What each party controls
The signing policy is the policy that the bank defines and the custody provider
enforces outside the CTS environment. A compromise of the CTS layer can
propose a transfer, but it cannot approve one outside policy or sign one at all.
Signing policy
Signing policy is configured at the custody provider, not in CTS. A bank typically controls these dimensions:- Transfer limits per transaction, per day, and per counterparty
- Allowlisted destination addresses, so settlement can only reach known wallets
- Approval thresholds requiring one or more human approvers above a given amount
- Separation of duties between the staff who define policy and those who approve transfers
- Time windows during which automated settlement may run
Self-custody
Self-custody is an arrangement in which a bank holds its own keys and runs its own key management. It is supported, with signing performed through the bank’s own hardware security modules. Self-custody changes ownership, not the mechanism. The bank takes on every row in the table above currently assigned to the custody provider, including hardware security module operation, key ceremony, rotation, and recovery. The integration surface is identical in either arrangement. CTS issues a signing request and does not depend on which system answers it. The choice is therefore operational and regulatory, not technical. See Overview for why most banks integrate a provider instead, and Connecting a Custody Provider for how either arrangement is wired in.Related
- Overview for the division of responsibility
- Connecting a Custody Provider for the integration surface
- Settlement Asset Custody for 24/7 Payments for where signing happens in a payment flow
- Digital Ledger Support for the chain the Suite runs alongside the core