1 Purpose and Scope
This manual establishes clear guidelines for Bitkaya B.V.’s regulatory reporting and communication obligations in Curaçao. It ensures compliance with all applicable local laws, promotes transparent communication with regulators, and provides internal procedures for timely reporting.
2 Key Regulatory Authorities
2.1 Central Bank of Curaçao and Sint Maarten (CBCS)
Role: Supervisory authority for financial institutions, including Virtual Asset Service Providers (VASPs) such as Bitkaya B.V.
Key Responsibilities for Bitkaya B.V.:
- Licensing and registration of the entity.
- Ongoing prudential and integrity supervision.
- AML/CFT compliance oversight.
- Fit & Proper testing of key persons.
Reporting Obligations:
- Periodic compliance reports (AML/CFT, governance, risk management).
- Annual audited financial statements.
- Notifications of material changes (ownership, management, business model).
- Incident reporting (cybersecurity, fraud, operational failures).
2.2 Financial Intelligence Unit (FIU Curaçao)
Role: National authority for AML/CFT reporting and monitoring of unusual transactions.
Key Responsibilities for Bitkaya B.V.:
- Enforcing the National Ordinance on the Reporting of Unusual Transactions (NORUT).
- Oversight of suspicious/unusual activity monitoring.
Reporting Obligations:
- Unusual Transaction Reports (UTRs): Mandatory reporting of all transactions that meet objective or subjective indicators.
- Timely reporting via the FIU online portal.
- Cooperation during investigations.
Communication Protocol:
- Reports filed electronically via the FIU system.
- Immediate notification of compliance officer for escalations.
- Maintain strict confidentiality – non-disclosure to customer (tipping-off prohibition).
2.3 Tax Authorities (Belastingdienst Curaçao)
Role: Responsible for taxation and enforcement of fiscal obligations.
Key Responsibilities for Bitkaya B.V.:
- Corporate Income Tax (CIT) compliance.
- Turnover Tax (if applicable).
- Wage tax and social security reporting for employees.
- Possible VAT/GST considerations depending on transaction types.
Reporting Obligations:
- Annual CIT filings (typically due within 5 months after financial year-end).
- Monthly/quarterly turnover tax filings.
- Monthly payroll/wage tax declarations.
Communication Protocol:
- All filings via the online tax portal.
- Prompt response to tax authority inquiries or audits.
- Maintain supporting documentation for at least 10 years.
3 Internal Roles & Responsibilities
A clear assignment of responsibilities is essential for ensuring regulatory compliance and effective communication with supervisory authorities. At Bitkaya B.V., oversight and reporting are shared among the Compliance Officer, Finance Department, and the Management Board, each of whom plays a distinct role in meeting the company’s obligations under Curaçao’s regulatory framework. The following outlines their respective duties in more detail.
3.1 Compliance Officer
The Compliance Officer acts as the primary liaison for AML/CFT/CPF-related regulatory communication and is responsible for coordinating internal case handling, UTR reporting, sanctions escalation, and any applicable supervisory reporting or notification to the CBCS arising from material sanctions, compliance, or financial crime matters.
The Compliance Officer also ensures that reporting decisions, internal classifications, supporting rationale, and communications with relevant authorities are properly documented and retained.
3.2 Finance Department
The Finance Department ensures the company’s financial transparency and accuracy in relation to both domestic taxation and regulatory reporting requirements.
- Tax & Fiscal Compliance: Prepares and files all statutory tax declarations, including Corporate Income Tax (CIT), turnover tax, and wage tax obligations, in line with deadlines set by the Curaçao Tax Authorities.
- Financial Reporting: Compiles and maintains financial statements and management accounts, ensuring consistency with international accounting standards and local regulations.
- Audit Coordination: Acts as the primary contact for external auditors, ensuring they have access to accurate and complete financial records for annual audits and special reviews required by regulators.
- Regulatory Submissions: Ensures the timely delivery of financial statements and related reports to the CBCS and Tax Authorities, coordinating with the Compliance Officer when regulatory overlaps exist.
- Documentation: Keeps organized and retrievable financial records for the statutory period (minimum 5 years), enabling easy access in case of inspections or audits. Maintain certain key records longer (for example, financial statements, audited reports, governance documents, contract documents, source of funds documentation, compliance policies) beyond the 5 years, potentially up to 7-10 years, where there is risk, ongoing litigation, or requested by regulator or auditor.
