How Banks and Fintechs Should Evaluate Stablecoin Wallet and Custody Infrastructure
Stablecoin payment volumes crossed $9 trillion in 2025, a figure no longer surprising to treasury and operations teams at banks and fintechs. What remains to be worked out is how to select custody infrastructure that meets institutional security standards, satisfies regulators across MAS, VARA, and ADGM jurisdictions, and scales with transaction volume. This guide provides a structured framework for that evaluation.
JPMorgan projects the stablecoin market will reach $500 billion by 2028. Chainalysis estimates stablecoins moved $28 trillion in economic transactions in 2025. For banks, payment firms, and regulated fintechs, this is no longer a forward-looking use case. It is current infrastructure. The question has shifted from whether to adopt stablecoin rails to which custody infrastructure can support institutional-grade operations.
This guide covers six evaluation dimensions: operational requirements, regulatory compliance, MPC wallet architecture, transaction governance, security certifications, and vendor due diligence. Each section includes specific questions institutions should ask before selecting a custody provider.
Why Stablecoin Custody Has Become a Board-Level Decision
Recent market data highlights the importance of stablecoins in the global market. According to a 2025 Chainalysis report, stablecoins are estimated to have moved $28 trillion in economic transactions. This number is expected to reach $1.5 quadrillion by 2035, surpassing the value of the global market for cross-border payments today.
Stablecoins are being used across industries for cross-border payments, treasury management, liquidity optimisation, and institutional settlement.
Regulatory frameworks across key digital asset markets are increasingly formalizing custody requirements. Jurisdictions spanning Asia-Pacific and the Middle East have introduced rules that go beyond permitting stablecoin use to specifying how institutions must manage and safeguard the underlying assets. For banks and fintechs operating in these markets, custody infrastructure is no longer an internal choice. It is a compliance obligation shaped by the regulatory environment they operate in
As regulatory frameworks continue to evolve, stablecoin custody has become a priority for businesses. CEOs and CFOs are examining custody infrastructure to meet compliance expectations, while auditors now place greater emphasis on governance, security controls, and custody practices.
Questions to Answer Before Evaluating Custody Providers
Treasury and operations leadership must address four fundamental questions before vendor evaluation. These questions define the operational and compliance scope before any vendor conversation begins.
- What settlement workflows do we need to support?
Organisations must be clear about the operational necessities. These necessities may range from instant settlement of stablecoin trades to staking stablecoins, where customers receive dividends. They may also include treasury management for individuals as well as atomic settlements between different blockchains.
Different operational processes imply that the required infrastructure will also differ. For example, the infrastructure required by a financial institution dealing with cross-border payments is not the same as that needed by a financial tech company providing stablecoin yield.
- What regulatory regimes do we operate under?
Regulatory requirements vary significantly by jurisdiction. Before shortlisting any provider, map the regulatory environments your institution operates in and confirm that the provider has experience serving clients in those markets. Ask for documentation of how they support compliance in each relevant jurisdiction, what licenses or registrations they hold where applicable, and how they stay current as regulations evolve. A provider that cannot answer these questions with specifics is not ready for institutional deployment in regulated markets.
- What transaction approval controls do our governance policies require?
Approval controls should reflect an organisation’s governance policies and risk management requirements. Sometimes board rules require multiple parties to approve a transaction before any significant amount of money can be transferred. In other cases, risk management procedures establish limits on the speed of particular transactions. Lastly, an institution needs to maintain efficient internal controls and appropriate enterprise custody capabilities.
- What are the provider’s operational resilience and recovery commitments?
Organisations should check how a vendor responds to operational disruptions such as infrastructure outages, cyber incidents, or financial distress. This includes a clear understanding of asset recovery procedures, business continuity plans, disaster recovery capabilities, and incident response commitments.
Learn More – How Do Stablecoins Reduce Costs and Delays in Cross-Border Payments
Custody Architecture Evaluation: Multi-Party Computation Wallet Significance
Financial institutions should evaluate two leading technical methodologies: multisignature wallet architecture and Multi-Party Computation (MPC) wallet architecture.
