ADGM Proof of Reserves Requirements: A Guide for Crypto Custodians

For crypto and virtual asset custodians in Abu Dhabi Global Market (ADGM), proof of reserves is not a rule. It is a supervisory expectation that sits on top of a demanding custody regime: segregated client assets, weekly reconciliations with senior sign-off, and an annual report from your auditor, the Safe Custody Auditor’s Report. FSRA guidance says independent proof of reserves verification should be carried out at least annually. In this article, we set out what the rules require, what the FSRA expects, and who can do the work.

What ADGM Requires: FSRA Crypto Custody Rules

The core obligation is COBS 17.8, which applies the Safe Custody Rules in COBS Chapter 15, and the Resolution Pack rules in Chapter 16, to any firm Providing Custody of virtual assets or Fiat-Referenced Tokens (COBS 17.8.1). FSRA guidance confirms this covers exchanges and other intermediaries that hold client virtual assets, not only dedicated custodians (Guidance, para 144). COBS is the Conduct of Business Rulebook of the Financial Services Regulatory Authority (FSRA), ADGM’s financial services regulator. A virtual asset service provider operating onshore in Abu Dhabi, outside ADGM, is licensed by the federal Capital Market Authority instead, and none of this applies to it.

Those rules, together with the audit rules in GEN, protect client assets in four ways, and FSRA guidance adds a fifth:

  • Segregation. Client assets must be recorded, registered and held separately from the firm’s own (COBS 15.3.2), in a Client Account (COBS 15.4.1), and cannot be used for the firm’s or anyone else’s purposes without the client’s prior written permission (COBS 15.4.4).

  • Weekly reconciliations. All three reconciliations in COBS 15.9.1 (your records against custodian statements, a count of the assets you hold, and each client’s ledger balance against your records) must be carried out at least every week for virtual assets, which overrides the monthly and six-monthly defaults in COBS 15.9.1 (COBS 17.8.3(b)).

  • Monthly client statements. Retail Clients must receive a statement of their assets at least monthly, rather than the six-monthly default in COBS 15.8.1(a) (COBS 17.8.3(a)). Professional Clients receive them at intervals agreed in writing (COBS 15.8.1(b)), and each statement must be prepared within one calendar month of its date (COBS 15.8.3).

  • An annual Safe Custody Auditor’s Report. You must arrange for your auditor to produce a Safe Custody Auditor’s Report, submitted to the FSRA each year within four months of your financial year end (GEN 6.6.1(4) and GEN 6.6.2).

  • Annual independent verification (FSRA guidance). An independent third party should check at least annually that the amount and value of the Accepted Virtual Assets you hold in custody for clients is correct and matches what you are supposed to hold (Guidance, para 158). This is guidance, not a rule, and is covered in more detail below.

In effect, every client asset must be there in full: it is the client’s property, held separately, not used without the client’s prior written permission, and reconciled weekly against client balances. On top of that, the FSRA guidance expects annual independent verification that those holdings are all there (para 158). That is, in substance, a proof of reserves engagement, and it is the clearest way to show the FSRA, your counterparties and your clients that every client asset is accounted for.

You may only provide custody of Accepted Virtual Assets (COBS 17.2.1), meaning assets you have assessed against the criteria in COBS 17.2 and notified to the FSRA. Client Fiat-Referenced Tokens held in custody follow the same custody rules (COBS 17.8.1), and only Accepted Fiat-Referenced Tokens may be used (COBS 17.2A.1). Tokenized securities are not virtual assets, so the weekly frequency in COBS 17 does not apply to them; their custody follows COBS Chapter 15 on its standard terms. Your client ledgers and master list of Client Accounts (COBS 15.4.3) define the population a reserves engagement will test, and your published list of Accepted Virtual Assets (COBS 17.2.6) sets its outer boundary.

Weekly Reconciliation Requirements Under COBS 15.9 and 17.8.3

COBS 15.9.1 sets out three reconciliations. On its own it sets minimum intervals of one month and six months, but for virtual assets COBS 17.8.3(b) requires all three at least weekly. Only a guidance note under COBS 15.9.6 points to this, so it is easy to miss if you read Chapter 15 alone.

