Designing risk management frameworks for digital assets: why adapting your TradFi model is not enough
SYSC risk management and systems-and-controls requirements in the FCA Handbook, the FCA's proposed prudential and conduct regime for cryptoassets within the crypto roadmap (consultation stage, with the cryptoasset perimeter expected to come into force in 2027), and the operational resilience expectations in SYSC 15A.
When a firm starts dealing in digital assets, the instinct I see most often is to take the risk management framework that already works for traditional assets and stretch it to cover the new ones. It’s the natural move, and it’s the wrong one. Digital assets don’t just add new instruments to an existing risk picture. They introduce categories of risk with no equivalent in traditional finance, and they take away some of the stabilisers that conventional risk models depend on without ever having to think about them. A framework built for equities and bonds won’t break loudly when you point it at crypto. It will look like it’s working while missing the risks that can take the firm down, and that is the more dangerous outcome.
Start with the stabilisers that conventional risk management takes for granted and that crypto doesn’t have. A traditional risk model is built around anchors of value: an equity has earnings, a bond has cash flows, and a discounted-cash-flow valuation gives the risk function a reference point for judging whether a price move is noise or signal. Many digital assets have no such anchor. No earnings reports, no coupon, no intrinsic cash flow to discount. The price can move on sentiment alone with nothing to pull it back, and the risk function loses the valuation reference it builds everything else on top of.
Then there’s market structure. A traditional model assumes that in a stress you can execute, that there’s a deep, consolidated market to sell into. Crypto liquidity is fragmented across many exchanges and on-chain venues, and a stress is exactly when that fragmentation does the most damage: liquidity that looked adequate when you summed it across venues turns out to be shallow on each one individually, right when you need to trade. In crypto, execution risk is structural rather than a tail event.
And the counterparties are different. A traditional framework assumes counterparties that are regulated, capitalised and subject to known prudential rules. In crypto a firm can face unregulated exchanges and protocols with no capital requirements, no prudential oversight, and in some cases no identifiable legal entity at all. Counterparty assessment built around credit ratings and regulatory capital has nothing to grip onto. The framework fails because three assumptions don’t hold in crypto: anchored value, executable liquidity and regulated counterparties.
Digital assets bring risk categories with no conventional analogue, which a framework has to name as first-class risks.
Protocol-level risk is the risk that the underlying blockchain itself is compromised. The clearest case is a 51 percent attack, where a single party gains enough of a network’s mining or staking power to rewrite recent transaction history, as happened to Ethereum Classic. For an asset whose entire value rests on the integrity of its ledger, an attack on that ledger is existential, with no equivalent in a market for company shares.
Smart contract risk is the risk that the code governing an asset or protocol contains a vulnerability or a flawed incentive mechanism. So much of crypto runs on self-executing contracts holding real value that a bug is a direct route to loss, and the code is often public, so attackers can study it at leisure.
Oracle risk is the risk that the external data feed a protocol relies on for prices can be manipulated. The Mango Markets exploit, where an attacker gamed the price feed to drain over 100 million dollars, is the textbook case: the protocol behaved exactly as coded, on a price that had been rigged.
Bridge risk is the risk in the cross-chain infrastructure that moves assets between blockchains. It’s been one of the most exploited points in the whole market, with billions stolen over the years and the Ronin bridge loss of around 600 million dollars among the largest. Maximal extractable value, or MEV, is the risk that validators reorder transactions to extract value at a firm’s expense, manipulation built into the infrastructure. And funding risk is the plain but serious point that there’s no deposit protection: no FSCS, no FDIC, so when a platform fails, client assets can just be gone, as a string of exchange and lender collapses has shown.
Even risks that do have traditional analogues behave differently in crypto, because two accelerants turn ordinary stress into fast contagion. The first is sentiment, amplified by social media. Crypto prices are driven by narrative and crowd behaviour to a degree with no real parallel, and a coordinated social wave can move a market faster than any risk system built around quarterly fundamentals can respond.
The second is interconnectedness inside the market. Protocols are composable: they build on and depend on each other, so a failure in one can cascade through everything that relied on it. The collapse of Terra and its Luna token is the defining example. An algorithmic stablecoin lost its peg, and the failure spread through lenders, funds and other protocols exposed to it, wiping out a large part of the market in days. A risk framework for digital assets has to model contagion that moves in hours and days, not the slower transmission a traditional framework assumes, because the interconnections are tighter and the reaction times are faster.
A fit-for-purpose framework keeps the discipline of traditional risk management and rebuilds it on assumptions that hold in this market. A few components matter most.
A specialised risk taxonomy comes first. The framework has to include protocol, smart contract, oracle, bridge, MEV and funding risk as first-class categories with owners, limits and monitoring, rather than folding them vaguely into operational risk. Scenario analysis has to be built for fast contagion: stress-testing not just a price fall but the failure of a major stablecoin, the collapse of a key counterparty, or the exploit of a protocol the firm depends on, with the speed of transmission taken seriously rather than assumed away.
