When crypto appears on an SMSF balance sheet, the auditor is looking for six things: evidence that the assets are separated from members’ personal holdings, documentation of the custody arrangement, alignment with the fund’s investment strategy, a defensible valuation at 30 June, a complete record of every acquisition and disposal, and the absence of the failures that commonly turn up in digital asset files. Each of those maps to a specific obligation under the Superannuation Industry (Supervision) Act 1993 (SIS Act), and each is a place where a digital asset file can fall short.

Key takeaways on auditing SMSF digital asset holdings

  • An approved SMSF auditor conducts an independent annual audit covering both the financial statements and the fund’s compliance with the SIS Act and regulations, under s 35C of the SIS Act.[1]
  • For digital asset holdings, the core evidence set is separation of assets, custody documentation, investment-strategy alignment, 30 June valuation, and complete transaction records.[4][5]
  • The failures that recur in practice are in-house asset breaches, missing or unsupported valuations, and gaps in key and access control that make separation impossible to evidence.[3][4]
  • A contravention that meets the reporting tests obliges the auditor to lodge an Auditor/Actuary Contravention Report (ACR) with the ATO, independent of the audit opinion on the financial statements.[6]
  • Australian SMSFs held approximately AUD 3.02 billion in digital assets at 30 June 2025, a holding large enough that audit-quality record-keeping is now a routine professional question rather than an edge case.[7]

What does an SMSF auditor look for when crypto is on the balance sheet?

The auditor is testing whether the fund can prove what it asserts. A line item that reads “digital assets” in the financial statements has to be supported by evidence that the assets exist, belong to the fund, are held separately from anyone’s personal property, are valued on a defensible basis, and were acquired and disposed of consistently with the fund’s investment strategy and the SIS Act.

The role itself is defined narrowly. Every SMSF must appoint an approved auditor to conduct an annual audit before the fund lodges its return, and that audit covers two things: the financial statements, and the fund’s compliance with the SIS Act and regulations.[1] The auditor forms an independent opinion. They do not advise the trustee, prepare the records, or design the custody arrangement. With digital assets, the practical effect of that independence is that the auditor will accept only what can be evidenced, not what the trustee describes.

For a crypto holding, the evidence set comes down to six items.

Auditor's digital-asset evidence checklist: six evidence items with the SIS Act or ATO basis and the document expected for each.

The file an auditor wants to see

A clean digital asset file lets the auditor verify each of the six items from documents rather than from the trustee’s recollection. The file should establish ownership, separation, valuation, and strategy alignment without the auditor having to reconstruct anything.

In practice that means the following sit in the file:

  • An investment strategy that names digital assets. The strategy should show that the trustee considered the asset class, its risk and return characteristics, liquidity, and the fund’s diversification before holding it. A strategy that is silent on crypto while the fund holds crypto is a gap the auditor has to note.[5]
  • Custody documentation. Account or wallet records in the name of the fund, the platform or exchange the assets are held through, and a description of how the assets are controlled. Where the holding is self-custodied, the file needs to show how the private keys are held and that they are held for the fund, not the member.[4]
  • Evidence of separation. Records that demonstrate the digital assets are kept separate from the personal assets of members and related parties. This is a covenant obligation under the SIS Act, reinforced by the ATO’s separation guidance.[4]
  • A 30 June valuation. Each asset valued at market value at the reporting date, with the source of the valuation recorded. Crypto markets trade continuously, so the auditor will look for a consistent, documented basis: the price source, the time, and the exchange rate applied.[5]
  • A complete transaction record. Every acquisition and disposal, with dates, amounts, counterparties, and the corresponding bank or platform movement. Gaps in the transaction record are one of the more common reasons a digital asset balance cannot be substantiated.[5]

The trustee builds this file. The accountant typically assembles it. The auditor tests it. A file assembled with the audit in mind moves through the audit faster and with fewer queries. The trustee-facing version of this build is covered in a separate guide to holding Bitcoin in an SMSF, and the accountant’s assembly checklist sits in the SMSF crypto ATO compliance checklist.

What are the common compliance failures in SMSF digital asset holdings?

Three failures recur: in-house asset breaches, missing or unsupported valuations, and key and access-control gaps that make separation impossible to evidence. Each one has a direct line back to a SIS Act obligation, and each is something an auditor is trained to surface.

In-house asset breaches

The in-house asset rules cap a fund’s investments in, loans to, and leases with related parties at 5% of total fund assets.[3] Digital assets create new ways to trip this. A fund that holds a token issued by a related party, lends crypto to a related entity, or transacts with a related-party platform can move over the 5% threshold without an obvious cash trail. The auditor checks the nature of the counterparties and the assets, not just the balances.