What gets reconciledVirtual assetsChapter 15 default
(a) Your records against statements from the third-party custodian holding the assetsWeeklyMonthly
(b) A count of the assets you hold yourself, against your own recordsWeeklyEvery 6 months
(c) Each client’s ledger balance against your record of what sits in client accountsWeeklyEvery 6 months

Each reconciliation does a different job. (a) is the only one that relies on a statement from a third party. (b) is the existence check, which for virtual assets in practice means the wallet or on-chain count. (c) ties each client’s entitlement to your records. For assets you hold yourself, (b) and (c) together are your internal check that you are fully reserved, because what you hold must match your records and your records must match what clients are owed; for assets with a third-party custodian, (a) and (c) do that job. You perform them yourself, though, so they are not independent verification.

If your assets sit with a third-party custodian, check how often it sends you statements. You must reconcile weekly, but the rule text for reconciliation (a) still refers to monthly statements, and many custodians send only monthly statements unless you ask for more. You control this: before passing assets to a custodian you must obtain its written acknowledgement, which must state how often it will send statements (COBS 15.6.1(e)). Many institutional custodians also offer real-time reporting through a portal or API, so the fix is usually simple: specify at least weekly statements in the acknowledgement, or a feed that produces a statement you can retain as at your cut-off. The harder part is timing: a live feed is only useful if it gives you balances at the same cut-off as the rest of the reconciliation. Agree a fixed cut-off (a set UTC time, mapped to the corresponding block height on each chain) so the custodian’s figure, your own wallet count and your client ledgers are all taken at the same moment.

The controls around the reconciliations are detailed and testable:

  • the process must not create a conflict of interest (COBS 15.9.2);

  • the reconciliation cannot be performed by anyone who operates Client Accounts or has authority over the assets, which requires a clear separation of duties (COBS 15.9.3). In practice that means staff with no role in operating Client Accounts and no authority over the assets, often in a separate finance or control function;

  • each reconciliation must be reviewed by someone of adequate seniority, who provides a written statement confirming it was done in accordance with the rules (COBS 15.9.4 and 15.9.5); and

  • unrectified material discrepancies must be notified to the FSRA without undue delay, and FSRA guidance counts discrepancies that are material cumulatively, such as longstanding ones (COBS 15.9.6).

That means a written statement for every weekly reconciliation, so at least fifty-two sets a year. If you also hold or control client money, the COBS 14.11.1 reconciliation must also be done at least weekly, and the COBS 14.11.4 reconciliation within five days of the date it relates to (COBS 17.9.1).

The Safe Custody Auditor’s Report

GEN 6.6.7 sets out what your auditor must state, as at the date of your audited statement of financial position (normally your financial year end, the same date as your audited financial statements; the controls statement covers the whole year):

  • the scope of your custody business, meaning the extent to which you were holding and controlling Client Investments, Arranging Custody or Providing Custody;

  • whether you maintained systems and controls throughout the year to comply with the Safe Custody Rules;

  • whether the Safe Custody Assets are registered, recorded or held in accordance with those rules;

  • whether there have been any material discrepancies in the reconciliation of Safe Custody Assets; and

  • whether any of the Safe Custody requirements have not been met, and whether the auditor received all the information and explanations it needed.

This is a compliance and internal controls report on your client asset arrangements, not a reserves opinion. The auditor reports on your controls, on whether client assets are held in line with the rules and on reconciliation discrepancies. Unlike the Client Money Auditor’s Report, it does not state whether you held the appropriate amount, so a shortfall would surface only indirectly, as a discrepancy or a breach. That question is the one FSRA guidance expects an independent third party to answer (see below). COBS 17.1.3 is what brings virtual assets into scope, by reading “Client Investments” in GEN as including them. If you also hold client money, a separate Client Money Auditor’s Report states how much you held and whether it was the appropriate amount (GEN 6.6.6).

Only your appointed auditor can produce this report (GEN 6.6.1(4), GEN 6.4.1). In practice, for an ADGM-incorporated firm that is its statutory auditor, which must be an ADGM Registered Auditor holding an FI Audit Permit, so a separate reserves practitioner cannot sign it. “Who Can Perform Proof of Reserves in ADGM?” below sets out the detail.

FSRA Guidance: Annual Independent Proof of Reserves Verification

The rulebook is not the whole picture. The FSRA’s Guidance on the Regulation of Virtual Asset Activities in ADGM contains the closest thing ADGM has to a proof of reserves requirement for custodians. Under the heading “Third party audit obligations”, paragraph 158 says:

Authorised Persons should have independent third party verification or checks carried out at least annually to verify that the amount and value of Accepted Virtual Assets held on custody on behalf of Clients is correct and matches what the Virtual Asset Custodian is supposed to hold.

