Audit Standards for IRA Gold Depositories: SOC, Lloyd, Chain of Custody

OPRS may receive compensation when readers open an account through partner links on this page. Our analysis is based on independent research, BBB data, and IRS publications.

30-second verdict

  • A gold IRA depository’s audit posture rests on four documented pillars: SOC 1 Type II, SOC 2 Type II, an independent physical inventory audit, and the Lloyd’s of London specie insurance certificate.
  • SOC 1 Type II covers internal controls relevant to the custodian’s financial reporting on the trust assets. SOC 2 Type II covers security, availability, and processing integrity of the depository’s information systems.
  • Both SOC Type II reports cover a defined audit period, typically 12 months, and are issued under AICPA SSAE 18. Type I reports cover a single point in time and are weaker evidence.
  • The annual physical inventory audit reconciles bars in the vault to the books on a serial-by-serial basis for segregated storage and on an aggregate weight basis for commingled storage.
  • The certificate of all-risk Lloyd’s specie insurance documents the aggregate vault limit, the per-claim sub-limit, and the exclusions schedule.
  • OPRS shortlists 3 dealers of the 27+ reviewed; Augusta Precious Metals is one of them, and the company-comparison checklist is the screen we point readers to before the dealer locks in a custodian and a depository whose audit posture has not been confirmed.

A retiree who opens a self-directed gold IRA inherits a chain of custody on the bullion: dealer to custodian to depository. The depository is the operational end of that chain, the regulated commercial vault that holds the metal for the life of the IRA. The audit standards that apply to the depository decide whether the inventory statements arriving each year actually reflect the bars in the vault.

See the dealers OPRS clears and the ones we warn against before the chain locks in. The dealer is the upstream decision, and its discipline (or lack of it) decides whether the audit posture at the depository ever surfaces in the planning conversation.

Element I of the framework is the audit standard itself: which AICPA attestation the depository undergoes, who issues the report, and what the report scope actually covers. Element II is the physical inventory reconciliation: who counts the bars, how often, and on what basis.

Element III is the insurance posture: the certificate of specie coverage and the limits attached to the policy. Element IV is the verification procedure the retiree runs (or the custodian runs on the retiree’s behalf) before any bullion leg lands in the chain.

Confirm the audit posture before the metal moves

A dealer that walks the audit chain into the planning conversation pulls the depository question forward, before the custodian relationship locks in. A dealer that skips the audit conversation defaults the retiree onto whichever depository is downstream of the custodian’s commercial relationships, audited or not.

3 of 27+ gold IRA dealers reviewed by OPRS make the 2026 trusted list. Updated July 2026.

Why audit standards matter on a gold IRA depository

A gold IRA holds bullion that the IRA owner cannot personally touch. The metal sits in a depository for the life of the account, and the only window into that vault is the inventory statement the depository issues through the custodian. The audit standards decide whether the statement is reliable.

The IRC Section 408(a) trustee rule and the non-bank trustee requirements under Treasury Regulation 1.408-2(e) require that the custodian hold the IRA’s assets under a fiduciary standard. The custodian delegates physical storage to a depository. The custodian’s fiduciary posture extends to its choice of depository: a custodian that contracts with an unaudited depository is taking on inventory risk it cannot independently verify.

The retiree’s window into that risk is the set of audit artifacts the depository can produce on request. Without those artifacts, the inventory statement is a representation, not an attestation.

The four audit pillars on an IRA depository

The audit posture of a credible US gold IRA depository rests on four documented pillars. Each pillar covers a different surface of operational risk, and a depository that can produce all four sits in the upper tier of the market.

