• Home
  • Blog
  • Scaling digital asset capabilities without losing control of the operating model

Scaling digital asset capabilities without losing control of the operating model

Bitpanda

By Bitpanda

For many banks, fintechs, brokers and payment providers, the first digital asset service is deliberately focused. It may offer access to a limited set of crypto-assets through an existing customer interface, with external partners providing execution, liquidity or custody. The challenge changes as the offering expands. Adding custody, transfers, staking, stablecoin payments, tokenisation or new markets can introduce further processes, controls, systems and provider relationships. The operating model must then connect these elements to the institution’s customer journeys, data, reporting and incident processes.

In this context, the operating model covers the roles, processes, data, controls, technology and external relationships required to deliver the service. Its quality cannot be judged by counting providers or technical connections. The more relevant question is whether the complete service remains understandable and governable as it grows.

More capabilities create more interfaces to govern

Adding a digital asset capability involves more than connecting another API. Consider an institution extending an investment service to support crypto-asset transfers. A customer instruction must be authenticated and screened, passed to the relevant wallet or custody infrastructure, monitored on-chain and reflected in the customer account and internal records.

Problems can emerge when the systems involved do not use the same identifiers, transaction states or update times. A blockchain transfer may be confirmed while the custody platform still records it as pending. The custody record may then be correct before the customer-facing balance has been updated. If an exception occurs, the institution must establish which record is authoritative and which party is responsible for resolving it.

Research into tokenised financial markets illustrates how these interface problems can grow. The BIS and Committee on Payments and Market Infrastructures found that siloed token arrangements can require bilateral connections between platforms, increasing complexity, extending transaction chains and raising costs. The report concerns tokenised money and assets, but the broader operating lesson is applicable elsewhere. Connections that are designed independently create additional reconciliation and coordination work.

Diversification is different from fragmentation

Using several providers does not necessarily mean that the operating model is fragmented. An institution may separate execution from custody, use multiple custodians, retain backup infrastructure or work with specialists in different markets. These choices can distribute specific exposures and reduce reliance on one organisation.

The trade-off is visible in a 2026 institutional investor survey from EY-Parthenon and Coinbase. Among 317 respondents already invested in digital assets who answered the custody question, 61 percent used more than one custodian. Those considering a move to one custodian most frequently cited integration costs and easier vendor management. Those retaining or moving towards multiple custodians most frequently cited risk reduction.

The survey reflects institutional preferences rather than proving that one model produces better risk outcomes. Its respondents were institutional investors and the overall sample was weighted towards the United States. It nevertheless demonstrates why consolidation and diversification should not be treated as automatic improvements. They address different problems.

Provider count can also conceal concentration. The Basel Committee’s 2025 principles for managing third-party risk explain that concentration can arise when several services are provided by one company, when providers operate in the same region or when apparently separate providers rely on the same underlying party. The principles are directed primarily at large internationally active banks and their supervisors, although the Basel Committee notes that other financial institutions may also find them useful.

A coherent multi-provider model assigns a clear purpose to each relationship and governs the connections between them. Fragmentation begins when information, controls, responsibilities or dependencies become disconnected.

Four characteristics of a coherent operating model

Regulatory and industry frameworks do not prescribe one universal operating model for all digital asset services. However, recurring requirements around record integrity, accountability, dependency mapping, operational resilience and controlled change appear across the IOSCO recommendations for crypto and digital asset markets, the Basel Committee’s principles for managing third-party risk and the Digital Asset Securities Control Principles developed by DTCC, Clearstream and Euroclear with BCG. Drawing these themes together, four practical characteristics can help institutions assess whether an expanding digital asset service remains coherent.

Data remains consistent across the transaction lifecycle

The institution should be able to follow a customer instruction through execution, settlement, custody and reporting without manually reconstructing the journey. This requires consistent identifiers, defined transaction states and clarity about which record is authoritative at each stage.

The requirement is particularly important in custody. Under Article 75 of MiCA, crypto-asset service providers offering custody must maintain a register of positions for each client and record movements affecting those positions. They must also establish procedures for safeguarding and returning client assets and maintain legal and operational segregation between client holdings and their own assets.

