Published 03/01/2025 · Updated 08/09/2026 · Houssen Issouf Aly, French chartered accountant
Crypto-assets · Companies · Directors
Practical guidance for companies and directors. Revised on 7 September 2026.
Original article: 2025-01-03 · Houssen Issouf Aly · HODL Consulting
A company wallet belongs within an operating process: someone prepares the transaction, another person checks it, authorised signers approve it and the accounting team reconciles the movement with supporting records. Choosing a brand does not establish that chain of responsibility.
Start with the use cases: customer receipts, supplier payments, treasury holdings or protocol interactions. Separating uses can help control, but adding wallets without an inventory can create omissions. The process should remain understandable when a director or employee is unavailable.
For each account or address, record the legal owner, network, purpose, expected assets, authorised people, associated tools and last review date. Include the source of transaction history, account-opening evidence and links with bank accounts.
An address used on several networks still requires records for each network. Separate company, personal and third-party holdings even when the same individual operates them.
Do not put private keys or recovery phrases in the inventory shared with the accounting firm. Secret backup and recovery arrangements require a separate, appropriate process tested with competent people.
Authentication protects account access. Transaction approval also depends on the wallet and its permissions. French official cybersecurity guidance recommends two-factor authentication where available. Application permissions and signer rights still require review.
Safe’s confirmation threshold specifies how many signers must confirm a transaction. Its setup documentation makes the configuration dependent on the use case. Its spending-limit feature can allow certain transfers without the usual signer confirmations. Review modules and exceptions as well as the displayed threshold.
A technical threshold does not establish legal authority or internal spending policy. Check who can replace signers, add permissions and change settings. These examples illustrate questions to ask, not a universal product recommendation.
Fictional example: a €2,400 supplier invoice is prepared and approved by different people. Required signatures follow the actual configuration. After execution, accounting receives the invoice, payment evidence and fee records. €2,400 is an illustrative amount, not a recommended approval limit.
A staff departure should trigger a review of accounts, delegated authority, API keys, devices and signer roles. Check that removing access does not unexpectedly prevent necessary operations. Sensitive configuration changes deserve a defined approval process too.
Keep an incident plan identifying contacts, ways to suspend activity where available, records to preserve and relevant specialists. An internal form cannot make an irreversible transaction recoverable. Exercises should test the team’s ability to respond without exposing secrets.
At period end, reconcile quantities by asset and network. Separate payments, conversion, fees and transfers between wallets owned by the same company. An internal movement should not automatically be classified as new revenue.
Reconciliation uses exports, documents and read-only access where required. It does not require authority to transfer funds.
No. Exposure, use cases, available people and recovery arrangements determine the assessment. Technology does not remove human risk or the need to review permissions.
Bring the inventory and a complete example transaction. Our accounting support structures the records and reconciliations. Read the fractional CFO guide for the planning workflow and the freelance payments guide for the connection with invoices.