Auditing Crypto-Assets under International Standards on Auditing (ISA)
How Independent Auditors Obtain Audit Evidence in Blockchain and Digital Asset Businesses
The emergence of blockchain technology and digital assets has transformed the way businesses create, transfer and safeguard value. Crypto-assets, distributed ledger technology and decentralised transaction processing present auditors with new challenges that require both technical expertise and a thorough understanding of International Standards on Auditing (ISA).
Although blockchain technology is innovative, the objective of a statutory audit remains unchanged. The auditor's responsibility is to obtain reasonable assurance that the financial statements are free from material misstatement, whether caused by fraud or error, and to express an independent opinion on those financial statements.
Auditing a blockchain business therefore requires the application of established auditing principles to a technology-driven environment, supported by an understanding of digital assets, wallet infrastructure, custody models and blockchain transaction flows.
The Objective of a Statutory Audit
A statutory audit is conducted in accordance with International Standards on Auditing, which require auditors to:
-
identify and assess risks of material misstatement;
-
understand the entity and its internal control environment;
-
obtain sufficient appropriate audit evidence;
-
evaluate accounting estimates and judgements;
-
assess the appropriateness of accounting policies;
-
conclude whether the financial statements have been prepared in accordance with the applicable financial reporting framework; and
-
issue an independent auditor's report.
These objectives apply equally to blockchain businesses and traditional organisations. What differs is the nature of the audit evidence and the specific risks that must be addressed.
Understanding the Business and Its Technology
Audit planning begins with developing a detailed understanding of the client's business model.
For a Crypto-Asset Service Provider (CASP) or blockchain business, this typically includes understanding:
-
the services offered;
-
the types of crypto-assets handled;
-
blockchain networks utilised;
-
custody arrangements;
-
wallet infrastructure;
-
revenue streams;
-
technology architecture;
-
outsourced service providers;
-
governance framework; and
-
regulatory environment.
This understanding enables the auditor to identify areas where material misstatements are more likely to arise.
Risk Assessment in Blockchain Audits
Every audit is risk-based.
Blockchain businesses often involve risks that differ from those encountered in conventional industries.
Examples include:
-
unauthorised wallet access;
-
loss of private keys;
-
inaccurate recording of blockchain transactions;
-
complex digital asset valuations;
-
reliance on third-party custodians;
-
smart contract vulnerabilities;
-
rapidly changing technology;
-
cybersecurity incidents;
-
fraud involving digital assets; and
-
evolving regulatory requirements.
The auditor assesses these risks before determining the nature, timing and extent of audit procedures.
Obtaining Audit Evidence for Crypto-Assets
One of the most significant aspects of a blockchain audit is obtaining sufficient and appropriate audit evidence relating to crypto-assets.
Unlike physical assets or traditional bank balances, crypto-assets exist on distributed ledger networks and may be controlled through private cryptographic keys.
Audit procedures are designed to obtain evidence regarding:
-
existence;
-
ownership and control;
-
rights and obligations;
-
completeness;
-
valuation;
-
presentation; and
-
disclosure.
The precise procedures depend on the entity's business model, the custody arrangements in place and the assessed audit risks.
Verifying Ownership and Control
Establishing that the entity controls the crypto-assets recognised in its financial statements is a key audit objective.
Depending on the circumstances, auditors may evaluate:
-
wallet ownership records;
-
custody agreements;
-
internal authorisation procedures;
-
governance over private keys;
-
documentation supporting wallet creation;
-
evidence relating to multi-signature arrangements; and
-
confirmations obtained from independent custodians where appropriate.
Ownership cannot be established solely by observing blockchain balances. Auditors must also consider whether the entity has the legal rights and practical ability to control the assets.
Reviewing Blockchain Transactions
Public blockchain networks provide transparent records of transactions.
These records may assist auditors in tracing transactions between wallets, confirming transaction dates and understanding transaction histories.
However, blockchain data alone is rarely sufficient.
