Advanced Digital Asset Custody and Infrastructure Training Course
| Course code | SD-FT-013 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Financial Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Digital asset custody is no longer limited to safeguarding private keys. Financial institutions, exchanges, asset managers and fintech firms must design operating models that withstand key compromise, insider risk, chain forks, transaction errors, sanctions exposure and service-provider failure. Teams responsible for custody need defensible controls across wallet architecture, transaction approval, key lifecycle management, reconciliation and incident response—while still enabling timely trading, settlement and client servicing.
This course examines the technical and operational infrastructure behind institutional digital asset custody. Participants assess hot, warm and cold wallet models; compare multisignature, MPC and hardware-security-module approaches; define role-based approval workflows; and map the full lifecycle of cryptographic keys. They build control requirements for wallet provisioning, deposit and withdrawal handling, blockchain monitoring, reconciliation, staking and disaster recovery. The programme also addresses third-party custodian due diligence, segregation of client assets, audit evidence, governance and regulatory expectations relevant to financial-services environments.
Teaching combines instructor-led architecture walkthroughs with custody failure case studies, control-design workshops and hands-on configuration exercises using representative custody and key-management tools. Participants work through realistic scenarios including a suspicious withdrawal, a compromised signer, a chain reorganisation and a custodian outage. They leave with a practical Digital Asset Custody Control Pack: a target-state custody architecture, transaction-authorisation matrix, key-management policy outline, operational risk register and incident-response playbook ready to adapt for their organisation.
The course is designed for professionals who already work with digital assets, financial operations, cybersecurity, risk or technology delivery and now need to make informed design, governance and control decisions about institutional custody infrastructure.
Course objectives
By the end of this course, participants will be able to:
- Design a target-state custody architecture covering hot, warm, cold and segregated wallet tiers
- Evaluate MPC, multisignature and HSM-based key-control models against defined risk scenarios
- Create a transaction-authorisation matrix with roles, thresholds, velocity limits and escalation paths
- Develop a cryptographic key lifecycle policy for generation, backup, rotation, recovery and destruction
- Configure control requirements for wallet whitelisting, address screening and withdrawal governance
- Perform an operational risk assessment for custody workflows using control mapping and residual-risk scoring
- Construct a blockchain-to-ledger reconciliation workflow with exception handling and evidence retention
- Produce a digital asset custody control pack containing architecture, policies, risk register and incident playbook
Benefits of attending
For you
- Gain the ability to challenge custody-platform designs beyond high-level vendor claims about security
- Build evidence-based recommendations for MPC, multisignature, HSM and wallet-tiering decisions
- Strengthen credibility when briefing risk committees, auditors and senior technology stakeholders on custody controls
- Apply a repeatable framework to investigate withdrawal incidents, signer compromise and reconciliation breaks
- Leave with reusable custody architecture and policy artefacts for digital asset governance responsibilities
For your organisation
- Reduce exposure to key loss, unauthorised transfers and concentration risk through better-defined custody controls
- Create consistent approval, whitelisting and transaction-monitoring procedures across digital asset operations
- Improve audit readiness with clearer evidence requirements for key lifecycle, wallet access and reconciliations
- Make more defensible custody-provider and infrastructure decisions using structured security and resilience criteria
- Shorten response time to custody incidents through documented escalation, containment and recovery playbooks
Target competencies
Who should attend
- Digital Asset Custody Managers — who own wallet operations, safeguarding controls and service resilience
- Blockchain and Fintech Architects — who design custody platforms and integrations with trading or banking systems
- Information Security Managers — who must assess key-management, privileged-access and cryptographic risks
- Risk and Compliance Professionals — who translate custody obligations into monitoring, governance and audit controls
- Digital Asset Operations Leaders — who manage deposits, withdrawals, reconciliation and exception processes
- Internal Audit and Assurance Managers — who need to test custody control design and evidence trails
Requirements and prerequisites
Participants should have working knowledge of blockchain transactions, public and private keys, wallet addresses, transaction signing and the operating model of a digital asset exchange, custodian or financial institution. Experience in technology risk, cyber security, operations, architecture or digital asset product delivery is strongly recommended. Familiarity with basic cloud-security concepts, access control and financial reconciliation will help participants progress quickly. No programming, smart-contract development or prior experience with a specific custody platform is required. The course explains specialist tools through guided exercises rather than assuming administrator-level configuration skills.
