Counterparty risk: how to vet who holds your company's balance
Counterparty risk is the chance that whoever holds your company's balance cannot return it. This guide gives a due diligence framework, with the concrete questions to ask before signing.
Every company that routes its operating balance through a bank, a payments fintech or a digital asset platform carries a risk its treasury committee rarely discusses out loud: what happens if that entity cannot return the money. That question gets answered before signing, not after an incident, and answering it takes a framework, not a gut feeling about which provider "seems trustworthy."
At Soulbit Academy we lay out a counterparty due diligence framework any CFO of a small or midsize business can apply to any third party holding balance: a bank, a payments fintech or a digital asset platform, whether Soulbit or any other. The criteria are the same for all of them: fund segregation, custody model, licensing, audits, concentration and operational red flags. This article teaches you to audit, not to buy.
What a counterparty risk assessment measures, and how it differs from market and operational risk
Counterparty risk is the probability that the entity holding or moving a company's money fails to meet its obligation to return, transfer or settle it when due. It is distinct from market risk, which measures how much an asset can lose to price movement, and from operational risk, which measures the odds of an internal failure or fraud.
The three risks are managed with different tools. Market risk is hedged with currency instruments; operational risk is reduced with internal controls, the kind set out in a written treasury policy. Counterparty risk, by contrast, cannot be fixed with an internal control of the company's own: it depends on the strength and transparency of a third party the business does not directly control.
A company can have flawless internal controls and still lose its balance if the chosen counterparty fails or mixes client money with its own. That is why counterparty risk is assessed before operating with an entity, not after a problem surfaces.
Fund segregation: the question that decides what happens if the provider fails
Fund segregation is the criterion that decides whether a company's balance is protected or lost the day a counterparty enters insolvency. When client funds are legally segregated from a provider's own balance sheet, a liquidator cannot distribute them among that entity's general creditors: the money never belonged to the provider, it was only held in custody.
The opposite pattern, platforms that mixed client funds with their own operating balance sheet and used them to fund other parts of the business, is the most repeated cause behind recent insolvency cases among financial and digital asset providers. When that happens, the client stops being the owner of a protected balance and becomes just another creditor.
Two recent regulatory frameworks show how this protection is being enforced. In the United States, Section 4(a) of the GENIUS Act requires payment stablecoin issuers to keep reserves segregated from operating funds, bans rehypothecation of those assets, and directs that customer property be treated and protected against the issuer's creditors. In the European Union, Article 70 of the MiCA regulation requires crypto-asset service providers to keep client funds in an account separately identifiable from the provider's own accounts, and to safeguard client ownership in the event of insolvency.
Does fund segregation guarantee a company recovers 100% of its balance in every scenario?
Fund segregation reduces the risk of loss to a liquidator, but it does not eliminate every risk, such as an operational delay in the withdrawal process or an issue with the technical custodian itself. A company should ask, in writing, how its funds are segregated and under what legal structure, rather than accept the word "segregated" on a marketing page.
Custody: who holds the key or the asset, and which model you can actually audit
The custody model defines who materially controls the asset or the key that moves it, and it is the technical question that complements legal segregation. On a digital asset platform there are, broadly, two models: institutional custody, where a specialized third party safeguards keys using schemes such as multi-party computation, known as MPC, with client balance recorded as client property; or balance simply booked as a liability on the provider's own balance sheet, with no independent custodian.
A company assessing a counterparty should ask, specifically, who holds the private key, whether that custodian is a legal entity distinct from the provider billing the service, and what happens to the balance if the provider stops operating but the custodian remains. These questions get answered with a document, not a verbal explanation from a sales team, the same way a KYB document checklist turns "we verify our clients" into a specific, checkable list.
When a counterparty deals in crypto assets, it also matters how it converts those assets to local currency, since the conversion mechanism affects real available liquidity. A request-for-quote OTC model, where the provider quotes price case by case rather than trading against a public order book, is a different model from an open exchange.
Licensing and registration: which regulator should know your counterparty
Every financial counterparty must be registered or authorized with the regulator of each country where it operates, and that registration is the first document a company should request before signing. A license does not guarantee solvency, but its absence is a signal that no supervisor is watching that entity at all.
The framework varies by country. In Mexico, the Law to Regulate Financial Technology Institutions requires electronic payment fund institutions to keep client resources identified separately from their own, under the authorization of Mexico's National Banking and Securities Commission (CNBV). In the United States, the GENIUS Act layers federal segregation requirements for payment stablecoin issuers on top of existing money transmitter licensing at the state level, and neither regime equals a full bank charter: each covers a distinct perimeter of activity, so a company must verify exactly which one applies to the counterparty it is assessing.
Declared compatibility with a regulatory framework does not always mean being authorized under it. A platform can declare MiCA compatibility or alignment with the GENIUS Act without holding a full authorization in that jurisdiction, and that difference is exactly what a company should ask to have clarified in writing before assuming it.
Third party audits and attestations: what each report actually proves
A third party audit or attestation only proves what its stated scope covers, and the most common CFO mistake is assuming any certificate covers a provider's overall solvency. Before accepting a report as evidence, a company should read what period it covers, what controls it evaluates and who issued it.
| Type of evidence | What it proves | What it does not prove |
|---|---|---|
| Financial statement audit | That the provider's accounts reasonably reflect its position on a given date | That the company will be able to withdraw its balance in the future |
| Security controls attestation | That certain documented technical processes and controls existed at the review date | The legal segregation of client funds |
| Point-in-time proof of reserves | That, at a given moment, declared assets existed and covered the client liability | That the coverage holds every day of the year |
| Active regulatory license or registration | That a supervisor knows the entity and requires periodic reporting | The financial solvency of the supervised entity |
| Custody agreement or terms of service | How funds are segregated and which law applies in a dispute | That the provider will honor the contract in practice |
Does a security certification prove that a company's funds are segregated?
