Cybersecurity, IT General Controls and the Statutory Audit of Crypto-Asset Service Providers (CASPs)

Why Information Technology Controls Matter for Blockchain Businesses

Technology is the foundation upon which Crypto-Asset Service Providers (CASPs) and blockchain businesses operate. Trading platforms, custody systems, digital wallets, blockchain nodes, cloud infrastructure and financial reporting systems all depend upon secure and reliable technology.

As digital asset businesses continue to grow, cybersecurity and information technology governance have become board-level priorities. Cyber incidents, unauthorised access, ransomware attacks and operational failures may not only disrupt business operations but also affect the integrity of financial reporting and the safeguarding of digital assets.

Although a statutory audit is not a cybersecurity audit or a penetration test, International Standards on Auditing (ISA) require auditors to obtain an understanding of the information systems and internal controls that are relevant to the preparation of the financial statements.

For Crypto-Asset Service Providers, effective IT General Controls (ITGCs) contribute to reliable financial reporting, operational resilience and regulatory compliance.

Our firm combines expertise in statutory auditing, digital assets and financial reporting to assess technology controls relevant to the audit while recognising the unique operational characteristics of blockchain businesses.


What Are IT General Controls?

IT General Controls (ITGCs) are the policies, procedures and technical safeguards that support the reliable operation of information systems.

They provide the foundation upon which automated financial reporting controls operate.

Typical IT General Controls include:

  • user access management;

  • privileged access controls;

  • authentication procedures;

  • password management;

  • change management;

  • backup and recovery;

  • system monitoring;

  • logging;

  • incident management;

  • software deployment controls;

  • cloud governance; and

  • business continuity arrangements.

Strong IT General Controls reduce the likelihood of unauthorised transactions, data loss and financial reporting errors.


Why IT Controls Are Critical for CASPs

Unlike many traditional businesses, CASPs rely heavily on technology for virtually every operational process.

Examples include:

  • processing customer transactions;

  • maintaining wallet infrastructure;

  • safeguarding private keys;

  • recording blockchain activity;

  • calculating customer balances;

  • generating financial information;

  • monitoring trading activity;

  • administering digital asset custody; and

  • supporting regulatory reporting.

Weak technology controls may therefore increase both operational risk and financial reporting risk.


Access Management

Controlling access to systems is one of the most important elements of an effective control environment.

Management should establish procedures governing:

  • user creation;

  • approval of access rights;

  • role-based permissions;

  • periodic review of access;

  • removal of inactive users;

  • privileged administrator accounts;

  • emergency access procedures; and

  • authentication mechanisms.

Access should be granted according to business responsibilities and reviewed regularly.


Multi-Factor Authentication

Where appropriate, organisations should implement Multi-Factor Authentication (MFA) to strengthen security.

MFA reduces the risk of unauthorised access by requiring users to verify their identity through multiple independent authentication methods.

Critical systems benefiting from MFA may include:

  • wallet administration;

  • cloud infrastructure;

  • accounting systems;

  • remote access platforms;

  • privileged administration accounts; and

  • email systems.

The effectiveness of authentication controls contributes to the overall strength of the control environment.


Change Management

Technology environments evolve continuously.

Software updates, infrastructure changes and application enhancements should be managed through formal change management procedures.

Good practice includes:

  • documented change requests;

  • technical testing;

  • management approval;

  • segregation between development and production environments;

  • implementation planning;

  • rollback procedures; and

  • post-implementation review.

Poorly controlled system changes may introduce errors affecting financial reporting.


Logging and Monitoring

Organisations should maintain appropriate system logs to support monitoring and incident investigation.

Examples include:

  • user login activity;

  • privileged account usage;

  • wallet administration events;

  • system configuration changes;

  • transaction approvals;

  • failed access attempts;

  • security alerts; and

  • administrator activities.

Monitoring should be proportionate to the organisation's size and operational complexity.


Backup and Disaster Recovery

Reliable backup procedures support operational resilience and business continuity.

Management should establish policies covering:

  • backup frequency;

  • secure storage;

  • encryption of backup media;

  • recovery testing;

  • restoration procedures;

  • retention periods; and

  • responsibilities for backup management.

Regular testing provides confidence that systems can be restored following an operational disruption.


Business Continuity Planning

Every CASP should establish a Business Continuity Plan (BCP) appropriate to its operations.

The plan should address:

  • cyber incidents;

  • technology failures;

  • cloud service outages;

  • loss of key personnel;

  • telecommunications disruption;

  • physical access restrictions;

  • recovery priorities; and

  • communication with stakeholders.