3.3 Management Board
The Management Board carries ultimate accountability for governance and ensures that Bitkaya B.V. maintains strategic compliance while fostering trust with regulators and stakeholders.
- Strategic Oversight: Ensures that compliance and governance frameworks are embedded in the company’s overall business strategy, balancing innovation with regulatory expectations.
- Approval Authority: Reviews and formally approves key regulatory submissions, including license applications, audited financial statements, compliance reports, and responses to official inquiries.
- Official Representation: Acts as the formal point of contact for regulators in cases requiring executive-level dialogue, such as licensing, enforcement actions, or strategic supervisory matters.
- Risk Management: Establishes internal policies to mitigate regulatory, reputational, and operational risks, ensuring adequate resources are allocated to compliance and financial reporting functions.
- Accountability & Culture: Promotes a company-wide culture of compliance, integrity, and transparency by setting the tone at the top.
4 Communication Framework
Effective communication with regulators is a cornerstone of Bitkaya B.V.’s compliance program. All interactions must adhere to the highest standards of professionalism and accountability to maintain trust and demonstrate transparency. The following guidelines govern how communication is prepared, delivered, escalated, and archived.
4.1 Tone
All communication with regulatory authorities must be professional, transparent, factual, and timely. Submissions or responses must:
- Present information objectively, without speculation or unnecessary interpretation.
- Avoid jargon and use clear, precise language that regulators can easily understand.
- Reflect transparency by disclosing all relevant facts, even if adverse, while highlighting corrective measures already taken.
- Be delivered within regulatory deadlines to demonstrate reliability and respect for supervisory processes.
4.2 Format
The preferred format for communication with regulators is written correspondence, unless otherwise directed by the authority. This includes:
- Formal letters for official submissions, signed by authorized representatives.
- Emails for routine updates, clarifications, or requests for information, ensuring professional tone and formatting.
- Regulatory portals where mandatory filings (e.g., FIU reports, tax submissions, CBCS templates) must be uploaded in the required format.
- In-person or telephone conversations should be minimized, and when they occur, they must be documented in writing immediately afterward.
4.3 Escalation
Regulatory escalation must distinguish between different categories of action. Where relevant, Bitkaya shall separately consider and document:
- internal escalation and management visibility;
- external FIU reporting obligations;
- CBCS supervisory reporting or notification obligations; and
- operational restrictive measures, including blocking, freezing, or holding transactions or relationships where legally required.
Sanctions-related matters, unusual transactions, and significant compliance incidents must be assessed across these separate dimensions rather than treated as a single generic event type.
4.4 Recordkeeping
All regulatory communications, filings, decisions, drafts, supporting evidence, escalation records, and follow-up actions must be retained in a secure and retrievable manner.
For AML/CFT/CPF and sanctions matters, the record must include, where applicable:
- the alert or trigger;
- internal classification;
- review notes and rationale;
- the basis for false-positive closure, where relevant;
- the status and outcome of escalation;
- any restrictive measures taken;
- UTR filing details, where applicable; and
- any CBCS notification or reporting record, where applicable.
5 Reporting Calendar
| Authority | Report Type | Frequency | Responsible Party | Deadline |
|---|---|---|---|---|
| CBCS | Prudential/AML Report | Quarterly | Compliance Officer | 30 days after quarter-end |
| CBCS | Audited Financials | Annually | Finance Dept | 5 months after year-end |
| FIU | Unusual Transactions | Ad hoc | Compliance Officer | Immediately upon detection |
| Tax Authorities | CIT Return | Annually | Finance Dept | 5 months after year-end |
| Tax Authorities | Turnover Tax | Monthly/Quarterly | Finance Dept | 15th of following month |
| Tax Authorities | Wage Tax | Monthly | Finance Dept | 15th of following month |
6 Training & Awareness
A strong culture of compliance is built on continuous education and awareness across the organization. Training ensures that employees understand their legal responsibilities, are able to identify potential risks, and can apply company policies effectively in daily operations. At Bitkaya B.V., training and communication initiatives are designed to reinforce the importance of AML/CFT obligations, regulatory reporting requirements, and clear communication practices.
