Purpose
Represent Bitkaya’s approved Enterprise Compliance Manual as the parent BCMS policy for compliance governance, regulatory accountability, risk management, internal controls, reporting and subordinate compliance manuals.
Policy Statement
Bitkaya must maintain a documented, risk-based and proportionate compliance framework that supports lawful VASP operations, transparent governance, client protection, financial crime prevention, operational resilience and effective regulatory supervision.
The Enterprise Compliance Manual is the parent policy for subordinate compliance frameworks, including AML/CFT/CPF, KYC/CDD, outsourcing, anti-bribery and corruption, client asset safeguarding, privacy, business continuity, market conduct, complaints handling, IT and cybersecurity, COTS acceptance, finance and tax compliance, employee conduct, internal controls and audit, regulatory reporting and training.
All directors, officers, employees, contractors, consultants and third parties acting on behalf of Bitkaya must comply with the framework applicable to their role and must support complete, accurate and auditable compliance records.
Scope
This policy applies to Bitkaya B.V. and to all business lines, products, systems, employees, officers and third parties acting for or on behalf of Bitkaya.
The manual covers:
- Business and compliance structure.
- Proportionality and scalability.
- Governance, ethics and ESG.
- Enterprise risk management.
- Outsourcing risk management.
- AML/CFT/CPF.
- Anti-bribery and corruption.
- KYC/CDD.
- Client asset safeguarding.
- Data protection and privacy.
- Business continuity management.
- Market conduct and trading compliance.
- Client complaints handling.
- IT and cybersecurity.
- Commercial off-the-shelf software acceptance.
- Finance and tax compliance.
- Employee compliance responsibilities.
- Internal controls and audit.
- Regulatory reporting and communication.
- Training and awareness.
Roles
- The Board provides overall governance, approves the compliance framework and receives reporting on material compliance and risk matters.
- Executive Management allocates resources, implements the framework and ensures business growth does not override compliance obligations.
- Compliance owns the manual, maintains the policy library, supports regulatory interpretation, monitors adherence and escalates material issues.
- Risk and Compliance challenge the first line, coordinate control testing and maintain risk-based oversight.
- Operations, Technology, Finance, Sales and other business functions own and operate controls in their areas.
- Internal or external audit provides independent assurance over governance, risk management and control effectiveness.
- Employees and third parties must follow applicable policies, complete training, escalate concerns and cooperate with reviews or audits.
Exceptions
Exceptions to this policy or subordinate manuals must be documented, risk assessed, approved by the appropriate authority and tracked to resolution. Exceptions must not override legal, regulatory, CBCS, FIU or sanctions obligations.
Manual Summary
The approved manual establishes Bitkaya’s enterprise-wide compliance framework and states that it serves as the parent policy governing creation, implementation and monitoring of subordinate compliance manuals and frameworks.
Key operating principles include:
- Controls must be risk-based, proportionate, documented and auditable.
- Responsibilities are organized under a three-lines model.
- Compliance and risk information is reported through management, committee and Board channels.
- Risk assessments occur at enterprise, process and client levels.
- Records must be securely retained and retrievable for audit or regulatory review.
- Policies, SOPs and risk assessments must be maintained in a version-controlled library.
- Training is mandatory on onboarding and periodically thereafter.
- Material breaches, control failures and regulator interactions must be escalated promptly.
Implementing Procedures and Controls
Procedures
- PROC-ECM-001 Maintain Compliance Framework Inventory
- PROC-ECM-002 Assess Regulatory Change and Framework Impact
- PROC-ECM-003 Review Approve and Publish Compliance Manuals
- PROC-ECM-004 Manage Compliance Reporting and Escalation
- PROC-ECM-005 Manage Compliance Training and Attestations
- PROC-ECM-006 Perform Compliance Assurance and Remediation
Controls
- CTRL-ECM-001 Ensure Compliance Framework Inventory Is Current
- CTRL-ECM-002 Ensure Regulatory Change Impact Assessment Is Completed
- CTRL-ECM-003 Ensure Compliance Manuals Are Approved and Version Controlled
- CTRL-ECM-004 Ensure Compliance Reporting and Escalation Occurs
- CTRL-ECM-005 Ensure Compliance Training and Attestations Are Completed
- CTRL-ECM-006 Ensure Assurance Findings Are Tracked to Closure
Source Document
- Document title: Bitkaya Compliance Manual
- Version: 2.3
- Status in source document: FINAL
- Date in source document: 21 April 2026
- Approver in source document: Board, based on the manual change log
- Permanent approved artifact location: Bitkaya Enterprise Compliance Manual v23 Approved.pdf
Requirement Coverage
This parent policy provides framework-level coverage for existing BCMS VASP, outsourcing, transaction monitoring and wallet verification requirements. It should not replace subordinate manuals, procedures or controls where detailed operating steps are required.
Relationships
- Primary regulatory source: SRC-VASP-001 Landsverordening toezicht virtuele activa dienstverleners
- Related outsourcing source: SRC-OUT-001 CBCS Guideline for the Sound Management of Outsourcing
- Related policy: POL-OUT-001 Outsourcing Risk Management Manual
- Governance process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Parent procedures: PROC-ECM-001 Maintain Compliance Framework Inventory, PROC-ECM-002 Assess Regulatory Change and Framework Impact, PROC-ECM-003 Review Approve and Publish Compliance Manuals, PROC-ECM-004 Manage Compliance Reporting and Escalation, PROC-ECM-005 Manage Compliance Training and Attestations, PROC-ECM-006 Perform Compliance Assurance and Remediation
- Parent controls: CTRL-ECM-001 Ensure Compliance Framework Inventory Is Current, CTRL-ECM-002 Ensure Regulatory Change Impact Assessment Is Completed, CTRL-ECM-003 Ensure Compliance Manuals Are Approved and Version Controlled, CTRL-ECM-004 Ensure Compliance Reporting and Escalation Occurs, CTRL-ECM-005 Ensure Compliance Training and Attestations Are Completed, CTRL-ECM-006 Ensure Assurance Findings Are Tracked to Closure
- Parent systems: SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository
- Related IT process: PRC-RSA-001 Resilience Systems and Assurance
- Related operating processes: PRC-GRO-001 Governance Risk and Outsourcing
- Publication: PUB-ECM-001 Enterprise Compliance Manual
Assurance
- Source PDF extracted: yes
- Manual version captured: yes
- Board approver captured from change log: yes
- Exact Board approval date captured: yes, 2026-04-21
- Subordinate framework inventory captured: yes
- BCMS relationship mapping completed: initial mapping
Potential follow-up checks:
- Confirm whether the Board approval date is 2026-04-21 or another April 2026 Board date.
- Decide whether to extract separate BCMS policies, processes, procedures and controls for each major manual chapter.
- Link this policy back from applicable source and requirement objects when the parent framework is approved.
History
- 2026-07-25: Created BCMS policy object from Bitkaya Compliance Manual version 2.3.
- 2026-07-25: Updated policy status to implemented with Board approval and effective date 2026-04-21.
- 2026-07-25: Added parent-level procedures, controls and systems for enterprise compliance framework governance.
- 2026-07-28: Enriched to 100% PDF coverage — all 21 chapters, every section and paragraph from the source manual incorporated.
1 About this Manual
This manual establishes Bitkaya’s regulatory compliance and governance framework, ensuring adherence to CBCS, FATF, and international standards for Virtual Asset Service Providers (VASPs). It is applicable to all directors, officers, employees, and third parties acting on behalf of Bitkaya B.V.
The manual demonstrates Bitkaya’s ongoing commitment to transparency, accountability, and lawful operations across Curaçao and any jurisdiction where Bitkaya conducts business. This manual serves as the parent policy that governs the creation, implementation, and monitoring of all subordinate compliance manuals and frameworks.
The manual establishes the governance framework for AML/CFT/CPF controls, data protection, client asset safeguarding, corporate governance, risk management, anti-bribery and cybersecurity.
Bitkaya recognizes that effective compliance depends on collective accountability, requiring active participation from employees, management, and the Board of Directors.
2 Business Overview
2.1 Services Overview
Bitkaya has three lines of business in the digital assets space:
- Principal Brokerage
- Agency Exchange
- Digital Asset Consulting
2.1.1 Principal Brokerage
- Bitkaya functions as a principal broker versus its clients, facilitating:
- Purchase of cryptocurrencies against payment in fiat;
- Sale of cryptocurrencies against receipt in fiat.
- Clients purchase from or sell directly to Bitkaya. Bitkaya does not function as their agent to route transactions on their behalf to a public order book, but instead facilitates trades for Bitkaya’s own risk and account via its proprietary trading book.
- Trades are settled on a Delivery-versus-Payment (‘DVP’) basis to either the client’s bank account or his non-custodial cryptocurrency wallet.
- For professional clients, Bitkaya offers the option to manage cryptocurrency wallets on their behalf for efficiency purposes and on the basis of a separate agreement.
- Principal Brokerage services are offered to both individual and corporate clients.
2.1.2 Agency Exchange
In its role as an agency exchange, Bitkaya facilitates transactions between buyers and sellers without taking a principal position. Services offered include:
- Market Access: Providing entry to a wide range of digital assets across various markets.
- Order Matching: Connecting clients to execute trades at mutually agreed prices.
- Custody: Holding fiat and digital assets on behalf of clients.
- Initial Coin Offerings (ICO): Bringing new tokens to market.
Agency Exchange services are intended to be offered to both individual and corporate clients.
As of the date of this Compliance Manual, Agency Exchange is not offered in the market but merely under investigation for possible implementation.
2.1.3 Digital Asset Consulting
Bitkaya offers clients a broad range of consulting services in the field of digital assets:
- Tokenization: assisting entities wishing to launch their own digital asset;
- Crypto Payments: advising organisations wanting to integrate payments in their operations;
- Due Diligence: analysis of crypto transactions and wallets, investigating incidents, assisting in asset recovery efforts;
- Education: programs to enhance understanding of digital assets, tailored training sessions;
- Strategic advisory: crafting strategies for entering or expanding within the digital asset space, including business model innovation.
2.1.4 Product-Market Fit
As Bitkaya continues to develop its offerings in principal brokerage, agency exchange, and digital asset consulting, it’s important to acknowledge that the company has not yet achieved product-market fit. This means that while Bitkaya is actively providing some of these services, it is still in the process of validating that its products effectively meet the needs of a specific market segment and that customers recognize and are willing to pay for these solutions. Consequently, Bitkaya is committed to iterating on its services based on customer feedback and market research, ensuring that its offerings evolve to better align with market demands. This adaptive approach allows Bitkaya to refine its value proposition, enhance customer satisfaction, and work towards achieving a sustainable product-market fit.
2.1.5 Business Plan
For a comprehensive understanding of Bitkaya’s strategic direction, financial outlook, and business model, please refer to the detailed business plan. This document encompasses:
- Financial Projections: Detailed forecasts of revenues, expenses, and profitability, providing insights into the company’s anticipated financial performance.
- Business Model Canvas: A representation of Bitkaya’s value propositions, customer segments, channels, customer relationships, revenue streams, key resources, key activities, key partnerships, and cost structure, offering a holistic view of the business strategy.
These components are integral to understanding how Bitkaya plans to achieve product-market fit and scale its operations effectively. The business plan serves as a roadmap, aligning strategic objectives with financial planning to guide decision-making and attract potential investors.
2.2 Group Structure
As of the writing of this manual, all shares in Bitkaya BV are held by Kwerines Holdings BV, which in turn is fully controlled by Cornelis Quirijns.
To facilitate future growth and attract investment, Bitkaya is actively engaging with potential investors through the issuance of Simple Agreements for Future Equity (SAFEs). These SAFEs are structured to convert into equity in 2026, providing investors with the opportunity to become shareholders.
2.3 Organizational Structure
Bitkaya’s organizational structure is crafted to support its core business areas—principal brokerage, agency exchange, and digital assets consulting—while maintaining agility and scalability. The company employs a centralized framework, wherein strategic decisions are made by top management and disseminated throughout the organization. This structure facilitates clear communication channels, defined roles and responsibilities, and efficient coordination across departments. As Bitkaya continues to evolve, this organizational design provides a solid foundation for growth, ensuring that the company can adapt to market changes and expand its operations effectively.
2.4 Compliance Structure
Bitkaya’s compliance structure is designed to align with its current scale as a startup while laying the groundwork for future expansion. The company employs a centralized compliance framework, ensuring that regulatory adherence and ethical standards are maintained across all operations. This structure facilitates clear communication channels, defined roles and responsibilities, and efficient coordination across departments. As Bitkaya continues to evolve, this organizational design provides a solid foundation for growth, ensuring that the company can adapt to market changes and expand its operations effectively.