Audit pillarStandard / frameworkWhat it actually validatesTypical cadence
SOC 1 Type IIAICPA SSAE 18Internal controls relevant to user-entity financial reporting (the custodian’s trust accounting on the bullion)Annual, covering a 12-month audit period
SOC 2 Type IIAICPA SSAE 18, Trust Services CriteriaSecurity, availability, processing integrity, confidentiality (and optionally privacy) of the systems holding the inventory dataAnnual, covering a 12-month audit period
Independent physical inventory auditIndependent third-party auditor engagementBar-by-bar reconciliation of the vault holdings to the depository’s booksAnnual at minimum, sometimes more frequent
Lloyd’s of London specie insurance certificateLloyd’s specie line policy, all-risk basisAggregate vault limit, per-claim sub-limit, exclusions scheduleRenewed annually with the policy period

Precious metals IRA fee-drag calculator

Precious metals IRAs charge mostly flat dollar fees (setup, annual custodian, storage). Flat fees take a much bigger bite out of a small account than a large one. Enter your numbers to see the drag.

Estimate only. Fee amounts vary by provider and are often not published; enter figures you confirm in writing. This tool ignores metal price changes and the dealer spread, which also affect returns. Not financial advice.

The right dealer explains every fee up front. Get Augusta's free precious metals IRA company checklist.

Each pillar is independent. A depository can hold a SOC 2 Type II report and still miss the annual physical inventory audit. A specie certificate alone does not substitute for the SOC reports, because insurance covers loss after the fact rather than control discipline before it. The retiree confirms the full set, not a subset.

SOC 1 Type II: controls over the custodian’s trust accounting

SOC 1 reports are issued under AICPA Statements on Standards for Attestation Engagements (SSAE) No. 18, formerly SSAE 16. A SOC 1 Type II report covers a defined audit period (typically 12 months) and validates that the service organization’s controls over financial reporting were designed appropriately AND operated effectively across the period.

For a gold IRA depository, the SOC 1 scope covers the controls relevant to the custodian’s financial reporting on the trust assets. That includes the controls around bullion receipt logging, segregated and commingled accounting, inventory reconciliation, and the data feeds that flow from the depository’s books into the custodian’s Form 5498 fair-market-value reporting under IRS Publication 590-A.

The Type II distinction is structural. A Type I report attests only to control design at a single point in time. A Type II report attests to operating effectiveness over the period. Type I is a snapshot. Type II is a film. A retiree screening a depository looks for the Type II report.

SOC 2 Type II: security and processing integrity of the data layer

SOC 2 reports are issued under the same SSAE 18 attestation framework but on the AICPA’s Trust Services Criteria rather than internal-control-over-financial-reporting criteria. The five Trust Services Criteria are security, availability, processing integrity, confidentiality, and privacy. Security is mandatory in every SOC 2 engagement. The other four are scoped at the service organization’s discretion.

For a gold IRA depository, the SOC 2 scope covers the information systems that hold the inventory data and the access controls that govern who can read or modify those systems. Security covers protection against unauthorized access. Availability covers system uptime against the service commitments. Processing integrity covers whether the inventory data is complete, valid, accurate, timely, and authorized end to end.

The retiree does not read the SOC 2 report itself in the usual case. The custodian’s compliance team reads it on the retiree’s behalf as part of the depository-selection due diligence. The retiree confirms the report exists, that it is the Type II variant, and that the audit period is current (the most recent report covers a 12-month window ending within the last 14 months).

How SOC report types differ in audit coverage

The SSAE 18 attestation framework produces four report types: SOC 1 Type I, SOC 1 Type II, SOC 2 Type I, and SOC 2 Type II. Each covers a different scope and a different audit period. The Type I versus Type II distinction is the practical one for a retiree screening a depository.

The chart below shows the audit period each report type covers, measured in months. The Type I reports are point-in-time attestations: control design as of one date. The Type II reports cover a 12-month operating period, which is the structurally stronger evidence of control discipline.

Bar chart of SSAE 18 SOC report audit period coverage in months showing SOC 1 Type I and SOC 2 Type I as zero point in time attestations on control design at a single date and SOC 1 Type II and SOC 2 Type II as twelve month attestations on operating effectiveness over the period the Type II reports providing structurally stronger evidence of control discipline for a gold IRA depository attestation posture
Figure 1. SSAE 18 SOC report audit period coverage in months. Type I reports are point-in-time attestations on control design as of one date. Type II reports cover a twelve-month operating period and are the structurally stronger evidence for a gold IRA depository. Sources: AICPA SOC for Service Organizations framework under SSAE 18.

