The Arithmetic of Trust
Verifiable accounting arithmetic without disclosure — why the next age of audit will not be built on more documents, but on proofs
Keywords: accounting information systems; audit evidence; zero-knowledge proofs; Merkle proofs; private verification; commitments; disclosure; blockchain evidence; verifiable arithmetic; digital cash systems; proof retrieval; accounting assurance; information asymmetry; costly state verification.
I. The Old Vice of Accounting: Everyone Wants Truth, Nobody Wants Disclosure
Accounting is the civilisation of facts dressed in the costume of numbers.
A ledger is not merely a list. It is a claim about the world. It says: this was earned, this was owed, this was paid, this was received, this was carried forward, this was reconciled, this was deducted, this was impaired, this was recognised, this was not. It is prose in numerical form, and like all prose it may be honest, artful, evasive, precise, or magnificently fraudulent.
The old problem was never that firms lacked records. They have always had records. They have records stacked upon records: invoices, ledgers, purchase orders, receipts, confirmations, bank statements, reconciliations, journal entries, tax schedules, warehouse notes, shipping records, ERP logs, approval trails, and reports produced for people who forgot why they asked for them. The bureaucracy of evidence has not starved accounting. It has fattened it.
The problem is that records are not truth. They are assertions.
An invoice asserts a sale. A receipt asserts payment. A ledger asserts classification. A reconciliation asserts correspondence. A report asserts aggregation. An audit file asserts that some mortal with a deadline and professional liability examined enough of this paper civilisation to say, in careful language, that the financial statements are not materially misstated.
Modern commerce is built on this elegant unease.
The buyer wants privacy. The seller wants privacy. The auditor wants evidence. The lender wants confidence. The regulator wants compliance. The tax authority wants calculation. The investor wants assurance. The market wants information. The firm wants confidentiality. Everyone wants truth, but nobody wants to undress in public.
That is the central conflict.
Full disclosure gives verification but destroys commercial privacy. Redaction protects privacy but destroys verification. Sampling reduces workload but leaves doubt. Management summaries preserve convenience but produce the oldest and least charming object in business: trust me.
Trust me is not an accounting control. It is a prayer said by someone holding the pen.
The next development in accounting information systems must therefore answer a sharper question:
Can accounting arithmetic be verified without disclosing the underlying accounting values?
Not merely whether a record exists. Not merely whether an invoice was time-stamped. Not merely whether a hash appears somewhere in a public medium. Those are useful, but partial. The real question is whether one can prove that the hidden values inside a private accounting system satisfy an equation: that the receivables roll-forward balances; that gross equals net plus tax less discount; that debits equal credits; that bank reconciliation items reconcile; that VAT payable follows from input and output tax; that an aggregate disclosure follows from committed components.
The answer is yes.
And its importance is not technical ornament. It is institutional.
It changes what accounting systems can produce. They no longer produce only records. They produce proofs.
II. From the Age of Documents to the Age of Proof
A document asks to be believed.
A proof demands to be checked.
This is the great distinction. It is also the distinction that accounting, for all its ritual solemnity, has not yet absorbed deeply enough.
The ordinary accounting process is document-centred. A firm issues an invoice. The counterparty receives it. The ERP records it. The payment system moves money or claims to have done so. The auditor later asks for documents. Documents are produced. Some are sampled. Some are traced. Some are vouched. Some are confirmed externally. Some are reconciled to other documents. The entire discipline is an elaborate choreography of one document bowing to another.
That choreography matters. It is not obsolete. But it is incomplete.
The weakness of documents is that they can be selected, altered, reconstructed, misclassified, redacted, or simply misunderstood. A document does not automatically carry with it proof that it belonged to a defined evidence population, that it was committed before the audit began, that it was not substituted, that its hidden components add correctly, or that the aggregate now disclosed follows from the components then recorded.
A cryptographic commitment changes part of this. It allows a party to bind itself to a value while keeping that value hidden. A Merkle proof changes another part. It allows a verifier to establish that a particular data item or transaction belongs to a larger anchored structure without receiving the whole structure. A zero-knowledge proof changes the arithmetic part. It allows a prover to demonstrate that hidden values satisfy a defined calculation without revealing those values.
Individually, these are technical mechanisms. Together, they become an accounting architecture.
The architecture is simple in principle:-
Accounting values are captured in an ERP or accounting system.
-
Each value is committed, meaning fixed but hidden.
-
Commitments are included in an evidence population.
