What belongs in a digital asset treasury policy?
Custody, counterparty limits, liquidity ladders, valuation and disclosure.
A digital asset treasury policy specifies which assets may be held and in what size, where they are custodied and under whose permissions, counterparty exposure limits, a liquidity ladder matching holdings to expected cash needs, a valuation methodology and frequency, disclosure obligations, and who approves the policy and how often it is reviewed.
What belongs in a digital asset treasury policy?
Seven sections. Eligible assets and sizing. Custody and permissions. Counterparty limits. Liquidity ladder. Valuation methodology and frequency. Disclosure obligations. Approval and review. Short enough to be read by the board that approves it, specific enough to be tested by an auditor.
| Section | What it must state | Tested by |
|---|---|---|
| Eligible assets and sizing | Which assets may be held, maximum size in absolute and relative terms, and the purpose of the holding | Whether an actual holding is within limits today |
| Custody and permissions | Where assets sit, which authorised entity holds them, how keys are controlled, who may authorise a transfer | Evidence of the provider’s authorisation on a register |
| Counterparty limits | Exposure caps per exchange, broker, lender, and stablecoin or e-money token issuer, and how they are monitored | A current exposure report against limits |
| Liquidity ladder | Which holdings are available at what notice, matched to expected and stressed cash needs | A stressed scenario run against the ladder |
| Valuation | Pricing source, methodology, frequency, and treatment of illiquid or restricted holdings | A valuation an auditor can reproduce |
| Disclosure | What is reported, to whom, how often, and what triggers an ad hoc disclosure | Minutes and reports at the stated cadence |
| Approval and review | Who approves, who may deviate and on what authority, and the review cadence | A dated approval and a review record |
What does not belong: market views, price targets and strategy narrative. A policy sets limits and processes. A policy that argues a thesis has to be rewritten whenever the thesis changes, which defeats its purpose.
How should custody be specified?
By naming entities, permissions and controls rather than asserting that assets are held securely. The section should identify which authorised provider holds which assets, under which authorisation and in which jurisdiction, and require evidence of that authorisation on a public register rather than a provider’s description of itself.
- Segregation model. Omnibus or client-segregated, and how the provider evidences your entitlement.
- Key management. Generation, storage, backup and recovery; whether self-custody is permitted and under what controls.
- Movement authorisation. Dual control, per-transaction and daily limits, whitelisted destination addresses, and delays on large movements.
- Provider failure. The insolvency analysis under the provider’s governing law, and a documented migration path.
- Prohibited activity. Whether lending, staking, rehypothecation or any yield activity is permitted, and if so under what limits and with which counterparties.
In the EU, custody of crypto-assets requires a MiCA authorisation, and a national VASP registration is a different status: an anti-money-laundering registration, not permission to provide custody. The policy should say which is required and require the register entry. Read which custody permission applies to which instrument.
Prohibitions are the most useful part of this section in a fast decision. A treasurer who can point to a line saying the treasury does not lend its holdings does not need to convene a committee to decline an offer.
What counterparty limits are appropriate?
Limits should be per counterparty, per counterparty type, and in aggregate, expressed as a percentage of treasury assets and as an absolute cap, with a stated basis for the cap. The right level depends on the entity’s balance sheet and risk appetite; the discipline is that a number exists and is monitored.
The exposures to capture go beyond trading venues. A stablecoin or e-money token position is an exposure to its issuer and reserves. A staking arrangement is an exposure to a protocol and often to a validator operator. A lending position is credit exposure. Assets at a custodian are exposure to that custodian’s solvency and controls, however well segregated.
| Exposure | What to limit | What to monitor |
|---|---|---|
| Trading venue or broker | Balance held on-venue, and time held | Daily balances; sweep to custody |
| Custodian | Share of total assets with one provider | Authorisation status, audit findings, incidents |
| Stablecoin or e-money token issuer | Position size per issuer | Reserve disclosures, redemption performance, authorisation |
| Lending counterparty | Notional and tenor | Collateral, mark-to-market, covenant compliance |
| Staking or protocol | Amount staked and lock-up | Slashing risk, validator performance, unbonding periods |
| Bank | Fiat balances above deposit protection | Concentration and credit standing |
Limits should be tested against actual exposure at least monthly, and breaches recorded and escalated rather than tolerated. An unmonitored limit is a statement, not a control.
