Join our Newsletter — 33% off our NHI Course

When should organisations treat proof of reserves as a solvency signal rather than a full audit?

Organisations should treat proof of reserves as one input, not a complete solvency assessment. It can show that an exchange controls certain assets at a point in time, but it does not prove liabilities, off balance sheet obligations, or liquidity under stress. A full assessment still needs governance review, financial context, and independent assurance around liabilities and risk exposure.

When Proof of Reserves Is Only a Signal, Not a Solvency Verdict

proof of reserves is strongest when it answers a narrow question: can the organisation demonstrate control of specific assets at a point in time? It becomes a solvency signal when the reader is assessing asset existence, custody, and basic transparency. It should not be read as a full balance sheet view, because liabilities, encumbrances, and funding stress are outside that check.

That distinction matters because solvency is not just asset ownership. A firm can show reserves on-chain or through attestations and still face hidden debts, pledged collateral, or a maturity mismatch that weakens its ability to meet withdrawals. The right mental model is “verified reserves plus unverified obligations,” which is why solvency requires broader financial and governance evidence.

What a Reserve Check Can Show, and What It Cannot

A reserve check can confirm that assets exist, are accessible, and are being represented consistently at the time of the snapshot. For exchanges and custodial platforms, that is useful evidence of control, transparency, and some level of operational discipline. It also helps external parties compare what is being claimed against what can be independently observed.

What it cannot do is establish the full economic position of the organisation. It does not prove the completeness of liabilities, the status of off balance sheet commitments, or whether short term liquidity is sufficient under a run scenario. It also rarely tells you whether assets are rehypothecated, restricted, borrowed, or otherwise unavailable when pressure increases.

That is why proof of reserves should be treated as partial assurance. SOC 2 Trust Services Criteria (AICPA) is a useful comparison point here, because it reflects broader assurance thinking around controls, availability, and governance rather than a single point-in-time asset assertion.

What Changes the Answer from Transparency to Solvency

The question changes once the organisation is trying to infer whether the entity can survive obligations as they fall due. At that point, the important evidence is not only asset existence, but also liability measurement, liquidity profile, collateral terms, governance over treasury activity, and whether the statement can be independently reconciled to the rest of the financial picture.

In practice, the solvency question becomes meaningful when users need to know whether reserves are sufficient after obligations, operational drains, and stress conditions are considered. A reserve statement alone can support confidence in custody, but it cannot substitute for independent assurance over the wider balance sheet and the organisation’s funding model. That is why many readers should pair reserve evidence with broader audit-style review and governance checks.

This is also where assurance boundaries matter. If the organisation controls customer assets but does not disclose liabilities or encumbrances, the reserve figure may be accurate and still misleading in context. The signal is therefore valid, but incomplete: it helps answer “what assets are visible?” more than “is the firm solvent?”

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while SOC 2 (AICPA) and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
SOC 2 (AICPA) CC9.2 — Change Management Reserve attestations depend on controlled reporting and change integrity.
Recommendation — Require independently controlled reporting processes before relying on reserve disclosures.
ISO/IEC 27001:2022 A.5.33 — Protection of Records Reserve statements need records that preserve evidence of assets and obligations.
Recommendation — Protect and retain records that support reserve and liability verification.
NIST CSF 2.0 GV.OV-01 — Oversight of Risk Management Strategy Solvency interpretation requires governance oversight beyond a single asset snapshot.
Recommendation — Use oversight processes to require broader assurance before treating reserves as solvency proof.

Practitioner Guidance

What to verify: Treat proof of reserves as credible only when you can confirm the scope of the attestation, the timestamp, and whether the same assets are free of restriction or double counting. If liabilities are not independently measured, do not elevate the result to a solvency conclusion.

Decision rule: If you are assessing counterparty survival, creditor protection, or withdrawal resilience, require more than a reserve snapshot, including liability evidence and liquidity analysis. If you are only assessing custody transparency at a point in time, proof of reserves may be sufficient as one input.

Practitioner takeaway: The practical test is whether the evidence answers an asset question or a balance sheet question, because only the second one supports a true solvency judgment.