Preparing for a Financial Statement Audit as a Digital Asset Company

Javier Salinas • July 30, 2026

Services: Audit Industries: Blockchain & Digital Assets


A financial statement audit is a significant undertaking for any business. For digital asset companies, the process can be especially complex because the audit must address assets, systems, controls, and transaction flows that often do not fit neatly into traditional audit procedures.

Digital asset companies may hold assets across self-custody wallets, qualified custodians, exchanges, multi-signature arrangements, decentralized protocols, staking platforms, lending arrangements, and treasury accounts. They may also transact at high volume, operate across jurisdictions, use multiple pricing sources, and rely on blockchain data that must be reconciled to internal books and records.

Preparing for the audit early can make a meaningful difference. The companies that move through the process most efficiently are typically those that have already documented their custody arrangements, valuation methodology, transaction controls, reconciliations, and accounting conclusions before fieldwork begins.

How FASB’s New Crypto Asset Guidance Affects the Audit

FASB’s ASU 2023-08 changed the crypto accounting model for certain assets. For fiscal years beginning after December 15, 2024, entities are required to measure qualifying crypto assets at fair value, with changes in fair value recognized in net income. Early adoption is permitted, subject to the standard’s transition rules.

The guidance does not apply to every digital asset. A threshold audit consideration is whether the asset falls within the scope of the standard. Among other requirements, the asset must be an intangible asset, must reside on a distributed ledger or similar technology, must be secured through cryptography, must be fungible, and must not be created or issued by the reporting entity or its related parties.

That scope analysis matters. Bitcoin and ether may often be straightforward examples of in-scope assets, but crypto asset accounting gaps involving other tokens, wrapped assets, NFTs, stablecoins, internally issued tokens, tokenized rights, and contractual arrangements may require more analysis.

Once an asset is within scope, the audit focus shifts to fair value measurement, income statement recognition, presentation, and disclosure. Auditors will evaluate whether the company’s fair value measurements are supportable, whether the selected market data is appropriate, whether the company’s principal market or most advantageous market analysis is documented, and whether required disclosures are complete and accurate.

For companies that have not fully transitioned from the prior cost-less-impairment model, ASU 2023-08 adoption will likely be a significant audit focus.

Core Audit Areas for Digital Asset Companies

Auditors do not approach digital assets as a single uniform balance sheet category. The audit response depends on the type of asset, how it is held, how it is used, and how the company records related activity. Several areas consistently receive close attention.

Existence & Completeness

Auditors need evidence that recorded digital assets exist and that the company’s records are complete. Blockchain data can be an important source of audit evidence, but it is not a complete audit answer by itself. Auditors must understand the wallet addresses, custodial records, exchange statements, transaction history, and internal accounting records that support the reported balances. They may also need to evaluate whether blockchain data has been extracted and interpreted accurately.

For self-custodied assets, auditors will generally focus on wallet ownership, private key controls, transaction authorization, and the company’s ability to demonstrate control over the relevant addresses. For assets held through custodians or exchanges, auditors will evaluate third-party statements, legal agreements, service organization controls, and reconciliation procedures.

Completeness is just as important as existence. Digital asset companies should be prepared to identify all wallets, accounts, custodians, exchanges, and protocols used during the reporting period, including wallets with zero period-end balances but relevant transaction activity.

Rights & Obligations

Holding a private key may provide evidence of control, but it does not automatically resolve the accounting question. Auditors will evaluate whether the company has enforceable rights to the asset and whether any restrictions, liens, collateral arrangements, lending agreements, staking terms, or custodial terms affect classification, presentation, or disclosure.

For example, assets held at a third-party platform may raise different accounting and audit considerations depending on whether the company has a direct property interest in the underlying asset, a contractual claim against the platform, or an interest in a pooled or commingled arrangement. Assets pledged as collateral, locked in staking, subject to withdrawal restrictions, or deployed in DeFi protocols may require additional analysis.

Companies should have custody agreements, wallet governance documentation, counterparty agreements, staking terms, lending arrangements, and collateral documentation organized before the audit begins.

Valuation

ASU 2023-08 makes valuation a central audit issue for in-scope crypto assets. For highly liquid assets traded in active markets, fair value may be supported by observable market data. For less liquid tokens, restricted assets, thinly traded markets, or assets with limited exchange availability, valuation can become more judgmental.

Auditors will evaluate the company’s fair value methodology under the fair value framework. This includes assessing the markets used, the reliability of pricing inputs, the timing of price observations, the treatment of exchange-specific pricing differences, and whether adjustments are required for restrictions or other asset-specific factors.

Pricing aggregators can be useful tools, but companies should not assume that an aggregator price alone resolves the valuation analysis. Auditors will want to understand the underlying exchanges or markets used by the pricing source, whether those markets are active and orderly, whether the data is observable, and whether the selected source is consistent with the company’s principal market analysis.

A well-documented valuation policy should address:

  • How the company determines fair value;
  • Which markets or data sources are used;
  • How the company evaluates principal market or most advantageous market considerations;
  • How illiquid or restricted tokens are valued;
  • How pricing exceptions are reviewed;
  • How fair value measurements are classified within the fair value hierarchy;
  • How management reviews and approves valuation conclusions.

Custody & Safeguarding Controls

Custody is one of the most important audit areas for digital asset companies. Auditors will want to understand how assets are safeguarded, who can initiate transactions, who can approve transfers, how private keys or signing authority are controlled, and how unauthorized transactions would be prevented or detected.

