Skip to content

Guide to Asset Custody Records for Exchanges

A guide to asset custody records for crypto and multi-asset exchanges: build audit-ready ledgers, reconcile daily, and control access with confidence.

Guide to Asset Custody Records for Exchanges

A customer asks for a BTC withdrawal, a cashier receives a cash deposit, and a treasury team moves gold inventory between vaults. If each event lands in a different spreadsheet, the exchange does not have a custody record system. It has a reporting risk. This guide to asset custody records explains how exchange operators can create a reliable, auditable view of assets held, assets owed, and the people authorized to move them.

Custody records are not merely a compliance file saved for a future audit. They are the operating evidence behind daily balances, customer liabilities, wallet activity, branch cash, bank movements, and management P&L. When records are complete and reconciled every day, finance and operations teams can identify exceptions before they become losses, disputes, or regulatory exposure.

What asset custody records need to prove

For an exchange, custody is the obligation to safeguard assets that belong to customers, counterparties, or the business itself. A useful record must answer three questions without requiring someone to reconstruct the day from chat messages and exports:

  1. What asset was received, held, moved, exchanged, or released?
  2. Who had the legal or operational claim to that asset at the time?
  3. What evidence supports the balance and the movement?

That standard applies across asset classes. For crypto, evidence may include wallet addresses, transaction hashes, network confirmations, internal transfer IDs, and signer approvals. For fiat, it may include bank references, cash receipt numbers, remittance instructions, and branch location details. For gold or oil, records may also need serial numbers, purity or grade, storage location, delivery documentation, and settlement status.

The key distinction is between a balance and a custody record. A balance tells you how much is present at a moment in time. A custody record explains why it is present, where it is held, whose asset it is, and what changed it. Exchanges need both.

Build asset custody records around a clear ledger structure

The fastest way to create confusion is to mix customer assets, company assets, fees, and unsettled transactions in the same account without clear classifications. Your chart of accounts should separate assets under custody from the liabilities owed to customers or counterparties. It should also distinguish operational wallets, cold storage, branch cash, bank accounts, inventory, clearing accounts, revenue, and expense accounts.

Every custody event should create a complete accounting trail. A customer crypto deposit, for example, increases the exchange's controlled crypto balance and increases the liability owed to that customer. A completed sale may reduce one customer asset position, increase another, recognize a fee, and move value through a settlement or clearing account. The exact entries depend on your operating model, but the underlying principle does not: every movement must preserve the relationship between custody, ownership, and accounting.

Use one source of truth for asset movements

A transaction record should carry more than an amount and date. At minimum, capture the asset type, quantity, valuation currency, timestamp, customer or counterparty account, source and destination, transaction reference, status, and employee or system that initiated the event.

For crypto, record the blockchain network separately from the asset symbol. USDT on Ethereum and USDT on Tron may share a ticker but do not share the same operational risk or wallet path. For fiat, keep bank transfer references and settlement dates attached to the movement. For physical assets, preserve custody-chain details from intake to storage to release.

This level of detail reduces a common failure point: a correct total that cannot be explained at transaction level. An auditor, operations manager, or customer support lead should be able to move from an account balance to the underlying activity without waiting for manual spreadsheet work.

Reconcile daily, not when an issue appears

Custody errors are rarely caused by one dramatic event. They often begin as small timing differences, duplicate postings, missing fees, unconfirmed blockchain transfers, or cash count variances that remain unresolved for several days. Daily reconciliation is the control that stops those differences from becoming normal.

A practical daily process compares three views of the same operation: the internal ledger, the external custody source, and the customer or counterparty obligation. For a crypto wallet, compare on-chain balances and transaction activity against the accounting ledger and customer liabilities. For a bank account, compare the bank statement, pending payment records, and booked ledger entries. For a branch cash position, compare physical counts, cashier activity, and recorded receipts or disbursements.

Timing matters. A transaction that is pending on a blockchain, awaiting bank settlement, or in transit between branches should not be treated as final just because it has been initiated. Use defined statuses such as pending, confirmed, rejected, reversed, and settled. Then assign each status a clear accounting treatment. This prevents teams from recognizing the same value twice or releasing funds before the supporting movement is final.

