Do We Agree on What an “Audit” Is? Toward Standardized Smart Contract Audit Reporting

dc.contributor.authorQasse, Ilham Ahmed
dc.contributor.authorHjálmtýsson, Gísli
dc.contributor.authorHamdaqa, Mohammad
dc.contributor.departmentDepartment of Computer Science
dc.date.accessioned2026-09-02T11:33:01Z
dc.date.available2026-09-02T11:33:01Z
dc.date.issued2026-07-31
dc.description.abstractSmart contract security audits are essential for trust in decentralized finance (DeFi), yet audit reports from different firms vary widely in scope definition, severity labels, fix verification, and report structure. These differences make it hard for developers, users, and other stakeholders to assess risk. In this paper, we address these issues by empirically analyzing 160 audit reports from 26 leading auditing firms to uncover patterns and gaps in current practices. Using qualitative content analysis, we extract a taxonomy of 19 common properties that audit reports include (or omit). We then apply Formal Concept Analysis (FCA) to identify five distinct “report style families” used by auditors, and perform a temporal trend analysis to see if the industry is converging on certain best practices. Finally, we synthesize a feature model that specifies a minimal defensible baseline for audit reports, distinguishing mandatory sections from optional extensions to support traceability and consistent interpretation across reports. This model enables reproducible comparisons across auditors, strengthens accountability for scope definition and fix verification, and provides an evidence base to improve the quality and uniformity of smart contract audit reporting.en
dc.description.versionPeer revieweden
dc.format.extent802137
dc.format.extent435-445
dc.format.extent
dc.identifier.citationQasse, I A, Hjálmtýsson, G & Hamdaqa, M 2026, Do We Agree on What an “Audit” Is? Toward Standardized Smart Contract Audit Reporting. in MSR '26 : Proceedings of the 23rd International Conference on Mining Software Repositories. Proceedings of the 23rd International Conference on Mining Software Repositories, Association for Computing Machinery, Inc, pp. 435-445. https://doi.org/10.1145/3793302.3793370en
dc.identifier.doi10.1145/3793302.3793370
dc.identifier.other250709168
dc.identifier.other18e60ecd-ee00-4a0b-ae37-57a9cd3d0679
dc.identifier.otherunpaywall: 10.1145/3793302.3793370
dc.identifier.urihttps://hdl.handle.net/20.500.11815/8149
dc.language.isoen
dc.publisherAssociation for Computing Machinery, Inc
dc.relation.ispartofseriesMSR '26; ()en
dc.relation.ispartofseriesProceedings of the 23rd International Conference on Mining Software Repositories; ()en
dc.rightsinfo:eu-repo/semantics/openAccessen
dc.titleDo We Agree on What an “Audit” Is? Toward Standardized Smart Contract Audit Reportingen
dc.type/dk/atira/pure/researchoutput/researchoutputtypes/contributiontobookanthology/conferenceen

Skrár

Original bundle

Niðurstöður 1 - 1 af 1
Nafn:
3793302.3793370.pdf
Stærð:
783.34 KB
Snið:
Adobe Portable Document Format