Insights Jul 28, 2026

What a bank's risk team actually checks before partnering with a digital-asset firm

Crypto companies keep failing bank diligence for the same reasons, and almost none are about the technology. A view from the bank's side of the table.

Digital-asset firms tend to prepare for bank diligence the way they’d prepare for a technical audit: harden the infrastructure, polish the pen-test report, rehearse the custody architecture. Then the partnership dies anyway, months later, without a clear reason.

Having sat on the bank’s side of that table, I can tell you the reason is usually clear — it just isn’t communicated. The firm answered the questions it thought were being asked. The bank was asking different ones.

The bank isn’t diligencing your security. It’s diligencing its own exam.

A sponsor bank that onboards you inherits you. Your incident becomes their exam finding; your AML gap becomes their consent order. So the risk team’s real question is never “is this company well-built?” It’s: “can I defend this relationship to my examiner, in writing, with evidence?”

That reframing explains almost everything crypto-native teams find baffling about the process:

  • Why your SOC 2 didn’t impress anyone. It’s an input, not an answer. The bank needs to map your controls into its third-party risk framework. If your documentation can’t be translated into their control language, someone on their side has to do the translation — and diligence teams don’t volunteer for homework. Slow no.
  • Why they keep asking about your BSA/AML program when “the exchange handles that.” Reliance has to be documented, tested, and defensible. “Our partner does it” without evidence of oversight reads, to an examiner, as “nobody does it.”
  • Why key management gets ten times the scrutiny of your smart contracts. An exploited contract is a loss event. Compromised keys with no provable custody segregation is an unquantifiable loss event. Banks can underwrite losses; they can’t underwrite “we’re not sure what’s reachable.”
  • Why the org chart questions feel invasive. They’re checking whether a named person owns compliance, security, and incident response — or whether it’s a founder wearing four hats. Committees and hats don’t survive exams; named owners do.

What “ready” actually looks like

The firms that clear diligence quickly share one property: they show up with the bank’s paperwork half-written. A controls matrix in bank-framework language. A custody architecture document a non-crypto risk officer can follow. Incident-response evidence, not an incident-response policy. Named owners. The diligence team’s job shifts from investigating you to filing you — and files move.

None of that requires becoming a bank. Most of it is a few weeks of focused work, sequenced correctly — and a named person who owns it afterward. But it has to be built before the process starts: retrofitting credibility mid-diligence reads as exactly what it is.


DAPL Corp’s Institutional Readiness sprint builds that package in two weeks — an ex-bank CISO’s read of your posture before the bank does theirs — and the fractional CISO / CTO retainer is the named owner afterward. If a partnership conversation is on your calendar, book the call first. The checklist version of this article is free to request.

#DigitalAssets #BankPartnerships #Custody

// briefing

The sponsor‑bank checklist.

The 40 things a bank's risk team checks before partnering with a fintech or digital‑asset firm, what counts as evidence for each, and who has to own it. Written from the bank's side of the table. No sales sequence follows it.

One document. No drip campaign.

Book a 30‑minute call.

No slides. No pitch. Leave with one concrete next step you can act on.