The rapid evolution of digital finance is transforming not only financial markets but also the foundations upon which organizations exercise control, manage risk, ensure accountability, and create sustainable value. Blockchain technologies, crypto-assets, tokenization, smart contracts, and decentralized finance challenge many of the assumptions traditionally underlying organizational control, accounting, auditing, compliance, and risk management. Against this background, the book investigates how Internal Control Systems and Enterprise Risk Management frameworks should be redesigned to operate effectively within blockchain-based and crypto-asset ecosystems. Its central argument is that technological sophistication does not automatically produce stronger controls, reliable information, or organizational resilience. Sustainable performance instead depends on the capacity to integrate technological innovation with risk identification, control design, asset safeguarding, accounting systems, compliance mechanisms, and assurance. The book first develops the conceptual foundations for interpreting digital finance from an organizational perspective and proposes an Enterprise Risk Management framework adapted to blockchain-based organizations. It then examines the administrative, accounting, and compliance dimensions of crypto-assets, including classification, documentation, measurement, reporting, custody, auditability, and regulatory requirements. Finally, the framework is applied to the cases of FTX, Terra/Luna, Celsius, and The Rock Trading. These cases demonstrate that blockchain transparency cannot substitute for effective internal controls and that weaknesses in accountability, reporting, asset safeguarding, and audit evidence can undermine organizational resilience despite sophisticated technological infrastructures. The book therefore provides an integrated perspective for making digital-asset business models more controllable, auditable, accountable, and resilient.The speed of this transformation has stimulated an extraordinary growth of academic and professional interest. A rich body of literature now investigates blockchain architectures, cryptographic protocols, token economics, decentralized governance models, cybersecurity, financial innovation, digital payments, regulatory developments, and the legal implications of crypto-assets. These contributions have significantly advanced our understanding of the technological and institutional dimensions of digital finance. Yet, despite this remarkable progress, one important question remains comparatively underexplored: how should organizations redesign their Internal Control Systems and Enterprise Risk Management frameworks to operate effectively within blockchain-based and crypto-asset ecosystems? This question constitutes the intellectual motivation of the present book. The central premise that guides this work is straightforward. Digital technologies do not merely introduce new financial instruments or more efficient technological infrastructures. Rather, they transform the nature of organizational risk itself. Consequently, they also require a profound rethinking of the systems through which organizations identify uncertainty, allocate responsibilities, monitor operations, protect assets, produce reliable information, ensure compliance, and support managerial decision-making. Viewed from this perspective, blockchain represents far more than a technological innovation. It challenges some of the most fundamental assumptions underlying traditional Internal Control Systems. Conventional control architectures have historically relied upon centralized information systems, hierarchical authorization processes, procedural segregation of duties, ex-post verification, and institutional intermediaries responsible for establishing trust. Blockchain-based environments modify many of these assumptions by introducing distributed ledgers, cryptographic validation, programmable transactions, immutable records, and increasingly automated execution mechanisms through smart contracts. These technological developments undoubtedly strengthen certain dimensions of organizational control. Information becomes more traceable. Transactions become increasingly transparent and verifiable. Manual reconciliation may be substantially reduced. Monitoring activities can become continuous rather than periodic. Large volumes of transactional data become immediately available for analytical purposes, opening unprecedented opportunities for continuous auditing and real-time assurance. At the same time, however, digital transformation generates entirely new categories of organizational risk. Cybersecurity threats, smart-contract vulnerabilities, operational resilience, technological dependence, governance ambiguity, regulatory fragmentation, valuation uncertainty, digital fraud, custody failures, algorithmic risks, and systemic interconnections introduce complexities that traditional control frameworks were never designed to address. For this reason, one of the fundamental propositions advanced throughout this book is that technological sophistication does not automatically translate into stronger internal controls. On the contrary, technological innovation may initially weaken organizational control whenever corresponding adaptations in risk management, control design, accountability mechanisms, and organizational processes fail to evolve at the same pace. Internal Control Systems should therefore no longer be interpreted simply as collections of administrative procedures designed to prevent errors or detect fraud. Within the digital economy, they increasingly represent integrated organizational