Why leading institutions are adopting the sub-custody model
Elise Devaux
Marketing Manager, TanganyNot all institutions can operate in every market alone, so many turn to a sub-custodian: a local specialist entrusted to hold assets on their behalf. In traditional finance, this model gives institutions access to expertise and risk controls that would otherwise take years to replicate internally.
In the digital asset ecosystem, the sub-custody model allows a licensed institution to outsource the infrastructure and processes of digital asset custody, such as key storage, security infrastructure and blockchain integration, to a trusted regulated provider.
This model is often adopted by banks, brokers or funds who secured authorizations to enter the crypto market but don’t want to immediately build the technical infrastructure and expertise demanded for the custody of digital assets.
Whether it’s to quickly answer client demand for new investment products or enable cross-border settlement on new rails with limited risks, sub-custody can be a simpler and accelerated path to offering digital asset custody services.
The operational challenges of digital asset custody today
Digital asset custody carries operational requirements that don't have a direct equivalent in traditional custody. Firstly, digital asset custody requires a specialized security model built around protecting private keys, the cryptographic credentials that control access to an institution's holdings and cannot be recovered if lost.
Secondly, transactions are irreversible once confirmed, which raises the stakes on every operational failure mode, demanding round-the-clock monitoring and incident response.
Additionally, blockchain integration has to be built and maintained separately for each supported asset and chain. And the obligations under the European regulatory framework for digital assets (MiCA) are new enough that few institutions have in-house precedent to draw on.
This is why licensed-instituations choose to work with a sub-custodian instead, an outsourcing arrangement explicitly enabled under MiCA.
Operating with a sub-custodian in practice
MiCA’s Article 73 enables authorized providers to outsource operational functions, such as custody, to third parties, provided they remain fully responsible for their obligations and the relationship with the end client stays unchanged.
In practice, the relationship runs on two separate arrangements: one between you and your end client and one between you and the sub-custodian. You keep the direct client interface, transaction reporting, and regulatory reporting, while the sub-custodian handles private key storage and the underlying security infrastructure (cold, warm, or hot wallet), blockchain integration for each supported asset and chain, day-to-day operational risk, and adjacent functions like transaction bookkeeping.
Regulatory liability to the end client stays with you as the license holder while the sub-custodian carries the operational risk and the contractual and insurance liability. Within this outsourcing arrangement, client assets are held separately from the sub-custodian's own balance sheet, and separately from other clients' holdings.
For institutions under German banking supervision, the arrangement is additionally assessed under their own MaRisk and §25b KWG framework, sub-custody sits within that governance.
By engaging a sub-custodian, institutions can offer digital asset services without the years of build time, security investment, expert knowledge, and specialized resources that running custody in-house demands.
When you should consider building in-house vs finding a partner
Sub-custody fits most institutions weighing this decision, but building still makes sense in specific circumstances. If:
Your volume is concentrated in one or two dominant assets: On bigger scale, dedicated infrastructure becomes a durable cost advantage rather than a one-off project
Custody itself is the product you're building, not a supporting function behind a different core business
A specific regulatory, sovereignty, or data residency requirement demands full operational control, not just legal responsibility
Sub-custody fits when speed to market matters more than ownership. For example, when you need to launch and test a new product fast, a multi-month build is sometimes not the relevant strategy.
It also fits the long tail: supporting every asset a client might eventually ask for isn't worth a dedicated build if usage stays low, so outsourcing the tail while keeping a core build in-house is a common middle path.
The same logic applies to new or exotic chains, each one needs its own integration, security review, and operational learning curve, and to low-volume or unproven use cases, where fixed infrastructure cost shouldn't be tied to uncertain demand.
Why institutions choose sub-custody over building their own infrastructure
Every institution weighs this decision differently, but sub-custody delivers on the metrics that matter most: cost, risk, scalability, and time-to-market.
1) Cost optimization
The headline infrastructure cost rarely covers everything that has to sit around it. Sub-custody removes the need to build or fund:
Security infrastructure (HSMs, MPC systems, key management hardware)
Compliance and licensing overhead for the custody function itself (AML/KYC, ongoing audits)
Transaction monitoring and Travel Rule tooling
24/7 operations staffing
Per-asset integration engineering, turning a fixed cost into one that scales with usage
Custody-specific insurance against theft, fraud, and hacking
High-upfront investment vs. lower initial costs
Security infrastructure, licensing, staffing, and insurance all get funded at roughly the same level whether year one brings ten clients or ten thousand. This capital commitment typically runs into the seven or eight figures before a single client asset can be held. Sub-custody converts the same coverage into a fee tied to actual usage, the institution pays for custody activity as it happens.
2) Risk mitigation
Custody carries several operational risks that can materialize independently of how well you're regulated. A sub-custodian's core business is preventing and insuring against them, raising the security bar of the infrastructure they provide
Key loss or mismanagement: allocated by contract to whoever runs the signing infrastructure
Insider risk: segregation of duties sits inside the sub-custodian's operations
Hacking and theft: covered contractually and typically by the partner's insurance
Operational execution errors: irreversible on-chain mistakes are a named failure mode, not an open question
Regulatory responsibility stays with you as license holder, but each operational risk has a named, accountable owner
Risk and insurance policy
Tangany's digital asset custody is backed by a Munich Re crime insurance policy, described as the first of its kind in the German market, alongside Professional Indemnity coverage for key-management failures and additional insurance carried by its wallet infrastructure providers.
3) Increased scalability
Each stage of growth, whether it’s more clients, new markets or new assets, tends to outgrow the infrastructure built for the stage before it. Sub-custody absorbs that growth.
Client and account growth is a change in volume and fees rather infrastructure
Adding new asset classes doesn’t require new internal security review or engineering.
Cross-border expansion doesn't require standing up separate infrastructure
Demand spikes are absorbed by infrastructure built for institutional scale
New product lines (staking, tokenization) can launch on existing infrastructure
Scalability across asset classes
Tangany supports more than 450+ cryptocurrencies plus tokenized assets and EUR/USD stablecoins, covering most of the top 100 by market cap, across standard and exotic chains (FET, CSPR, KAS, SEI, SUI, TAO, VET). Once an asset is confirmed feasible, it's typically enabled within about five working days.
4) Faster time-to-market
Custody infrastructure has a long lead time before it can hold a single client asset. Sub-custody removes that lead time from your own roadmap.
Save time on the design and build phase for HSM/MPC infrastructure entirely.
No repeat audit and penetration testing cycle before launch
Technical groundwork for MiCA's outsourcing requirements is already in place
When it comes to per-chain integration time, adding a new asset is an API call away
Limit resources spent on recruiting specialized custody security engineers
Reduced time-to-market
Across 80 projects, Tangany has brought institutions live within 3 to 5 months, against 9 to 12 months typical for building custody infrastructure in-house from scratch. Institutions migrating from a legacy custodian have gone live in under a month.
Those advantages add up to a straightforward case: sub-custody is a MiCA-enabled path to offering digital asset custody. The right choice still depends on an institution's volume, assets, and long-term ambitions, but where time, resources, or specialized expertise are the binding constraint, sub-custody offers a faster, lower-risk way to get there.
Sub-custody with Tangany
Whether you're launching your first digital asset product or adding to an existing offering, we can scope what sub-custody looks like for your specific case. We've worked with banks including Baader Bank, dwpbank, and FlatexDEGIRO Bank, alongside asset managers and corporates such as Exporo.
Read more
Keep learning and keep reading
Stay informed on the world of crypto regulation and read the latest about Tangany.