Financial Statement Audits in Cyprus

    Crypto audits for blockchain companies in Cyprus

    A statutory audit that actually reads the chain.

    Audited financial statements for crypto exchanges, CASPs and VASPs, Web3 companies and DAO treasuries, funds, and any Cyprus company holding digital assets on its balance sheet — delivered together with CYAUSE Audit Services Ltd, our ICPAC-licensed audit partner. They issue the opinion. We prove what is on the chain behind it.

    CYAUSE Audit Services Ltd logoOndology Labs

    In partnership with CYAUSE Audit Services

    CYAUSE Audit Services Ltd is an ICPAC-licensed audit and accounting firm in Cyprus. Statutory audit opinions on the engagements we run jointly are issued by CYAUSE as the licensed audit office, while we provide the on-chain examination that a digital-asset balance sheet requires.

    CYAUSE brings

    • The ICPAC audit licence and the statutory audit opinion
    • Financial statement audit methodology under IFRS
    • Cyprus tax, regulatory, and CySEC licensing experience
    • A dedicated audit crypto department

    Ondology Labs brings

    • Cryptographic verification of wallet control
    • On-chain balances read directly from the chain, not from a schedule
    • Reconciliation of chain activity to the accounting ledger
    • Identification of connected and related-party addresses

    The Engagement Team

    Two firms, one engagement. These are the people who do the work.

    Corporate & Audit Team CYAUSE Audit Services Ltd

    Carries the audit licence, the methodology, and the opinion.

    Kyriakos Tramountanellis — Engagement Partner

    Kyriakos Tramountanellis

    Engagement Partner

    Carries responsibility for the audit as the signing partner: client acceptance and independence checks at the outset, the audit judgements taken along the way, and the opinion itself. Founding director of CYAUSE and a UK Fellow Chartered Accountant who trained with UHY Hacker Young in London, he is also the point of reference for the Cyprus tax and CySEC licensing questions that surface mid-engagement.

    • FCA (ICAEW)
    • ICPAC
    • ACCA
    • Advanced CySEC exams
    • Advanced AML exams
    Marinos Tramountanellis — Audit Manager

    Marinos Tramountanellis

    Audit Manager

    Runs the day-to-day audit fieldwork on engagements where digital assets sit on the balance sheet. He sets the sample, tests the controls and disclosures, and works directly against our on-chain findings to turn them into audit evidence. Leads the Audit Crypto Department at CYAUSE, which he joined in 2017 as an ACCA trainee.

    • Lead Manager, Audit Crypto Department
    • ACCA background

    Crypto Expert Team Ondology Labs

    Proves what is on the chain and turns it into audit evidence.

    Iraklis Anastasiou — Blockchain Lead

    Iraklis Anastasiou

    Blockchain Lead

    Leads the on-chain side of the engagement. Agrees the wallet, exchange, and custodian scope with the audit team, then establishes control of every reported address by cryptographic signature or a nominal transfer. Anything that cannot be proven is reported as unverified rather than assumed. He is the first point of contact on scope and timetable.

    • ISO Technical Committee Member
    • 7+ years in cryptocurrency
    • Forensic investigations & data analysis
    Panayiotis Kattides — Chain Analytics Lead

    Panayiotis Kattides

    Chain Analytics Lead

    Builds and runs the analysis behind the evidence. Reconciles on-chain movement to the accounting ledger, separates internal transfers from genuine economic events across bridges and swaps, and clusters connected addresses that point to related-party transactions the accounting system never recorded.

    • AI & Machine Learning professional
    • 5+ years in cryptocurrency
    • Financial crime & forensic analysis

    More about our audit partner on the CYAUSE team page, and about us on our team page.

    Why a Crypto Balance Sheet Needs More Than a Standard Audit

    A bank balance is confirmed by writing to the bank. A wallet balance has nobody to write to. It is confirmed by proving control of a private key and reading the chain — and an audit team without that capability has little choice but to rely on a schedule prepared by management, which is exactly the assertion the audit exists to test.