systems through which risks are identified, assessed, monitored, mitigated, communicated, and continuously reviewed. Their purpose extends beyond operational efficiency toward supporting organizational resilience, informed managerial decision-making, reliable financial reporting, regulatory compliance, and long-term value creation. Accordingly, this book adopts Internal Control Systems and Enterprise Risk Management as its primary analytical lenses. Rather than treating internal control as a subsidiary function of corporate governance, we consider it the operational architecture through which organizations transform strategic objectives into coordinated managerial action under conditions of uncertainty. Enterprise Risk Management complements this perspective by providing the dynamic processes through which organizations continuously identify emerging risks, evaluate their interactions, assess their potential impacts, and design appropriate responses. Throughout the volume, governance remains an important institutional context, but it is not the principal focus of our analysis. Instead, governance is examined insofar as it influences the effectiveness of Internal Control Systems, organizational accountability, and enterprise-wide risk management. Our primary concern is understanding how organizations can design integrated control architectures capable of operating effectively within increasingly digital, decentralized, and technologically complex environments. This perspective also reflects a broader evolution within management scholarship. Increasingly, organizational performance depends not only upon technological capabilities but upon the organization's ability to integrate technology with robust control processes, reliable accounting information, effective compliance mechanisms, continuous assurance, and adaptive risk management. Technology alone rarely constitutes sustainable competitive advantage. Rather, sustainable advantage emerges when technological innovation is embedded within coherent organizational systems capable of maintaining control while simultaneously supporting innovation. One of the recurring observations emerging from recent developments in digital finance is that many organizations continue to approach blockchain primarily as an engineering challenge. Significant investments are devoted to developing technological infrastructures while comparatively less attention is paid to redesigning the internal control architecture required to support those infrastructures. As a result, organizations may successfully automate transactions without strengthening accountability, improve transaction speed without improving control reliability, or increase transparency without producing information that remains auditable, decision-useful, and institutionally trustworthy. The consequences of this imbalance have become increasingly visible. Several of the most significant failures observed in recent years within crypto-asset markets were not caused primarily by deficiencies in blockchain technology itself. Rather, they reflected weaknesses in internal controls, deficient risk management practices, inadequate segregation of duties, ineffective safeguarding of customer assets, insufficient audit evidence, weak reporting systems, poor organizational accountability, and failures to recognize emerging risks before they materialized into organizational crises. Understanding these failures requires moving beyond technological explanations toward organizational analysis. This book seeks to contribute precisely to this shift in perspective. The intellectual foundations of this work have matured through several complementary research and educational experiences developed over recent years. A first important source of inspiration derives from our participation in the Next Generation EU research project GRINS – Growing Resilient, Inclusive and Sustainable, particularly within the research area dedicated to the economic and financial sustainability of systems and territories. Although the project addressed a broad range of sustainability-related issues, our research focused specifically on corporate crime, organizational resilience, and the systemic consequences of control failures within contemporary economic systems. This experience reinforced our conviction that effective Internal Control Systems constitute one of the essential institutional mechanisms through which organizations contribute to broader economic sustainability. A second significant influence emerged from our involvement in the PRIN - Projects of great national interest (Progetti di Ricerca di Rilevante Interesse Nazionale - PRIN 2022 PNRR) project entitled Follow the Money: Cryptocurrencies and Criminal Organizations. This research offered the opportunity to investigate the increasingly complex relationships between crypto-assets, illicit financial flows, criminal organizations, legitimate businesses, regulatory authorities, and financial institutions. Once again, our analysis naturally evolved toward questions of organizational control, risk identification, compliance, accountability, and assurance rather than toward purely technological considerations. Further research activities were subsequently developed around blockchain governance, compliance and organizational control. In September 2025, at the international workshop Smart Contracts, Blockchain, Cryptocurrencies and Digital Dispute Resolution: Legal Innovation in AI-Driven Business Paradigm, organized by the Vrije Universiteit Brussel and the University of Naples "Federico II", we presented two complementary applications of the same analytical perspective. The first, Banking Compliance in the