← All field notes
Due diligenceField note / digital-asset-due-diligence-scorecard

A Practical Digital-Asset Due-Diligence Scorecard

The point is not to turn uncertainty into a neat score. It is to force the missing evidence, hidden dependency, and unpriced failure into view.

Digital-asset research often begins with price, narrative, or a list of prominent backers. Due diligence should begin earlier: identify the asset, the rights it carries, the systems that control it, and the people or institutions whose performance the holder depends on.

This scorecard is a forcing function. It does not declare an asset safe. It makes incomplete reasoning harder to hide.

How to use the scorecard

Rate each section from zero to three:

  • 0 — Unknown: no reliable evidence found.
  • 1 — Claimed: the project makes the claim, but independent or primary support is weak.
  • 2 — Supported: documentation and evidence exist, with material gaps or dependencies.
  • 3 — Demonstrated: the claim is documented, testable, and supported by operating history or strong external evidence.

Do not add the numbers into an investment grade. A single zero in custody, redemption, or legal rights can matter more than high scores elsewhere. The value is the evidence ledger and the unresolved questions.

1. Asset identity

Question: What exactly is the unit?

Record the network, contract address where applicable, issuer, version, and canonical documentation. Look for copycat tokens, wrapped versions, bridged representations, and similarly named assets.

Red flags: The asset is identified mainly by ticker; official sources conflict; contract addresses are hard to verify; promotion directs users through private messages.

2. Holder rights

Question: What does possession entitle the holder to do or receive?

Rights may include network use, governance, redemption, revenue, access, settlement, ownership, or no enforceable claim beyond transfer. Find the governing terms and the entity or system expected to honor them.

The CFTC advises buyers to understand the rights attached to a token, how funds will be used, whether money can be recovered, and which factors can affect value.

Red flags: “Utility” is asserted without a working use; economic rights live only in marketing material; redemption language is discretionary or contradictory.

3. Control and custody

Question: Who can move, freeze, mint, burn, upgrade, or recover the asset?

Map administrator keys, multisignature signers, governance thresholds, custodian powers, issuer controls, and emergency functions. Identify whether the user holds keys directly or relies on a platform.

Red flags: One undisclosed key can change critical behavior; upgrade authority is unclear; “decentralized” branding obscures concentrated control.

4. Counterparties and reserves

Question: Whose solvency and performance matter?

List issuers, reserve managers, banks, custodians, bridges, market makers, oracle providers, administrators, and legal wrappers. For backed assets, distinguish an audit from an attestation or self-reported dashboard.

Red flags: Reserve composition is vague; assets may be encumbered; related parties occupy several critical roles; holders lack a direct claim.

5. Economics and supply

Question: How is supply created, allocated, unlocked, and destroyed?

Review issuance, distribution, insider allocation, vesting, emissions, fees, burns, collateral requirements, and incentives. Model who benefits from new demand and who can sell into it.

Red flags: Circulating supply is emphasized while future dilution is hidden; insiders have short or modifiable lockups; yield comes mainly from issuing more of the same token.

6. Market and redemption

Question: How does a holder exit under normal and stressed conditions?

Separate direct redemption from selling to another market participant. Record eligible redeemers, minimums, fees, delays, liquidity concentration, exchange dependence, and historical market disruptions.

Red flags: A claimed peg depends entirely on secondary markets; volume is concentrated or unverified; redemption can be suspended without a defined process.

7. Technology and operations

Question: Which technical systems must work?

Document networks, contracts, bridges, wallets, oracles, front ends, data availability, and upgrade processes. Look for current code, security reviews, incident reports, and response procedures. An audit is evidence about a defined scope at a point in time—not a permanent warranty.

Red flags: The product is mostly a white paper; audit branding appears without a report; critical components are closed or undocumented; incidents are deleted rather than explained.

8. Governance and accountability

Question: Who decides, and how can users observe or challenge the decision?

Identify legal entities, leaders, governing bodies, voting power, delegates, administrators, and dispute processes. Compare formal governance with practical control.

Red flags: Team identities or jurisdictions are hidden while trust is required; voting is nominal because ownership is concentrated; emergency powers have no review.

Question: Which rules, registrations, and jurisdictions affect the asset and its intermediaries?

Legal treatment depends on structure and facts. A crypto asset may function as a digital commodity, tool, collectible, stablecoin, or security, and the token itself may not answer how a transaction involving it is regulated.

Red flags: Marketing claims “approved” without naming an authority or action; legal opinions are summarized but unavailable; access is offered where terms prohibit it.

10. Failure and recovery

Question: What happens when the strongest assumption fails?

Write the failure cases: issuer insolvency, reserve shortfall, chain halt, key compromise, bridge exploit, oracle error, governance capture, regulatory restriction, lost liquidity, or custodian shutdown. Then identify detection, communication, containment, recovery, and loss allocation.

Red flags: Risk language says only that loss is possible; no responsible party owns incident response; recovery depends on informal promises.

The one-page conclusion

Finish with four blocks:

  1. What is demonstrated — claims supported by inspectable evidence.
  2. What is merely claimed — assertions that depend on the project’s own account.
  3. What remains unknown — missing evidence that could change the conclusion.
  4. What would break the thesis — specific events or discoveries that invalidate the current view.

The discipline is not predicting price. It is refusing to confuse visibility, popularity, and confidence with evidence.

Sources and scope

This scorecard expands the due-diligence questions in the CFTC’s digital-token customer advisory, its digital-asset fraud resources, and the SEC’s current asset taxonomy. It is a research template, not a recommendation. This is general education, not financial, investment, legal, or tax advice.

Evidence ledger

Sources used in this field note

  1. Use Caution When Buying Digital Coins or TokensCommodity Futures Trading Commission ↗
  2. Digital Asset FraudsCommodity Futures Trading Commission ↗
  3. Crypto Assets and the Federal Securities LawsU.S. Securities and Exchange Commission ↗
Scope note

This material is educational and general. It is not financial, investment, legal, or tax advice.