Wallet Verification, Digital Asset Custody and Proof of Ownership in a Statutory Audit

How Auditors Verify the Existence, Ownership and Control of Crypto-Assets

One of the most distinctive aspects of auditing a blockchain business is verifying digital assets. Unlike cash held with a bank or securities held through traditional custodians, crypto-assets exist on distributed ledger networks and are controlled through cryptographic keys rather than physical possession.

Although blockchain technology provides an immutable record of transactions, a statutory audit requires considerably more than confirming wallet balances. Auditors must obtain sufficient and appropriate audit evidence regarding the existence, ownership, rights and obligations, valuation and presentation of digital assets within the financial statements.

For Crypto-Asset Service Providers (CASPs), exchanges, custodians and other blockchain businesses, establishing effective custody arrangements and maintaining comprehensive documentation are essential components of sound financial reporting and corporate governance.


Understanding Digital Asset Custody

Digital assets can be safeguarded using a variety of custody models.

These commonly include:

  • self-hosted wallets;

  • institutional custodians;

  • exchange wallets;

  • cold storage solutions;

  • hot wallets connected to the internet;

  • hardware wallets;

  • multi-signature wallets; and

  • hybrid custody arrangements.

Each model presents different operational, governance and audit considerations.

Understanding how assets are safeguarded is one of the first stages of planning a statutory audit.


Ownership Versus Control

A common misconception is that a wallet address proves ownership.

In reality, a blockchain address merely records that crypto-assets are associated with that address.

The auditor must determine whether the reporting entity has:

  • legal rights to the assets;

  • practical control over those assets;

  • authority to authorise transfers;

  • appropriate governance over wallet administration; and

  • supporting documentation demonstrating ownership.

This distinction is particularly important where crypto-assets are held by custodians or on behalf of clients.


Audit Objectives

When auditing digital assets, auditors generally seek evidence regarding:

  • existence of the assets;

  • ownership and legal rights;

  • control over private keys or custody arrangements;

  • completeness of recorded balances;

  • appropriate valuation;

  • proper classification;

  • presentation within the financial statements; and

  • adequacy of disclosures.

The audit procedures performed will depend upon the entity's business model and the assessed risks.


Understanding Wallet Structures

Many blockchain businesses operate multiple wallets across different blockchain networks.

Examples include:

  • treasury wallets;

  • operational wallets;

  • client custody wallets;

  • settlement wallets;

  • reserve wallets;

  • staking wallets;

  • liquidity wallets; and

  • testing environments.

Management should maintain a complete wallet register identifying:

  • wallet addresses;

  • purpose of each wallet;

  • authorised users;

  • blockchain network;

  • custody arrangements;

  • date established;

  • status (active or inactive); and

  • responsible business function.

A comprehensive wallet inventory greatly assists both internal governance and the statutory audit.


Private Key Governance

Control of digital assets ultimately depends upon control of private cryptographic keys.

Accordingly, management should establish documented procedures governing:

  • generation of private keys;

  • storage arrangements;

  • encryption;

  • backup procedures;

  • recovery processes;

  • approval of transfers;

  • emergency access arrangements;

  • key rotation where appropriate; and

  • monitoring of privileged access.

Weak governance over private keys significantly increases operational and financial reporting risks.


Multi-Signature Controls

Many organisations use multi-signature (multisig) wallets to strengthen governance.

These arrangements typically require multiple authorised individuals to approve transactions before transfers can be executed.

Benefits include:

  • reduced fraud risk;

  • segregation of duties;

  • improved governance;

  • stronger authorisation procedures;

  • reduced dependence upon one individual; and

  • enhanced operational resilience.

Auditors evaluate how these controls operate in practice rather than merely confirming that a multisig wallet exists.


Custody with Third-Party Providers

Many Crypto-Asset Service Providers use independent custodians to safeguard digital assets.

Where assets are held by external providers, auditors may consider:

  • custody agreements;

  • service level arrangements;

  • confirmation of balances;

  • responsibilities of each party;

  • governance over transfers;

  • independent assurance reports where available;

  • reconciliation procedures; and

  • management oversight of the custodian.

