Purpose
Represent Bitkaya’s Board-approved Client Asset Protection and Safeguarding Manual as the policy for protecting client money, virtual assets, related access means and safeguarding records.
Policy Statement
Bitkaya shall keep client assets identifiable, segregated, fully recorded, controlled, resilient and protected against misuse, commingling, shortfall, unauthorized movement, loss, legal breach and operational failure. Safeguarding shall remain integrated with AML/CTF/CPF, sanctions, fraud, cybersecurity, outsourcing, business continuity, risk, assurance and regulatory obligations.
1 Purpose and Scope
This manual establishes Bitkaya’s policies and procedures for the protection, handling, safeguarding, recording, and controlled movement of client money and virtual assets. It applies to all employees, officers, directors, contractors, and relevant third parties involved in client asset handling, wallet operations, payment flows, reconciliations, authorizations, monitoring, or reporting.
The objective is to protect client assets against misuse, commingling, loss, unauthorized transfer, control failure, and legal or regulatory breach, while ensuring that safeguarding arrangements remain aligned with Bitkaya’s AML/CTF/CPF, sanctions, cybersecurity, operational risk, and regulatory obligations.
2 Definitions
- Client Money: Funds of any currency held or controlled by Bitkaya on behalf of a client in the course of, or in connection with, virtual asset activities, excluding fees or charges due to Bitkaya.
- Client Virtual Assets (VAs): Digital representations of value held or controlled by Bitkaya on behalf of a client, not owned by Bitkaya and not forming part of Bitkaya’s estate in the event of insolvency.
- Client Account: A bank account maintained by Bitkaya, titled “Client Account”, used exclusively for holding client money.
- Client VA Wallet: A digital wallet labeled “Client VA Wallet” in Bitkaya’s records, used exclusively for holding client virtual assets.
3 Segregation of Client Assets
To ensure the highest level of protection and transparency, Bitkaya enforces strict segregation between client assets and the company’s own funds and holdings. This principle safeguards client money and virtual assets from misuse, misallocation, or loss in the event of financial distress or insolvency. By maintaining clear distinctions in how assets are recorded, stored, and managed, Bitkaya upholds regulatory requirements, fosters client trust, and minimizes systemic risks.
3.1 Client Money
- Client money must be held in a Client Account wallet separate from Bitkaya’s own funds.
- Client money must be paid into a Client Account within three (3) calendar days of receipt.
- Bitkaya must not deposit its own funds into a Client Account wallet, except to meet a temporary shortfall under exceptional and documented circumstances.
3.2 Client Virtual Assets
- Client VAs must be held in separate Client VA Wallets from Bitkaya’s own virtual assets.
- Client VA Wallets must be clearly labeled in records and systems.
- Use of Client VAs for lending, staking, or other financial activities is prohibited unless:
- Explicit prior client consent is obtained; and
- Bitkaya has appropriate licensing for such activity.
4 Handling and Processing of Client Money
The safeguarding of client money requires not only segregation and accurate recording, but also appropriate control over source, destination, authorization, and legal restriction.
Bitkaya must ensure that client money movements are:
- properly recorded and traceable;
- supported by appropriate instructions and documentation;
- consistent with the client relationship and applicable control requirements;
- subject to authorization by designated personnel; and
- restricted or escalated where legal, sanctions, fraud, compliance, or safeguarding concerns exist.
Client money movements must not proceed where there is an unresolved sanctions concern, legal restriction, or material compliance alert affecting the transaction, client, or destination.
4.1 Identifiability and Security
Client money must always remain clearly identifiable, separate from Bitkaya’s own funds, and safeguarded through secure banking and accounting practices.
4.2 Accurate Recording of Transactions
All receipts and payments of client money must be promptly recorded in Bitkaya’s systems, with details including:
- Date of transaction
- Unique client identifier
- Amount received or disbursed
- Transaction reference number
This ensures accuracy, traceability, and full auditability of client funds.
4.3 Authorization and Documentation of Withdrawals
Withdrawals from client accounts must be supported by appropriate documentation and authorized by designated personnel. This ensures that client money is only used for purposes expressly permitted under client agreements and applicable regulations.
