Purpose

Provide complete, accurate, controlled and traceable support for external, regulatory and financial-statement audits.

Steps

  1. Confirm auditor authority, independence, scope, criteria, timetable, contacts and confidentiality.
  2. Assign an audit coordinator and evidence owners.
  3. Establish a request register and controlled evidence room.
  4. Collect, quality-check and approve organized evidence libraries per the manual’s section 4.3, including: policies, client due diligence records, screening outputs, internal case-management records, UTR files, escalation packs, restrictive-measure records, remediation evidence, and relevant control documentation.
  5. For financial statement audits (section 4.4), support the following scope and focus areas:
    • Crypto Assets and Liabilities: classification, valuation, proof of ownership, segregation of client vs corporate assets.
    • Revenue Recognition: fees, spreads, staking/lending income, custody fees.
    • Custody and Safeguarding: reconciliation of wallets, client asset disclosures, proof-of-reserves considerations.
    • IT and Cyber Controls: wallet security, reconciliations, access management, data integrity.
    • Financial Crime and Compliance: alignment with AML/CFT/CPF obligations, suspicious transaction reporting, sanctions risk.
    • Disclosures: fair value hierarchy, risk concentrations, governance.
  6. Address key audit risks: existence and rights (cryptographic proof that assets belong to the VASP), valuation (accuracy of market pricing, illiquid assets, fair value hierarchy), completeness (capturing all wallets, DeFi positions, and off-chain obligations), revenue (correct recognition of trading fees, lending returns, and rebates), and safeguarding (clear presentation of client assets and fiduciary responsibilities).
  7. Provide procedures and evidence: wallet proofs (signed messages/test sends), on-chain reconciliation vs ledger balances, independent price testing and cut-off analysis, revenue recalculations on sample transactions, confirmations from banks/custodians/stablecoin issuers, and testing of IT controls and incident logs.
  8. Record interviews, submissions, clarifications, open requests and deadlines.
  9. Escalate missing, inaccurate or contradictory evidence and any material issue identified during preparation.
  10. Review draft findings for factual accuracy without compromising auditor independence.
  11. Record deliverables: audit opinion (clean, qualified, adverse, or disclaimer), management letter (control gaps, remediation recommendations), and audit committee report if applicable (summary of key matters, adjustments, uncorrected misstatements).

Exceptions and Escalation

Documents shall not be altered, concealed or created retrospectively to misrepresent control operation. Gaps shall be disclosed and remediated.

Records

  • Scope, authority and independence
  • Request register and evidence pack
  • Submission and interview record
  • Audit opinion and reports
  • Findings and resulting actions

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: event-driven and annual financial audit

History

  • 2026-07-26: Created from sections 4.3 and 4.4 of the approved ICA Manual.