How do you build a liquidity ladder?
Map holdings against the time required to convert them into usable cash, then map that against expected and stressed cash needs over defined horizons. The ladder is useful only if the conversion times assume a poor market rather than a calm one.
- Define horizons. Typically immediate, one week, one month, one quarter, and beyond.
- Assign holdings to horizons. Based on realistic conversion time including custody withdrawal, settlement and payment.
- Layer in constraints. Unbonding periods, lock-ups, encumbrance, and venue withdrawal limits.
- State cash needs per horizon. Operating costs, committed capital, debt service, tax.
- Stress it. Apply a drawdown and a liquidity contraction simultaneously, since they arrive together.
- Record the gap. If a horizon is short of cover, the policy should say what action is triggered and by whom.
Two honest inputs make the difference. Withdrawal from custody is not instant, and staked or locked assets are not liquid regardless of the asset’s market depth. A ladder that treats a locked position as available at one week is a ladder that will fail when it is needed.
Where the treasury holds tokenized instruments, their redemption terms come from the instrument’s documentation and belong in the ladder as stated, not as assumed. See the tokenized treasury products comparison.
How should assets be valued, and how often?
On a named pricing source, by a stated methodology, at a stated frequency, reviewed by someone other than the person who trades. For liquid assets with observable prices, daily or at each reporting date is normal; for thinly traded, restricted or locked positions, the policy must state how a price is derived and who approves it.
The specifics an auditor will ask for: which venue or index, at what time of day, in which currency, and what happens when the primary source is unavailable. A policy that names a fallback source and a tie-break rule avoids an argument at the worst moment.
Encumbrance must be visible in the valuation, not only in a footnote. Pledged, lent or locked holdings should be identified separately, because their contribution to net asset value is not equivalent to unencumbered holdings. This is exactly the disclosure the market prices when it values a listed vehicle. Read why digital asset treasuries trade below NAV.
Frequency should match decision-making, not appearances. If limits are monitored monthly, valuation must be at least monthly, and a treasury that reports quarterly while trading weekly has a control gap regardless of methodology.
What must be disclosed, and to whom?
Internally: holdings, valuations, exposures against limits, liquidity position, breaches and incidents, at the agreed cadence, to the board or committee named in the policy. Externally: whatever accounting standards, listing rules, lender covenants and regulatory obligations require, plus anything the entity has voluntarily committed to.
For listed vehicles the disclosures investors actually use are holdings, custody arrangements, encumbrances, leverage and any dilution mechanism. Publishing those reduces the risk premium in the discount at very low cost, which is the cheapest governance improvement available.
The policy should also define what triggers an ad hoc disclosure: a custody incident, a provider failure, a limit breach of a stated size, a material valuation event, or a change to the policy itself. Deciding this in advance prevents the disclosure question from being litigated during the event.
One caution on voluntary disclosure: commit only to what can be sustained. A vehicle that publishes weekly holdings and then stops has created a negative signal where none existed.
Who approves the policy, and how often is it reviewed?
The board or an investment committee approves it, a named executive owns it, and it is reviewed at least annually and on any material change: a new asset class, a new custodian, a change in a provider’s regulatory status, a loss event, or a change in the entity’s funding position.
Deviations require documented approval at a stated level. The policy should name who may authorise a temporary deviation, for how long, and what must be reported afterwards. Silence here is what produces the informal exception that becomes the practice.
Evidence of operation matters as much as the document. Minutes recording that limits were monitored, that breaches were recorded and resolved, and that the ladder was tested, are what an auditor, lender or acquirer will ask for. A policy with no operating record reads as an aspiration.
Read next: what a digital asset treasury is, and what good governance looks like, how the market prices it, or which custody permission your holdings require.
- Regulation (EU) 2023/1114 (MiCA); Directive 2014/65/EU (MiFID II); Directive 2011/61/EU (AIFMD); Directive 2009/65/EC (UCITS) — EU Official Journal.
- COSIMO Digital regulatory authorisations, described as of 28 July 2026. Pending authorisations are not effective until granted.
This page is for informational purposes only. Nothing in it is an offer to sell, or a solicitation of an offer to buy, any security, and nothing here is investment, legal, tax, or financial advice. Regulatory authorisations are described as of the date stated; pending authorisations are not effective until granted.
← All Learn articles