Verifying that crypto-assets exist, that the entity owns them and that it controls the keys is the most distinctive part of a digital-asset audit. It cannot be settled with a bank confirmation, so the audit relies on on-chain evidence, cryptographic proof of control and, where assets sit with third parties, confirmation from exchanges and custodians.
Around that sits the control environment. Trading platforms, custody systems, digital wallets, blockchain nodes, cloud infrastructure and the financial reporting systems themselves all depend on technology working reliably, so IT general controls and the governance framework around key management form part of the audit scope.
Proof of Reserves exercises are often confused with an audit. They are a useful transparency measure, but they are not a substitute for an independent audit of financial statements — the page below sets out exactly where the difference lies.