Governance is the written answer to four questions: who decides, who executes, who reviews, and what evidence each step leaves behind. Most family offices answer the first and improvise the other three. My view is that the crypto version fails in one place: a signed transaction settles on its own, so every control a bank would apply after an instruction has to sit in front of the signature instead.
Part of our guide: Family Office.
The short version
- A single family office sits outside the Advisers Act by design. 17 CFR 275.202(a)(11)(G)-1 excludes it from the adviser definition, so no examiner will ever ask to see these controls. The family imposes them or nobody does.
- Split approval from signing. The federal internal control standard separates authority, custody, and accounting. On-chain those three collapse into one person at one keyboard unless a written policy pries them apart.
- The address allowlist has the best return of any control here. It works before the signature, which is the only place an on-chain control can work.
- Write the threshold that triggers a second approver, then re-set it on a fixed date, because a limit stated only in dollars loosens as the price rises.
- Name the substitute before the key person is unreachable, and define unreachable in days rather than leaving it to the room.
The office nobody examines
A registered adviser operates inside a supervisory apparatus: a compliance program, books and records obligations, and a regulator that can arrive and test them. A single family office sits deliberately outside all of it.
“(a) Exclusion. A family office, as defined in this section, shall not be considered to be an investment adviser for purpose of the Act.”
The rule sets three conditions, and the governance-relevant one is the second: the office must be wholly owned by family clients and exclusively controlled, directly or indirectly, by family members or family entities. Congress placed the exclusion in 15 U.S.C. § 80b-2(a)(11)(G) and left the definition to the Commission.
Exclusive family control is the condition of the exclusion, and it is also why the usual external checks are absent. Elsewhere a control survives partly because somebody outside will eventually test it. Here it survives only because the family keeps deciding it should. That is the starting point for an investment committee and for the policy statement it works from.
Authority, custody, and accounting
The federal internal control standard names the three duties that belong to different people. The current edition is the 2025 Green Book, effective beginning with fiscal year 2026, which replaced the 2014 revision most policies still cite:
“Segregation of duties helps prevent fraud, waste, and abuse in the internal control system. Management considers the need to separate control activities related to authority, custody, and accounting of operations to achieve adequate segregation of duties within the entity’s business processes.”
Authority is the decision that a transfer should happen. Custody is the ability to make it happen, which here means holding enough key material to reach the signing threshold. Accounting is whoever later compares what moved against what was approved.
For a wire, infrastructure you did not build keeps those apart: someone approves in one system, someone releases at the bank, and a statement arrives from a third party with no incentive to agree with your ledger. An error has a recall process to attempt. On-chain, one person with one device performs all three and produces the only record that any of it happened. The transfer is final, the recipient is a string of characters, and no institution can be called.
So the separation has to be manufactured. In a small office that means an approver who holds no key material, a signing threshold requiring two devices held by two people in two places, and a reconciliation performed by someone with no signing capability. The Green Book anticipates entities too small to divide duties cleanly and directs them to design alternative control activities, which here means substituting review for separation: a second read of every outgoing address, a monthly reconciliation of balances to the ledger, and a standing agenda item.
Four artifacts, and what each one proves
The threshold schedule. One number will not carry the policy: write a routine tier a single authorized person may execute, a middle tier requiring an approver who holds no key, and a top tier requiring the committee. State each in dollars and in units, since a limit written only in dollars widens after a rally. Record who may move a tier.
The address allowlist. Every destination the office is willing to send to, with who requested it, who verified it, and the date. A new destination earns its place through a small test transfer and a waiting period. It is also a tax artifact: Rev. Proc. 2024-28 sets a safe harbor for allocating unused basis to each wallet or account as of January 1, 2025, so an address nobody wrote down is a hole in the tax record as much as a gap in the controls.
The review cadence. Monthly, on-chain balances against the ledger, checked by a person who cannot sign. Quarterly, the allowlist, the signer roster, and any standing authorization. Annually, a live rehearsal of the recovery path with the people it names. Every review leaves a dated artifact with a name on it, because that artifact is the evidence the control operated.
The absence plan. Define unreachable in days. Name who assumes the approval role and who assumes the signing role, by office rather than by individual. State where the recovery material sits and who may retrieve it. Where the family office serves or supports a trustee, this runs into trustee exposure, measured by the process followed rather than the result obtained.