Paragraph 61, addressed to all Authorised Persons, makes a related point: it asks for at least annual third-party verification or audit of core systems, including, where relevant, of custody arrangements and “purported holdings of Virtual Assets and Client Money”.

That is exactly the question a reserves engagement answers, but the verb is “should” and it sits in guidance, not a rule. The same guidance says custodians “must not” allow sole-signatory arrangements (para 153), and the contrast suggests the FSRA treats independent verification as an expectation rather than a requirement.

Do not read “should” as “ignore”. It is a published supervisory expectation, and a firm that chooses not to follow it should expect to explain why if the FSRA asks. In practice the commercial pressure usually arrives first: counterparties, exchanges, banking partners and institutional clients ask for reserves verification regardless of what the rulebook says.

What an ADGM Proof of Reserves Engagement Covers

Beyond the reconciliations, one area shapes how a reserves engagement is scoped and what evidence it needs: demonstrating control of the assets.

Proving Existence and Control of Crypto Assets

A proof of reserves engagement has to establish two things about the assets: that they exist, and that you control them on your clients’ behalf. Querying each blockchain address for its balance at the agreed cut-off time settles the first. For assets with a third-party custodian, which may sit in the custodian’s omnibus wallets, existence evidence usually comes from the custodian’s statement or a direct confirmation. The second comes from your key management setup and your ability to demonstrate control, through account ownership, send-to-self transactions or digital signatures. COBS 17.5.1 requires documented wallet and key management controls, and those are the evidence a practitioner may use to support your position on control.

Your custody model decides where the evidence comes from. The FSRA recognizes three (Guidance, para 148): in-house wallets, where you hold the keys; outsourced wallets, where a third-party custodian holds them but you keep full regulatory responsibility; and self-custody, where clients hold their own keys and you are generally not Providing Custody at all. Before using a third-party custodian you must assess it and conclude on reasonable grounds that it is suitable, keep it under review and ensure equivalent protections (COBS 15.5.1), and you remain fully responsible for it (Guidance, para 157).

What is not prescribed is which of those methods you use to demonstrate control to a practitioner. Agree it before fieldwork.

Who Can Perform Proof of Reserves in ADGM?

The guidance asks only for “independent third party verification or checks” (para 158). It names no qualification, no approved list and no location requirement, and it does not reserve the work to your appointed auditor. A qualified, independent practitioner, including a US CPA firm, appears to be allowed to perform it.

That is different from the Safe Custody Auditor’s Report, which must come from your appointed auditor (GEN 6.6.1(4)). In practice, for an ADGM-incorporated firm that is its statutory auditor, which must be an ADGM Registered Auditor (Companies Regulations 2020, section 1032) holding an FI Audit Permit to audit a financial institution (Companies Regulations (Auditors) Rules 2025(A), Rule 13). On its terms, that regime governs auditors appointed under Part 15 of the Companies Regulations (section 1031), and it does not appear to extend to voluntary attestation work.

Which Assurance Standard Applies to ADGM Proof of Reserves?

Nothing in the ADGM rules or guidance names an engagement standard, whether ISAE 3000 (Revised), ISRS 4400 (Revised) or the AT-C series. For custodians, para 158 states the subject matter but not detailed criteria. The choice between agreed-upon procedures and an assurance engagement rests with you and your practitioner, and the criteria have to be built and agreed. Note that an agreed-upon procedures report expresses no conclusion, so consider whether it meets para 158’s language about verifying that holdings are correct. If the report will be shared with the FSRA, expect it to scrutinize the criteria.

Settle this at scoping, not during fieldwork. Because the reconciliations run weekly, an engagement covering a period will often need to address the reconciliations carried out throughout it, not just a period-end position. For a first engagement, scoping is often the most labor-intensive phase.

Proof of Reserves for ADGM Stablecoin (Fiat-Referenced Token) Issuers

Issuers of Fiat-Referenced Tokens, ADGM’s regulated fiat-backed stablecoins, are the one place ADGM does have a full reserves regime, in COBS Chapter 19A:

  • Reserves at all times. The market value of reserve assets must equal or exceed all outstanding redemption claims (COBS 19A.7.1), with a valuation at the end of every day (COBS 19A.7.2) and immediate notification to the FSRA of any actual or suspected shortfall (COBS 19A.7.3).