4.4 Prohibition of Misuse or Commingling
Client money belonging to one client must never be used to satisfy another client’s obligations or Bitkaya’s own operational needs. This prohibition guarantees fairness, transparency, and compliance with safeguarding requirements.
5 Handling and Processing of Client Virtual Assets
Bitkaya safeguards client virtual assets on the basis of ownership integrity, segregation, traceability, and controlled execution.
Client virtual asset transfers must be subject to appropriate operational, security, and compliance controls, including where relevant:
- wallet ownership verification;
- address whitelisting or destination controls;
- risk-based transaction review;
- sanctions and wallet exposure screening;
- documented authorization steps; and
- escalation where unusual, restricted, or high-risk circumstances arise.
Where a transfer cannot be completed in a manner consistent with Bitkaya’s legal, compliance, or safeguarding obligations, the transfer must not proceed until the matter has been appropriately resolved or escalated.
5.1 One-to-One Holding Requirement
Client VAs must be maintained on a strict one-to-one basis, ensuring that balances in custody always match client entitlements. This eliminates the risk of shortfalls and guarantees that clients can access their assets in full at any time.
5.2 Accrual of Proceeds
Any proceeds generated from client VAs, such as airdrops, staking rewards, or other network-based distributions, must accrue to the client’s benefit. Exceptions may only apply if explicitly agreed in writing, ensuring full transparency and client consent.
5.3 Ownership and Trust Principles
Bitkaya must not assume ownership rights over client VAs. The only permissible exception is where assets are placed under trust, with clients recognized as the ultimate beneficiaries. This structure ensures that, even in insolvency scenarios, client VAs remain legally distinct from Bitkaya’s own estate.
6 Reconciliation and Record-Keeping
Accurate reconciliation and record-keeping are essential to safeguarding client assets and supporting legal, regulatory, operational, and audit requirements.
Bitkaya must maintain complete and auditable records of:
- client balances and entitlements;
- receipts, disbursements, and transfers;
- wallet addresses and payment instructions where relevant;
- authorization and approval records;
- holds, restrictions, reversals, and exceptions;
- reconciliation differences and their resolution; and
- any linked compliance or safeguarding escalations affecting client asset movements.
Where a safeguarding event overlaps with a sanctions, fraud, AML/CTF/CPF, cybersecurity, or operational incident, the records must support cross-reference to the relevant escalation and remediation process.
6.1 Regular Reconciliations
Reconciliations must be performed on a regular basis, comparing internal records with external bank and wallet statements. This ensures that reported balances accurately reflect the assets actually held on behalf of clients.
6.2 Discrepancy Management
Any inconsistencies identified during reconciliation must be investigated immediately and resolved without delay. Corrective actions must be documented to ensure accountability and prevent recurrence.
6.3 Comprehensive Record Maintenance
Full records must be maintained for every transaction involving client assets, including receipts, disbursements, and current balances. This supports transparency, auditability, and regulatory reporting.
6.4 Retention of Records
Records must be retained for at least the minimum period mandated by applicable laws and regulations, and longer where necessary to comply with contractual or regulatory obligations.
7 Client Reporting
Client reporting must be accurate, timely, and sufficiently clear to allow clients to understand their holdings, transactions, and any relevant restrictions or delays that affect their assets.
Where a transaction, withdrawal, or transfer is delayed or restricted due to legal, compliance, fraud, sanctions, or safeguarding concerns, client communication must be handled carefully, consistently, and in accordance with applicable legal and confidentiality constraints.
No communication should be made in a manner that breaches anti-tipping-off, confidentiality, or regulatory restrictions.
7.1 Regular Statements
Clients must receive statements on at least a monthly basis. These statements must detail:
- Client money balances
- Virtual asset holdings
- Transactions conducted during the reporting period
- Any interest earned or charges applied
7.2 Timely Preparation and Delivery
All statements must be prepared and delivered to clients within 25 calendar days of the statement date, ensuring clients have access to up-to-date information.
7.3 Transparency and Accuracy
Reports must be clear, accurate, and free from omissions or misleading information. Discrepancies identified by clients must be promptly investigated and corrected.
7.4 Regulatory Compliance
The reporting process must align with applicable laws, regulations, and industry standards, ensuring that clients are afforded the highest level of protection and transparency.
