Integrating governance, technology, and regulatory expectations to mitigate digital asset risks

Digital asset internal controls

Young businesswoman working on a laptop alongside her colleague in an office at night

Overview

Digital assets, including cryptocurrencies, stablecoins, and tokenized assets, introduce new risks and challenges that traditional frameworks are not designed to address. From private key management and smart contract execution to real-time settlement and decentralized infrastructure, organizations must rethink how controls are designed, implemented, and monitored.

PwC helps organizations design and operationalize fit-for-purpose internal control environments - integrating governance, technology, and regulatory expectations. Whether you are launching new products, scaling operations, or preparing for audit and regulatory scrutiny, we help you identify control gaps and implement controls aligning with your enterprise risk appetite and compliance requirements. 

While risk and regulatory programs define what risks must be managed, internal controls define how those risks are mitigated in day-to-day operations and financial reporting.

Why controls matter  

Digital asset ecosystems differ from traditional financial systems:

  • Transactions are often irreversible 

  • Assets are secured through cryptographic keys rather than intermediaries 

  • Activities span onchain and offchain environments 

  • Markets operate 24/7 with real-time settlement 

  • Dependencies on third-party infrastructure and protocols may be significant 

These characteristics increase the importance of preventive, automated, and continuously monitored controls to help mitigate financial, operational, and compliance risks.

How PwC can help   

PwC helps organizations design, implement, and scale control environments tailored to digital asset activities.

Design digital asset control frameworks aligned to COSO, SOX, and regulatory expectations. Define control objectives, map risks across onchain and offchain processes and integrate digital assets into enterprise ICFR and governance structures.

Perform current state assessments and gap analyses across digital asset activities, such as custody, wallet and key management, smart contracts, stablecoins, transaction processing, and reconciliation. Evaluate control design and operating effectiveness across business and IT processes and identify areas for enhancement. 

Design and implement internal controls over digital asset processes to support SOX compliance and ICFR requirements. Establish scalable control frameworks, define control activities, and support readiness for IPO or new digital asset capabilities, including consideration of activities and technology outsourced to third parties.

Provide SOC 1 and SOC 2 readiness assessments for digital asset platforms and services. Design and enhance controls to support third-party assurance requirements and meet customer, investor, and stakeholder expectations.

Provide readiness assessments over stablecoin reserve reporting aligned to regulatory requirements and industry frameworks. Design and enhance internal controls across reserve management, reconciliation, and reporting processes to support monthly attestations and scalable stablecoin issuance and redemption operations.

Remediate control deficiencies, including significant deficiencies and material weaknesses. Support audit and regulatory readiness through control testing, issue resolution, and development of audit-ready documentation and evidence.

Perform internal audit reviews focused on digital asset activities or augment internal audit functions with specialized digital asset risk and controls expertise.

Questions business leaders are asking

How do we design controls for assets that exist onchain rather than in traditional systems?

Digital asset controls require a hybrid approach that combines traditional control principles with blockchain-native capabilities. This includes embedding controls directly into workflows, leveraging blockchain transparency for monitoring, and integrating onchain data into enterprise systems for reconciliation and reporting.  

What does a “well-controlled” digital asset environment look like to regulators and auditors?

A well-controlled digital asset environment typically demonstrates:

  • Clear governance and accountability 

  • Documented processes and control activities 

  • Strong custody and key management practices  

  • Reliable transaction recording and reconciliation 

  • Robust audit trails and evidence 

  • Continuous monitoring and issue remediation 

Regulators and auditors expect controls to be designed, implemented, and tested, with clear linkage to identified risks. 

How can we scale controls as our digital asset activities grow?

Scalable control environments rely on:

  • Automation and integration across systems 

  • Standardized control frameworks across products and jurisdictions 

  • Use of real-time monitoring and analytics  

  • Clear operating models and ownership structures 

PwC helps organizations move from manual, fragmented controls to integrated, technology-enabled control ecosystems.

Contact us

Jenna Surface

Jenna Surface

Digital Assurance and Transparency Director, PwC US

Carey Carpenter

Carey Carpenter

Digital Assurance & Transparency Partner, PwC US

Follow us