Training methodology
The programme uses short instructor-led technical briefings followed by applied custody-design work. Participants examine wallet architectures, transaction-flow diagrams, control logs and incident evidence drawn from institutional scenarios. Guided exercises use Fireblocks-style policy concepts, AWS CloudHSM key-protection patterns and HashiCorp Vault access-control workflows without requiring production credentials. Small groups assess a custody-provider case, design approval thresholds and resolve reconciliation exceptions. Each day adds artefacts to an end-of-course Digital Asset Custody Control Pack, followed by a facilitated implementation-planning session.
Course outline
Day 1: Institutional custody architecture and threat modelling
- Custody operating models for banks, exchanges, asset managers and fintech firms
- Hot, warm and cold wallet architecture patterns
- Omnibus, segregated and client-controlled wallet structures
- Digital asset custody threat modelling using attack-path analysis
- Trust boundaries between custody platforms, blockchains and internal systems
- Asset segregation, beneficial ownership and wallet attribution controls
- Target-state architecture documentation and control inventory methods
Workshop: Participants map a target custody architecture for a fictional institutional trading firm and produce a trust-boundary diagram with priority control points.
Day 2: Key management and cryptographic control models
- Private-key generation, entropy sources and secure key ceremonies
- Multisignature quorum design and signer-distribution patterns
- Multi-party computation architecture and operational trade-offs
- Hardware security module deployment models with AWS CloudHSM
- Key backup, shard recovery and break-glass procedures
- Key rotation, signer replacement and cryptographic material destruction
- NIST SP 800-57 key-management policy requirements
Workshop: Participants compare MPC, multisignature and HSM designs for three risk profiles and produce a justified key-management decision matrix.
Day 3: Transaction governance and custody operations
- Role-based access control and segregation-of-duties design
- Transaction policy engines, approval chains and spend thresholds
- Wallet whitelisting and beneficiary-address verification controls
- Velocity limits, transaction holds and out-of-band approvals
- Blockchain analytics, sanctions screening and suspicious-transfer escalation
- Deposit, withdrawal and internal-transfer operational workflows
- Blockchain-to-general-ledger reconciliation and exception management
Workshop: Participants configure a transaction-authorisation matrix for a treasury operation and resolve a simulated withdrawal and reconciliation exception.
Day 4: Resilience, third-party risk and assurance
- Custody incident taxonomy for compromised keys, erroneous transfers and chain events
- Chain forks, protocol upgrades and blockchain reorganisation response
- Business continuity design for custodian, cloud and signer outages
- Third-party custody-provider due diligence and control testing
- HashiCorp Vault policy patterns for privileged-access governance
- Audit logging, evidence retention and control-attestation requirements
- Operational risk registers and residual-risk acceptance methods
Workshop: Participants conduct a tabletop response to a compromised signer and custodian outage, producing an incident timeline, escalation plan and recovery actions.
Day 5: Custody control pack and implementation roadmap
- Fireblocks policy concepts for wallet groups and transaction approvals
- Control mapping across custody, security, operations and compliance functions
- Custody governance committees, decision rights and reporting metrics
- Key risk indicators for wallet exposure, approval exceptions and reconciliation breaks
- Implementation sequencing for platform, process and policy changes
- Control testing schedules and internal-audit evidence packs
- Executive presentation techniques for custody risk decisions
Workshop: Participants assemble and present their Digital Asset Custody Control Pack, including target architecture, approval matrix, risk register and 90-day implementation roadmap.
Tools & standards covered
Fireblocks, AWS CloudHSM, HashiCorp Vault, NIST SP 800-57
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Financial Technology
Open Banking API Implementation for Retail Banks Training Course
Retail banks implementing open banking APIs must expose regulated account and payment capabilities while protecting customer data, maintaini…
Financial Technology Fundamentals for Finance Professionals Training Course
Finance teams are increasingly asked to assess payment platforms, automate reconciliations, interpret digital transaction data, support open…
Temenos Transact Core Banking Administration Training Course
Temenos Transact administrators are expected to keep a high-volume core banking platform secure, available, controlled and ready for daily p…
Fintech Product Management for Product Managers Training Course
Financial product managers must make decisions where a familiar product trade-off can also create a regulatory breach, reconciliation failur…