New Report Alert! Our latest guide on Stablecoin Payment Infrastructure is live. Download Now

Evaluate Stablecoin Custody Infrastructure For Banks Fintechs

Share this article

How Banks and Fintechs Should Evaluate Stablecoin Wallet and Custody Infrastructure

Stablecoin payment volumes crossed $9 trillion in 2025, a figure no longer surprising to treasury and operations teams at banks and fintechs. What remains to be worked out is how to select custody infrastructure that meets institutional security standards, satisfies regulators across MAS, VARA, and ADGM jurisdictions, and scales with transaction volume. This guide provides a structured framework for that evaluation.

JPMorgan projects the stablecoin market will reach $500 billion by 2028. Chainalysis estimates stablecoins moved $28 trillion in economic transactions in 2025. For banks, payment firms, and regulated fintechs, this is no longer a forward-looking use case. It is current infrastructure. The question has shifted from whether to adopt stablecoin rails to which custody infrastructure can support institutional-grade operations.

This guide covers six evaluation dimensions: operational requirements, regulatory compliance, MPC wallet architecture, transaction governance, security certifications, and vendor due diligence. Each section includes specific questions institutions should ask before selecting a custody provider.

Why Stablecoin Custody Has Become a Board-Level Decision

Recent market data highlights the importance of stablecoins in the global market. According to a 2025 Chainalysis report, stablecoins are estimated to have moved $28 trillion in economic transactions. This number is expected to reach $1.5 quadrillion by 2035, surpassing the value of the global market for cross-border payments today.

Stablecoins are being used across industries for cross-border payments, treasury management, liquidity optimisation, and institutional settlement.

Regulatory frameworks across key digital asset markets are increasingly formalizing custody requirements. Jurisdictions spanning Asia-Pacific and the Middle East have introduced rules that go beyond permitting stablecoin use to specifying how institutions must manage and safeguard the underlying assets. For banks and fintechs operating in these markets, custody infrastructure is no longer an internal choice. It is a compliance obligation shaped by the regulatory environment they operate in

As regulatory frameworks continue to evolve, stablecoin custody has become a priority for businesses. CEOs and CFOs are examining custody infrastructure to meet compliance expectations, while auditors now place greater emphasis on governance, security controls, and custody practices.

Questions to Answer Before Evaluating Custody Providers

Treasury and operations leadership must address four fundamental questions before vendor evaluation. These questions define the operational and compliance scope before any vendor conversation begins.

  1. What settlement workflows do we need to support?

Organisations must be clear about the operational necessities. These necessities may range from instant settlement of stablecoin trades to staking stablecoins, where customers receive dividends. They may also include treasury management for individuals as well as atomic settlements between different blockchains.

Different operational processes imply that the required infrastructure will also differ. For example, the infrastructure required by a financial institution dealing with cross-border payments is not the same as that needed by a financial tech company providing stablecoin yield.

  1. What regulatory regimes do we operate under?

Regulatory requirements vary significantly by jurisdiction. Before shortlisting any provider, map the regulatory environments your institution operates in and confirm that the provider has experience serving clients in those markets. Ask for documentation of how they support compliance in each relevant jurisdiction, what licenses or registrations they hold where applicable, and how they stay current as regulations evolve. A provider that cannot answer these questions with specifics is not ready for institutional deployment in regulated markets.

  1. What transaction approval controls do our governance policies require?

Approval controls should reflect an organisation’s governance policies and risk management requirements. Sometimes board rules require multiple parties to approve a transaction before any significant amount of money can be transferred. In other cases, risk management procedures establish limits on the speed of particular transactions. Lastly, an institution needs to maintain efficient internal controls and appropriate enterprise custody capabilities.

  1. What are the provider’s operational resilience and recovery commitments?

Organisations should check how a vendor responds to operational disruptions such as infrastructure outages, cyber incidents, or financial distress. This includes a clear understanding of asset recovery procedures, business continuity plans, disaster recovery capabilities, and incident response commitments.

Learn More – How Do Stablecoins Reduce Costs and Delays in Cross-Border Payments

Custody Architecture Evaluation: Multi-Party Computation Wallet Significance

Financial institutions should evaluate two leading technical methodologies: multisignature wallet architecture and Multi-Party Computation (MPC) wallet architecture.

Multisignature (Multisig) Wallet Architecture

Multisig wallets require a defined number of co-signers, for example, 2-of-3 or 3-of-5, to authorise each transaction. Each co-signer holds a complete, independent private key. The wallet executes the transaction once it collects the required signatures.

Multisig has known limitations for institutional use. Each co-signer key is a discrete attack surface. Key rotation requires on-chain transactions, creating operational overhead. Some blockchain networks have limited or inconsistent multisig support, constraining multi-chain treasury operations.

