AICPA Proposes Attestation Standard Updates Covering Digital Assets
The AICPA's Auditing Standards Board has voted to release a proposed update to its attestation standards for public comment, and digital assets sit prominently alongside sustainability and cybersecurity as one of the emerging areas the revised framework is designed to address. For accounting firms and CFOs already wrestling with how to present crypto financial statements under US GAAP, this signals that the assurance layer sitting above those statements is about to be formally modernised. The comment period will run for no fewer than 120 days from the exposure draft's publication date, and adoption is expected the following year, giving practitioners a defined but tight window to engage.
What the AICPA Is Actually Proposing
The Auditing Standards Board, the standard-setting body within the AICPA responsible for US auditing and attestation guidance, approved a motion to expose proposed changes to its attestation standards. The move is driven by a recognised shift in the nature of practitioner engagements: CPAs and assurance providers are routinely being asked to opine on matters well beyond the traditional financial statement audit.
The two-part structure of the exposure draft
The exposure draft is structured in two main parts. While the full text will not be available until the document is formally published, the AICPA has confirmed that the proposed changes are designed to bring attestation standards in line with the breadth of work practitioners now perform. Digital assets, sustainability reporting, cybersecurity posture, governance frameworks, and related internal controls are all identified as areas where current standards have not kept pace with market demand.
For digital assets specifically, this matters because assurance engagements involving crypto holdings, staking arrangements, or tokenised securities do not map cleanly onto existing attestation literature. Practitioners have had to adapt general standards to novel fact patterns, and that improvisation carries professional risk. A revised framework would provide clearer criteria for what constitutes sufficient evidence, what disclosures require examination, and how a practitioner should scope and report on an engagement involving on-chain assets.
Timeline and process
The exposure draft was expected to be published on or around 26 February. Once live, the comment period will be no shorter than 120 days. After that window closes, the Auditing Standards Board will review submissions, make revisions, and deliberate further before adoption. Adoption is expected in the following year. Firms that want to influence the final standard should prioritise submitting a formal comment letter rather than waiting for the finished product.
Why This Matters for Crypto Financial Statements Under US GAAP
The accounting treatment of digital assets in the US has changed substantially in recent years. FASB's ASC 350-60, which requires entities holding certain crypto assets to measure them at fair value with changes recognised in net income, fundamentally altered how crypto balance sheet positions are reported. That shift raised the stakes for the assurance layer: if fair value movements now flow through the income statement, the quality and credibility of the underlying fair value measurements become audit-critical, not just a disclosure footnote.
The gap between accounting standards and attestation standards
FASB's fair value approach under ASC 350-60 is now reasonably well understood. What has lagged behind is the attestation infrastructure needed to give investors, counterparties, and regulators confidence that the numbers are right. When a company reports unrealised gains on its Bitcoin treasury under the new FASB rules, what procedures should the auditor perform? What does a review engagement or an agreed-upon procedures engagement look like when the subject matter is a cold-wallet balance or a DeFi liquidity position? Current attestation standards were not designed with those questions in mind. The AICPA's proposed update is the standard-setting community's attempt to close that gap.
For firms advising clients who report under US GAAP and hold digital assets, this also has a practical resourcing dimension. Revised attestation standards will likely require practitioners to demonstrate competence in specific technical areas, whether that means understanding how blockchain confirmations function as evidence, how custody arrangements affect control assertions, or how to evaluate the reliability of third-party pricing feeds used for fair value measurement. Firms that build that competence now, before the standard is finalised, will be better positioned than those who wait.
Implications for Accounting Firms and Their Audit Practices
The proposed changes land at a moment when client demand for crypto-related assurance work is already outpacing the available guidance. Exchanges, crypto-native treasuries, tokenised fund structures, and traditional corporates with digital asset holdings all represent potential engagements. But without a clear standard, firms have either declined that work, scoped it very narrowly, or relied on adaptations of existing guidance that may not hold up to scrutiny.
Engagement scoping and risk assessment
One of the most immediate practical questions a revised attestation standard would need to answer is how practitioners scope an engagement involving digital assets. The scope question touches on custody (who holds the private keys and under what controls), valuation (which pricing source is used and how its reliability is assessed), completeness (how the practitioner confirms that all on-chain positions are captured), and the treatment of assets that do not have a readily observable market price. Each of these is a distinct risk area, and current standards provide limited specific guidance on any of them.
Firms should begin reviewing their existing digital asset engagement documentation now. Where clients hold crypto assets measured at fair value under ASC 350-60, the audit file should already document the procedures performed on those fair value measurements. Under a revised attestation standard, those procedures may need to be more explicit, more technically detailed, or structured differently depending on the type of engagement.
Staff training and specialist involvement
Revised standards that formally recognise digital assets as a subject matter for attestation will almost certainly raise expectations around practitioner competence. Firms should assess whether their current audit and assurance teams have sufficient understanding of how blockchain transactions are recorded, verified, and reported. Where gaps exist, specialist involvement, whether from an internal blockchain forensics team or a qualified external specialist, will need to be documented as part of the engagement approach.