3 Proportionality and Scalability
3.1 Introduction
As a burgeoning Virtual Asset Service Provider (VASP) operating in Curaçao, Bitkaya acknowledges the necessity of implementing an organizational and compliance framework that aligns with its current scale while being adaptable to future expansion. This chapter outlines Bitkaya’s approach to structuring its organizational roles and responsibilities, emphasizing proportionality, functional consolidation, and scalability.
3.2 Proportionality in Organizational Structure
In line with international best practices, Bitkaya adopts a proportional approach to its organizational structure, tailoring roles and responsibilities to the nature and scale of its operations. This ensures that the company’s resources are utilized efficiently without compromising on governance and oversight.
3.3 Consolidation of Functions
Given its current size, Bitkaya may consolidate multiple roles and responsibilities within single individuals or small teams. This consolidation spans various organizational functions, including:
- Compliance and Risk Management: Overseeing adherence to regulatory requirements and managing potential risks.
- Finance and Accounting: Managing financial planning, budgeting, and accounting processes.
- Human Resources and Operations: Handling recruitment, employee relations, and day-to-day operational activities.
- Information Technology and Security: Maintaining IT infrastructure and ensuring cybersecurity measures are in place.
This approach is managed carefully to maintain the effectiveness of each function, ensuring that duties are performed competently and without conflicts of interest.
3.4 Commitment to Organizational Standards
Despite operating as a startup, Bitkaya is committed to establishing and maintaining high standards across all organizational functions. This commitment includes:
- Policy Development: Implementing comprehensive policies that address key areas such as compliance, finance, human resources, and information security.
- Training and Development: Providing ongoing training to employees to foster a culture of continuous learning and ensure awareness of organizational obligations.
- Monitoring and Review: Regularly assessing processes and controls to identify areas for improvement and ensure alignment with evolving business needs.
3.5 Scalability for Future Growth
Bitkaya’s organizational framework is designed with scalability in mind, allowing for the seamless expansion of functions as the company grows. This includes:
- Resource Allocation: Planning for the addition of specialized personnel and resources in line with business growth.
- Process Enhancement: Upgrading systems and processes to handle increased complexity and volume of operations.
- Governance Structures: Establishing formal governance structures to provide oversight and strategic direction.
4 Governance, Ethics & ESG
4.1 Purpose and Scope
This policy defines Bitkaya’s approach to Environmental, Social, and Governance (ESG) standards and ethical conduct. It sets the framework for integrating responsible, transparent, and sustainable practices into all aspects of operations and decision-making.
The purpose of this framework is to:
- Embed ESG and ethical principles in business strategy, governance, and culture.
- Monitor and report ESG performance transparently.
- Drive continuous improvement across environmental stewardship, social responsibility, and governance integrity.
This policy applies to all Bitkaya entities, employees, officers, and third parties acting on its behalf. It promotes responsible innovation in the digital asset sector while supporting sustainable development in Curaçao and globally.
4.2 ESG Governance Structure
A structured governance model ensures oversight, accountability, and progress in ESG performance.
- Board of Directors: Provides overall oversight of ESG strategy, approves related policies, and ensures alignment with the company’s objectives and stakeholder expectations.
- ESG Committee: A cross-functional team composed of leaders from key departments, responsible for implementing ESG initiatives, monitoring progress, and reporting on outcomes. The committee meets quarterly to review performance indicators, emerging risks, and opportunities for improvement.
- Compliance & Risk Function: Ensures that ESG principles are embedded within the enterprise risk management framework. Upholds ethical business conduct and compliance with anti-corruption, AML/CFT, and transparency standards.
4.3 Environmental Responsibility
Bitkaya is committed to minimizing its environmental impact and promoting sustainable operations. Efforts focus on energy efficiency, responsible resource use, and environmentally conscious partnerships.
4.3.1 Energy & Emissions
- Monitor and progressively reduce energy consumption across IT infrastructure and operations.
- Transition toward renewable or low-carbon energy sources where feasible.
- Limit greenhouse gas (GHG) emissions.
- Encourage remote and hybrid work models to reduce commuting-related emissions.
4.3.2 Resource Management
- Reduce waste generation and promote recycling and responsible e-waste disposal.
- Prioritize procurement from vendors with demonstrated ESG alignment.
- Adopt paperless workflows and leverage digital tools to minimize physical resource use.
4.4 Social Responsibility
- Employee Well-being: Promote diversity, equity, and inclusion; support training, professional growth, safe work conditions, and employee wellness.
- Community Engagement: Contribute to local social and economic development through partnerships, financial literacy programs, and volunteer initiatives.
- Human Rights: Uphold human rights across operations and supply chains, in line with international standards.
4.5 Governance Practices
Strong governance is central to Bitkaya’s sustainability and ethical culture.
- Ethical Conduct: All staff must adhere to the company’s Code of Ethics, anti-bribery and anti-corruption standards, and transparency obligations. Data protection, confidentiality, and accurate reporting are mandatory.
- Risk Management: ESG-related risks are identified and assessed within the broader Enterprise Risk Management (ERM) framework. This includes evaluating climate, social, compliance, and reputational risks and ensuring they are mitigated through appropriate controls. ESG oversight is also integrated with AML/CFT programs, cybersecurity, and incident escalation procedures.
- ESG Integration: ESG factors are applied in investment decisions, product development, and strategic partnerships. Stakeholder engagement is encouraged to ensure transparency and accountability. The company actively pursues innovation that supports sustainable finance and inclusive digital growth.
4.6 Further Details
For detailed implementation guidelines, reporting templates, and performance metrics, refer to the Governance, Ethics & ESG Manual.
5 Risk Management Framework
5.1 Purpose, Scope, and Principles
The Risk Management Framework sets out how Bitkaya identifies, assesses, manages, monitors, and reports all significant risks across the business. It ensures that risks arising from Bitkaya’s activities as a Virtual Asset Service Provider are understood and controlled within defined boundaries.
The framework covers governance and decision-making, product development, the full client lifecycle, technology and custody operations, outsourcing, and financial management. It complements Bitkaya’s other core frameworks — including those for Anti-Money Laundering, Counter-Terrorism and Proliferation Financing, Business Continuity, Information Security, Legal, Human Resources, and Finance.
Risk management at Bitkaya is:
- Risk-based and proportionate – controls match the level of exposure.
- Structured under the “Three Lines” model – clear accountability between business, oversight, and audit.
- Focused on client and market integrity.
- Evidence-driven – decisions supported by measurable indicators.
- Documented and auditable – all steps can be traced and reviewed.
5.2 Governance and Roles
5.2.1 Oversight and Accountability
- Board of Directors: Approves this framework and the company’s overall risk appetite. Receives quarterly risk reports and an annual summary of trends.
- Risk and Compliance Committee: Reviews the overall risk profile, monitors breaches, oversees remediation, and approves new products and risk models.
- Executive Management: Allocates resources and ensures the framework is implemented effectively across the company.
5.2.2 The Three Lines of Responsibility
- First Line – Business and Operations: Business, Operations, and Technology teams own and manage their risks directly. They are responsible for designing and maintaining effective controls.
- Second Line – Risk and Compliance: The Risk and Compliance functions (including the Money Laundering Reporting Officer) set the standards, monitor adherence, and challenge the business where necessary.
- Third Line – Internal or External Audit: Provides independent assurance once per year to confirm the framework’s effectiveness.
5.2.3 Key Roles
Key roles include the Money Laundering Reporting Officer (MLRO), Head of Risk, Chief Information Security Officer, Product Owner for new product approvals, and Vendor Manager.
5.2.4 Risk Categories
Bitkaya’s risk taxonomy includes: financial crime, market and liquidity, operational, technology and cyber, legal and compliance, counterparty and credit, third-party, strategic, reputational, and business continuity risks.
5.3 Risk Appetite
The Risk Appetite Statement describes how much risk Bitkaya is willing to take in each area, combining qualitative boundaries with measurable indicators and escalation rules.
- Financial crime: Very low tolerance. If high-risk clients exceed 10% of total volume, it triggers a committee review; 15% triggers an onboarding pause.
- Cybersecurity: Very low tolerance. Critical vulnerabilities must be fixed within 48 hours; multi-factor authentication is mandatory for all users.
- Custody and asset protection: Very low tolerance. No exceptions to dual-authorization; reconciliation issues must be resolved within a week.
- Liquidity: Low tolerance. Bitkaya must be able to operate for at least 30 days under stress conditions.
- Third-party providers: Moderate tolerance. Core vendors must maintain valid security certifications (such as ISO or SOC2).
Each risk indicator has a defined owner, measurement method, threshold, and escalation process.
5.4 Risk Assessment
Bitkaya maintains a centralized record of all incidents, near misses, and external events, which feeds into its annual risk assessments.
- Enterprise-level assessment: Conducted once a year to measure both inherent risk (before controls) and residual risk (after controls). Results guide priorities, staffing, and monitoring.
- Process-level assessment: Each department reviews its controls at least annually, particularly when introducing new systems or products.
- Client-level assessment: Individual client risk ratings determine the level of due diligence and transaction monitoring applied.
- Scoring: Risks are scored by likelihood and impact on a scale of 1 to 5, summarized in a heatmap showing high, medium, or low priority.
5.5 Controls and Monitoring
Bitkaya operates a library of key controls across its business, including:
- Customer and transaction verification processes.
- Custody controls such as multi-signature wallets, hardware security modules, and daily reconciliations.
- Cybersecurity controls such as multi-factor authentication, endpoint protection, and secure software development.
- Separation of duties (“maker–checker” principle) in critical processes.
- Vendor management, service level agreements, and regular performance reviews.
- Trading safeguards such as kill-switch mechanisms and market surveillance.
Risk indicators are tracked through dashboards and thematic reviews. Issues are logged, assigned to responsible owners, and monitored until resolved.
5.6 Stress Testing and Scenario Analysis
Bitkaya conducts stress tests to ensure resilience against extreme but plausible situations, such as: a major custody breach, liquidity shortfall, sanctions event, or extended cloud outage. Each test examines the impact on liquidity, custody, cybersecurity, and compliance functions. Results are reviewed by the Risk Committee and the Board, and corrective actions are tracked to completion.
5.7 New Product and Change Risk
Any significant change — such as launching a new asset or chain, entering a new jurisdiction, or adding new client functionality — requires prior risk assessment. Each proposal must include a business case, legal and compliance review, security assessment, and operational readiness plan.
Decisions are recorded in the new-product register, followed by a post-launch review within 30 days. The risk team provides independent challenge and approval before launch.
5.8 Incidents, Issues, and Complaints
- Incidents: Classified when detected, with an initial report within 24 hours and a full root-cause analysis within five business days. Regulators are notified if required.
- Issues: Each issue has an assigned owner, action plan, and due date for resolution.
- Complaints: Logged and monitored under the company’s complaint-handling policy. Trends are analyzed as part of the regular risk reporting cycle.
5.9 Third-Party and Counterparty Risk
Bitkaya evaluates and monitors all vendors and counterparties before and during the relationship.
- Due diligence includes: verification of licenses and certifications, sanctions checks, financial stability, and data protection measures.
- Contracts must contain clear performance standards, audit rights, breach notification obligations, and exit provisions.
- Ongoing oversight includes quarterly performance reviews and annual reassessment.
- Virtual asset counterparties (VASPs) are categorized by risk level, and relationships are declined if due diligence fails.
5.10 Business Continuity and Disaster Recovery
Bitkaya maintains defined recovery targets to minimize downtime:
- Trading services restored within 24 hours.
- Wallet services within 24 hours.
- Compliance operations within 48 hours.
- Reporting within 76 hours.
Back-up data recovery objectives range from near-real-time for transactions to 24 hours for KYC files.
The company tests these plans annually, conducts tabletop simulations every six months, and maintains pre-approved communications for clients and regulators during incidents.
5.11 Data, Records, and Model Management
All records — including client data, risk logs, and reports — are securely stored for at least five years, and up to ten years where required by law.
Analytical and scoring models used in transaction monitoring or sanctions screening are documented, tested, and independently validated once per year.
5.12 Reporting and Management Information
Risk information is shared at three levels:
- Weekly to Executive Management: Key alerts, sanctions results, custody breaks, cybersecurity incidents, complaints, and exceptions.
- Monthly to the Risk and Compliance Committee: Risk heatmaps, breaches, vendor metrics, new product updates, outstanding issues, and staff training.
