Surviving Your Crypto SMSF Audit: What the Auditor Checks
How to pass your crypto SMSF audit without the year-end scramble for records.
In this article
- Does your crypto SMSF need an audit?
- Why do crypto funds get extra scrutiny?
- What does a crypto SMSF auditor actually check?
- Does your trust deed and strategy allow crypto?
- How do you prove your SMSF owns a self-custody wallet?
- Are screenshots or CSV files enough?
- How do you value your crypto at 30 June?
- What records does a crypto SMSF audit require?
- What mistakes fail a crypto SMSF audit?
- Why won’t my accountant touch crypto, and why does the audit go in circles?
- Safekeep Case Study: A self-custody audit that stalled for a year, cleared in weeks
- What does a crypto SMSF audit cost?
- What if you’re already behind, or it’s a mess? Can it be fixed?
- What happens if the auditor can’t verify it?
- How do you make your crypto SMSF audit a non-event?
- Frequently Asked Questions about crypto SMSF audits
- Sources
Every SMSF is audited once a year, and a fund that holds crypto gets extra attention. The auditor checks three things about your crypto: that it exists, that the fund owns it, and that it’s valued correctly at 30 June. Prove those three and the audit is a non-event.
The annual audit is not an ATO audit. It’s a routine, independent check every fund goes through before it lodges. This guide shows you exactly what the auditor checks, what proves each piece, and how to keep the whole thing boring.
Does your crypto SMSF need an audit?
Yes. Your SMSF must be independently audited each year by an ASIC-registered SMSF auditor before it lodges its annual return, whether it holds crypto, shares or cash. The auditor gives two opinions in one report. The first part is the financial statements, and the second part is on compliance with the super rules. They must be appointed at least 45 days before the return is due.
The auditor’s job is to check compliance, nothing more. For a tidy fund, it barely registers. If there are problems, the auditor flags them and you sort them out.
In practice, you won’t deal with the auditor directly. Your provider engages an independent third-party auditor they already work with, and everything goes back and forth through your provider.
Why do crypto funds get extra scrutiny?
Because crypto is harder to verify than a share or a property, not because it’s suspicious. (Well, the government certainly thinks crypto is suspicious.) But a share has a registry and a property has a title, so ownership is easy to confirm. Crypto held in a decentralised wallet has neither. Prices also swing hard, which matters for the 30 June valuation. The ATO flags crypto as a higher-risk asset it watches closely.
So the auditor asks for specific evidence. That’s not a red flag. It’s just what happens when you hold something no registry can vouch for.
What does a crypto SMSF auditor actually check?
There are three main things the auditor checks for at 30 June. That the asset exists, the fund owns it, and that it’s recorded at the right value. Here’s what each check needs:
| What the auditor must confirm | What proves it |
|---|---|
| Existence (the crypto is really there at 30 June) | The public wallet address, which the auditor re-checks on a blockchain explorer, plus a dated balance record |
| Ownership (the fund owns it, not you) | A declaration of trust naming the exact address, the funding trail, and a proof of control (a signed message or a test transfer) |
| Valuation (recorded at market value) | The 30 June closing price from a reputable exchange with historical data, in a signed valuation minute |
| The trail (it all reconciles) | The full year’s transaction history reconciled to the fund’s bank account, plus trade confirmations |
Nail those four and there’s nothing left for the auditor to question. Each holding sits at its own wallet address, a bit like the HIN on a share holding, so the address does much of the work.
The numbers also have to line up. For example, a cold wallet is booked at $648,000 on the 30 June accounts, but on-chain it held $615,000. The auditor queries the gap, usually a second wallet nobody disclosed.
Does your trust deed and strategy allow crypto?
Before the auditor looks at your wallet, they check the fund is allowed to hold crypto at all. Two documents decide it.
Your trust deed has to permit it. Most modern deeds allow a wide range of assets, or name “other assets,” which covers crypto. An older deed may not, and if crypto’s a big part of the fund, the deed might need an update.
Your investment strategy has to name it. It must spell out how crypto fits the fund’s approach to risk, diversification, liquidity and cash flow. If your strategy doesn’t mention a big crypto holding, that’s a common thing the auditor pulls you up on. This comes from section 52B of the SIS Act and regulation 4.09 of the SIS regulations.