8 Third-Party Banks and Wallet Providers
Where Bitkaya relies on third-party banks, payment providers, custodians, wallet providers, or similar infrastructure, it must ensure that these arrangements do not undermine safeguarding, control, transparency, or legal compliance.
Due diligence and oversight must consider, where relevant:
- operational reliability and resilience;
- control environment and security;
- segregation capability;
- reporting and statement quality;
- sanctions and jurisdictional exposure;
- incident and breach notification arrangements;
- support for restriction or hold measures where legally required; and
- the ability to retrieve records and maintain continuity during disruption.
8.1 Authorized and Independent Banking Partners
Client Accounts must be maintained exclusively with banks that are duly authorized to accept deposits and operate independently from Bitkaya’s corporate group. This separation ensures objectivity, reduces conflicts of interest, and enhances the security of client money.
8.2 Written Acknowledgments from Banks
Bitkaya must obtain formal written confirmations from each banking partner stating that:
- Client money is held in trust for the benefit of clients, and
- Such funds are not subject to set-off, liens, or any other claims by the bank.
This provides a legal safeguard ensuring that client funds remain fully protected.
8.3 Secure and Reputable Wallet Providers
Client Virtual Asset (VA) Wallets must be managed through reliable, secure, and well-established wallet providers. These providers must meet stringent due diligence standards, ensuring that custody arrangements protect against theft, hacking, and operational failures.
8.4 Safety, Resilience, and Integrity
Wallet providers must demonstrate strong security protocols, operational resilience, and transparent governance. Regular due diligence reviews and monitoring are required to ensure ongoing compliance with Bitkaya’s standards and regulatory expectations.
9 Compliance and Audit
Compliance and audit processes are essential to ensuring that Bitkaya consistently upholds its obligations to safeguard client assets. By maintaining strong internal controls, conducting regular reviews, and promptly addressing any issues, Bitkaya reinforces accountability, transparency, and adherence to regulatory requirements.
9.1 Implementation of Policies and Controls
Bitkaya must establish and maintain comprehensive policies, procedures, and systems that align with this manual and applicable regulatory frameworks. These controls must cover all aspects of client asset safeguarding, from segregation to reporting.
9.2 Regular Internal and External Audits
Independent reviews, whether performed internally or by external auditors, must be carried out on a scheduled basis. These audits assess compliance, test the effectiveness of safeguards, and provide recommendations for improvement.
9.3 Breach Identification and Response
Any breaches, discrepancies, or deficiencies identified in the safeguarding of client assets must be investigated without delay. Root causes must be determined, corrective actions must be implemented, and follow-up monitoring must ensure the issue is fully resolved.
9.4 Continuous Improvement
Lessons learned from audits and breach investigations must feed into policy updates, staff training, and system enhancements. This ensures that Bitkaya continually strengthens its safeguarding framework and adapts to evolving regulatory and operational risks.
10 Client Agreements
Clear and transparent client agreements are essential for building trust and ensuring that clients fully understand how their assets are safeguarded. By setting out detailed terms, rights, obligations, and disclosures, Bitkaya ensures that clients are well-informed and protected, while also meeting its regulatory and fiduciary responsibilities.
10.1 Clear Terms and Conditions
All client agreements must include comprehensive provisions covering:
- How client money and virtual assets are handled and safeguarded
- The rights and obligations of both Bitkaya and the client
- Risk disclosures and the protections in place to mitigate such risks
10.2 Client Awareness of Asset Handling
Clients must be informed in writing of:
- How and where their assets are held (e.g., client accounts, segregated VA wallets)
- The safeguards and controls applied to protect their assets
- Any potential risks associated with the services provided by Bitkaya
10.3 Transparency and Disclosure
Agreements must use clear, concise language that avoids ambiguity or misleading terms. Clients should be provided with sufficient information to make informed decisions about engaging Bitkaya’s services.
10.4 Regulatory Alignment
Agreements must comply with all applicable legal and regulatory requirements, ensuring enforceability and alignment with client asset protection obligations.
11 Governance and Accountability
Safeguarding governance must ensure that client asset protection is managed not only as an accounting or custody function, but also as a legal, compliance, operational, and client protection responsibility.
