Service 04
Audit & assurance
Managed end to end — readiness, evidence, controls and the auditor relationship.
Why this is hard
The hardest assertion in a digital-asset audit is existence and rights: proving that the entity controls the addresses it claims. That means a complete wallet inventory, message-signing evidence for each address, documented key ceremonies and a signing policy — none of which most firms have when the auditor first asks. Regulators have flagged widespread deficiencies in crypto audits around exactly this.
What we do
Inside this service.
Readiness diagnostic
A gap assessment against what your auditor will actually test, before the fieldwork starts.
Proof-of-control evidence
Address register, signing evidence and custodian confirmations, assembled as a workpaper pack.
Key management policy
Ceremony documentation, multisig and MPC quorum policy, backup, rotation and leaver process.
Controls design
A risk-and-control matrix over wallet activity, withdrawal whitelists and transaction approval.
SOC readiness
Preparation for SOC 1 and SOC 2 examinations, including the complementary user-entity controls.
Auditor liaison
Sitting between you and the audit team on technical positions — usually the difference between a two-month and a six-month audit.
Tell us what you are holding, and where.
We will tell you what applies to you, what is already late, and what it takes to fix. In Dubai, Dublin, London or Tokyo, in person if you prefer.