The practical implication is that a depository representing a SOC report should be specific about the type. SOC 1 versus SOC 2 names the scope. Type I versus Type II names the audit period. A depository that says only that it is SOC-audited without naming the type and the period is not naming the strength of the attestation.

The annual independent physical inventory audit

The SOC reports cover the control environment. The annual physical inventory audit covers the inventory itself: are the bars represented on the books actually present in the vault, in the form, weight, and purity the books report?

An independent third-party auditor (typically a regional or national accounting firm with a precious-metals audit practice) physically enters the vault, samples or fully counts the holdings, and reconciles the count back to the inventory ledger. For segregated storage, the auditor verifies bar serial numbers against the records, weight and purity against the original assay. For commingled storage, the auditor verifies aggregate weight and purity against the pool.

Major US depositories publish summary statements of the audit. The detailed report is typically not released publicly, but the summary statement names the auditor, the audit date, the scope (segregated, commingled, or both), and the result (no exceptions, exceptions noted, etc.). A depository that produces no summary statement on request is not running the audit on a public posture.

The cadence is at minimum annual. Some depositories run more frequent counts on a rolling basis, particularly on segregated storage where bar-level reconciliation is faster on a smaller sample. The annual count is the documented attestation; the rolling counts are operational discipline.

The Lloyd’s of London specie insurance certificate

The fourth audit pillar is the certificate of all-risk specie insurance. The Lloyd’s specie line covers physical damage and theft on bullion and similar high-value movable property. The major US gold IRA depositories all run their insurance posture on this line, with one or more Lloyd’s syndicates underwriting the policy.

The certificate names the aggregate vault limit (the total payable across all claims in the policy period), the per-claim sub-limit (the maximum payable on any single loss event), and the schedule of exclusions. A standard schedule excludes war, nuclear events, government seizure, employee infidelity above named thresholds, and mysterious disappearance without documented chain of custody.

Federal backstop programs do not extend to this layer. FDIC deposit insurance covers bank deposits, not physical bullion. SIPC coverage covers securities held by member broker-dealers, not physical metal in a commercial vault. The all-risk specie certificate is the standalone insurance layer on a gold IRA, and its limits are the binding ceiling on any single loss event.

For a standard balance, the per-claim sub-limit is rarely the binding constraint. For a multi-million-dollar bullion leg, the gap above the per-claim ceiling becomes a planning question. The HNW-specific treatment of the per-claim ceiling and supplemental specie procurement is covered separately.

Chain of custody: how the four pillars protect the bullion in transit

The audit pillars cover the vault at rest. The chain of custody covers the bullion in motion: from the dealer’s vault to the depository, between depositories on a custodian transfer, and from the depository to the retiree on an in-kind distribution.

The procedure runs in five documented stages. Each stage has a defined custody holder, a defined transfer protocol, and a defined insurance attachment. The procedure below describes the stages a retiree (or the custodian) walks through when verifying the audit chain from initial bullion receipt to the steady-state inventory statement.

Flowchart of the five stage chain of custody verification on a gold IRA depository showing stage one dealer assay and shipment manifest stage two depository intake assay and receipt logging stage three vault placement under segregated or commingled storage with serial level reconciliation stage four steady state inventory statements issued quarterly or annually through the custodian to the retiree and stage five movement out of the vault on written instructions from the custodian for sale in kind distribution or custodian to custodian transfer
Figure 2. Chain of custody verification across five sequential stages. Each stage has a defined custody holder, transfer protocol, and insurance attachment. A break in any single stage compromises the audit chain. Sources: AICPA SOC for Service Organizations framework under SSAE 18; Lloyd’s specie line overview.