    The same problem runs through the rest of the file. Internal transfers between a company's own wallets look identical to disposals unless someone maps the wallets. Bridges and swaps turn one economic event into several on-chain legs. Staking rewards and airdrops arrive without an invoice. Connected addresses can reveal related-party transactions that never appear in the accounting system at all.

    That is the work we do alongside CYAUSE: the on-chain examination that turns a digital-asset balance sheet into something an auditor can actually form an opinion on.

    What the Audit Covers

    A full statutory audit, with the digital-asset areas evidenced on-chain rather than accepted on assertion.

    Digital assets on the balance sheet

    Existence, ownership, and valuation of crypto holdings at the reporting date, verified against the chain rather than against a management schedule.

    Wallet control and custody

    Cryptographic evidence that the entity controls the wallets it reports, across hot, cold, multi-signature, and MPC arrangements, plus assets held with third-party custodians.

    Revenue and transaction flows

    Trading, fee, staking, and protocol revenue traced from the chain to the ledger, with internal transfers separated from genuine economic events.

    Liabilities and customer balances

    Amounts owed to customers or token holders, tested for completeness against the internal ledger rather than accepted at face value.

    Related parties and connected wallets

    Identification of connected addresses and counterparties that indicate related-party transactions requiring disclosure.

    Disclosures and going concern

    Whether the financial statements disclose digital-asset risk, valuation policy, and custody arrangements in a way a reader can rely on.

    How a Joint Audit Runs

    One engagement, one timetable, one set of audited financial statements.

    01

    Scoping and acceptance

    We agree the reporting framework, the entities and wallets in scope, and the timetable. CYAUSE performs its own client acceptance and independence checks as the licensed audit office.

    02

    On-chain examination

    We verify wallet control cryptographically, read balances directly from the chain at the reporting date, and reconcile every on-chain movement to the ledger.

    03

    Financial statement audit fieldwork

    CYAUSE performs the statutory audit work — controls, testing, judgements, and disclosures — using our on-chain findings as audit evidence over the digital-asset balances.

    04

    Resolution of differences

    Unexplained flows, misclassified internal transfers, and valuation differences are investigated and resolved rather than adjusted away.

    05

    Audit opinion and report

    CYAUSE issues the audit opinion as the ICPAC-licensed audit office. You receive financial statements your board, investors, bank, and regulator can rely on.

    What an Audit Does and Doesn't Do

    An audit opinion is a specific thing with specific limits, and both are worth stating before the engagement rather than after.

    It does

    • Give an independent opinion on whether the statements are fairly stated
    • Verify digital-asset holdings against the chain, not against a schedule
    • Test revenue, liabilities, and related parties as part of the whole entity
    • Produce statements your bank, board, investors, and regulator can rely on

    It does not

    • Guarantee that no fraud exists — an audit is not a fraud investigation
    • Assess your AML framework, which is a separate compliance review
    • Prepare your books; reconciliation must happen before the audit starts
    • Predict solvency or performance after the reporting date

    If your records are not yet reconciled, start with transaction reconciliation. If you need to show customers their deposits are backed between audits, that is proof of reserves.

    Financial Statement Audit FAQ

    Does a blockchain company in Cyprus need an audit?

    In almost all cases, yes — and not because it is good practice. A company registered in Cyprus is required to prepare annual financial statements, have them audited by a licensed audit firm, and file them with the Registrar of Companies alongside its tax return. The obligation attaches to the company, not to what the company does. Running a crypto exchange, a Web3 product, a DAO treasury, or a token issuer does not exempt you from it. What being a blockchain business changes is not whether you are audited but what the audit has to examine: the obligation is ordinary, the evidence is not. That gap is why crypto-native companies in Cyprus routinely struggle to close an audit on time. If you hold a CySEC authorisation as a crypto-asset service provider, the audit sits alongside your supervisory obligations rather than replacing them — your AML framework and client-asset safeguarding are reviewed separately. Exemptions in Cyprus are narrow and change, so we confirm your exact filing position and deadlines with CYAUSE at scoping rather than leaving you to assume them.

