Board Responsibilities and Corporate Governance for Crypto-Asset Service Providers (CASPs)
Directors' Duties, Governance Expectations and the Role of the Statutory Audit
The success of a Crypto-Asset Service Provider (CASP) depends not only on innovative technology but also on effective corporate governance. Directors are responsible for setting the strategic direction of the organisation, overseeing risk management, ensuring compliance with applicable legislation and promoting reliable financial reporting.
As the digital asset sector continues to mature under the European Union's Markets in Crypto-Assets Regulation (MiCA), expectations regarding governance have increased significantly. Investors, regulators, banking institutions and other stakeholders expect CASPs to demonstrate sound governance, transparent decision-making and robust internal controls.
While management is responsible for the day-to-day operation of the business, the board of directors retains ultimate responsibility for oversight. An effective board helps ensure that the organisation operates responsibly, maintains reliable accounting records and prepares financial statements that comply with the applicable financial reporting framework.
Our firm provides statutory audit services to Cyprus Crypto-Asset Service Providers and blockchain businesses, supporting directors through independent assurance while recognising the unique governance challenges associated with digital assets.
Why Corporate Governance Matters
Corporate governance establishes the framework through which an organisation is directed and controlled.
Strong governance promotes:
-
accountability;
-
transparency;
-
ethical business conduct;
-
effective decision-making;
-
financial discipline;
-
operational resilience;
-
investor confidence; and
-
long-term business sustainability.
Good governance is particularly important in the digital asset sector, where businesses often operate within rapidly changing technological and regulatory environments.
The Role of the Board of Directors
Although operational responsibilities are delegated to management, directors remain responsible for overseeing the organisation.
Typical board responsibilities include:
-
approving the business strategy;
-
overseeing financial reporting;
-
monitoring risk management;
-
reviewing internal controls;
-
safeguarding company assets;
-
approving significant transactions;
-
overseeing regulatory compliance;
-
appointing external auditors;
-
reviewing business performance; and
-
acting in the best interests of the company.
The board should receive timely and reliable information to support informed decision-making.
Financial Reporting Responsibilities
Directors are responsible for ensuring that annual financial statements are prepared in accordance with the applicable financial reporting framework.
This includes responsibility for:
-
maintaining adequate accounting records;
-
selecting appropriate accounting policies;
-
ensuring accounting policies are applied consistently;
-
approving significant accounting estimates;
-
overseeing year-end reporting;
-
reviewing financial statement disclosures; and
-
approving the financial statements before publication.
The statutory auditor provides an independent opinion on those financial statements but does not assume management's responsibilities.
Oversight of Internal Controls
The board should ensure that management establishes internal controls appropriate to the nature and complexity of the business.
Areas requiring oversight typically include:
-
financial reporting controls;
-
wallet governance;
-
digital asset custody;
-
segregation of duties;
-
transaction approvals;
-
access management;
-
cybersecurity;
-
outsourced service providers;
-
reconciliation procedures; and
-
document retention.
Periodic reporting from management assists directors in assessing whether controls remain effective.
Risk Management
Every CASP faces strategic, financial, operational and regulatory risks.
The board should ensure that management identifies, evaluates and monitors risks relating to:
-
digital assets;
-
market volatility;
-
liquidity;
-
cybersecurity;
-
fraud;
-
technology failures;
-
regulatory developments;
-
outsourced activities;
-
business continuity; and
-
financial reporting.
Risk management should form part of regular board discussions rather than being considered only during periods of difficulty.
Governance over Digital Assets
Boards should understand how digital assets are acquired, safeguarded and recorded.
Key governance questions include:
-
Who approves new wallets?
-
Who controls private keys?
-
Are wallet inventories maintained?
-
How are client assets distinguished from company assets?
-
How are wallet balances reconciled?
-
What authorisation is required for transfers?
-
Are multi-signature arrangements appropriate?
-
How are custody providers monitored?
Although directors need not be blockchain specialists, they should understand the governance framework surrounding digital assets.
Oversight of Technology
Technology is central to the operations of every blockchain business.
The board should receive regular reporting regarding:
Technology governance should be integrated into the organisation's broader risk management framework.