Business continuity planning demonstrates organisational resilience and supports sound governance.


Cloud Service Providers

Many blockchain businesses rely upon cloud infrastructure.

Management should implement governance procedures covering:

  • provider selection;

  • contractual arrangements;

  • service monitoring;

  • information security responsibilities;

  • data protection;

  • resilience;

  • access controls; and

  • contingency arrangements.

Although services may be outsourced, responsibility for governance remains with management.


Wallet Security Controls

Digital wallets require governance extending beyond traditional IT controls.

Management should establish documented procedures for:

  • wallet creation;

  • authorisation of transfers;

  • multi-signature arrangements where appropriate;

  • key storage;

  • recovery procedures;

  • wallet inventories;

  • transaction approval workflows; and

  • periodic review of wallet activity.

Strong wallet governance contributes directly to safeguarding digital assets.


Cybersecurity Governance

Cybersecurity should be integrated into the organisation's overall governance framework.

Good governance generally includes:

  • board oversight;

  • information security policies;

  • employee awareness training;

  • vulnerability assessments;

  • incident response planning;

  • periodic risk assessments;

  • supplier security reviews; and

  • ongoing monitoring of emerging threats.

Cybersecurity is not solely an IT function—it is an enterprise-wide governance responsibility.


Third-Party Risk Management

CASPs frequently depend on external technology providers.

Management should oversee:

  • custodians;

  • cloud providers;

  • software vendors;

  • blockchain infrastructure providers;

  • cybersecurity consultants;

  • managed service providers; and

  • outsourced development teams.

Appropriate due diligence, contractual protections and ongoing monitoring reduce third-party risks.


IT Controls and the Statutory Audit

International Standards on Auditing require auditors to understand the information systems relevant to financial reporting.

Depending on the circumstances, auditors may evaluate controls relating to:

  • user access;

  • system changes;

  • automated financial reporting processes;

  • interface controls;

  • reconciliation procedures;

  • transaction processing; and

  • management review controls.

The extent of testing depends upon the assessed audit risks and the nature of the entity's systems.

Importantly, a statutory audit does not provide an opinion on the overall effectiveness of an organisation's cybersecurity programme.


Common IT Control Weaknesses

Common observations within growing blockchain businesses include:

  • excessive administrator access;

  • shared user accounts;

  • undocumented change procedures;

  • incomplete user access reviews;

  • weak password controls;

  • insufficient backup testing;

  • outdated system documentation;

  • lack of formal incident response procedures;

  • inconsistent monitoring of privileged users; and

  • inadequate documentation supporting cloud governance.

Addressing these weaknesses contributes to stronger operational resilience and more reliable financial reporting.


Best Practices for Directors

Directors should ensure that management:

  • reviews access rights regularly;

  • documents IT policies;

  • performs periodic risk assessments;

  • maintains tested backup procedures;

  • monitors critical systems;

  • oversees third-party providers;

  • reviews cybersecurity reports;

  • updates incident response plans; and

  • integrates technology governance into board reporting.

Technology governance should evolve alongside business growth.


Frequently Asked Questions

Does a statutory audit include penetration testing?

No. A statutory financial statement audit is not designed to test the effectiveness of cybersecurity defences through penetration testing or vulnerability assessments.

Will auditors review our cybersecurity controls?

Auditors obtain an understanding of technology controls relevant to financial reporting. The scope depends on the nature of the business and the assessed audit risks.

Are IT General Controls required for small CASPs?

Yes. Every organisation should establish technology controls appropriate to its size, complexity and risk profile.

Why is access management so important?

Restricting system access reduces the risk of unauthorised transactions, data manipulation and financial reporting errors.

Can outsourcing IT remove management's responsibilities?

No. Directors remain responsible for governance, oversight and ensuring that outsourced technology services support reliable financial reporting.


Independent Assurance for Technology-Driven Businesses

Technology underpins every aspect of a modern Crypto-Asset Service Provider. Effective governance over information systems, digital wallets and cybersecurity contributes not only to operational resilience but also to reliable financial reporting and stakeholder confidence.

Our firm provides statutory audit services to Cyprus Crypto-Asset Service Providers and blockchain businesses, combining expertise in International Standards on Auditing, IFRS Accounting Standards and blockchain technology. Through a risk-based audit approach, we assess the technology controls relevant to the financial statements while delivering independent assurance that supports transparent reporting and sound corporate governance.