Crypto Treasury Management: Why Corporate Pilots Need Audit Controls

Crypto treasury management is becoming a practical treasury function, not a side experiment. This overview shows how stablecoin pilots, fair-value reporting under FASB ASU 2023-08, and audit-ready controls fit together so finance teams can test digital asset rails without creating reconciliation or compliance gaps.

Hubert Olkiewicz[email protected]
LinkedIn
9 min read

Crypto treasury management is the enterprise discipline of handling liquidity, settlement rails, custody and accounting for digital assets alongside traditional cash positions. We recommend a compliance-first posture: pilot stablecoin rails against existing accounting and audit controls before scaling given the fair-value accounting required under FASB’s ASU 2023-08 and the regulatory scrutiny arriving through the GENIUS Act.


TL;DR:

  • FASB’s ASU 2023-08 requires covered crypto assets at fair value, sending price changes through net income; daily pricing and transaction records support reporting.
  • Run a pilot for one or two quarters on a single payment corridor with limited risk, involving treasury, accounting, audit, and compliance from day one.
  • Map each mint, transfer between chains, and redemption flow to a clear reconciliation trigger before launch, or unmatched events will create recurring manual exceptions.
  • Use allowlisted addresses, dual approval, scheduled key rotation, and reconciliation on a fixed schedule, because confirmed blockchain transactions generally cannot be reversed.
  • Tax treatment depends on jurisdiction, entity structure, and asset use, while GENIUS Act rules for payment stablecoins remain proposed; keep compliance workflows adaptable.

Bitecode
Build Controls Into Crypto Workflows
Bitecode builds custom business software with financial processing, blockchain integration, and workflow automation for complex enterprise systems.
Explore Bitecode

Why crypto belongs in corporate treasury: stablecoins, tokenization and business use cases

Stablecoins give treasury teams something traditional rails cannot: settlement that clears in minutes rather than days, availability on weekends and holidays, and materially lower friction on cross-border flows compared with correspondent banking chains. Tokenization extends that further by making payments programmable, so a transfer can carry its own conditions, timing and reconciliation data instead of relying on a separate message layer.

The practical use cases are narrower than the hype suggests, but they are real:

  • Intercompany payroll and contractor payouts across jurisdictions that otherwise wait on multiple banking cutoffs.
  • Marketplace or platform payouts to sellers and partners who need same-day access to funds.
  • A liquidity buffer held in stablecoins to cover weekend or holiday settlement gaps without pre-funding every corridor.

None of these use cases require abandoning existing banking relationships. They sit alongside them, handling the slice of volume where speed and uptime matter most.

Liquidity and settlement workflows: on-chain rails, off-chain bridges, and operational patterns

Treasury teams choosing between on-chain and off-chain rails are really choosing where reconciliation happens. On-chain settlement gives an immutable, time-stamped ledger entry the moment a transaction confirms; off-chain rails keep settlement inside bank-grade systems but add a bridging step to bring that data into treasury’s books.

Three flow types dominate stablecoin movement, and each leaves a different reconciliation footprint:

  1. Mint-only flows, where new stablecoin supply is created against fiat collateral and must be matched against a custodian’s attestation.
  2. Burn-and-mint flows, used for cross-chain transfers, which require matching a burn event on one chain to a mint event on another before the position is considered settled.
  3. Burn-only flows, where stablecoin is redeemed for fiat, closing the loop and triggering the final ledger entry.

Treasury teams generally design liquidity corridors around a small number of trusted custody counterparties rather than spreading balances thin, and they time settlement batches to match banking cutoffs so stablecoin positions can still be swept into traditional accounts overnight.

Pro Tip: Map each settlement pattern to its reconciliation trigger before go-live; a flow without a clear match event will generate manual exceptions every single cycle.

Accounting, reporting and audit implications for treasury-held crypto assets

FASB’s ASU 2023-08 requires in-scope crypto assets to be measured at fair value, with changes recognized directly in net income under ASC 350-60. That single rule changes how treasury has to think about holding digital assets: unrealized price movement now flows straight through earnings instead of sitting quietly on the balance sheet.

Meeting that standard in practice means treasury systems need to generate daily pricing, P&L attribution and a defensible audit trail, since auditors will ask for the same categories of evidence they expect from any other financial instrument:

  • Pricing sources that are consistent, documented and defensible under review.
  • Custody attestation reports confirming the assets exist and are controlled as claimed.
  • Blockchain transaction logs that tie back to the general ledger entry for entry.