Age of Smart Contracts: Rethinking MOG 231 with AI and Blockchain Governance, examined how banking compliance frameworks, particularly the Italian corporate compliance and control framework under Legislative Decree No. 231/2001, must adapt to artificial intelligence, blockchain and smart contracts. The second, Fan Tokens in Italian Minor League Football: Community Engagement, Regulatory Lessons, and Governance Innovations from Siracusa Calcio, investigated how a non-speculative fan token can support stakeholder engagement, symbolic participation and regulatory compliance in a resource-constrained sport organization. These research experiences converged around a common realization: many of the emerging challenges associated with digital finance cannot be adequately understood without adopting an integrated Internal Control System and Enterprise Risk Management perspective. The present volume has also been strongly influenced by our teaching activities within the Master's Degree in Compliance, Business Development and Crime Prevention at the Department of Political Sciences and International Relations of the University of Palermo. Since its establishment, this program has sought to integrate management, compliance, organizational development, crime prevention, and risk management into a coherent educational framework capable of addressing the growing complexity of contemporary organizations. More recently, these educational activities have been enriched through the advanced program on Compliance and Cybercrime, jointly designed with the Italian National Cybersecurity Agency and developed with the collaboration of leading industrial partners. The dialogue among academics, practitioners, public institutions, cybersecurity experts, auditors, and compliance professionals has significantly contributed to shaping many of the ideas developed throughout this book. The first part develops the conceptual foundations necessary for interpreting digital finance through the lenses of Internal Control Systems and Enterprise Risk Management. Rather than analyzing blockchain exclusively as a technological infrastructure, it examines how digital finance transforms the logic of organizational control, accounting information systems, assurance mechanisms, continuous monitoring, and enterprise-wide risk management. Particular attention is devoted to developing an integrated conceptual framework capable of extending established control principles to blockchain-based organizational environments. The second part examines the administrative, accounting, and compliance dimensions of crypto-assets. Here, crypto-assets are interpreted not simply as digital financial instruments but as organizational objects requiring classification, documentation, measurement, reporting, safeguarding, auditability, and regulatory compliance. Administrative processes, accounting systems, and compliance mechanisms are therefore analyzed as complementary components of an integrated Internal Control System designed to generate reliable organizational information while mitigating operational, financial, and regulatory risks. The final part translates the proposed conceptual framework into practice through the analysis of several highly significant organizational failures within crypto-asset markets. The cases of FTX, Terra/Luna, Celsius, and The Rock Trading demonstrate that technological transparency alone cannot substitute for effective internal controls. Instead, they illustrate how weaknesses in risk identification, control design, asset safeguarding, organizational accountability, audit evidence, reporting systems, and assurance mechanisms can progressively erode organizational resilience, ultimately leading to systemic failure despite the presence of highly sophisticated technological infrastructures. Collectively, these three parts develop a unified analytical perspective in which Internal Control Systems and Enterprise Risk Management become the primary interpretative frameworks through which digital finance can be understood. Technology remains fundamental, regulation remains indispensable, and governance provides the institutional environment within which organizations operate. Nevertheless, sustainable organizational performance ultimately depends upon the effectiveness with which risks are identified, controls are designed, information is generated, compliance is ensured, and organizational learning continuously adapts to changing technological conditions. This book is intended for researchers, graduate students, auditors, internal auditors, compliance officers, regulators, financial managers, accounting professionals, and risk managers seeking to understand the institutional foundations of digital finance from an organizational rather than purely technological perspective. It is written for readers interested not only in crypto-assets as financial innovations, but also in the broader challenge of making digital-asset business models controllable, auditable, accountable, and resilient within established systems of organizational management. Our ambition is neither to celebrate nor to criticize technological innovation. Instead, we seek to demonstrate that the long-term success of digital finance will depend less upon technological sophistication than upon the capacity of organizations to design Internal Control Systems and Enterprise Risk Management frameworks capable of governing complexity, mitigating uncertainty, producing reliable information, and sustaining stakeholder confidence.

Scire', G., Bivona, E. (2026). FinTech and Crypto-Assets: An Internal Control System & Risk Management perspective in the Digital Economy. Cham : Palgrave Macmillan.

