Quick answer
Gold IRA depositories operate under four to six overlapping audit layers, and no single report covers everything
Internal cycle counts, annual physical audits by specialist metals firms, SOC 1 and SOC 2 examinations, exchange-facility inspections, and insurance reviews each cover a different dimension of risk. Understanding which layer does what helps you ask your custodian the right due-diligence questions. Audit practices differ by facility, so verifying the specific depository your custodian uses matters more than assuming a single industry standard applies.
The Audit Stack at a Glance
Precious metals depositories serving gold IRA customers operate under several overlapping layers of oversight. Each layer is run by a different party, targets different risks, and produces a different type of evidence. The table below maps the primary layers.
| Audit Layer | Who Conducts It | What It Covers | Typical Frequency |
|---|---|---|---|
| Internal cycle counts | Depository’s own vault staff | Physical count and weight of metals vs. inventory records | Continuous to quarterly |
| Annual independent audit | Specialist metals inspection firm (e.g., Bureau Veritas, SGS, Inspectorate) | Full physical inventory count, assay spot-checks, record reconciliation | Annually (point-in-time) |
| SOC 1 examination (SSAE 18) | Independent CPA firm under AICPA standards | Controls over processes affecting custodian financial reporting, NOT bar counts | Annually, Type II covers 6-12 months |
| SOC 2 examination | Independent CPA firm under AICPA Trust Services Criteria | Security, availability, processing integrity, confidentiality, and privacy controls | Annually, Type II covers 6-12 months |
| Exchange-facility inspection | CME Group inspectors (for COMEX-approved facilities) | Compliance with exchange facility rules: insurance, security standards, and record-keeping | Periodic, exchange-mandated |
| Insurance review | Insurer (commonly Lloyd’s of London syndicates for high-value commodity storage) | Physical security risk assessment: access controls, alarm systems, value at risk | At policy inception and annual renewal |
Layer 1: Internal Cycle Counts
Every accredited depository runs its own continuous or scheduled inventory program. Vault staff physically weigh and count metals and reconcile the figures against the ledger. Segregated storage accounts are checked individually: the bars or coins assigned to a specific account are verified against the title record for that account.
Cycle counts are the highest-frequency control in the stack, but they are also the most internal. Because the depository conducts them, they rely on the integrity of the institution itself rather than outside verification. That structural limitation is exactly why the other five layers exist alongside them.
If you hold segregated storage, the cycle count directly touches your specific metals. If you hold allocated non-segregated (pooled) storage, the count verifies that the pool your account draws on is whole, not that any specific bar is assigned to you personally.
Layer 2: Annual Independent Audits by Specialist Firms
Once a year at minimum, most reputable depositories engage an independent specialist precious metals inspection firm to conduct a full physical inventory. These firms, which include global commodity inspection companies such as Bureau Veritas, SGS, and Inspectorate International, are separate from the accounting firms that conduct SOC examinations. Their expertise is physical metals: they count bars and coins, spot-check for assay compliance, and reconcile the physical result against the depository’s own records.
A clean independent audit report provides the strongest publicly available evidence that the physical inventory matches the books at the date of the audit. It does not provide a continuous guarantee. The audit captures a snapshot in time, typically on one or two consecutive days when vault movement is suspended. What happens between annual audits is managed by the internal cycle-count layer and the operational controls covered in SOC examinations.
When a depository publishes an audit report, the primary audience is its custodian partners, not individual IRA holders. Custodians use these reports to fulfill their fiduciary duties. Some depositories make summary audit letters available to account holders on request, but the full report is typically restricted to institutional counterparties under a confidentiality arrangement.
Layer 3: SOC 1 Examinations (AICPA SSAE 18)
A SOC 1 report is a formal examination of a service organization’s internal controls over financial reporting. Depositories that hold metals on behalf of IRA custodians are service organizations under this framework because the accuracy and security of their records directly affects the custodian’s own financial reporting and the accuracy of IRA account statements sent to holders.
SOC 1 examinations are conducted by independent CPA firms under AICPA Statement on Standards for Attestation Engagements No. 18 (SSAE 18). The examination covers controls such as vault access restrictions, dual-custody procedures for moving metals, ledger reconciliation processes, exception reporting, and staff background verification. A Type II SOC 1 report covers both the design and the operating effectiveness of those controls over a period of typically six to twelve months.
What SOC 1 does not attest to: it does not count individual bars or coins. A clean SOC 1 report means the controls designed to prevent unauthorized movement or misrecording of metals were operating as designed during the report period. It is evidence about the quality of the process, not proof that every ounce on a ledger is physically present at the time you read the report.
Custodians should request SOC 1 reports from their depositories and make relevant summary information available to account holders on request. If your custodian cannot confirm that its depository holds a current SOC 1 Type II report, that absence is a meaningful gap worth raising.
