 3402 and licences in the jurisdictions the manager operates in

Network managers expect the same control architecture they run across every other asset class. That means policy enforcement, segregation of duties, audit trails and risk and compliance tooling need to be part of the platform’s core design — not bolted on afterwards, says Sawyer. “This is what determines whether the platform can actually be deployed within an institution’s own infrastructure, under its own governance and data sovereignty requirements, or whether it demands workarounds that introduce new operational risk,” he says.

Configurability is another expectation. Institutions do not run identical control frameworks and the infrastructure has to accommodate that. A fixed governance model may work for a crypto-native firm but it creates friction the moment a regulated institution needs to map it to its own workflows or audit requirements.

Managers’ control expectations include role-based permissions, multi-party approvals, transaction limits, address allowlisting, segregation of duties, audit trails and policy enforcement that can be tailored to the institution’s internal requirements. “They also need visibility across functions,” adds Sporn. “Compliance, operations, risk and finance teams need a clear view of custody, trading, settlement, financing and reporting activity. Infrastructure should reduce manual processes and reconciliation wherever possible.”

One extension or four new builds

As institutions look to expand into staking, lending or tokenisation, a single integrated infrastructure layer prevents the operational fragmentation that typically comes with adding new asset classes.

The biggest risk lies in building separate infrastructure stacks for each new use case — a particular challenge within banks where those use cases are siloed within individual businesses.

“Custody, staking, tokenisation, lending, collateral management and settlement share many of the same foundational capabilities: wallets, key management, identity, connectivity, compliance, reporting, risk controls and asset servicing,” observes Behzad. “A unified platform allows institutions to build these capabilities once and reuse them across multiple products and asset classes while allowing clients to manage tokenised cash, tokenised securities, digital assets, staking positions and collateral from a single operational environment.”

Pellizzari assesses the impact of fragmentation in stark terms, observing that every activity on its own system doubles the operational surface and by scaling with different wallets, keys, reconciliations and auditors, institutions will find themselves running four post-trade stacks inside a year.

Each new capability can create another operational silo if it is introduced through a separate provider, system and control framework and this is a more complex challenge in digital assets because markets develop quickly. “A consistent framework matters,” says Sporn. “It can reduce manual processes, improve oversight and help institutions apply governance standards across a broader range of digital asset activity. The objective is not simply access to new products — it is controlled, scalable access within an operating model that institutions can support.”

Fragmentation is rarely the focus at the pilot stage. However, once institutions launch custody and start planning staking, the operational burden becomes visible in that new vendor assessments, integrations and legal agreements all need to be repeated for the next capability.

“Wallets and keys are only a fraction of a custody business,” says Sawyer. “The bulk of it — onboarding, multi-tenant structures, transaction governance, compliance, audit, reporting and connectivity — is the connective tissue. That is where projects stall and where regulators focus.”

Custody alone rarely generates the returns that justify the investment, so the revenue case depends on activating adjacent services in an operationally straightforward way. Institutions on fragmented stacks will spend most of their time managing complexity rather than building the business. “Built right, custody stops being a cost centre and becomes the foundation you build revenue on,” suggests Sawyer. “Staking, tokenised assets, collateral and new chains get added by configuration, not a fresh integration each time,” he says, adding that many institutions have completed pilots but not yet moved to production.

Pilots test the fittings, not the foundation

The challenge here is that while a pilot can run on limited resources, production requires the platform to sit inside a governance framework, meet data sovereignty requirements, satisfy compliance functions and operate under regulatory oversight. Infrastructure built for a pilot is often not designed to carry that weight. “Building the full stack yourself is typically a multi-year engineering programme that stalls under security review,” adds Sawyer. “That is why the institutions that made the transition successfully worked with providers who understood what a live regulated operation actually requires and brought that operational experience into the deployment itself.”

Behzad says clear business ownership and accountability are essential and that institutions require production-grade governance, risk, legal and compliance frameworks before scaling volumes. He suggests shifting the focus from proving blockchain technology works to proving the operating model works. “Integration with core systems (treasury, payments, custody, accounting, risk, reporting and client platforms) is crucial. A successful transition typically starts with a targeted use case where the economic benefits are clear, such as institutional custody, tokenised deposits, collateral mobility or settlement optimisation. Most importantly, institutions need a roadmap that treats digital assets as strategic infrastructure rather than an isolated innovation project.”

According to Pellizzari, pilots fail on features while production fails on ownership. Referring to an operating model rather than simply a procurement change, she recommends having a licensed custodian in every operating jurisdiction; integration beyond APIs into fund accounting, trade surveillance and the risk engine; a genuine maker-checker with second-line risk approvers (not IT proxies); and tested business continuity planning.

“Pilots often show that technology works — production requires showing that the full operating model works,” concludes Sporn. “For institutions, that means infrastructure designed to be resilient, controlled, auditable and able to scale with the business.”