Make approvals demonstrable and difficult to bypass
By the end, explain the diagram in your own words, solve the case and justify the correction.
Prerequisites : Hot, warm and cold wallets
Level 3 · Advanced →Reading path · 5 / 17 · Advanced
An operational control should have a defined risk, owner, frequency, evidence and exception process.
The essentials
An operational control should have a defined risk, owner, frequency, evidence and exception process. In digital assets, common controls include beneficiary allowlists, transaction limits, independent approvals, reconciliation and monitoring of signing-policy changes. A control description alone does not establish that it operates effectively.
How it works
Risk and control self-assessment, or RCSA, connects risks to mitigating controls and remaining exposure. The three-lines model distinguishes operational ownership, risk and compliance oversight, and independent assurance. Independence depends on actual reporting and decision rights rather than job titles.
What to watch
An incident exercise can simulate a signing-provider outage during a time-sensitive withdrawal. Test communications, recovery time, dependency alternatives and reconciliation after recovery. Forks and airdrops need asset-support decisions and entitlement rules. Sanctions alerts require investigation and escalation; a screening score should not be treated as a definitive legal determination.
Understand the details
A control needs an owner, a trigger, a rule and evidence. For withdrawals, separate request creation, beneficiary changes, approval and signing wherever the risk requires it. A two-person approval loses much of its value if one administrator can silently change both identities or disable the rule.
Boundaries and common mistakes
Preventive controls block unsuitable actions; detective controls identify exceptions after or during processing. Recovery controls restore service safely. Logs must connect the authorized instruction to the signed payload and resulting transaction, while protecting sensitive information. A screenshot of an approval is weaker than a traceable, integrity-protected record.
The mechanism at a glance
- Request
- Policy and independent approval
- Sign and execute
- Reconcile and review exceptions
Apply the lesson to a case
A destination allowlist changes five minutes before a large withdrawal. Design a review that considers who changed it, who approved the payment and whether an emergency override was used. Include an escalation owner.
Collect the change request, independent approval, reason, timing, policy version and resulting transaction. An exception should follow a defined process and later review. If one actor can erase the evidence or approve their own override, the apparent separation needs redesign.
Prepare a correction note
Describe the passage and the proposed correction. This creates a local note for you to share; it sends nothing. Do not include personal or confidential information.