Management remains responsible for maintaining adequate accounting records even where custody has been outsourced.


Blockchain Verification

Public blockchains enable auditors to observe transaction histories and wallet balances.

Blockchain explorers may assist in:

  • confirming transaction dates;

  • tracing transfers;

  • identifying wallet activity;

  • reviewing historical balances; and

  • understanding transaction flows.

However, blockchain information alone is not sufficient audit evidence.

Auditors also consider contracts, accounting records, custody documentation, management representations and other corroborating evidence.


Reconciling Wallets to the Accounting Records

Regular reconciliations are fundamental to reliable financial reporting.

Management should periodically reconcile:

  • wallet balances;

  • blockchain records;

  • exchange statements;

  • accounting ledgers;

  • custody reports; and

  • client asset records where applicable.

Differences should be investigated promptly and documented appropriately.

These reconciliations form an important component of both internal controls and statutory audit procedures.


Client Assets

Crypto-Asset Service Providers frequently safeguard assets belonging to clients.

Management should maintain clear records identifying:

  • assets owned by the business;

  • client assets;

  • omnibus wallets;

  • segregated wallets;

  • restricted assets;

  • pledged assets; and

  • assets subject to contractual limitations.

Appropriate segregation assists management, auditors and regulators in understanding the entity's rights and obligations.


Documentation Supporting Ownership

Reliable documentation remains essential.

Examples include:

  • wallet registers;

  • custody agreements;

  • board approvals;

  • internal wallet authorisations;

  • exchange confirmations;

  • transaction reports;

  • reconciliation schedules;

  • accounting records;

  • blockchain references; and

  • supporting contractual documentation.

Good documentation strengthens both governance and audit efficiency.


Proof of Reserves Versus a Statutory Audit

Following developments within the digital asset industry, many organisations have introduced proof of reserves exercises.

Although proof of reserves may provide information regarding certain digital asset balances at a specific point in time, it is not equivalent to a statutory audit.

A statutory audit encompasses a much broader assessment, including:

  • accounting policies;

  • valuation;

  • internal controls;

  • governance;

  • liabilities;

  • revenue recognition;

  • financial statement presentation;

  • disclosures;

  • going concern considerations; and

  • compliance with International Standards on Auditing.

Accordingly, proof of reserves should not be regarded as a substitute for an independent statutory audit.


Common Custody Risks

Blockchain businesses commonly encounter risks including:

  • undocumented wallets;

  • poor key management;

  • inadequate segregation of duties;

  • reliance on a single individual;

  • incomplete reconciliations;

  • weak access controls;

  • undocumented transfers;

  • insufficient oversight of custodians; and

  • inadequate disaster recovery arrangements.

Addressing these risks contributes to stronger governance and more reliable financial reporting.


Frequently Asked Questions

Can auditors access private keys?

No. Auditors do not require possession of private keys. Audit procedures are designed to obtain sufficient appropriate evidence while preserving the security of the entity's digital assets.

Is a blockchain explorer enough to verify ownership?

No. Blockchain explorers provide valuable information regarding transactions and balances but do not establish legal ownership or control.

Does a third-party custodian remove management's responsibilities?

No. Directors remain responsible for maintaining adequate accounting records, implementing effective governance and preparing the financial statements.

What is the difference between custody and ownership?

Custody relates to safeguarding digital assets, whereas ownership concerns the legal rights to those assets. The two are not always identical.

Is proof of reserves the same as an audit?

No. Proof of reserves generally focuses on demonstrating certain asset balances. A statutory audit evaluates the financial statements as a whole in accordance with International Standards on Auditing.


Independent Audit Expertise for Digital Asset Businesses

Verifying crypto-assets requires more than reviewing blockchain transactions. It demands an understanding of custody models, governance, accounting, internal controls and the principles of International Standards on Auditing.

Our firm provides statutory audit services to Cyprus Crypto-Asset Service Providers and other blockchain businesses, combining expertise in blockchain technology, IFRS and independent assurance. Through a structured, risk-based audit approach, we help organisations demonstrate transparency, strengthen governance and enhance confidence among investors, regulators and other stakeholders.