Missing or unsupported valuations

A holding has to be valued at market value at 30 June, and the valuation has to be supported. The failures here are usually a missing valuation, a valuation pulled from an inconsistent or undocumented source, or a balance carried forward from the prior year without revaluation. Because crypto prices move continuously and vary across exchanges, a valuation with no recorded source and timestamp is difficult for an auditor to accept.[5]

Key and access-control gaps

Separation of fund assets from personal assets is a covenant obligation.[4] With digital assets, separation lives in how the keys and accounts are controlled. A holding in a member’s personal exchange account, a wallet that mixes fund and personal assets, or private keys held in a member’s name rather than the fund’s name all defeat separation. The auditor will look for account and key arrangements that put control of the assets unambiguously with the fund.

Decision flow for whether a digital asset finding triggers an Auditor/Actuary Contravention Report, branching from the ATO reporting tests to either lodge an ACR or document with no ACR required.

What triggers an auditor’s contravention report?

An auditor must lodge an Auditor/Actuary Contravention Report with the ATO when a contravention they identify meets the ATO’s reporting criteria. The obligation is separate from, and additional to, the audit opinion on the financial statements.[6]

Not every contravention is reportable, and not every reportable contravention is one the auditor first discovered. The ATO sets out tests the auditor applies, including the trustee’s behaviour and willingness to rectify, the financial impact on the fund, the value and duration of the contravention, and whether it has been reported before.[6] A digital asset contravention runs through the same tests as any other. An in-house asset breach that pushes a fund materially over the 5% cap, or a separation failure the trustee will not rectify, is the kind of finding that tends to meet the threshold.

The point for trustees and advisers is that the auditor’s reporting duty does not depend on the trustee agreeing there is a problem. The auditor forms the view independently and reports where the criteria are met. A file that prevents the contravention in the first place is the only reliable way to avoid the report.

What are the recent ATO areas of focus for SMSF crypto?

The ATO’s published position on SMSFs and crypto assets pre-dates the Digital Assets Framework and continues to apply through the transition to it. That guidance centres on the sole purpose test, separation of assets, valuation, and documentation of acquisitions and disposals.[5]

The sole purpose test in s 62 of the SIS Act requires the fund to be maintained for the purpose of providing retirement benefits to members.[2] For digital assets, the ATO’s concern is any arrangement where a member derives a present-day benefit from the fund’s crypto, such as personal use of a fund-held asset or access to fund-held keys for personal transactions. Separation and the sole purpose test reinforce each other here: an asset a member can personally control is an asset that raises both questions at once.

Valuation and record-keeping remain the practical pressure points. The ATO expects holdings valued at market value at 30 June with a documented basis, and a complete record of every transaction. These are the same items the auditor tests, which is why a file built to the ATO’s documentation expectations is also a file built for the audit. The regulatory backdrop is shifting as well: the Digital Assets Framework commences on 9 April 2027, introducing the digital asset platform (DAP) and tokenised custody platform (TCP) categories, which over time will change the kind of custody evidence available to support an audit.[8] What an auditor looks for under the SIS Act does not change with the Framework. The quality of the records produced by the platforms should.

The platform side of this, including what Framework-licensed custody will look like for an SMSF, is covered in a separate piece on SMSF crypto custody. The pillar overview of the Framework sits at the Digital Assets Framework pillar overview.

Common questions

What does an SMSF auditor check for crypto holdings?

The auditor checks that the digital assets exist and belong to the fund, that they are held separately from members’ personal assets, that the holding aligns with the fund’s investment strategy, that each asset is valued at market value at 30 June on a documented basis, and that there is a complete record of every acquisition and disposal. They also test for common contraventions such as in-house asset breaches and separation failures.[4][5]

Is an SMSF auditor allowed to advise the trustee on crypto?

No. The auditor’s role under s 35C of the SIS Act is to conduct an independent annual audit of the financial statements and the fund’s compliance.[1] Advising the trustee on how to hold or structure the crypto would compromise that independence. Strategy, custody design, and record assembly sit with the trustee, the accountant, and a licensed adviser.

What digital asset valuation will an auditor accept?

A market value at 30 June with a recorded, consistent source: the price, the exchange or data source used, the time, and the AUD conversion where relevant. Because crypto prices move continuously and differ across venues, the auditor is looking for a documented and repeatable basis rather than a single number with no provenance.[5]

How do in-house asset rules apply to crypto in an SMSF?

The in-house asset rules cap related-party investments, loans, and leases at 5% of total fund assets.[3] Digital assets can breach this through tokens issued by related parties, crypto lent to related entities, or dealings with related-party platforms. The auditor examines the nature of the counterparties and assets, not just the headline balances.

When must an SMSF auditor lodge a contravention report for crypto?