- Quarterly to the Board: Overall trends, progress against appetite limits, results of stress tests, regulatory feedback, and major incidents.
5.13 Assurance and Review
- Second-line testing: The Risk and Compliance teams perform quarterly reviews of control effectiveness and follow up on remediation actions.
- Independent audit: An internal or external audit team performs an annual review of the Risk Management and Compliance frameworks.
- Regulatory readiness: All evidence — policies, registers, logs, and reports — is maintained in a structured library to demonstrate compliance at any time.
5.14 Training and Culture
Training is tailored to each role:
- Directors and executives focus on governance and oversight.
- Product and technology teams receive risk and cybersecurity training.
- Operational and client teams are trained on daily controls and incident response.
Cultural health is measured through staff participation in training, reporting of issues, and time taken to close them.
5.15 Policy Maintenance and Version Control
The framework is reviewed at least annually or whenever regulatory, business, or operational changes occur. A version log records all updates, their rationale, approval dates, and related procedures affected.
5.16 Further Details
For detailed guidance, refer to the full Risk Management Framework Manual, which contains templates, registers, and assessment tools that support this policy.
6 Outsourcing Risk Management
6.1 Purpose and Scope
Bitkaya may use external service providers where this is operationally efficient and consistent with sound risk management. Bitkaya recognizes that outsourcing can create operational, compliance, legal, ICT, confidentiality, concentration, and business continuity risks if not properly controlled.
Bitkaya therefore maintains an Outsourcing Risk Management framework designed to ensure that outsourcing does not weaken governance, internal control, regulatory compliance, operational resilience, customer protection, or effective supervision by the Centrale Bank van Curaçao en Sint Maarten (CBCS). CBCS requires regulated entities to maintain an outsourcing policy and manage outsourcing risks through an appropriate governance and control framework.
6.2 General Rule
Outsourcing does not transfer responsibility. Bitkaya remains responsible for outsourced activities, processes, and services at all times. Outsourcing must not impair Bitkaya’s ability to comply with law and regulation, maintain sound operations, protect clients and confidential information, or remain effectively supervised by CBCS.
6.3 Classification and Approval
Before entering into an outsourcing arrangement, Bitkaya assesses whether the arrangement is standard, material, or critical / essential.
Critical or essential outsourcing includes arrangements where failure would materially impair regulatory compliance, core operations, key controls, or business continuity. Bitkaya applies stronger review and oversight to material and critical arrangements and seeks prior CBCS approval where required for critical or essential functions.
The engagement of individual contractors is not automatically treated as outsourcing. Where a contractor operates as embedded staff under Bitkaya’s direct management, systems, controls, and governance structure, the arrangement may be treated as a contractor engagement rather than outsourcing. Where the contractor or provider performs an ongoing function in a more independent manner, provides a managed service, or relies on its own systems or processes, the arrangement is assessed as potential outsourcing.
6.4 Core Controls
Bitkaya performs due diligence and a risk assessment appropriate to the nature, scale, and risk of the arrangement. Outsourcing arrangements are documented in writing, monitored on a risk basis, and recorded in a central outsourcing register.
For material and critical arrangements, Bitkaya also considers continuity, substitutability, and exit planning.
6.5 Proportionality
Bitkaya applies the outsourcing framework proportionately. As a small but growing VASP, Bitkaya uses practical and risk-based controls, including a designated internal owner, simple assessment tools, a central register, and deeper review only where the risk of the arrangement justifies it.
6.6 Further Details
Further details, including the full classification approach, approval workflow, contractor treatment, monitoring expectations, outsourcing register, and CBCS interaction process, are set out in the Bitkaya Outsourcing Risk Management Manual.
7 AML/CFT/CPF
7.1 Policy Statement & Governance
Bitkaya operates with integrity and full compliance with Curaçao law and FATF standards as a licensed Virtual Asset Service Provider (VASP). The company’s core compliance controls include enterprise risk assessment, client risk profiling, customer due diligence (CDD) and enhanced due diligence (EDD), transaction and wallet monitoring, counterparty verification (KYV), sanctions screening and freezing, reporting, and recordkeeping.
The Compliance function reports directly to the Board, while the Audit function—whether internal or external—remains independent to strengthen oversight. Human Resources ensures pre-employment screening and mandatory AML/CFT training for all employees. The overall program is reviewed at least annually, or sooner if triggered by regulatory, business, or audit changes.
7.2 Scope & Regulatory Framework
This policy applies to all Bitkaya entities, staff, systems, onboarding procedures, services, and financial operations across every jurisdiction in which the company operates. Relevant legal and regulatory instruments include the Penal Code, NORUT, NOIS, Sanctions Ordinances, NOSVASP, and applicable CBCS Procedures and Guidelines. It also aligns with the FATF’s 40 Recommendations and the Global Digital Finance (GDF) codes. Bitkaya’s regulatory supervisor is the Central Bank of Curaçao and Sint Maarten (CBCS).
7.3 Risk-Based Approach (RBA)
Clients are classified as low risk, medium risk, or high risk based on Bitkaya’s documented risk-scoring methodology.
Low-risk clients are reviewed at least once every three years. Medium-risk clients are reviewed at least once every two years. High-risk clients are reviewed at least once every year and are subject to enhanced monitoring, escalation thresholds, and additional due diligence requirements, including source of wealth assessment before approval where applicable.
7.4 Customer Due Diligence (CDD)
Bitkaya applies a risk-based CDD framework designed to identify, assess, and mitigate financial crime risks throughout the client lifecycle.
The CDD framework includes KYC, KYT, KYV, sanctions screening, risk profiling, transaction monitoring, internal escalation, and external reporting where required.
For legal entities, Bitkaya collects and reviews documentation sufficient to establish legal existence, authorized representatives, ownership and control, and beneficial ownership. The extent of documentation and verification required is determined on a documented risk basis.
For VASP counterparties and other relevant institutional relationships, Bitkaya applies Know Your VASP (KYV) measures proportionate to the nature and risk of the relationship. Simplified treatment is not applied automatically solely because a VASP is established in a particular jurisdiction or claims to be regulated.
7.5 FIU Reporting
Bitkaya maintains an internal case-handling and escalation process for unusual or suspicious matters identified through onboarding, sanctions screening, transaction monitoring, staff escalation, or other control activities.
For internal purposes, Bitkaya may use case classifications such as SAR, STR, FFR, or PNMR to support review, prioritization, escalation, and recordkeeping.
For external purposes, reporting to the FIU Curaçao is made exclusively through a Unusual Transaction Report (UTR), where reporting is required under applicable law. Sanctions-related matters may also involve separate obligations relating to restrictive measures, asset blocking or freezing, and regulatory reporting or notification to the CBCS where applicable.
7.6 Travel Rule
The Travel Rule applies to transfers between VASPs or other obliged entities where the value is equal to or exceeds USD/EUR 1,000. Bitkaya must collect and transmit the following information using secure protocols such as IVMS 101:
For the originator: name, account or ID, address or ID number, date and place of birth. For the beneficiary: name and account or ID.
Counterparties must be verified, and transfers continuously monitored. For unhosted wallets, Bitkaya collects required data from its own customer and applies risk-based measures.
Non-custodial wallet ownership (whitelisting): Ownership verification may involve message signing, micro-transactions (“satoshi test”), or Address Ownership Proof Protocol (AOPP). Verified addresses are whitelisted and re-verified if the risk profile changes.
7.7 Recordkeeping
Bitkaya retains records relating to client due diligence, monitoring, screening, internal case handling, UTR reporting, internal classifications, restrictive measures, review outcomes, and supporting evidence in accordance with applicable legal and regulatory requirements.
Training & Awareness
Staff receive AML/CTF/CPF training appropriate to their role, including training on sanctions screening, transaction monitoring, escalation procedures, internal case classification, external UTR reporting obligations, and documentation standards.
7.8 Technology & Controls
Bitkaya utilizes third-party tools for KYC/ID verification, blockchain analytics, sanctions screening, case management, and ERP dashboards. Security measures include role-based access control (RBAC), multi-factor authentication (MFA), encryption, immutable audit logs, and regular backups. Vendors undergo due diligence, and all systems are reviewed annually.
7.9 Independent Testing
An independent review—conducted annually by internal audit (if independent) or by an external party—assesses the effectiveness of onboarding, screening, monitoring, risk rating, reporting, training, and access controls. Findings are reported to the MLRO, management, and Board, and remediation actions are tracked to completion.
7.10 Policy Management
All policies, SOPs, and risk assessments are maintained in a version-controlled library. Reviews occur annually or upon significant changes.
Where material AML/CFT/CPF changes are made following legal developments, regulator feedback, internal findings, or control enhancements, related subordinate manuals, SOPs, and operational guidance shall be updated in parallel to maintain consistency across the compliance framework.
7.11 Further Details
For full details, refer to the AML/CFT/CPF Compliance Manual, which outlines the complete Anti-Money Laundering, Countering the Financing of Terrorism, and Counter-Proliferation Financing frameworks.
8 Anti-Bribery & Corruption
8.1 Purpose and Scope
Bitkaya maintains an Anti-Bribery & Corruption (ABC) framework to prevent, detect, and respond to bribery and corruption risk across the organization. As a regulated Virtual Asset Service Provider (VASP), Bitkaya recognizes that bribery and corruption can expose the company and its personnel to legal, regulatory, financial, operational, and reputational harm and are incompatible with Bitkaya’s commitment to integrity, accountability, and transparent business conduct.
This framework applies to all directors, officers, employees, contractors, consultants, temporary staff, and third parties acting on behalf of Bitkaya, across all business lines and support functions. Further implementation requirements are set out in the Bitkaya ABC Manual.
8.2 Policy Statement
Bitkaya maintains a zero-tolerance approach to bribery and corruption. No person acting for or on behalf of Bitkaya may offer, promise, give, request, agree to receive, or accept a bribe, whether directly or indirectly, or provide anything of value in order to improperly influence a decision, secure an undue advantage, avoid a regulatory consequence, or distort a commercial outcome. Bitkaya also prohibits the concealment of improper payments through false invoices, sham agreements, misleading accounting entries, undocumented reimbursements, inflated commissions, or the use of third parties to bypass internal controls.
8.3 Governance and Responsibilities
The Board of Directors has ultimate responsibility for oversight of Bitkaya’s ABC framework. Executive Management is responsible for implementation and for ensuring that business growth and commercial pressure do not override ABC controls. The Compliance Officer, or another formally designated person with sufficient experience and expertise, is responsible for coordinating the ABC program, supporting escalation and training, maintaining the ABC framework, and overseeing periodic reporting. Finance, department heads, and other control owners support the framework through appropriate payment controls, recordkeeping, escalation, and first-line implementation. Internal Audit or another competent independent reviewer may periodically assess the design and effectiveness of ABC controls.
8.4 Risk-Based Approach
Bitkaya applies a risk-based and proportionate approach to bribery and corruption risk. ABC risk may arise through third-party relationships, public-official or state-linked exposure, gifts and hospitality, charitable or sponsorship activity, hiring or internships, books and records, financial flows, and periods of business change or growth. Higher-risk arrangements require stronger scrutiny, clearer approvals, enhanced documentation, and closer monitoring. Bitkaya documents its overall ABC risk profile through an ABC Enterprise-Wide Risk Assessment (ABC EWRA), which is reviewed periodically and when material changes occur.
8.5 Core Control Areas
Bitkaya’s ABC framework includes risk-based controls over third parties and intermediaries, gifts and hospitality, dealings with public officials and state-linked entities, charitable donations and sponsorships, conflicts of interest, and books and records. All material decisions, benefits, payments, approvals, and third-party arrangements must be lawful, properly documented, transparent, and capable of review. Any attempt to disguise improper conduct through weak documentation, unsupported payments, or misleading records is prohibited.
8.6 Training, Escalation, and Oversight
Bitkaya provides ABC training on a risk-based basis and requires relevant personnel to understand their responsibilities, applicable red flags, escalation obligations, and conduct expectations. Suspected bribery, corruption, improper influence, falsified records, or related misconduct must be escalated promptly through the appropriate internal channels. Bitkaya monitors the effectiveness of its ABC framework through management oversight, compliance review, testing, and periodic reporting to Senior Management and the Board.
8.7 Further Details
Further details, including operating procedures, approval requirements, escalation rules, monitoring expectations, and implementation guidance, are set out in the Bitkaya Anti-Bribery & Corruption (ABC) Manual.
9 KYC & CDD
9.1 Purpose & Scope
This framework establishes Bitkaya’s standards for Know Your Customer (KYC) and Customer Due Diligence (CDD) in line with Curaçao law, FATF recommendations, and global VASP best practices.
