Auditors and compliance officers are being tasked with assessing systems they have never used before as both banks, payment companies, and asset managers bring digital assets into their balance sheets and product lines. Understanding the term crypto is not enough when reviewing a crypto custody arrangement or a stablecoin reserve. There's a need to be familiar with blockchain mechanics, wallet controls, AML/KYC requirements, governance of the blockchain, and the internal controls surrounding it. The issue these professionals do have is, what should they actually pay attention to before joining a certification?
What You Need to Know
The following areas should be included in a Digital Assets Compliance Certification: blockchain basics, digital assets, AML/KYC, FATF guidance, crypto regulations, governance, risk management, and internal controls. Auditors must have a solid understanding of digital asset risks and control environments to conduct effective digital asset audits. Regulatory knowledge, regulatory monitoring, and regulatory governance are of importance to compliance officers. The curriculum is more important than the certification title, in either case.
Why Auditors Need Digital Asset Compliance Knowledge
The internal auditor who audits a bank's new crypto custody arrangement is asking questions that are not part of the traditional bank audit: How are the private keys stored, who can give the all-clear for the wallet to be transferred, and what if a smart contract doesn't behave as expected? On top of the regulatory compliance questions that any financial product presents, digital assets add regulatory considerations regarding wallet controls, tokenized assets, smart contract risk, access controls, operational risk, blockchain transactions, and custody. This is not a substitute for the basic audit training. It enhances it, enabling auditors to have the right technical understanding to ask the right questions and determine if controls are being put in place to mitigate the risks a blockchain-based system poses.
Why Compliance Officers Need Digital Asset Expertise
Compliance officers have another layer of responsibility. If the customer's funds were transferred from multiple blockchain addresses to an exchange, the process of customer due diligence and enhanced due diligence is different. When creating transaction monitoring systems for wire transfers, there's a chance they might require updates to detect patterns unique to crypto asset transactions. The FATF Recommendations and the Travel Rule influence the reporting requirements for virtual asset transfers; the specific requirements vary depending on whether the business is a bank, an exchange, or a custodian, and whether or not it is based in the jurisdiction in question. The level of reporting requirements for a compliance officer at one payment entity in one country could be significantly different from that of another payment entity in another country with similar compliance roles.
What Should the Certification Curriculum Include?
From the technical perspective, a well-rounded program should include blockchain fundamentals, cryptocurrencies, stablecoins, and tokenization; AML, KYC, CDD, and EDD; internal controls, governance, and risk assessment; and regulatory, operational, technology, custody, and counterparty risk. The reason: in practice, these roles are becoming overlapping, and because the theory of blockchain is abstract, it doesn't help someone evaluate a real control environment.
What Auditors and Compliance Officers Should Compare
Before deciding on a program, consider the depth of the curriculum, regulatory coverage, blockchain basics, audit and control coverage, AML/KYC coverage, scope of risk management, case studies, assessment approach, instructor expertise, applicable accreditation, and the regulatory content's freshness. Confirm with the actual syllabus, not with marketing material.
Which Type of Professional Should Choose What?
Internal auditors should look at programs that have robust blockchain controls and governance, and that have risk assessment frameworks. AML/KYC, FATF guidance, and financial crime compliance content should be the priority for compliance officers. AML/KYC professionals should seek coverage relating to VASPs, Travel Rule mechanics, and financial crime typologies affecting cryptocurrencies. Custody and governance frameworks should be considered along with operational, regulatory, and technology risk.
A Structured Learning Example
101 Blockchains' Certified Digital Assets Compliance Expert (CDACE)™ is a CPD-accredited Digital Assets Compliance Certification focused on blockchain compliance, AML and KYC, FATF guidance, crypto regulations, digital asset governance, and risk management. Auditors and compliance officers may compare it to other programs by matching its coursework to the knowledge gaps in their jobs. It is not an alternative to any existing audit or accounting qualifications and should be viewed as complementary, not as an alternative to any existing qualifications.
Frequently Asked Questions
Is it required for the auditor to have a Digital Assets Compliance Certification?
Not obligatory, but it can help develop blockchain and risk literacy to audit digital asset systems effectively.
Does digital asset compliance help internal auditors?
Yes, especially when it comes to providing clarity on custody controls, wallet governance, and smart contract risk for an audit scope.
So what should compliance officers be looking for in a digital asset certification?
Robust AML/KYC, FATF and Travel Rule coverage, and governance content pertinent to their organisation's business model.
Does a Digital Assets Compliance Certification take the place of traditional AML/Audit certifications?
No. It is not a substitute for those qualifications, but is complementary to them.
What are the most crucial digital asset skills for auditors and compliance officers?
Blockchain basics, AML/KYC knowledge, regulatory knowledge, and an understanding of the risk categories specific to digital assets.
Conclusion
While the ground for auditors and compliance officers is indeed overlapping, their responsibilities are different, and thus, the appropriate certification will be based on the knowledge gaps of the particular role. The depth of the curriculum, scope of regulatory coverage, relevance of the curriculum to audits, AML/KYC curriculum, and scope of risk management are more definitive than any single title, and a good programme enhances, not supplants, existing knowledge.
Top comments (0)