Purpose
Prevent unauthorized access, tampering, misuse, or loss involving client assets and related operational records. Protect custody, wallet administration, payment processing, reconciliation, and linked compliance systems by applying security controls appropriate to those systems.
Scope
Applies to all systems supporting custody, wallet administration, payment processing, reconciliation, and linked compliance controls.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Maintain an inventory of safeguarding systems | Cover systems, accounts, wallets, keys, privileged roles and integrations. | System, wallet, key, privileged-role and access inventory |
| 2 | Apply secure authentication to all safeguarding systems | Ensure authentication controls are in place across all safeguarding systems. | Authentication configuration and access approval records |
| 3 | Apply role-based access restrictions and least privilege | Ensure personnel only access what their role requires. | Access approval and role assignment records |
| 4 | Apply privileged access control | Protect high-risk administrative functions. | Privileged access control configuration and approval records |
| 5 | Apply maker-checker controls for elevated-risk movements and configuration changes | Ensure dual review for high-risk operations. | Maker-checker records for movements and configuration changes |
| 6 | Protect key generation, storage, use, backup, rotation, recovery and destruction | Maintain protected key and wallet administration. | Key-management lifecycle records (generation, storage, use, backup, rotation, recovery, destruction) |
| 7 | Implement secure logging and auditability | Log access, configuration, authorization and asset-movement events securely and review material anomalies. | Secure event logs for access, configuration, authorization and asset-movement |
| 8 | Review user and privileged access periodically | Promptly remove unnecessary access. | Periodic access review records |
| 9 | Protect the integrity of embedded screening, restriction and approval controls | Where compliance-related controls are embedded in asset movement workflows, their integrity must also be protected. | Control integrity review records |
| 10 | Maintain backup and recovery capability | Maintain redundancy, resilience and incident-response arrangements. | Backup, recovery and incident-response test results |
| 11 | Test recovery and access continuity | Remediate failures before relying on the arrangement. | Recovery test results and remediation records |
Records
- System, wallet, key, privileged-role and access inventory
- Access approvals and periodic access reviews
- Key-management lifecycle records (generation, storage, use, backup, rotation, recovery, destruction)
- Secure event logs for access, configuration, authorization and asset-movement
- Backup, recovery and incident-response test results
- Security incidents and remediation records
Relationships
- Policy: POL-SAFU-001 Client Asset Protection and Safeguarding Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Control: CTRL-SAFU-006 Ensure Custody Technology Access Keys and Recovery Are Secure
History
- 2026-07-26: Created from sections 12-14 of the approved SAFU Manual.