Multi-Party Computation Wallet Architecture

MPC wallet architecture distributes private key material across multiple parties as cryptographic shares. No single share constitutes a usable key. Transaction signing is performed collaboratively through a cryptographic protocol, producing a valid signature without ever reconstructing the complete key in any single location.

For institutional implementation, MPC architecture addresses three specific requirements:

Operational continuity. Key shares can be reassigned when personnel change, without disrupting wallet operations or requiring on-chain key rotation.

Single-point-of-failure elimination. No individual, device, or system holds a complete private key. Compromise of one share does not compromise the wallet.

Regulatory alignment. MPC architecture supports asset segregation and distributed control requirements that institutional regulators and auditors across regulated digital asset markets commonly expect.

Liminal’s MPC wallet infrastructure combines threshold signature schemes with HSM Vault capabilities, allowing institutions to choose the security model appropriate to their operational profile.

Compliance Infrastructure: What Institutional Custody Providers Must Support

A provider’s compliance capabilities determine whether they can comply with institutional requirements. If compliance infrastructure is not sufficient, vendors will be disqualified regardless of technology.

Compliance capability gaps disqualify a provider regardless of their technical architecture. Evaluate each of the following:

Travel Rule Compliance
FATF Recommendation 16 requires VASPs and financial institutions to share originator and beneficiary information when transferring digital assets above threshold amounts. Providers must support automated counterparty identification, secure data transmission to recipient VASPs, and audit trail generation. Ask which Travel Rule protocol the provider supports (for example, IVMS 101 standard) and which VASP directories they are integrated with.

AML Transaction Monitoring
Institutional transaction volumes make manual monitoring impractical. Providers must offer automated on-chain transaction screening, risk scoring, and suspicious activity flagging integrated with your compliance workflows. Confirm whether the provider’s monitoring covers both on-chain activity and fiat on-ramp/off-ramp transactions.

Sanctions Screening
Providers must screen wallet addresses and counterparties against OFAC, UN, EU, and jurisdiction-specific sanctions lists in real time. Confirm that screening is applied pre-transaction, not retrospectively.

KYC Integration
KYC must be embedded in the custody workflow, not treated as a separate process. Providers should support integration with your existing identity verification systems and maintain customer risk profiles linked to wallet activity.

Regulatory Licensing
Ask for specific license documentation, not general compliance statements. Confirm which licenses or regulatory registrations the provider holds in the jurisdictions where you operate, and verify that these are current. Providers that respond with broad claims about regulatory awareness rather than specific documentation are not ready for institutional onboarding in regulated markets.

Transaction Policy Governance: Institutional Safeguard Architecture

Stablecoin transactions are irreversible. Once a transaction is confirmed on-chain, no legal mechanism, central authority, or chargeback process can retrieve the funds. The transaction policy layer is the final institutional control before that finality takes effect.

Institutional custody platforms should allow organisations to define and enforce the following policy types:

  • Multi-party approval thresholds: Require 2-of-3 or higher approval for transactions above defined value limits.
  • Allowlist enforcement: Restrict outbound transfers to pre-approved wallet addresses only.
  • Velocity controls: Cap the volume or frequency of transfers within defined time windows.
  • Cross-border authorisation: Apply additional approval requirements for international transfers.
  • Role-based access: Assign initiator, approver, and auditor roles with distinct permissions.

These controls serve three institutional purposes: preventing unauthorised transfers, catching operational errors before they become permanent, and generating the audit documentation that regulatory examinations require.

Security Certifications: What Institutional Custody Providers Must Hold

Three certifications define the baseline security and privacy standard for institutional custody providers:

ISO 27001 (Information Security Management)
Confirms the provider has implemented a documented, audited information security management system. ISO 27001 certification demonstrates that security controls are systematic and maintained, not ad hoc.

ISO 27701 (Privacy Information Management)
Extends ISO 27001 to cover personal data protection. Required for providers handling KYC data, customer identity information, and transaction records subject to data protection regulations.

SOC 2 Type II (Operational Security Controls)
The most operationally significant certification for institutional due diligence. A SOC 2 Type II audit assesses security controls over a sustained period, typically 6 to 12 months, conducted by an independent auditor. This demonstrates consistent security maintenance, not a point-in-time snapshot.

Providers that cannot produce current SOC 2 Type II audit reports, or that offer only SOC 2 Type I certification, should be treated as unqualified for institutional onboarding until the gap is remediated.

Liminal holds ISO 27001, ISO 27701, and SOC 2 Type II certifications, supporting the security and compliance due diligence requirements of banks and regulated fintechs.

Critical questions to ask before onboarding any vendor

Before proceeding further, compliance and procurement teams should ask the following questions:

Once the evaluation framework narrows your provider shortlist, these questions confirm readiness before contract.

  1. What licenses do you hold in our operating jurisdictions?

Request documentation, not statements. Ask for MAS licensing details if you operate in Singapore, VARA licensing if you operate in the UAE, and equivalent documentation for any other jurisdiction. Providers that cannot produce specific license references are not institutionally ready.

