Ali Khawaja on Digital Asset Auditing & Valuation
1. Why Digital Assets Change the Audit
Digital assets do not eliminate traditional audit concepts; they change how those concepts are evidenced. Auditors still evaluate existence, rights and obligations, completeness, valuation, cutoff, presentation, and disclosure. The challenge is that blockchain records, exchanges, custodians, wallets, smart contracts, and token economics distribute evidence across systems that may operate continuously and across jurisdictions.
The AICPA's digital asset resources emphasize that accounting and auditing considerations continue to evolve. Auditors should begin by understanding the specific asset and activity rather than applying a generic crypto checklist. Bitcoin held in qualified custody, a locked venture token, a staking reward receivable, and a loan of stablecoins present very different risks.
2. Understanding the Asset and Transaction Flow
Before designing procedures, the audit team should map the full transaction flow. This includes where trades are initiated, which exchanges or over-the-counter counterparties are used, how transactions are approved, how assets settle, where assets are held, how records enter the general ledger, and who reconciles internal records to blockchain or custodian data.
3. Existence and Rights
Existence testing may include inspecting blockchain balances, obtaining confirmations from custodians or exchanges, and reconciling wallet activity. Yet rights and obligations can be more difficult. The audit team should understand who is the legal customer of the custodian, whether assets are segregated, whether the entity can direct transfers, whether liens or lending arrangements exist, and whether customer and proprietary assets are commingled.
Proof-of-control procedures, such as signing a message or executing a small test transaction, may provide evidence in some circumstances, but they must be carefully designed. A test transaction can show access to a key; it may not establish exclusive control, legal title, or the absence of undisclosed obligations.
4. Custody and Private-Key Risk
Custody is central because possession or control of a private key can enable irreversible transfers. Risks include theft, loss of keys, unauthorized transactions, compromised credentials, weak segregation of duties, and failure of a custodian. The SEC has repeatedly highlighted that digital asset custody involves mechanics and risks that differ from traditional securities, including the potential inability to reverse fraudulent or erroneous transfers.
Auditors should evaluate the custody model: direct self-custody, omnibus custody, segregated wallets, multi-signature arrangements, or sub-custody. Important controls include withdrawal allowlists, multi-person approval, cold-storage procedures, key generation ceremonies, backup and recovery, incident response, and monitoring of privileged access.
5. Valuation and Principal Markets
Digital assets may trade on numerous venues at different prices and levels of liquidity. Valuation therefore requires more than selecting the highest-volume screen price at year-end. Management should identify the principal market, or in the absence of a principal market, the most advantageous market, consistent with the applicable fair value framework. Auditors should evaluate the market selected, the reliability of pricing sources, trading activity, bid-ask spreads, restrictions, and whether the entity has access to the market.
For less liquid tokens, locked assets, or instruments with transfer restrictions, observable prices may require adjustment or a model-based valuation. Auditors should understand the economics of the restriction and whether it is an attribute of the asset or specific to the holder. The AICPA has identified valuation as a particularly complex area in digital asset audits and provides targeted guidance on controls and procedures.
6. Completeness and Blockchain Evidence
Public blockchain data can strengthen evidence, but completeness remains challenging. The auditor may see known wallet addresses while remaining unaware of undisclosed addresses, assets held through intermediaries, decentralized finance positions, staking arrangements, or tokens received through airdrops and forks. Procedures may include inquiries, inspection of exchange and custodian accounts, analysis of fiat transfers, wallet discovery processes, review of governance documentation, and reconciliation of all known addresses to the ledger.
Blockchain explorers are tools, not audit conclusions. The team should understand chain reorganizations, token contracts, wrapped assets, bridges, layer-two networks, and whether the chosen data source captures the relevant activity accurately.
7. Internal Controls and Service Providers
Digital asset operations often rely on exchanges, custodians, administrators, pricing vendors, and technology providers. Auditors should understand which controls operate at the entity and which operate at service organizations. SOC reports may be relevant, but the scope, period, control objectives, subservice organizations, and complementary user entity controls require evaluation. A report over general technology controls may not address ownership, transaction authorization, staking, or asset segregation.
8. Staking, Lending, and Other Activities
Holding a token may be only the beginning. Entities may stake assets, delegate to validators, lend through centralized or decentralized platforms, provide liquidity, receive rewards, or use derivatives. Each activity changes the risk profile and may create additional assets, liabilities, revenue streams, restrictions, counterparty exposure, and disclosure considerations. Audit teams should understand protocol mechanics, contractual terms, slashing risk, lock-up periods, reward calculation, and whether assets remain under the entity's control.
9. Practical Audit Scenario
Assume a registered product holds bitcoin with a third-party custodian and values the position using an index calculated from several exchanges. A strong audit approach would not stop at confirming the custodian balance. The team would evaluate the legal custody arrangement, obtain evidence of rights, assess the custodian control environment, reconcile transactions, test cutoff around the reporting date, evaluate the index methodology and constituent exchanges, and confirm that disclosures describe custody and valuation risks appropriately.
Now assume the product also earns staking rewards on another token through a sub-custodian. The audit plan must expand to address delegation, reward completeness, validator fees, lock-up and unbonding periods, slashing exposure, valuation of rewards, and whether service-organization reports cover the relevant controls. The additional activity is not simply another revenue test; it changes the custody and rights analysis.
10. Key Takeaways
· Start with the specific asset, protocol, and custody model.
· Separate evidence of existence from evidence of rights and control.
· Treat private-key governance as a core financial reporting control.
· Evaluate the principal market, pricing source, liquidity, and restrictions.
· Use blockchain data as part of an evidence package, not as a substitute for judgment.
· Expand the audit approach for staking, lending, wrapped assets, and decentralized finance.
Selected Authoritative References
· AICPA and CIMA, Accounting for and Auditing of Digital Assets Practice Aid (nonauthoritative guidance).
· AICPA and CIMA, Digital Assets and Blockchain Resources, including materials on existence, rights and obligations, and valuation.
· Financial Accounting Standards Board, ASU 2023-08, Accounting for and Disclosure of Crypto Assets.
· PCAOB AS 1105, Audit Evidence, and AS 2501, Auditing Accounting Estimates, Including Fair Value Measurements.
· U.S. Securities and Exchange Commission staff materials addressing digital asset custody and distributed ledger technology.
About the Author
Ali Khawaja is an accounting professional with experience supporting investment management audit engagements involving registered funds, private investments, Level 3 securities, broker-dealers, quarterly reviews, and digital asset-related engagements. His professional interests include fair value measurement, financial reporting, internal controls, and the practical application of auditing standards to complex investment products.

Comments
Post a Comment