An allocator who has already decided to hold digital assets, and how much, still has one more question to answer before capital moves: this specific manager, holding assets in this specific way. That is operational due diligence, and it runs differently here than for a conventional long/short equity vehicle, because things a conventional allocator takes for granted, an independent custodian, undisputed closing prices, one settlement system, do not exist in the same form. This piece works through what to examine before wiring money: custody and who can move assets, key management, valuation, counterparty exposure, what the administrator and auditor actually verify, conflicts including proprietary trading, and the patterns that have preceded real failures. It follows our piece on whether and how much to allocate. None of it is investment, legal, tax or accounting advice.
Why a standard hedge fund DDQ misses the risk
A standard institutional questionnaire assumes a manager trades through prime brokers, settles through a central depository, and holds cash and securities with a bank or broker-dealer answerable to its own regulator. Digital assets strain each assumption: there is no consolidated tape, trading is spread across venues of uneven reliability, and custody of a token that is not itself a security sits awkwardly inside rules written for funds and securities. The Alternative Investment Management Association recognised the gap: on 27 February 2023 it published a due diligence questionnaire for digital asset funds, covering strategy, trading, risk management, leverage, liquidity risk and fund service providers, including custody, costs and expenses, performance and valuation. The SEC's Division of Examinations had flagged much of the same ground in a 26 February 2021 risk alert, pointing examiners to controls over private keys and trading platform access, valuation methodology, and, for broker-dealers acting as or trading on platforms, conflicts of interest that require disclosure and mitigation.
None of this is exotic once named. It has to be asked about explicitly, because a manager's stock answers to a generic DDQ will not surface it.
Custody: who can move the assets, and under what agreement
The first document to request is the custody agreement itself, not a description of it. We have written separately about what "qualified custodian" does and does not mean; the due diligence version of that question is narrower. For a US-registered adviser, ask which of the four categories in the rule's definition the custodian falls into (a bank or savings association, a registered broker-dealer, a registered futures commission merchant, or a qualifying foreign financial institution), and ask to see the clause that establishes it, not the custodian's marketing page.
A settled SEC matter shows what happens when this step is skipped. On 3 September 2024 the SEC announced that Galois Capital Management LLC, adviser to a crypto-focused private fund, had agreed to pay a $225,000 penalty, without admitting or denying the findings. The SEC found that, beginning in July 2022, certain of the fund's crypto assets were not maintained with a qualified custodian but held in online trading accounts at platforms including FTX Trading Ltd., and that roughly half the fund's assets under management were lost in connection with FTX's collapse that November. The order also found that some investors were told redemptions required at least five business days' notice while others were allowed to redeem on shorter notice. Both findings sit in documents an allocator can request: the custody arrangements and the offering documents, read together rather than summarised.
The US position is also moving. On 30 September 2025 the SEC's Division of Investment Management issued a staff no-action letter allowing registered advisers and registered funds to treat certain state-chartered trust companies as banks for the custody of crypto assets, on conditions: an initial and annual assessment of the trust company, its audited financial statements and a SOC 1 (or equivalent) internal control report, a custody agreement that segregates the assets and bars their use, rehypothecation or pledging without consent, disclosure of the material risks, and a determination that the arrangement is in the client's best interest. That letter followed the Commission's withdrawal, effective 17 June 2025, of its 2023 proposal to extend the custody rule to all client assets, crypto included; the Commission said it did not intend to issue final rules on those proposals. So an allocator is relying on staff no-action conditions, not a rewritten rule, and should ask the manager to walk through each condition against the actual custodian, by name.
In the UK, the FCA published final rules for its cryptoasset regime on 30 June 2026, with client asset protections set out in PS26/11. The FCA expects the authorisation window to open on 30 September 2026 and close on 28 February 2027, and the regime applies from 25 October 2027. None of it applies yet, so ask a UK-facing manager whether its custodian intends to apply in that window.
Key management and signing policy
Custody status is a legal question. Key management is a more mechanical one: who can actually sign a transaction that moves the assets, and under what control. Ask for the signing scheme (multi-signature or threshold MPC), how many independent signers are required, whether any of them also sit on the trading desk, and what happens operationally when a signer leaves. A two-of-three scheme sounds robust until two of the three key-holders turn out to report to the same person.
The Celsius Network examiner's findings show the value of asking rather than assuming. Examiner Shoba Pillay's report, filed on 19 November 2022, found that Celsius launched its custody programme "without sufficient accounting and operational controls or technical infrastructure", that assets were commingled in main wallets rather than kept separate, and that shortfalls in custody wallets were covered using other company holdings. Celsius was a lending platform, not a fund, but the lesson transfers: a segregation policy on paper is not a wallet architecture that enforces it. Ask for the wallet structure and the exception log, not the policy document alone.
Valuation: whose price, and struck when
A conventional fund marks positions to an exchange closing price nobody disputes. A crypto fund prices assets that trade continuously across many venues with no consolidated tape. The valuation policy should specify, in writing, a source hierarchy: which venues count, how they are weighted, what happens when volume on the primary venue is thin, and who owns the exception process when a mark disagrees with what the desk believes a position is worth. Ask for the policy, then a sample month's NAV pack, so you can see the hierarchy applied to anything illiquid: locked or vesting tokens, private-round positions, LP tokens in a thinly traded pool. "Fair valued" is not an answer; ask for the model.
Ask, too, whether the valuation committee includes anyone whose pay depends on the fund's reported performance. If trading and valuation sign-off sit with the same small group, that is itself the finding.
