top of page
Search

AICPA Digital Assets Practice Aid

Writer: Katarzyna  Celińska
Katarzyna Celińska
12 hours ago
2 min read

I am not a CPA, CFO or accountant. However, because we work with SOC1, SOC2 and SOC3 engagements and are members of AICPA, I like to know what is happening in the profession, especially where Technology, Audit and GRC meet.

 

Photo: brgfx na Magnific


The updated AICPA “Accounting for and Auditing of Digital Assets” Practice Aid is therefore a very interesting publication. What I particularly like is that AICPA does not treat Digital Assets as one homogeneous category. The guide considers different situations involving entities that hold digital assets, investment companies, broker-dealers, stablecoin holders and issuers, lenders and borrowers, miners, mining pools, data-centre hosts, custodians and organizations using self-custody. The accounting and audit implications can be very different depending on the rights, obligations and business model.

 

 

One of the most practical parts is the discussion of service organizations and SOC reporting. Digital assets are very often dependent on third parties: custodians, exchanges, wallet providers, platforms, data-centre operators or other organizations responsible for safeguarding, processing or accounting for assets. This is where SOC reports can become an important element of Third Party Risk Management and assurance.

 

AICPA explains that SOC 1 may provide evidence about controls relevant to ICFR, while SOC 2 can provide information about information security.

 

For digital assets, the relevant control scope may include, for example:

➡️ generation, storage and lifecycle management of private keys,

➡️ hot and cold wallet security,

➡️ authorization and segregation of duties,

➡️ reconciliation between blockchain records, customer ledgers and accounting records,

➡️ safeguarding and segregation of customer assets,

➡️ controls over commingled addresses,

➡️ transaction processing,

➡️ monitoring for unauthorized activity,

➡️ KYC/AML-related processes,

➡️ relevant subservice organizations and dependencies.

 

AICPA explicitly notes that a SOC report may not contain all control objectives needed to address digital-asset risks. Where relevant risks or events are outside the scope, the user auditor may need additional evidence, additional procedures or potentially an adjustment to the scope of assurance work.

 

If we want additional assurance over digital assets, we can define what assurance we expect from the service organization and request that relevant digital-asset processes and controls are included within the scope of its SOC examination. Then we can verify not only whether the controls were described, but, particularly through a Type 2 report, whether they were implemented and operated effectively during the period.


 
 
 

Comments


Stay in touch

META FOR MENA Information Technology Consultants Est.

City Avenue, 7th floor, office 706-0114

2 27 Street, Port Saeed, Deira, Dubai, United Arab Emirates
P.O. BOX: 40138
Licence N.O.: 1049080

​

Privacy policy

  • Facebook
  • Twitter
  • LinkedIn
  • Instagram
bottom of page