Tokenized assets need custody models that address ownership, control, compliance, transfer restrictions, servicing, reporting, and institutional risk.

Get weekly updates with our Newsletter

Join the community — Get Updates and Tips

Regular updates ensure that readers have access to fresh perspectives, making the Blocks & Bonds newsletter a must-read.

August 15, 2026

10 minutes

Institutional Custody Models for Tokenized Assets

One of the promises of tokenization is that financial assets can move more directly.

Ownership can be represented digitally. Transfers can occur over shared ledgers. Settlement can become faster. Smart contracts can automate functions that once required several institutions and multiple databases.

It is tempting, then, to assume that tokenization makes custody less important.

The opposite may be true.

As tokenized assets move from experiments into institutional portfolios and financial-market infrastructure, custody becomes one of the critical questions determining whether those assets can be trusted at scale.

The reason is straightforward. A bank, asset manager, pension fund, corporation, or other institution does not merely need to know that a token exists on a blockchain. It needs to know who controls it, who is authorized to move it, what legal rights attach to it, how those rights are recorded, how client assets are segregated, what happens if an intermediary fails, and how control can be restored if technology or credentials are compromised.

That makes digital custody much more than a wallet problem.

It is an architecture of control.

And understanding that architecture is essential to understanding how tokenized capital markets are likely to develop.1

Tokenization does not eliminate custody. It changes what custody has to accomplish.

Custody Is No Longer Just About Where an Asset Sits

Traditional custody feels intuitive because financial markets have spent decades building legal and operational systems around it.

A custodian holds securities or other financial assets on behalf of clients, maintains records, facilitates settlement, handles corporate actions, provides reporting, and establishes controls intended to protect client property.

Tokenized assets complicate that picture.

A token may exist on a blockchain rather than inside a custodian's proprietary database. Control over that token may depend on cryptographic credentials. Transfers may be executed automatically or through smart contracts. Ownership may also be reflected in an issuer's register, transfer-agent records, a securities entitlement, or some combination of on-chain and off-chain systems.

The result is an important distinction: Technical control of a token is not necessarily the same thing as legal ownership of the asset it represents.

A party might control the private key capable of transferring a token without possessing all of the legal rights associated with the underlying asset. Conversely, an investor may possess the legal economic interest while a regulated intermediary controls the credentials required to move the token.

That distinction is no longer theoretical. In its January 2026 statement on tokenized securities, SEC staff emphasized that tokenization structures can differ significantly and that the rights associated with a tokenized security depend on how the product is structured. The token may represent the issuer's security directly, or a third party may create a separate crypto asset linked to an underlying security or entitlement.2  

This is why one of the most useful questions in tokenized finance remains deceptively simple:vWho actually owns the asset?3

The answer requires looking beyond the wallet address.

The Four Institutional Custody Models

There will not be one universal custody model for tokenized assets.

Different institutions will make different decisions depending on regulation, asset type, internal capabilities, transaction volume, risk tolerance, and the level of operational control they require.

But most institutional arrangements can be understood through four broad models.

1. Direct Institutional Custody

In the direct model, the institution assumes primary responsibility for the technical infrastructure required to control its digital assets.

It may operate its own key-management environment, authorization policies, transaction controls, cybersecurity protections, monitoring systems, and recovery procedures.

The attraction is control.

The institution reduces its dependence on an outside custodian and can design the custody architecture around its own operating requirements.

But control brings responsibility.

Safeguarding cryptographic credentials requires specialized technology, governance, cybersecurity, operational processes, and personnel. A compromised or inaccessible key can have consequences fundamentally different from an employee losing a password to a conventional financial database.

Federal banking regulators have identified cryptographic key management as one of the central risks of crypto-asset safekeeping and have emphasized the need for strong controls, appropriate expertise, governance, monitoring, and recovery procedures.4

For that reason, direct custody is most plausible for institutions with sufficient scale, technical capability, and strategic reason to own the infrastructure themselves.

2. Third-Party Institutional Custody

A second model delegates custody to a specialized provider.

Here, the institution retains the economic relationship with the asset but relies on a custodian to safeguard the credentials, execute authorized transactions, maintain controls, and frequently provide reporting, compliance, settlement, and other supporting services.

This model looks more familiar to traditional finance. Its advantage is specialization.