The five stages are sequential. A break in any single stage compromises the chain. The most common failure point is stage 2 (depository receipt logging) when the dealer’s shipment manifest does not match the depository’s intake assay. The discrepancy surfaces in the SOC 1 control environment, which is one of the reasons the SOC 1 attestation is the structural backstop on the dealer-to-depository handoff.

What the retiree (or custodian) actually verifies before committing

The verification procedure is short. The retiree does not need to read the SOC reports cover to cover or read the specie policy in detail. The retiree confirms the artifacts exist and are current.

  1. SOC 1 Type II report exists and is current. Confirm the report covers a 12-month audit period ending within the last 14 months. Confirm it names a recognized accounting firm as auditor. Confirm the opinion is unqualified (no material exceptions).
  2. SOC 2 Type II report exists and is current. Same checks as SOC 1 on period, auditor, and opinion. Confirm the Trust Services Criteria in scope include security at minimum.
  3. Annual physical inventory audit summary exists. Confirm the summary names an independent third-party auditor, the audit date is within the last 14 months, and the scope covers the storage type relevant to the account (segregated or commingled).
  4. Lloyd’s specie certificate exists and the policy period is current. Confirm the certificate names the aggregate vault limit and the per-claim sub-limit. Confirm the policy period covers the date the retiree opens the account.
  5. The four artifacts are presented through the custodian, not directly by the dealer. The dealer can confirm the depository’s audit posture as part of the planning conversation, but the original artifacts come through the custodian’s compliance pack.

A depository that cannot produce the four artifacts on request is a depository the retiree (or the custodian on the retiree’s behalf) does not commit to. The cost of confirming the four artifacts at the front of the chain is small. The cost of discovering the audit gap after the bullion has landed in the vault is the time and friction of moving the account to a different chain.

Common audit gaps to watch for

A small number of gap patterns recur on the audit side of the depository market. None of them is necessarily fatal, but each is a reason to ask follow-up questions before the chain locks in.

  • Type I only. The depository produces a SOC 1 Type I or SOC 2 Type I report rather than the Type II. The point-in-time attestation is a weaker form of evidence. Ask whether a Type II report is in progress.
  • Stale audit period. The SOC report covers a period ending more than 14 months ago. SSAE 18 reports are intended to be current; a stale report suggests the next audit cycle has slipped.
  • Summary inventory audit without auditor identity. The summary statement names “an independent auditor” without naming the firm. The retiree (or custodian) asks for the firm name; a credible audit names its auditor.
  • Specie certificate aggregate without per-claim sub-limit. The depository markets the aggregate limit without disclosing the per-claim ceiling. For a standard balance the per-claim is not the binding constraint, but the omission is a reason to ask.
  • Bundled custodian-and-depository attestation. The custodian and the depository share a parent company and a single SOC report covers both. The arrangement is not disqualifying, but the structural independence the SOC report normally validates is partially internal.

The gaps surface during the dealer conversation if the dealer is running disciplined process documentation. They stay hidden if the dealer treats the depository as a downstream service the retiree never inspects.

Check this dealer against the 2026 OPRS shortlist before any custodian conversation begins. The dealer-side discipline is the cheapest correction in the audit chain, because it surfaces every gap downstream as a planning conversation rather than as an inventory surprise.

Where Augusta sits in the dealer landscape on this topic

On the depository audit posture, Augusta’s Education-First process, run by salaried non-commissioned educators, surfaces the dealer-custodian-depository chain in the initial conversation rather than burying it inside an order-confirmation packet. The company-comparison checklist is the higher-intent asset for a household screening dealers against the four-marker trust-signal stack before the custodian and depository audit artifacts are reviewed.

Screen the dealer with a company-comparison checklist

The free company-comparison checklist walks through the dealer, custodian, and depository posture a retiree should screen before the audit artifacts are requested. Augusta is one of three dealers OPRS currently clears; the checklist is the higher-intent asset for confirming the four-marker trust-signal stack before the depository chain is selected.

OPRS may receive compensation when readers proceed. Editorial selection is independent. Updated July 2026.