Multisignature (Multisig) Wallet Architecture
Multisig wallets require a defined number of co-signers, for example, 2-of-3 or 3-of-5, to authorise each transaction. Each co-signer holds a complete, independent private key. The wallet executes the transaction once it collects the required signatures.
Multisig has known limitations for institutional use. Each co-signer key is a discrete attack surface. Key rotation requires on-chain transactions, creating operational overhead. Some blockchain networks have limited or inconsistent multisig support, constraining multi-chain treasury operations.
Multi-Party Computation Wallet Architecture
MPC wallet architecture distributes private key material across multiple parties as cryptographic shares. No single share constitutes a usable key. Transaction signing is performed collaboratively through a cryptographic protocol, producing a valid signature without ever reconstructing the complete key in any single location.
For institutional implementation, MPC architecture addresses three specific requirements:
Operational continuity. Key shares can be reassigned when personnel change, without disrupting wallet operations or requiring on-chain key rotation.
Single-point-of-failure elimination. No individual, device, or system holds a complete private key. Compromise of one share does not compromise the wallet.
Regulatory alignment. MPC architecture supports asset segregation and distributed control requirements that institutional regulators and auditors across regulated digital asset markets commonly expect.
Liminal’s MPC wallet infrastructure combines threshold signature schemes with HSM Vault capabilities, allowing institutions to choose the security model appropriate to their operational profile.
Compliance Infrastructure: What Institutional Custody Providers Must Support
A provider’s compliance capabilities determine whether they can comply with institutional requirements. If compliance infrastructure is not sufficient, vendors will be disqualified regardless of technology.
Compliance capability gaps disqualify a provider regardless of their technical architecture. Evaluate each of the following:
Travel Rule Compliance
FATF Recommendation 16 requires VASPs and financial institutions to share originator and beneficiary information when transferring digital assets above threshold amounts. Providers must support automated counterparty identification, secure data transmission to recipient VASPs, and audit trail generation. Ask which Travel Rule protocol the provider supports (for example, IVMS 101 standard) and which VASP directories they are integrated with.
AML Transaction Monitoring
Institutional transaction volumes make manual monitoring impractical. Providers must offer automated on-chain transaction screening, risk scoring, and suspicious activity flagging integrated with your compliance workflows. Confirm whether the provider’s monitoring covers both on-chain activity and fiat on-ramp/off-ramp transactions.
Sanctions Screening
Providers must screen wallet addresses and counterparties against OFAC, UN, EU, and jurisdiction-specific sanctions lists in real time. Confirm that screening is applied pre-transaction, not retrospectively.
KYC Integration
KYC must be embedded in the custody workflow, not treated as a separate process. Providers should support integration with your existing identity verification systems and maintain customer risk profiles linked to wallet activity.
Regulatory Licensing
Ask for specific license documentation, not general compliance statements. Confirm which licenses or regulatory registrations the provider holds in the jurisdictions where you operate, and verify that these are current. Providers that respond with broad claims about regulatory awareness rather than specific documentation are not ready for institutional onboarding in regulated markets.
Transaction Policy Governance: Institutional Safeguard Architecture
Stablecoin transactions are irreversible. Once a transaction is confirmed on-chain, no legal mechanism, central authority, or chargeback process can retrieve the funds. The transaction policy layer is the final institutional control before that finality takes effect.
Institutional custody platforms should allow organisations to define and enforce the following policy types:
- Multi-party approval thresholds: Require 2-of-3 or higher approval for transactions above defined value limits.
- Allowlist enforcement: Restrict outbound transfers to pre-approved wallet addresses only.
- Velocity controls: Cap the volume or frequency of transfers within defined time windows.
- Cross-border authorisation: Apply additional approval requirements for international transfers.
- Role-based access: Assign initiator, approver, and auditor roles with distinct permissions.
These controls serve three institutional purposes: preventing unauthorised transfers, catching operational errors before they become permanent, and generating the audit documentation that regulatory examinations require.
Security Certifications: What Institutional Custody Providers Must Hold
Three certifications define the baseline security and privacy standard for institutional custody providers:
ISO 27001 (Information Security Management)
Confirms the provider has implemented a documented, audited information security management system. ISO 27001 certification demonstrates that security controls are systematic and maintained, not ad hoc.
