Crypto audit support for auditors and their clients
Keep your auditor. Add the crypto expertise.
Specialist digital-asset audit evidence for engagements that already have an auditor. We verify wallet control cryptographically, read balances directly from the chain, reconcile on-chain activity to the ledger, and deliver working papers the audit file can rely on. For companies whose auditor cannot test the crypto balances, and for audit firms who need a crypto expert on the engagement.
Two Ways We Support an Audit
The engagement stays where it is. We bring the part of it that lives on the chain.
For companies with their own auditor
You have an auditor you trust, and the relationship works. What the audit is missing is someone who can verify wallet control, read balances from the chain, and reconcile on-chain activity to your ledger. We plug that gap and work alongside your auditor, so the engagement stays theirs and the digital-asset areas stop holding up sign-off.
- Your auditor keeps the engagement and issues the opinion
- We evidence the digital-asset balances they cannot test themselves
- The audit closes on time instead of stalling on crypto questions
For audit firms with crypto clients
A client holds digital assets and your audit programme has nowhere to send the confirmation letter. We act as your crypto specialist on the engagement: agree the procedures with you, perform the on-chain examination under your instruction, and deliver working papers your file can carry. You keep the client, the methodology, and the opinion.
- Engagement-level support under your instruction and review
- Working papers with documented methodology, ready for the file
- Strict confidentiality, one client or a whole portfolio
No auditor yet? If you need the whole statutory audit, opinion included, that is our Financial Statement Audits service, delivered with our ICPAC-licensed audit partner.
What We Deliver to the Audit
Audit evidence over the digital-asset areas, documented so it can be reviewed, challenged, and re-performed.
Wallet control verification
Cryptographic proof that the entity controls every reported address, by message signature or a nominal transfer performed on instruction. Hot, cold, multi-signature, and MPC arrangements, plus assets held with custodians.
Balances at the reporting date
Holdings read directly from the chain at the reporting date, not from a management schedule. Every figure traceable to a block and independently repeatable.
On-chain to ledger reconciliation
On-chain movement matched to the accounting records, with breaks investigated and explained rather than plugged.
Transaction classification
Internal transfers separated from genuine economic events across bridges, swaps, and exchange accounts, so disposals, income, and mere movement stop looking identical.
Related-party identification
Clustering of connected addresses and counterparties that points to related-party transactions the accounting system never recorded.
Working papers and methodology
Findings delivered as documented working papers: what was tested, how, against which blocks and records, and what could not be verified. Written to be reviewed, challenged, and filed.
How an Engagement Runs
Scoped with the audit team, delivered as working papers, supported until the opinion is signed.
Scoping
A call with you and, where one exists, the audit team. We agree the entities, wallets, exchange accounts, and custodians in scope, the reporting framework, and the timetable.
Engagement model
We agree who engages us: the auditor, using our work as an auditor's expert, or the company, with our output made available to the auditor. Confidentiality and independence are settled here, in writing.
On-chain examination
Wallet control verified cryptographically, balances read from the chain at the reporting date, activity reconciled to the ledger, and connected addresses identified.
Working papers delivered
The auditor receives documented procedures, evidence, and findings, including an explicit list of anything we could not verify. Nothing is asserted that cannot be re-performed.
Support through review
We stay available for audit queries, partner and EQR review questions, and regulator follow-ups until the opinion is signed.
Where Our Role Starts and Stops
Audit support has clean edges, and stating them up front is what makes the auditor's reliance on our work defensible.
We do
- Produce audit evidence over wallets, balances, and on-chain flows
- Verify wallet control cryptographically, never from screenshots
- Document every procedure so the file shows what was tested and how
- Answer audit, partner review, and regulator queries until sign-off
We do not
- Issue the audit opinion; that stays with the engaged audit firm
- Replace the auditor's judgement or responsibility for the audit
- Prepare the books we are evidencing; reconciliation is kept separate
- Assert anything we could not verify; it is reported as unverified
If your records are not reconciled yet, start with transaction reconciliation. If you need the full statutory audit rather than support inside one, see financial statement audits.
Crypto Audit Support FAQ
What is crypto audit support?
Specialist help with the digital-asset part of a financial statement audit, provided to whoever is running that audit. A conventional audit programme confirms a bank balance by writing to the bank. A wallet has nobody to write to: its balance is confirmed by proving control of a private key and reading the chain. Crypto audit support means we perform that examination, verifying wallet control, reading balances at the reporting date, reconciling on-chain activity to the ledger, and identifying connected addresses, and we hand the results to the auditor as documented working papers. The auditor keeps the engagement, applies their own judgement to our work, and issues the opinion.
We already have an auditor we trust. Do we have to switch?
