Crypto exchanges increasingly publish reserve reports to demonstrate that they hold assets supporting customer balances. These reports may be described as reserve attestations, independent verifications, agreed-upon procedures or Proof of Reserves reports.
Although such publications can improve transparency, they are frequently confused with full financial audits. The distinction matters because the two processes have different objectives, scopes, procedures and levels of assurance.
A reserve attestation may examine whether an exchange held specified assets against selected customer liabilities at a particular time. A financial statement audit normally examines the company’s wider financial position, including assets, liabilities, revenue, expenses and financial disclosures.
This comparison is part of the broader exchange transparency conversation. For the full framework connecting PoR, attestations, liability reporting and customer-asset protection, see Proof of Reserves, Attestations and Exchange Transparency Controls.
What Is a Reserve Attestation?
A reserve attestation is an independent engagement relating to information presented by a crypto exchange about its reserves, customer liabilities or asset-backing position.
The exact meaning of “reserve attestation” depends on the engagement. The term does not automatically indicate one standard methodology or assurance level.
A reserve-related engagement may involve an independent accountant examining:
-
Cryptoasset balances in identified wallets
-
Evidence that the exchange controls those wallets
-
Customer liabilities included in a reserve calculation
-
The method used to create a liability snapshot
-
Merkle tree or other cryptographic records
-
The reserve ratio at a specified time
-
Reconciliations between blockchain and internal records
Some engagements may provide limited or reasonable assurance against defined criteria. Others may be agreed-upon procedures engagements in which the accountant performs specific procedures and reports the factual findings without expressing an overall assurance conclusion.
International assurance standards distinguish engagements covering information other than audits or reviews of historical financial statements from traditional financial statement audits. This means an assurance engagement can be professionally performed while still having a much narrower objective than an audit.
Compliance teams should therefore read the actual report instead of relying on the word “attestation.”
What Is a Financial Audit?
A financial audit is an independent examination of an organisation’s financial statements under an established accounting and auditing framework.
The auditor seeks reasonable assurance that the financial statements are free from material misstatement, whether caused by error or fraud. The auditor then provides an opinion on whether the statements are presented fairly, in all material respects, under the applicable accounting framework.
A financial statement audit generally considers:
-
Assets and liabilities
-
Revenue and expenses
-
Cash flows
-
Equity or capital
-
Accounting policies
-
Significant estimates
-
Related-party transactions
-
Financial statement disclosures
-
Events occurring after the reporting date
-
Evidence relevant to going-concern considerations
Auditing standards require auditors to examine evidence supporting financial statement amounts and disclosures, assess accounting principles and significant estimates, and evaluate the overall financial statement presentation.
An audit is broader than a reserve attestation, but it is not an absolute guarantee that the organisation will remain solvent or that every fraud will be discovered. It provides reasonable rather than absolute assurance.
Reserve Attestations vs Financial Audits: Key Differences
The main differences concern purpose, scope, assurance, timing and the form of the final report.
Purpose
A reserve attestation normally addresses a defined reserve-related question.
For example:
Did the exchange control sufficient Bitcoin to cover the Bitcoin customer liabilities included in its calculation at a specified time?
A financial audit addresses a broader question:
Do the company’s financial statements fairly present its financial position and performance under the applicable accounting framework?
The reserve engagement focuses on a particular subject. The audit considers the organisation’s wider financial reporting.
Scope
A reserve attestation may cover selected cryptoassets, wallets, customer accounts or legal entities. It may exclude corporate liabilities, operating expenses, legal claims, loans and off-chain assets.
A financial audit usually covers the complete set of financial statements and related disclosures.
This broader scope can reveal risks that a reserve report may not address, including:
-
Corporate debt
-
Operating losses
-
Related-party balances
-
Legal obligations
-
Tax liabilities
-
Weak asset valuation
-
Liquidity pressure
-
Going-concern uncertainty
The PCAOB warns that Proof of Reserves reports may not address an exchange’s liabilities, customer rights or whether assets were borrowed temporarily for the verification.
Assurance Level
A financial audit provides reasonable assurance that the financial statements are free from material misstatement.
A reserve engagement may provide reasonable assurance, limited assurance or no assurance, depending on its design.
In an agreed-upon procedures engagement, the accountant generally reports the procedures performed and the findings obtained. Readers must interpret those findings rather than relying on an overall audit opinion.