-
A Merkle proof entity proves that the relevant commitment or transaction exists in the anchored population.
-
A selective proof-retrieval layer retrieves only the Merkle proof fragments needed for a verifier’s query.
-
A zero-knowledge proof demonstrates that the hidden committed values satisfy a specified accounting equation.
-
The verifier learns that the calculation is correct, but does not learn the underlying values.
-
Selective disclosure remains possible for authorised fields, exceptions, samples, or disputes.
This is not magic. It is better than magic. Magic asks for awe. This asks for verification.
The old document economy says: here are the records, inspect them.
The new proof economy says: here are the commitments, here is their inclusion proof, here is the arithmetic proof, here are the exact limits of what has been proven.
That last phrase matters: the exact limits.
No serious accounting system should claim more than it proves. The market is already cluttered with fashionable inventions that confuse a timestamp for truth and a ledger entry for economic reality. A proof of inclusion does not prove delivery. A signature does not prove commercial substance. A zero-knowledge proof does not prove that management was honest. It proves the statement encoded in the proof system. No more. No less.
The virtue of the new architecture is not that it proves everything. It is that it proves something narrow, valuable, and previously difficult to prove without disclosure.
It proves arithmetic over private accounting data.
III. The Scandal of Redaction
Redaction is the confession that privacy and verification have not yet been reconciled.
A firm hands over a document with black bars laid across the sensitive parts. The verifier sees structure without substance. The firm says: the hidden parts are confidential. The verifier says: but those hidden parts are exactly what I would need to recalculate the total. The firm says: you must trust the total. The verifier says: then why did you bring me the document?
Redaction is often necessary. It is also often absurd.
It preserves secrecy by injuring evidence. It is the veil that makes the witness less useful. It may protect customer names, prices, discounts, margins, bank details, or contractual terms, but it usually destroys the ability to verify the computation. If the unit price is hidden, the quantity is hidden, and the discount is hidden, what does the invoice total prove? It proves that the visible number is visible. A triumphant accomplishment, no doubt, for those who consider opacity a control environment.
Verifiable accounting arithmetic without disclosure changes this.
The firm need not reveal the unit price, quantity, discount, or tax detail. It can commit to those values. It can prove that the gross invoice amount equals the sum of the hidden line items plus tax less discount. It can reveal the gross amount if authorised, or keep even that hidden if the verification purpose only requires equality or compliance. It can prove range constraints: that values are non-negative, that they fall within permitted bounds, that no overflow trick has been used, that the tax rate belongs to an authorised set, that the same value was not duplicated in the calculation.
The verifier does not see the commercial secret. The verifier does not accept a blind assertion. Both sides gain something better than compromise: they gain a proof.
This is what makes the idea more than another ornamental blockchain proposal. It solves a real institutional conflict.
Markets need information. Firms need secrecy. Auditors need evidence. Regulators need compliance. Lenders need covenant assurance. Tax authorities need arithmetic. Counterparties need confidence. Competitors need to know nothing.
The current institutional answer is often full disclosure under confidentiality, selective disclosure under professional privilege, or summary disclosure with trust. Each has its place. None resolves the fundamental contradiction. The proposed architecture does.
It allows verification without exposure.
In a world where data is both an asset and a liability, that is not a marginal improvement. It is a new instrument.
IV. Merkle Proofs: The Certificate That the Evidence Exists
The first layer of the architecture is evidence presence.
A calculation over hidden values is useless if the hidden values can be invented after the fact. A firm cannot be allowed to say: here are some secret numbers, believe that they came from the actual books, and admire this proof that they add correctly. Fraud can add. Fraud has always been excellent at arithmetic.
So the values used in the proof must be tied to an evidence population that existed at the relevant time.
This is where Merkle proof infrastructure matters.
A Merkle proof allows a verifier to check that a data item belongs to a larger set represented by a root. It does not require the verifier to receive the whole set. It uses a path of hashes from the item to the root, allowing membership to be checked efficiently. That is not an accounting conclusion; it is an inclusion conclusion. It says: this item belongs to that committed structure.
The Merkle Proof Entity patent, WO 2022/100946 A1, describes a method and entity for providing proof that target data of a blockchain transaction exists on a blockchain. The entity obtains or uses a transaction identifier, Merkle root, target block hash, and Merkle proof so that a requesting party can verify that the target blockchain transaction exists as part of the target blockchain transaction on the blockchain. In accounting terms, this supplies the presence layer: the commitment or evidence object is not merely claimed; its inclusion can be proven.