Audit and attestation authorities have pointed to SOC reports and consistent attestation frameworks as the evidence base auditors need for crypto custody and stablecoin reporting. A SOC 1 Type 2 report, paired with AICPA’s criteria for stablecoin reporting, gives external auditors something they can actually test against, which shortens audit cycles considerably compared with ad hoc evidence gathering.

Custody, keys and operational risk controls

Custody decisions set the ceiling on everything else treasury can automate safely. Three models cover most corporate arrangements: self-custody using hardware security modules or key management systems under direct control, institutional custodians who hold keys on the organization’s behalf, and hybrid setups that split signing authority between internal teams and an external custodian.

Whichever model is chosen, the controls around it matter more than the label:

  • Withdrawal allowlists that restrict outbound transfers to pre-approved addresses.
  • Multi-signature or multi-party approval for any transaction above a defined threshold.
  • HSM or KMS-backed key storage with a documented rotation schedule.
  • Reconciliation performed on a fixed cadence rather than only at period close.

Dual approval on every settlement instruction, paired with a SOC 1 Type 2 report from each custody counterparty, gives treasury the paper trail auditors and internal risk committees both expect.

Pro Tip: Treat key rotation like a payroll run: schedule it, log it and never let it depend on one person’s availability.

Tools, automation, and integration patterns for enterprise treasury operations

A functioning crypto treasury stack usually combines five categories: institutional-grade wallets, a treasury accounting engine capable of fair-value accounting, reconciliation tooling that matches on-chain events to ledger entries, compliance modules for sanctions and transaction monitoring, and integrations back into the existing treasury management system.

The integration pattern that holds up at enterprise scale separates governance from execution. AWS’s Web3 engineering team describes a hybrid architecture built around a Canonical Settlement Instruction, or CSI: an off-chain control plane issues the instruction, an orchestration layer (built on something like Lambda or a comparable compute runtime) signs and submits it, and an on-chain contract validates the signed instruction before settling. That separation keeps governance and policy off-chain while making on-chain settlement idempotent and auditable.

  • An off-chain control plane that issues and tracks canonical settlement instructions.
  • An orchestration layer, KMS-backed, that signs and submits those instructions to the relevant chain.
  • On-chain contracts that validate signatures and settle, generating a full audit trail by default.

APIs connecting this stack to the general ledger matter because manual data entry is where most reconciliation breaks happen, and audit logs matter because they are the first thing an auditor requests.

Practical implementation roadmap for treasury teams

Most treasury teams that get this right follow a similar sequence, and the discipline is in not skipping steps:

  1. Establish policy and governance first: who approves what, which custody model applies, and what the risk appetite is before any code is written.
  2. Run a small pilot on a single, low-risk corridor, such as one intercompany payment lane, to validate the settlement pattern end to end.
  3. Confirm custody and accounting readiness, including a working mark-to-market process and a custodian SOC report on file.
  4. Integrate automation, connecting wallets, reconciliation tooling and the general ledger through the orchestration pattern described above.
  5. Bring auditors in before scaling, then expand volume once reconciliation accuracy and settlement timing hold steady.

A typical pilot runs for one or two quarters, gated by measurable thresholds: reconciliation accuracy above an internally defined target, settlement time consistently inside the expected window and audit evidence that is ready without a scramble. Stakeholders should include treasury operations, accounting, internal audit and compliance from day one rather than brought in after the pilot is already live.

How Bitecode supports treasury automation and compliant crypto integration

Our Financial Module and Token Module map directly onto the patterns above: the Financial Module handles accounting and reconciliation logic, while the Token Module provides the on-chain settlement layer, both integrating with KMS and HSM-backed signing rather than replacing existing custody controls. AI assistant and automation tooling can connect these modules into the off-chain control plane and orchestration pattern, enabling a pilot corridor to go live without building that architecture from scratch.

Tax implications and compliance for crypto treasury holdings

Treasury-held crypto assets create tax questions that differ meaningfully from holding cash or securities, and the answers depend heavily on jurisdiction, entity structure and how the assets are used. A stablecoin held purely as a liquidity buffer may be treated differently from the same stablecoin used to settle a cross-border payment, and gains or losses on disposal typically need to be tracked lot by lot rather than on a blended average basis.

