On this page
For teams: running crypto risk like a pro
The principles above apply to individuals, but organizations face additional layers. A treasury or fund managing digital assets should treat crypto participation as an operational risk program, not just an investment decision:
- Custody policy — define what may be held on an exchange vs. a qualified custodian vs. self-custody (multi-sig), with limits per venue and per asset.
- Segregation of duties — separate initiators, approvers, and reconcilers so no single role can both move and hide funds.
- Counterparty & vendor risk — due diligence on every venue, custodian, and staking provider; monitor for changes in status.
- Limits & thresholds — per-transaction and aggregate exposure limits; escalate approvals above thresholds.
- Record-keeping for audit — every transaction, cost basis, fair-market value at event time, counterparty, and approval evidence, retained per policy.
- Valuation & reporting — mark-to-market policy, impairment rules for held assets, and regular board/committee reporting.
- Insurance & continuity — crime coverage, key-person risk, and a documented key-recovery/succession plan.
These connect to other units
Custody specifics are in the Wallets unit; vendor/venue due diligence in the Exchanges unit; and the regulatory backdrop (qualified custodians, segregation, sanctions) in the Regulation unit.