Client asset protection is the set of rules, contracts, records, and controls intended to distinguish a client's cash and instruments from the intermediary's own assets and support their identification, return, and access when something goes wrong.
In plain terms — “Where are my assets?” does not have one answer. You need to know who holds them, in whose name they are recorded, which other entities are involved, and which rules apply in a crisis.
Five different concepts
Ownership and rights. These determine what right the client holds and against whom it can be exercised. The answer depends on the contract, asset type, and applicable law.
Segregation. This separates client assets from a firm's own assets in its books or under the law. It reduces specific risks, but its effectiveness depends on records, reconciliations, account structure, and insolvency law.
Custody. This includes safekeeping, recording, and administering assets. A custodian may use sub-custodians; Clearing, settlement, and custody reconstructs the post-trade chain.
Omnibus account. This pools the assets of several clients at one level of the chain. Each client's interest must remain reconstructable from the intermediary's records. “Omnibus” does not automatically mean protected or unprotected; the structure, controls, and law determine the outcome.
Compensation arrangement. This may respond only under its own conditions, for eligible entities and within stated limits. It does not normally cover every market loss and does not replace segregation or custody.
Follow the full chain
Start with the legal entity named in the contract. Then identify the account type, the recipient of the cash, the custodian and sub-custodians, the records used to attribute positions, and the rules governing transfers, use, collateral, and insolvency.
A platform may display a balance without holding the asset directly; a broker may execute the order while custody is provided elsewhere; a custodian may record a position through an omnibus account. Broker risk and custody risk overlap when one entity combines both roles, but they can also interact through contracts, records, and operational dependencies across the chain.
Reconciliations compare internal records with those of banks, custodians, or external infrastructures. Unresolved differences, incomplete records, or undisclosed dependencies can make assets harder to identify and return.
What happens in a crisis
The right questions are operational. Does the client retain a proprietary interest or only a claim? Are the assets separate from the firm's estate? Who controls the records? Is there a transfer process? Which sub-custodians and foreign laws enter the chain? Does a compensation arrangement cover that entity and that type of shortfall?
Answers vary by instrument and jurisdiction. Authorisation, segregation, and compensation may reduce the impact of some failures, but do not guarantee immediate access, full recovery, or market value.
Common mistake — Reading “segregated funds” or “assets held in custody” as a universal guarantee without identifying the entity, account, custodian, law, and scenario covered.
Crypto-assets and self-custody
For a crypto custody service, distinguish control of the keys, internal records, segregation of holdings, omnibus wallets, contractual liability, and the ability to return assets. Within its perimeter, MiCA sets requirements for safeguarding clients' crypto-assets and funds and specific obligations for custody and administration services.
Self-custody removes some dependencies on a custodian but transfers key, backup, signing, and smart-contract risks to the user. Proof of reserves may provide point-in-time evidence about certain reserves; by itself, it does not establish complete liabilities, legal title, controls, or solvency.
Check before depositing
As part of due diligence, save the contract and answer five questions: which entity am I contracting with; who receives the cash; who holds the assets; how do they appear in the records; and what happens during a withdrawal, transfer, or crisis? If an answer relies only on marketing copy, the check is incomplete.
Sources
- IOSCO — Recommendations Regarding the Protection of Client Assets — principles covering custody, records, reconciliations, risks, and disclosure.
- ESMA — MiFID II, Article 16: organisational requirements — safeguarding client financial instruments and funds within its perimeter.
- EUR-Lex — Commission Delegated Directive (EU) 2017/593 — safeguarding measures, records, accounts, and use of client instruments.
- ESMA — MiCA, Article 70 — safeguarding clients' crypto-assets and funds.
- ESMA — MiCA, Article 75 — custody and administration of crypto-assets on behalf of clients.
- PCAOB — Exercise Caution with Third-Party Verification/Proof of Reserve Reports — limits of proof-of-reserves reports as investor evidence.
- Investor.gov — SIPC Protection: Part 1 — a US example of the limits of a protection scheme: it does not cover market losses.
Protections are specific to an entity, service, asset, country, and date. This page does not determine the legal outcome of a particular insolvency.