Governance covers decisions that put assets to work, alongside decisions that move them. Rev. Rul. 2023-14 treats validation rewards as income when the taxpayer obtains dominion and control, so authorizing the office to stake creates a recognition date somebody has to capture. Key rotation belongs in the same document, and NIST SP 800-57 is the reference for the interval.
What I actually see
The first pattern: the committee that approves and the individual who signs are the same person. Minutes record a decision, that person executes it, and that person prepares the report where a discrepancy would surface. It shows up in almost every office where the principal is also the technically capable one.
The second is the allowlist that exists as a habit. Addresses live in a phone’s contacts or an exchange’s saved-address book with no record of who checked them. Nobody can say when an entry appeared or who approved it, which means nobody can say whether it was ever verified.
The third is governance written for the position as it stood in 2022. The document names a custodian the office stopped using, a threshold set when holdings were a quarter of their current size, and two signers, one of whom has left. Nothing broke. The document stopped describing the office.
The exercise I would run: take one transfer from the last six months and rebuild it from the record alone. You want the approval showing a person distinct from the signer, the allowlist entry for that destination with a date and a verifier, the reconciliation covering that month signed by someone who cannot sign transactions, and the signer roster in force at the time. If any of the four takes more than a day to produce, treat that control as untested.
Where this goes wrong
Governance decays where the document and the keys stop describing the same office.
The specific failures: a threshold denominated only in dollars that becomes a formality after a rally, so the committee tier is never reached again. Approval by group chat, which leaves no signature and nothing searchable a year later. A signer who departs with the device wiped and the seed phrase never rotated, leaving live capability outside the roster. Allowlist entries created during a transfer, under exactly the time pressure the control existed to absorb. A reconciliation prepared by the person who signs, which reports on itself. A second custody relationship added with no single inventory covering both. And the version that gathers all of them: a loss, a family member asking who authorized the transfer, and a record that answers with a screenshot.
The decision rule
- Write down who may decide, who may sign, and who must review, naming roles rather than individuals.
- Bar the approver from holding key material above the routine tier, and store the approval where it can be retrieved years later.
- Set thresholds in dollars and in units, and re-set them on a calendar date rather than when somebody notices.
- Route every destination through an allowlist, with a test transfer, a named verifier, and a waiting period.
- Reconcile to on-chain balances monthly, signed by a person with no ability to sign transactions.
- Define unreachable in days, and name the substitute approver and substitute signer by office.
- Rehearse the recovery path annually with the people the plan names, using a real transaction.
- Revise the document whenever a signer, a custodian, or the position size changes, and date every version.
Where this sits
Governance is the layer that makes the other decisions enforceable. Custody settles who physically can move assets, and governance settles who is permitted to. Trusts and estate planning settle what happens when the people named stop being available. Due diligence settles what the office is willing to hold at all, and the checklist is the place to begin if none of this is written down yet.
The join is where it breaks. The attorney drafts the entity documents and the trust, the CPA closes the books and files the returns, and the custody arrangement gets built by whoever solved the operational problem first. Those three rarely read each other’s work, so the office ends up with an approval right that lives in a document and a signing capability that lives on a device, with nothing reconciling the two. Someone has to own that seam by name, and the review cadence is where the ownership becomes visible.
Sources
- 17 CFR 275.202(a)(11)(G)-1, Family offices
- 15 U.S.C. § 80b-2, Definitions (Investment Advisers Act)
- GAO-25-107721, Standards for Internal Control in the Federal Government (2025 Green Book)
- NIST, Special Publication 800-57 Part 1 Revision 5, Recommendation for key management
- IRS, Rev. Proc. 2024-28, Digital asset basis allocation
- IRS, Rev. Rul. 2023-14, Staking rewards and dominion and control
- IRS, Digital assets
Related
- How should a family office investment committee review crypto?
- Digital asset investment policy statement for family offices
- Crypto due diligence for family offices
- How should a family office report crypto?
- Crypto family office checklist
- Crypto family offices
Last updated: 3 August 2026.
This article is general education, not legal, tax, or investment advice, and nothing here recommends any asset, allocation, or timing. Governance and control design can reduce certain risks but do not eliminate them, and outcomes depend on your facts, your documents, and the people who follow them. Talk to a qualified attorney and CPA about your own situation.