A custody provider can spread infrastructure, security, personnel, insurance, compliance, and operational costs across many clients rather than requiring every asset manager or institution to recreate the same capabilities internally.

But outsourcing technical control does not outsource responsibility for understanding the arrangement.

Institutions still need to know how assets are held, how transactions are authorized, how customer property is identified, what contractual protections exist, whether other providers are involved, and what happens during insolvency, cyber incidents, or operational failures.

The custodian therefore becomes more than a storage provider. It becomes part of the institution's risk architecture.5

3. Sub-Custody and Outsourced Infrastructure

The third model is more layered.

A bank or primary custodian can maintain the customer relationship while using another company to provide some of the underlying digital-asset infrastructure.

This may include specialized custody technology, key management, transaction execution, blockchain connectivity, or a sub-custodian that actually safeguards the digital assets.

This structure matters because traditional financial institutions do not necessarily have to build every component of digital custody themselves.

The OCC has confirmed that national banks and federal savings associations may outsource permissible crypto-asset custody and execution services to third parties, provided that appropriate third-party risk-management practices are followed.6

That creates an important strategic possibility.

A bank could remain the trusted institutional interface while specialized technology companies operate portions of the infrastructure underneath it.

The customer may see the bank. The bank may see a network of technology providers and sub-custodians. From the client's perspective, however, the critical question does not change: who ultimately has control, and who is responsible when something goes wrong?

Every additional layer introduces another relationship that has to be understood, governed, monitored, and legally defined.

4. Hybrid and Distributed-Control Custody

The fourth model distributes control rather than placing it entirely with one institution.

Technologies such as multi-signature arrangements and multi-party computation can divide the authority needed to approve transactions among different people, systems, or organizations.

An institution and a custodian might share elements of control. Multiple internal teams may have to approve certain transactions. Critical credentials may be distributed so that the compromise of one component does not automatically compromise the asset.

The important idea is not the underlying cryptography. It is the governance principle.

No single person, device, provider, or credential necessarily needs to possess unilateral control over an institutional asset.

That can create additional safeguards, but it also introduces complexity. Institutions must determine who has authority, how approvals work, what happens when participants become unavailable, how emergency procedures operate, and how responsibility is allocated among the parties.

Distributed technical control still requires clearly defined institutional accountability.

Omnibus or Segregated? The Account Structure Matters

Another important decision sits beneath these four models: whether assets are held through an omnibus structure or separately for individual clients.

In an omnibus model, assets belonging to multiple customers can be held together operationally while the custodian maintains internal records identifying each customer's interest.

In a segregated model, client assets are associated more directly with separate accounts or blockchain addresses.

Neither model is automatically superior.

Omnibus structures may improve operational efficiency, liquidity management, and transaction processing. Segregated structures may provide greater transparency around the location and identification of specific customer assets.

The tradeoffs become especially important during reconciliation, operational failures, disputes, or insolvency.

U.S. banking regulators specifically advise banking organizations providing crypto-asset safekeeping to consider the different risks associated with omnibus and separate-account structures.7

For an institution, the relevant question is not simply whether the assets are "segregated."

It is how segregation operates technically, operationally, contractually, and legally.

The wallet structure tells you where the token is. It does not, by itself, tell you who owns it.

Custody Is a Legal Architecture

This is where custody and tokenization become inseparable.

A token can indicate that an address controls a digital object. That does not necessarily answer what legal rights the holder possesses against an issuer, fund, corporation, custodian, or underlying asset.

For institutional assets, custody therefore has to connect several layers of truth.

There is the blockchain record: what does the ledger say?

There is the custody record: which client does the intermediary associate with the asset?

There is the issuer or transfer record: whom does the issuer recognize as the holder?

And there is the legal claim: what rights can the investor actually enforce?

Ideally, these layers align. If they do not, the architecture needs to establish which record prevails and how discrepancies are resolved.

This is particularly important for tokenized securities. The SEC staff's 2026 tokenization statement makes clear that the legal consequences can differ depending on whether the token is issued by the securities issuer itself or by a third party, and whether the holder has rights in the underlying security, a security entitlement, or another contractual arrangement.8

That is why the legal architecture of tokenized assets 9 matters as much as their technological architecture.

A blockchain can record a transfer with extraordinary precision. It cannot, on its own, determine every legal consequence of that transfer.