    We are a Web3 company or DAO rather than a financial business. Does this apply?

    If the entity is a Cyprus-registered company, the filing obligation is the same as for any other company. What differs is the evidence: treasury held in multi-signature wallets, protocol revenue arriving on-chain without invoices, contributor payments made in tokens, and governance decisions recorded on-chain rather than in board minutes. Those are all auditable, but only by a team that can read them. We see this structure often and scope for it directly.

    Who actually signs the audit opinion?

    CYAUSE Audit Services Ltd does, as the ICPAC-licensed audit office. In Cyprus a statutory audit opinion can only be issued by a licensed audit firm, so the partnership is structured accordingly: CYAUSE carries the audit responsibility and the licence, and Ondology Labs provides the blockchain examination that produces audit evidence over the digital-asset balances. You engage one team and receive one set of audited financial statements.

    Why does a crypto business need a specialist for a normal audit?

    Because the evidence lives somewhere a conventional audit programme does not look. A bank balance is confirmed by writing to the bank. A wallet balance has no one to write to — it is confirmed by proving control of a private key and reading the chain. Auditors without that capability tend to rely on management-prepared schedules, which is precisely the assertion an audit is supposed to test independently.

    What does the on-chain part of the audit actually involve?

    Proving control of every reported wallet by cryptographic signature or a nominal transfer on our instruction, reading balances directly from the chain at the reporting date, reconciling on-chain movement to the ledger, separating internal transfers from genuine economic events, and identifying connected addresses that suggest related-party transactions. Anything we cannot verify is reported as unverified rather than assumed.

    Which reporting framework do you audit under?

    IFRS as adopted in the EU is the usual framework for Cyprus entities, and it is what most digital-asset businesses here report under. The accounting treatment of crypto assets under IFRS is not always intuitive, particularly on classification and measurement, so we agree the treatment and its basis early rather than at the reporting date.

    How is this different from a proof of reserves attestation?

    Scope and level of assurance. A proof of reserves engagement is a targeted attestation about assets and customer liabilities at a point in time. A financial statement audit is an opinion on the whole entity — revenue, expenses, going concern, related parties, and disclosures — issued under statutory audit standards. Many businesses need both: reserves attestations frequently for customers, and an annual audit for regulators, banks, and investors.

    We are a CASP authorised in Cyprus. Does this cover our obligations?

    An audited set of financial statements is one part of what a supervised firm has to produce, and it is the part this engagement delivers. It does not by itself evidence your AML framework or your client-asset safeguarding, which are separate reviews. Confirm your specific filing obligations with your own compliance function or counsel; we scope the audit around what you are actually required to file.

    What do you need from us, and how long does it take?

    The wallet and exchange account list, ledger and accounting system exports, custody documentation, and the prior year financial statements. Timelines depend far more on the state of your records than on the audit itself: a business whose on-chain activity is already reconciled moves quickly, while one reconciling for the first time should expect that work to dominate the timetable.

    Our books are not reconciled. Can you still audit us?

    Not straight away, and it is better to say so than to start and stall. Reconciliation is a prerequisite, not part of the audit — an auditor cannot both prepare the underlying records and issue an independent opinion on them. Where the gap is significant we will tell you at scoping and set out what has to happen first.

    Do you audit businesses outside Cyprus?

    The statutory audit is delivered through CYAUSE as a Cyprus-licensed audit firm, so it fits Cyprus-registered entities and their group reporting most directly. For entities audited elsewhere, we are frequently engaged by the incumbent auditor to perform the digital-asset examination and provide evidence they can rely on. That works well and is a common arrangement.

    More questions answered on our general FAQ.

    Ready for your year-end?

    Tell us your reporting framework, your wallet and exchange footprint, and your filing deadline. We will scope the audit with CYAUSE and tell you honestly what has to happen before fieldwork can start.

    • A named engagement partner and a fixed timetable
    • An honest read on whether your records are audit-ready
    • One team for the audit and the on-chain examination