Its purpose is to prevent money laundering, terrorism financing, and proliferation financing by ensuring all clients are properly verified, risk-assessed, and monitored throughout their entire business relationship.
The policy applies to all onboarding, monitoring, and review activities across Bitkaya’s retail, corporate, institutional, and intermediary clients. It is built on four key pillars: KYC/KYT/KYV, Sanctions Screening, Risk Profiling, and Transaction Monitoring.
9.2 KYC / KYT / KYV
KYC (Know Your Customer)
Bitkaya uses digital identity verification (IDV) with liveness detection. Individuals are required to submit a valid passport, national ID, or driver’s license. For legal entities, simplified due diligence is permitted if the entity is licensed by the CBCS. In all other cases, the entity must provide verified documentation proving ownership, ultimate beneficial ownership (UBO), and signatory authority through notarized or official sources.
Only verified and transparent clients are eligible for onboarding.
KYT (Know Your Transaction)
All fiat and cryptocurrency activity is monitored using blockchain analytics and rule-based detection systems. These tools flag anomalies such as velocity spikes, exposure to mixers or darknet markets, and deviations from typical behavior. Alerts are reviewed and escalated as appropriate.
KYV (Know Your VASP)
Bitkaya conducts due diligence on all VASP counterparties. Simplified measures apply to supervised VASPs based in the US or Western Europe, while standard or enhanced due diligence is required for others.
9.3 Client Onboarding
- All client relationships are subject to risk-based onboarding controls.
- Low-risk and medium-risk clients require management approval before activation.
- High-risk clients require Compliance approval in addition before onboarding may be completed.
- Where sanctions alerts remain unresolved, onboarding may not proceed until the alert has been appropriately resolved or escalated.
- Where the client is classified as high risk, source of wealth must be assessed before approval.
9.4 Sanctions Screening
Bitkaya performs sanctions screening before onboarding, during periodic review, when relevant sanctions lists are updated or refreshed, and before or during relevant transactions where the control framework requires transaction-level or wallet-level screening. Screening may extend beyond the client and beneficial owner to include authorized signatories, directors, intermediary entities, relevant counterparties, and associated wallet addresses where relevant.
False positives must be documented with the basis for closure. Unresolved alerts prevent the relationship or transaction from proceeding until appropriately resolved or escalated. Confirmed sanctions matches require legally required restrictive measures and are handled in accordance with applicable FIU and CBCS reporting or notification requirements.
9.5 Risk Profiling
Each client receives a residual risk score based on multiple factors, including client type, PEP exposure, onboarding method, geography, products and services, behavior, and delivery channel. The applicable scores across these categories determine the client’s overall risk rating.
Indicators of potential red-flag risk include structuring, sudden transaction spikes, or unexplained third-party deposits. Blockchain analytics providers assess over twenty on-chain risk sources and assign wallet risk tiers:
- 0–25%: Low risk
- 25–75%: Cautionary
- 75%: Rejection recommended
Initial and recurring classifications are documented, and discrepancies between onboarding and follow-up assessments must be explained and justified.
9.6 CDD Levels
- Simplified Due Diligence may only be applied where a client has been assessed and documented as low risk.
- Medium-risk clients are subject to standard due diligence, including source of funds collection at least on a self-declaration basis.
- High-risk clients are subject to enhanced due diligence, including source of wealth assessment before approval, enhanced monitoring, and more intensive review requirements.
9.7 Transaction Monitoring
Bitkaya’s transaction monitoring program is designed to detect structuring, rapid fund movement, involvement of high-risk assets or wallets, and discrepancies between client behavior and expected activity.
Monitoring rules are calibrated according to client risk level, and alerts are consolidated across fiat and crypto channels. All alerts are logged in a centralized case management system linked to Unusual Transaction Report (UTR) decisions. Reviews are conducted in both real-time and retrospectively.
9.8 Ongoing Monitoring Cadence
Ongoing reviews are conducted according to the client’s risk rating:
- Low risk: every two years
- Medium risk: every year
- High risk: quarterly or upon detection of red flags
All clients and wallets remain under continuous sanctions and PEP screening throughout the relationship.
9.9 Suspicious Activity Reporting
Internal case classifications may be used for handling, escalation, and recordkeeping of unusual or suspicious matters. External FIU reporting is made exclusively through the UTR process where reporting is required.
9.10 Record-Keeping
KYC, CDD, and transaction monitoring records—including profiles, wallet analytics, and case files—are securely retained for a minimum of five years, or longer if instructed by authorities. All data are encrypted, access is strictly controlled, and retrieval must be immediate upon audit or regulatory request.
9.11 Training
All employees receive annual AML and KYC training. Staff working in onboarding, risk management, or compliance also complete specialized modules, including blockchain forensics and typology recognition.
Regular updates ensure awareness of emerging crypto-specific risks and evolving regulatory requirements.
9.12 Governance & Oversight
The Board of Directors is responsible for approving this policy and receives quarterly compliance updates. The MLRO oversees the execution of KYC and CDD processes, ensures timely reporting, and maintains FATF-aligned standards. (Internal) Audit conducts independent assessments of program effectiveness and regulatory adherence.
9.13 Further Details
For detailed procedures, refer to the KYC & CDD Manual, which provides comprehensive guidance on Know Your Client and Customer Due Diligence standards.
10 Client Asset Protection & Safeguarding
10.1 Purpose & Scope
This policy ensures that all client money and virtual assets are protected, properly segregated, and never misused. It applies to all employees, officers, contractors, and third parties acting on behalf of Bitkaya. The framework supports regulatory requirements and reinforces client trust by ensuring assets are safeguarded at all times.
10.2 Key Definitions
- Client Money: Funds held on behalf of clients, excluding principal trades, fees or charges due to Bitkaya.
- Client Virtual Assets (VAs): Digital assets that belong to clients and are not part of Bitkaya’s own property.
- Client Account: A dedicated bank account used solely for holding client money.
- Client VA Wallet: A wallet reserved exclusively for holding client virtual assets.
10.3 Segregation of Assets
All client assets must be kept separate from Bitkaya’s own funds and holdings.
- Client funds must be deposited only in designated Client Accounts.
- Client virtual assets must be stored in Client VA Wallets with no commingling.
- Rehypothecation (using client assets for other purposes) is only permitted with explicit written consent and, where applicable, under the appropriate license or legal structure.
10.4 Handling Client Money
- Client funds must be deposited into the Client Account within three business days of receipt.
- Each transaction must be recorded accurately, including the date, client identifier, amount, and reference.
- Withdrawals must be properly documented and approved before execution.
- Misuse of funds or cross-funding between clients is strictly prohibited.
10.5 Handling Client Virtual Assets
- Virtual assets are held on a one-to-one basis, matching each client’s entitlement.
- Clients are entitled to the proceeds or benefits (such as airdrops or staking rewards) unless otherwise agreed in writing.
- Bitkaya does not assume ownership of client assets except where held in a trust or other recognized safeguarding structure.
10.6 Reconciliation & Recordkeeping
- Client balances must be reconciled regularly against external bank and wallet statements.
- Any discrepancies must be investigated and resolved immediately.
- Records of all reconciliations, transactions, and related documentation must be maintained for a minimum of ten years.
10.7 Client Reporting
Clients must receive regular, transparent reporting on their holdings.
- Statements are issued monthly, detailing balances, holdings, and all transactions, to the extent not provided by blockchain explorers.
- Reports must be delivered within 25 days after the end of each reporting period.
- All statements must be clear, accurate, and compliant with regulatory standards.
10.8 Third-Party Custodians
Bitkaya only partners with reputable, authorized banks and digital asset custodians.
- Banks must confirm in writing that client funds are legally recognized as client property.
- Wallet and custody providers must pass stringent due diligence and meet high security and operational standards before engagement and throughout the relationship.
10.9 Compliance & Audit
- Internal controls for safeguarding are embedded in daily operations.
- Regular internal and external audits verify compliance and control effectiveness.
- Any breaches or weaknesses identified must be promptly investigated, and corrective actions tracked to completion.
10.10 Client Agreements
All client agreements must clearly explain how assets are handled, safeguarded, and reported. They must specify client rights, the nature of the risks involved, and the protections in place. Clients must be informed of where and how their assets are held, and all agreements must comply with relevant legal and regulatory requirements.
10.11 Governance & Accountability
- Board of Directors: Approves and oversees this policy and receives periodic reports on safeguarding controls.
- Senior Management: Ensures operational implementation and adequate resource allocation.
- Compliance Officer: Monitors compliance with this policy and reports directly to the Board.
10.12 Risk Management & Internal Controls
- Regular risk assessments identify vulnerabilities in asset protection.
- Controls include segregation of duties, dual authorization for transfers, and automated reconciliation systems.
- Any available insurance or compensation schemes must be disclosed to clients.
10.13 Cybersecurity
Strong cybersecurity measures protect all client assets:
- Wallet access requires multi-factor authentication and multi-signature approval.
- All data and keys are encrypted, with intrusion detection systems and penetration tests performed regularly.
- Private keys are managed through hardware security modules (HSMs).
- Business continuity and disaster recovery procedures are in place and tested regularly.
10.14 Withdrawals & Transfers
All withdrawals and transfers must follow strict verification and authorization processes:
- Client identity and transaction legitimacy must be confirmed before release of funds or assets.
- Dual authorization is required for all transactions, supported by complete documentation.
- Any unusual or suspicious activity must be escalated to Compliance for review.
10.15 Insolvency Protection
Client assets are ring-fenced and protected from Bitkaya’s own estate in the event of insolvency. Trust or equivalent legal structures are used to ensure client ownership rights. Both regulators and clients are notified immediately in the event of any material insolvency event affecting client assets.
10.16 Training
All relevant employees must complete mandatory training on anti-money laundering, counter-terrorist financing, and safeguarding responsibilities. Training is refreshed annually and tailored to specific roles. Records of completion are maintained and reviewed by Compliance.
10.17 Breach Management
- Any breach or incident related to client asset protection must be reported immediately.
- Material incidents must be disclosed promptly to regulators and affected clients.
- A root cause analysis must be completed, with corrective and preventive actions implemented and tracked.
10.18 Policy Review
This policy is reviewed at least once per year, or sooner if there are significant regulatory or operational changes. All revisions are approved by the Board, and a version log is maintained to document updates, approvers, and effective dates.
10.19 Further Details
For more detailed procedures and technical specifications, refer to the Client Asset Protection & Safeguarding Manual, which supplements this policy with operational guidance and control checklists.
11 Data Protection & Privacy
11.1 Purpose and Scope
As a licensed Virtual Asset Service Provider (VASP), Bitkaya processes sensitive personal and financial information. This policy ensures that all data handled by Bitkaya—across business units, employees, contractors, partners, and vendors—is processed securely, lawfully, and transparently.
Objectives:
- Comply with the Curaçao Privacy Act (2013), General Data Protection Regulation (GDPR), and Financial Action Task Force (FATF) standards.
- Protect the privacy and rights of clients, employees, and business partners.
- Define accountability for data controllers, processors, and all staff members.
Scope: Applies to all personal and financial data collected or processed by Bitkaya, including KYC/AML information, wallet and transaction details, employee and vendor records, monitoring logs, and data shared through third-party integrations.
11.2 Principles of Data Protection
Bitkaya’s data handling practices are based on the following principles:
- Lawfulness and Transparency: All data processing activities must have a valid legal basis, and individuals are informed of how their data is used.
- Purpose Limitation: Data is collected for specific, legitimate purposes and not reused for unrelated activities.
- Data Minimization and Accuracy: Only information necessary for the stated purpose is collected, kept accurate, and regularly updated.
- Storage Limitation: Personal data is retained only as long as required. (Anti-Money Laundering record-keeping obligations may override erasure requests.)
- Integrity and Security: Data is protected through encryption, controlled access, and detailed logging.
- Accountability: Bitkaya maintains comprehensive records of processing and conducts regular audits to ensure compliance.
11.3 Roles and Responsibilities
- Data Controller: Bitkaya determines the purposes and means of all data processing activities.
- Data Processors: Third-party service providers acting on behalf of Bitkaya must adhere to equivalent privacy and security standards.
- Compliance Officer: Oversees compliance, advises management on data protection risks, and serves as the point of contact for regulators.
- Employees: Must handle data in accordance with company policy. Breaches of confidentiality or data protection rules may result in disciplinary action.
11.4 Data Subject Rights
Bitkaya respects and facilitates the following rights of individuals whose data it processes:
- The right to be informed about data collection and use.
- The right to access and obtain copies of personal data.