In crypto, whoever controls the private keys controls the asset, which makes key management foundational. The framework has to cover how keys are generated, stored and used, the split between hot and cold storage, multi-signature and multi-party computation arrangements, and what happens if a key is lost or compromised, because a custody failure here isn’t a reconciliation break. It’s permanent loss. Counterparty due diligence has to be rebuilt for a world of unregulated venues, testing the operational soundness, governance and proof of reserves of exchanges and protocols rather than relying on a regulatory status that often doesn’t exist. And liquidity strategy has to be fragmentation-aware, planning execution across venues and accepting that aggregate liquidity overstates what’s really available in a stress.
In digital assets, custody determines whether the firm owns its assets at all. In traditional finance, an asset held at a custodian is recoverable even if the records are imperfect, because there’s a legal and infrastructural chain of ownership that can be reconstructed. In crypto, possession of the private key is possession of the asset. A lost key means the asset is unrecoverable; a stolen key means an irreversible transfer; a failed custodian can leave the firm’s claim worthless. The sector’s failures have often been custody failures: commingled client assets, rehypothecated holdings, and collapses that left clients as unsecured creditors.
A serious framework treats key management as a first-order risk with board-level visibility. It looks at how keys are generated and whether that process can be trusted, how they’re stored across hot wallets for operational liquidity and cold storage for the bulk of holdings, whether multi-signature or multi-party computation arrangements stop any single person or system from moving assets alone, and what the recovery and succession plan is if a key holder becomes unavailable. It also asks whether assets held with a third-party custodian or exchange are segregated and bankruptcy-remote, or whether the firm is really an unsecured creditor dressed up as an asset holder. The incoming regime reinforces this, putting significant weight on safeguarding client cryptoassets, because the regulator has watched the same custody failures the market has. A firm that can’t describe its key controls in detail may not actually own the assets it reports.
Building ahead of the rules costs money, but the framework has to be in place before the rules apply. The FCA’s crypto roadmap sets out a phased path towards a full regulatory perimeter for cryptoassets, expected to take effect in 2027, covering prudential treatment, conduct, custody and market integrity. Internationally, the Basel Committee has finalised a prudential treatment for banks’ cryptoasset exposures that applies punitive capital treatment to the riskiest, unbacked crypto, a signal of how seriously prudential regulators now take these assets. The FCA’s roadmap and the Basel treatment point to a demanding framework covering digital-asset-specific risks.
Building the framework now means doing it on your own timeline rather than under deadline pressure. A firm that waits faces the harder job of building real capability while trying to demonstrate compliance at the same time, which is the worst order in which to do it. The risk framework is the base that authorisation, prudential adequacy and conduct compliance in crypto will all sit on.
The categories with no clean traditional analogue, and the control each one calls for.
| Risk category | Traditional analogue | Illustrative event | Framework response |
|---|---|---|---|
| Protocol-level | None | Ethereum Classic 51% attack | Network security monitoring, chain selection criteria |
| Smart contract | None | Numerous DeFi exploits | Code audit requirements, exposure limits per protocol |
| Oracle | None | Mango Markets (100m+) | Oracle dependency mapping, price-feed diversity |
| Bridge | None | Ronin bridge (600m) | Minimise bridge use, limit assets in transit |
| MEV | None | Sandwich and front-running | Execution protection, private order routing |
| Funding / no deposit protection | Partial (bank failure) | Exchange and lender collapses | Custody control, counterparty diligence, asset segregation |
Take a firm with exposure to a yield-bearing protocol that depends on a particular stablecoin, with assets custodied partly on an exchange and trading run across three venues. A traditional risk framework looks at the position size, the historical volatility and the counterparty’s published financials, decides the exposure is within appetite, and moves on.
A crypto-native framework asks the questions the traditional one can’t. What happens if that stablecoin loses its peg: which of the firm’s positions depend on it directly, and which depend on protocols that themselves depend on it? That’s the composability question. If the exchange holding the custodied assets froze withdrawals tomorrow, the way several have, what would the firm recover, and are the keys to the rest under the firm’s control? If all three trading venues thinned out at once in a stress, the way fragmented liquidity tends to, could the firm exit anywhere near the marks it’s carrying? The framework has already modelled these as connected events, because in crypto they tend to arrive together, and it has set limits and controls to match: a cap on exposure routed through any single stablecoin, a custody arrangement that doesn’t rely wholly on one exchange, and a liquidity plan that doesn’t assume aggregate depth.
The traditional framework measured the right position but asked the wrong market’s questions. A crypto-native framework can get the firm out of positions when the market turns, not just log exposures.
This insight is provided for general informational purposes only and doesn’t constitute legal, investment, or regulatory advice.