The later patent publication, WO 2025/119666 A1, titled “Method and System for Enabling Verification of Data,” extends the problem from single proof provision to efficient proof management. It describes generating Merkle proof data for selected transaction parts, storing that proof data, publishing proof-assistance data, dividing Merkle proof data into portions, indexing those portions, and retrieving proof fragments. This matters because large accounting systems do not produce one invoice and then retire to a hilltop. They produce millions of events.
Proofs must scale.
A naive system stores everything, repeats everything, discloses too much, and then wonders why nobody wants to use it. A serious accounting information system must retrieve only the proof fragments needed for a particular assertion, sample, exception, reconciliation, or audit query. Many records in a batch or period share parts of the same proof structure. Those shared parts should not be stored endlessly like bureaucratic wallpaper. They should be sharded, indexed, retrieved, and verified.
This is the move from proof as a curiosity to proof as infrastructure.
The Merkle layer answers the question:
Did this committed accounting value belong to the anchored evidence population?
It does not answer:
Was the accounting calculation correct?
That second question belongs to zero-knowledge arithmetic.
V. Commitments: The Locked Box That Still Casts a Shadow
A commitment is a locked box with a public silhouette.
It hides the value but fixes it. A party cannot later change the value without detection, yet the verifier need not see the value at the time of commitment. This is precisely the property accounting needs when secrecy and assurance collide.
For accounting, the committed object may be:-
an invoice line amount;
-
a tax amount;
-
a gross invoice amount;
-
a payment value;
-
a receivable movement;
-
a credit note;
-
a write-off;
-
a bank reconciliation item;
-
an inventory quantity;
-
a depreciation charge;
-
an accrual;
-
a deferred revenue movement;
-
a covenant input;
-
a VAT/GST field;
-
an ESG measurement.
The system commits to the value. The value remains hidden. Later, the party can selectively open it, or prove arithmetic about it without opening it.
The elegance is severe.
A commitment stops the dishonest party from enjoying both secrecy and flexibility. One may hide the value, but one may not change it at leisure. This is the basic moral structure of cryptographic accounting: privacy without opportunistic revision.
It is not enough, however, merely to commit to values. A bag of hidden commitments is not accounting. It is a locked drawer full of numbers no one can see. Accounting requires relationships among values. It requires equations.
Gross equals net plus tax less discount.
Closing receivables equal opening receivables plus invoices less receipts, credit notes, and write-offs.
Debits equal credits.
Book cash reconciles to bank balance through reconciling items.
VAT payable equals output VAT less input VAT.
Inventory closing quantity equals opening quantity plus purchases less sales, wastage, shrinkage, or transformation.
Commitments bind the numbers. Zero-knowledge proofs verify the relationships.
VI. Zero-Knowledge Arithmetic: The Proof That Refuses to Gossip
Zero-knowledge proof is the rare technical phrase that sounds more mystical than it is.
Its principle is clean: one party proves a statement is true without revealing the secret information that makes it true.
In accounting, that means a firm can prove that hidden committed values satisfy a calculation without showing those values.
This is not concealment pretending to be evidence. It is evidence designed not to reveal more than the verifier is entitled to know. There is a moral clarity in that. Disclosure should not be an indiscriminate strip search. It should be disciplined by purpose.
Consider a receivables roll-forward:
Closing accounts receivable equals opening accounts receivable plus invoices issued less cash receipts, credit notes, and write-offs.
A lender may need assurance that the roll-forward is arithmetically correct. But the borrower may not be able to disclose customer-level balances, prices, payment timings, credit notes, disputes, or write-off detail. Under the old regime, one party demands disclosure and the other demands secrecy. The negotiation then descends into the usual theatre of confidentiality agreements, summaries, samples, and professional assurances.
Under the new architecture, the firm commits to the underlying values. The commitments are tied to an anchored evidence population. A zero-knowledge proof demonstrates that the hidden values satisfy the roll-forward equation. The verifier checks the proof. Specific items can be selectively opened later for sampling, exception testing, or legal necessity.
The lender learns what it needs: the arithmetic works over the committed population.
The firm reveals what it chooses or is required to reveal: not the whole private commercial anatomy.
This is not a substitute for audit. It is a better evidentiary object inside audit.
