Executive introduction
Crypto and tokenised assets are increasingly connected with traditional finance through custody, exchange-traded products, tokenised funds, stablecoins and institutional trading infrastructure. For European firms, 2026 is also a significant regulatory transition year because the MiCA grandfathering period for eligible crypto-asset service providers ended across the EU on 1 July 2026.
Traditional investment firms therefore need a risk framework that distinguishes several very different exposures: volatile crypto-assets, regulated tokenised financial instruments, stablecoins, custody arrangements and third-party crypto service providers.
Key takeaways
- Digital-asset risk should be decomposed into market, liquidity, custody, counterparty, technology and legal risks.
- MiCA does not make crypto-assets economically risk free; it establishes regulatory requirements for defined activities and assets.
- Stablecoins introduce reserve, redemption and liquidity risks in addition to price risk.
- Tokenised financial instruments may preserve the economic risk of the underlying asset while adding technology and settlement dependencies.
- Custody and private-key arrangements require operational controls different from conventional securities custody.
Market and liquidity risk
Crypto-assets can exhibit high volatility, fragmented liquidity and continuous 24-hour trading. Correlations can change rapidly during stress, and price gaps can occur across venues.
Risk limits should therefore consider realised and implied volatility, venue concentration, order-book depth, weekend liquidity, stablecoin settlement dependence and the possibility that market access differs by jurisdiction.
Custody risk
Custody of digital assets introduces risks around private keys, wallet architecture, cyber security, transaction authorisation and recovery. Traditional segregation concepts remain important, but operational implementation is different.
Firms should understand whether assets are held on-chain, with a qualified custodian, through an omnibus structure or through an exchange account, and what legal claim the client has if the provider fails.
Counterparty and venue risk
Crypto trading often depends on exchanges, brokers, custodians and stablecoin issuers. Concentration can be high. Counterparty due diligence should therefore assess financial strength, regulatory status, segregation, settlement, cyber controls and withdrawal capability.
Risk limits should reflect the possibility that an exchange can become unavailable during the exact period in which the firm wants to reduce exposure.
Stablecoin risk
Stablecoins aim to maintain a stable value but can face reserve, liquidity, governance and redemption risks. BIS analysis in 2026 continues to highlight potential macro-financial consequences if stablecoins become widely used substitutes for deposits or money-market instruments.
Investment firms should therefore avoid treating stablecoin balances as equivalent to insured bank cash without analysing the specific issuer and reserve structure.
Tokenisation
ESMA’s 2026 risk monitoring describes tokenisation as gaining momentum while adoption remains limited. Tokenisation can improve settlement and programmability, but it can also add smart-contract, interoperability, technology-provider and legal-ownership risks.
The risk of a tokenised bond remains fundamentally linked to the issuer and cash flows of the bond. DLT changes the infrastructure, not the underlying credit economics.
MiCA transition in 2026
ESMA stated that the EU-wide transitional period under MiCA expired on 1 July 2026. Firms providing crypto-asset services without the required authorisation after the applicable transition must cease unauthorised services.
Traditional investment firms should therefore verify the regulatory status of crypto service providers and distinguish crypto-assets under MiCA from tokenised instruments that qualify as financial instruments under other EU legislation.
Practical example
An asset manager uses a regulated custodian for Bitcoin exposure but holds settlement balances in a stablecoin on a trading venue. The portfolio market risk appears limited because positions are hedged. A venue outage prevents withdrawal while the stablecoin temporarily trades below par.
The loss arises not from the directional Bitcoin position but from settlement, counterparty and stablecoin liquidity. This illustrates why digital-asset risk cannot be reduced to price volatility.
What risk leaders should do now
- Classify digital exposures by legal and economic structure.
- Separate market risk from custody and counterparty risk.
- Set venue and custodian concentration limits.
- Assess stablecoin issuer and reserve risk explicitly.
- Verify MiCA or other applicable regulatory status of service providers.
- Stress withdrawal restrictions, exchange outages and de-pegging.
- Maintain key-management and incident-response controls for direct custody.
- Treat tokenisation technology as an additional infrastructure layer, not a replacement for credit analysis.
Frequently asked questions
MiCA provides a regulatory framework for crypto-assets and crypto-asset service providers in the EU, but it does not remove market, operational or counterparty risk. Traditional risk-management controls remain necessary.
Tokenised securities and crypto-assets are not necessarily the same. A token can represent a conventional financial instrument, in which case the applicable regulatory classification may differ from a crypto-asset governed primarily by MiCA.
Conclusion
Digital assets should be brought inside the ordinary enterprise-risk architecture rather than treated as a completely separate universe. Market, credit, liquidity and operational principles still apply, but the infrastructure creates new failure modes.
The strongest approach decomposes the exposure into underlying asset risk, venue risk, custody risk, settlement risk, technology risk and regulatory status. That makes digital-asset risk manageable without pretending that every token represents the same economic problem.