Custody Audit
Pronunciation: KUS-tuh-dee AW-dit
Definition
A custody audit evaluates whether asset holdings, records, controls, keys, segregation, and client obligations are accurately maintained within a defined scope. Reliable results for Custody Audit depend on representative evidence, reproducible sampling, qualified judgment, traceable findings, named owners, deadlines, and verification that corrective actions work. Custody Audit provides bounded assurance rather than a permanent guarantee; conclusions apply only to the reviewed scope, criteria, configuration, evidence, and time period.
Overview
A custody audit examines how an organization safeguards and accounts for assets held for itself or clients. Scope may include ownership records, wallet balances, bank accounts, key management, approvals, reconciliations, segregation, transfers, access logs, and incident procedures.
Proof of reserves or selected wallet verification covers only part of custody assurance. Auditors also need reliable liability data, legal ownership, encumbrances, off-chain assets, completeness of addresses, and evidence that controls operated throughout the assessment period.
Reports should state criteria, dates, systems, entities, sampling, exceptions, and limitations. Users should not interpret a clean audit as permanent protection from future compromise, insolvency, governance abuse, or changes occurring after the reviewed period.
An auditable record of Custody Audit should link enrollment, signing, approval, broadcast, confirmation, revocation, and recovery events to the governing policy or model version, source evidence, decision, approver, exception, action, and final outcome.
The wallet and custody workflow for Custody Audit should locate where evidence enters, where a rule or judgment is applied, what state changes, and which downstream service relies on the result.
A custody audit evaluates whether asset holdings, records, controls, keys, segregation, and client obligations are accurately maintained within a defined scope. Reliable results for Custody Audit depend on representative evidence, reproducible sampling, qualified judgment, traceable findings, named owners, deadlines, and verification that corrective actions work. A custody audit provides scoped evidence about holdings and controls, but it is not a permanent guarantee of solvency or asset safety.
Implementation of Custody Audit should map evaluation of whether asset holdings, records, controls, keys, segregation, and client obligations are accurately maintained within a defined scope to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for whether asset holdings, records, and controls should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the Custody Audit context and whether asset holdings, records, and controls should trigger reassessment instead of silent reuse of an outdated conclusion.
Key Takeaway
A custody audit provides scoped evidence about holdings and controls, but it is not a permanent guarantee of solvency or asset safety.
Sources
- Ethereum Foundation Documentation: En — Ethereum Foundation (2026-07-30)