6.1 Annual AML/CFT Training for All Employees
All employees, regardless of their role, must participate in mandatory annual AML/CFT training. This ensures that:
- Staff are familiar with the requirements of the National Ordinance on the Reporting of Unusual Transactions (NORUT), CBCS provisions, and FIU guidance.
- Employees can recognize unusual or suspicious activities and understand escalation procedures.
- Practical case studies and scenarios are used to reinforce learning and link policies to real-world risks.
- Attendance is tracked and completion is documented to demonstrate compliance to regulators.
6.2 Periodic Refreshers for Finance and Compliance Staff
Employees directly involved in regulatory reporting, specifically those in the Finance Department and Compliance function, must undergo refresher training sessions on a periodic basis (at least semi-annually). These refreshers will:
- Provide updates on new CBCS circulars, FIU reporting requirements, or tax authority guidelines.
- Address lessons learned from recent internal audits, inspections, or regulatory findings.
- Ensure staff remain confident in preparing, reviewing, and submitting reports accurately and on time.
- Emphasize the importance of cross-departmental collaboration for regulatory compliance.
6.3 Quarterly Reinforcement of Internal Communication Protocols
To maintain consistency and prevent miscommunication, internal communication protocols will be reinforced every quarter. This process includes:
- Reminders to staff on escalation procedures, reporting lines, and documentation requirements.
- Internal briefings led by the Compliance Officer to highlight emerging regulatory risks or changes in reporting standards.
- Simulated communication drills (e.g., mock regulator requests) to ensure staff can respond promptly and appropriately.
- Documentation of each reinforcement session in the company’s training log.
Training on regulatory communication must include AML/CFT/CPF reporting obligations, internal case classification, UTR reporting procedures, sanctions-related escalation, documentation standards, confidentiality requirements, and circumstances in which CBCS supervisory notification or reporting may also be required.
7 Breach Management & Regulator Interaction
Despite robust internal controls, there may be instances where reporting deadlines are missed, compliance obligations are not fully met, or operational breaches occur. To maintain regulatory trust and safeguard the integrity of Bitkaya B.V., all such incidents must be handled with urgency, transparency, and accountability. The following procedures apply to the identification, escalation, and remediation of breaches.
7.1 Reporting to Senior Management
Any breach, delay, or non-compliance must be escalated to senior management within 24 hours of detection. This ensures that:
- Leadership is promptly aware of compliance risks that may have financial, reputational, or legal implications.
- Decisions regarding resource allocation, risk mitigation, and communication strategies can be taken swiftly.
- A centralized record of incidents is maintained for oversight and governance purposes.
7.2 Proactive Regulator Notification
The Compliance Officer is responsible for evaluating whether a breach or delay must be disclosed to regulators. Where required, the officer will:
- Notify the relevant authority (CBCS, FIU, or Tax Authorities) without undue delay, ensuring transparency and good faith communication.
- Provide factual details, including the nature of the breach, its root cause, and steps already taken to contain it.
- Coordinate with the Management Board for regulator interactions involving strategic or reputational risks.
7.3 Corrective Actions and Tracking
All corrective actions arising from a breach must be formally documented and tracked until resolution. This process includes:
- Assigning responsibility to a designated staff member or department.
- Establishing timelines for remediation and follow-up.
- Monitoring progress through compliance logs and management oversight.
- Conducting a post-incident review to identify lessons learned and strengthen internal controls to prevent recurrence.
7.4 Sanctions Hits
Not all sanctions or financial crime matters should be treated solely as generic breach events. Confirmed sanctions matches may create immediate legal obligations relating to restrictive measures, asset blocking or freezing, FIU reporting, and CBCS notification or reporting. These obligations must be considered separately and documented clearly.
8 Proportionality Implementation
8.1 Purpose and Rationale
Bitkaya applies the principle of proportionality to its Regulatory Reporting and Communication Framework to ensure that the company’s systems, controls, and governance arrangements are commensurate with its size, nature, complexity, and risk profile.
This approach aligns with the Central Bank of Curaçao and Sint Maarten (CBCS) supervisory expectations, the National Ordinance on the Supervision of Virtual Asset Service Providers (NOSVASP), and FATF risk-based principles.
As a small and startup-stage VASP, Bitkaya’s regulatory communication and reporting framework emphasizes practicality, efficiency, and scalability, maintaining full compliance while ensuring proportional use of resources. Proportionality allows Bitkaya to meet all regulatory obligations without imposing excessive administrative or technical burdens that would be unsuitable for its current operational scale.
8.2 Guiding Principles
- Risk-Based Application: The scope, frequency, and depth of reporting and communication with regulators are determined by the materiality and risk level of activities. High-impact domains (e.g., AML/CFT reporting, prudential filings, cybersecurity incident notifications) receive greater attention and formality than low-risk, routine interactions.
- Clarity and Simplicity: Communications are designed to be clear, structured, and easily reviewable by regulators. Templates, standardized correspondence formats, and concise reporting summaries are used to ensure transparency and consistency without overcomplexity.
- Efficiency and Scalability: Processes are streamlined to match the company’s resource capacity. As the company grows, communication and reporting mechanisms will scale in granularity and automation — evolving from manual registers to structured digital dashboards or RegTech solutions.
- Accountability and Traceability: All regulatory correspondence and submissions are tracked in a central log managed by the Compliance Officer. Documentation evidences who prepared, reviewed, and approved each report, ensuring transparency and audit readiness.
- Continuous Alignment: The proportionality assessment is reviewed annually or when there are material changes to the company’s size, risk exposure, or supervisory expectations. Adjustments are made to ensure continued adequacy and compliance.
8.3 Governance and Oversight
The Compliance Officer serves as the primary point of contact and custodian of the regulatory reporting framework. The Finance Department and Management Board provide supporting oversight proportional to their responsibilities:
- Compliance Officer: Oversees CBCS and FIU reporting, maintains communication logs, ensures timely submissions, and coordinates cross-departmental input.
- Finance Department: Handles tax-related submissions and financial statement filings proportionate to business activity and scale.
- Management Board: Reviews and approves material submissions, ensuring they align with Bitkaya’s governance and risk management standards.
For a small VASP, combined oversight roles are acceptable provided that segregation of duties and Board visibility are maintained. As Bitkaya grows, oversight functions will expand into more specialized compliance and finance sub-departments.
8.4 Application of Proportionality Across Regulatory Reporting Domains
| Domain | Proportionality Measures for a Small VASP |
|---|---|
| CBCS Prudential & AML Reports | Use simplified quarterly reporting templates. Reporting frequency remains per CBCS schedule, but content is concise and focused on key metrics (capital, governance, AML controls). |
| FIU Curaçao Submissions | The Compliance Officer manages filings manually via the FIU portal, supported by internal tracking sheets. Automated RegTech solutions will be adopted as transaction volumes increase. |
| Tax & Fiscal Reporting | Annual CIT filings and monthly/quarterly tax declarations are prepared by Finance using standardized checklists. External audit support is engaged as needed. |
| Incident & Breach Notifications | Immediate notification to the Compliance Officer and escalation to management; only material events are reported to the CBCS or FIU to maintain proportionality and focus. |
| Communication & Recordkeeping | Regulatory contact logs maintained in digital format (Excel or secure shared drive) to document all communications. Migration to compliance management software planned upon operational scaling. |
| Training & Awareness | Annual training sessions focused on communication protocols and regulatory expectations. As the company expands, specialized training modules will be introduced. |
8.5 Documentation and Audit Trail
All reporting and communication activities are supported by verifiable documentation, including submission records, internal reviews, and correspondence evidence. A centralized Regulatory Communication Log records:
- Date and type of communication
- Counterparty regulator
- Subject and summary
- Responsible preparer and approver
- Follow-up or corrective action (if applicable)
All records are retained for at least five (5) years, or longer when required by regulators or ongoing reviews.
8.6 Continuous Improvement and Scalability
Proportionality does not imply static simplicity; it requires dynamic evolution. Bitkaya commits to enhancing its regulatory reporting capacity in line with growth milestones such as increased transaction volumes, staff expansion, or additional licensing scopes. Continuous improvement measures include:
- Annual proportionality review by the Compliance Officer.
- Technology integration (e.g., automated filing and dashboard tools).
- Independent assessment during internal audits to ensure adequacy of communication protocols.
- Feedback incorporation from regulators and auditors to refine processes.
This adaptive approach ensures Bitkaya remains compliant, efficient, and transparent as it scales, consistent with the CBCS principle that oversight and reporting must evolve in line with institutional development.
CBCS Enforcement and Penalty Framework
CBCS enforcement consequences for AML/CFT/CPF non-compliance are defined in the October 2023 Updated Policy Rule on the Violation of AML/CFT/CPF Legislation and Provisions & Guidelines (SRC-ENF-001 Policy Rule on AML CFT CFP Violations October 2023). The policy rule establishes a penalty gradation from warnings to fines to license revocation, with aggravating and mitigating factors. Specific administrative fine amounts for NOIS/LID identification violations (up to NAF 500,000) are set by PB 2023 nr. 6, which is referenced as the penalty framework under SRC-ENF-001. This enforcement context informs Bitkaya’s compliance prioritization and risk assessment but does not impose new operational obligations beyond those already captured in the existing REQ-MOT, REQ-LID, and REQ-VASP requirement sets.
Change Log
| Version | Date | Summary of Changes | Approvers | Impacted Policies/Procedures | Notes |
|---|---|---|---|---|---|
| 1.0 | October 2025 | Initial manual | Board | All | |
| 1.1 | April 2026 | Cross-manual harmonization following AML/CTF/CPF Manual v2.1. | Board | 2.2, 3.1, 4.3, 4.4, 5, 6, 7 | |
| 1.2 | July 2026 | Added SRC-ENF-001 enforcement policy rule reference and penalty framework (PB 2023 nr. 6) cross-reference. Added CBCS Enforcement and Penalty Framework section. | MD | All | CHG-RES-004, CHG-RES-005 |
Implementing Procedures and Controls
Procedures
- PROC-REG-001 Govern Regulatory Authorities Obligations and Calendar
- PROC-REG-002 Prepare Review Approve and Submit Regulatory Reports
- PROC-REG-003 Coordinate FIU and Sanctions Regulatory Reporting
- PROC-REG-004 Coordinate CBCS Reports Notifications and Inquiries
- PROC-REG-005 Coordinate Tax and Audited Financial Reporting
- PROC-REG-006 Manage Regulatory Communications Requests and Records
- PROC-REG-007 Manage Reporting Breaches Training and Proportionality
Controls
- CTRL-REG-001 Ensure Regulatory Obligations and Calendar Are Current
- CTRL-REG-002 Ensure Regulatory Submissions Are Complete Accurate and Timely
- CTRL-REG-003 Ensure FIU and Sanctions Reporting Is Complete and Confidential
- CTRL-REG-004 Ensure CBCS Reporting and Notifications Are Controlled
- CTRL-REG-005 Ensure Tax and Audited Financial Reports Are Timely
- CTRL-REG-006 Ensure Regulatory Communications and Records Are Traceable
- CTRL-REG-007 Ensure Reporting Breaches Training and Proportionality Are Managed
Source Document
- Document title: Regulatory Reporting & Communication Manual
- Version: 1.1
- Status in source document: FINAL
- Date shown in source document: April 2026
- Approver shown in change log: Board
- Exact BCMS approval and effective date: 2026-04-21, taken from the approved PDF metadata because the visible document states only April 2026
- Permanent approved artifact: Bitkaya Regulatory Reporting Communication Manual V11.pdf
- Note: the manual is an internal policy artifact and is not registered as a regulatory source.
Assurance
- Design status: implemented from approved Regulatory Reporting and Communication Manual version 1.1
- Operating assurance: pending system-derived assessment
- Evidence status: expected evidence is defined in the implementing controls
- Review cadence: annual and after material regulatory, organizational, licensing, reporting or assurance change
- Overall status: implemented design; operating-effectiveness testing pending
History
- 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
- 2026-07-26: Registered the approved REG Manual and established its operating process, procedures and controls.
- 2026-07-28: Enriched policy body to full PDF coverage — all 8 sections, every paragraph and table from the approved Regulatory Reporting & Communication Manual v1.1.
- 2026-07-29: Added SRC-ENF-001 to sources frontmatter; added CBCS Enforcement and Penalty Framework body text section referencing the October 2023 Policy Rule and PB 2023 nr. 6 penalty amounts (CHG-RES-004, CHG-RES-005).