Proof of reserves is a transparency practice used to show that an organisation holds assets matching customer or reported liabilities. It is meant to improve confidence in solvency and custody integrity. For practitioners, the value depends on the quality of underlying records, internal controls, and the completeness of what is included in the calculation.
What Proof of Reserves Actually Demonstrates
Proof of reserves is not a full solvency audit. It is a transparency claim about whether reported assets appear to cover reported liabilities at a point in time, based on the records and scope used in the calculation.
The key limitation is scope. A reserve attestation may cover only certain wallets, entities, or account balances, while liabilities can change quickly and may sit outside the disclosed perimeter. That means the question is less “does the organisation have assets?” and more “what exactly was measured, and under what controls?”
How Proof of Reserves Is Built and Verified
Most proof of reserves exercises depend on two sides of the same reconciliation: asset evidence and liability evidence. Asset evidence may come from on-chain holdings, custodian records, or bank and treasury records, while liability evidence depends on complete customer balances, ledger integrity, and a clear cutoff date.
Verification quality improves when the methodology is explicit, the data sources are independent, and the organisation can show that liabilities were not omitted or netted away in a misleading way. Techniques such as attestations, cryptographic commitments, and independent review can strengthen confidence, but none of them is meaningful if the underlying records are incomplete.
Why Proof of Reserves Matters for Trust and Transparency
For users, counterparties, and regulators, proof of reserves is mainly a confidence signal. It helps answer whether the organisation appears to be holding enough assets to meet the obligations it says it has taken on, which is especially important where custody, client funds, or redemption promises are involved.
That signal is useful, but it should be interpreted carefully. A reserve proof can reduce information asymmetry, yet it does not by itself prove liquidity, future resilience, operational soundness, or absence of other obligations. It is one input into trust, not a complete trust model.
Common Failure Modes and What They Mean
Proof of reserves breaks down when the evidence is stale, the liability population is incomplete, the valuation is misleading, or the controls around the reconciliation are weak. The result can be a report that looks reassuring while missing material exposures.
It can also be weakened by selective disclosure, off-balance-sheet obligations, rehypothecation, or asset transfer timing that makes the snapshot look stronger than the ongoing reality. In that sense, the integrity of the method matters as much as the headline ratio.
Risk and Threat Considerations
Proof of reserves creates a false sense of safety when organisations treat a snapshot as a substitute for continuous solvency, custody control, or liquidity management. The main risk is not the disclosure itself, but the possibility that the disclosure is incomplete, outdated, or structured to overstate apparent coverage.
Failure mechanism: Weak reconciliation controls, excluded liabilities, stale asset evidence, or manipulated cutoff timing can let an organisation publish a reserve position that does not reflect the real exposure.
Impact: Customers, counterparties, and supervisors may rely on an inflated picture of solvency, increasing the chance of run dynamics, reputational damage, contractual loss, or delayed intervention after stress emerges.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Proof of reserves depends on reconciling records and reviewing evidence quality. |
| AC-1 — Access Control Policy and Procedures | Custody integrity relies on governed control ownership and documented procedures. | |
| CM-8 — System Component Inventory | Reserve proofs require a complete asset population and bounded scope. | |
| Recommendation — Review reconciliation evidence for completeness, anomalies, and cutoff integrity. Define ownership and procedures for reserve reporting and asset-liability reconciliation. Maintain a complete inventory of assets and entities included in reserve calculations. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | Reserve evidence depends on knowing which assets and records are in scope. |
| A.5.33 — Protection of records | The credibility of a reserve proof depends on protecting the integrity of records used. | |
| Recommendation — Keep an accurate inventory of in-scope assets, accounts, and supporting records. Protect ledger, custody, and liability records from tampering and unauthorized change. | ||
Practitioner Guidance
Why practitioners should care: A proof-of-reserves programme is only as credible as the control environment behind it. If the underlying ledger, custody, and liability records are not tightly governed, the disclosure becomes a communications exercise rather than a control.
Common misunderstanding: Many teams over-read the result as a certificate of safety. Practitioners should treat it as a bounded assertion about a specific date, scope, and methodology, then make sure those boundaries are plainly disclosed.
Practitioner takeaway: The strongest proof of reserves is the one that is narrow, auditable, and honest about what it does not prove.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org