Auditors also examine:
-
accounting records;
-
contracts;
-
invoices;
-
exchange reports;
-
reconciliation schedules;
-
supporting management documentation; and
-
explanations for unusual or significant transactions.
Combining blockchain information with conventional audit evidence enables the auditor to reach appropriate conclusions.
Evaluating Digital Asset Valuation
Valuing crypto-assets can be challenging because market prices may fluctuate significantly over short periods.
Auditors evaluate whether management's valuation methodology is appropriate and consistently applied.
Considerations may include:
-
the accounting framework adopted;
-
availability of observable market data;
-
principal markets;
-
pricing sources;
-
valuation techniques;
-
impairment assessments, where applicable; and
-
disclosures relating to estimation uncertainty.
Material valuation judgements frequently receive particular audit attention.
Internal Controls and Technology
Strong internal controls remain fundamental to reliable financial reporting.
Auditors assess controls relevant to the preparation of the financial statements, which may include controls over:
Where controls operate effectively, they may influence the nature and extent of substantive audit testing.
Fraud Considerations
International Standards on Auditing require auditors to consider the risk of fraud in every audit.
Within blockchain businesses, fraud risks may include:
-
misappropriation of digital assets;
-
fictitious transactions;
-
unauthorised transfers;
-
management override of controls;
-
related-party transactions;
-
manipulation of valuations; and
-
concealment of liabilities.
Auditors maintain professional scepticism throughout the engagement and design procedures responsive to assessed fraud risks.
The Importance of Documentation
Audit conclusions must be supported by appropriate documentation.
Management should therefore retain comprehensive records including:
-
wallet inventories;
-
blockchain transaction references;
-
custody documentation;
-
reconciliation schedules;
-
accounting policies;
-
contracts;
-
board approvals;
-
valuation support; and
-
evidence supporting significant judgements.
Good documentation not only facilitates the audit but also strengthens financial reporting and corporate governance.
Specialist Knowledge Matters
Blockchain technology continues to evolve rapidly.
Auditors working with digital asset businesses benefit from understanding:
-
blockchain architecture;
-
wallet technologies;
-
consensus mechanisms;
-
custody models;
-
digital asset accounting;
-
information technology controls;
-
cybersecurity risks;
-
financial reporting requirements; and
-
the regulatory environment applicable to crypto businesses.
Combining technical audit expertise with an understanding of blockchain enables auditors to focus on the risks that matter most while delivering an efficient and high-quality statutory audit.
Frequently Asked Questions
Can blockchain itself replace a statutory audit?
No. Blockchain technology provides transparent transaction records, but a statutory audit involves evaluating the financial statements as a whole, including internal controls, accounting policies, estimates, disclosures and governance. A blockchain ledger is only one source of audit evidence.
Is viewing a wallet balance enough to verify ownership?
Not necessarily. Auditors must obtain sufficient appropriate evidence regarding the entity's rights and control over the crypto-assets, not merely confirm that a wallet contains a particular balance.
How do auditors assess digital asset valuations?
Auditors evaluate whether management has applied an appropriate valuation methodology consistent with the applicable accounting framework and whether sufficient supporting evidence exists for the recorded values.
Why are technology controls important?
Weak IT controls can increase the risk of unauthorised transactions, inaccurate financial reporting and loss of digital assets. Auditors therefore assess those controls that are relevant to the audit.
Do blockchain businesses require specialist auditors?
While statutory audits are conducted in accordance with the same International Standards on Auditing across all industries, experience in blockchain technology, digital assets and crypto-asset business models enables auditors to understand sector-specific risks more effectively.
Independent Audit Services for Blockchain Businesses
Digital asset businesses require auditors who combine rigorous application of International Standards on Auditing with an appreciation of the technology, governance and operational risks that characterise the blockchain ecosystem.
Our firm provides statutory audit services to Cyprus Crypto-Asset Service Providers (CASPs) and other blockchain businesses, delivering independent assurance supported by expertise in financial reporting, blockchain technology and digital asset operations. We work closely with management and those charged with governance to deliver audits that are efficient, risk-focused and aligned with professional standards.