Treasury teams did not ask for this problem. A finance function that spent a decade optimising cash pooling, FX hedges, and bank relationship management is now being asked to hold, move, and account for digital assets it was never trained to govern. The board wants yield. The CFO wants to reduce settlement risk. The COO wants payments that clear in minutes, not days. And somewhere in the room, someone asks the question that stops the conversation cold: "Do we actually have a policy for this, or are we just doing it?"
For most enterprises that have started using stablecoins for cross-border settlement, or that are holding Bitcoin as a treasury reserve asset, the honest answer is that governance has lagged adoption. Treasury desks moved first because the operational case was undeniable: fewer intermediaries, faster settlement, lower structural cost. Policy, controls, and audit-readiness came second, if they came at all.
That sequencing is exactly backwards, and it is exactly what auditors, regulators, and boards are now testing for. A treasury policy that was written for correspondent banking relationships and traditional FX exposure does not extend to bearer-asset custody, smart contract counterparty risk, or the accounting ambiguity that still surrounds digital assets in most jurisdictions. Enterprises that treat digital treasury as an extension of existing cash management policy, rather than a distinct governance discipline, are the ones that fail audits, trigger regulatory findings, and lose board confidence.
This is a governance problem before it is a technology problem. It applies whether the treasury holds USDC for supplier settlement in Lagos, USDT for a corridor into Nairobi, or Bitcoin as a long-duration reserve asset. The mechanics differ; the governance test does not. Auditors want evidence. Regulators want a defensible compliance posture. Boards want a document they can point to when a shareholder, a rating agency, or a journalist asks how the company is managing this exposure.
This article sets out the anatomy of a stablecoin and Bitcoin treasury policy that will hold up to all three audiences, with the specific evidence, controls, and reporting cadence each one is actually looking for.
The Governance Gap Is Now a Balance Sheet Risk
Digital asset treasury holdings have moved from experimental to material for a meaningful share of large enterprises. Treasury benchmarking work across corporates that have begun holding stablecoins or Bitcoin on the balance sheet points to a consistent pattern: adoption of the asset class is running well ahead of adoption of the governance structure needed to hold it defensibly.
A few figures illustrate the scale of the exposure most finance leaders are underestimating:
• Corporates that have moved cross-border settlement volume onto stablecoin rails report average savings of 3.5–8% per transaction the structural SWIFT tax charged by correspondent banking networks but fewer than a third have a board-approved policy governing counterparty limits, custody standards, or wallet-level controls for the stablecoin balances that generate those savings.
• In surveyed finance functions holding digital assets for more than twelve months, over 60% could not produce a documented risk appetite statement covering digital assets when asked by their external auditor.
• Treasury teams that experienced a qualified audit opinion or a management letter finding related to digital assets cited absence of segregation-of-duties controls over private key management as the single most common root cause.
• The average time between a treasury desk's first stablecoin transaction and the finance function's first board-approved digital asset policy is estimated at 14–18 months — a governance lag that leaves the enterprise exposed for well over a year.
• Enterprises with a documented, board-approved treasury policy for digital assets report audit cycle times 20–30% shorter than those without one, because evidence requests that would otherwise require ad hoc reconstruction are answered by policy artefacts that already exist.
None of this is a case against holding stablecoins or Bitcoin on the balance sheet. It is a case against holding them without the paperwork, controls, and reporting lines that turn a treasury decision into a defensible one. The good news is that the governance gap is closable, and the anatomy of a policy that closes it is well understood, even if very few finance functions have actually written one down.
Why Bank-Grade Treasury Policy Does Not Transfer
Most finance teams reach for their existing treasury policy, the one governing bank deposits, money market funds, and FX hedging and try to extend it to cover digital assets with a clause or two. This fails for four structural reasons.
Custody is a new risk category, not a variant of an old one.
Traditional treasury policy assumes a regulated custodian (a bank) holds the asset and bears fiduciary responsibility for its safekeeping. Digital asset custody introduces private key management, multi-signature authorisation, and in self-custody or hybrid models direct operational responsibility for asset control that the treasury has never had to hold before. A policy silent on custody model, key management procedure, and recovery process is not a policy; it is a gap waiting to be found by an auditor.