This is why two reports both described as reserve attestations can provide substantially different levels of confidence.
Reporting Period
Reserve attestations frequently examine assets and liabilities at one specific date and time.
A financial audit examines financial statements covering a reporting period, such as a financial year, together with the financial position at the reporting date.
A point-in-time reserve report cannot show whether assets were transferred, borrowed, lent or made unavailable before or after the snapshot. The PCAOB specifically identifies this limitation in Proof of Reserves reporting.
Applicable Standards
Financial audits are conducted under established auditing standards applicable to the organisation and jurisdiction.
Reserve attestations may be conducted under attestation or assurance standards, agreed-upon procedures standards or a methodology designed for the specific engagement.
Some reserve verifications may also be performed by non-accounting providers. The PCAOB notes that there is a lack of uniformity in the providers and procedures used for Proof of Reserves engagements.
Final Report
A financial audit concludes with an auditor’s opinion on the financial statements.
A reserve attestation may provide:
-
An assurance conclusion
-
A limited-assurance conclusion
-
Factual findings from specified procedures
-
A description of exceptions
-
A reserve ratio
-
A list of tested wallets and liabilities
Users should confirm exactly what conclusion the accountant has provided.
What Do Independent Accountants Verify?
The procedures performed depend on the engagement letter and applicable professional standard.
In a reserve engagement, the accountant may verify whether:
-
The exchange supplied a list of customer liabilities at the reporting time.
-
The liability data was used to generate a Merkle root.
-
Selected customer balances were represented accurately.
-
Reported wallet addresses held the stated assets.
-
The exchange demonstrated control of those wallets.
-
Verified assets exceeded the included liabilities.
-
The reserve calculation followed the published methodology.
The accountant may use blockchain explorers, cryptographic message signing, custodian confirmations, internal ledgers and reconciliation records.
However, an accountant may not have been engaged to determine whether the exchange included every liability, borrowed assets temporarily or used customer funds outside the reporting period.
A financial audit involves broader procedures. The auditor may test accounting records, confirm balances with third parties, examine agreements, evaluate estimates and consider whether the financial statements contain material misstatements.
Audit procedures can also identify conditions relevant to the company’s ability to continue operating. Under PCAOB standards, auditors evaluate whether identified conditions create substantial doubt about the company’s ability to continue as a going concern for the relevant assessment period.
Even so, the absence of a going-concern warning should not be interpreted as a guarantee that the company cannot fail.
Scope and Limitations of Reserve Attestations
Reserve attestations can provide useful evidence that specified assets existed and were linked to the exchange at a particular time.
They may also help customers verify that their balances were included in a liability dataset.
However, common limitations include:
-
Point-in-time reporting
-
Exclusion of corporate liabilities
-
Incomplete coverage of customer products
-
Limited testing of liability completeness
-
Possible temporary borrowing
-
Assets pledged or otherwise encumbered
-
Exclusion of affiliated legal entities
-
Lack of information about liquidity
-
Different methodologies across providers
An exchange could report a reserve ratio above 100% while still facing substantial debts or being unable to access enough liquid assets to process withdrawals.
The SEC’s former chief accountant warned that non-audit crypto assurance work is not as rigorous or comprehensive as a financial statement audit and may not provide reasonable assurance to investors.
Scope and Limitations of Financial Audits
A financial audit provides a broader and more standardised assessment, but it also has limitations.
Auditors test information on a sample basis and focus on matters that could cause material misstatement. An audit is not designed to confirm every transaction individually.
A financial audit also may not provide the same level of real-time transparency as public blockchain monitoring. Audited financial statements are normally issued periodically and can become less current as the reporting date passes.
An audit may confirm the overall financial position while offering customers limited ability to verify their personal balance against specific on-chain reserves.
For this reason, financial audits and reserve attestations can complement each other.
Why Do Exchanges Publish Reserve Attestations?
Exchanges publish reserve attestations because customers want clearer evidence that deposited assets are appropriately backed.
Reserve reporting can help an exchange:
-
Demonstrate control of reported wallets
-
Support customer confidence
-
Allow personal balance verification
-
Strengthen internal reconciliations
-
Identify asset-backing shortfalls
-
Respond to market concerns
-
Provide information between annual audits
-
Support regulatory and commercial discussions
A reserve attestation may also be narrower, faster or more frequent than a full financial audit.