A zero-knowledge proof cannot prove that the invoices were legitimate. It cannot prove that goods were delivered. It cannot prove that a write-off was reasonable. It cannot prove that recognition complied with IFRS 15 or ASC 606. It cannot prove that management did not collude. It cannot prove that a hidden value corresponds to economic reality unless the value is itself tied to reliable source evidence.
It proves the encoded arithmetic statement.
That may sound modest only to those who have never watched institutions spend fortunes verifying arithmetic through documents they are not allowed to fully see.
VII. The Five Equations That Matter
The importance of verifiable accounting arithmetic becomes clearer when seen through ordinary accounting equations.
1. Invoice arithmetic
Gross equals net plus tax less discount.
This is the small equation that governs millions of commercial events. A buyer, auditor, tax authority, or counterparty may need to know that invoice arithmetic is correct. But line-item pricing, quantity, discount, or margin may be commercially sensitive.
A private arithmetic proof can establish that the visible or hidden gross amount follows from committed hidden components. It can also prove that tax rates are drawn from an authorised set, that values are non-negative, and that no arithmetic overflow has been used.
The invoice becomes selectively verifiable, not merely redacted.
2. Receivables roll-forward
Closing receivables equal opening receivables plus invoices less cash receipts, credit notes, and write-offs.
This is the most powerful example because it cuts through the heart of audit evidence. Receivables are sensitive. Customer identities are sensitive. Payment timings are sensitive. Discounts and disputes are sensitive. Yet lenders, auditors, investors, and regulators often need assurance over receivables movement.
A private proof can establish that the roll-forward balances over committed values without revealing customer-level data. Selective disclosure can then be reserved for samples, exceptions, and high-risk items.
3. Debit-credit equality
Total debits equal total credits.
This is the ancestral equation of double-entry bookkeeping. It is not sufficient for truth, but it is necessary for structure. A private proof can show that a hidden set of journal entries balances without disclosing the account-level or transaction-level detail.
That matters for staged assurance, covenant monitoring, group reporting, and confidential subsidiary reporting.
4. Bank reconciliation
Book cash plus or minus reconciling items equals external bank balance.
The difficulty here is that bank data, outstanding payments, deposits in transit, and timing differences may be sensitive. A proof can establish reconciliation arithmetic over committed values while leaving underlying items hidden unless selected for inspection.
It does not prove that the bank balance is genuine unless the bank-side evidence is independently reliable. But it can prove that the reconciliation computation is correct.
5. Tax arithmetic
VAT or GST payable equals output tax less input tax.
Tax authorities require calculation. Firms fear disclosure beyond lawful necessity. A system that proves the arithmetic of tax over committed invoices can support staged compliance: arithmetic proof first, selective disclosure second, full inspection only where required.
The civilised state should prefer proofs to fishing expeditions.
VIII. Why This Matters to Audit
Audit is not arithmetic. But audit contains arithmetic.
The distinction matters.
A financial statement audit is not a mechanical recalculation exercise. It involves risk assessment, professional scepticism, internal control understanding, substantive procedures, analytical review, judgement, materiality, estimation uncertainty, fraud risk, external confirmation, and evidence evaluation. No cryptographic proof abolishes that.
But many audit procedures depend on verifying calculations over data: totals, roll-forwards, reconciliations, allocations, cut-off populations, tax schedules, depreciation, interest, inventory movement, revenue deferrals, and account balances. Today, the auditor typically verifies these through access to the underlying data, samples, reconciliations, reports, or re-performance.
Private arithmetic assurance changes the menu.
It allows an auditor or assurance provider to verify that a calculation is correct over a committed population before, or alongside, selective disclosure. It allows full-population arithmetic testing without full-population value disclosure. It gives a stronger basis for deciding where to sample, where to demand documents, and where to focus scepticism.
This is especially important in continuous auditing. IJAIS research has long explored continuous monitoring, process mining, data-level audit systems, and blockchain-enabled audit possibilities. The direction is clear: audit moves from periodic document inspection toward data-driven, system-level assurance. But data-driven assurance has its own vice: the more data one demands, the more one collides with privacy, confidentiality, commercial sensitivity, and governance limits.
A private arithmetic proof layer offers a way through.
It is not continuous surveillance. It is not bulk extraction. It is not a demand that all parties surrender their books because technology has become nosy enough to ask. It is a disciplined proof mechanism that lets a verifier test specific assertions.
The auditor does not need to see everything to know something.
That is not weakness. It is precision.
IX. Why This Matters to Lenders, Regulators, and Markets
The usefulness of private arithmetic assurance extends beyond audit.
