Purpose

Prevent unauthorized access, tampering, misuse, or loss involving client assets and related operational records. Protect custody, wallet administration, payment processing, reconciliation, and linked compliance systems by applying security controls appropriate to those systems.

Scope

Applies to all systems supporting custody, wallet administration, payment processing, reconciliation, and linked compliance controls.

Steps

#ActionDetailsEvidence
1Maintain an inventory of safeguarding systemsCover systems, accounts, wallets, keys, privileged roles and integrations.System, wallet, key, privileged-role and access inventory
2Apply secure authentication to all safeguarding systemsEnsure authentication controls are in place across all safeguarding systems.Authentication configuration and access approval records
3Apply role-based access restrictions and least privilegeEnsure personnel only access what their role requires.Access approval and role assignment records
4Apply privileged access controlProtect high-risk administrative functions.Privileged access control configuration and approval records
5Apply maker-checker controls for elevated-risk movements and configuration changesEnsure dual review for high-risk operations.Maker-checker records for movements and configuration changes
6Protect key generation, storage, use, backup, rotation, recovery and destructionMaintain protected key and wallet administration.Key-management lifecycle records (generation, storage, use, backup, rotation, recovery, destruction)
7Implement secure logging and auditabilityLog access, configuration, authorization and asset-movement events securely and review material anomalies.Secure event logs for access, configuration, authorization and asset-movement
8Review user and privileged access periodicallyPromptly remove unnecessary access.Periodic access review records
9Protect the integrity of embedded screening, restriction and approval controlsWhere compliance-related controls are embedded in asset movement workflows, their integrity must also be protected.Control integrity review records
10Maintain backup and recovery capabilityMaintain redundancy, resilience and incident-response arrangements.Backup, recovery and incident-response test results
11Test recovery and access continuityRemediate failures before relying on the arrangement.Recovery test results and remediation records

Records

  • System, wallet, key, privileged-role and access inventory
  • Access approvals and periodic access reviews
  • Key-management lifecycle records (generation, storage, use, backup, rotation, recovery, destruction)
  • Secure event logs for access, configuration, authorization and asset-movement
  • Backup, recovery and incident-response test results
  • Security incidents and remediation records

Relationships

History

  • 2026-07-26: Created from sections 12-14 of the approved SAFU Manual.