The accounting treatment is still unsettled in most jurisdictions.
Whether stablecoins are treated as cash equivalents, intangible assets, or a separate class varies by accounting standard and by the specific stablecoin's structure and reserve backing. Bitcoin's treatment as an indefinite-lived intangible asset under most current standards creates impairment-only accounting that traditional treasury policy was never built to explain to a board. A policy needs an explicit accounting position, agreed with the external auditor in advance, not discovered during year-end close.
Counterparty risk looks different.
Correspondent banking risk is concentrated in a small number of relationship banks with known credit ratings. Stablecoin exposure concentrates counterparty risk in the issuer's reserve management and redemption mechanics, a different risk entirely, and one that requires its own due diligence framework, not a repurposed bank counterparty checklist.
The regulatory perimeter is still being drawn.
cross African markets, the regulatory status of stablecoins ranges from explicit licensing regimes to conditional guidance to outright silence. A treasury policy written for one jurisdiction's clarity will not survive contact with a regulator in a market where the rules are still being written which is the position most African CFOs are actually operating in today.
The risk owner is often unclear.
In traditional treasury, market risk sits with treasury, credit risk sits with credit, and operational risk sits with operations. Digital asset holdings blur these lines: a custody failure is simultaneously an operational risk, a market risk event, and potentially a compliance breach. Policy needs to name a single accountable owner, not assume the existing risk committee structure will absorb the gap.
The Seven Components of a Defensible Policy
A stablecoin and Bitcoin treasury policy that will satisfy an auditor, a regulator, and a board needs seven components. Each one answers a distinct question that at least one of those three audiences will ask.
1. Objectives and risk appetite statement.
This is the section a board actually reads. It states, in plain language, why the enterprise holds digital assets reducing the SWIFT tax on settlement, margin protection against local currency depreciation, a lower cost of capital on working balances, competitive necessity and sets explicit, numerical limits on exposure: maximum percentage of treasury balance, maximum single-issuer concentration, maximum unhedged Bitcoin exposure relative to working capital requirements. A risk appetite statement without numbers is a mission statement, not a policy.
2. Asset eligibility criteria.
Not every stablecoin is equivalent, and treating them as interchangeable is the fastest way to fail a counterparty due diligence review. The policy should specify eligible stablecoins by name or by criteria reserve composition, attestation frequency, issuer jurisdiction, redemption mechanics, and liquidity under stress and should separately address Bitcoin's distinct risk profile as a volatile, non-yield-bearing reserve asset rather than a cash equivalent. Where a stablecoin structure offers a stablecoin yield component through its underlying reserves, that yield should be treated as a secondary benefit, not the primary justification for holding it. Where local-currency-referenced instruments are in scope, the same eligibility discipline applies.
3. Custody and key management standards. This section names the custody model (qualified third-party custodian, multi-signature self-custody, or hybrid), the segregation-of-duties structure for transaction authorisation, and the recovery procedure in the event of key loss or personnel departure. This is the single section auditors scrutinise most closely, because it is the one most likely to reveal a control gap.
4. Compliance and regulatory mapping.
The policy should state, jurisdiction by jurisdiction, the current regulatory status of the assets and activities in scope licensed, permitted, restricted, or unclear and the compliance obligations that follow, including AML/KYC standards applied to any counterparty or payment corridor. Where regulatory status is genuinely unclear, the policy should say so explicitly rather than implying certainty that does not exist. This is where a single authoritative regulatory reference, updated as rules change, becomes operationally necessary rather than a nice-to-have.
5. Accounting and valuation methodology.
A pre-agreed position with the external auditor on classification, initial recognition, subsequent measurement, and impairment testing, documented before the first transaction rather than reconstructed at year-end.
6. Reporting and escalation structure.
Who reports what, to whom, and how often. At minimum this should specify board or audit committee reporting frequency, the metrics included in that reporting (exposure levels, concentration, custody incidents, regulatory developments), and the escalation trigger for material events: a depeg event, a custody breach, a regulatory action against an issuer.
7. Review and amendment cadence.
Given how quickly both the regulatory environment and the stablecoin issuer landscape are moving across African markets, a policy reviewed annually is already out of date. A semi-annual review cycle, with an explicit trigger for out-of-cycle review upon material regulatory change, is the standard that holds up to scrutiny.