  1. How is private key material stored, and who can access it?

Ask for technical specifications on key storage architecture. Confirm use of hardware security modules (HSMs). Determine whether key shares are distributed geographically. Identify who, technically and organizationally, can access key material. This question separates providers with genuine institutional architecture from those with consumer-grade infrastructure.

  1. What are your incident response SLAs for critical security events?

Operational disruptions, infrastructure outages, and security incidents will occur. Require written SLAs that specify maximum response times for critical incidents, including outside business hours. Do not accept verbal commitments.

  1. Can you demonstrate support for our specific settlement workflows?

Do not assume capability. Ask providers to confirm, in writing, support for your specific workflows: cross-chain atomic settlement, stablecoin staking, multi-currency treasury operations, or whichever apply. Request a technical demonstration if necessary.

  1. What current audit certifications do you hold, and can you share recent reports?

Request the most recent SOC 2 Type II report, ISO 27001 certificate, and ISO 27701 certificate. Ask for the audit period covered by the SOC 2 report. Providers unwilling to share audit documentation are not ready for institutional partnership.

How Liminal Custody can help

How Liminal Supports Institutional Stablecoin Custody

Liminal is a Singapore-based digital asset custody and wallet infrastructure platform serving banks, payment firms, exchanges, and regulated fintechs across APAC and MENA. The platform has supported over $100 billion in transaction volume.

MPC Wallet Infrastructure and HSM Vault
Liminal’s MPC-based wallet architecture eliminates single points of failure in private key management. For institutions requiring hardware-backed security, Liminal’s HSM Vault combines hardware security module protection with operational flexibility, supporting secure transaction signing at institutional scale.

Compliance Infrastructure
Liminal supports Travel Rule compliance, AML transaction monitoring, sanctions screening, and KYC workflow integration. The platform is certified to ISO 27001, ISO 27701, and SOC 2 Type II standards, meeting the security and privacy due diligence requirements of regulated financial institutions.

Governance Firewall
Liminal’s Governance Firewall enables institutions to configure role-based access controls, multi-level transaction approval workflows, policy-based transfer rules, and comprehensive audit trails. These controls support both internal governance requirements and external regulatory examinations.

The Bottom Line

Stablecoin custody selection is not a technology procurement decision. It determines regulatory compliance posture, operational resilience, transaction governance, and long-term business scalability.

The six-dimension framework in this guide (operational requirements, regulatory compliance, MPC architecture, transaction governance, security certifications, and vendor due diligence) gives treasury, compliance, and operations teams a structured evaluation methodology.

Banks and fintechs that evaluate custody infrastructure rigorously before deployment reduce regulatory exposure, minimize operational risk, and build the audit-ready governance structures that institutional growth requires.

If you are evaluating stablecoin custody infrastructure for your institution, [speak with Liminal’s solutions team] to walk through your specific requirements.

 

Frequently Asked Questions

What is stablecoin custody infrastructure and why does it matter for financial institutions?

Stablecoin custody infrastructure comprises the systems that store digital assets, manage cryptographic private keys, and authorize transactions on behalf of institutional clients. For financial institutions, it matters because stablecoin transactions are irreversible: there is no central authority that can recover funds lost through error or unauthorized transfer. Custody infrastructure is the primary control layer that prevents that outcome.

Traditional payment processors operate on reversible transaction rails with fraud chargebacks and central dispute resolution. Stablecoin custody operates on blockchain networks where transactions settle with permanent finality. This shifts the evaluation criteria from SLA metrics and chargeback procedures toward key management architecture, on-chain governance controls, regulatory licensing, and audit certifications.

MPC distributes private key material across multiple parties as cryptographic shares. No single party holds a complete key, and transaction signing requires collaborative computation across shares. For institutions, MPC eliminates single-point-of-failure risk in key management, supports operational continuity through personnel changes, and satisfies regulatory requirements for asset segregation and distributed control.

Institutional custody providers must support Travel Rule compliance (FATF Recommendation 16), automated AML transaction monitoring, real-time sanctions screening against OFAC and equivalent lists, and KYC integration. Providers operating in regulated markets must also hold jurisdiction-specific licenses or registrations relevant to the markets they serve. Always request current documentation rather than accepting general compliance statements.

More on Crypto

Stablecoin payment volumes crossed $9 trillion in 2025, a figure no longer surprising to treasury and operations teams at banks and fintechs….
August 27, 2026
Vietnam receives more money from abroad than most countries in the world. World Bank data places annual remittance inflows at USD 16–18 billion in 2024,…
August 21, 2026
Three years after legislator Chiang Yung-chang first introduced Taiwan’s dedicated virtual asset bill in 2023, the Virtual Asset Service Act (VASA) was passed by the Legislative Yuan on June 30, 2026, …
August 18, 2026

Find out what is the Ideal Custody Solution for you