For self-custody arrangements, auditors may evaluate controls over hardware wallets, multi-signature approvals, seed phrase storage, key generation, access provisioning, employee onboarding and offboarding, disaster recovery, and incident response.

For third-party custody, auditors will review the custodian’s agreements, account statements, control reports, and the company’s own oversight controls. A SOC 1 Type 2 report can be helpful when it covers relevant controls, but it is not automatically sufficient. The company and auditor still need to evaluate the scope of the report, complementary user entity controls, subservice organizations, carve-outs, exceptions, and whether the report period aligns with the audit period. Depending on the facts, SOC 2 reporting, cybersecurity documentation, or other evidence may also be relevant.

Transaction Authorization & Recordkeeping

Digital asset companies often process high volumes of transactions across multiple systems. Auditors will focus on how transactions are authorized, executed, captured, classified, and reconciled.

Companies should be prepared to show clear procedures for:

  • Approving transfers;
  • Recording purchases, sales, swaps, staking rewards, airdrops, mining rewards, fees, and other activity;
  • Identifying related-party transactions;
  • Classifying realized and unrealized gains and losses;
  • Tracking tax lots and cost basis, where relevant;
  • Reconciling subledgers, wallet records, exchange data, and the general ledger;
  • Reviewing manual journal entries;
  • Investigating unreconciled differences.

Informal processes may create audit friction, especially when a small group of individuals can both initiate transfers and record accounting entries. Segregation of duties is particularly important where digital assets can be transferred quickly and irreversibly.

Revenue, Token Issuances, & Complex Transactions

Many digital asset companies have business models that create complex accounting questions beyond asset measurement. These may include token issuances, token warrants, SAFTs, staking arrangements, mining or validator rewards, exchange fees, custody fees, lending and borrowing arrangements, liquidity incentives, NFT transactions, software subscriptions, protocol revenue, and treasury management activity.

Auditors will evaluate whether the company has documented its accounting conclusions for material transaction types. In many cases, the analysis may require consideration of revenue recognition, liability versus equity classification, derivative accounting, consolidation, fair value measurement, impairment, principal-versus-agent considerations, and related-party disclosures.

Companies should not wait until the audit to develop technical accounting positions for significant digital asset activity. Where the accounting is judgmental, a contemporaneous technical memo can significantly reduce audit delays.

Internal Controls & Financial Close Readiness

Internal control readiness is often the difference between an efficient audit and a prolonged one. Auditors will evaluate whether the company has internal controls for crypto transactions that address the risks of material misstatement arising from digital asset activity.

Areas that commonly receive attention include:

  • Wallet creation and approval;
  • Custodian and exchange onboarding;
  • Private key and signing authority controls;
  • Multi-signature governance;
  • User access reviews;
  • Transaction approvals;
  • Completeness of wallet and account listings;
  • Reconciliations between blockchain records, custodians, exchanges, subledgers, and the general ledger;
  • Valuation review controls;
  • Financial statement close procedures;
  • Review of manual entries;
  • Cybersecurity and incident response protocols;
  • Monitoring of third-party service providers.

For companies preparing for a first audit, these controls may not need to look like those of a mature public company, but they do need to be designed, documented, and operating in a way that supports reliable financial reporting.

How to Prepare for a Digital Asset Audit

Preparation should begin before fieldwork. A digital asset company focused on audit readiness should consider the following steps:

  • Identify all digital assets held or transacted during the period;
  • Determine which assets are within the scope of ASU 2023-08;
  • Document the accounting treatment for significant asset classes and transaction types;
  • Prepare a wallet and account inventory, including custodians, exchanges, DeFi protocols, and cold storage arrangements;
  • Gather custody agreements, exchange statements, staking terms, lending agreements, collateral documents, and other relevant legal agreements;
  • Obtain SOC reports or other control reports from significant custodians and service providers, where available;
  • Document fair value methodologies, pricing sources, and principal market conclusions;
  • Reconcile blockchain, custodian, exchange, subledger, and general ledger records;
  • Resolve unreconciled differences before fieldwork;
  • Review segregation of duties and transaction approval procedures;
  • Prepare technical accounting memos for significant or judgmental transactions;
  • Ensure required financial statement presentation and disclosures are complete.

The goal is not to produce a polished audit package for its own sake. The goal is to demonstrate that management understands the company’s digital asset activity, has evaluated the relevant accounting issues, and can provide audit evidence that supports the financial statements.

Working With BPM on Your Digital Asset Audit

BPM provides audit services to companies across the blockchain & digital asset industry, including startups, infrastructure providers, exchanges, custodians, funds, token issuers, miners, validators, DeFi businesses, and companies holding digital assets as part of their treasury strategy.

Our audit professionals understand the accounting, control, valuation, and evidence-gathering issues that are specific to digital asset businesses. We also work closely with BPM’s technical accounting, outsourced accounting, tax, and Blockchain and Digital Assets professionals to help clients address issues that may arise before, during, or after the audit process.

Whether your company is preparing for its first crypto audit, adopting ASU 2023-08, improving its financial close process, evaluating custody controls, or documenting complex digital asset transactions, BPM can help you prepare for the expectations of a digital asset audit. To learn more, contact BPM’s Blockchain and Digital Assets team.

Profile picture of Javier Salinas

Javier Salinas

Partner, Tax - International
Blockchain and Digital Assets Leader

Javier is a distinguished international tax advisor with over 21 years experience. Clients rely on Javier when navigating complex cross-border …

Start the conversation

Looking for a team who understands where you’re headed and how to help you get there? Whether you’re building something new, managing growth or preserving success, let’s talk.


More insights in your inbox