A custody operation does not have a single risk. It has a taxonomy of risks, and the taxonomy maps onto the binders that respond to each. The first useful step a risk officer can take, before reading a single binder, is to write the firm's own custody-risk taxonomy in the firm's own terms — then walk it against the market. What follows is the taxonomy I reach for when I read a custody operation for placement.
Five operational dimensions
A custody operation lives along five dimensions. Each dimension has its own peril vocabulary, its own architectural decisions, and its own implications for the binders that will respond.
1. Key storage. Hot, warm, cold. The hot/warm/cold split, expressed as a percentage of assets under custody (AUC) in each tier, is the single most-asked underwriting question. A custody operation with 5% hot / 15% warm / 80% cold reads differently from one with 25% hot / 25% warm / 50% cold. Underwriting will probe the rationale and the operational triggers that move assets between tiers.
2. Key material structure. Single-key, multi-signature, MPC. The cryptographic structure of the key material determines the attack surface and the structural redundancy. Multi-signature with an m-of-n policy and MPC with a t-of-n signing share scheme are not the same and do not protect against the same perils. Underwriters will ask, in particular, about the geographic and operational distribution of signing parties.
3. HSM grade and certification. FIPS 140-2 Level 3 or Level 4; FIPS 140-3 where available; specific hardware models. A custody operation that signs into a FIPS Level 4 HSM with a documented key-ceremony procedure reads differently from one that signs from a software wallet on a developer's laptop. Underwriters will ask for the certification documentation.2
4. Operational controls. Segregation of duties, dual-control workflows, time-locks on large transfers, withdraw-limit policy, named approvers. Operational controls determine the human-side attack surface and the residual exposure to insider fraud and social engineering.
5. Recovery posture. Backup key structure, disaster-recovery plan, incident-response retainer (named provider), forensic-accounting retainer, tabletop-exercise cadence. Recovery posture determines the loss expectancy in the event of a peril realising.
A complete taxonomy reads each dimension against the others. A custody operation with 80% cold storage and Level 4 HSMs but no documented key-ceremony and no incident-response retainer is exposed in places that the cold-storage percentage alone does not reveal.
The peril map
Mapped against the five operational dimensions, the perils break down as follows.
Hot-wallet compromise. Driven primarily by Dimension 1 (storage tier), Dimension 2 (key material structure), and Dimension 4 (operational controls). Standard Lloyd's market structure: Crime / Specie binder against a Listed Wallet Schedule, as discussed in Why hot-wallet cover doesn't imply smart-contract cover (znobia Insights, this issue).1
Cold-storage compromise. Driven primarily by Dimension 1 (cold-tier architecture), Dimension 3 (HSM and physical-facility posture), and Dimension 4 (key-ceremony and physical-access controls). Standard structure: Specie binder against a Listed Facility Schedule. Hot-wallet wording does not respond.
Smart-contract logic failure. Driven by Dimension 2 (contract architecture), Dimension 4 (deployment controls and audit history), and the firm's bridge / oracle / dependency footprint. Standard structure: discrete contract binder against a Listed Contract Schedule. Neither hot-wallet nor cold-storage wording responds.
Validator slashing. Driven by Dimension 2 (validator-key structure), Dimension 4 (operational controls on validator infrastructure), and protocol-specific slashing conditions. Standard structure (where available): discrete slashing binder against a Listed Validator Schedule.3
Insider fraud / internal collusion. Driven primarily by Dimension 4 (segregation of duties, dual-control, joiner-mover-leaver) and Dimension 5 (audit posture). Standard structure: Crime / fidelity wording, frequently dovetailing with the hot-wallet binder for crypto-direct loss and the cyber binder for credential-mediated loss.
Cyber-mediated theft. Driven by Dimension 4 (identity and access management, MFA, social-engineering controls) and the firm's broader cyber posture. Standard structure: cyber tower, sitting alongside Crime / Specie at the boundary discussed in Crime / cyber dovetails — reading the seams (forthcoming).
Operational error. Driven by Dimension 4 across the board, particularly settlement and reconciliation workflows. Standard structure: PI binder with attention to the Professional Services definition, dovetailing with cyber for system-error events.
MPC versus multi-signature — a structural note
In 2022-2024, the operational debate among custody operators turned heavily on multi-party computation (MPC) versus on-chain multi-signature. The 2026 market position is that both are credible architectures and that underwriters do not, in practice, treat one as categorically superior to the other; they treat the implementation as the question. A 2-of-3 multi-signature scheme with all three signers in the same physical location and no documented key-ceremony reads worse than a 3-of-5 MPC scheme with signers across three legal entities, two geographies, and a quarterly key-ceremony refresh. The dimensions matter, not the brand of the architecture.4
What an underwriting submission needs to contain
If you are running this taxonomy internally before bringing a submission to a market, the underwriting submission should include, at minimum:
- A custody architecture diagram showing the storage tiers, the signing infrastructure, and the data flows between them.
- A wallet schedule (production wallets, identified by chain and address or by a stable identifier where on-chain address rotation is in use).
- The HSM / hardware schedule.
- The signing-quorum policy, with named roles (not named individuals — the policy survives staff changes).
- The key-ceremony procedure.
- The withdrawal-authorisation matrix with the limit and approval thresholds.
- The incident-response plan with the named provider and contact details.
- The audit-and-pen-test history (SOC 2 Type II date and scope; ISO 27001; last pen-test report date).5
- The claims-and-near-miss history for the prior 36 months.
- The chain-analytics provider and sanctions-screening posture.
A custody operation that can produce this submission in 10 business days is reading itself well. A custody operation that cannot is exposed in places the operation itself does not yet know about.
"The dimensions matter, not the brand of the architecture."
A note on what the 2026 market expects
By 2026 most institutional underwriters expect a custody operation to be able to read its own taxonomy in roughly the form above, present it as an underwriting submission, and discuss it at depth with a broker who reads the same vocabulary. Operations that can do this tend to place. Operations that cannot frequently do not — even where the underlying architecture is sound — because the underwriter cannot read what is not written down.
The broker's function in this market is partly to translate. Increasingly, it is to insist that the buyer write the taxonomy in the buyer's own terms first, and only then walk the wording against it. That is the order we use.