- The right to rectify inaccurate or incomplete data.
- The right to erasure (where permitted by law).
- The right to object to or restrict processing, particularly for marketing purposes.
- The right to data portability in a commonly used, machine-readable format.
- The right to safeguards in cases of automated decision-making or profiling.
11.5 Legal Bases for Processing
Data processing at Bitkaya is always grounded in one or more lawful bases:
- Consent: For optional services such as marketing communications.
- Contractual necessity: For account setup, service delivery, and transaction execution.
- Legal obligation: To comply with anti-money laundering, tax, and employment laws.
- Vital or public interest: For fraud prevention, sanctions compliance, and regulatory cooperation.
- Legitimate interest: For security, system monitoring, and service improvement.
11.6 Special Categories of Data
Sensitive personal information (such as data on health, religion, political opinions, or criminal records) is not collected unless explicitly required by law or with the individual’s consent. When processing is unavoidable, such data must be encrypted, strictly access-controlled, and logged for audit purposes.
11.7 Data Transfers
Personal data may only be transferred to countries or entities offering adequate levels of protection. If data is transferred to a country without equivalent safeguards, Bitkaya must implement appropriate protections such as:
- Written consent from the data subject.
- Standard contractual clauses (SCCs) approved by regulators.
- Binding corporate rules or other recognized mechanisms.
11.8 Security and Risk Management
Bitkaya employs both technical and organizational measures to protect data:
- Technical Controls: Encryption, cold-storage segregation, secure key management, and intrusion detection systems.
- Organizational Controls: Role-based access management, regular cybersecurity and AML training, and independent penetration testing.
- Incident Response: Any data breach must be reported within 72 hours to the Compliance Officer, who assesses and notifies regulators and affected individuals where there is a high risk of harm.
11.9 FATF-Specific Data Handling
Bitkaya’s data processing supports AML and counter-terrorism obligations:
- Customer Due Diligence (CDD): Verification of client identity, address, and beneficial ownership.
- Travel Rule: Recording and transmission of sender and recipient data for transactions exceeding USD/EUR 1,000.
- Record Retention: Data is stored for at least five years after the end of the relationship or last transaction.
- Unusual Transaction Reports (UTRs): Submitted to the Financial Intelligence Unit (FIU) Curaçao as required.
- Access Control: Only authorized personnel may access CDD or transaction monitoring records.
11.10 Third-Party Processing
All third parties processing data on behalf of Bitkaya may enter into a Data Processing Agreement (DPA) covering:
- Clear instructions on data use and retention.
- Adequate security and confidentiality measures.
- Prompt breach notification procedures.
- Prohibition on unauthorized sub-processing without approval.
11.11 Oversight and Governance
- Annual Reviews and Audits: Regular internal assessments ensure policy effectiveness.
- Data Protection Impact Assessments (DPIAs): Required for new products or processes that pose a high privacy risk.
- Training: Provided to all staff at onboarding and refreshed annually.
- Senior Management Oversight: The Board and executive management monitor compliance through periodic reports from the Compliance Officer.
11.12 Sanctions and Liabilities
Non-compliance with data protection laws may result in:
- Regulatory fines or enforcement actions.
- Civil claims for damages from affected individuals.
- Criminal penalties where applicable.
- Revocation of Bitkaya’s licenses or authorizations.
Employees or contractors responsible for violations may face disciplinary measures, up to and including termination.
11.13 Further Details
For detailed operational guidance, templates, and compliance checklists, refer to the Data Protection & Privacy Manual.
12 Business Continuity Management
12.1 Purpose and Scope
This framework establishes Bitkaya’s Business Continuity Management (BCM) approach, designed to ensure operational resilience, compliance with the Central Bank of Curaçao and Sint Maarten (CBCS) and ISO 22301 standards, and the ability to recover effectively from any disruption.
It applies to all departments, employees, contractors, suppliers, partners, regulators, and clients. The policy ensures that critical business operations can continue or resume rapidly following unforeseen incidents.
12.2 BCM Policy Statement
The BCM Policy is formally approved by the Board of Directors and reflects Bitkaya’s commitment to resilience, preparedness, and accountability. The company ensures that sufficient resources and governance structures are maintained to comply with all legal, regulatory, and contractual obligations.
The policy is reviewed at least annually and following any significant incident to ensure ongoing effectiveness and alignment with current risks.
12.3 Objectives
The primary objectives of Bitkaya’s BCM framework are to:
- Protect employees, clients, and other stakeholders.
- Restore critical operations within defined Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
- Minimize financial, legal, operational, and reputational impacts.
- Ensure compliance with supervisory, legal, and contractual obligations.
12.4 Context and Stakeholders
Bitkaya’s continuity planning considers both external and internal factors that may affect resilience:
External context: The regulatory and political environment, fintech developments, natural hazards, and market or competitive pressures.
Internal context: The company’s products and services, IT infrastructure, personnel, governance model, and vendor dependencies.
Key stakeholders include regulators, clients, employees, suppliers, auditors, insurers, and emergency services, all of whom play a role in ensuring the continuity of operations.
12.5 Governance & Responsibilities
BCM governance is structured as follows:
- Board of Directors: Approves the policy, allocates necessary resources, and reviews audit results.
- Departments: Maintain departmental continuity sub-plans and ensure staff are trained and aware of their responsibilities.
- Employees: Adhere to assigned BCM roles, follow procedures, and participate in training and exercises.
- Audit Function: Conducts annual internal or external audits, ensuring that identified issues are tracked to resolution.
12.6 Business Impact Analysis (BIA)
The Business Impact Analysis identifies the company’s critical business functions, their interdependencies, and the maximum tolerable downtime for each. It establishes RTOs and RPOs to guide recovery priorities and strategies.
The BIA is reviewed annually or whenever significant operational, structural, or technological changes occur.
12.7 Risk Assessment
An annual BCM risk assessment evaluates potential threats to business operations, including cyber incidents, natural disasters, operational disruptions, and regulatory events.
The assessment identifies single points of failure and defines mitigation strategies such as risk reduction, transfer, avoidance, or acceptance, ensuring that risk exposure remains within Bitkaya’s tolerance level.
12.8 Continuity Strategies
Bitkaya maintains robust continuity strategies to ensure uninterrupted operations during crises, including:
- Use of alternate worksites and remote working capabilities.
- Redundant and distributed data backups with defined recovery procedures.
- Vendor continuity agreements and the designation of backup suppliers to reduce dependency risks.
12.9 Continuity Sub-Plans
The BCM framework includes specific sub-plans addressing key operational areas:
- Principal Plan: Defines command structure, roles, responsibilities, and vendor contact directories.
- IT Disaster Recovery Plan (DRP): Focuses on restoring infrastructure, applications, and essential data.
- Cybersecurity Recovery Plan: Provides detailed playbooks for managing ransomware, DDoS attacks, and insider threats.
- Evacuation Plan: Outlines evacuation routes, muster points, and regular drill procedures.
Each sub-plan is regularly updated and tested to ensure operational readiness.
12.10 Incident Response Plan
The Incident Response Plan defines activation criteria, roles of the Incident Response Team, escalation pathways, and regulatory reporting obligations.
Communication Protocols:
- Internal: Secure messaging via chat, call trees, SMS, and email.
- External: Timely updates to clients, notifications to regulators, and coordinated media responses.
- Alternatives: Backup channels such as satellite phones, radios, and secure messaging apps.
Communication procedures are tested yearly to ensure effectiveness under stress conditions.
12.11 Training, Awareness & Resources
All employees receive annual BCM training, which includes tabletop exercises, phishing simulations, and crisis management workshops.
Dedicated resources are allocated for staff training, backup site maintenance, communication systems, and insurance coverage. Continuous awareness ensures readiness across all organizational levels.
12.12 Testing & Exercises
Bitkaya’s BCM testing schedule ensures consistent validation of recovery capabilities:
- Tabletop drills.
- IT recovery exercises.
- IT disaster recovery test.
- Organization-wide simulation exercises.
Results and lessons learned from each test are documented, reviewed by management, and followed by corrective action plans to close any identified gaps.
12.13 Maintenance, Review & Audit
All BCM policies and plans are reviewed annually or following significant changes or incidents. Findings are documented, tracked, and resolved to maintain continuous improvement.
12.14 Documentation & Records
Comprehensive records of BCM policies, plans, training logs, test results, incident reports, and regulatory submissions are securely maintained. All documentation is stored in secure, auditable repositories and remains readily available for inspection or audit purposes.
12.15 Further Details
For further details, refer to the Business Continuity Management Manual, which outlines the full set of procedures supporting Bitkaya’s resilience and recovery framework.
13 Market Conduct and Trading
13.1 Purpose and Scope
This policy defines the principles and procedures governing Bitkaya’s market conduct and trading activities as a licensed VASP. It applies to all employees, officers, directors, contractors, and third parties acting on Bitkaya’s behalf.
The policy covers:
- The issuance, exchange, custody, and transfer of virtual assets.
- Dealings with clients, regulators, and service providers.
- Marketing, advertising, communications, and promotional activities.
Its purpose is to ensure that all market interactions are conducted with integrity, transparency, and accountability, in full compliance with legal and ethical standards.
13.2 Core Principles
Bitkaya is committed to operating ethically, transparently, and in the best interests of its clients. All staff and business partners must adhere to the following principles:
13.2.1 Integrity & Fairness
Bitkaya prohibits any form of manipulative trading, including spoofing, front-running, wash trading, or any activity designed to distort market prices. Communications must be honest, balanced, and not misleading, ensuring that all clients are treated fairly and equitably.
13.2.2 Transparency
All clients must receive clear disclosures on pricing, fees, risks, and applicable policies. Any material changes to terms or procedures are communicated promptly. Regulatory reporting must be accurate, timely, and complete to maintain confidence and compliance.
13.2.3 Compliance
Bitkaya fully adheres to all applicable laws, including AML/CFT regulations, sanctions rules, data protection laws, and consumer protection requirements. All employees complete mandatory compliance training, and continuous monitoring systems are in place to identify and address potential breaches.
13.2.4 Accountability
Each employee and manager is responsible for the integrity of their decisions and actions. The Board of Directors provides overall governance and oversight of market conduct and trading practices. All third-party partners are subject to due diligence, monitoring, and periodic reassessment.
13.2.5 Client-Centricity
Client interests are prioritized above short-term profitability. Bitkaya ensures secure custody, segregation of client accounts, and where feasible, maintains insurance coverage to protect client assets. Client feedback and complaints are reviewed systematically and used to strengthen service quality.
13.2.6 Innovation with Responsibility
New products and services undergo thorough risk, compliance, and cybersecurity assessments before launch. Identified risks are mitigated, disclosed, and monitored. Bitkaya contributes to the development of responsible and sustainable digital asset industry standards.
13.3 Prohibited Practices
The following activities are strictly forbidden:
- Market Manipulation: Any action intended to mislead or distort the market, including wash trading, spoofing, or pump-and-dump schemes.
- Insider Trading: Use or disclosure of material non-public information for personal or third-party gain.
- Misrepresentation: False, misleading, or exaggerated statements in any form of communication or marketing.
- Conflicts of Interest: Undisclosed or unmanaged conflicts between personal and client interests.
- Unlicensed Activity: Offering regulated services without obtaining all required licenses or approvals.
13.4 Trading Conduct
Bitkaya enforces high standards of trading discipline:
- Best Execution: Every order is executed to achieve the most favorable outcome for clients, with periodic reviews of execution quality.
- Order Handling: All orders are processed fairly, promptly, and confidentially, with complete audit trails.
- Front Running: Strictly prohibited, with automated surveillance in place to detect and prevent it.
- Personal Trading: Employees must never use insider information.
13.5 Communication & Promotion
All marketing and communication activities must reflect Bitkaya’s commitment to transparency and integrity:
- Advertising: Must be accurate, fair, and compliant with regulations.
- Client Communication: All communications must include clear risk disclosures, relevant updates, and accessible feedback channels.
- Social Media: Only authorized representatives may post on behalf of Bitkaya. Confidential, misleading, or speculative content is strictly forbidden.
13.6 Client Asset Protection
Bitkaya safeguards client assets through stringent security and custody measures:
- Segregation: Client assets are fully segregated from company funds.
- Custody: Assets are secured using institutional-grade technologies such as multi-signature wallets, hardware security modules (HSMs), and cold storage.
- Insurance: Coverage is obtained where feasible, with full disclosure of terms and limitations.
- Safeguards: Systems employ advanced cybersecurity, encryption, incident response, and business continuity protocols.
