Valucrest

Maximize Your Business Potential

BTC for Company Treasuries – Part 5

Key Ceremonies, Wallet Tiers, and Why Auditors Care

Last week we looked at custody choices and how to evaluate providers with a structured due diligence scorecard. This week, we move into the nuts and bolts of operating a Bitcoin treasury:

How are keys generated, who holds them, and how are wallets structured?”


My Pilot Reality

In my small company, I’ve kept it simple for now:

  • A 2-of-3 multisig wallet, with offline backup.
  • I ran test transactions to ensure all signatures worked as intended.
  • I have a written log of each step (screenshots + addresses), so I have audit evidence if ever required. (Obviously never keep screenshots of your 24-word passphrase)

This is enough for a pilot, but in larger companies, the expectations (from boards, auditors, and regulators) are much higher.


Wallet Architecture for Companies

A mature treasury usually defines tiers of wallets to separate operational needs from long-term reserves and balance accessibility against security:

  • Cold Wallet (Treasury Reserve):
    • Multisig setup.
    • Rarely accessed.
    • Keys geographically distributed.
    • Used for strategic allocation, not daily spending.
  • Warm Wallet (Operational Treasury):
    • Lower thresholds.
    • Quicker access for liquidity needs (e.g., vendor payments in BTC).
    • Still requires multi-approver flow.
  • Hot Wallet (Receipts & Testing):
    • Minimal balances.
    • Used for small incoming/outgoing transactions.
    • Treated as “operational change” money, not part of reserves.

This tiered model mirrors traditional finance (think: vault vs current account vs petty cash).


Key Ceremonies: More Than Just Generating a Seed

A corporate-grade key ceremony goes beyond creating a wallet, it becomes a documented governance event.

Best practice includes:

  • Witnessed generation: Participants include finance leads, compliance officers, or even an auditor.
  • Secure handling: Seed phrases sealed, no digital copies.
  • Audit records: Addresses, test transactions, approvals logged.
  • Rotation protocols: Keys rotated if holders leave or at scheduled intervals.

Emerging practice among larger institutions also includes:

  • Cryptographic proofs: Publishing ceremony transcripts, checksums, or hashes to confirm authenticity.
  • Device details: Recording hardware wallet serial numbers and firmware versions.
  • Direct transaction evidence: Signed test transactions stored as audit artifacts.

This might sound heavy-handed for a startup. But auditors love it, regulators see it as serious and investors view it as professional.


Why This Matters for Compliance

Corporate governance and regulatory frameworks now directly touch on digital asset custody. Here are the key references:

  • King IV™ (South Africa):
    • Principle 12: Governing body should govern technology and information in support of strategy.
    • Principle 15: Governing body should ensure fair and responsible safeguarding of assets (including digital).
  • IFRS & Audit Standards:
    • IFRS 9 (Financial Instruments): Guides classification and disclosure of crypto assets.
    • ISA 500 (Audit Evidence): Requires sufficient, appropriate evidence, meaning companies must show secure custody with verifiable records.
  • FSCA (South Africa):
    • Conduct Standard 3 of 2025: Requires asset managers to safeguard client assets with documented operational controls. While treasuries aren’t FSPs, mirroring this standard signals regulator-grade governance.
    • FICA obligations: Where relevant, companies must integrate AML/KYC and transaction monitoring.
  • MiCA (EU): Requires crypto-asset service providers to maintain robust internal controls, segregate assets, and ensure operational resilience.
  • FCA (UK): Expects operational resilience and record-keeping for firms handling crypto assets, including procedures for custody and disaster recovery.

Together, these frameworks show why wallet governance isn’t just technical, it’s compliance-critical.

In other words: your custody is only as credible as your documentation of the ceremony and wallet architecture.


This Week’s Artifact: Key Ceremony SOP

I’ve created a Key Ceremony SOP Template you can adapt for your company. It covers:

  • Participants & ceremony overview.
  • Wallet tier architecture.
  • Key generation, storage, and backup.
  • Signing & verification steps.
  • Audit evidence (addresses, TXIDs, device info, firmware versions).
  • Rotation & contingency procedures.
  • Compliance references.

📄 Download the Key Ceremony SOP Template


Next Week

We’ll zoom out again and build a Compliance Register, mapping all regulatory touch points (FSCA in South Africa, MiCA in the EU, FCA in the UK), so you know which obligations can apply.


🔗 This is Part 5 of the Bitcoin Treasury Series. Find the full archive here.