FinTech and Crypto-Assets: An Internal Control System & Risk Management perspective in the Digital Economy

Giovanni Scire';Enzo Bivona
2026-01-01

Abstract

The rapid evolution of digital finance is transforming not only financial markets but also the foundations upon which organizations exercise control, manage risk, ensure accountability, and create sustainable value. Blockchain technologies, crypto-assets, tokenization, smart contracts, and decentralized finance challenge many of the assumptions traditionally underlying organizational control, accounting, auditing, compliance, and risk management. Against this background, the book investigates how Internal Control Systems and Enterprise Risk Management frameworks should be redesigned to operate effectively within blockchain-based and crypto-asset ecosystems. Its central argument is that technological sophistication does not automatically produce stronger controls, reliable information, or organizational resilience. Sustainable performance instead depends on the capacity to integrate technological innovation with risk identification, control design, asset safeguarding, accounting systems, compliance mechanisms, and assurance. The book first develops the conceptual foundations for interpreting digital finance from an organizational perspective and proposes an Enterprise Risk Management framework adapted to blockchain-based organizations. It then examines the administrative, accounting, and compliance dimensions of crypto-assets, including classification, documentation, measurement, reporting, custody, auditability, and regulatory requirements. Finally, the framework is applied to the cases of FTX, Terra/Luna, Celsius, and The Rock Trading. These cases demonstrate that blockchain transparency cannot substitute for effective internal controls and that weaknesses in accountability, reporting, asset safeguarding, and audit evidence can undermine organizational resilience despite sophisticated technological infrastructures. The book therefore provides an integrated perspective for making digital-asset business models more controllable, auditable, accountable, and resilient.The speed of this transformation has stimulated an extraordinary growth of academic and professional interest. A rich body of literature now investigates blockchain architectures, cryptographic protocols, token economics, decentralized governance models, cybersecurity, financial innovation, digital payments, regulatory developments, and the legal implications of crypto-assets. These contributions have significantly advanced our understanding of the technological and institutional dimensions of digital finance. Yet, despite this remarkable progress, one important question remains comparatively underexplored: how should organizations redesign their Internal Control Systems and Enterprise Risk Management frameworks to operate effectively within blockchain-based and crypto-asset ecosystems? This question constitutes the intellectual motivation of the present book. The central premise that guides this work is straightforward. Digital technologies do not merely introduce new financial instruments or more efficient technological infrastructures. Rather, they transform the nature of organizational risk itself. Consequently, they also require a profound rethinking of the systems through which organizations identify uncertainty, allocate responsibilities, monitor operations, protect assets, produce reliable information, ensure compliance, and support managerial decision-making. Viewed from this perspective, blockchain represents far more than a technological innovation. It challenges some of the most fundamental assumptions underlying traditional Internal Control Systems. Conventional control architectures have historically relied upon centralized information systems, hierarchical authorization processes, procedural segregation of duties, ex-post verification, and institutional intermediaries responsible for establishing trust. Blockchain-based environments modify many of these assumptions by introducing distributed ledgers, cryptographic validation, programmable transactions, immutable records, and increasingly automated execution mechanisms through smart contracts. These technological developments undoubtedly strengthen certain dimensions of organizational control. Information becomes more traceable. Transactions become increasingly transparent and verifiable. Manual reconciliation may be substantially reduced. Monitoring activities can become continuous rather than periodic. Large volumes of transactional data become immediately available for analytical purposes, opening unprecedented opportunities for continuous auditing and real-time assurance. At the same time, however, digital transformation generates entirely new categories of organizational risk. Cybersecurity threats, smart-contract vulnerabilities, operational resilience, technological dependence, governance ambiguity, regulatory fragmentation, valuation uncertainty, digital fraud, custody failures, algorithmic risks, and systemic interconnections introduce complexities that traditional control frameworks were never designed to address. For this reason, one of the fundamental propositions advanced throughout this book is that technological sophistication does not automatically translate into stronger internal controls. On the contrary, technological innovation may initially weaken organizational control whenever corresponding adaptations in risk management, control design, accountability mechanisms, and organizational processes fail to evolve at the same pace. Internal Control Systems should therefore no longer be interpreted simply as collections of administrative procedures designed to prevent errors or detect fraud. Within the digital economy, they increasingly represent integrated organizational systems