13.7 Complaint Handling
Bitkaya maintains transparent and efficient channels for client complaints. Complaints are acknowledged within five business days and resolved within standard response timelines. Reviews are impartial, consistent, and documented. Unresolved or serious matters are escalated to senior management or regulators as appropriate. All records are maintained for at least ten years, and complaint trends are analyzed to identify areas for improvement.
13.8 Monitoring & Enforcement
Bitkaya applies robust monitoring and enforcement mechanisms:
- Surveillance: Automated tools continuously detect market abuse, insider trading, and AML/CFT red flags.
- Audit: Independent, risk-based audits validate the effectiveness of controls.
- Disciplinary Actions: Sanctions range from written warnings to termination; serious breaches are reported to relevant authorities.
- Whistleblowing: Employees are encouraged to report misconduct confidentially and are protected from retaliation.
13.9 Regulatory Compliance
Bitkaya maintains all required licenses and renewals on time. The company fulfills its AML/CFT obligations, including accurate and timely submission of Unusual Transaction Reports (UTRs).
Bitkaya engages proactively and transparently with supervisory authorities and ensures compliance with FATF and multi-jurisdictional standards in all cross-border activities.
13.10 GDF Code Alignment
Bitkaya aligns its practices with the Global Digital Finance (GDF) Code of Conduct, ensuring adherence to international standards of ethical behavior, transparency, and responsible innovation within the digital asset sector.
13.11 Risk Management & Conflicts of Interest
Bitkaya operates under an enterprise-wide risk management framework that encompasses operational, financial, technological, compliance, and reputational risks. This framework includes controls for monitoring, cybersecurity, business continuity, and stress testing.
All potential conflicts of interest must be disclosed and effectively managed. Employees are restricted from personal trading that could influence client outcomes or create bias. The acceptance of gifts or benefits that may impair impartial judgment is strictly prohibited.
Bitkaya upholds a client-first principle, ensuring that all decisions are made in the best interest of clients and the integrity of the market.
13.12 Further Details
For further details, refer to the Market Conduct & Trading Compliance Manual, which provides the full operational procedures supporting this policy.
14 Client Complaints Handling
14.1 Purpose & Scope
Bitkaya is committed to ensuring that all client complaints are managed promptly, fairly, and transparently, in full alignment with the requirements of the Central Bank of Curaçao and Sint Maarten (CBCS).
Purpose:
- Ensure full compliance with applicable regulatory and supervisory standards.
- Protect the rights and interests of clients, partners, and stakeholders.
- Use complaints as valuable feedback to enhance the quality of services and internal controls.
Scope: This policy applies to all complaints received about Bitkaya’s products, services, staff behavior, compliance processes, or ethical practices. Complaints may be submitted verbally, in writing, or electronically.
14.2 Definitions
- Complaint: Any expression of dissatisfaction related to Bitkaya’s products, services, or personnel—regardless of how the concern is phrased.
- Complainant: Any client, partner, or stakeholder who raises a concern with Bitkaya.
14.3 Governance
- The policy is approved by Senior Management and forms part of Bitkaya’s overall risk management framework.
- The Complaints Handling process is reviewed yearly to ensure effectiveness, fairness, and regulatory alignment.
- Regular updates are communicated to the Board as part of the compliance reporting cycle.
14.4 Complaints Function
The Compliance Officer oversees the entire process—from intake to resolution—ensuring impartiality and consistency. Responsibilities include:
- Receiving and registering complaints.
- Investigating facts objectively, with input from relevant departments.
- Ensuring timely communication with the complainant.
- Escalating unresolved or complex cases when necessary.
- Reporting trends and findings to management and regulators.
The Compliance Officer must act independently and in the best interests of clients and the company’s integrity.
14.5 Submission Channels
Clients can submit complaints through any of the following channels:
- Email: complaints@bitkaya.com
- Online Form: www.bitkaya.com/complaints
- Mail: Bitkaya Board, Julianaplein 36, Willemstad, Curaçao
Complainants are encouraged to include their full contact information, a clear description of the issue, relevant dates, and any supporting documents or evidence.
14.6 Acknowledgment
- Bitkaya will acknowledge receipt of a complaint within five (5) business days.
- Within two (2) weeks, the complainant will receive confirmation of registration, the name of the assigned Complaints Officer, and an estimated timeline for resolution.
14.7 Register & Recordkeeping
- All complaints are recorded in a secure complaints register that tracks details, status, and resolution.
- Records include all correspondence, evidence, findings, and follow-up actions.
- Complaints records are retained for a minimum of ten (10) years and made available for regulatory review upon request.
14.8 Investigation
Each complaint is reviewed objectively and confidentially.
- Investigations include evidence analysis and, where appropriate, consultation with internal experts or external specialists.
- The confidentiality of both the complainant and any individuals involved is protected throughout the process.
14.9 Resolution
- Bitkaya aims to provide a final resolution within thirty (30) business days from the date of acknowledgment.
- The complainant will receive a final written response outlining the findings, the decision, and any corrective or preventive measures taken.
- If additional time is required due to complexity, the complainant will be informed with an updated timeline.
14.10 Reporting & Follow-Up
- Complaint data is analyzed periodically to identify recurring issues, trends, or root causes.
- Senior Management reviews these findings every six months as part of continuous risk oversight.
- Reports are shared with the CBCS when required, including summaries of the nature, volume, and outcome of complaints.
14.11 Information to Clients
Information on the complaints process is clearly communicated through:
- Bitkaya’s website
- Client onboarding documents
- Brochures, contracts, and other communications
All information must be current, transparent, and easy to understand.
14.12 Escalation
If a complainant is dissatisfied with Bitkaya’s response or handling of a complaint, they may escalate the matter to one of the following external authorities:
- Central Bank of Curaçao and Sint Maarten (CBCS)
- Court of Justice or an Alternative Dispute Resolution (ADR) mechanism, where applicable
Bitkaya will fully cooperate with all regulatory or judicial bodies in the event of escalation.
14.13 Continuous Improvement
Complaints are treated not only as issues to resolve but as opportunities for learning and improvement.
- Recurrent or escalated cases trigger root cause analysis and corrective action plans.
- Lessons learned feed into risk management, staff training, and service enhancement initiatives.
- The Compliance Officer tracks implementation of corrective measures and reports outcomes to management.
14.14 Further Details
For further details, procedures, and templates, refer to the Client Complaints Handling Manual, which supplements this policy with operational guidance and reporting formats.
15 IT & Cybersecurity
15.1 Purpose and Scope
This policy establishes the governance, risk management, and information security framework for Bitkaya’s technology environment. It ensures that all systems and digital assets are protected against unauthorized access, loss, or misuse, while maintaining operational continuity across critical services.
The framework covers:
- Governance of IT systems and cybersecurity controls.
- Protection of cryptocurrency wallets and private keys.
- Business continuity for trading, wallet, and compliance platforms.
- Cybersecurity standards aligned with AML/CFT obligations.
- Secure authentication tools, including hardware keys and password managers.
This policy applies to all Bitkaya systems and data environments, including cloud and on-premise infrastructure, trading and custody platforms, KYC/AML systems, and data related to customers, employees, and partners.
15.2 Governance & Oversight
- Board of Directors: Ensures compliance with CBCS, FATF, and applicable custody and cybersecurity standards. Approves all strategic IT and wallet security policies.
- IT Steering Committee: Oversees IT risk management, custody arrangements, vendor and cloud risks, and platform resilience. Reviews and approves material changes to core systems.
- Audit & Compliance Function: Conducts annual reviews of AML/CFT systems, IT monitoring, cybersecurity controls, and adherence to internal policies.
- Key Decisions: Include wallet architecture, transaction approval flows, segregation of duties, and access management for high-privilege systems.
15.3 Information Security Management
Bitkaya’s information security practices are designed to protect all sensitive systems and data:
- Private keys, wallets, and blockchain systems are safeguarded through strong encryption and secure storage.
- Multi-Factor Authentication (MFA) using hardware keys is mandatory for all critical systems.
- A corporate password manager is required to ensure the secure handling of credentials.
- Hardware Security Modules (HSMs) are used for key storage and encryption, supported by verified backups.
- Blockchain analytics tools are fully integrated with AML monitoring systems for continuous oversight.
15.4 IT & Cyber Risk Management
Key threats include wallet or exchange hacks, phishing attacks, ransomware, denial-of-service (DDoS) incidents, insider misuse, and AML control failures.
Preventive and detective controls include:
- Hardware key authentication and centralized password management.
- Cold storage and multi-signature configurations for asset custody.
- Network and behavioral monitoring to detect anomalies.
- Regular penetration testing and smart contract reviews by independent specialists.
- Segregation of duties and automated alerts for unusual activity.
15.5 Software Testing & Quality Assurance
Before deployment, all software releases undergo rigorous testing to ensure reliability and security.
- Testing covers wallets, AML filters, custody solutions, and user interfaces.
- Crypto-specific checks include address validation, replay and fraud prevention, and attack simulations.
- Test environments are fully isolated and protected with MFA and restricted access.
- Release approvals require sign-off from both IT and Compliance.
15.6 IT Service Management
- Critical Services: Wallet management, trading engines, blockchain nodes, and compliance systems must maintain defined uptime and recovery standards.
- All IT incidents are logged, and AML-related events are escalated to Compliance without delay.
- System changes — including those affecting wallets, custody arrangements, or smart contracts — require committee or Board approval.
- Service Level Agreements (SLAs) specify uptime targets, Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs) in alignment with the Business Continuity Plan.
15.7 Safe and Sound Electronic Banking
Bitkaya enforces strict cybersecurity measures for all digital financial operations:
- MFA and hardware keys are mandatory for all administrators and strongly encouraged for clients.
- Dual authorization is required for large withdrawals.
- Client education programs promote safe practices, including phishing awareness and scam prevention.
15.8 Business Continuity & Disaster Recovery
Bitkaya ensures technology resilience through redundant systems and tested contingency plans:
- Cold wallet backups are stored securely.
- Redundant blockchain nodes ensure uninterrupted transaction processing.
- Critical operations — trading, wallet management, and AML monitoring — have predefined recovery procedures.
- Annual recovery tests and simulated cyber drills assess readiness for incidents such as ransomware, wallet compromise, or DDoS attacks.
- Incident playbooks outline immediate steps, roles, and communication channels for crisis management.
15.9 IT Framework & Integration
Bitkaya’s IT and cybersecurity framework aligns with recognized international standards:
- ISO 27001 – Information Security Management.
- ISO 22301 – Business Continuity Management.
- COBIT – IT Governance and Control.
- ISO 20000 / ITIL – IT Service Management.
- FATF Guidance – Technology and AML/CFT obligations.
- Integrated third-party and vendor risk management practices ensure all service providers meet comparable standards.
15.10 Training & Awareness
Building a strong cybersecurity culture is a shared responsibility across all levels of Bitkaya.
- Mandatory Training: All staff must complete annual cybersecurity, and wallet security training.
- Specialized Modules: Technical teams receive focused training on password management, YubiKeys, and custody security.
- Client Education: Clients receive guidance on MFA setup and fraud prevention through digital campaigns and support materials.
- Ongoing Awareness: Regular phishing simulations, visual reminders, and awareness initiatives promote continuous vigilance and “crypto hygiene”.
15.11 Continuous Improvement
Bitkaya continually evaluates and enhances its IT and cybersecurity practices through defined performance metrics and oversight mechanisms.
- Key indicators include system uptime, fraud detection rates, and incident response times.
- Annual Board reviews assess alignment with CBCS, FATF, and international best practices.
- Lessons learned from incidents and recovery drills are integrated into updated controls and training.
- Independent audits validate the effectiveness of custody, key management, and AML-related systems.
15.12 Further Details
For more detailed technical standards, operational procedures, and control checklists, refer to the IT & Cybersecurity Manual.
16 Commercial Off-The-Shelf (COTS) Software Acceptance & Testing
16.1 Purpose and Scope
This policy establishes the framework for evaluating, testing, and approving all Commercial Off-The-Shelf (COTS) software used by Bitkaya. It ensures that every software acquisition supports operational resilience, data integrity, and compliance with CBCS regulatory requirements.
Purpose:
- Ensure all COTS solutions align with operational, security, and compliance standards.
- Mitigate risks associated with third-party software use.
- Promote consistency and transparency in testing and approval.
Scope: Applies to all COTS systems used across Bitkaya, including onboarding, AML/CFT monitoring, reporting, HR, and IT applications. The policy covers new acquisitions, software patches, version upgrades, and system migrations. It is fully integrated within Bitkaya’s Operational Risk Management Framework (ORMF).
