Operational due diligence has always been about a single question: does what the manager says happens match what actually happens? That question doesn't change in digital assets. What changes is where the answers hide.
The traditional framework relies on a set of independent intermediaries. A prime broker holds positions and confirms them. A custodian bank segregates assets. A transfer agent processes subscriptions. An administrator strikes NAV against third-party data. Each of those parties absorbs some risk, and each provides an independent point of verification.
In digital assets, several of those parties may be absent, materially weaker, or performed by an affiliate of the manager. The risk they used to absorb does not disappear. It relocates — usually much closer to the investment team.
Why traditional frameworks fall short
Applying an unmodified hedge fund ODD questionnaire to a digital asset manager produces a review that looks thorough and tests very little. The questions assume infrastructure that may not exist.
Four structural differences drive this:
- Settlement is final and irreversible. There is no correspondent bank to reverse an erroneous transfer, no chargeback, no clearing house unwinding a failed trade. An operational error is a permanent loss.
- Control of assets can be genuinely unilateral. A private key is bearer authority. Whoever holds it can move the asset, without a counterparty's cooperation and without anyone's approval.
- Venues carry credit risk, not just execution risk. Assets held at a trading venue are, in most cases, an unsecured claim against that venue. Recent history has made the consequences of this concrete.
- The 24/7 market has no natural control point. There is no close, no settlement window, no overnight batch. Controls that assume a daily cycle don't map cleanly.
Custody and key management
This is the centre of the review. If you have limited time, spend it here.
Establish who can actually move assets
Not who is supposed to be able to — who can. The distinction between a qualified custodian, a technology provider offering wallet infrastructure, and self-custody with institutional tooling is frequently blurred in marketing material and rarely blurred in the underlying agreements. Read the agreements.
Specific areas to establish:
- Custody model. Qualified custodian, MPC-based infrastructure, multi-signature arrangements, or direct self-custody — and the split across them, since most managers use more than one.
- Key generation and ceremony. How keys were generated, who was present, what was documented, whether the process was observed independently.
- Quorum structure. How many signers are required, who they are, and — critically — whether any single individual controls enough to move assets alone.
- Signer independence. Whether signers sit inside the investment team, whether any are genuinely independent, and what happens if a signer leaves or is unavailable.
- Backup and recovery. Where seed material and backups are held, in what form, who can access them, and whether recovery has ever been tested end to end.
- Withdrawal controls. Address allowlisting, time delays on new addresses, transaction limits, and out-of-band confirmation for large transfers.
Ask the manager to walk through, step by step, exactly what would need to happen for one million dollars to leave the fund and reach an address nobody authorised. The quality and specificity of that answer tells you more than any questionnaire response. Managers with real controls answer it fluently. Managers without them get uncomfortable.
Verify independently
Digital assets offer a verification advantage that has no analogue in traditional markets: you can confirm balances directly on-chain. Use it — but understand its limits.
On-chain confirmation tells you an address holds a balance. It does not tell you who controls the keys to that address, whether the address belongs to the fund rather than an affiliate or a third party, or what off-chain obligations exist against that balance. A borrowed asset and an owned asset look identical on-chain.
Valuation
Liquid, exchange-traded assets with deep order books present a manageable valuation problem. Most of what causes disputes sits outside that category.
Areas that warrant attention:
- Pricing sources and hierarchy. Which venues, which index providers, what happens when sources diverge materially, and who decides.
- Timing convention. In a market with no close, the chosen valuation point is a policy decision. It should be documented, consistent, and not subject to discretion after the fact.
- Thin and illiquid tokens. Where the position exceeds what the order book could absorb, mark-to-market overstates realisable value. Ask whether liquidity discounts are applied, and how they're derived.
- Locked, vesting, and staked positions. These are not equivalent to freely tradeable holdings. Unbonding periods, cliffs, and vesting schedules should be reflected.
- Pre-launch and SAFT positions. Frequently the largest single source of valuation subjectivity in a portfolio.
- LP positions and derivative exposures. Impermanent loss, oracle dependency, and protocol-level risk that a simple token-balance view will miss entirely.
The governing question is one of independence: how much distance sits between the investment team and the final mark? Where the administrator relies on manager-supplied prices for material positions, that distance is smaller than it appears on the org chart.
Counterparty and venue risk
Assets sitting at a trading venue are typically an unsecured claim against that venue. This is not a theoretical concern.
What to examine:
- Venue concentration. How much sits at any single venue, at any point, and what the policy limit is
- Sweep discipline. Whether balances are swept to custody on a defined schedule, and whether the schedule is actually followed
- Venue selection and monitoring. Whether venues were diligenced on any basis beyond liquidity, and whether that assessment is refreshed
- Legal terms. What the venue's terms actually say about asset segregation and treatment in insolvency
- Lending and rehypothecation. Whether fund assets are lent, to whom, against what collateral, and on what terms
- Bridge and cross-chain exposure. Frequently overlooked, and historically a significant source of loss
- Smart contract exposure. Audit history, time in production, value at risk, and whether the manager can articulate the failure modes
Service providers
The traditional ODD approach of verifying service providers directly still applies. What changes is that the relevant providers are different, and their capabilities vary far more than in traditional markets.
