The short answer
What does this use case involve?
An exchange custody operating model connects customer entitlements to controlled wallets, liquidity and external settlement. Separate the customer ledger, custody arrangement, hot-wallet operations, treasury reserves and venue or counterparty settlement. Every movement should have a policy owner, durable identifier and reconciliation path; fast blockchain confirmation does not by itself prove that a customer withdrawal or counterparty settlement is complete.
Where the current process breaks down
An exchange must keep customer entitlements aligned with wallets, omnibus accounts and trading records while moving assets quickly enough for deposits, withdrawals and settlement. Unclear ownership between custody, treasury and operations creates concentrated risk. Useful for centralized exchanges, broker platforms, OTC desks and digital asset marketplaces that operate customer wallets, treasury reserves and external settlement relationships.
From input to outcome
How does the workflow operate?
The following is an illustrative operating model, not a claim about a specific deployment. Ownership, approvals and exception handling should be agreed before implementation.
- 01
Record the customer obligation
Attribute deposits to the correct customer and asset, apply confirmation policy and preserve the relationship between blockchain transaction, account balance and any compliance review.
- 02
Approve asset movement
Apply destination screening, velocity and value limits, role-based approvals and independent review for policy exceptions before a withdrawal or treasury transfer reaches signing.
- 03
Sign and settle
Use the approved hot, warm, cold or third-party custody path. Track signing, broadcast, confirmations, counterparty acceptance and final delivery as distinct states.
- 04
Reconcile and rebalance
Reconcile wallets, custodian accounts and exchange liabilities. Replenish operational wallets under limits and investigate unexplained balance, fee and status differences.
Build the operating stack
Which infrastructure is needed?
These capabilities may sit inside an existing system, a specialist service or an integrated platform. Map each one to a responsible owner; do not assume a single vendor covers every function.
- Regulated custody or wallet infrastructure
- Hot, warm and cold wallet policy
- Transaction screening and approval
- Exchange ledger and reconciliation
- Liquidity and settlement connectivity
- Incident recovery and customer communication
Evidence and context
FATF virtual assets guidancePublic guidance on virtual-asset risks and controls. Exact custody, safeguarding, Travel Rule and reporting obligations depend on the exchange's services and jurisdictions.
Design for the exceptions
What can go wrong?
Customer and wallet records diverge
Reconcile liabilities to controlled addresses and custodian balances with independent exception review.
Privileged user redirects assets
Separate request, policy administration, approval and signing; monitor destination and role changes.
Ambiguous retry duplicates a withdrawal
Use persistent withdrawal IDs and check the original instruction across ledger, signer and chain before retrying.
When this is not the right fit
Do not centralize exchange, treasury and custody authority in one operator or undifferentiated wallet. A provider cannot compensate for an exchange ledger that cannot prove customer entitlements and reconcile exceptions.
A bounded first deployment
How should a team start?
Start with one workflow and named operational owners. A pilot should show that the process works through exceptions, not just that a transaction can succeed once.
- Select one asset, network and limited customer cohort.
- Map deposit, withdrawal, treasury replenishment and external settlement separately.
- Test prohibited destinations, unavailable approvers, webhook loss, chain congestion and ambiguous retries.
- Run daily liability-to-asset reconciliation and an emergency wallet migration before expanding.
What should the pilot measure?
- Customer liabilities versus controlled asset balances
- Withdrawal completion time including held and failed cases
- Unreconciled wallet, fee and settlement exceptions
Set a baseline and acceptance thresholds before choosing technology. Include support effort and failed cases in the comparison, and validate the result with the teams that will operate it.
Procurement questions
What should you ask vendors?
- Which system is authoritative for customer balances?
- Who may change withdrawal policy, destinations and approval roles?
- How are hot-wallet limits and replenishment evidence reviewed independently?
Request evidence from comparable workflows, a clear responsibility matrix, integration documentation and an export or exit plan. Confirm current capabilities directly rather than relying on a category listing.
Relevant vendor directories
Common questions
Does a custodian operate the exchange's customer ledger?
Usually not. Custody balances and the exchange's customer liabilities are separate records that require controlled reconciliation.
How much should remain in hot wallets?
Set a risk-based limit using measured withdrawal demand, replenishment timing and loss tolerance, then monitor and approve exceptions rather than relying on a fixed industry percentage.
Sources and further reading
Independent implementation guidance, not legal, investment or regulatory advice. Requirements depend on your product, jurisdiction and operating model.
Last updated