16.2 Governance & Responsibilities
Strong governance ensures independent oversight and accountability in the COTS selection and testing process.
- Managing Board: Establishes policies, allocates resources, and communicates acceptance standards.
- Corporate Operational Risk Function (CORF): Provides independent challenge, reviews testing outcomes, evaluates operational and compliance risks, and delivers related training.
- Internal Audit: Conducts periodic reviews to verify compliance and audit the test management framework in line with TMMi Level 2 (or higher) standards.
16.3 COTS Acceptance Process
Every COTS product must undergo a structured, risk-based evaluation before approval for production use.
- Risk Assessment: Evaluate potential risks related to information security, legal and regulatory compliance, data protection, and vendor reliability.
- Test Strategy: Define testing levels (e.g., integration, user acceptance, operational acceptance), specify entry and exit criteria, and align scope with risk severity.
- Test Planning: Outline objectives, testing methodology, resources, timelines, and stakeholder roles. All plans must receive formal sign-off before execution.
16.4 Testing Requirements
All COTS software must be tested under controlled conditions to verify functionality, security, and compatibility.
- Environment: Testing must occur in an isolated, controlled environment that closely mirrors production.
- Design & Execution: Test cases must include valid and invalid inputs, apply structured testing techniques, and log all defects in a central repository.
- Security Testing: Perform penetration tests, vulnerability scans, configuration reviews, and checks on authentication and encryption mechanisms.
- Acceptance Criteria: Software can only be approved if no critical defects remain, all residual risks are within appetite, and the CORF provides formal approval.
16.5 Ongoing Testing & Maintenance
To maintain reliability and security, all software is subject to continuous evaluation:
- Conduct regression testing following updates, patches, or configuration changes.
- Maintain a repository of all test results, plans, approvals, and defect logs for audit purposes.
- Perform internal TMMi maturity assessments regularly at least once every three years.
16.6 Training & Competence
Testing personnel must be adequately trained and certified to ensure competence and consistency.
- Bitkaya’s Test Training Program covers test design, risk-based testing, AML/CFT compliance, and COTS best practices.
- Delivery methods include workshops, mentoring, vendor-led sessions, and certification programs.
- Training effectiveness is reviewed annually, with refresher sessions or corrective action where gaps are identified.
16.7 Continuity & Outsourcing
COTS software must meet the same business continuity and outsourcing standards as internal systems.
- Solutions must align with Bitkaya’s Business Continuity Plan (BCP) and Disaster Recovery (DR) framework.
- Vendor contracts must include clear Service Level Agreements (SLAs) covering support, patching, and incident reporting timelines.
- All outsourced COTS arrangements must comply with CBCS outsourcing best practices.
16.8 Review Cycle
- The policy is reviewed annually or sooner if triggered by changes in CBCS regulation, major software incidents, or the introduction of new critical applications.
- Reviews are coordinated by the Managing Board.
16.9 Further Details
For detailed testing procedures, templates, and approval workflows, refer to the Commercial Off-The-Shelf Software Acceptance & Testing Manual.
17 Finance & Tax Compliance
17.1 Purpose and Scope
This policy provides Bitkaya B.V. with a framework to ensure full compliance with Curaçao’s corporate governance, accounting, and tax obligations as a licensed Virtual Asset Service Provider (VASP). It establishes clear standards for legal compliance, transparency, and financial accountability.
Scope:
- Legal: Compliance with Book 2 of the Civil Code governing B.V. companies.
- Tax: Adherence to Corporate Income Tax (CIT), Turnover Tax (TOT), wage tax, social security, and applicable withholding tax (WHT) obligations.
- Reporting: Preparation and filing of statutory financial statements, management reports, and regulatory submissions.
- Authorities: Engagement with the Tax Inspectorate, the Social Security Bank (SVB), and the Central Bank of Curaçao and Sint Maarten (CBCS).
- Applicability: Directors, management, finance personnel, and any third-party accounting or compliance providers acting for Bitkaya.
17.2 Legal & Corporate Governance Framework
Corporate Form
Bitkaya B.V. is a private limited liability company. Shareholders’ liability is limited to their capital contribution as recorded in the company’s Articles of Association.
Administrative Duties
- Maintain accurate and complete accounting records reflecting the company’s financial position and operations.
- Records must be organized so that the company’s rights and obligations can be determined at any time.
- All financial records must be retained for a minimum of 10 years.
Annual Financial Statements
- Annual financial statements must include a balance sheet, profit and loss account, notes, and an external expert opinion.
- Financial statements must be submitted to the CBCS within required timelines, along with any management letter.
- Shareholders must approve the accounts, which must present a true and fair view of the company’s financial position.
17.3 Taxation Framework
17.3.1 Corporate Income Tax (CIT)
- The standard CIT rate is 22%, though reduced rates may apply for activities.
- Annual CIT returns must be filed within six months after the end of the financial year.
- Transfer pricing rules apply to transactions with related parties and must be supported by documentation.
17.3.2 Turnover Tax (TOT)
- TOT is generally levied at 6% on domestic supplies of goods and services.
- Exemptions may apply to exports, e-zone operations, and certain financial services.
- Returns must be filed monthly, supported by accurate invoices and customer classifications.
17.3.3 Payroll & Social Security
- Bitkaya must withhold wage tax and SVB contributions from employee salaries.
- Monthly filings and timely payments are mandatory.
- Employment of foreign nationals requires proper work and residence permits.
- Residency status determines wage tax applicability.
17.3.4 Withholding Tax (WHT)
- Curaçao generally does not levy withholding tax on dividends, interest, or royalties.
- Exceptions may apply under specific legislation or treaty provisions.
- All outbound payments must be properly documented and supported by tax opinions if necessary.
17.4 Record-Keeping & Reporting
- Financial reporting should align with International Financial Reporting Standards (IFRS) wherever practicable.
- All financial and tax records must be retained for 10 years.
- Large entities may be subject to external audit requirements under IFRS.
- Monthly management accounts are recommended for oversight.
- Duties related to financial reporting, approvals, and reconciliations must be properly segregated.
17.5 Interaction with Authorities
- CIT: Filed annually with quarterly advance payments.
- TOT: Filed monthly with full supporting records.
- Wage Tax & SVB: Filed and paid monthly with complete employee documentation.
- Authorities (Tax Inspectorate, CBCS, SVB) may request records at any time; full cooperation is required.
- To ensure compliance:
- Maintain a tax and reporting calendar.
- Document all tax positions and decisions.
- Engage proactively with authorities to clarify uncertainties and avoid penalties.
17.6 Compliance Checklist
To remain in full compliance, Bitkaya must ensure that:
- Corporate registration details are up to date with the Chamber of Commerce.
- Annual accounts are prepared, approved, filed with CBCS, and published within statutory deadlines.
- CIT returns and quarterly advance payments are completed and submitted.
- TOT registration remains active, and monthly returns are filed accurately.
- Payroll and SVB filings are current and reconciled.
- Financial and tax records are securely retained for at least 10 years.
- External audit requirements are assessed and fulfilled annually.
- A compliance calendar tracks all statutory obligations and deadlines.
- Shareholders are briefed on dividend and withholding tax implications.
- Directors receive regular updates on compliance risks and legal duties.
17.7 Further Details
For detailed guidance on reporting standards, filing templates, and compliance procedures, refer to the Finance & Tax Compliance Manual.
18 Employee Handbook
18.1 Introduction
Bitkaya operates in a fast-paced and highly regulated environment where integrity, responsibility, and accountability are essential. This handbook defines how every employee, officer, and contractor is expected to act in accordance with our ethical standards and regulatory obligations. It outlines the company’s core policies on ethics, anti-bribery and corruption, and whistleblowing, and reinforces our collective responsibility to maintain a culture of compliance and transparency.
18.2 Employee Responsibilities
All employees share responsibility for upholding Bitkaya’s reputation and compliance framework. Expectations include:
-
Read and Understand Policies — Employees must familiarize themselves with all company policies and seek guidance from HR or Compliance whenever clarification is needed.
-
Complete Mandatory Training — Participation in mandatory training—including AML/CFT, Anti-Bribery and Corruption (ABC), Cybersecurity, and the Code of Ethics—is required on time and with periodic refreshers.
-
Act Honestly — Employees must act with honesty and integrity at all times, avoiding any form of deception, fraud, or misuse of company resources. Each employee represents Bitkaya’s reputation.
-
Protect Assets and Data — Client funds must remain segregated at all times. Employees must follow all information security and access control procedures, reporting any data loss, theft, or breach immediately.
-
Speak Up — Suspected misconduct, unethical behavior, or policy breaches must be reported in line with the Whistleblower Policy. Retaliation against individuals who raise concerns in good faith is strictly prohibited.
-
Avoid Conflicts of Interest — Employees must disclose any personal or financial interests that may conflict with their duties—such as trading on insider information, vendor relationships, or acceptance of gifts or favors.
-
Support Reviews and Audits — All employees are expected to cooperate fully with internal or external audits and reviews, providing accurate and timely information when requested.
18.3 Consequences of Non-Compliance
18.3.1 Violations
- Minor infractions such as missed training or incomplete documentation may result in written warnings and mandatory retraining.
- Serious violations, including AML/CFT breaches, cybersecurity incidents, or undisclosed conflicts of interest, may result in disciplinary action up to termination and may be reported to authorities.
- Gross misconduct, such as insider trading, fraud, bribery, theft, or market manipulation, leads to immediate dismissal and potential criminal prosecution.
18.3.2 Accountability
Both individuals and Bitkaya as a company may face legal or regulatory penalties for non-compliance. Every employee is accountable for maintaining the standards expected by regulators, clients, and the public.
18.3.3 Why It Matters
Adherence to these standards protects clients, preserves our regulatory licenses, and upholds market integrity and trust.
18.4 Commitment from Leadership
Leadership Commitments
Bitkaya’s leadership team is committed to modeling integrity, providing adequate resources for compliance and training, fostering a culture where employees can safely raise concerns, and embedding compliance into business operations.
Equal Accountability
Leaders are held to the same standards as all employees. Breaches of conduct or compliance obligations at the management level are treated with the same seriousness and consequences.
18.5 Anti-Bribery & Corruption (ABC)
Bitkaya enforces a zero-tolerance policy toward bribery and corruption as detailed in the standalone ABC Manual:
- General Rule: Bribery, corruption, and facilitation payments are strictly prohibited.
- Gifts and Hospitality: Permitted only when nominal, infrequent, transparent, and not intended to influence business decisions.
- Political and Charitable Contributions: Political donations are not permitted. Charitable donations must be legitimate and pre-approved.
- Due Diligence: All third-party partners and vendors must undergo integrity and compliance vetting.
- Record-Keeping: All transactions must be accurately recorded. Off-book or unrecorded accounts are prohibited.
- Disciplinary Measures: Violations of the ABC Policy can result in termination and potential legal prosecution.
- Employee Responsibility: All employees must complete ABC training and promptly report any suspicions of bribery or corruption.
18.6 Whistleblower Policy & Reporting
Bitkaya encourages open reporting and ensures protection for those who raise genuine concerns.
- Scope: Applies to employees, contractors, suppliers, and other third parties.
- Reportable Issues: Fraud, legal or policy breaches, health and safety violations, harassment, discrimination, and environmental or ethical concerns.
- Reporting Channels: Reports may be made through direct managers, HR, the Board, or externally to the CBCS. Anonymous reporting is permitted.
- Protection: Retaliation is prohibited. Confidentiality is maintained wherever possible.
- Process: Reports are acknowledged within five business days, assessed, investigated, and outcomes communicated to the reporting party.
- Bad-Faith Reports: Malicious or false reports made in bad faith are not protected and may result in disciplinary action.
18.7 Code of Ethics
Bitkaya’s Code of Ethics outlines the fundamental principles that guide behavior and decision-making:
- Integrity: Always act honestly and responsibly.
- Compliance: Follow all applicable laws, regulations, and internal policies.
- Client-First: Place client interests ahead of personal or corporate gain.
- Conflict Disclosure: Declare any situation that could influence impartiality.
- Confidentiality: Protect company and client information.
- Professionalism: Maintain respectful, ethical, and transparent conduct at all times.
For VASP operations, employees must comply with AML/CFT obligations, refrain from market abuse or insider trading, promptly report cyber or operational risks, and align conduct with the Global Digital Finance (GDF) Code of Conduct.
Annual certification of adherence is required, and violations may lead to disciplinary and regulatory actions.
18.8 Conclusion
Bitkaya’s reputation depends on the integrity and judgment of its people. Every action, however small, contributes to the trust our clients and regulators place in us.