A lender may need covenant assurance. The borrower may not wish to disclose every component behind EBITDA, receivables, cash, leverage, inventory, or working capital. A zero-knowledge proof can establish that the covenant calculation follows from committed values, subject to agreed definitions.
A regulator may need compliance evidence. A firm may not wish to expose unrelated commercial data. A proof can show that a calculation satisfies the regulatory formula, while preserving selective disclosure for investigation.
A tax authority may need confidence in return arithmetic. A firm may resist broad document production where no risk is identified. Proof can separate arithmetic assurance from inspection.
An insurer may need exposure calculations. A customer may need proof that a supplier meets threshold requirements. A platform may need proof of reserve ratios or settlement balances. A group parent may need assurance from subsidiaries operating in sensitive markets. An investor may need confidence in aggregate metrics without seeing trade secrets.
All of these are forms of the same institutional problem: one party needs assurance; another party has legitimate reasons not to disclose the full underlying data.
Economics has long recognised the cost of verification. Townsend’s costly state verification framework matters because it explains why contracts and institutions are shaped by the cost of discovering the true state of the world. Disclosure theory likewise shows that information is not free, not neutral, and not automatically revealed. Firms disclose strategically; markets interpret signals; information asymmetry has consequences.
Private arithmetic assurance reduces a specific verification cost.
It does not eliminate costly state verification. It refines it. Instead of verifying everything by inspection, the verifier can demand proof of defined relationships and reserve deeper inspection for exceptions, samples, and substantive claims.
This changes institutional design.
The more cheaply and privately parties can verify agreed calculations, the more precisely contracts, covenants, reporting systems, and assurance workflows can be written.
In plainer language: when proof becomes cheaper, trust becomes less theatrical.
X. Why Merkle Proofs Alone Are Not Enough
A Merkle proof can show that a value, commitment, or transaction belongs to a set.
That is essential. It is not sufficient.
A receipt may be included in a block and still be irrelevant. An invoice may be anchored and still be false. A set of commitments may be present and still not add to the disclosed total. A beautifully indexed proof store may retrieve evidence that proves only that the wrong thing was preserved very efficiently.
Presence is not arithmetic.
Inclusion is not correctness.
The Merkle layer must therefore be subordinated to the accounting question. It should not become another idol. The purpose is not to admire Merkle paths. The purpose is to prove that the values used in the arithmetic proof are the same committed values that belonged to the relevant evidence population.
The sequence matters:-
Commit to values.
-
Anchor commitments.
-
Prove inclusion.
-
Retrieve proof efficiently.
-
Prove arithmetic over those commitments.
-
Selectively disclose where necessary.
-
State the audit boundary.
Miss any step, and the system weakens.
Without commitments, the values can be changed. Without Merkle inclusion, the commitments may float outside the evidence population. Without proof retrieval, the system may not scale. Without zero-knowledge arithmetic, the verifier learns only that data existed, not that the calculation works. Without range proofs, hidden negative values or overflow tricks may corrupt the result. Without audit boundaries, the system becomes another carnival of technological overclaim.
The serious architecture is not one trick. It is a hierarchy of proofs.
XI. Why Zero-Knowledge Proofs Alone Are Not Enough
The reverse error is equally dangerous.
A zero-knowledge proof can prove that hidden numbers satisfy an equation. But if those hidden numbers are not tied to the accounting evidence population, the proof may be irrelevant. A conjurer can prove a theorem about numbers he invented that morning. Accounting needs proof about numbers that belong to the books.
So the zero-knowledge layer must be anchored to commitments, and the commitments must be anchored to evidence populations, and the evidence populations must be retrievable and verifiable.
A proof that says “these hidden values add correctly” is useful only if the verifier can also know which hidden values they are.
This is why the integration matters.
The Merkle Proof Entity supplies evidence presence. The selective proof-retrieval system supplies scalable proof availability. Commitments supply hidden binding values. Zero-knowledge proofs supply arithmetic assurance. Range proofs supply numerical validity. Audit mapping supplies professional meaning.
No single layer does the whole job.
Accounting is a systems discipline. A proper solution must be a system.
XII. The Reviewer’s Objection, Answered Before It Is Asked
The sensible reviewer will ask: what does this prove?
The answer must be precise.
It proves that committed values included in an anchored evidence population satisfy a specified accounting equation.
The reviewer will ask: does it prove the values are true?