through which risks are identified, assessed, monitored, mitigated, communicated, and continuously reviewed. Their purpose extends beyond operational efficiency toward supporting organizational resilience, informed managerial decision-making, reliable financial reporting, regulatory compliance, and long-term value creation. Accordingly, this book adopts Internal Control Systems and Enterprise Risk Management as its primary analytical lenses. Rather than treating internal control as a subsidiary function of corporate governance, we consider it the operational architecture through which organizations transform strategic objectives into coordinated managerial action under conditions of uncertainty. Enterprise Risk Management complements this perspective by providing the dynamic processes through which organizations continuously identify emerging risks, evaluate their interactions, assess their potential impacts, and design appropriate responses. Throughout the volume, governance remains an important institutional context, but it is not the principal focus of our analysis. Instead, governance is examined insofar as it influences the effectiveness of Internal Control Systems, organizational accountability, and enterprise-wide risk management. Our primary concern is understanding how organizations can design integrated control architectures capable of operating effectively within increasingly digital, decentralized, and technologically complex environments. This perspective also reflects a broader evolution within management scholarship. Increasingly, organizational performance depends not only upon technological capabilities but upon the organization's ability to integrate technology with robust control processes, reliable accounting information, effective compliance mechanisms, continuous assurance, and adaptive risk management. Technology alone rarely constitutes sustainable competitive advantage. Rather, sustainable advantage emerges when technological innovation is embedded within coherent organizational systems capable of maintaining control while simultaneously supporting innovation. One of the recurring observations emerging from recent developments in digital finance is that many organizations continue to approach blockchain primarily as an engineering challenge. Significant investments are devoted to developing technological infrastructures while comparatively less attention is paid to redesigning the internal control architecture required to support those infrastructures. As a result, organizations may successfully automate transactions without strengthening accountability, improve transaction speed without improving control reliability, or increase transparency without producing information that remains auditable, decision-useful, and institutionally trustworthy. The consequences of this imbalance have become increasingly visible. Several of the most significant failures observed in recent years within crypto-asset markets were not caused primarily by deficiencies in blockchain technology itself. Rather, they reflected weaknesses in internal controls, deficient risk management practices, inadequate segregation of duties, ineffective safeguarding of customer assets, insufficient audit evidence, weak reporting systems, poor organizational accountability, and failures to recognize emerging risks before they materialized into organizational crises. Understanding these failures requires moving beyond technological explanations toward organizational analysis. This book seeks to contribute precisely to this shift in perspective. The intellectual foundations of this work have matured through several complementary research and educational experiences developed over recent years. A first important source of inspiration derives from our participation in the Next Generation EU research project GRINS – Growing Resilient, Inclusive and Sustainable, particularly within the research area dedicated to the economic and financial sustainability of systems and territories. Although the project addressed a broad range of sustainability-related issues, our research focused specifically on corporate crime, organizational resilience, and the systemic consequences of control failures within contemporary economic systems. This experience reinforced our conviction that effective Internal Control Systems constitute one of the essential institutional mechanisms through which organizations contribute to broader economic sustainability. A second significant influence emerged from our involvement in the PRIN - Projects of great national interest (Progetti di Ricerca di Rilevante Interesse Nazionale - PRIN 2022 PNRR) project entitled Follow the Money: Cryptocurrencies and Criminal Organizations. This research offered the opportunity to investigate the increasingly complex relationships between crypto-assets, illicit financial flows, criminal organizations, legitimate businesses, regulatory authorities, and financial institutions. Once again, our analysis naturally evolved toward questions of organizational control, risk identification, compliance, accountability, and assurance rather than toward purely technological considerations. Further research activities were subsequently developed around blockchain governance, compliance and organizational control. In September 2025, at the international workshop Smart Contracts, Blockchain, Cryptocurrencies and Digital Dispute Resolution: Legal Innovation in AI-Driven Business Paradigm, organized by the Vrije Universiteit Brussel and the University of Naples "Federico II", we presented two complementary applications of the same analytical perspective. The first, Banking Compliance in the Age of Smart Contracts: Rethinking MOG 231 with AI and Blockchain Governance, examined how banking compliance frameworks, particularly the Italian corporate compliance