Compliance obligations extend beyond tax filings. Anti-money-laundering and sanctions screening apply to crypto settlement the same way they apply to wire transfers, and the GENIUS Act NPRM published by the Department of the Treasury proposes specific rules around the issuance, offer and sale of payment stablecoins, including scope definitions and exemptions that treasury and compliance teams will need to map against their own activity. Because this rulemaking is still proposed rather than final, treasuries should treat it as a signal to build flexible compliance workflows rather than hard-code a single regulatory outcome.

The practical response most teams adopt is to route crypto tax and compliance questions through the same governance process used for any new financial instrument: tax counsel reviews the specific use case and entity structure, compliance confirms sanctions and transaction monitoring coverage, and the treasury system logs enough transaction-level detail (counterparty, chain, timestamp, settlement instruction) to support both. Treating crypto holdings as a reporting afterthought is the most common source of year-end surprises, since fair-value accounting under ASC 350-60 means tax and book treatment can diverge in ways that cash positions never did.

Tax and compliance review with transaction evidence fields

Strategies for diversification within crypto treasury (asset selection and allocation)

Diversification inside a crypto treasury allocation looks different from diversification in a securities portfolio, because the goal is usually operational resilience rather than return optimization. Most corporate treasuries holding digital assets for settlement purposes concentrate heavily in regulated, fiat-backed stablecoins precisely because the volatility of other digital assets would undermine the predictability treasury is supposed to provide.

Within that stablecoin allocation, diversification still matters at the issuer and custody level. Relying on a single stablecoin issuer or a single custodian concentrates counterparty risk in a way that a treasury team managing traditional cash would never accept from a single bank. A more resilient posture spreads balances across more than one regulated stablecoin and more than one custody counterparty, with clear thresholds for how much exposure any single counterparty can carry.

For treasuries exploring broader digital asset exposure beyond settlement-focused stablecoins, allocation decisions should separate operating liquidity (stablecoins needed for near-term settlement) from any strategic holding, with different governance, custody and accounting treatment applied to each. Mixing the two inside one policy tends to produce exactly the kind of fair-value swings under ASC 350-60 that make treasury reporting unpredictable. The discipline that works in practice is the same one that governs traditional cash: define the purpose of each holding first, then size and diversify around that purpose rather than around market opportunity.

Security best practices beyond custody models (fraud prevention, incident response)

Custody controls prevent unauthorized withdrawal, but they do not address the full range of fraud vectors treasury teams face once crypto settlement is live. Social engineering targeting approval workflows, compromised API keys and address-poisoning attacks (where a malicious address is crafted to resemble a legitimate counterparty) all bypass custody protections entirely because they exploit the approval process rather than the wallet itself.

Effective fraud prevention layers several controls on top of custody: transaction monitoring tuned to flag unusual counterparties or amounts, a documented approval hierarchy that cannot be overridden by a single compromised credential, and regular testing of the approval workflow itself rather than just the technical infrastructure. Treasury teams that have built mature programs around traditional wire fraud tend to extend the same playbook to crypto settlement rather than treating it as a separate discipline.

Fraud routes and layered transaction approval controls

Incident response needs its own runbook specific to digital assets, since the remediation options differ from a disputed wire transfer. A confirmed on-chain transaction generally cannot be reversed, which makes pre-incident controls, such as allowlisting and transaction limits, far more important than post-incident recovery. Teams evaluating how to build that layered monitoring and incident response capability without building it entirely in-house often look to managed compliance and continuous monitoring providers, such as MARFI’s compliance operations services, for evidence-driven audit readiness and 24/7 monitoring coverage that would otherwise require a dedicated internal team.

Cross-border payment and settlement considerations unique to crypto treasury

Cross-border settlement is where stablecoin rails show their clearest advantage over correspondent banking, but the considerations that matter are different from a domestic pilot. Settlement finality, for instance, depends on the specific blockchain’s confirmation characteristics, and treasury teams need to understand how many confirmations constitute “final” for their risk tolerance before treating a cross-border payment as settled.

Currency and regulatory scope add complexity that a single-jurisdiction pilot does not surface. A stablecoin pegged to one fiat currency moving between counterparties in different jurisdictions can trigger foreign exchange, sanctions and local licensing questions simultaneously, and the GENIUS Act NPRM specifically addresses extraterritorial application, meaning a stablecoin issuer’s obligations can extend to activity involving counterparties outside the United States depending on how the final rule lands.