The table below summarises these seven components against the specific evidence each audience is looking for.
What Auditors Are Actually Testing For
External auditors approaching a digital asset treasury balance for the first time are not testing whether the enterprise made a good investment decision. They are testing whether the control environment around that decision is sound enough to support an unqualified opinion. Three things dominate their testing in practice.
Existence and rights.
Can the enterprise prove it actually controls the asset, and prove it in a way that does not rely on a single individual's access credentials? This is where multi-signature custody arrangements and independently verifiable wallet balances matter far more than which custody provider's brand is on the door.
Valuation.
Given the accounting ambiguity discussed above, auditors want to see a documented, consistently applied valuation methodology, agreed in advance rather than negotiated at year-end under time pressure.
Completeness of the control environment.
This is the segregation-of-duties question: can one person unilaterally move funds? If yes, that is a finding, regardless of how sophisticated the technology stack is. Auditors have seen enough digital asset losses attributable to single points of control to treat this as close to non-negotiable.
Common Audit Findings and the Policy Provisions That Prevent Them
What Regulators Expect, Even Where the Rules Are Still Forming
Regulatory clarity on stable coins varies significantly across African markets from jurisdictions with defined VASP/CASP licensing frameworks to markets where guidance remains informal or is still being drafted. This uncertainty is not a reason to defer governance; it is the reason governance matters more, not less.
Regulators consistently reward two behaviours regardless of where formal rules currently stand: demonstrated intent to comply with whatever framework does exist or is emerging, and a documented AML/KYC standard applied to counter parties and payment corridors that meets or exceeds what would be expected of a licensed financial institution. Enterprises that can show a regulator a policy document, a compliance mapping, and a consistent AML/KYC standard are treated fundamentally differently from those that cannot even in jurisdictions where the specific licensing question has not yet been resolved. The posture a regulator is testing for is not "did you get every rule right," it is "can this enterprise be trusted to self-govern responsibly while the rules catch up."
This is also where jurisdiction-specific regulatory tracking becomes a genuine operational requirement rather than a compliance nicety. A treasury team operating across multiple African corridors, say, Nigeria, Kenya, and South Africa is navigating three distinct and independently evolving regulatory postures simultaneously. A policy that does not name the current status in each jurisdiction of operation, and update that status on a defined cadence, cannot credibly claim to be regulator-ready.
What the Board Actually Wants to See
Boards are not asking the treasury to explain blockchain mechanics. They are asking three questions, consistently, across every enterprise that has brought this topic to board level: How much are we exposed to? What is the worst case, and can we survive it? Who is accountable if it goes wrong?
A treasury policy that answers those three questions in the first two pages, before it gets into custody procedures and accounting methodology, is a policy that will actually get read and approved rather than tabled for further review. The risk appetite statement and the reporting section carry the most weight here: a board approving a policy is really approving a set of numerical limits and a reporting cadence, not a technology choice.
It is worth being explicit about one distinction boards frequently conflate: stable coins and Bitcoin are not the same risk category, and a single policy that treats them identically will under serve both. Stable coins, properly selected, function as a payment rail and working capital tool; the relevant risk lens is counter party and operational, not market volatility. Bitcoin, held as a reserve asset, carries a fundamentally different risk profile, price volatility, no yield, and a longer holding horizon logic. Boards should expect, and treasury should provide, separate risk appetite limits for each.
Stable coins vs. Bitcoin — Distinct Risk Profiles Requiring Distinct Board Limits
Governance Cadence: Making the Policy a Living Document
A policy document that sits unreviewed for two years is functionally the same as no policy at all, from an auditor's perspective, because it will not reflect the current issuer landscape, the current regulatory posture, or the current scale of exposure. The enterprises that pass audit cleanly and keep regulators satisfied treat the policy as a living operational tool with a defined maintenance cycle:
• A semi-annual formal review by the treasury risk committee, with sign-off recorded.
• A standing agenda item at quarterly audit committee meetings covering exposure, concentration, and any control incidents.
• A defined out-of-cycle triggers a depeg event, a regulatory action in any jurisdiction of operation, or a material change in issuer reserve composition that forces immediate review rather than waiting for the next scheduled cycle.
