IIA Wants Mandatory Internal Audits for US Crypto Exchanges

The Institute of Internal Auditors said it wants an independent internal audit function at all US crypto exchanges to restore investor confidence in the industry


chase4concept/Shutterstock modified by Blockworks


The Institute of Internal Auditors sent a letter to Congress Thursday recommending that all US crypto exchanges have an independent “internal audit function.”

Inside were four separate legislative proposals that will “promote stronger corporate governance, greater transparency and accountability, and enhanced investor protections at cryptocurrency exchanges operating in the United States,” according to the May 4 letter written by Anthony Pugliese, president and CEO of the IIA.

The second proposal defines an internal audit function as “a professional individual or group…responsible for providing the board of directors and management with…: objective assurance over the covered entity’s internal controls; consulting services; and strategic advice on risk mitigation.”

Additionally, the second proposal stipulates that the internal audit function will be independent from management.

The third proposal mandates the establishment of this internal audit function for all US crypto exchanges. The leader of the function will also be responsible for briefing a crypto exchange’s board on “material risks” no less than twice a year.

This IIA previously sent a letter to Congress in December following the collapse of FTX to begin a dialogue with lawmakers and “help shape their policy recommendations” amid the crypto winter. 

“The IIA conducted numerous meetings with congressional staff and external stakeholders to determine the appropriate role that internal audit could serve in potential policy solutions that Congress might consider regarding the lack of sufficient investor protections and corporate governance safeguards at cryptocurrency exchanges,” Pugliese wrote in the May 4 letter.

The final proposal that was attached to the IIA letter suggested that lawmakers create an annual auditing report that the management staff of crypto exchanges must fill out and send to whichever regulatory authorities Congress deems appropriate. Management would also have to have evaluated the effectiveness of the company’s internal controls 90 days prior to submitting the report. 

Pugliese closed out his message to lawmakers telling them that these guidelines could bolster investor confidence in a sector that’s been hammered by numerous shady actors.

“The IIA believes inclusion of new internal audit requirements will, in part, promote transparency and accountability designed to restore investor confidence in the cryptocurrency market,” he wrote.

Get the day’s top crypto news and insights delivered to your email every evening. Subscribe to Blockworks’ free newsletter now.

Want alpha sent directly to your inbox? Get degen trade ideas, governance updates, token performance, can’t-miss tweets and more from Blockworks Research’s Daily Debrief.

Can’t wait? Get our news the fastest way possible. Join us on Telegram and follow us on Google News.


upcoming event

MON - WED, MARCH 18 - 20, 2024

Digital Asset Summit (DAS) is returning March 2024. This year’s event will be held in our nation’s capital, where industry leaders, policymakers, and institutional experts will come together to discuss the latest developments and challenges in the ever-evolving world of cryptocurrency. […]

upcoming event

MON - WED, SEPT. 11 - 13, 2023

2022 was a meme.Skeptics danced, believers believed.Eventually, newcomers turned away, drained of liquidity and hope.Now, the tide is shifting and it’s time to rebuild. Permissionless II is the brainchild of Blockworks and Bankless. It’s not just a conference, but a call […]

recent research

Cosmos Hub: ATOM Economic Zone


Replicated Security, the Hub’s Validation-as-a-Service offering that went live in March, is the first step in bringing value accrual to ATOM stakers.



OP holders might not be feeling very optimistic with the rollup’s token unlock schedule now in effect


Two lords are pushing for the government to ensure that the Bank of England could not implement “Britcoin” without legislative backing


This is the second fee switch proposal that failed to pass a community vote


This partnership comes as Nike released its first NFT collection, Our Force 1, this month


The weaknesses of large language models like ChatGPT are “too great to use reliably for security,” OpenZeppelin’s machine learning lead says


Giddy will now enable users to spend their yield on real-world goods and services