This is also relevant to quality management. AICPA quality management standards already require firms to identify and address competence gaps in their practice. A formal attestation standard covering digital assets makes the competence question explicit rather than implicit, which will surface in peer reviews and inspections.
What CFOs at Digital Asset-Holding Companies Should Watch
For CFOs whose companies hold crypto assets on the balance sheet, the AICPA's proposed update has two direct consequences. First, the scope and rigour of any assurance engagement over those holdings may increase once the revised standard is adopted. Second, the quality of the company's own controls and documentation will determine how smoothly an assurance engagement proceeds.
Preparing the control environment
Attestation standards generally require practitioners to evaluate the subject matter against suitable criteria and to assess whether the responsible party's assertions are fairly stated. For digital assets, that means the company's internal controls over custody, valuation, and transaction recording need to be coherent and documented. CFOs should treat the pending standard update as a prompt to review those controls now, not after the standard is finalised and auditors arrive asking for evidence.
Specific areas to examine include: the completeness and accuracy of the company's digital asset inventory, the segregation of duties around wallet access and transaction authorisation, the methodology and documentation behind fair value measurements used for ASC 350-60 reporting, and the controls over any third-party custodians or prime brokers. If any of these areas are underdocumented or rely on informal processes, now is the time to formalise them.
Coordinating with external auditors early
The comment period on the exposure draft represents an opportunity for companies as well as practitioners. CFOs who engage their external auditors in a conversation about the proposed changes now will be better prepared for what revised standards may require. It also gives both parties time to agree on how the current audit or review engagement addresses digital assets, and to identify any procedural gaps before they become findings.
This is particularly relevant for companies reporting FASB crypto fair value movements under ASC 350-60 for the first time. The intersection of a new accounting standard and a soon-to-be-revised attestation standard creates a period of transition where early preparation is a genuine competitive advantage in terms of audit efficiency and cost.
The Broader Assurance Landscape and What Comes Next
Digital assets are one part of a wider modernisation project. Sustainability reporting, cybersecurity, and governance are all identified in the AICPA's announcement as areas the revised standards are intended to address. The bundling of digital assets with these other emerging topics reflects a view among standard-setters that the core attestation framework needs structural updating, not just incremental patches.
For firms already tracking SEC crypto rule changes shaping 2026 compliance priorities and the evolving regulatory environment, the AICPA's move is a complementary development on the professional standards side. Regulatory change and standard-setting change are moving in parallel, and firms that track only one will find themselves behind on the other. Similarly, the SEC crypto safe harbor and what accounting firms must act on underscores how quickly the US landscape is shifting across both enforcement and standards fronts.
The 120-day comment period is a meaningful opportunity. Firms with hands-on experience of digital asset engagements are exactly the practitioners whose input the Auditing Standards Board needs. A well-constructed comment letter, grounded in real engagement experience, can shape the practical workability of the final standard in ways that matter to clients.
Frequently Asked Questions
What is the AICPA Auditing Standards Board and why does its decision matter?
The Auditing Standards Board is the AICPA body responsible for setting US auditing and attestation standards for non-public company engagements. Its standards govern how CPAs scope, perform, and report on a wide range of assurance engagements. When it updates attestation standards, it changes the professional obligations of practitioners who take on those engagements, including any involving digital assets.
How does this relate to FASB's ASC 350-60 fair value rules for crypto assets?
ASC 350-60 changed how companies account for certain crypto assets on their balance sheets, requiring fair value measurement with gains and losses in net income. The AICPA's attestation standard update addresses how practitioners provide assurance over the resulting financial information. The two developments are complementary: one sets the accounting treatment, the other sets the assurance framework that sits on top of it.
When will the revised attestation standards take effect?
Adoption is expected in the year following the comment period and subsequent deliberation by the Auditing Standards Board. The exposure draft comment period runs for no fewer than 120 days from publication. Firms should treat the comment period as the start of their preparation, not a waiting period.
Do these proposed changes affect IFRS reporters as well?
The AICPA's attestation standards apply to engagements conducted under US professional standards, so they are most directly relevant to US-based practitioners and companies reporting under US GAAP. Companies reporting under IFRS and subject to IAASB standards operate under a different attestation framework, though many of the practical challenges around digital asset assurance are common across jurisdictions.
What should firms do right now before the standard is finalised?
Three priorities stand out. First, review existing digital asset engagement files to assess whether current procedures would satisfy more explicit requirements around evidence, valuation, and custody. Second, evaluate staff competence in blockchain and digital asset fundamentals and address gaps through training or specialist engagement. Third, consider submitting a formal comment letter to the Auditing Standards Board once the exposure draft is published, drawing on real engagement experience to help shape workable final standards.
Source: AICPA & CIMA