Regulatory Compliance
Directors should establish governance arrangements supporting compliance with applicable legal and regulatory obligations.
This includes oversight of:
-
regulatory reporting;
-
anti-money laundering compliance;
-
sanctions compliance;
-
data protection;
-
corporate filings;
-
financial reporting deadlines;
-
tax obligations; and
-
internal compliance monitoring.
Compliance should be viewed as an ongoing governance responsibility rather than a periodic administrative exercise.
Audit Committee Considerations
Larger organisations may establish an audit committee or assign equivalent responsibilities to the board.
Typical responsibilities include:
-
overseeing the financial reporting process;
-
reviewing significant accounting judgements;
-
monitoring internal controls;
-
overseeing the statutory audit;
-
reviewing the auditor's findings;
-
monitoring implementation of agreed actions; and
-
safeguarding auditor independence.
Even where no formal audit committee exists, these responsibilities remain important.
Working with the External Auditor
A constructive relationship with the external auditor contributes to an efficient audit.
Directors should:
-
approve the auditor's appointment;
-
review the audit timetable;
-
discuss significant accounting matters;
-
consider audit findings;
-
oversee implementation of recommendations; and
-
ensure management provides the auditor with unrestricted access to relevant information.
The statutory auditor remains independent from management throughout the engagement.
Board Reporting
Effective governance depends on timely management information.
Regular board reporting may include:
-
financial performance;
-
liquidity;
-
digital asset holdings;
-
significant operational incidents;
-
compliance matters;
-
internal control observations;
-
cybersecurity updates;
-
litigation;
-
regulatory developments; and
-
progress against strategic objectives.
Reliable reporting enables directors to discharge their responsibilities effectively.
Common Governance Weaknesses
Statutory audits of growing blockchain businesses frequently identify governance improvements such as:
-
board meetings not held regularly;
-
incomplete board minutes;
-
undocumented approval processes;
-
limited oversight of technology risks;
-
unclear reporting responsibilities;
-
inadequate review of financial information;
-
insufficient monitoring of outsourced providers;
-
absence of documented risk registers; and
-
delayed implementation of internal control improvements.
Addressing these matters strengthens organisational resilience.
Characteristics of Well-Governed CASPs
Well-governed organisations generally demonstrate:
-
active board engagement;
-
clearly documented responsibilities;
-
reliable financial reporting;
-
effective internal controls;
-
regular management reporting;
-
strong risk management;
-
appropriate technology governance;
-
transparent decision-making;
-
timely regulatory compliance; and
-
constructive engagement with the external auditor.
Good governance supports sustainable growth while reducing operational and financial reporting risks.
Frequently Asked Questions
Are directors responsible for preparing the financial statements?
Yes. Directors are responsible for preparing the financial statements and maintaining adequate accounting records. The external auditor provides an independent opinion on those financial statements.
Do directors need technical blockchain expertise?
Not necessarily. However, directors should understand the business model, the principal risks associated with digital assets and the governance arrangements established to manage those risks.
Can directors rely entirely on management?
No. Directors may delegate operational responsibilities but remain responsible for oversight, governance and monitoring the organisation's performance.
Does the statutory auditor report internal control weaknesses?
Where appropriate, auditors communicate significant deficiencies in internal controls identified during the audit to those charged with governance. This communication does not constitute a comprehensive review of all controls.
Why is board documentation important?
Board minutes and supporting papers provide evidence of governance, oversight and significant decisions. They also assist directors in demonstrating that appropriate matters have been considered and approved.
Governance Creates Confidence
Strong corporate governance is one of the defining characteristics of successful Crypto-Asset Service Providers. As the regulatory environment continues to evolve, organisations that invest in effective governance, transparent financial reporting and sound risk management are better positioned to earn the confidence of regulators, investors, banking partners and clients.
Our firm provides statutory audit services to Cyprus Crypto-Asset Service Providers and other blockchain businesses, combining expertise in International Standards on Auditing, IFRS Accounting Standards and blockchain technology. Through independent assurance and a risk-focused audit approach, we support directors in meeting their governance responsibilities while enhancing confidence in the organisation's financial reporting.