• Version control on the policy document itself, so that any audit or regulatory inquiry can show exactly what the policy said at the time of any given transaction.
This cadence is what converts a static document into the kind of evidence trail that shortens audit cycles and satisfies regulators operating in still-forming frameworks the difference, in practice, between a treasury function that can answer a hard question in the room and one that has to go away and reconstruct an answer under pressure.
Answering the Objections Treasury Will Hear
Every enterprise writing this policy for the first time runs into the same three objections, usually from the same three directions: finance, legal, and the desk that has been managing payments the old way. A defensible policy needs to answer each one directly rather than avoid it.
"Traditional banks feel safer."
This framing treats speed as a risk rather than what it actually is: a fiduciary duty. A CFO who accepts a three-day settlement and an 8% FX spread as the safe option is choosing a known, quantifiable cost over an unfamiliar one and that choice deserves the same scrutiny as any other capital allocation decision. The policy's role is to make the fast option auditable, not to argue that speed alone justifies the switch.
"The parallel market already gets this done."
Informal channels solve the settlement problem and create an audit problem in its place. Hash Impact's position is that the objective was never speed for its own sake; it is a settlement process that satisfies the same auditors and the same board that traditional banking already satisfies. A documented policy is what separates a defensible treasury decision from an informal workaround that will not survive a compliance review.
"Stablecoins are banned, or too complex, in our market."
In most jurisdictions this objection conflates the asset with the absence of a policy. The response is not to sell the asset it is to sell governance: a Treasury Transformation Policy with turnkey compliance mapping that positions the enterprise to move the moment the regulatory picture clarifies, rather than starting the governance work from zero once it does.
Where Most Policy-Building Efforts Stall
Treasury teams that set out to write this policy internally tend to stall in the same two places, regardless of company size or sector.
The first stall point is accounting treatment. Finance teams are reluctant to commit to a valuation methodology without external auditor sign-off, and external auditors are reluctant to commit to a position without seeing the specific instruments and custody model in scope. This creates a chicken-and-egg delay that can run for months if no one owns the process of getting both parties into the same room early, with a concrete proposal on the table rather than an open question.
The second stall point is jurisdictional regulatory mapping. A treasury team operating across three or four African markets often finds that no single internal function has a current, defensible view of stablecoin regulatory status in each one legal counsel may have partial visibility, compliance may have partial visibility, and neither has the specialist context to translate central bank guidance into an operational compliance standard. This is precisely the gap a single authoritative regulatory reference is built to close, and it is usually faster and more defensible to draw on specialist coverage than to build jurisdiction-by-jurisdiction legal research from scratch for a first policy draft.
Neither stall point is a reason to delay writing the policy. Both are reasons to sequence the work correctly: draft the risk appetite, eligibility, and custody sections first, since those depend on internal decisions the enterprise can make independently; bring in the external auditor and specialist regulatory input in parallel for the accounting and compliance mapping sections; and treat the first board approval as a baseline to be refined at the first semi-annual review, not as a document that needs to be perfect on the first pass.
Conclusion
The enterprises getting this right are not the ones with the most sophisticated technology stack. They are the ones that treated digital asset treasury as a governance discipline from the outset with named risk owners, numerical limits, pre-agreed accounting treatment, and a reporting cadence that keeps the board, the audit committee, and the compliance function in the loop before a problem forces the conversation.
The governance gap between adoption and policy is closing across the market, but slowly, and the enterprises still operating without a documented, board-approved treasury policy for stablecoins and Bitcoin are carrying a form of risk that has nothing to do with price volatility or FX exposure. It is the risk of being unable to answer a straightforward question from an auditor, a regulator, or a board member with a document rather than an explanation improvised on the spot.
Writing that policy is not a technology project. It is a governance exercise that treasury, compliance, and the board need to own together, built on the same rigour applied to every other material treasury decision the enterprise makes.
If your treasury is already holding stablecoins or Bitcoin without a board-approved policy behind it, the fastest next step is not a full rewrite; it is a structured diagnostic of where your current position would hold up under audit, and where it wouldn't. Hash Impact's Treasury Clarity Session is built for exactly that conversation: a focused review against the seven components above, mapped to your specific jurisdictions and your existing governance structure.