Get these two right before 30 June and the rest of the audit is about evidence, not permission.
How do you prove your SMSF owns a self-custody wallet?
You can prove it with these four things:
- A declaration of trust naming the exact public address, stating the wallet is held on trust for the fund. The precise address is what ties the paper to the crypto.
- The funding trail of money out of the fund’s bank account, into a fund-named exchange account, and on to the wallet. It shows the fund, not you, paid for the crypto.
- A proof of control with a small test transfer from the wallet. Only the key-holder can do that, so it shows the fund controls the wallet.
- Setup records like the trustee resolution, the deed clause that allows crypto, and a note of who holds the keys.
When you see the balance on the blockchain, it proves the crypto exists, but not control or ownership. A wallet whose keys are lost still shows a balance forever. That’s why ownership needs its own proof, not just a balance. We cover the how-to in depth in SMSF crypto wallets and self-custody.
Are screenshots or CSV files enough?
No, not on their own. A screenshot or an exchange CSV is something you create and can edit, so the auditor treats it as backup, not proof. Auditing standards rank self-made records below evidence the auditor can check independently. That means the wallet address on a blockchain explorer, or the funding trail from the fund’s bank account.
A self-custody wallet issues no statement, so you do have to write some records yourself, like the valuation minute and the declaration of trust. That is fine, as long as each one points back to something on-chain the auditor can verify. It’s the opposite of making evidence up, and that difference matters more than ever. In the 2025/26 audit season, David Saul of SMSF firm Saul SMSF reports a wave of AI-generated evidence reaching auditors. These are fabricated deeds, agreements and back-dated explanations, built to plug gaps where no record ever existed. Under auditing standard ASA 500, the auditor must obtain evidence that is genuine and reliable. So made-up paperwork gets a lot more scrutiny now. See his piece, AI-generated evidence in SMSF audits, in SMSF Adviser.
How do you value your crypto at 30 June?
At market value in Australian dollars on 30 June, backed by evidence your auditor can check. You take the 30 June price from a reputable source, apply it to the quantity you hold, and record where it came from. Holding statements or investment summaries on their own are not enough. That rule sits in regulation 8.02B.
One thing changed recently. The ATO used to point trustees to the 30 June closing price on an Australian exchange. It no longer names one source, because Australia has no single crypto exchange like the ASX, so prices differ a little between platforms. The rule now is to use a reputable source, and be able to justify the figure to your auditor.
Where to get the price:
- Start with the exchange your fund already uses. Take the 30 June closing price in Australian dollars from the platform you bought and hold on. Any reputable, AUSTRAC-registered exchange that publishes historical prices works, such as CoinSpot, Independent Reserve, BTC Markets, Swyftx or Kraken. This is the cleanest option, because it matches where your crypto lives.
- For an asset you don’t hold on an Australian exchange, or as a cross-check, use a reputable price tracker such as CoinMarketCap, CoinGecko or Yahoo Finance. If the price is in US dollars, convert it to Australian dollars at the 30 June rate and note the rate you used.
Two habits keep the auditor happy. Use the same source every year, and if you ever change it, write down why. And keep your figure close to the market. A small gap is fine, but sitting four or five per cent off on a volatile day will get queried.
Prices move after 30 June, sometimes hard. That later movement doesn’t change your 30 June figure, because the value was set and public on the day. But if the move is large, the auditor may add a short “emphasis of matter” note to the report. That falls under auditing standard ASA 560, which has the auditor check events right up to the day they sign. A sudden government rule change on crypto can trigger the same note.
The deliverable is a signed valuation minute recording the asset, the quantity, the price, the source and its link, and the date, plus a blockchain balance record. The full tax side lives in SMSF crypto tax.
What records does a crypto SMSF audit require?
The auditor wants a clean pack that shows every crypto move for the year, all in the fund’s name. Keep it as you go and the audit is quick. Here’s the list:
- account-opening documents in the fund’s name,
- a hardware-wallet invoice addressed to the fund,
- the full transaction history (1 July to 30 June): every buy, sell, crypto-to-crypto swap and fee,
- trade confirmations, and your wallet addresses,
- trustee minutes for the decisions, and the 30 June valuation.