Management oversight should therefore include visibility over:
- segregation and reconciliation performance;
- safeguarding incidents and near misses;
- withdrawal and transfer exceptions;
- unresolved restrictions, holds, or breaks;
- third-party dependency risk;
- interaction between safeguarding and compliance controls; and
- remediation actions following incidents, findings, or control failures.
12 Risk Management and Internal Controls
Bitkaya applies internal controls to reduce the risk of misappropriation, commingling, unauthorized transfer, operational error, legal restriction failure, or delayed detection of safeguarding issues.
Controls include, where relevant:
- segregation of client and corporate assets;
- maker-checker or dual-authorization processes;
- restricted wallet and payment permissions;
- reconciliations and discrepancy follow-up;
- transaction monitoring and exception review;
- destination and wallet verification controls;
- sanctions and legal restriction checks where applicable;
- incident escalation;
- secure recordkeeping; and
- periodic management and control review.
Where a safeguarding process intersects with AML/CTF/CPF, sanctions, fraud, or cybersecurity controls, the applicable frameworks must be applied consistently.
13 Cybersecurity and Technology Safeguards
Technology safeguards are essential to preventing unauthorized access, tampering, misuse, or loss involving client assets and related operational records.
Bitkaya must apply security controls appropriate to the systems supporting custody, wallet administration, payment processing, reconciliation, and linked compliance controls.
This includes:
- secure authentication;
- role-based access restrictions;
- privileged access control;
- secure logging and auditability;
- protected key and wallet administration;
- backup and recovery capability; and
- resilience and incident response arrangements.
Where compliance-related controls are embedded in asset movement workflows, the integrity of those controls must also be protected.
14 Withdrawal, Transfer, and Disbursement Procedures
Withdrawals, transfers, and disbursements of client assets must be subject to controlled verification, authorization, and review.
Before processing, Bitkaya must ensure that:
- the request is properly authenticated and authorized;
- the destination is permitted under Bitkaya’s control framework;
- the transaction is not subject to a legal, sanctions, compliance, fraud, or safeguarding restriction;
- supporting records are complete; and
- any elevated-risk features have been reviewed and escalated where required.
Where a sanctions alert, legal restriction, unusual activity concern, fraud concern, or other material control issue remains unresolved, the withdrawal or transfer must not proceed until the matter has been appropriately resolved or escalated.
All decisions, authorizations, holds, restrictions, and exceptions must be documented.
15 Treatment in Insolvency or Resolution
To safeguard clients’ rights under all circumstances, including financial distress, Bitkaya has established policies to ensure that client assets remain fully protected in the event of insolvency or resolution. These measures guarantee that client money and virtual assets are never treated as part of Bitkaya’s estate and that clients retain full ownership and recovery rights.
15.1 Ring-Fencing of Client Assets
All client assets, including money and virtual assets, must be legally and operationally segregated from Bitkaya’s own estate. In the event of insolvency, such assets must be excluded from creditor claims and preserved exclusively for clients.
15.2 Legal Trust or Equivalent Structures
Client assets must be placed under a trust arrangement or equivalent legal framework that clearly establishes clients as the beneficial owners. This structure ensures that, regardless of Bitkaya’s financial condition, client assets remain protected and legally distinct.
15.3 Regulatory and Client Notifications
If insolvency or resolution proceedings occur, Bitkaya must notify:
- Regulators immediately, in line with applicable legal requirements, and
- Clients promptly, providing transparent communication on the status of their assets and the recovery process.
15.4 Resolution Planning
Bitkaya must maintain contingency plans to facilitate the orderly return of client assets in the event of insolvency. These plans should include documented procedures for asset distribution, communication protocols, and regulator coordination.
15.5 Client Confidence and Transparency
By implementing these safeguards, Bitkaya provides assurance to clients that their assets remain secure even in adverse scenarios, strengthening confidence in its custody and safeguarding framework.
16 Training and Awareness
Safeguarding client assets requires not only strong policies and controls but also a well-informed and vigilant workforce. Bitkaya is committed to ensuring that all staff understand their responsibilities in protecting client money and virtual assets through comprehensive training and ongoing awareness programs.
16.1 Mandatory Training
All staff must undergo mandatory training covering:
- Client asset protection principles
- Integration of Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) requirements
- Safeguarding protocols and escalation procedures
16.2 Annual Refresh and Certification
Training must be refreshed annually to ensure knowledge remains current and aligned with regulatory updates. Employees must provide certification or acknowledgment of completion to demonstrate compliance.