Common questions retirees ask about depository audits

The questions below come up in the first detailed conversation about depository selection. Answers are general; specific cases turn on the custodian agreement, the depository’s published audit posture, and the retiree’s planning horizon.

Is a SOC 1 Type II audit better than a SOC 2 Type II audit?

Neither is better. The two reports cover different scopes. SOC 1 covers the controls relevant to the user entity’s financial reporting (the custodian’s trust accounting). SOC 2 covers the security and processing integrity of the depository’s systems. A credible depository runs both, because each pillar addresses a different risk surface. A depository that runs only one is a depository running a partial audit posture.

Who pays for the audit?

The depository pays for its own SOC reports, its physical inventory audit, and its specie insurance. The cost flows into the storage fees the custodian passes through to the IRA. A retiree does not pay separately for the audit; the storage fee already incorporates the cost.

Can the retiree request a copy of the full SOC report?

The full report is typically issued under a non-disclosure agreement and shared only with user entities (the custodians that contract with the depository) and their regulators. A retiree typically does not receive the full report. The custodian’s compliance team reviews it on the retiree’s behalf. The retiree receives a confirmation that the report exists, the type (Type II), the audit period, and the auditor’s opinion (unqualified or qualified).

What if the depository’s annual audit identifies exceptions?

An exception is not automatic disqualification. The auditor reports the exception, the depository’s management responds with a remediation plan, and the next audit period covers whether the remediation closed the exception. The retiree (or custodian) reviews the nature of the exception. Procedural exceptions on documentation are different in kind from inventory exceptions on bar reconciliation. The latter is a direct concern; the former is a paperwork discipline question.

Does ISAE 3402 substitute for SOC 1 on a non-US depository?

For a gold IRA depository, the question is largely academic. Non-US depositories are not generally available for IRA-side bullion because the trustee qualification under IRC Section 408(n) has been granted only to US-based trustees. A US gold IRA’s bullion stays in a US depository, audited under SSAE 18. The retiree’s planning horizon does not normally cross the SSAE-versus-ISAE boundary.

How does the audit posture interact with the IRS Form 5498 fair-market-value reporting?

The custodian files Form 5498 annually under IRS instructions for Form 5498, reporting the fair market value of the IRA’s assets as of December 31. For a bullion-holding IRA, the value flows from the depository’s inventory data through the custodian’s pricing engine. The SOC 1 control environment covers the control discipline on that data feed. An unaudited inventory feed makes the Form 5498 less defensible if the IRS examines the return.

A retiree weighing a self-directed gold IRA understands the depository’s audit posture as a precondition for trusting the inventory statement, not as a back-office detail. Four pillars carry that posture together: SOC 1 Type II, SOC 2 Type II, the annual physical inventory audit, and the Lloyd’s specie certificate. They attest to the discipline that keeps bars in the vault matched to books on the account.

The dealer-side discipline pulls those four pillars forward, into the planning conversation, before the custodian relationship locks in. A dealer that skips the audit conversation defaults the retiree onto whichever audit posture is downstream of the custodian’s commercial relationships, audited or not. A retiree’s cheapest correction is dealer screening. The audit posture, the storage type, and the insurance posture cascade from that initial choice for the next generation of the household’s planning paperwork.

Sources cited

  1. IRC Section 408(a) and 408(n), Individual Retirement Account Trustee Requirements
  2. Treasury Regulation 1.408-2, Individual Retirement Accounts (Non-Bank Trustee Requirements)
  3. IRS Publication 590-A, Contributions to Individual Retirement Arrangements
  4. IRS Publication 590-B, Distributions from Individual Retirement Arrangements
  5. IRS Instructions for Form 5498, IRA Contribution Information
  6. AICPA SOC for Service Organizations, SSAE 18 Attestation Framework
  7. Lloyd’s of London, Specie Insurance Industry Overview
  8. FDIC, Deposit Insurance Coverage Categories and Limits
  9. SIPC, What SIPC Protects and What SIPC Does Not Protect
  10. FINRA Investor Insights, Gold and Other Precious Metals

More on OPRS