What the auditor asks for depends on how you hold it
| How you hold it | What the auditor wants |
|---|---|
| On an exchange (custodial) | The full year’s transaction history, and a 30 June balance listing with the fund clearly named as the holder. If the exchange itself isn’t audited, the auditor may still qualify the report. |
| In your own wallet (self-custody) | The wallet address, the full year’s transaction history, and a signed declaration confirming the 30 June balance and quantity of each asset, that the fund owns and uses the wallet only, that the device is stored securely, and that the crypto wasn’t bought from a related party. |
Keep transaction and accounting records for at least five years, and minutes for ten. Keep the trustee declaration you signed on joining for the life of the fund. Where a custodian or exchange holds the crypto for the fund, the auditor relies on an ASAE 3402 Type 2 controls report from that provider. Self-custody has no such report, which is exactly why the address-and-valuation pack matters. For the full year-by-year run of what’s due, see your crypto SMSF’s yearly checklist.
What mistakes fail a crypto SMSF audit?
A few errors cause almost all the pain, and none of them are about crypto being risky.
- A personal-name account or wallet is the biggest one. Fund assets must be kept separate from yours under regulation 4.09A, so putting them in your own name breaks the separation rule.
- No 30 June valuation, or only a screenshot, means no supportable value, so it can't be signed off.
- Personal and fund crypto mixed on one wallet or device.
- Missing or incomplete transaction history, where a gap means the auditor can't verify the trail.
- Trying to move your personal crypto into the fund, which the related-party rule bars (section 66) and can't be undone.
- Offshore or no-KYC exchanges, which leave ownership and records hard to prove.
- Paying a pension in crypto. Pension payments have to be made in cash (regulation 6.17).
- Taking staking rewards, rebates or commissions into a personal account, which breaks the arm's length rule (section 109).
- Posting crypto as collateral to borrow (section 67), or trading crypto derivatives, which puts a charge over fund assets (regulation 13.14).
If the auditor can’t verify a material holding, they qualify the report and may lodge a contravention report. Separation and valuation breaches also carry trustee penalties, which is why getting the setup right matters far more than it looks. The full rulebook is in SMSF crypto rules: what the ATO requires.
Why won’t my accountant touch crypto, and why does the audit go in circles?
Because it’s tedious work many accountants and auditors have never done. A self-custody wallet issues no statements, so you can end up paying to teach them. A year of trades is slow to reconcile, and one swap can spawn dozens of tax lines, which pushes up the cost of the return. Auditors tend to be cautious too, so an unfamiliar one often qualifies the fund, or declines it, just to stay safe.
It gets worse if you used an international platform that isn’t a major exchange, because these often don’t recognise SMSFs, which is a common set-up mistake. Then the auditor sends back a list of queries. Your accountant doesn’t know how to answer them for crypto, so they pass them to you. You don’t know either. Nothing moves, the deadline creeps closer, and you’re stuck in a loop, each person waiting on the other. This is the part that costs you sleep, and it’s completely avoidable.
The way out is simple: someone who has done it before breaks the loop, and a clean pack stops the questions being asked in the first place. That’s the whole job.
What does a crypto SMSF audit cost?
The audit fee itself is modest, usually $400 to $800 depending on complexity. The real cost is the preparation. If you hold crypto and the person preparing your accounts doesn’t understand it, expect a lot of back and forth. Time and cost build up before the audit even starts. And if the fund doesn’t pass, it has to be done again.
The good news is that the cost is almost entirely in your hands. A fund with clean records, a fund-named account and a tidy 30 June valuation is cheap and fast to audit. The expense comes from untangling a year of undocumented activity after the fact. For the full picture of running an SMSF, see how to set up an SMSF to buy crypto.
What if you’re already behind, or it’s a mess? Can it be fixed?
Almost always, yes. If you’re reading this with a sinking feeling because your records are a mess or your last audit stalled, breathe. Most of it can be rebuilt.
Transaction history can be reconstructed from exchange and blockchain data. A declaration of trust can be put in place now to evidence ownership. A 30 June value can be rebuilt from historical prices. Once the pack is assembled, the fund goes back to being audit-ready. The sooner you start, the cheaper and calmer it is, but “I’ve left it too long” is rarely true.
