An institutional crypto product is a chain of obligations rather than a single trade. Investors, sponsors, portfolio managers, brokers, venues, market makers, custodians, banks, administrators, pricing agents, auditors, technology providers, and oversight teams can all participate. The product works only when assets, cash, instructions, records, and authority remain aligned across that chain.
Stack analysis is a method for finding where the economic claim changes hands and where a failure can interrupt it. It prevents a familiar brand or polished interface from standing in for due diligence. The analyst traces a normal transaction and several stressed transactions from decision through execution, settlement, custody, valuation, accounting, reporting, redemption, and final return of assets.
What you will learn
- Map every role, legal entity, asset location, and critical data flow
- Perform product, counterparty, technology, operational, and financial diligence
- Test end-to-end settlement, valuation, accounting, incidents, and exit scenarios
Begin with the economic and legal claim
Identify the investor's instrument and obligor. A direct token, fund share, note, derivative, deposit token, and custody account create different rights. Record governing documents, jurisdiction, priority, collateral, redemption, transfer restrictions, fees, and termination events. Then identify every legal entity that holds assets, owes performance, or can exercise control.
Corporate groups deserve entity-level analysis because a trading brand may use separate affiliates for custody, lending, and execution. Guarantees, capital, licenses, and insolvency treatment may not extend across them. A due-diligence map should connect each service to the signed contract, asset location, bank account, wallet, and subcontractor rather than relying on group-level descriptions.
Trace execution and settlement as state changes
Write down what happens when an order is authorized, routed, filled, allocated, confirmed, funded, and settled. Specify when market risk begins, when counterparty exposure arises, when legal title changes, and when assets become reusable. Distinguish an exchange's internal ledger update from blockchain finality and a bank payment instruction from final available cash.
The same map should cover failed and partial states: an order fills but cash does not arrive; crypto transfers but the receiving venue does not credit it; a chain reorganizes; a bank closes; a sanctions review pauses payment; or a pricing source fails. Ownership of each exception and the source of truth should be defined before production.
Due diligence tests evidence across domains
Financial diligence examines capital, liquidity, revenue dependence, insurance, audited statements, and funding. Legal diligence reviews rights, liabilities, collateral, default, data, subcontracting, and applicable regimes. Operational diligence tests staff, segregation of duties, reconciliations, service levels, change management, incident history, business continuity, and capacity. Technology diligence covers key management, code, privileged access, infrastructure, monitoring, dependencies, and recovery.
Market diligence evaluates spread, depth, market impact, hedging, benchmark methodology, valuation, and behavior during dislocation. Compliance assesses onboarding, screening, surveillance, conflicts, and reporting obligations. Accounting and tax specialists determine treatment for the actual entity, instrument, and jurisdiction. No single badge, audit, license, proof-of-reserves exercise, or penetration test spans all these questions.
Data, valuation, and accounting must reconcile
A complete record links orders, fills, fees, cash, blockchain transactions, custodian subledgers, positions, valuations, and the general ledger. Price policies identify sources, timestamps, hierarchy, outlier handling, illiquid assets, forks, and unavailable data. Independent review should be able to reproduce material balances and explain differences rather than accept a dashboard total.
Continuous crypto markets meet periodic financial reporting through controlled cutoffs. That creates timing differences, not permission to choose favorable prices. Accounting conclusions and disclosures depend on applicable standards and jurisdiction, while operational systems must preserve the evidence those conclusions require. Data lineage is therefore part of financial control, not merely a technology concern.
Resilience is tested through exits and incidents
Tabletop exercises should combine cyber compromise, provider insolvency, market gaps, frozen banking, chain congestion, valuation outages, and unavailable decision-makers. Teams practice who can restrict transactions, move collateral, notify stakeholders, preserve evidence, and authorize an alternate provider. Recovery objectives should reflect the economic cost of delay, not generic technology targets alone.
Exit readiness covers termination rights, return of assets and collateral, pending settlements, replacement custody, alternate execution, wallet allowlists, data exports, and historical records. Concentration should be measured through shared banks, custodians, clouds, software, pricing sources, and owners. The institutional stack is ready when its participants can explain normal operation, survive exceptions, and unwind without discovering essential dependencies too late.
Common misconceptions
“Institutional adoption can be measured mainly by announced buying pressure.”
Durable activity depends on product rights, custody, liquidity, settlement, data, controls, accounting, compliance, and client demand operating together over time.
“A regulated provider with an audit can be treated as fully diligenced.”
Regulation and audits have defined scopes; institutions still need entity, product, contract, financial, operational, technology, market, and exit analysis.
Risks and limitations
- Hidden affiliates or subcontractors can concentrate obligations in entities that lack expected capital, permissions, or contractual accountability.
- Asynchronous records across blockchains, banks, custodians, venues, and books can conceal missing assets or unsettled exposures.
- Shared infrastructure can cause several apparently independent providers to fail at the same time.
- Weak portability can trap assets, collateral, and records when a provider relationship deteriorates or must end quickly.
- Valuation and accounting errors can propagate from unreliable source data into financial statements, limits, and investor reporting.
Key takeaways
- The stack begins with the investor's claim and every legal entity that supports it.
- Execution is incomplete until cash, assets, ownership, and records reach defined final states.
- Institutional due diligence requires several domains of evidence rather than one assurance artifact.
- Data lineage connects market operations to valuation, accounting, and oversight.
- Incident and exit tests reveal dependencies that normal-operation diagrams miss.
Primary and further reading
Test your understanding
Score at least 2 out of 3 to complete this lesson. Explanations appear after you submit.