Layer 4: SOC 2 Examinations (Trust Services Criteria)
A SOC 2 report covers a different set of criteria from SOC 1. Where SOC 1 focuses on controls relevant to the custodian’s financial reporting, SOC 2 covers the five AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Not all five criteria need to be included in a single SOC 2 report; a depository typically includes security and availability at minimum.
For a precious metals depository, the security criterion covers physical access controls to the vault (biometric readers, key-card systems, video surveillance, guard protocols), network security for the digital ledger system, change-management controls for software, and incident-response procedures. The availability criterion covers the reliability of the systems used to track and report holdings. Processing integrity covers whether those systems process transactions accurately and completely.
Like SOC 1, SOC 2 is about controls rather than physical counts. The two examinations complement each other: SOC 1 covers controls relevant to financial reporting, while SOC 2 covers the broader operational and security infrastructure. A depository with current Type II reports for both provides a more complete control picture than one with only a single type of report.
SOC 2 reports are typically shared under non-disclosure agreements with custodians and institutional auditors. Account holders generally cannot obtain the full report directly, but they can ask their custodian to confirm the depository’s current SOC 2 status and the period covered by the most recent report.
Layer 5: CME/COMEX Exchange-Facility Requirements
The CME Group operates the COMEX division, which runs the primary US futures markets for gold and silver. Depositories approved to hold metals for delivery against COMEX futures contracts must meet ongoing facility requirements published by CME Group. These requirements include minimum insurance coverage, physical security standards, record-keeping systems, and the right for CME Group inspectors to audit the facility at any time.
CME Group maintains a publicly available list of approved depositories, updated periodically. The approval process is ongoing: approved facilities remain subject to inspection and can be removed from the list if they fall out of compliance. This differs from a one-time certification; the risk of losing exchange approval creates a continuous incentive to maintain standards.
This layer is relevant to gold IRA holders because most large depositories serving the self-directed IRA market also hold COMEX approval for at least some of their facilities. COMEX status signals baseline operational standards maintained under threat of losing market access. Not every IRA depository is COMEX-approved, however. Asking whether the depository your custodian uses holds CME Group approval is a useful due-diligence question.
Layer 6: Insurance-Driven Audit Requirements
Precious metals depositories carry substantial insurance policies against physical loss from theft, fire, flood, and transit damage. Insurers underwriting these policies, a market dominated by Lloyd’s of London syndicates for high-value commodity storage, impose their own inspection and documentation requirements as a condition of coverage.
Before underwriting a policy, the insurer or its appointed assessor typically inspects the facility’s physical security, staff vetting practices, alarm and surveillance systems, and fire suppression infrastructure. At each annual policy renewal, updated loss runs, security certifications, and evidence of standard compliance are generally required. The insurance review is not a metals count; it is a risk assessment designed to determine whether the insurer will carry the loss exposure and at what premium.
A depository that cannot obtain adequate insurance at all is effectively disqualified from serving IRA custodians, because most custodians require proof of insurance as a condition of a depository relationship. The insurance layer therefore functions as a secondary barrier to entry and an ongoing operational baseline. You can ask your custodian for a certificate of insurance showing the depository as the named insured and the total coverage amount.
State Regulatory Oversight
Depending on their corporate structure, depositories may be subject to state regulatory examination. A depository organized as a state-chartered trust company is examined periodically by that state’s banking regulator, such as the Ohio Division of Financial Institutions or the Texas Department of Banking. The scope of those examinations covers the trust company’s fiduciary practices, operational controls, and financial condition.
The custodian holding your IRA is also regulated. Custodians of self-directed IRAs that hold physical assets must qualify as a bank, federally insured credit union, savings and loan association, or an entity specifically approved by the IRS under Treasury Regulation 1.408-2(e) to act as an IRA trustee or custodian. State-chartered trust companies serving as custodians are examined by state banking regulators, and those examiners review the custodian’s oversight of its depository partners. For the full picture on who regulates custodians, see our guide on the regulatory framework governing gold IRA custodians.
What You Can Actually Request as a Holder
One practical gap in the audit stack is that most reports described above are not directly shared with individual IRA holders. Here is what you can realistically request and expect to receive.
From your custodian: You have a right to an account statement showing your specific holdings: metal type, weight, description, and account value. Most custodians provide quarterly statements at minimum, and many provide online access with near-real-time balances. The statement reflects the depository’s records as submitted to the custodian, not a live vault count, but it is the baseline document for your account.
From your custodian on request: Ask whether the depository holds a current independent audit report and a current SOC 1 Type II report. Ask when the most recent annual physical audit was completed, who conducted it, and whether a summary letter is available. Ask for evidence of the depository’s insurance coverage. Most custodians can provide this information even if the full underlying reports are confidential.
From the depository for segregated accounts: Some depositories, particularly those offering fully segregated (title-specific) storage, will provide a holding confirmation letter that lists the specific bars or coins allocated to your account by serial number. This is the strongest direct evidence of your specific metals. Availability varies by facility and account type, so ask before choosing a storage tier.