What happens if the auditor can’t verify it?
The report has two parts, and crypto can land on either. Part A is the accounts. Part B is compliance with the super rules.
If you can’t prove a material holding exists, belongs to the fund, or is valued right, the auditor qualifies Part A. They can’t confirm the accounts are right. If the problem is a breach, like a wallet in your personal name, that hits Part B, and the auditor may lodge an Auditor Contravention Report with the ATO. A personal-name account can trigger both at once.
That sounds alarming, but a qualification isn’t automatic disqualification, and the contravention report runs off thresholds, it’s not a punishment. In most cases the fix is the right evidence, produced after the fact. The exception is lost keys with no succession plan. If a material holding has no documented way to pass on the keys, that alone can qualify Part A.
How do you make your crypto SMSF audit a non-event?
Everything above comes down to one habit: keep the fund’s crypto in the fund’s name, and keep the evidence as you go. Before each 30 June:
- hold the account and wallet in the fund’s name,
- have a declaration of trust naming the wallet address,
- record the 30 June value from your usual exchange,
- keep the full transaction history and the bank trail,
- and file it all in one place.
Do that and the audit is quiet, quick and cheap. If you’d rather hand it to someone who does this every day, talk to our SMSF crypto compliance team.
Frequently Asked Questions about crypto SMSF audits
What does the auditor check on a crypto SMSF?
Three things at 30 June: that the crypto exists, that the fund owns it, and that it’s recorded at market value. For a self-custody wallet they also want proof the fund controls the keys.
How do I prove my SMSF owns its crypto wallet?
With a declaration of trust naming the exact public address, the funding trail from the fund’s bank account, and a proof of control such as a signed message or a small test transfer.
Are exchange screenshots or CSV files enough for the audit?
No. They’re self-generated and editable, so they count as backup, not proof. The auditor wants evidence they can reproduce, like the address checked on an explorer plus the funding trail.
What if I lost crypto to a hack or scam, or lost my keys?
You may be able to claim a capital loss, but only with evidence. The ATO wants the dates you acquired and lost the crypto, the wallet address, what you paid, and how much was in the wallet. You also need proof the fund controlled it, such as the device held by the fund and transactions that trace back to it. A lost-key wallet still shows a balance on-chain, so document the loss. Don’t just point at the address.
Do staking, airdrops or DeFi make the SMSF audit harder?
They add records to keep, because each reward is income and each swap is a disposal. It’s manageable with tidy records. See crypto staking in an SMSF and SMSF crypto tax.
Can the same accountant do my books and my crypto SMSF audit?
No. The auditor must be independent of whoever prepared the accounts. Your accountant can prepare the fund, but a separate ASIC-registered auditor signs it off.
Sources
- AUASB Guidance Statement GS 009 “Auditing Self-Managed Superannuation Funds” (June 2020).
- Australian Taxation Office: Auditing SMSFs with crypto assets; Ownership and separation of fund assets; Verifying the market value of fund assets; Keeping crypto records; Appoint an SMSF auditor.
- SIS Regulation 4.09A (separation of assets); Regulation 8.02B (market value); SIS Act s35A/s103/s104A (records).
- AUASB ASAE 3402 / GS 007 (custodial controls reports).
- SIS Act ss 52B, 65, 66, 67, 109 and SIS Regulations 4.09, 6.17, 13.14 (crypto compliance breaches); Auditing Standards ASA 500 (audit evidence) and ASA 560 (subsequent events).
- Shelley Banton, ASF Audits, “Crypto and NFTs: Compliance Risk for the Unwary” (SMSF Audit Conference, July 2023).
- Assurify, SMSF Audit Checklist (for years to 30 June 2024).
General information only. This article is not personal financial, tax or legal advice and does not take your circumstances into account. Speak to a qualified, licensed professional about your situation before acting on it.
Keep reading
Crypto SMSF - The Complete Guide (2026) Everything you need to know to set up, run, or close down a crypto SMSF. Read more
SMSF Crypto Wallets and Self-Custody: A Guide Your custody options, why self-custody protects the fund, and how to keep it audit-proof. Read more
SMSF Crypto Tax: How Much You'll Pay What your fund pays on crypto, what triggers a tax event, and the legal levers to pay less. Read more