When a contravention the auditor identifies meets the ATO’s reporting criteria, which include the trustee’s behaviour, the financial impact, the value and duration of the contravention, and whether it has been reported before.[6] A serious in-house asset breach or an unrectified separation failure involving crypto can meet the threshold. The reporting duty is independent of the audit opinion.

Does the Digital Assets Framework change how SMSF crypto is audited?

The SIS Act obligations the auditor tests do not change when the Framework commences on 9 April 2027.[8] Separation, sole purpose, valuation, and record-keeping continue to apply. What should improve over time is the quality of custody and reporting records produced by Framework-licensed platforms, which makes the audit evidence easier to assemble and verify.

What is the most common reason a crypto holding fails an SMSF audit?

In practice it is an inability to evidence separation, often because the assets sit in a member’s personal exchange account or in a wallet whose keys are held in a member’s name. The second most common is a 30 June valuation with no documented source. Both are file problems rather than judgment calls, which means both are avoidable with records built for the audit.[4][5]

Where to start

Alpha Node is the regulated digital asset infrastructure layer Australian advice practices and SMSF trustees use for execution, custody, and audit-ready reporting, so the records that reach an auditor are complete from the start. Alpha Node produces those records for the trustee and adviser and does not act as the fund’s auditor or influence the audit opinion.[9]

If you advise SMSF trustees holding digital assets and want their files to stand up to an independent audit, the appropriate next step is a conversation.

Explore the SMSF Partnership pathway →

Sources

  1. Superannuation Industry (Supervision) Act 1993 (Cth) s 35C, requirement to appoint an approved SMSF auditor and conduct an annual audit of the fund’s financial statements and compliance with the Act and regulations. https://www.legislation.gov.au/C2004A04633/latest/text ↩
  2. Superannuation Industry (Supervision) Act 1993 (Cth) s 62, sole purpose test: an SMSF must be maintained for the purpose of providing retirement benefits to members. https://www.legislation.gov.au/C2004A04633/latest/text ↩
  3. Superannuation Industry (Supervision) Act 1993 (Cth) ss 71 and 82, in-house asset rules capping related-party investments, loans, and leases at 5% of total fund assets. https://www.legislation.gov.au/C2004A04633/latest/text ↩
  4. Superannuation Industry (Supervision) Act 1993 (Cth) s 52B(2)(d) (trustee covenants to keep fund assets separate from personal assets); separation-of-assets operating standard in the Superannuation Industry (Supervision) Regulations 1994 (Cth), reg 4.09A; ATO “SMSFs and crypto assets” guidance on asset separation. https://www.legislation.gov.au/C2004A04633/latest/text ↩
  5. Australian Taxation Office, “SMSFs and crypto assets”, guidance on the sole purpose test, separation of assets, market-value valuation at 30 June, and documentation of acquisitions and disposals. The ATO position is the regulator’s position as published and is subject to change. https://www.ato.gov.au/individuals-and-families/investments-and-assets/crypto-asset-investments ↩
  6. Australian Taxation Office, Auditor/Actuary Contravention Report (ACR) requirements and reporting criteria for approved SMSF auditors. https://www.ato.gov.au/tax-and-super-professionals/for-superannuation-professionals/smsf-auditors ↩
  7. Australian Taxation Office, SMSF Quarterly Statistical Report, June 2025: SMSFs held approximately AUD 3.02 billion in digital assets at 30 June 2025, across 653,062 funds with total assets of approximately AUD 1.05 trillion. https://www.ato.gov.au/about-ato/research-and-statistics/in-detail/super-statistics/smsf/self-managed-super-fund-quarterly-statistical-report ↩
  8. ASIC, “ASIC’s roadmap for digital assets law reform implementation”, 20 April 2026. The Digital Assets Framework commences on 9 April 2027, introducing the digital asset platform (DAP) and tokenised custody platform (TCP) categories. https://www.asic.gov.au/about-asic/news-centre/news-items/asic-s-roadmap-for-digital-assets-law-reform-implementation/ ↩
  9. Alpha Node Global, regulatory authorisations. Alpha Node X Pty Ltd (ACN 689 717 422; AUSTRAC VASP 100903039); Alpha Node Capital Pty Ltd (ACN 603 150 634; AFSL 479974; AUSTRAC VASP 100612840-001), wholesale clients only; Alpha Node Capital Management Pty Ltd (ACN 675 404 047; CAR 1308193 of Alpha Node Capital; AUSTRAC VASP 100895147-001); Alpha Node Advisors Pty Ltd (ACN 154 320 000; AFSL 416956; AUSTRAC VASP 100282425-001), wholesale clients only; Alpha Node Finance Pty Ltd (ACN 675 410 116; Credit Representative 556504 of Fair Loans Foundation Pty Ltd, ACL 378968). https://alphanode.global/regulatory/ ↩