Start with the mandate and legal entity
Define the client entities, investor restrictions, jurisdictions, required assets, transaction volumes, servicing needs and target operating model. Then identify the exact provider entity that would sign the agreement. Group-level marketing is not a substitute for the licence, regulator, permissions and balance-sheet or insolvency analysis of that entity.
Institutional custody due-diligence matrix
| Workstream | Questions to resolve | Evidence to request |
|---|---|---|
| Regulatory | Which entity, licence, regulator, jurisdiction, client type and asset are in scope? | Register entry, licence or charter, legal opinion where necessary, proposed agreement |
| Asset ownership and segregation | Are assets individually segregated or omnibus, and how are entitlements recorded? | Account terms, books-and-records process, wallet structure, insolvency analysis |
| Technology | Who controls keys or key shares, policies, privileged access and recovery? | Architecture, key ceremony, access matrix, penetration testing and recovery evidence |
| Operations | How do deposits, withdrawals, approvals, exceptions and incidents work? | Operating procedures, service levels, cut-offs, escalation tree and sample audit trail |
| Insurance | Which losses, assets, locations and service providers are covered or excluded? | Policy summary, limits, exclusions, sub-limits, insurer and claims process |
| Settlement and counterparties | Where does settlement occur and which venues, banks or sub-custodians are involved? | Flow diagrams, counterparty list, finality rules and failed-settlement procedures |
| Reporting and API | Can data support reconciliation, audit, valuation, tax and treasury integration? | Sample reports, API specification, permissions, webhooks and data-export process |
| Resilience | Can the service recover from signer, cloud, vendor or blockchain failure? | BCP and disaster-recovery results, recovery objectives, backups and exit plan |
| Governance | Who approves policy changes, exceptions and material incidents? | Governance chart, role matrix, change controls and incident communications |
Operational and technology testing
Do not stop at policy documents. Walk through a normal withdrawal, an emergency withdrawal, a rejected transaction, a new asset, a compromised user, a lost signer and a provider outage. Test MPC or HSM controls in the context of the full workflow, including role separation, whitelisting, policy changes, logs, API automation and manual fallback.
Jurisdiction, cross-border and counterparty risk
A global provider may use different affiliates, banks, exchanges, validators, cloud services or sub-custodians across markets. Map where assets, key material, contractual rights, operational staff and data are located. Review sanctions, data-transfer, insolvency, enforcement and regulatory-notification implications for every material jurisdiction.
RFP checklist and scoring discipline
- Issue the same factual questions and definitions to every provider.
- Separate mandatory requirements from scored preferences.
- Require “not available” or “not applicable” instead of unsupported yes/no answers.
- Score the contracting entity and proposed service, not the provider brand in general.
- Record evidence, owner, review date, open issue and remediation commitment.
- Run legal, risk, compliance, operations, technology and business approvals independently.
- Define exit, portability and transition requirements before contract signature.
Use the existing custody provider RFP template to structure comparable responses.
Frequently asked questions
What is custody provider due diligence?
It is the evidence-based review of a provider's legal entity, regulation, asset structure, security, operations, counterparties, reporting, resilience and contract against an institution's mandate.
How should institutions compare regulation, custody, settlement and service?
Use one matrix for every provider, identify the exact contracting entity, verify primary evidence, map the end-to-end asset and settlement flow, and score exceptions separately from confirmed controls.
How should a large fund evaluate global custody providers?
Start with fund and investor jurisdictions, then test entity permissions, sub-custody, segregation, cross-border enforceability, reporting, service coverage, resilience and exit options for the required assets.
Who should join diligence calls?
Legal, compliance, risk, information security, operations, finance, tax, technology and the accountable business owner should participate according to the mandate.
What is a common diligence mistake?
A common mistake is treating a group-level licence, certification or insurance claim as if it automatically applies to the proposed legal entity, product, asset and jurisdiction.
When is due diligence complete?
It is complete when material evidence is reviewed, exceptions have owners and approvals, residual risk is accepted, and the institution can execute both normal operations and an orderly exit.
What belongs on a stronger custody due diligence path?
A stronger custody provider due diligence process links governance, operations, controls, reporting, servicing, and escalation paths back to the actual use case. That usually creates a more useful short list than broad brand comparisons.
This page should also connect directly to provider comparison, qualified custodian research, digital asset custody, and Europe specific selection pages so the diligence process becomes part of one consistent buyer journey.
Last updated 9 August 2026. This framework supports institutional review but is not legal, regulatory or investment advice.
Continue the institutional custody research path
Move from broad topic research into provider comparison, due diligence, and contact so the page does not end as a dead end.
Need to contact a provider?
Use custodyproviders.com to narrow the field and route a more qualified provider conversation.