Trading counterparties and exchange exposure
Ask for the current counterparty list, the exposure limit per venue, and whether those limits are monitored in real time or reconciled after the fact. A fund that nets exposure across venues in its own reporting but cannot show gross exposure per counterparty on request has not measured its own concentration risk.
Three Arrows Capital is the cautionary case. A 10 October 2022 analysis by the risk consultancy S-RM argued that anyone able to trace the fund's wallets, holdings and the smart contracts setting its margin-call thresholds would have found a reality "very different" from its "market neutral" pitch to investors and lenders. The practical point: for a crypto manager, some stated exposure can in principle be checked against public blockchain data rather than taken on trust. That check has limits, since off-chain leverage, exchange sub-accounts and bilateral derivatives do not appear on a block explorer, the same caveat that applies to proof of reserves: it confirms what it looks at, and nothing about what it does not.
What the administrator and the auditor actually verify
An independent administrator strikes NAV, but the number is only as good as what feeds it. Ask whether the administrator independently reconciles on-chain wallet balances and exchange statements against the manager's position records, or simply applies the pricing policy to whatever the manager reports. The FTX debtors' first interim report, released on 9 April 2023 after a review of more than a million documents and interviews with 19 former employees, found that the FTX Group "failed to implement appropriate controls in areas that were critical for safeguarding cash and crypto assets", with failures across management and governance, finance and accounting, digital asset management, and information security. An administrator that takes a manager's numbers as given would not catch failures of that kind, at a large group or a small fund.
An annual audit opinion answers a narrower question than allocators sometimes assume: whether the financial statements as a whole are fairly stated, at a materiality threshold, as of a period end. Ask what the engagement letter covers, and separately whether the custodian can produce a SOC 1 report for the audit period. The AICPA describes SOC 1 as an examination of controls at a service organisation that are likely to be relevant to its users' internal control over financial reporting, which is closer to the allocator's question than a general security review.
Then ask how a US-registered manager meets the custody rule's verification requirement. Under 17 CFR 275.206(4)-2, an adviser with custody generally needs a surprise examination by an independent public accountant, filed on Form ADV-E within 120 days of the date the accountant chooses, with material discrepancies reported to the SEC within one business day. For a pooled fund, the more common route is the audit provision instead: the fund is audited at least annually and the audited financial statements are distributed to investors within 120 days of the fiscal year end. Ask which route the manager relies on, ask for the most recent Form ADV-E or audited statements with evidence of when they were delivered, and ask how the auditor or accountant verified that the crypto assets existed and were controlled by the fund.
Conflicts, including proprietary trading
IOSCO finalised eighteen policy recommendations for crypto and digital asset markets on 16 November 2023. They cover, among other areas, conflicts of interest, including those at vertically integrated crypto-asset service providers that combine functions such as trading venue, proprietary trading and custody, and the custody of client assets. IOSCO's October 2025 thematic review of twenty jurisdictions pointed to the need for greater consistency in implementation and stronger enforcement, so this remains a question to ask directly rather than assume a regulator has settled.
For a fund manager, the same conflict shows up smaller and more specific. Ask whether the manager or its principals run a proprietary book in the same instruments and venues, and ask for the trade allocation policy in writing, with timestamped logs available on request, not a statement that allocation is "fair". Ask whether the manager takes rebates or preferential terms from any venue it routes flow to, and whether that is disclosed. Ask whether the fund stakes or lends assets for extra yield, who the counterparty is, whether it was diligenced separately, and whether the practice appears in the governing documents rather than only in a monthly letter. And ask whether the "independent" administrator or custodian shares ownership or personnel with the manager; independence claimed in a pitch deck is not independence checked against a corporate registry.
Patterns that have preceded real failures
Set side by side, the cases above point to a short list:
- Fund assets held in exchange trading accounts rather than with an entity meeting the qualified custodian definition, as the SEC found at Galois Capital.
- A stated risk profile, such as "market neutral", that on-chain analysis suggests does not match actual positioning, as S-RM argued of Three Arrows Capital.
- Assets that are meant to be segregated but are commingled, with shortfalls covered from other holdings, as the Celsius examiner found.
- Control over cash and crypto assets without the oversight or control framework to safeguard them, as the FTX debtors' report described at group level.
- An administrator or auditor engagement whose scope, once read, is narrower than the assurance the manager implies it provides.
Each item has a document behind it: the custody agreement, the wallet architecture and exception log, the valuation policy and a sample NAV pack, the counterparty exposure report, the administrator's reconciliation methodology, the auditor's engagement letter and the custodian's SOC 1 report, and a written conflicts and related-party disclosure. Ask for all of them before capital moves.
What remains unresolved
The regulatory floor has not settled. In the United States, the 2023 custody proposal was withdrawn in June 2025, and what sits in its place for state trust companies is a staff no-action letter, not a rule. In the UK, final rules exist but do not apply until October 2027. IOSCO's recommendations do not bind anyone directly, and its own review called for more consistent implementation. An allocator diligencing a manager today is relying, to a real extent, on contract terms it has negotiated and evidence it has verified itself. That is a reason to ask harder questions, not to skip them. None of it replaces a manager-specific review by qualified counsel and an operational due diligence professional.
At Proof of Talk's Paris 2026 edition at the Louvre Palace, a panel on how institutions actually access tokenised assets brought together Julian Sawyer, then billed as CEO of Zodia Custody, and Fabian Dori, billed as Chief Investment Officer of Sygnum, among others, with Xavier Gomez of Vancelian moderating. The questions underneath that access, who holds the keys and on what terms, are the ones this piece has tried to make concrete. The archived agenda lists the full session.