An audit of a digital-asset payout asks three questions: where did the value come from, who authorised it, and is there a record that shows both. If any of the three cannot be answered, the operation is difficult to defend — regardless of how well it settled. Getting this right is mostly a matter of design, not effort after the fact.
Provenance
Provenance begins before the payout. Source-of-funds checks, sanctions screening and reliance on another institution's due diligence all belong to the moment an operation is admitted, not to the moment it is questioned. In SUPA's design, that work happens in the legitimacy-validation layer, which checks reliance confirmation, sanctions screening, agent mandate, client-profile fit and network anomaly signals a single time per operation. Reliance, built on FATF Recommendation 17, is codified in a multilateral agreement that fixes who is responsible for what and the data accompanying each operation — while leaving each party's own legal duties intact.
Authorisation
The second question is who authorised the movement. That requires more than a signature: it requires an identified principal legally standing behind the operation, a revocable agent identity that is never anonymous, and a policy — limits, approved counterparties and approval thresholds — applied below the model, where the agent cannot argue with it. An over-limit operation becomes a human approval request rather than a rejection, which keeps the authorisation trail explicit.
Records
The third question is the record. SUPA's ledger is double-entry, on TigerBeetle, with attribution to principal, agent and policy version. Documents are signed and verifiable, and reporting is available per unit. That combination means a digital-asset payout can be traced on the same terms as any other operation, with the digital-asset leg as a step in a longer chain rather than a gap in it.
In short
- Provenance, authorisation and records are the three audit questions.
- Screening and reliance should happen when an operation is admitted.
- Authorisation requires a principal, a revocable agent and policy.
- Over-limit cases should leave an explicit human decision.
- The ledger should tie every payout to principal, agent and policy version.
This is general information, not legal, tax or financial advice. For the compliance view, see /institutions/