Treasury & FX

Counterparty risk: how to vet who holds your company's balance

Counterparty risk is the chance that whoever holds your company's balance cannot return it. This guide gives a due diligence framework, with the concrete questions to ask before signing.

Equipo Soulbit12 min read
Share
Treasury

Every company that routes its operating balance through a bank, a payments fintech or a digital asset platform carries a risk its treasury committee rarely discusses out loud: what happens if that entity cannot return the money. That question gets answered before signing, not after an incident, and answering it takes a framework, not a gut feeling about which provider "seems trustworthy."

At Soulbit Academy we lay out a counterparty due diligence framework any CFO of a small or midsize business can apply to any third party holding balance: a bank, a payments fintech or a digital asset platform, whether Soulbit or any other. The criteria are the same for all of them: fund segregation, custody model, licensing, audits, concentration and operational red flags. This article teaches you to audit, not to buy.

What a counterparty risk assessment measures, and how it differs from market and operational risk

Counterparty risk is the probability that the entity holding or moving a company's money fails to meet its obligation to return, transfer or settle it when due. It is distinct from market risk, which measures how much an asset can lose to price movement, and from operational risk, which measures the odds of an internal failure or fraud.

The three risks are managed with different tools. Market risk is hedged with currency instruments; operational risk is reduced with internal controls, the kind set out in a written treasury policy. Counterparty risk, by contrast, cannot be fixed with an internal control of the company's own: it depends on the strength and transparency of a third party the business does not directly control.

A company can have flawless internal controls and still lose its balance if the chosen counterparty fails or mixes client money with its own. That is why counterparty risk is assessed before operating with an entity, not after a problem surfaces.

Fund segregation: the question that decides what happens if the provider fails

Fund segregation is the criterion that decides whether a company's balance is protected or lost the day a counterparty enters insolvency. When client funds are legally segregated from a provider's own balance sheet, a liquidator cannot distribute them among that entity's general creditors: the money never belonged to the provider, it was only held in custody.

The opposite pattern, platforms that mixed client funds with their own operating balance sheet and used them to fund other parts of the business, is the most repeated cause behind recent insolvency cases among financial and digital asset providers. When that happens, the client stops being the owner of a protected balance and becomes just another creditor.

Two recent regulatory frameworks show how this protection is being enforced. In the United States, Section 4(a) of the GENIUS Act requires payment stablecoin issuers to keep reserves segregated from operating funds, bans rehypothecation of those assets, and directs that customer property be treated and protected against the issuer's creditors. In the European Union, Article 70 of the MiCA regulation requires crypto-asset service providers to keep client funds in an account separately identifiable from the provider's own accounts, and to safeguard client ownership in the event of insolvency.

Does fund segregation guarantee a company recovers 100% of its balance in every scenario?

Fund segregation reduces the risk of loss to a liquidator, but it does not eliminate every risk, such as an operational delay in the withdrawal process or an issue with the technical custodian itself. A company should ask, in writing, how its funds are segregated and under what legal structure, rather than accept the word "segregated" on a marketing page.

Custody: who holds the key or the asset, and which model you can actually audit

The custody model defines who materially controls the asset or the key that moves it, and it is the technical question that complements legal segregation. On a digital asset platform there are, broadly, two models: institutional custody, where a specialized third party safeguards keys using schemes such as multi-party computation, known as MPC, with client balance recorded as client property; or balance simply booked as a liability on the provider's own balance sheet, with no independent custodian.

A company assessing a counterparty should ask, specifically, who holds the private key, whether that custodian is a legal entity distinct from the provider billing the service, and what happens to the balance if the provider stops operating but the custodian remains. These questions get answered with a document, not a verbal explanation from a sales team, the same way a KYB document checklist turns "we verify our clients" into a specific, checkable list.

When a counterparty deals in crypto assets, it also matters how it converts those assets to local currency, since the conversion mechanism affects real available liquidity. A request-for-quote OTC model, where the provider quotes price case by case rather than trading against a public order book, is a different model from an open exchange.