No. It proves they are committed and arithmetically related. Truth requires source evidence, controls, external confirmation, legal context, physical reality, and professional judgement.
The reviewer will ask: does it prove completeness?
Only if the population controls are strong enough to establish that the committed population is complete. Otherwise, it proves arithmetic over the committed population, not over the universe of omitted transactions.
The reviewer will ask: does it replace audit?
No. It supplies a new class of audit evidence.
The reviewer will ask: does it prevent fraud?
No. It raises the cost of certain frauds and makes later alteration more difficult. Collusive false origination remains possible. So does misclassification. So does sham commercial activity.
The reviewer will ask: does it protect all privacy?
No. It protects values from disclosure under the proof design. It does not automatically eliminate timing analysis, batching inference, record-size leakage, network-origin leakage, or authorised-party disclosure.
The reviewer will ask: is this merely cryptography?
No. It is an accounting information systems artefact: a workflow integrating ERP capture, commitment, evidence anchoring, proof retrieval, private arithmetic verification, selective disclosure, audit assertion mapping, and limitation reporting.
The reviewer will ask: what is new?
The integration is new as an AIS contribution. Merkle proofs exist. Commitments exist. Zero-knowledge proofs exist. Audit arithmetic exists. The contribution is the architecture that turns these mechanisms into private arithmetic assurance over anchored accounting evidence.
The reviewer will ask: why should an accounting journal care?
Because the artefact changes what accounting systems can provide as evidence.
That is enough.
XIII. The Five Core AIS Conversations It Extends
This idea does not appear from nowhere. It extends five existing conversations in accounting information systems.
First, blockchain-accounting literature has examined event accounting, real-time accounting, triple-entry accounting, and continuous auditing. That literature established the possibility that shared or anchored records may change accounting evidence.
Second, blockchain adoption literature has warned that accounting technology is too often overpromised and under-implemented. Any serious contribution must therefore move beyond enthusiasm into specific artefacts, workflows, evaluation, and limitations.
Third, smart-contract auditing work has shown how audit rules may be encoded and executed to flag suspicious activity. But rule execution is not the same as private arithmetic proof. A smart contract may detect a visible breach; it does not necessarily prove a hidden receivables roll-forward without disclosure.
Fourth, continuous monitoring research has long treated audit as a system-level process rather than an occasional document hunt. Private arithmetic assurance fits this trajectory because it creates a persistent verification layer over accounting data.
Fifth, layered audit-system research shows that audit technologies work best when separated into functions: data capture, analysis, detection, evaluation, and reporting. The proposed architecture does the same: commitment, inclusion, retrieval, arithmetic proof, range proof, selective disclosure, and audit conclusion.
That is the journal fit.
The idea does not ask accounting information systems to become cryptography. It asks accounting information systems to use cryptography where accounting has a verification problem.
The result is not a cryptographic paper with accounting examples. It is an accounting systems paper with cryptographic machinery.
XIV. The Public Medium Is Not a God
A public anchor is a control dependency, not a deity.
Too many blockchain proposals make the same intellectual error: they put something “on-chain” and then bow as if truth had entered the room wearing a crown. But a public medium proves only what its design permits it to prove: ordering, inclusion, persistence, and tamper evidence under its own assumptions. It does not prove commercial reality.
For private arithmetic assurance, the public medium must satisfy minimum requirements:-
append-only or tamper-evident persistence;
-
independently verifiable ordering;
-
durable availability;
-
documented finality;
-
retention over the relevant accounting period;
-
protection against undetected equivocation;
-
a clear archive and reconstruction process;
-
governance suitable for audit reliance.
A proof server must likewise be treated carefully. It may retrieve proof fragments; it must not become the source of truth. If the proof server lies, the proof should fail. If it withholds, availability is impaired, but false verification should not result. The verifier’s trust should terminate in independently checkable commitments, Merkle roots, anchors, and proof verification.
This is the difference between infrastructure and authority.
A proof-retrieval layer is a servant. It is not the master.
XV. A Private Proof Is Not a Private Lie
There will be a predictable objection from those who confuse disclosure with honesty.
They will say: if the values are hidden, the system is opaque.
That is wrong. Hidden is not the same as unverifiable. A sealed safe is opaque. A mathematical proof about the contents of the safe is evidence. The entire point is to replace naked disclosure with disciplined verification.