16.3 Awareness Programs
Ongoing awareness initiatives must be implemented to reinforce key safeguarding principles. These programs must emphasize the critical importance of maintaining clear separation between client assets and Bitkaya’s own assets.
16.4 Role-Specific Training
Employees in sensitive roles (e.g., finance, custody operations, compliance, IT security) must receive enhanced training tailored to their responsibilities in safeguarding client assets.
16.5 Accountability
Records of training completion and staff acknowledgments must be maintained and subject to audit to demonstrate compliance with regulatory expectations.
17 Breach Management and Escalation Procedures
Any safeguarding breach, near miss, unauthorized movement, reconciliation failure, unexplained shortfall, unauthorized access event, or material control failure affecting client assets must be escalated promptly.
Escalation must assess, where relevant:
- the immediate safeguarding impact;
- whether client assets must be restricted, isolated, or otherwise protected;
- whether there is an associated fraud, cybersecurity, AML/CTF/CPF, or sanctions dimension;
- whether regulatory reporting or notification obligations may arise; and
- whether client communication is required and legally permissible.
Corrective actions, root cause analysis, and remediation tracking must be documented and monitored to closure.
18 Proportionality Implementation
18.1 Purpose and Rationale
This chapter establishes how Bitkaya applies the principle of proportionality within its Client Asset Protection and Safeguarding Framework.
Proportionality ensures that safeguarding measures for client money and virtual assets are commensurate with the company’s size, complexity, and risk exposure, while maintaining compliance with CBCS supervisory expectations and the Landsverordening toezicht virtuele activa dienstverleners (LTVAD, 2025).
For Bitkaya, as a small, startup-stage Virtual Asset Service Provider (VASP), this principle ensures that safeguarding controls remain fit-for-purpose, cost-effective, and scalable as the company grows, without compromising the integrity, segregation, or protection of client assets.
18.2 Guiding Principles
Bitkaya’s proportionality framework is grounded in the following principles:
- Risk-Based Safeguarding: The depth and frequency of controls depend on the inherent and residual risks related to custody, client fund flows, and service channels. Higher-risk activities (e.g., wallet custody, withdrawals) receive enhanced oversight.
- Scalability: Client safeguarding mechanisms—such as reconciliations, reporting, and third-party oversight—are designed to scale as the number of clients, transaction volume, and product complexity increase.
- Resource Efficiency: Governance and oversight structures are right-sized. Core safeguarding functions (e.g., segregation of assets, reconciliation, breach management) are integrated into existing operations, supported by automation as the company matures.
- Regulatory Alignment: Proportionality is applied within the boundaries of applicable CBCS guidelines, FATF standards, and the LTVAD, ensuring that simplified structures do not weaken compliance or accountability.
- Continuous Improvement: Safeguarding procedures evolve in line with supervisory feedback, independent audits, and lessons learned from reconciliation or incident reviews.
18.3 Governance and Oversight
Governance under the proportionality principle follows a lean oversight structure appropriate for a small VASP:
- The Designated Safeguarding Officer (DSO) oversees client asset protection, reconciliations, and custody integrity.
- The Head of Risk & Compliance periodically reviews proportionality justifications and reports to the Board.
- The Board of Directors approves proportionality adjustments annually or after material changes (e.g., new custody providers, expansion to new jurisdictions).
This ensures accountability without the need for a large, dedicated safeguarding department at the current stage of operations.
18.4 Application of Proportionality Across Safeguarding Domains
| Safeguarding Domain | Proportionality Measures for a Small VASP |
|---|---|
| Governance & Oversight | DSO combines roles with Compliance under segregation-of-duties controls; reports quarterly to the Board. |
| Client Asset Segregation | One-to-one separation maintained via distinct client accounts and wallets; periodic reconciliations conducted weekly instead of daily during early-stage operations, increasing with scale. |
| Reconciliation & Record-Keeping | Simplified reconciliation templates and digital records maintained in cloud systems; enhanced automation planned as transaction volumes grow. |
| Third-Party Oversight | Due diligence performed annually on banking and wallet partners; frequency and depth of review increase as total custody value grows. |
| Client Reporting | Monthly client statements generated automatically; review scope and report frequency will expand with the client base. |
| Audit and Assurance | Independent audit coverage initially focused on custody and reconciliation; later broadened to include automated systems and third-party integrations. |
| Breach and Escalation | Streamlined incident escalation to the CEO and Board; formal risk committees introduced as organization size increases. |
18.5 Documentation and Approval of Proportionality Decisions
All proportionality-based decisions, such as frequency of reconciliations, staffing allocation, or automation thresholds, are documented and approved by the DSO and the Board.
