Who Controls the Keys, and Why the Answer Determines Everything Else
Provider-held, co-signed and self-managed arrangements have different legal positions, not just different convenience.
Business wallet products describe similar features and sit in three quite different legal positions. The difference is who can move funds without you. It is worth seeing what an institutional crypto wallet enforces by default before deciding how much of this to build yourself.
Arrangement one: the provider holds everything
The provider controls key material and moves assets on your instruction, enforcing your policy in software.
This is custody. It requires the permission, and where it exists your assets should be segregated client assets not available to the provider’s creditors.
Convenient, and entirely dependent on the provider’s authorisation and solvency.
Arrangement two: co-signing
You hold a key, the provider holds a key, both are required.
The provider cannot move funds alone. Neither can you, unless there is a recovery path.
This is a materially different position: the provider’s failure does not give anyone access to your assets, though it may make them difficult to reach until you execute recovery.
Whether it constitutes custody depends on the specifics and on the jurisdiction.
Arrangement three: self-managed
You hold all keys. The provider supplies software.
No custody, no counterparty, and the entire operational burden is yours.
The question that reveals which you have
Can the provider move my assets without my participation.
If yes, it is custody and the permission matters.
If no, ask the follow-up: can I move my assets without the provider’s participation. If the answer is also no, you have a dependency that needs a documented recovery path. Funds face the same question with an extra reporting layer, which is what a provider serving funds and family offices is structured around.
Why marketing blurs this
All three are described as secure, non-custodial, or institutional grade, and those terms do not map cleanly onto the distinction.
The words to look for are in the agreement rather than on the site.
The practical checks
Which arrangement applies, in writing.
If the provider holds keys, which permission covers it and is it on the register.
If you hold a key, what is the recovery procedure without the provider, and has anyone tested it.
That last one is where most arrangements fail. A recovery path that exists in documentation and has never been executed is a plan rather than a capability.
What organisations actually choose
Co-signing for operating balances, because it removes the provider’s unilateral access while keeping their operational support.
Self-managed for reserves, where movement is rare and coordination is manageable.
Provider-held where the organisation cannot staff key management at all, which is a legitimate position and makes the provider’s authorisation the central question. The part that only matters on a bad day is whether there is a support channel with a named contact, and that is worth testing before you need it.
Filed under: custody, control, regulation