No, and this service exists precisely so you do not have to. Your auditor keeps the engagement, the relationship, and the opinion. We are brought in for the digital-asset areas only: the wallet verification, on-chain balances, and reconciliation work that a generalist audit team cannot perform itself. Most companies that come to us are not unhappy with their auditor. They are stuck, because the audit cannot close until someone evidences the crypto balances, and nobody on the engagement can.
How do you work with the incumbent auditor?
Under one of two models, agreed at scoping. Either the audit firm engages us directly and uses our work as an auditor's expert under ISA 620, which gives them the most direct control over our procedures, or the company engages us and our output is made available to the auditor as evidence they evaluate under ISA 500. Both are ordinary, well-understood arrangements. In either case the auditor decides what to rely on and remains responsible for the opinion; our job is to make that reliance defensible by documenting exactly what we tested and how.
We are an audit firm. What do you actually give us?
Working papers you can put on the file. For each area: the procedures performed, the wallets and accounts covered, the blocks and records tested against, the results, and an explicit list of anything we could not verify. Wallet control is evidenced by cryptographic signature or a nominal transfer performed on instruction, never by accepting a screenshot. Balances are read from the chain and are independently re-performable by anyone who wants to check. You review the work, challenge it where you need to, and decide what it supports.
Can our firm use you across several clients?
Yes. Some firms bring us in for a single awkward engagement; others use us as their standing digital-asset specialists across a portfolio. Each engagement is scoped and priced on its own, information is never shared between clients, and we are comfortable operating quietly in the background of your client relationship. We do not compete for the audit: we are not the signing firm on your engagement and we do not want to be.
Does your work satisfy audit standards?
Our work is built to be relied on under them. Auditing standards let an auditor use the work of an expert, but they require the auditor to evaluate the expert's competence, objectivity, and methods. So we document all three: who did the work and their qualifications, the basis of our independence from the audited entity, and a methodology section that sets out each procedure in enough detail to be re-performed. The standards judgement always remains the auditor's, which is exactly how it should be.
Do you need access to our systems or private keys?
Never private keys, and we will not accept them if offered. Control of a wallet is proven by the holder signing a message we specify, or moving a nominal amount on our instruction, both of which demonstrate key control without disclosing anything. Beyond that we work from read-only material: address lists, exchange account exports, custody statements, and ledger extracts. Chain data itself is public; we read it directly rather than asking anyone for it.
What does the on-chain examination cover?
Wallet control for every reported address, balances at the reporting date read directly from the chain, reconciliation of on-chain movement to the accounting ledger, separation of internal transfers from genuine economic events across bridges and swaps, and clustering of connected addresses that indicate related-party transactions. We cover the major chains and the usual custody arrangements: hot and cold wallets, multi-signature, MPC, and third-party custodians. Anything that cannot be verified is reported as unverified rather than assumed.
Do you only work with audits in Cyprus?
No. The chain is the same from anywhere, and this work is performed remotely against public data and the records you provide, so we support audits under any jurisdiction's statutory framework. We are based in Cyprus and know the Cyprus and wider EU reporting environment first-hand, which helps where the engagement is local, but audit firms and companies elsewhere engage us on the same basis.
When should we bring you in?
At planning, not at the deadline. Involving us early means the wallet list is agreed before fieldwork, control verification is scheduled rather than improvised, and reconciliation gaps surface while there is still time to fix them. We do take engagements that are already stuck at year-end, and unsticking them is common work for us, but the same audit costs less and closes faster when the digital-asset scope is set at the start.
Our records are a mess. Can you fix them and then support the audit?
The fixing is a separate engagement, and keeping it separate protects the audit. If your on-chain activity has never been reconciled to your books, start with our transaction reconciliation service, which gets the records audit-ready. Where we act as the auditor's expert on evidence, we are careful about independence: the roles of preparing records and evidencing them are kept distinct, and we agree the boundaries with the auditor in writing at scoping.
How is this different from your financial statement audit service?
By who signs the opinion. Our financial statement audit service is the whole engagement: a statutory audit delivered together with CYAUSE Audit Services Ltd, our ICPAC-licensed audit partner, who issues the opinion while we evidence the chain. Crypto audit support is for every other arrangement: you already have an auditor, or you are the auditor, and what is needed is the digital-asset expertise inside an engagement that belongs to someone else. If you do not yet have an auditor and need the full audit, the financial statement audit page is the right place to start.
More questions answered on our general FAQ.
Related Reading
Is crypto holding up an audit?
Tell us who the auditor is, the reporting framework, and the wallet and exchange footprint. We will propose the engagement model, the procedures, and a timetable that fits the audit's own.
- A scoping call with you and the audit team
- Working papers the audit file can carry
- Confidential, whether one engagement or a portfolio