| Provider | What to establish |
|---|---|
| Administrator | Digital asset experience specifically. Whether they independently verify holdings on-chain or accept manager-supplied positions. How they price illiquid tokens. |
| Auditor | Whether the firm audits other digital asset funds. How they verify existence of holdings. Prior opinion history. |
| Custodian | Regulatory status, insurance coverage and its actual scope, SOC reporting, and asset segregation model. |
| Legal counsel | Genuine digital asset regulatory capability, not general fund formation experience. |
| Analytics provider | Which blockchain analytics tooling is used, how alerts are handled, and by whom. |
Confirm each relationship directly with the provider. Confirm scope as well as existence — an administrator engaged for a limited scope is not the same as one performing independent verification, and the difference will not be visible in the manager's presentation.
Controls and segregation of duties
Small teams make genuine segregation difficult, and most digital asset managers are small teams. That does not excuse its absence — it means compensating controls have to be real.
Test for:
- Whether the person who initiates a transfer can also approve it
- Whether trade execution and reconciliation sit with the same individual
- Whether the person managing venue relationships also controls withdrawal permissions
- How new withdrawal addresses are added, approved, and verified out of band
- Reconciliation frequency, and whether breaks are documented and resolved on a defined timeline
- Key-person dependency — what happens operationally if one specific individual is unavailable for two weeks
The most consequential single finding in digital asset ODD is a founder or portfolio manager holding sufficient key material to move assets unilaterally. It is common, it is often not disclosed unless asked directly, and it should be a threshold question rather than a detail buried in the operations review.
Governance and the regulatory perimeter
Governance in digital assets is frequently thin, and its thinness is often defended on the grounds that the sector moves too quickly for it. Test the substance rather than the org chart.
- Independent directors. Whether any exist, whether they have relevant expertise, and how many other boards they sit on
- Committee function. Whether valuation and risk committees meet, and whether minutes reflect genuine challenge or ratification
- Conflicts. Personal trading by the investment team is a materially larger concern here than in traditional strategies, given the ease of trading the same assets personally
- Affiliated entities. Whether the manager runs a venue, a market maker, a token project, or a validator business alongside the fund, and how those conflicts are managed
- Token treatment. How the manager handles airdrops, staking rewards, governance rights, and forks — and whether the policy is documented or improvised
- Regulatory posture. Registration status, jurisdictional analysis, and whether the manager can articulate a coherent position on the regulatory treatment of what it holds
Red flags
Not disqualifying in isolation, but each warrants substantially more work:
- Reluctance to name the custodian, or vagueness about the custody model
- Inability to explain the key management structure without preparation
- An administrator or auditor with no other digital asset clients
- Sustained large balances at trading venues with no sweep policy
- Material positions in tokens the manager or an affiliate helped launch
- Valuation policy that exists as a paragraph rather than a document
- No independent verification of holdings by any third party
- Resistance to on-chain verification of stated positions
- Compliance function held by someone with an investment role
- An operational history with no documented incidents at all — in this asset class, that usually indicates incidents aren't being recorded
What good looks like
Managers who clear operational review tend to share a specific characteristic: they answer hard questions with specifics rather than reassurance. They can produce the key ceremony documentation. They have tested recovery and can describe what failed the first time. They know their venue exposure at any given moment because it is limited by policy rather than habit. They have had operational incidents, documented them, and changed something as a result.
The absence of that specificity is itself the finding.
Common questions
How is crypto fund ODD different from hedge fund ODD?
The core discipline is the same — you are testing whether stated operations match actual operations. What changes is where the risk concentrates. Traditional ODD leans on independent custodians, prime brokers and transfer agents. In digital assets, several of those intermediaries may be absent, weaker, or performed by an affiliate, so control of assets often sits much closer to the investment team.
What is the single most important area to review?
Custody and key management. It determines whether the manager can unilaterally move assets, and it is where catastrophic, unrecoverable loss originates. Nothing else in the review matters as much.
Can on-chain data replace traditional verification?
It supplements it. On-chain analysis can verify balances and transaction history with a precision that has no analogue in traditional markets. It cannot tell you who controls the keys, what off-chain obligations exist against those balances, or whether an address is actually the fund's.
How long does a digital asset ODD review take?
It depends on structure, strategy, and the number of venues and counterparties in scope. A manager trading on a handful of venues with a qualified custodian is a materially different exercise than a multi-strategy fund with self-custody, DeFi exposure, and cross-chain positions.
Should ODD be repeated after the initial allocation?
Yes. Operational risk in digital assets changes faster than in traditional strategies — venues fail, custody arrangements change, staff turn over, and strategy drift into new protocols happens quietly. Point-in-time diligence ages quickly.
Diligencing a digital asset manager?
We conduct independent operational due diligence reviews for allocators — scoped to the specific structure and strategy in front of you, not a generic checklist.
Discuss an engagementThis page is general information about regulatory frameworks, not legal advice, and does not create an attorney-client relationship. Licensing requirements, thresholds, and agency guidance change frequently and vary by state. Verify current requirements against the relevant regulator, NMLS, and qualified counsel before relying on anything here.