Records of justifications, control adjustments, and related audit evidence are maintained for at least five (5) years, ensuring traceability and regulatory transparency.
18.6 Dynamic Review of Proportionality Framework
Bitkaya’s proportionality framework is dynamic and reassessed annually or after significant changes in:
- Business scale (e.g., transaction volume, client base, or assets under custody)
- Regulatory updates or CBCS guidance
- Operational or cybersecurity incidents
Updates of this manual must be approved by the Board and communicated to all staff. A version control log must record all changes, effective dates, and approving authorities.
Qualified Legal Statements
The manual’s trust, insolvency exclusion, no-set-off, licensing and uninterrupted-access statements require supporting legal opinions, executed bank acknowledgments, current authorization and tested operating arrangements. BCMS records these as policy objectives, not independently verified legal facts, until the evidence in ISS-SAFU-001 Confirm Safeguarding Architecture Legal Protections and Operating Evidence is completed.
Operating Layer
This policy is implemented through PRC-CPO-001 Client Protection and Operations and the linked PROC-SAFU-* procedures and CTRL-SAFU-* controls. It is the detailed safeguarding layer beneath PROC-MCT-005 Safeguard Client Assets and Custody Operations.
Implementing Procedures and Controls
Procedures
- PROC-SAFU-001 Govern Safeguarding Roles Risk Training and Proportionality
- PROC-SAFU-002 Segregate and Maintain Client Money and Virtual Assets
- PROC-SAFU-003 Control Client Asset Receipts Withdrawals Transfers and Restrictions
- PROC-SAFU-004 Reconcile Client Assets Maintain Records and Issue Statements
- PROC-SAFU-005 Govern Banks Custodians Wallet Providers and Continuity
- PROC-SAFU-006 Secure Custody Access Keys Logging Backup and Recovery
- PROC-SAFU-007 Maintain Safeguarding Agreements Disclosures and Communications
- PROC-SAFU-008 Manage Safeguarding Breaches Resolution Audit and Improvement
Controls
- CTRL-SAFU-001 Ensure Safeguarding Governance Training and Proportionality Are Maintained
- CTRL-SAFU-002 Ensure Client Assets Are Segregated and Fully Matched
- CTRL-SAFU-003 Ensure Client Asset Movements Are Authorized and Permitted
- CTRL-SAFU-004 Ensure Client Assets Are Reconciled and Reported Accurately
- CTRL-SAFU-005 Ensure Safeguarding Providers and Continuity Are Controlled
- CTRL-SAFU-006 Ensure Custody Technology Access Keys and Recovery Are Secure
- CTRL-SAFU-007 Ensure Safeguarding Terms and Client Communications Are Accurate
- CTRL-SAFU-008 Ensure Safeguarding Breaches Resolution and Assurance Are Effective
Source Document
- Document title: Client Asset Protection & Safeguarding Manual
- Version on cover and change log: 1.1
- Footer version: 1.0, recorded as a document-control discrepancy
- Status: FINAL
- Date shown: April 2026
- Approver shown in change log: Board
- Exact BCMS approval and effective date: 2026-04-21, taken from the approved PDF metadata
- Permanent approved artifact: Bitkaya Client Asset Protection & Safeguarding Manual V11 Approved.pdf
- Note: the manual is an internal policy artifact and is not registered as a regulatory source.
Assurance
- Design status: implemented from the Board-approved SAFU Manual version 1.1
- Operating assurance: pending system-derived assessment
- Evidence status: architecture, legal protections, provider arrangements and operating samples require confirmation
- Overall status: implemented design; operating-effectiveness testing pending
History
- 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
- 2026-07-26: Registered the approved SAFU Manual and established its operating layer.