Liquidity corridor design also changes shape across borders. Rather than holding a single stablecoin balance globally, treasury teams typically maintain corridor-specific liquidity, sized to the volume and settlement timing of each trading relationship, with custody counterparties chosen partly for their regulatory standing in the relevant jurisdictions. Reconciliation needs to account for time zone differences in banking cutoffs even when the blockchain settlement itself happens continuously, since the fiat leg on either end still runs on traditional banking hours. The net effect is that cross-border crypto settlement removes some friction (speed, availability) while introducing new friction elsewhere (jurisdictional scope, corridor-specific compliance) that a purely domestic pilot will not reveal.

Impact of blockchain network fees and transaction speed on treasury decisions

Network fees and confirmation speed directly shape which settlement patterns are viable for a given use case, and they vary significantly across blockchains and even across times of day on the same network. A payroll disbursement that needs to settle in minutes at predictable cost behaves very differently on a congested network than on one designed for high throughput, and treasury teams generally choose their settlement chain based on the specific corridor’s volume and timing requirements rather than defaulting to a single chain for everything.

Fee volatility also affects how treasury models the cost of a settlement pattern over time. A corridor that looks economical when fees are low can become uneconomical during periods of network congestion, which is why mature treasury operations build fee monitoring into their settlement decision logic rather than assuming a static cost per transaction. Batching smaller payments into fewer on-chain transactions is a common mitigation, trading some settlement speed for materially lower aggregate fees.

Transaction speed also interacts with the reconciliation patterns described earlier: a mint-and-burn flow that takes several minutes to finalize on both chains creates a reconciliation window during which the position is technically in transit, and treasury systems need to account for that window explicitly rather than treating settlement as instantaneous. Choosing a settlement rail, in practice, is a joint decision about fee cost, confirmation time and the operational tolerance for a reconciliation gap, not a choice driven by blockchain preference alone.

A pragmatic view on crypto treasury adoption

Treasuries that succeed with digital assets tend to start smaller than their ambition suggests: one corridor feeding the same accounting and audit cycles already in place, rather than a parallel system built on faith that compliance will catch up later. Bringing auditors and compliance into the pilot from week one, not after launch, is what separates programs that scale from ones that stall at the first audit finding. We are glad to share pilot templates and module configurations with teams working through this stage.

— Bitecode

How Bitecode can accelerate your crypto treasury pilot

Modular Financial and Token modules come with a significant portion of the baseline system pre-built, enabling a compliance-first pilot to reach production controls faster than a multi-quarter build cycle.

Bitecode

  • Start with a scoped pilot covering one settlement corridor and your existing custody and accounting requirements.
  • Review the Financial Module for accounting, audit and reconciliation logic built for treasury use.
  • Pair it with our AI business process automation workflows to connect settlement data into your ledger without manual rework.

If a scoped pilot sounds like the right next step, request a scoping call and we will map the modules to your corridor.

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

FAQ

What is a crypto treasury company?

A crypto treasury company or function manages an organization’s digital asset holdings, covering custody, liquidity, settlement and accounting rather than trading digital assets for speculative return. Most corporate treasuries that hold crypto do so to support faster settlement and payouts, not as an investment strategy.

What are the tools of treasury management?

Core tools include institutional-grade wallets, a treasury accounting engine capable of fair-value measurement, reconciliation software, compliance and transaction-monitoring modules, and integration into the existing treasury management system. The pattern that ties them together, described by AWS’s Web3 engineering team, separates an off-chain control plane from an on-chain settlement layer to keep the system auditable.

Who owns 3% of Bitcoin?

This article does not cover Bitcoin ownership concentration, and we have not found a sourced figure to confirm or deny that specific claim. Treasury teams focused on stablecoin settlement, which is the dominant corporate use case, generally do not need to track Bitcoin ownership distribution.

Does the US government regulate cryptocurrency?

Yes, regulation is actively developing: the Department of the Treasury has published a proposed rule under the GENIUS Act covering payment stablecoin issuance, offers and sales. Treasury teams should treat current rules as evolving and build compliance workflows flexible enough to adapt as the rulemaking finalizes.

Sources

Articles

Dive deeper into the practical steps behind adopting innovation.

Software delivery6 min

From idea to tailor-made software for your business

A step-by-step look at the process of building custom software.

AI5 min

Hosting your own AI model inside the company

Running private AI models on your own infrastructure brings tighter data & cost control.

Hi!
Let's talk about your project.

this helps us tailor the scope of the offer

Przemyslaw Szerszeniewski's photo

Przemyslaw Szerszeniewski

Bitecode co-founder

LinkedIn