Internal Controls for Crypto-Asset Service Providers (CASPs) and Blockchain Businesses

Building a Strong Governance and Control Environment for Digital Asset Organisations

As the digital asset industry continues to mature, effective internal controls have become a fundamental component of sound corporate governance. For Crypto-Asset Service Providers (CASPs), cryptocurrency exchanges, custodians and other blockchain businesses, internal controls are essential not only for safeguarding assets but also for supporting reliable financial reporting, regulatory compliance and operational resilience.

The introduction of the European Union's Markets in Crypto-Assets Regulation (MiCA) has reinforced the importance of governance, organisational arrangements and prudent risk management within regulated crypto businesses. Directors are expected to establish systems that enable the organisation to identify, manage and monitor the risks associated with digital assets while maintaining accurate financial records and protecting client interests.

From an audit perspective, a well-designed control environment reduces the risk of material misstatement and contributes to a more efficient statutory audit. Conversely, weak governance or inadequate controls often result in increased audit procedures, higher operational risk and greater regulatory scrutiny.

Our firm assists Cyprus CASPs and blockchain businesses by performing statutory audits, evaluating financial reporting controls and providing independent observations that help organisations strengthen their governance frameworks.


What Are Internal Controls?

Internal controls are the policies, procedures and organisational measures implemented by management to provide reasonable assurance that the organisation achieves its objectives.

These objectives generally include:

  • safeguarding company and client assets;

  • maintaining accurate accounting records;

  • preparing reliable financial statements;

  • complying with applicable laws and regulations;

  • preventing and detecting fraud;

  • ensuring operational efficiency; and

  • supporting sound corporate governance.

Internal controls are not limited to accounting processes. They extend across technology, operations, cybersecurity, compliance and executive oversight.


Why Internal Controls Are Critical for Blockchain Businesses

Blockchain businesses manage assets that can often be transferred rapidly and irrevocably. This creates risks that differ from those encountered in many traditional industries.

For example, organisations may face risks relating to:

  • unauthorised wallet access;

  • compromise of private keys;

  • cyberattacks;

  • operational errors;

  • fraud;

  • inaccurate recording of blockchain transactions;

  • inadequate segregation of duties;

  • failures in third-party service providers;

  • technology outages; and

  • ineffective governance.

Appropriate internal controls help reduce these risks while supporting confidence among investors, clients, regulators and auditors.


Governance and the Tone from the Top

An effective control environment begins with governance.

The board of directors and senior management establish the organisational culture and define the expectations for ethical behaviour, accountability and risk management.

Good governance generally includes:

  • clearly documented organisational structures;

  • defined responsibilities and reporting lines;

  • board oversight of significant risks;

  • regular management reporting;

  • documented policies and procedures;

  • periodic review of internal controls; and

  • active monitoring of regulatory compliance.

A strong governance framework demonstrates that management is committed to maintaining a controlled operating environment.


Segregation of Duties

Segregation of duties is one of the most effective methods of reducing operational and fraud risk.

No individual should have complete control over an entire transaction from initiation through to recording and approval.

Depending on the size and complexity of the organisation, responsibilities should be appropriately separated between:

  • transaction initiation;

  • wallet administration;

  • accounting;

  • payment approval;

  • reconciliation;

  • system administration;

  • compliance monitoring; and

  • executive oversight.

Where staffing limitations make complete segregation impractical, compensating controls should be implemented.


Wallet Governance and Private Key Management

For blockchain businesses, digital wallets represent one of the most significant operational risks.

Management should establish clear procedures governing:

  • wallet creation;

  • wallet ownership;

  • authorised users;

  • private key generation;

  • secure storage of private keys;

  • backup procedures;

  • recovery mechanisms;

  • multi-signature approval arrangements;

  • wallet inventories; and

  • periodic reconciliation of wallet balances.

Documented governance over wallet administration assists both management and auditors in demonstrating effective control over digital assets.


Access Controls

Access to systems and digital assets should be restricted to authorised personnel based on business responsibilities.

Effective access management typically includes:

  • formal user approval procedures;

  • role-based access permissions;

  • periodic review of user privileges;

  • prompt removal of inactive accounts;

  • multi-factor authentication;

  • monitoring of privileged users; and

  • secure password management.

Access controls should extend to accounting systems, blockchain platforms, cloud infrastructure and supporting applications.