  • Monthly attestation. An independent third party, to whose appointment you have received the FSRA’s written non-objection, must attest each month, at the end of the period and on one randomly selected day, to the reserves held, the tokens outstanding, whether reserves at least equal the redemption value, and whether proceeds are held in qualifying form (COBS 19A.9.1). The rule does not necessarily require an ADGM Registered Auditor, so a non-ADGM firm, including a US firm, could be appointed, subject to the FSRA’s written non-objection. The attestation is published on your website and sent to the FSRA by the end of the following month (COBS 19A.9.2).

  • Annual audit. An independent external auditor approved by the FSRA (the rule’s test is FSRA approval and it does not mention ADGM registration, so a US firm may be possible; confirm with the FSRA) must audit the composition and valuation of reserve investments and the related controls each year, reporting within four months of year end (COBS 19A.10).

  • Stress testing. At least annually, or more often if the FSRA notifies you in writing, with a written summary to the FSRA on completion (COBS 19A.8).

For an fiat-referenced token issuer, several Chapter 15 rules described above, including client statements (15.8), reconciliations (15.9) and use of client assets (15.4.4), do not apply, and “Client Account” is read as “Reserve Account” (COBS 19A.5.1). If you also hold other client assets, confirm with the FSRA how this applies. If you issue a Fiat-Referenced Token, these are the rules your proof of reserves work is built around.

How to Prepare for an ADGM Proof of Reserves Engagement

Whether the request comes from the FSRA, a counterparty, an exchange or your own board, a proof of reserves engagement goes faster when three things are ready before fieldwork:

  • A clean reconciliation record. Weekly reconciliations for the whole period, dated and signed off, with custodian statements, wallet counts and client ledgers all taken at the same cut-off time.

  • A defined asset population. Your client ledgers and master list of Client Accounts (COBS 15.4.3), checked against your published list of Accepted Virtual Assets (COBS 17.2.6), with every wallet address mapped to them.

  • Agreed evidence of control. A documented method for proving control of every address (account ownership, send-to-self transactions or digital signatures), settled with your practitioner before fieldwork starts.

The absence of a separate reserves rule for ADGM custodians is not an absence of obligation. The weekly reconciliations, the separation of duties, the signed reviews and the annual auditor’s report are a demanding regime by any standard. What they do not do is answer the question a proof of reserves engagement answers. The FSRA expects that question to be answered by an independent third party at least annually, and counterparties, exchanges and your own board often ask for it too.

Rules referenced are current as of October 2026 (COBS VER24.160926, GEN VER15.160926; FSRA Guidance on the Regulation of Virtual Asset Activities in ADGM, 10 June 2025). This article is for general information and is not legal or regulatory advice.

How The Network Firm Can Help

We support ADGM custodians across their whole proof of reserves program:

  • Reconciliation processes. Designing and implementing weekly reconciliation processes that meet COBS 15.9 and 17.8.3, with aligned cut-off times and documented senior sign-off.

  • Key management and reconciliation controls. Reviewing and strengthening wallet, key management and reconciliation controls so they can be evidenced to a practitioner and to the FSRA.

  • Proof of reserves engagements. Independent third-party reporting covering the assets you hold match what you owe your clients, in line with the FSRA’s guidance.

The Network Firm is the leading proof of reserves provider in the world, performing proof of reserves attestations for exchanges, custodians and token issuers. We have served exchanges since our inception, with experience dating back to 2020, when our team performed the first-ever CPA-assisted proof of reserves. Talk to a TNF expert or explore our Proof of Reserves services. For a comprehensive overview of Proof of Reserves, download The Practitioner’s Guide to Proof of Reserves and subscribe to The Network Firm YouTube Channel.

Related reading: The Power of Proof of Reserves · Common Pitfalls in Stablecoin Proof of Reserves Audits · Where Smart Contracts End and Proof of Reserves Begins

Author Bio:
Jericho Sarmiento is a Staff Auditor at The Network Firm, where he supports audit and attestation engagements involving digital assets and blockchain-based financial systems. He is a Certified Public Accountant (CPA) with a strong foundation in accounting and assurance.

Jericho brings over five years of professional experience, including one year focused on crypto and digital assets. He has assisted in audit and attestation engagements across industry participants such as exchanges, custodians, and stablecoin issuers. His work includes supporting stablecoin attestations, Proof of Reserves (PoR) procedures, crypto asset verification, and the preparation of detailed audit documentation and workpapers in accordance with evolving assurance standards.

In addition to his professional work, Jericho independently researches smart contract security, focusing on understanding protocol mechanics and analyzing logical behaviors and potential security risks.

Connect with Jericho on LinkedIn for more expert advice

Next
Next

VARA Proof of Reserves Requirements: A Guide for Dubai VASPs