I wouldn't just do coin control because you ABSOLUTELY do not want to fuck it up and connect your KYC and noKYC stacks.
too easy to make a mistake.
Separate bip44 wallets should be ok if you have a good UI to handle it. Ive never used it. tbh I'd just install Sparrow and use two completely separate seeds with different signing devices.
but since most mistakes happen due to user error, it's better to use tools you are comfortable with.