Reconciliations and Financial Reporting Controls

Accurate financial reporting depends upon timely reconciliation of accounting records to supporting evidence.

Management should establish procedures for reconciling:

  • digital wallet balances;

  • exchange accounts;

  • bank accounts;

  • client asset records;

  • accounting ledgers;

  • transaction reports;

  • fee calculations; and

  • treasury holdings.

Regular reconciliations assist in identifying discrepancies promptly and reduce the risk of material misstatements in the financial statements.


Cybersecurity Controls

Cybersecurity is a critical component of the internal control environment for blockchain businesses.

Management should implement appropriate measures to protect systems and digital assets against unauthorised access, malware, phishing attacks and other cyber threats.

Typical cybersecurity controls include:

  • endpoint protection;

  • network monitoring;

  • vulnerability management;

  • penetration testing;

  • security awareness training;

  • encryption;

  • incident response procedures;

  • log monitoring; and

  • regular security updates.

Although cybersecurity extends beyond the scope of a financial statement audit, technology controls relevant to financial reporting may form part of the auditor's assessment.


Outsourced Service Providers

Many blockchain businesses rely upon external providers for custody, cloud infrastructure, payment services, software development or information technology support.

Management remains responsible for ensuring that outsourced activities are appropriately governed.

This includes:

  • due diligence before appointment;

  • clearly documented contractual arrangements;

  • ongoing performance monitoring;

  • review of assurance reports where available;

  • assessment of information security practices; and

  • contingency planning should the provider become unavailable.

Oversight of outsourced service providers is an important element of operational resilience.


Business Continuity and Operational Resilience

Digital asset businesses should prepare for events that may disrupt normal operations.

Business continuity planning generally includes:

  • disaster recovery procedures;

  • backup of critical systems;

  • recovery testing;

  • alternative communication arrangements;

  • succession planning for key personnel;

  • incident response governance; and

  • procedures for restoring operations following significant disruptions.

Operational resilience supports both regulatory expectations and the long-term sustainability of the business.


The Role of Internal Controls in the Statutory Audit

International Standards on Auditing require auditors to obtain an understanding of the internal controls relevant to the preparation of the financial statements.

Where controls are appropriately designed and effectively implemented, they may reduce the extent of detailed substantive testing required in certain audit areas.

Conversely, significant deficiencies in controls may increase audit risk and require additional audit procedures.

The statutory audit therefore provides management with valuable observations regarding the control environment, while remaining independent and focused on the financial statements.


Common Control Weaknesses Observed in Blockchain Businesses

As blockchain businesses evolve, organisations frequently encounter similar governance challenges.

Examples include:

  • undocumented wallet procedures;

  • inadequate segregation of duties;

  • incomplete reconciliation processes;

  • insufficient documentation supporting digital asset balances;

  • excessive reliance on manual processes;

  • weak access controls;

  • inadequate monitoring of outsourced providers;

  • inconsistent accounting policies; and

  • limited board oversight of technology risks.

Addressing these issues proactively can improve governance and facilitate a smoother audit process.


Frequently Asked Questions

Are internal controls only relevant to large CASPs?

No. Every blockchain business should implement internal controls that are proportionate to its size, complexity and risk profile. Even smaller organisations benefit from clearly documented procedures and appropriate oversight.

Does the statutory auditor design our controls?

No. Designing and implementing internal controls is the responsibility of management. The auditor evaluates controls relevant to the audit but does not assume management's responsibilities.

Why are reconciliations important?

Regular reconciliations help ensure that accounting records agree with wallet balances, exchange statements and other supporting documentation, reducing the risk of errors and omissions.

Do auditors assess cybersecurity?

A statutory audit is not a cybersecurity audit. However, auditors consider technology controls where they are relevant to the preparation of the financial statements and the assessment of audit risk.

Can strong internal controls reduce audit disruption?

Yes. Well-documented processes, reliable reconciliations and effective governance generally make the audit process more efficient by reducing the need for extensive follow-up requests and additional testing.


Strengthening Governance Through Independent Assurance

Strong internal controls are essential for maintaining stakeholder confidence, protecting digital assets and supporting reliable financial reporting.

Our firm provides statutory audit services to Cyprus Crypto-Asset Service Providers and blockchain businesses, combining expertise in International Standards on Auditing, financial reporting and digital asset operations. Through a risk-focused audit approach, we help organisations demonstrate robust governance while delivering independent assurance in accordance with the highest professional standards.