The deed and the investment strategy
Two documents must permit the investment before a single satoshi is bought. The trust deed must not prohibit cryptocurrency, and the fund's investment strategy must expressly contemplate it, addressing risk, return, diversification, liquidity and the ability to discharge liabilities.
A generic strategy that only mentions 'shares, property and cash' does not cover Bitcoin. Auditors raise this every year and it is entirely avoidable.
Separation of assets is the big one
SIS Regulation 4.09A requires fund assets to be held separately from those of members and related parties. In practice this means the Bitcoin must be held in a wallet or exchange account in the name of the fund or its corporate trustee - not in the member's personal wallet, and not in a wallet that also contains personal coins.
Mixing personal and fund Bitcoin in the same wallet is the most common serious breach we see. It is very hard to unwind after the fact and it is exactly what an auditor is looking for.
Sole purpose and personal use
The sole purpose test requires the fund to be maintained solely to provide retirement benefits. Using fund Bitcoin to buy anything, borrowing against it personally, or storing it on a device used for personal spending all put the fund's complying status at risk.
Related-party acquisition rules also apply: a member generally cannot sell their personal Bitcoin into their own SMSF, because crypto is not on the narrow list of assets that can be acquired from related parties.
Evidence, valuation and audit
Every year the auditor needs proof of ownership and value at 30 June. That means wallet addresses attributable to the fund, exchange statements in the fund's name, a documented valuation source, and a signed trustee minute for the investment decision.
Where the fund self-custodies, the auditor will want evidence linking the wallet to the trustee. Prepare this at setup - reconstructing it later is painful.
Where most setups go wrong
The pattern is consistent: the deed was never checked, the strategy was never updated, the coins sit in the member's personal Ledger, no minute was ever signed, and the 30 June valuation is a screenshot from a phone. Each item is small; together they are a qualified audit and a potential compliance notice.
Getting the custody structure right at the start - fund-titled accounts or documented fund-only self-custody, ideally multisig - solves most of it permanently.