A security controls certification proves a provider follows certain technical and process controls as of the review date, but it does not prove legal segregation of funds or the provider's solvency. These are complementary pieces of evidence, not interchangeable ones, and a company that confuses the two may believe it is protected when it has only verified a systems control.
Concentration and red flags: when to reduce exposure to a counterparty
Concentration is the risk of leaving an entire operating balance with a single counterparty, and it is managed by setting a maximum cap per provider before an incident, not after. A conservative treasury committee limits exposure to a single entity to a fraction of total available balance, spreading the rest across other counterparties that meet the same due diligence framework.
There are operational red flags that should trigger an immediate review, and they are worth listing explicitly since they rarely appear all at once. The first is a repeated delay in withdrawals that used to process within the standard timeframe. The second is a sudden change in terms of service without prior notice. The third is the departure of key executives or an entire compliance team in a short period. The fourth is the lack of a clear answer when the company asks about its license, its custody model or its last audit. The fifth is any public report, from a regulator or a specialized outlet, about an open investigation into that entity.
What happens to a company's balance if the custody platform becomes insolvent?
A company's balance follows whatever the applicable law and the signed custody agreement set out. If funds were segregated and correctly identified as client property, the insolvency process should return them ahead of general creditors; if they were not, the company joins the line of ordinary creditors and the outcome depends on what remains at the end of the process.
What Soulbit V1 delivers against this framework, and the questions your company should keep asking
Soulbit V1 supports part of this due diligence framework without replacing a company's own judgment, and it is worth stating precisely what is confirmed and what is not. A company's balance is held in third party omnibus accounts under institutional custody with MPC technology, not on Soulbit's own operating balance sheet, and Soulbit does not hold a bank charter or deposit insurance: a distinction every CFO should record in writing, not assume, the same way accounting for USDC under IFRS requires recording the balance as what it legally is, not as cash at a bank.
| Due diligence criterion | Auditable today at Soulbit? | How it is verified |
|---|---|---|
| Segregation of funds from the provider's own balance sheet | Yes | Third party omnibus accounts, distinct from the company's operating balance sheet |
| Custody model for the stablecoin balance | Yes | Institutional custody with MPC technology, service agreement available |
| Bank charter and deposit insurance | No | Soulbit is not a bank: no bank charter and no deposit insurance |
| Declared compatibility with a regulatory framework | Yes | MiCA compatibility declared; verify exact scope in writing |
| Public third party audit or attestation report | Not confirmed | No publicly available report today; request it directly before signing |
Before leaving balance with any counterparty, Soulbit or otherwise, it is worth asking six concrete questions and requiring the document that backs each answer. The first is what license or registration it holds with the regulator of each country, backed by the registration number and the supervising body. The second is how client funds are legally segregated, backed by the custody agreement. The third is who controls the private key, backed by a written description of the custody model. The fourth is what the last audit found, backed by the report with its date and scope. The fifth is what concentration limit the company itself sets for that counterparty. The sixth is what real withdrawal timeline another client has seen under stress.
Frequently asked questions
What is counterparty risk in corporate treasury?
Counterparty risk is the probability that a bank, a fintech or a digital asset platform fails to meet its obligation to the company, typically returning the balance it was entrusted with. It differs from market risk, which depends on an asset's price, and from operational risk, which depends on an internal process failure. A company can have flawless internal controls and still lose its balance if the counterparty holding it fails or misuses client funds.
What does client fund segregation actually mean?
Client fund segregation means client balances are held in accounts separate from the provider's own balance sheet, so a creditor of that provider cannot claim client money in bankruptcy. It is the criterion that matters most in an insolvency scenario: where segregation is legally required, client balances are protected; where it is not, the client competes as an ordinary creditor. The GENIUS Act in the United States and the MiCA regulation in the European Union both impose this segregation on stablecoin issuers and providers.
How many counterparties should a company use for its operating balance?
A prudent company spreads its operating balance across more than one counterparty and sets a maximum cap per provider, calculated over total available cash. That cap varies with each company's risk tolerance, but it always limits a fraction of the total balance, never all of it, to a single entity. Concentrating the entire operating balance in one provider multiplies the impact of any counterparty event, from a temporary freeze to insolvency.
What does a third party audit or attestation actually prove?
A financial audit proves that a provider's financial statements reasonably reflect its position on a given date, while a third party attestation usually verifies a point in time control, such as a process or a balance existing at a specific moment. Neither certifies that a company will be able to withdraw its balance at any point in the future: that depends on licensing, segregation and real liquidity, not on the paperwork attached. A company must read the stated scope of each report before treating it as proof.
What document should a company request before leaving balance with a digital asset platform?
The document backing each answer depends on the criterion being tested: the license or registration with the relevant regulator, the custody agreement or terms of service describing fund segregation, and the most recent audit or attestation report with its stated scope and date. A company that cannot obtain any of these three documents in writing should treat that absence as a warning sign, not an administrative detail.
Want your company to add stablecoins to its operations?
Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.
Join the waitlist