Employees are encouraged to use this handbook as a guide and to always ask themselves:
- Is this action honest and ethical?
- Does it protect our clients and the company?
- Would it withstand regulatory or public scrutiny?
By consistently making the right choices, we build a compliant, trusted, and innovative Bitkaya.
18.9 Further Details
For further details, refer to the Employee Handbook, which provides comprehensive guidance on conduct, compliance, and workplace ethics.
19 Internal Controls & Audit
19.1 Purpose and Scope
This policy defines Bitkaya’s internal control and audit framework as a licensed Virtual Asset Service Provider (VASP). It ensures that the company operates with integrity, transparency, and resilience while meeting its legal and regulatory obligations.
Objectives:
- Ensure compliance with AML/CFT/CPF and licensing requirements.
- Safeguard client assets and strengthen operational resilience.
- Maintain transparent governance, accountability, and auditability.
- Align internal controls with recognized global standards such as FATF, ISO 27001, SOC 2.
This framework applies to all business units, products, jurisdictions, and third-party service providers engaged by Bitkaya.
19.2 Governance & Accountability
Effective governance and clear accountability are essential to maintaining control integrity and ensuring independent oversight.
- Board of Directors: Provides ultimate oversight, approves this framework, and ensures adequate resources for control and audit functions.
- Compliance Officer (Second Line): Designs, implements, and monitors internal controls; reports deficiencies; escalates unresolved risks to the Board.
- Internal Audit (Third Line): Provides independent assurance on the effectiveness of governance, risk management, and control systems. Reports functionally to the Board.
- All Employees: Must comply with control requirements, promptly report breaches, and support a culture of compliance, transparency, and continuous improvement.
19.3 Core Internal Control Domains
Bitkaya’s control environment is organized into key domains to ensure coverage across critical risks:
19.3.1 Financial Crime Compliance
- Customer and counterparty due diligence (KYC, KYB, KYT).
- Sanctions screening and transaction monitoring.
- Reporting of suspicious activities (UTRs).
- Record retention for 5–10 years in compliance with regulatory standards.
19.3.2 Custody & Asset Protection
- Segregation of client and company funds.
- Secure multi-signature and hardware security module (HSM) wallet management.
- Daily reconciliations between on-chain and internal records.
- Appropriate insurance coverage for custody operations.
19.3.3 IT & Cybersecurity
- Least-privilege access management and encryption of sensitive data.
- Defined incident response protocol: 1-hour triage, 24-hour reporting, 5-day root cause analysis.
- Business continuity management (BCM) with established recovery time (RTO) and recovery point (RPO) objectives.
19.3.4 Operations & Client Protection
- Robust complaint-handling process with fair and transparent outcomes.
- Clear communication of fees and terms to clients.
- Monitoring of service-level agreements and response performance.
19.3.5 Third-Party & VASP Oversight
- Comprehensive vendor and counterparty due diligence.
- Service level agreements (SLAs) defining roles, responsibilities, and breach notification within 24 hours.
- Annual reassessments of third-party performance and risk.
- Verification of counterparties (Know Your VASP – KYV).
19.4 Audit Framework
Bitkaya maintains a multi-layered audit framework to ensure comprehensive, risk-based oversight and continuous improvement.
19.4.1 Internal Audit
- Conducts annual, risk-based audits covering key areas such as AML/CFT compliance, ABC, custody operations, IT and cybersecurity, BCM, and governance.
- Reports findings directly to the Audit & Risk Committee and the Board.
19.4.2 Second Line Testing
- Quarterly compliance reviews and control testing conducted by the Risk & Compliance function.
- Tracks remediation actions and verifies completion of corrective measures.
19.4.3 External and Regulatory Audits
- Annual AML/CFT audit conducted by an independent external reviewer.
- Evidence libraries maintained for regulatory readiness.
- Full cooperation with CBCS and other supervisory authorities during inspections or inquiries.
19.4.4 Financial Statement Audit
- Annual external audit under IFRS or GAAP standards.
- Focus areas include custody asset valuation, safeguarding, and revenue recognition.
19.5 Reporting & Escalation
- Weekly Operations Pack: Key control metrics and exceptions.
- Monthly Risk & Compliance Committee (RCC): Thematic findings and trend analysis.
- Quarterly Board Reports: Summary of risk trends, audit outcomes, and control improvements.
- Immediate Escalation: Material breaches or systemic risks reported without delay to senior management and regulators when required.
19.6 Training & Culture
- Mandatory onboarding and annual refresher training for all staff.
- Specialized training for high-risk functions (e.g., custody, AML, IT).
- Culture metrics include “speak-up” participation rates, phishing test results, and remediation timeliness.
19.7 Document Management
- The policy is reviewed annually or upon material changes in regulation or operations.
- A version-controlled log records all updates, approvals, and effective dates.
19.8 Further Details
For further details on audit procedures, templates, and schedules, refer to the Internal Controls & Audit Manual.
This document is confidential and intended solely for internal use by Bitkaya B.V. employees and authorized partners.
20 Regulatory Reporting & Communication
20.1 Purpose and Scope
This policy defines Bitkaya B.V.’s approach to regulatory reporting and communication in Curaçao. It ensures that all submissions, notifications, and regulator interactions are accurate, timely, and compliant with applicable laws and supervisory requirements.
The framework applies to all departments, employees, and third-party service providers involved in financial, operational, or compliance reporting.
Objectives:
- Fulfill all obligations under Curaçao law and CBCS VASP licensing conditions.
- Maintain transparent and cooperative communication with regulators.
- Ensure consistent standards for documentation, escalation, and response.
20.2 Key Regulatory Authorities
20.2.1 Central Bank of Curaçao & Sint Maarten (CBCS)
- Supervises Virtual Asset Service Providers (VASPs) and assesses “fit & proper” criteria for directors and key officers.
- Monitors financial soundness, governance, and AML/CFT compliance.
- Required reports include:
- Quarterly AML/CFT and governance reports.
- Annual audited financial statements and management letters.
- Notifications of material changes in ownership, management, or operations.
- Incident and breach reports within specified timelines.
20.2.2 Financial Intelligence Unit (FIU Curaçao)
- Oversees AML/CFT compliance and unusual transaction monitoring (NORUT).
- Required reports:
- Unusual Transaction Reports (UTRs) submitted via the FIU online portal.
- Immediate internal escalation of suspicious activity to the Compliance Officer.
- All staff are prohibited from tipping off clients or external parties.
20.2.3 Tax Authorities
- Responsible for corporate, turnover, payroll, and withholding taxes.
- Required reports:
- Annual Corporate Income Tax (CIT) return.
- Monthly or quarterly Turnover Tax (TOT) returns.
- Monthly payroll and social security filings.
- All filings are made through the official tax portal, and supporting records are retained for at least 10 years.
20.3 Internal Roles & Responsibilities
- Compliance Officer: Acts as primary contact for CBCS and FIU. Oversees AML/CFT reporting, manages suspicious activity and unusual transaction filings, maintains regulatory records, and provides staff guidance.
- Finance Department: Manages tax filings, financial records, audits, and submissions to CBCS and Tax Authorities. Coordinates with external auditors and ensures deadlines are met.
- Management Board: Provides strategic oversight, approves all regulatory submissions, ensures open engagement with regulators, and promotes a culture of compliance and accountability.
20.4 Communication Framework
To maintain professionalism and traceability, all communications with regulators must follow these standards:
- Tone: Professional, factual, timely, and respectful.
- Format: Preferably written via official correspondence or regulatory portals; verbal discussions must be documented.
- Escalation: Any urgent or sensitive request (≤72 hours response time) must be escalated to the Compliance Officer immediately.
- Recordkeeping: All regulatory correspondence, reports, and responses must be securely archived for at least 5 years and be retrievable upon request.
20.5 Reporting Calendar
| Authority | Report Type | Department | Frequency |
|---|---|---|---|
| CBCS | Prudential / AML / Governance Reports | Compliance | Quarterly |
| CBCS | Audited Financial Statements | Finance | Annually |
| FIU Curaçao | Unusual Transaction Reports (UTRs) | Compliance | As Occurring |
| Tax Authority | CIT Return | Finance | Annually |
| Tax Authority | Turnover Tax | Finance | Monthly / Quarterly |
| Tax Authority | Payroll / Social Security | Finance | Monthly |
20.6 Training & Awareness
- All employees must complete annual AML/CFT and regulatory compliance training.
- Finance and Compliance teams receive refreshers covering CBCS, FIU, and tax reporting updates.
- Awareness sessions reinforce escalation protocols and simulate regulator response scenarios.
20.7 Breach Management & Regulator Interaction
- Internal Escalation: All reporting breaches or material control failures must be reported to senior management within 24 hours.
- Regulator Notification: The Compliance Officer promptly informs CBCS, FIU, or Tax Authorities if a reportable incident occurs, including remedial actions taken.
- Corrective Action: Root causes are analyzed, action plans are assigned, and progress is tracked until full resolution.
20.8 Further Details
For further detail on submission formats, templates, and escalation procedures, refer to the Regulatory Reporting & Communication Manual.
21 Training and Awareness
21.1 Purpose and Scope
Bitkaya’s Training and Awareness Framework ensures that every employee understands their responsibilities in maintaining compliance, protecting client assets, and fostering a culture of integrity and accountability.
Objectives:
- Provide staff with the necessary knowledge to safeguard information, uphold AML/CFT obligations, and support operational resilience.
- Reinforce ethical conduct and risk awareness across all departments.
- Ensure continuous compliance with regulatory, legal, and industry standards.
This framework applies to all employees, contractors, and third parties acting on behalf of Bitkaya.
21.2 Roles and Responsibilities
- Human Resources (HR): Coordinates all training programs, tracks completion rates, and maintains employee learning records.
- Compliance Officer: Ensures all training aligns with regulatory requirements and monitors overall program effectiveness.
- Department Heads: Identify role-specific needs, recommend additional learning, and ensure participation in refresher programs.
- Employees: Complete assigned training on time, apply knowledge in daily work, and report any misconduct or suspicious activity.
21.3 Training Programs
1. Induction Training
All new employees complete orientation covering:
- Bitkaya’s structure, products, and VASP license obligations.
- AML/CFT fundamentals, sanctions compliance, ABC and whistleblower policies.
- Cybersecurity, data protection, and safe handling of client information.
2. Ongoing Training
Regular sessions reinforce updates on laws, internal policies, emerging risks, and typologies.
3. Specialized Training
Tailored modules for:
- Compliance & Risk Teams: AML/CFT, ABC, Travel Rule, reporting protocols.
- IT & Security Staff: Access control, threat mitigation, incident response.
- Client-Facing Roles: KYC, client communication, and ethical standards.
4. Awareness Campaigns
- Bulletins on fraud trends, phishing, and cybersecurity best practices.
- Phishing simulations and “crypto hygiene” initiatives.
21.4 Competency Assessment
- Initial Evaluation: Skills and compliance knowledge assessed during onboarding.
- Periodic Review: Staff performance monitored via audits, reviews, and incident response.
- Remediation: Non-compliance triggers refresher courses, coaching, or reassignment where necessary.
Completion rates and assessment results are reviewed regularly by HR and Compliance.
21.5 Continuous Improvement
- Training materials updated regularly to reflect new risks, laws, and technologies.
- Employee feedback and audit results used to refine future sessions.
- Benchmarked annually against CBCS, FATF, and industry best practices.
- Annual program review approved by the Board.
21.6 Further Details
For more details on employee education and compliance learning, refer to the Training & Awareness Manual.
Change Log
The following change log is extracted from the source PDF:
| Version | Date | Summary of Changes | Approvers | Impacted Policies/Procedures | Notes |
|---|---|---|---|---|---|
| 1.0 | June 2025 | Initial Compliance manual before introduction of NOSVASP | Board | All | |
| 1.1–2.0 | July–September 2025 | Implementation of NOSVASP requirements and CBCS guidelines in draft Enterprise Compliance Manual | None | All | Update, procurement, and implementation of systems and tools |
| 2.1 | October 2025 | Finalization of NOSVASP requirements and CBCS guidelines in Enterprise Compliance Manual | Board | All | Legacy client dossiers and transactions reviewed against updated compliance manual |
| 2.2 | April 2026 | Added standalone Anti-Bribery & Corruption and Outsourcing chapters | Board | ABC / Outsourcing | ABC EWRA and Outsourcing Register implemented |
| 2.3 | April 2026 | Cross-manual harmonization following AML/CTF/CPF Manual v2.1 | Board | Chapter 7 AML CTF/CPF and 9 KYC & CDD |