Make exceptions visible and owned

A reconciliation is only useful when differences have an owner and a deadline. Assign exceptions by type: treasury investigates wallet differences, finance investigates ledger posting differences, branch managers investigate cash variances, and compliance reviews suspicious or unusual activity.

Keep an exception log with the amount, asset, date discovered, likely cause, assigned owner, evidence reviewed, and resolution. A difference that is immaterial today may still identify a broken process, an employee training issue, or a system integration failure. Closing the amount without documenting the cause leaves the control incomplete.

Control who can create, approve, and release movements

Custody records are only as credible as the access model behind them. If the same user can create a customer withdrawal, approve it, edit the record, and reconcile the account, the organization has created a preventable control gap.

Role-based access should reflect actual operating duties. Cashiers may enter branch transactions but should not change historical ledger entries. Treasury staff may prepare wallet transfers but require separate approval for release. Finance teams may post adjustments but should retain a reason code and approval trail. Executives need visibility without unrestricted transaction authority.

The most effective custody controls are specific and testable:

  • Segregate transaction initiation, approval, release, and reconciliation across appropriate roles.
  • Require approval thresholds based on value, asset type, risk level, or destination.
  • Preserve immutable activity logs for changes, approvals, reversals, and user access.
  • Restrict access to sensitive reports and customer data by role, branch, or legal entity.
  • Review dormant users, elevated permissions, and failed login activity on a defined schedule.

These controls should fit the size of the exchange. A smaller operator may use fewer roles, while an enterprise exchange may require multi-level approval and separate teams by branch or entity. The goal is not process for its own sake. It is to ensure no single person can move or conceal assets without detection.

Retain evidence that supports the full custody chain

Records should be organized so that a transaction can be reviewed years later with its supporting evidence intact. That includes customer instructions where applicable, trade confirmations, payment receipts, wallet transaction hashes, bank statements, vault receipts, internal approvals, and adjustment explanations.

Retention periods depend on jurisdiction, licensing obligations, tax requirements, contractual terms, and the nature of the asset. Your legal and compliance teams should define the policy. Operations and finance must then make it workable. A policy that requires evidence but stores it across personal inboxes, local desktops, and disconnected applications will fail when the business needs it most.

Cloud-based systems can improve access and continuity, but they do not replace disciplined record design. Look for encrypted storage, controlled permissions, audit logs, reliable backups, and clear data ownership. For exchange operators managing crypto, fiat, gold, and oil in parallel, a unified accounting operating system such as Siferex can reduce the need to reconcile disconnected records across separate teams and tools.

Measure the health of your custody process

A custody control environment should be managed with operating metrics, not assumptions. Track unreconciled balances by asset and age, the number of manual adjustments, reconciliation completion time, approval turnaround, failed or reversed transfers, and open exceptions by owner.

These measures show where risk is accumulating. A growing volume of aged reconciling items can indicate an integration issue or an understaffed finance team. Frequent manual journals can signal that transaction workflows are not mapped correctly. Delayed approvals may create customer service problems, while rushed approvals can create fraud exposure. The right response depends on the pattern, but the data must be available in real time.

A practical rollout sequence

Start by mapping every place where value can enter, move, settle, or leave the business. Include wallets, exchanges, bank accounts, cash drawers, vaults, payment processors, branches, and internal clearing accounts. Then define the required record fields and the accounting treatment for each transaction type.

Next, establish daily reconciliation ownership and an escalation path for exceptions. Configure user roles before onboarding the entire team, then test common scenarios: a customer deposit, a withdrawal, an internal transfer, a reversal, a branch cash variance, and a month-end close. Testing should confirm not only that balances calculate correctly, but also that the system records who did what and when.

Finally, migrate historical balances with supporting references where possible. Speed matters, but an unverified opening balance can carry old errors into a new environment. Reconcile opening positions to source evidence, document known differences, and obtain finance sign-off before relying on the new ledger.

The strongest custody record is one your team can explain immediately: what was held, who owned it, where it moved, who approved it, and how the balance was verified. Build that discipline into daily operations, and financial control becomes a visible capability rather than a year-end scramble.