How to Build a Crypto Custody Policy

Write down five things: what is held and where, who may authorize a transfer, who may execute one, what happens when either is unavailable, and how any of it changes. Keep it to a couple of pages. A policy nobody reads is worth less than a shorter one everybody follows, and the value is in the rehearsal rather than the document.

The short version

  • The policy exists so decisions are made before the pressure, not during it.
  • Separate authorization from execution. The person who approves a transfer should not be the only person who can perform it.
  • The clause almost every policy is missing: what happens when a signer is unreachable for a defined period.
  • For an entity, the policy has to agree with the operating agreement, or you have documented a gap between authority and capability.
  • Rehearse it annually. An unrehearsed policy has an unknown condition.

The five sections

1. Inventory. Every wallet, account, and device, what it holds, which custodian, and who has access. Dated, reviewed on a schedule, and containing no secrets so it can be stored where people will actually find it.

2. Authorization. Who may approve a transfer, and at what thresholds. Most companies want a low threshold for routine movement and a higher one above a stated amount, with a defined ceiling on the low tier.

3. Execution. Who physically signs, and how. Which devices, which addresses are whitelisted, and the verification steps before a send. This is where the test transaction rule belongs.

4. Contingency. What happens when a signer is unavailable, loses a device, forgets a passphrase, or dies. Each case needs a named path, and the trigger has to be defined in days rather than left to judgment.

5. Change control. How a signer is added or removed, who approves it, and who outside the company must be told. The custodian’s file is the operative record for the custodian, so an amendment that never reaches them changes nothing in practice.

The separation that does the work

Authorization and execution should not sit with one person.

In an ordinary company this happens naturally, because approval and payment are different systems and a bank sits between them. On-chain there is no bank. Whoever holds the key both approves and executes unless the policy deliberately separates them, and nothing external enforces the separation.

The practical version: a transfer above the routine threshold needs a named approver who is not the signer, and the approval is recorded. That single control catches address errors, catches an approver acting outside authority, and creates a record showing the decision was made properly.

It also matters for a manager’s own protection. A manager judged later against a duty of care measured by what a reasonable person in that role would do is in a much stronger position with a written policy and evidence it was followed.

What most policies leave out

The unavailability window. Not death, which has a legal process. A signer unreachable for two weeks. Most policies have nothing, so the answer is improvised under pressure by people who are worried.

Who tells the custodian. Signer changes that never reach the institution leave authority on paper and capability in practice pointing at different people.

Where inbound assets land. Staking rewards, airdrops, forks. Undesignated destinations are how clean structures become commingled without anyone deciding anything.

The rehearsal schedule. A policy is a hypothesis about what would happen. The rehearsal is the test.

What I actually see

Policies get written at the length of the writer’s enthusiasm and read at the length of the reader’s patience. Twelve pages is a document nobody consults. Two pages taped inside the safe is a document people use.

The gap that recurs is between the policy and the keys. The document names a manager who may authorize transfers, and three family members hold signing devices. The policy is describing a company that does not exist operationally.

The habit worth adopting: once a year, take the policy and try to execute a small transfer using only what it says, with the people it names, including at least one contingency path. Every setup I have seen tested this way had at least one defect, and it was always cheaper to find it that way.

Where this goes wrong

The policy describes intentions and the wallet enforces something else.

The specific failures: a document written at formation and never revised as devices, people, and custodians changed. Contingency clauses that name individuals rather than roles, so the plan dies with the person. A whitelist populated once in a hurry and never verified. Approval thresholds nobody enforces because the approver is also the signer. And the policy stored somewhere only the person it depends on can reach.

The decision rule

  1. Two pages, five sections. Inventory, authorization, execution, contingency, change control.
  2. Separate authorizer from signer above a stated threshold.
  3. Define the unavailability trigger in days, with a named path.
  4. Designate a destination for every inbound event before it occurs.
  5. Reconcile with the operating agreement so authority and capability name the same people.
  6. Rehearse annually, including one contingency path, with a real transaction.
  7. Store it where a successor can reach it without you.

Where this sits

The policy is where custody stops being a technology choice and becomes an operating practice. What custody is frames the two jobs. The multi-sig policy is the signing half in detail. The operating agreement is where the authority half is legally binding. Succession is the contingency section taken to its conclusion.

A custody policy is the document that turns four separate decisions into one arrangement that a stranger could follow.

Sources

Related

Last updated: 3 August 2026.

This article is general education, not legal, tax, or investment advice. Operational controls can reduce certain risks but do not eliminate them. Talk to a qualified attorney about your own situation.

Sources

    Jake Claver

    Written by

    Jake Claver

    Family office professional working on how substantial holdings are held, structured and passed on. Qualified Family Office Professional. Finance degree, University of North Texas. Board member, Arkansas Blockchain Council. Author of Wealth in Numbers and Infinite Banking for Crypto Investors.