The crude mind recognises only two states: reveal everything or trust nothing. Commerce cannot live that way. Neither can audit. Neither can markets. All real institutions operate between secrecy and disclosure. The question is whether that middle ground is governed by vague assurance or formal proof.
Private arithmetic assurance says: do not reveal what need not be revealed; prove what must be proven.
That is not secrecy against accountability. It is accountability without indiscretion.
A firm should not be required to expose every customer, price, discount, supplier, margin, tax detail, and operational weakness merely to prove that a roll-forward adds. A regulator should not need to seize the entire commercial diary to check a calculation. A lender should not need customer-level receivables to verify covenant arithmetic unless the credit agreement requires deeper disclosure. An auditor should not confuse full access with better evidence when a proof can provide a stronger initial test.
Disclosure is costly. Exposure is risky. Data, once shared, does not politely return home.
The proof is the civilised alternative.
XVI. What Could Go Wrong
Every powerful idea deserves suspicion.
The first risk is garbage in. If management commits false values, the proof may confirm arithmetic over false values. That is not a failure of the arithmetic proof. It is the eternal accounting problem: representation must be tied to source evidence and controls.
The second risk is incomplete population. A firm can prove arithmetic over the records it committed while omitting records outside the population. Completeness must be addressed by population controls, system boundaries, reconciliation to external sources, sequence checks, and audit procedures.
The third risk is circuit error. A zero-knowledge proof proves the circuit it encodes. If the accounting rule is wrongly encoded, the proof may be perfectly correct and economically useless. Circuit governance, review, version control, and reproducibility are essential.
The fourth risk is parameter or setup risk. Some proof systems require setup assumptions. These must be disclosed, governed, and suitable for the assurance context.
The fifth risk is metadata leakage. Even if values remain hidden, timing, frequency, payload size, batching, and request patterns may reveal information. Operational privacy requires design, not slogans.
The sixth risk is legal misunderstanding. Technical proof is not legal admissibility. It may support evidence; it does not automatically decide enforceability, rights, obligations, or liability.
The seventh risk is worship. The industry may start saying that because arithmetic has been proven, the accounts are true. That would be the usual degradation of a good idea by bad marketing. Arithmetic proof is not audit opinion. It is a component of evidence.
These limitations do not weaken the idea. They make it usable.
The honest system says exactly what it proves. The dishonest one sells certainty by the pound.
XVII. Why It Is Important
This is important because accounting has reached the limit of document-centred verification.
The volume of records is too large. The sensitivity of data is too high. The demand for assurance is too broad. The cost of disclosure is too great. The expectation of real-time or near-real-time verification is rising. The institutional appetite for trust me is shrinking.
A modern accounting information system should be able to answer not only:-
What did you record?
-
When did you record it?
-
Who approved it?
-
Where is the document?
-
Does the counterparty confirm it?
but also:-
Can you prove this hidden calculation is correct?
-
Can you prove the values used were committed before the dispute?
-
Can you prove they belong to the relevant evidence population?
-
Can you prove no value is negative where it cannot be negative?
-
Can you prove this aggregate follows from the undisclosed components?
-
Can you disclose only the exception, not the whole population?
That is a different class of accounting system.
It is not a ledger with better storage. It is a ledger with evidentiary intelligence.
The importance is also theoretical. Information asymmetry is not merely a market inconvenience. It shapes contracts, lending, valuation, governance, disclosure, regulation, and audit. Costly state verification is not an academic curiosity. It explains why institutions simplify, collateralise, audit, insure, covenant, disclose, conceal, and litigate.
Reduce the cost of verification, and institutional form changes.
Allow private verification, and the disclosure frontier changes.
Permit arithmetic assurance without exposure, and the bargaining position of firms, auditors, lenders, regulators, and counterparties changes.
It is fashionable to speak of transparency as if it were always a virtue. It is not. Transparency without purpose is voyeurism with a spreadsheet. The better virtue is verifiability. Verifiability asks for proof, not spectacle.
Accounting does not need a glass house.
It needs stronger walls with better windows.
XVIII. The Future Shape of Assurance
The future will not abolish auditors. It will humiliate bad audit evidence.
The future audit file should not be a museum of PDFs. It should contain verifiable commitments, inclusion proofs, arithmetic proofs, selective disclosures, exception trails, source evidence, professional judgements, and explicit limitation statements. The auditor should not merely inspect documents produced after year-end; the auditor should verify evidence generated at the time of transaction and calculation.
The firm should not merely export reports; it should produce proofs.