and control framework under Legislative Decree No. 231/2001, must adapt to artificial intelligence, blockchain and smart contracts. The second, Fan Tokens in Italian Minor League Football: Community Engagement, Regulatory Lessons, and Governance Innovations from Siracusa Calcio, investigated how a non-speculative fan token can support stakeholder engagement, symbolic participation and regulatory compliance in a resource-constrained sport organization. These research experiences converged around a common realization: many of the emerging challenges associated with digital finance cannot be adequately understood without adopting an integrated Internal Control System and Enterprise Risk Management perspective. The present volume has also been strongly influenced by our teaching activities within the Master's Degree in Compliance, Business Development and Crime Prevention at the Department of Political Sciences and International Relations of the University of Palermo. Since its establishment, this program has sought to integrate management, compliance, organizational development, crime prevention, and risk management into a coherent educational framework capable of addressing the growing complexity of contemporary organizations. More recently, these educational activities have been enriched through the advanced program on Compliance and Cybercrime, jointly designed with the Italian National Cybersecurity Agency and developed with the collaboration of leading industrial partners. The dialogue among academics, practitioners, public institutions, cybersecurity experts, auditors, and compliance professionals has significantly contributed to shaping many of the ideas developed throughout this book. The first part develops the conceptual foundations necessary for interpreting digital finance through the lenses of Internal Control Systems and Enterprise Risk Management. Rather than analyzing blockchain exclusively as a technological infrastructure, it examines how digital finance transforms the logic of organizational control, accounting information systems, assurance mechanisms, continuous monitoring, and enterprise-wide risk management. Particular attention is devoted to developing an integrated conceptual framework capable of extending established control principles to blockchain-based organizational environments. The second part examines the administrative, accounting, and compliance dimensions of crypto-assets. Here, crypto-assets are interpreted not simply as digital financial instruments but as organizational objects requiring classification, documentation, measurement, reporting, safeguarding, auditability, and regulatory compliance. Administrative processes, accounting systems, and compliance mechanisms are therefore analyzed as complementary components of an integrated Internal Control System designed to generate reliable organizational information while mitigating operational, financial, and regulatory risks. The final part translates the proposed conceptual framework into practice through the analysis of several highly significant organizational failures within crypto-asset markets. The cases of FTX, Terra/Luna, Celsius, and The Rock Trading demonstrate that technological transparency alone cannot substitute for effective internal controls. Instead, they illustrate how weaknesses in risk identification, control design, asset safeguarding, organizational accountability, audit evidence, reporting systems, and assurance mechanisms can progressively erode organizational resilience, ultimately leading to systemic failure despite the presence of highly sophisticated technological infrastructures. Collectively, these three parts develop a unified analytical perspective in which Internal Control Systems and Enterprise Risk Management become the primary interpretative frameworks through which digital finance can be understood. Technology remains fundamental, regulation remains indispensable, and governance provides the institutional environment within which organizations operate. Nevertheless, sustainable organizational performance ultimately depends upon the effectiveness with which risks are identified, controls are designed, information is generated, compliance is ensured, and organizational learning continuously adapts to changing technological conditions. This book is intended for researchers, graduate students, auditors, internal auditors, compliance officers, regulators, financial managers, accounting professionals, and risk managers seeking to understand the institutional foundations of digital finance from an organizational rather than purely technological perspective. It is written for readers interested not only in crypto-assets as financial innovations, but also in the broader challenge of making digital-asset business models controllable, auditable, accountable, and resilient within established systems of organizational management. Our ambition is neither to celebrate nor to criticize technological innovation. Instead, we seek to demonstrate that the long-term success of digital finance will depend less upon technological sophistication than upon the capacity of organizations to design Internal Control Systems and Enterprise Risk Management frameworks capable of governing complexity, mitigating uncertainty, producing reliable information, and sustaining stakeholder confidence.
2026
Settore ECON-06/A - Economia aziendale
9783032370747
Scire', G., Bivona, E. (2026). FinTech and Crypto-Assets: An Internal Control System & Risk Management perspective in the Digital Economy. Cham : Palgrave Macmillan.
File in questo prodotto:
File Dimensione Formato  
final version.pdf

Solo gestori archvio

Tipologia: Pre-print
Dimensione 2.05 MB
Formato Adobe PDF
2.05 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10447/712183
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact