Change Log

VersionDateSummary of ChangesApproversImpacted Policies/ProceduresNotes
1.0October 2025Initial manualBoardAll
1.1April 2026Cross-manual harmonization following AML/CTF/CPF Manual v2.1Board3.1, 3.5, 4.2, 4.3, 4.5

1. Purpose and Scope

This manual sets out the internal control framework and audit standards for Bitkaya B.V. as a licensed or registered Virtual Asset Service Provider (VASP). Its objective is to ensure:

  • Compliance with applicable AML/CFT/CPF regulations and VASP licensing requirements.
  • Operational resilience and protection of client assets.
  • Transparent governance, accountability, and auditability of business activities.
  • Alignment with international standards (e.g., FATF, ISO 27001, SOC2, Basel principles).

Applies to all business units, products, jurisdictions, and third parties engaged by Bitkaya B.V.

2. Governance and Accountability

Clear governance and accountability are essential to maintaining a strong system of internal controls. Each level of the organization has defined responsibilities to ensure risks are identified, managed, and escalated appropriately.

2.1 Roles and Responsibilities

  • Board of Directors — Holds ultimate responsibility for oversight of the internal control framework, ensuring it is effective, adequately resourced, and aligned with regulatory obligations.
  • Head of Risk and Compliance (2nd Line of Defense) — Designs, tests, and monitors the risk and control framework, providing independent oversight of business operations and escalating issues to the Board and committees.
  • Money Laundering Reporting Officer (MLRO) — Accountable for AML/CFT/CPF compliance, including suspicious activity reporting, regulatory engagement, and ensuring that financial crime controls remain effective and up to date.
  • Internal Audit (3rd Line of Defense) — Provides independent assurance on the adequacy and effectiveness of internal controls, risk management, and governance, reporting directly to the Audit and Risk Committee.
  • All Staff — Required to adhere to policies and control procedures, actively report breaches or weaknesses, and contribute to a culture of compliance and operational discipline.

3. Core Internal Control Domains

This section outlines the core internal control domains that protect the integrity of Bitkaya’s operations as a Virtual Asset Service Provider (VASP). It covers financial crime compliance, custody of client assets, IT and cybersecurity safeguards, operational and client protections, and third-party/VASP oversight. Together, these controls ensure compliance with regulatory obligations, safeguard client trust, and maintain the resilience of business operations.

3.1 Financial Crime Compliance

  • Bitkaya maintains internal controls over KYC, KYV, KYT, sanctions screening, transaction monitoring, internal case escalation, and external reporting.
  • Sanctions screening includes onboarding screening, periodic review screening, list-refresh screening where relevant, and transaction- or wallet-level screening where required by the control framework.
  • Bitkaya maintains a documented internal case-classification and escalation process for unusual or suspicious matters. External reporting to the FIU Curaçao is made through the UTR process where required.
  • Recordkeeping controls ensure retention of client due diligence files, screening results, internal classifications, escalation records, UTR-related records, and supporting documentation in accordance with legal and regulatory requirements.

3.2 Custody and Asset Protection

  • Segregation of client vs. corporate funds.
  • Multi-signature and hardware security modules (HSMs) for key management.
  • Daily reconciliations between on-chain balances and internal ledgers.
  • Insurance coverage and operational runbooks for loss events.

3.3 IT and Cybersecurity Controls

  • Access Management: least privilege, MFA, periodic reviews.
  • Data Security: encryption in transit and at rest, secure data location.
  • Incident Response: triage within 1h, initial report in 24h, RCA in 5d.
  • Business Continuity: RTO/RPO targets defined (see BCM §1.4).

3.4 Operations and Client Protection

  • Client Complaints: handled per defined SLAs, trends monitored as KRIs.
  • Fee Transparency: approval of changes through New Product Approval process.
  • Service Level Monitoring: uptime, custody breaks, cyber tickets tracked in weekly Ops Pack.

3.5 Third-Party and VASP Oversight

  • Bitkaya applies risk-based due diligence to third parties, VASPs, and relevant counterparties.
  • For VASP relationships, KYV measures are determined on a documented risk basis and may include licence or supervisor information, registry evidence, incorporation documents, ownership and control information where relevant, sanctions screening results, and independent source checks.
  • Simplified treatment is not applied automatically solely because a counterparty is regulated or located in a particular jurisdiction.

4. Audit Framework

This chapter defines the assurance and oversight mechanisms that safeguard the effectiveness of Bitkaya’s internal control environment. Through a combination of independent audit, second line testing, external review, structured reporting, and continuous training, the organization ensures that risks are identified, monitored, and remediated in a transparent and accountable manner. Document governance processes further reinforce consistency, traceability, and regulatory readiness.

4.1 Internal Audit

  • Independent from management, reporting to the Audit and Risk Committee of the Board.
  • Conducts risk-based audits annually, covering:
    • AML/CFT/CPF framework
    • Custody and reconciliation controls
    • IT/cybersecurity
    • Business continuity
    • Governance and reporting

4.2 Second Line Testing (Compliance and Risk)

Second line testing includes thematic and control effectiveness reviews over key AML/CFT/CPF controls, including:

  • onboarding approval controls by risk tier;
  • source of funds and source of wealth requirements;
  • sanctions screening coverage and tool governance;
  • false-positive closure rationale;
  • unresolved-alert stop controls;
  • internal escalation and case-classification processes;
  • UTR decisioning and reporting controls;
  • wallet or transaction tracing practices in escalated cases; and
  • periodic review cadence and file completeness by risk classification.

Testing outcomes, remediation actions, and overdue items must be tracked and reported through the governance framework.

4.3 General External and Regulatory Audits

Regulatory readiness is maintained through organized evidence libraries including policies, client due diligence records, screening outputs, internal case-management records, UTR files, escalation packs, restrictive-measure records, remediation evidence, and relevant control documentation.

4.4 Financial Statement Audit

  • Provide independent assurance that financial statements are fairly presented under IFRS/Local GAAP.
  • Enhance regulatory confidence and client trust in reported financials.

Scope and Focus Areas

  • Crypto Assets and Liabilities: classification, valuation, proof of ownership, segregation of client vs corporate assets.
  • Revenue Recognition: fees, spreads, staking/lending income, custody fees.
  • Custody and Safeguarding: reconciliation of wallets, client asset disclosures, proof-of-reserves considerations.
  • IT and Cyber Controls: wallet security, reconciliations, access management, data integrity.
  • Financial Crime and Compliance: alignment with AML/CFT/CPF obligations, suspicious transaction reporting, sanctions risk.
  • Disclosures: fair value hierarchy, risk concentrations, governance.

Key Audit Risks

  • Existence and Rights: cryptographic proof that assets belong to the VASP.
  • Valuation: accuracy of market pricing, illiquid assets, and fair value hierarchy.
  • Completeness: capturing all wallets, DeFi positions, and off-chain obligations.
  • Revenue: correct recognition of trading fees, lending returns, and rebates.
  • Safeguarding: clear presentation of client assets and fiduciary responsibilities.

Procedures and Evidence

  • Wallet proofs (signed messages/test sends).
  • On-chain reconciliation vs ledger balances.
  • Independent price testing and cut-off analysis.
  • Revenue recalculations on sample transactions.
  • Confirmations from banks, custodians, stablecoin issuers.
  • Testing of IT controls and incident logs.

Deliverables

  • Audit Opinion: on financial statements (clean, qualified, adverse, or disclaimer).
  • Management Letter: control gaps, remediation recommendations.
  • Audit Committee Report (if applicable): summary of key matters, adjustments, uncorrected misstatements.

4.5 Reporting and Escalation

Material control failures, sanctions true matches, unresolved material sanctions issues, UTR-reportable cases, and significant AML/CFT/CPF control weaknesses must be escalated through the appropriate governance channels.

Reporting should distinguish, where relevant, between:

  • internal management escalation;
  • operational restrictive measures;
  • external UTR reporting status; and
  • CBCS notification or reporting status.

4.6 Training and Culture

  • Role-based training for Board, Product/Tech, Ops/Client-facing staff.
  • Minimum: onboarding + annual refresh; 90%+ pass rate required.
  • Remediation for failed assessments.
  • Culture KPIs: speak-up rates, phishing test results, time-to-close issues, training completion.

4.7 Document Management and Version Control

  • Owner: Head of Risk (with Compliance and MLRO).
  • Review cadence: annually or upon material regulatory/product/incident change.
  • Change log: version, date, summary, approvers, impacted procedures.

5. Proportionality Implementation

5.1 Purpose and Rationale

Bitkaya applies the principle of proportionality to its Internal Control and Audit Framework to ensure that governance, oversight, and assurance processes are commensurate with the company’s size, complexity, and risk exposure.

This approach aligns with the CBCS supervisory expectations, the FATF’s risk-based guidance, and the National Ordinance on the Supervision of Virtual Asset Service Providers (NOSVASP) requirements.

As a small, startup-stage Virtual Asset Service Provider (VASP), Bitkaya’s internal control and audit functions are designed to be practical, scalable, and risk-focused—ensuring that controls remain effective and compliant while avoiding unnecessary administrative burden. Proportionality ensures that the control environment grows in sophistication as the company matures.

5.2 Guiding Principles

  1. Risk-Based Application: The scope, intensity, and frequency of internal control reviews and audits are determined by the inherent and residual risks within business and compliance domains. Critical areas (e.g., AML/CFT, custody, IT and cybersecurity) receive more frequent testing and assurance.
  2. Startup-Appropriate Design: Control design, documentation, and testing are structured for a lean operational model, with combined functions (e.g., Risk and Compliance oversight) permitted under separation-of-duties safeguards.
  3. Scalability: As the company grows, audit coverage, independence, and automation will scale accordingly — transitioning from simplified second-line control testing to more formalized, risk-based internal audit programs.
  4. Efficiency and Resource Alignment: Resource allocation for audit and control testing is proportional to the potential financial, operational, and reputational impacts of deficiencies, ensuring efficient use of available expertise and tools.
  5. Continuous Alignment: Proportionality assessments are reviewed annually and upon material changes in business scale, regulatory obligations, or risk exposure.

5.3 Application Across Internal Control and Audit Domains

DomainProportionality Measure for a Small VASP
Governance and OversightThe Head of Risk and Compliance also serves as Audit Coordinator, reporting results directly to the Board or Audit and Risk Committee.
Control EnvironmentKey operational and compliance controls are documented in concise registers and periodically tested using simplified checklists and walkthroughs.
Audit Frequency and ScopeInternal audits are conducted annually on high-risk areas (e.g., AML/CFT, custody, cybersecurity) and biannually for low-risk domains. External audits are limited to financial statements and regulatory assurance.
Reporting and EscalationFindings are consolidated into a single quarterly report to the Board, supported by corrective action tracking within existing compliance registers.
Independence and ExpertiseInternal audits may be supplemented by independent third-party reviews when in-house capacity is limited, ensuring independence and objectivity.

5.4 Documentation and Audit Trail

All audit and testing activities are supported by evidence-based documentation, including control testing sheets, management responses, and follow-up verification logs. A central digital repository maintains these records for a minimum of five years, ensuring traceability and regulatory readiness.

5.5 Continuous Improvement and Scalability

Bitkaya’s Internal Control and Audit Framework evolves in proportion to organizational growth, product diversification, and regulatory expectations. As new services are introduced or additional jurisdictions are entered, proportionality measures will be recalibrated to ensure adequacy of control coverage and independence.

Annual reviews by the Board or Audit and Risk Committee will assess whether proportionality justifications remain appropriate, ensuring the framework remains fit-for-purpose, efficient, and compliant with CBCS standards.

This manual ensures that Bitkaya B.V. operates with robust internal controls, transparent governance, and independent assurance, protecting client trust and meeting the highest regulatory expectations for a Virtual Asset Service Provider.

Policy Statement

Bitkaya shall maintain an effective, risk-based and auditable system of internal controls across all business units, products, jurisdictions and relevant third parties.

Control ownership shall remain with the first line, independent monitoring and challenge with Risk and Compliance, and independent assurance with internal audit or suitably objective external reviewers. Findings and material control failures shall be documented, escalated and remediated.

Policy Requirements

  • Maintain a documented control framework covering all material risk and regulatory domains.
  • Assign each control an owner, objective, frequency, evidence expectation and testing approach.
  • Preserve separation between control operation, second-line testing and independent audit.
  • Approve a risk-based internal audit plan covering high-risk domains at least annually.
  • Perform second-line thematic and control-effectiveness testing and track outcomes and overdue actions.
  • Maintain organized evidence for external, regulatory and financial-statement audits.
  • Escalate material control failures, sanctions matters, reportable cases and significant AML/CFT/CPF weaknesses through the appropriate channels.
  • Provide role-based onboarding and annual refresher training with a minimum 90 percent pass standard and remediation for failure.
  • Retain audit and testing evidence, management responses and follow-up verification for at least five years.
  • Apply proportionality on a documented basis and reassess scope, independence and frequency annually and after material change.

Operating Layer

This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-ICA-* procedures and CTRL-ICA-* controls.

It is subordinate to POL-ECM-001 Enterprise Compliance Manual and provides the assurance layer for POL-RMF-001 Risk Management Framework Manual and the detailed operational manuals. It does not replace the controls or procedures owned by those frameworks.

Implementing Procedures and Controls

Procedures

Controls

Source Document

  • Document title: Internal Controls and Audit Manual
  • Version: 1.1
  • Status in source document: FINAL
  • Date shown in source document: April 2026
  • Approver shown in change log: Board
  • Exact BCMS approval and effective date: 2026-04-21, taken from the approved PDF metadata because the visible document states only April 2026
  • Permanent approved artifact: Bitkaya Internal Controls and Audit Manual v11 Approved.pdf
  • Note: the manual is an internal policy artifact and is not registered as a regulatory source.

Assurance

  • Design status: implemented from approved Internal Controls and Audit Manual version 1.1
  • Operating assurance: pending system-derived assessment
  • Evidence status: expected evidence is defined in the implementing controls
  • Review cadence: annual and after material regulatory, organizational, product, incident, control or assurance change
  • Overall status: implemented design; operating-effectiveness testing pending

History

  • 2026-07-29: Added SRC-ICA-001 to sources frontmatter (CHG-RES-003).
  • 2026-07-28: Enriched policy body to 100% PDF coverage — all sections, paragraphs and tables from the approved ICA Manual v1.1 reproduced verbatim.
  • 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
  • 2026-07-26: Registered the approved ICA Manual and established its operating process, procedures and controls.