Related reading: if you are curious about whether you can physically visit the vault and see your metals in person, see our guide on visiting your gold in the depository. For what insurance covers and what it excludes, see our guide on insurance coverage at gold IRA depositories.
What No Single Audit Covers: The Structural Gaps
The audit stack is real and meaningful. Understanding where each layer falls short helps you evaluate it honestly rather than assuming comprehensive continuous coverage.
Audits are point-in-time: The annual independent audit is a one or two-day snapshot. SOC reports cover a period of months but assess controls, not counts, on an ongoing basis. Between annual physical audits, you are relying on internal cycle counts and the operational controls documented in SOC reports to maintain ledger accuracy.
Audit practices differ by facility: Not every depository publishes the same level of audit documentation. Some post annual audit summary letters publicly; others require custodian-mediated requests. Some hold both SOC 1 and SOC 2 Type II reports; others hold only one or neither. Verify the specific practices of the depository your custodian uses rather than assuming a uniform industry standard.
SOC reports are about controls, not counts: A depository can have excellent control reports and still have a physical discrepancy that is caught only at the annual independent audit. The layers are designed to be redundant and complementary, not individually sufficient.
Insurance covers physical loss, not all scenarios: Standard policies cover theft, fire, flood, and transit loss. Coverage for other scenarios varies by policy. If a specific risk concerns you, ask your custodian for the certificate of insurance and have an attorney review what the policy does and does not cover.
Frequently Asked Questions
Does a SOC 2 audit mean my gold was physically counted?
No. A SOC 2 report attests to the operational controls protecting the depository’s systems and physical facility, such as access controls, surveillance procedures, and security protocols under the AICPA Trust Services Criteria. It does not include a bar-by-bar physical count. That function is served by the annual independent audit conducted by a specialist metals inspection firm, which is a separate engagement with a different scope.
How often are gold IRA depositories physically audited?
Reputable depositories conduct internal cycle counts on a continuous or quarterly basis and engage an independent specialist firm for a full physical inventory at least annually. Some larger facilities conduct more frequent independent audits. SOC examinations are typically annual, with Type II reports covering a six-to-twelve-month operating period. Insurance audits occur at policy inception and at each annual renewal. The frequency of any specific layer varies by facility.
What is the difference between a SOC 1 and SOC 2 report for a depository?
A SOC 1 report under AICPA SSAE 18 covers controls relevant to the custodian’s financial reporting: vault access procedures, ledger reconciliation processes, and dual-custody protocols that affect the accuracy of account statements. A SOC 2 report under the AICPA Trust Services Criteria covers broader operational controls: physical and digital security, system availability, processing integrity, confidentiality, and privacy. Both are produced by independent CPA firms, both are about controls rather than physical inventory counts, and they address different but complementary risk dimensions.
Can I get a copy of my depository’s audit report?
Direct access to the full report is uncommon for individual account holders. SOC reports and specialist-firm audit reports are typically shared only with institutional counterparties under confidentiality restrictions. However, you can request from your custodian: confirmation that a current report exists, the date of the most recent independent physical audit, evidence of the depository’s insurance coverage, and for segregated accounts a holding confirmation letter listing your specific metals by serial number.
What does CME/COMEX approval mean for the depository holding my IRA metals?
CME Group approval means the depository has met the facility requirements for holding metals eligible for delivery against COMEX futures contracts. Those requirements include minimum insurance coverage, physical security standards, record-keeping systems, and ongoing inspection rights for CME Group. While COMEX approval is not a direct guarantee of your individual account accuracy, it signals that the facility maintains an operational standard under continuous exchange oversight and faces meaningful consequences if it falls short. Not all IRA depositories carry CME approval.
Is segregated storage more thoroughly audited than pooled allocated storage?
The audit layers themselves are generally the same across storage types. The meaningful difference is what each audit verifies for your specific account. In fully segregated storage, your specific bars or coins are tagged to your account and can be verified individually during cycle counts and annual audits. In allocated pooled storage, the audit confirms the total pool is intact but does not trace individual bars to individual accounts. Segregated storage therefore makes it easier to obtain a serial-number holding confirmation tied directly to your account.
Sources
- American Institute of Certified Public Accountants (AICPA). Statement on Standards for Attestation Engagements No. 18 (SSAE 18). Effective for examination report periods beginning on or after May 1, 2017.
- American Institute of Certified Public Accountants (AICPA). SOC 2 Examinations: Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- CME Group. COMEX Approved Precious Metals Facilities and Brands. CME Group, current listing.
- Internal Revenue Service. IRA FAQs: Trustee and Custodian Requirements. Treasury Regulation 1.408-2(e).
- Internal Revenue Service. Publication 590-A: Contributions to Individual Retirement Arrangements (IRAs).
- FINRA Investor Education. Precious Metals Fraud Alert. Financial Industry Regulatory Authority.