The security that makes a cold wallet safe is what makes it hard to audit. Keys held offline, in your hands, are harder for hackers to reach. That is the whole point of the design, and also why funds holding crypto offline can struggle to prove to an auditor that the coins exist, and that the fund controls them.
Part 1 covered ownership. This part covers existence and control, where the type of wallet you use changes the evidence.
What "existence" means in an audit
Two things, at 30 June:
- The asset existed: the holding was real, in the quantity reported.
- The fund controlled it: the fund, not a trustee personally, held the private key.
For cash or listed shares, a bank or share registry confirms the holding for you. Crypto has no external authority of that kind: no share registry, bank or title office. What proves the holding is control of the private key, and how that control can be shown depends on where you keep it.
Three custody models, three evidence profiles
Exchange or custodial account
The platform holds the assets and produces the records. Auditors typically rely on the platform's statements, account ownership details and independent confirmations. The trade-off is trust in the provider: many crypto-asset providers are not licensed, so the fund may not be protected if the platform fails.
In its October 2025 guidance, "Auditing SMSFs with crypto assets", the ATO says that where a custodian such as an exchange holds the crypto, the auditor should obtain a Type 2 assurance report if one is available. That is a report on the platform's own controls, prepared by the platform's auditor. The auditor should still perform further substantive testing to confirm the holding statement is correct.
Hot wallet
A software wallet you hold yourself. The assets, proof of ownership and transaction records are accessible through an online portal. The evidence comes from you, not a third party, so expect your auditor to check it against the public blockchain.
Cold wallet
A hardware device that stores the private keys offline, which can make the wallet harder for hackers to reach. It also leaves the weakest default audit trail. There is no platform issuing statements and no portal to log into. Everything depends on the records the trustee kept.
Cold storage is not a compliance problem. It is a documentation problem, and one you can solve in advance.
Why a screenshot is not enough
A screenshot is a picture of a number. It is not independently verifiable, it does not establish who controls the address, and it does not tie the holding to your fund. The ATO makes the same point about market value in its October 2025 guidance: holding statements or investment summaries alone are not sufficient, and the auditor must obtain additional objective, supportable evidence. The principle transfers. A document you produced about your own holding is a starting point, not proof.
The evidence for self-custody
Hot and cold wallets are both self-custody. For either, expect your auditor to ask for:
- The fund's public wallet addresses. Your auditor can look up the holding on the public blockchain: independent verification from a source neither of you controls.
- Full transaction history, reconciled to the fund's records: every purchase, sale and transfer.
- Wallet setup records showing the wallet was established for the fund.
- Evidence of control of the private keys, with a record of who holds them and how they are secured.
One practical method is message signing. The wallet signs a message, and the auditor verifies the signature against the wallet's address to confirm who controls it. Some wallets have a message-signing function built in.
The ATO's guidance does not require it, but it answers a question that otherwise has no good answer.
Never send a private key or seed phrase to anyone, including your auditor. No audit procedure requires it.
Key-person risk
If one trustee holds the keys, what happens if that person dies or loses capacity? The fund can be locked out of the asset permanently. Documenting how the wallet can be accessed is treated as good practice in professional guidance. Appointing a professional custodian may help support continuity, and it puts the records back in the hands of a platform.
The licensing shift
Your fund's records are only as durable as the platform holding them. Under ASIC's no-action position, providers of digital asset financial products had to apply for an Australian financial services licence, or a variation to one, by 30 June 2026. Firms that needed one and did not apply risk breaching the financial services laws.
The Corporations Amendment (Digital Assets Framework) Act 2026 brings digital asset platforms and tokenised custody platforms under that licensing regime in April 2027. A platform that cannot or will not be licensed may leave the market, which is why records you hold yourself matter.
Evidence prepared in advance
Where an auditor cannot verify that the fund's crypto exists, belongs to the fund or is reported at market value, and the amount is material, the auditor must qualify both parts of the audit report. Part A is the opinion on the financial statements; Part B is the opinion on compliance. Where the reporting criteria apply, the auditor also lodges an Auditor Contravention Report for a breach of regulation 8.02B, the rule requiring fund assets to be reported at market value.
The evidence that settles existence and control is easiest to assemble as you go. That means wallet addresses recorded when each wallet is created, transaction histories exported through the year, and control evidence agreed with your auditor before 30 June.
Existence and control settled, the next question is what the holding was worth at 30 June. Part 3 takes the price.
SMSF Audit Group are independent, ASIC-registered SMSF auditors. If your fund self-custodies crypto, talk to us about the evidence to assemble before year end.
