What the Dual Audit Standard checks
The on-chain and off-chain audits paired by the question each one answers, and what neither one covers.
Why two audits
A tokenized asset has two failure surfaces. The contract can be wrong, and the thing behind the contract can be wrong. A code audit says nothing about whether the bills exist; a financial audit says nothing about whether the mint function is access controlled. The Dual Audit Standard requires both, from independent firms, with both reports published before the first token is minted.
The on-chain audit
The on-chain audit reads the deployed contract and its dependencies. It covers five areas. Contract code and access controls: who can mint, burn, pause and upgrade, and whether those roles are held by the right keys. Upgrade paths and reserve logic: whether the contract can change after deployment, under what process, and how it enforces that supply never exceeds verified reserves. Deployment verification: that the bytecode on CenterChain matches the audited source. Proof of reserve: that the attestation feed the contract reads is the one the auditor reviewed. Monitoring: which events are emitted and how anomalies are surfaced.
The off-chain audit
The off-chain audit reads the issuer and the assets. It pairs with the on-chain list. Financial statements: the issuer's audited accounts for the last period. Legal standing and authority to issue: that the entity exists, is in good standing, and has board and regulatory authority to issue the instrument. Custody arrangements: the custody agreement, account segregation and the custodian's own controls. Asset existence and valuation: that the bills or deposits are there, in the stated amounts, valued by the stated method. Sanctions and AML screening: that the issuer, its officers and its counterparties have been screened.
What the standard does not cover
The standard does not assess whether the asset is a good investment, does not predict the issuer's future solvency, and does not replace the holder's own eligibility and suitability checks. It is a statement about what was verified, by whom, and when. Each report carries its scope and its date, and the seal on an asset page derives its state from the presence of both dates.
How to read a report
Start with the scope paragraph, then the findings table. A finding marked resolved links to the commit or document that resolved it. Reports are published with their hash so that a copy can be checked against the original.1
- Hashes are SHA-256 of the published PDF; the copy button on the document list copies the hash. Back