The lender should not merely receive management schedules; it should verify covenant arithmetic.
The regulator should not merely demand data dumps; it should require proof, then inspect where proof fails, risk rises, or law requires disclosure.
The tax authority should not merely hope that arithmetic follows from invoices; it should be able to verify tax computations over committed records.
The market should not demand that every secret be made public. It should demand that the claims made from secrets be provable.
That is the civilised line.
A commercial society does not thrive by abolishing privacy. Nor does it thrive by tolerating unverifiable claims. It thrives when property, contract, evidence, and accountability are joined without forcing every private fact into the street.
Verifiable accounting arithmetic without disclosure serves that end.
It allows a firm to say:
I will not show you every value.
But I will prove that the values I committed satisfy the equation.
I will not expose every customer.
But I will prove that the aggregate follows from committed customer-level records.
I will not hand you every transaction unless required.
But I will prove the calculation and open the exceptions.
I will not confuse secrecy with immunity.
And you will not confuse curiosity with entitlement.
That is not merely technical progress. It is institutional refinement.
XIX. Conclusion: Proof Is the Discipline of Civilised Distrust
The finest systems are not built for saints. They are built for men as they are: ambitious, secretive, rational, frightened, inventive, vain, occasionally honest, frequently tempted, and always capable of explaining why an exception should be made for them.
Accounting exists because memory is weak and temptation is strong.
Audit exists because management assertions are not enough.
Disclosure exists because markets punish darkness.
Confidentiality exists because markets also punish nakedness.
The old machinery forces these values into conflict. The new machinery can reconcile part of them.
Merkle proof entities establish that evidence exists. Selective proof retrieval makes that evidence available at scale. Commitments bind hidden values. Zero-knowledge proofs establish arithmetic without disclosure. Range proofs keep the hidden values honest within defined bounds. Audit procedures supply judgement. External evidence supplies reality. Law supplies enforceability.
Together, they form something accounting has long needed:
a method for proving calculations without surrendering secrets.
That is the importance.
Not a new slogan. Not a new ledger fashion. Not another theatrical promise that technology will purify commerce. Commerce does not need purification. It needs better instruments for disciplined distrust.
The age of accounting by document is not ending. But it is no longer enough.
The next serious accounting system will not merely say: here are my records.
It will say: here is what I committed, here is where it was anchored, here is how it can be verified, here is the arithmetic proof, here is what remains undisclosed, and here is what the proof does not claim.
That is the sound of accounting becoming less rhetorical.
That is the sound of trust being replaced, where possible, by proof.
References
Akter, M., Kummer, T.-F., & Yigitbasioglu, O. (2024). Looking beyond the hype: The challenges of blockchain adoption in accounting. International Journal of Accounting Information Systems.
Alles, M., Brennan, G., Kogan, A., & Vasarhelyi, M. A. (2006). Continuous monitoring of business process controls: A pilot implementation of a continuous auditing system at Siemens. International Journal of Accounting Information Systems.
Ben-Sasson, E., Chiesa, A., Tromer, E., & Virza, M. (2014). Succinct non-interactive zero knowledge for a von Neumann architecture. Proceedings of the 23rd USENIX Security Symposium, 781–796.
Guo, X., Zuo, Y., & Li, D. (2025). When auditing meets blockchain: A study on applying blockchain smart contracts in auditing. International Journal of Accounting Information Systems.
Han, H., Shiwakoti, R. K., Jarvis, R., Mordi, C., & Botchie, D. (2023). Accounting and auditing with blockchain technology and artificial intelligence: A literature review. International Journal of Accounting Information Systems, 48, Article 100598.
Hevner, A. R., March, S. T., Park, J., & Ram, S. (2004). Design science in information systems research. MIS Quarterly, 28(1), 75–105.
Townsend, R. M. (1979). Optimal contracts and competitive markets with costly state verification. Journal of Economic Theory, 21(2), 265–293.
Verrecchia, R. E. (2001). Essays on disclosure. Journal of Accounting and Economics, 32(1–3), 97–180.
WIPO. (2022). WO 2022/100946 A1: Merkle Proof Entity. International patent publication.
WIPO. (2025). WO 2025/119666 A1: Method and System for Enabling Verification of Data. International patent publication.
Yoon, K., Liu, L., Chiu, V., & Vasarhelyi, M. A. (2021). Design and evaluation of an advanced continuous data level auditing system: A three-layer structure. International Journal of Accounting Information Systems.