Licensing and registration: which regulator should know your counterparty

Every financial counterparty must be registered or authorized with the regulator of each country where it operates, and that registration is the first document a company should request before signing. A license does not guarantee solvency, but its absence is a signal that no supervisor is watching that entity at all.

The framework varies by country. In Mexico, the Law to Regulate Financial Technology Institutions requires electronic payment fund institutions to keep client resources identified separately from their own, under the authorization of Mexico's National Banking and Securities Commission (CNBV). In the United States, the GENIUS Act layers federal segregation requirements for payment stablecoin issuers on top of existing money transmitter licensing at the state level, and neither regime equals a full bank charter: each covers a distinct perimeter of activity, so a company must verify exactly which one applies to the counterparty it is assessing.

Declared compatibility with a regulatory framework does not always mean being authorized under it. A platform can declare MiCA compatibility or alignment with the GENIUS Act without holding a full authorization in that jurisdiction, and that difference is exactly what a company should ask to have clarified in writing before assuming it.

Third party audits and attestations: what each report actually proves

A third party audit or attestation only proves what its stated scope covers, and the most common CFO mistake is assuming any certificate covers a provider's overall solvency. Before accepting a report as evidence, a company should read what period it covers, what controls it evaluates and who issued it.

Type of evidenceWhat it provesWhat it does not prove
Financial statement auditThat the provider's accounts reasonably reflect its position on a given dateThat the company will be able to withdraw its balance in the future
Security controls attestationThat certain documented technical processes and controls existed at the review dateThe legal segregation of client funds
Point-in-time proof of reservesThat, at a given moment, declared assets existed and covered the client liabilityThat the coverage holds every day of the year
Active regulatory license or registrationThat a supervisor knows the entity and requires periodic reportingThe financial solvency of the supervised entity
Custody agreement or terms of serviceHow funds are segregated and which law applies in a disputeThat the provider will honor the contract in practice
Table 1. What each type of common evidence proves when assessing a financial counterparty, and what questions it leaves unanswered.

Does a security certification prove that a company's funds are segregated?

A security controls certification proves a provider follows certain technical and process controls as of the review date, but it does not prove legal segregation of funds or the provider's solvency. These are complementary pieces of evidence, not interchangeable ones, and a company that confuses the two may believe it is protected when it has only verified a systems control.

Concentration and red flags: when to reduce exposure to a counterparty

Concentration is the risk of leaving an entire operating balance with a single counterparty, and it is managed by setting a maximum cap per provider before an incident, not after. A conservative treasury committee limits exposure to a single entity to a fraction of total available balance, spreading the rest across other counterparties that meet the same due diligence framework.

There are operational red flags that should trigger an immediate review, and they are worth listing explicitly since they rarely appear all at once. The first is a repeated delay in withdrawals that used to process within the standard timeframe. The second is a sudden change in terms of service without prior notice. The third is the departure of key executives or an entire compliance team in a short period. The fourth is the lack of a clear answer when the company asks about its license, its custody model or its last audit. The fifth is any public report, from a regulator or a specialized outlet, about an open investigation into that entity.

What happens to a company's balance if the custody platform becomes insolvent?

A company's balance follows whatever the applicable law and the signed custody agreement set out. If funds were segregated and correctly identified as client property, the insolvency process should return them ahead of general creditors; if they were not, the company joins the line of ordinary creditors and the outcome depends on what remains at the end of the process.

What Soulbit V1 delivers against this framework, and the questions your company should keep asking

Soulbit V1 supports part of this due diligence framework without replacing a company's own judgment, and it is worth stating precisely what is confirmed and what is not. A company's balance is held in third party omnibus accounts under institutional custody with MPC technology, not on Soulbit's own operating balance sheet, and Soulbit does not hold a bank charter or deposit insurance: a distinction every CFO should record in writing, not assume, the same way accounting for USDC under IFRS requires recording the balance as what it legally is, not as cash at a bank.