The Institutional Custody Stack

The easiest mistake is therefore to reduce digital custody to private-key storage.

Institutional custody is better understood as a stack.

At the foundation is legal ownership and asset recognition. The institution needs to know what the asset is and what rights it conveys.

Above that sits asset segregation and recordkeeping. Customer interests must be identifiable and reconciled.

Then comes cryptographic control: the infrastructure that protects the credentials required to move the asset.

Above that is transaction authorization: the policies determining who may initiate, approve, block, or modify transactions.

Then comes compliance and monitoring: identity controls, sanctions screening, transaction monitoring, transfer restrictions, smart-contract oversight, and other regulatory requirements.

Finally, institutions need reporting, auditability, resilience, and recovery.

If something fails, can the institution reconstruct what happened?

Can it prove ownership?

Can it recover access?

Can it continue operating?

Can auditors and regulators understand the control environment?

These questions explain why institutional custody becomes substantially more complex than simply putting a token into cold storage.

The BIS has similarly emphasized that tokenized financial arrangements continue to face familiar financial-market risks—including custody, operational, cyber, governance, liquidity, and access risks—even though those risks may manifest differently as financial functions move onto programmable platforms.10  

Custody May Become a Strategic Choke Point

This has important implications for where value accrues in tokenized markets.

Tokenization is often associated with removing intermediaries. In practice, it may remove some functions, automate others, and increase the strategic importance of a smaller number of trusted control layers.

Custody is a candidate to become one of those layers.

Institutions do not change critical infrastructure casually.

Once a custody provider is integrated into an asset manager's trading systems, compliance processes, accounting, reporting, settlement, risk management, and internal controls, replacing it becomes more difficult.

Trust matters.

Regulatory standing matters.

Insurance and capitalization matter.

Technology matters.

Integration matters.

And the ability to support multiple networks, asset types, jurisdictions, and transaction models may matter increasingly as tokenized markets become more complex.

This is the broader lesson behind Where Value Accrues in the Crypto Stack [I5]: technological importance and economic capture do not necessarily occur in the same layer.

A blockchain may record the asset.

An asset manager may issue it.

An investor may own it.

But the company that becomes the trusted control layer connecting those parties may capture a durable share of the economics surrounding the market.

In tokenized markets, control may become one of the most valuable forms of infrastructure.

What Institutions Should Watch

The custody market is unlikely to converge immediately around a single model.

Banks, specialist custodians, asset managers, tokenization platforms, exchanges, and technology providers are approaching the problem from different starting points.

What matters is not which custody architecture appears most technologically sophisticated.

The more useful signals are whether institutions can establish clear ownership rights, safely delegate or distribute control, maintain asset segregation, integrate compliance, survive operational failures, recover from compromised credentials, and connect digital assets with the accounting and reporting systems institutions already use.

The strongest models will also need to work across more than one blockchain or tokenization platform.

That matters because institutional investors are unlikely to want a separate custody architecture for every network, asset type, or issuer.

The winning infrastructure will make complexity disappear rather than transfer it to the client.

The Custody Question Does Not Go Away

Tokenization can change the way financial assets are issued, transferred, settled, and administered.

It may reduce reconciliation. It may automate transfer restrictions. It may shorten settlement. It may make ownership records more programmable and financial assets easier to integrate into digital systems.

But it does not eliminate one of finance's oldest questions: Who controls the asset?

For institutional markets, that question expands into several others.

Who owns it?

Who can move it?

Who records that ownership?

Who protects the credentials?

Who is responsible if a third-party provider fails?

What happens if the records disagree?

And what happens when something goes wrong?

The technology underneath custody is changing.

The economic function is not.

Financial institutions still require a trusted system for establishing control, protecting client property, enforcing permissions, maintaining records, and recovering from failure.

That is why custody should not be treated as a supporting detail of tokenization.

It is part of the infrastructure that determines whether tokenization can operate at institutional scale.

And as tokenized capital markets develop, the institutions that become trusted enough to control those assets may become some of the most important—and valuable—participants in the stack.

Continue the Analysis

Custody answers one part of the tokenization question: who controls the asset?

The next question is larger: what happens to capital markets when issuance, ownership, settlement, collateral, and servicing begin moving onto programmable infrastructure?

Next: Tokenization & RWAs: The Rewiring of Capital Markets


Explore the Report