The word "audited" appears in nearly every stablecoin press release, news article, and marketing page. Tether has been "audited." Circle's reserves are "audited." FDUSD is "audited."
Almost none of these statements are accurate. And the imprecision is not harmless.
What an Audit Actually Is
An audit is an engagement performed under Generally Accepted Auditing Standards (GAAS) — in the U.S., that means AICPA AU-C standards or PCAOB standards for public companies. The practitioner examines historical financial statements in their entirety: the balance sheet, income statement, cash flow statement, and notes. The opinion covers whether those financial statements, taken as a whole, are presented fairly in accordance with GAAP.
An audit is comprehensive. It covers the entity's entire financial position, not a single assertion about a single asset class on a single date.
The only stablecoin issuer that has ever been subject to a full financial statement audit by a major firm is Circle, whose fiscal year financial statements are audited by Deloitte. And that audit covers Circle the company — not USDC the token.
What Stablecoin "Attestations" Actually Are
What stablecoin issuers publish are attestation engagements — a fundamentally different category of assurance. The three types, in descending order of assurance:
Examination (AT-C 205): The highest level. The practitioner obtains sufficient evidence to express an opinion on whether a specific assertion is fairly stated. Circle's monthly USDC reports are examinations: Deloitte opines that management's assertion about reserve balances is fairly stated, in all material respects, as of a specific date. KPMG performs the same engagement for Paxos (PYUSD, USDP). BPM LLP does it for Gemini (GUSD).
Review (AT-C 210): Limited assurance. The practitioner performs inquiry and analytical procedures — substantially less work than an examination — and states the conclusion in the negative: "Nothing came to our attention that caused us to believe the assertion is materially misstated." Less work, less assurance, lower cost.
Agreed-Upon Procedures (AT-C 215): No assurance at all. The practitioner performs specific procedures agreed to by the engaging party and reports the factual findings. No opinion. No conclusion. This is what BDO Italia performs for Tether — an ISAE 3000 engagement that reports findings without expressing a conclusion on the assertions.
The gap between "Deloitte examined Circle's reserves" and "BDO performed agreed-upon procedures on Tether's reserves" is enormous in professional terms. Both get reported as "audited."
Why the Distinction Matters Now
The GENIUS Act — the first federal regulatory framework for payment stablecoins — makes this distinction statutory. The Act requires examination-level attestation of reserve disclosures, performed by a PCAOB-registered public accounting firm, published monthly.
That is a specific, high bar:
- Examination, not review or AUP
- PCAOB-registered, not just any CPA firm
- Monthly, not quarterly or annual
Look at the current landscape through this lens:
Circle (USDC): Monthly examination by Deloitte (PCAOB-registered). Already meets the expected GENIUS standard. The Reserve Attestation Registry tracks ten months of these reports.
Tether (USDT): Quarterly agreed-upon procedures by BDO Italia (not PCAOB-registered). Three gaps: the engagement type is AUP not examination, the cadence is quarterly not monthly, and the practitioner is not PCAOB-registered. Tether has engaged KPMG for its first-ever full financial statement audit — but that's an audit of the company, not a monthly reserve examination.
Paxos (PYUSD, USDP, USDG): Monthly examination by KPMG (PCAOB-registered). Meets the expected standard.
Ripple (RLUSD): Monthly examination by Deloitte (PCAOB-registered). Meets the expected standard.
Gemini (GUSD): Monthly examination by BPM LLP (PCAOB-registered). Meets the expected standard.
First Digital (FDUSD): Monthly examination by Prescient Assurance (not PCAOB-registered as far as publicly documented). Meets the examination and cadence requirements; PCAOB registration is the question.
The issuers who use examinations are already positioned for GENIUS. The ones who use AUP or review engagements have work to do. And every news outlet that reports all of these as "audited" makes it harder for the market to see the difference.
What This Means for Practitioners
I perform AT-C 205 examinations professionally. The work is demanding. An examination requires the practitioner to plan the engagement, assess risks, obtain evidence, evaluate the reliability of management's assertions, and form an opinion. It is not a checklist exercise.
The GENIUS Act will create a step-function increase in demand for practitioners who can perform this work — monthly, at scale, for issuers holding billions in reserves. The supply of CPA firms with the expertise, the PCAOB registration, and the crypto-native infrastructure to do this is small. Deloitte, KPMG, and BPM are there. Most firms are not.
This is not a commentary on whether the GENIUS Act's requirements are correctly calibrated. It is a factual observation that the market for stablecoin examination practitioners is about to get significantly larger, and the distinction between examination, review, and AUP is about to become legally significant rather than merely professionally significant.
The Registry as Evidence
The Reserve Attestation Registry exists because no structured, citable source tracks these distinctions. When a journalist writes "Tether is audited," there is no reference they can check that says "actually, BDO performs agreed-upon procedures, not an examination, under ISAE 3000, not GAAS."
Every record in the registry captures the engagement type, the standard, and the practitioner. The data speaks for itself. The interpretation — what the GENIUS Act requires, how issuers compare, what the gaps mean — belongs in commentary. The facts belong in the registry.
The facts are now public. What you do with them is up to you.