ISO 27701 (Privacy Information Management)
Extends ISO 27001 to cover personal data protection. Required for providers handling KYC data, customer identity information, and transaction records subject to data protection regulations.
SOC 2 Type II (Operational Security Controls)
The most operationally significant certification for institutional due diligence. A SOC 2 Type II audit assesses security controls over a sustained period, typically 6 to 12 months, conducted by an independent auditor. This demonstrates consistent security maintenance, not a point-in-time snapshot.
Providers that cannot produce current SOC 2 Type II audit reports, or that offer only SOC 2 Type I certification, should be treated as unqualified for institutional onboarding until the gap is remediated.
Liminal holds ISO 27001, ISO 27701, and SOC 2 Type II certifications, supporting the security and compliance due diligence requirements of banks and regulated fintechs.
Critical questions to ask before onboarding any vendor
Before proceeding further, compliance and procurement teams should ask the following questions:
Once the evaluation framework narrows your provider shortlist, these questions confirm readiness before contract.
- What licenses do you hold in our operating jurisdictions?
Request documentation, not statements. Ask for MAS licensing details if you operate in Singapore, VARA licensing if you operate in the UAE, and equivalent documentation for any other jurisdiction. Providers that cannot produce specific license references are not institutionally ready.
- How is private key material stored, and who can access it?
Ask for technical specifications on key storage architecture. Confirm use of hardware security modules (HSMs). Determine whether key shares are distributed geographically. Identify who, technically and organizationally, can access key material. This question separates providers with genuine institutional architecture from those with consumer-grade infrastructure.
- What are your incident response SLAs for critical security events?
Operational disruptions, infrastructure outages, and security incidents will occur. Require written SLAs that specify maximum response times for critical incidents, including outside business hours. Do not accept verbal commitments.
- Can you demonstrate support for our specific settlement workflows?
Do not assume capability. Ask providers to confirm, in writing, support for your specific workflows: cross-chain atomic settlement, stablecoin staking, multi-currency treasury operations, or whichever apply. Request a technical demonstration if necessary.
- What current audit certifications do you hold, and can you share recent reports?
Request the most recent SOC 2 Type II report, ISO 27001 certificate, and ISO 27701 certificate. Ask for the audit period covered by the SOC 2 report. Providers unwilling to share audit documentation are not ready for institutional partnership.
How Liminal Custody can help
How Liminal Supports Institutional Stablecoin Custody
Liminal is a Singapore-based digital asset custody and wallet infrastructure platform serving banks, payment firms, exchanges, and regulated fintechs across APAC and MENA. The platform has supported over $100 billion in transaction volume.
MPC Wallet Infrastructure and HSM Vault
Liminal’s MPC-based wallet architecture eliminates single points of failure in private key management. For institutions requiring hardware-backed security, Liminal’s HSM Vault combines hardware security module protection with operational flexibility, supporting secure transaction signing at institutional scale.
Compliance Infrastructure
Liminal supports Travel Rule compliance, AML transaction monitoring, sanctions screening, and KYC workflow integration. The platform is certified to ISO 27001, ISO 27701, and SOC 2 Type II standards, meeting the security and privacy due diligence requirements of regulated financial institutions.
Governance Firewall
Liminal’s Governance Firewall enables institutions to configure role-based access controls, multi-level transaction approval workflows, policy-based transfer rules, and comprehensive audit trails. These controls support both internal governance requirements and external regulatory examinations.
The Bottom Line
Stablecoin custody selection is not a technology procurement decision. It determines regulatory compliance posture, operational resilience, transaction governance, and long-term business scalability.
The six-dimension framework in this guide (operational requirements, regulatory compliance, MPC architecture, transaction governance, security certifications, and vendor due diligence) gives treasury, compliance, and operations teams a structured evaluation methodology.
Banks and fintechs that evaluate custody infrastructure rigorously before deployment reduce regulatory exposure, minimize operational risk, and build the audit-ready governance structures that institutional growth requires.
If you are evaluating stablecoin custody infrastructure for your institution, [speak with Liminal’s solutions team] to walk through your specific requirements.