Due diligence criterionAuditable today at Soulbit?How it is verified
Segregation of funds from the provider's own balance sheetYesThird party omnibus accounts, distinct from the company's operating balance sheet
Custody model for the stablecoin balanceYesInstitutional custody with MPC technology, service agreement available
Bank charter and deposit insuranceNoSoulbit is not a bank: no bank charter and no deposit insurance
Declared compatibility with a regulatory frameworkYesMiCA compatibility declared; verify exact scope in writing
Public third party audit or attestation reportNot confirmedNo publicly available report today; request it directly before signing
Table 2. What of the counterparty due diligence framework can be audited today at Soulbit V1, and what remains unconfirmed publicly.

Before leaving balance with any counterparty, Soulbit or otherwise, it is worth asking six concrete questions and requiring the document that backs each answer. The first is what license or registration it holds with the regulator of each country, backed by the registration number and the supervising body. The second is how client funds are legally segregated, backed by the custody agreement. The third is who controls the private key, backed by a written description of the custody model. The fourth is what the last audit found, backed by the report with its date and scope. The fifth is what concentration limit the company itself sets for that counterparty. The sixth is what real withdrawal timeline another client has seen under stress.

Frequently asked questions

What is counterparty risk in corporate treasury?

Counterparty risk is the probability that a bank, a fintech or a digital asset platform fails to meet its obligation to the company, typically returning the balance it was entrusted with. It differs from market risk, which depends on an asset's price, and from operational risk, which depends on an internal process failure. A company can have flawless internal controls and still lose its balance if the counterparty holding it fails or misuses client funds.

What does client fund segregation actually mean?

Client fund segregation means client balances are held in accounts separate from the provider's own balance sheet, so a creditor of that provider cannot claim client money in bankruptcy. It is the criterion that matters most in an insolvency scenario: where segregation is legally required, client balances are protected; where it is not, the client competes as an ordinary creditor. The GENIUS Act in the United States and the MiCA regulation in the European Union both impose this segregation on stablecoin issuers and providers.

How many counterparties should a company use for its operating balance?

A prudent company spreads its operating balance across more than one counterparty and sets a maximum cap per provider, calculated over total available cash. That cap varies with each company's risk tolerance, but it always limits a fraction of the total balance, never all of it, to a single entity. Concentrating the entire operating balance in one provider multiplies the impact of any counterparty event, from a temporary freeze to insolvency.

What does a third party audit or attestation actually prove?

A financial audit proves that a provider's financial statements reasonably reflect its position on a given date, while a third party attestation usually verifies a point in time control, such as a process or a balance existing at a specific moment. Neither certifies that a company will be able to withdraw its balance at any point in the future: that depends on licensing, segregation and real liquidity, not on the paperwork attached. A company must read the stated scope of each report before treating it as proof.

What document should a company request before leaving balance with a digital asset platform?

The document backing each answer depends on the criterion being tested: the license or registration with the relevant regulator, the custody agreement or terms of service describing fund segregation, and the most recent audit or attestation report with its stated scope and date. A company that cannot obtain any of these three documents in writing should treat that absence as a warning sign, not an administrative detail.

Want your company to add stablecoins to its operations?

Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.

Join the waitlist

Related articles

Treasury

Export invoice factoring: when it actually pays off

Export invoice factoring advances payment on a foreign receivable for a discount. This guide shows how to calculate that discount as an annualized rate and when it is worth paying.

12 min read
Export invoice factoring: when it actually pays off
Treasury

Multi Currency Bank Reconciliation: A Step-by-Step Method

Reconciling several bank accounts in several currencies is not one converted total against the ledger. It is one statement per account, items in transit specific to each currency, correspondent bank fees that arrive net, and a foreign exchange difference that has to be isolated and posted.

10 min read
Multi Currency Bank Reconciliation: A Step-by-Step Method
Treasury

Treasury Policy Template for SMBs: Sections and Sign-Off

Without a written treasury policy, every payment depends on who happens to be around that day. This guide is a template: seven sections, each with a drafter and a signer.

11 min read
Treasury Policy Template for SMBs: Sections and Sign-Off