For digital securities, DTCC, Clearstream, Euroclear and Boston Consulting Group describe interoperability as preserving asset integrity, ownership rights, lifecycle and legal treatment across traditional and distributed ledgers. Although narrower than a complete operating model, this provides a useful standard. The same asset should produce the same rights and outcome wherever it is recorded.

Accountability remains clear when activities are distributed

External provision does not remove the institution’s responsibility for the service it offers. Responsibilities can be allocated between internal teams and providers, but ownership of the complete customer outcome cannot be left ambiguous. This principle is explicit under Article 73 of MiCA. A crypto-asset service provider that outsources operational functions remains fully responsible for its obligations. It must retain the expertise and resources needed to supervise the outsourced service, maintain access to relevant information and establish contingency and exit arrangements.

The Basel Committee applies a similar principle to banks within the scope of its third-party risk guidance. Using external providers must not diminish a bank’s responsibility to its customers, supervisors and other authorities.

Making accountability operational requires more than assigning contractual liability. The operating model should define who monitors the complete process, investigates exceptions, coordinates incidents, communicates with customers and confirms that service has been restored.

Critical dependencies are visible

A direct provider may rely on cloud infrastructure, market venues, liquidity sources, data providers, sub-custodians or other technical services. Several primary providers may also depend on the same underlying infrastructure, limiting the diversification that the institution expected to achieve.

The Basel Committee’s 2025 principles ask banks within their scope to maintain information on criticality, substitutability, contingent providers and key underlying parties. This information can help identify common dependencies that may not be visible from the primary contracts alone.

EU requirements address the same issue for ICT services. DORA requires financial entities to maintain information on contractual arrangements with ICT third-party providers. The related European Commission standards require institutions to consider subcontracting, provider and geographic concentration, data location, service transferability and the effect of disruption when ICT supports a critical or important function.

This does not require every supplier in the wider market to be mapped to the same level. The depth of oversight should reflect the importance of the service and the potential consequences of failure.

The model can change without being redesigned from the beginning

Scalability does not mean that a new asset, market or capability can be introduced under unchanged controls. Different products can create new custody, liquidity, financial-crime, conduct or regulatory requirements. A scalable operating model allows the existing governance and control framework to be extended without rebuilding it from the ground up.

The same principle applies when a provider or technical component must be replaced. The Basel Committee states that exit plans for critical third-party arrangements should address the transfer of data, applications, APIs, records and relevant rights in an appropriate format. MiCA requires CASPs outsourcing operational functions to maintain contingency plans and exit strategies, while the DORA standards require documented and periodically tested exit plans for critical ICT arrangements.

A component is not meaningfully replaceable if the institution cannot recover its records, reproduce its controls or transfer the service within an acceptable period. Exit planning therefore needs to be considered during architecture and procurement, rather than when the relationship is already ending.

Integration should be assessed by the dependencies it creates

Closer integration can reduce duplicated interfaces, reconciliation work and the number of relationships an institution must coordinate. It can also concentrate reliance on a provider, platform or orchestration layer.

The Bank of England’s DLT Innovation Challenge found that interoperability solutions often shift trust and operational dependencies between systems instead of removing them. Middleware can make several platforms easier to connect while becoming an important point of coordination and control itself.

The same trade-off applies to provider strategy. A single integrated relationship may reduce coordination work while increasing the effect of a provider failure. A multi-provider model may distribute selected exposures while creating more interfaces to manage. Integration should therefore be assessed by the dependencies it creates as well as the connections it simplifies.

A more useful measure of scalability

A digital asset operating model is scalable when new capabilities can be added without obscuring the transaction lifecycle, weakening accountability or creating dependencies that the institution cannot manage.

Neither consolidation nor diversification guarantees that outcome. What matters is whether records remain consistent, responsibilities are explicit, critical dependencies are visible and individual components can be adapted or replaced without losing control of the complete service. This provides a more reliable measure of scalability than the number of providers, APIs or supported assets.

Talk to our team about building a digital asset operating model that can support your next stage of growth.

Disclaimer:

This is a marketing communication. Crypto investments are volatile and carry a risk of loss. Crypto-asset services are provided by Bitpanda GmbH (FN 569240v), authorised by the Austrian Financial Market Authority (FMA) in accordance with Regulation (EU) 2023/1114 (MiCAR). Stella-Klein-Löw-Weg 17, AT-1020 Vienna.

Bitpanda

Bitpanda