However, speed and frequency should not be confused with completeness. A monthly reserve report may provide current asset information but still omit significant company-wide liabilities.
Compliance and Regulatory Significance
Reserve attestations can support custody oversight, asset reconciliation and customer-protection controls. They may also provide evidence that compliance, finance and treasury teams are monitoring customer asset backing.
A well-governed programme should require compliance teams to understand:
-
Which legal entities are covered
-
Which customer products are included
-
How wallet control was verified
-
How liabilities were calculated
-
Whether assets are restricted
-
Which assurance standard was applied
-
What exceptions were identified
-
How frequently verification occurs
Regulators and customers may be misled when an exchange markets a narrow reserve engagement as a complete audit. The SEC has warned accounting firms and crypto companies about language suggesting that non-audit work is equivalent to, or more precise than, a financial statement audit.
Public communications should therefore use accurate terminology and clearly explain the report’s limitations.
Common Misconceptions
“An Accountant Verified It, So It Must Be an Audit”
An accountant can provide several services, including audits, reviews, examinations and agreed-upon procedures. The accountant’s involvement alone does not determine the type of engagement.
“A Reserve Attestation Proves Solvency”
A reserve attestation may compare selected assets with selected customer liabilities. Solvency requires consideration of the organisation’s complete assets and liabilities.
“A 100% Reserve Ratio Means Withdrawals Are Guaranteed”
Reported assets may be illiquid, pledged, locked or unavailable during an operational incident.
“A Merkle Tree Proves Every Liability Was Included”
A Merkle proof shows that a particular record was included in a dataset. It does not independently confirm that the dataset contains every customer or liability.
“A Financial Audit Guarantees the Exchange Cannot Fail”
An audit provides reasonable assurance about financial statement presentation. It does not predict every future event or guarantee continued operation.
When Should Exchanges Perform Both?
Crypto exchanges holding customer assets should consider reserve attestations and financial audits as complementary controls rather than alternatives.
A reserve attestation can provide frequent, asset-specific transparency. A financial audit provides a broader assessment of the company’s financial position and reporting.
Using both can offer:
-
Frequent verification of customer asset backing
-
Broader examination of corporate liabilities
-
Public blockchain transparency
-
Testing under established auditing standards
-
Better information about liquidity and financial performance
-
Greater accountability to customers and regulators
An effective framework may include continuous internal reconciliation, frequent reserve reporting, periodic independent reserve assurance and annual financial statement audits.
The exact approach should reflect the exchange’s size, legal obligations, custody model and customer risk.
Frequently Asked Questions
What Is the Main Difference Between a Reserve Attestation and an Audit?
A reserve attestation examines specific reserve information, while a financial audit assesses the company’s broader financial statements under established auditing standards.
Is a Proof of Reserves Report a Reserve Attestation?
It may be. Some Proof of Reserves reports involve independent attestation or agreed-upon procedures, while others are produced internally or verified by non-accounting providers.
Does a Reserve Attestation Provide Assurance?
It depends on the engagement. It may provide reasonable assurance, limited assurance or only factual findings with no overall assurance conclusion.
Can a Reserve Attestation Identify Hidden Debt?
Not necessarily. Corporate borrowing and other liabilities may be outside the scope of the engagement.
Does a Financial Audit Verify Crypto Wallets?
An auditor may test cryptoasset existence, rights, custody arrangements, valuation and reconciliations when those matters affect the financial statements. The procedures depend on the audit risks and circumstances.
Which Is More Reliable?
A financial audit is broader and more comprehensive. A well-designed reserve attestation may provide more frequent and specific information about customer asset backing. They answer different questions.
Should Exchanges Publish Both Reports?
Where practical and appropriate, publishing both can provide a more complete picture. Reserve reports show asset backing, while audited financial statements provide broader financial context.
Conclusion
The difference between reserve attestations vs financial audits is primarily a difference in purpose and scope.
A reserve attestation may demonstrate that an exchange controlled specified assets against selected customer liabilities at a particular time. It can support customer verification, reconciliation and exchange transparency.
To build a practical working understanding of reserve reporting, attestations and transparency governance, explore Proof of Reserves, Attestations and Exchange Transparency Controls. The course is designed for compliance teams that need to evaluate PoR reports, liability coverage, wallet-control evidence, segregation, custody governance and disclosure risks.




