Auditen
practitioner note

Does an Unseen Audit Count?

Tether has finally completed its first full audit by KPMG. This is the sort of news that usually triggers a sigh of relief from those tasked with managing counterparty risk and reserve verification. However, there is a catch that should make any compliance officer reach for the peppermint tea: the audited financial statements haven't actually been published.

In the world of paperwork, a "completed audit" that remains private is not a regulatory milestone. It is a conversation.

For the practitioner responsible for internal controls, this creates a specific, irritating problem regarding evidence. If you are marking a risk as 'mitigated' because a third party has been audited, you have effectively replaced an actual control with a press release. An audit opinion is only useful when it can be cross-referenced against the assertions made in the public domain. When the report stays in a drawer, the audit ceases to be a tool for transparency and becomes a shield for plausible deniability.

We see the other side of this coin with AI Financial Corporation. They've delayed their quarterly SEC filing. While Tether is choosing when to show its hand, AI Financial simply cannot produce one. Both scenarios result in the same output: a void where evidence should be.

The temptation here is to argue that an independent firm like KPMG has seen the books and therefore "the truth" is known to someone competent. This is a dangerous assumption. Independence is not a magical property that validates a balance sheet in secret; it is a process that culminates in a signed, dated, and public opinion. Without the publication, there is no accountability for the auditor's findings or the company's responses to them.

A private audit is just an expensive internal review.

The second-order effect here lands squarely on the auditors and the firms that rely on these assertions downstream. When a firm claims it has been audited but hides the result, it creates a "ghost assurance" loop. If the assets later vanish, perhaps in a fashion similar to the $425 million Ponzi scheme recently flagged by the SEC, the auditor becomes the primary target for the inevitable litigation. They will be asked why they signed off on figures that were never shared with the market, while the firm will claim they relied on the auditor's expertise.

It also puts the regulator in a curious position. The SEC has spent the last week acting with a level of inconsistency that would be comical if it weren't so disruptive to planning. They've cancelled important meetings on digital assets just as the White House is reportedly rolling out the red carpet for crypto executives.

This regulatory vacuum doesn't mean the rules have vanished; it means they are being applied sporadically. The practitioners who think this gap allows them to relax their evidence standards are mistaken. In fact, when regulators pivot, and they always do, they tend to look for the easiest targets first. A company that claims to be "audited" but cannot produce a public statement is an incredibly easy target.

The strongest objection from the industry is usually that publishing such statements would reveal proprietary strategies or expose the firm to predatory trading. This is a red herring. Financial audits are not meant to reveal your secret sauce; they are meant to prove you actually have the ingredients in the cupboard. If a statement cannot be published without ruining the business model, then the business model is likely the problem, not the audit requirement.

For those of you updating your risk registers this month, look at your "Third Party Assurance" column. If you have listed 'Audited' next to a vendor or partner, but you haven't actually seen the signed opinion, your evidence is zero. You are relying on faith, which is not a recognised accounting standard.

Check your filings. Ensure that "completed" means "available."

The SEC might be cancelling its Friday meetings, and they might be ignoring the digital assets space for a few weeks while the political winds shift, but the requirement for verifiable evidence remains static. 14,000 Bitcoin wallet users found out via a Trezor breach that security assertions are meaningless without implementation. The same logic applies to financial transparency.

I suspect we'll see a sudden surge in "unpublished" audits becoming public the moment the SEC decides to stop cancelling meetings and start issuing fines again. Until then, keep asking for the PDF.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Trump White House to Reportedly Host Crypto, Prediction Market Executives as SEC Cancels Crucial Digital Assets Meeting - TradingView Compliance Week (Google News)
  2. AI Financial Corporation Delays Quarterly SEC Filing - The Globe and Mail PCAOB
  3. SEC accuses crypto firm founder of running $425 million Ponzi scheme - InvestmentNews Compliance Week (Google News)
  4. SEC Scraps Friday Meeting To Propose Crypto Regulations - Law360 Compliance Week (Google News)
  5. Flock Safety announces search mandates amid mounting privacy concerns - National Desk Data Privacy (Google News)
  6. Women targeted by Regina police sergeant file sexual assault lawsuits - The Globe and Mail Data Privacy (Google News)
  7. More than 1,000 nonprofits impacted by cybersecurity breach - The Baptist Paper InfoSec Compliance (Google News)
  8. Flock Safety, which is facing increasing scrutiny of its car-tracking technology that law enforcement agencies across the U.S. use, announced several updates on Thursday that the company said would improve privacy protections. Critics say the measures leav - facebook.com Data Privacy (Google News)

How stories are selected and assessed