1 Purpose and Scope

A strong training and awareness framework is essential to safeguard client assets, support sound operations, and ensure compliance with applicable legal and regulatory requirements.

This manual establishes Bitkaya’s framework for training and awareness and is designed to:

  • ensure all employees understand their roles in maintaining compliance, ethical conduct, cybersecurity, and operational resilience;
  • support effective implementation of Bitkaya’s AML/CTF/CPF, sanctions, safeguarding, privacy, risk, and governance frameworks;
  • ensure employees and relevant associated persons understand how to identify, escalate, and document risk events, control issues, unusual activity, and compliance concerns; and
  • promote a culture of integrity, accountability, and continuous improvement.

This manual applies to all employees and, where relevant, contractors, consultants, temporary staff, and other persons acting on behalf of Bitkaya. Training content and frequency shall be proportionate to the individual’s role, responsibilities, and exposure to regulatory, operational, financial crime, cybersecurity, or client protection risk.

2 Roles and Responsibilities

Clearly defined responsibilities help ensure training is consistent, effective, documented, and aligned with Bitkaya’s risk profile and regulatory obligations.

Human Resources (HR) Department

Coordinates the overall training programme across the organization. Maintains attendance, completion, and certification records. Supports onboarding training logistics and follow-up on overdue training.

Compliance Officer

Ensures that compliance-related training content is accurate, current, and aligned with Bitkaya’s legal and regulatory obligations. Oversees AML/CTF/CPF, sanctions, conduct, and regulatory reporting training content. Monitors whether employees understand escalation obligations, documentation standards, and internal reporting procedures.

Department Heads

Identify role-specific training needs within their teams and ensure employees complete mandatory and function-specific training on time. Reinforce the practical application of training in day-to-day work and escalate capability gaps where identified.

Risk, IT, and Other Subject Matter Owners

Support the development and delivery of specialist training content relevant to their control areas, including cybersecurity, business continuity, safeguarding, transaction monitoring, tooling, and incident response.

Employees and Relevant Associated Persons

Must complete all mandatory training in a timely manner, participate actively, apply the training in practice, remain alert to regulatory and operational risks, and escalate issues where required.

3 Training Programs

Training programmes form the foundation of employee readiness. Bitkaya applies a structured training programme that is risk-based, practical, and scalable.

Training is delivered through a combination of onboarding modules, annual refreshers, role-specific sessions, ad hoc updates, awareness communications, and practical exercises.

At a minimum, the programme covers:

  • AML/CTF/CPF and sanctions compliance;
  • ethical conduct and anti-bribery / anti-corruption;
  • client due diligence and escalation responsibilities;
  • cybersecurity and information security awareness;
  • safeguarding of client assets and sensitive information;
  • complaints handling and client communication standards;
  • operational resilience, incident reporting, and business continuity awareness; and
  • documentation, recordkeeping, and internal control expectations.

3.1 Introduction Training

Introduction training provides new employees with the foundational knowledge required to begin their roles responsibly and in line with Bitkaya’s compliance and control framework.

All new employees must receive onboarding training covering, as relevant to their role:

  • Bitkaya’s business model, services, governance structure, and compliance culture;
  • core conduct expectations, including ethics, conflicts of interest, speak-up obligations, and accountability;
  • AML/CTF/CPF fundamentals, including client due diligence, sanctions awareness, unusual activity escalation, and the importance of timely documentation;
  • the distinction between internal escalation and external regulatory reporting;
  • data protection, confidentiality, and information handling obligations;
  • cybersecurity hygiene, authentication, phishing awareness, and secure system use; and
  • reporting lines, approval requirements, and key operational procedures relevant to the employee’s role.

Introduction training must be completed within a reasonable onboarding period defined by management and HR, and completion must be documented.

3.2 Ongoing Training

Ongoing training ensures that employees remain up to date with changes in law, regulation, internal policy, risk exposure, systems, and business activity.

At a minimum, all employees must complete annual refresher training covering the key policies and procedures relevant to their responsibilities.

Ongoing training shall reinforce:

  • updates to laws, regulations, and internal policies;
  • changes in Bitkaya’s risk profile or control environment;
  • lessons learned from incidents, findings, control failures, or near misses;
  • changes to systems, onboarding tools, screening tools, monitoring tools, or workflows; and
  • practical expectations regarding escalation, documentation, client treatment, and control compliance.

Where policy or tool changes materially affect control operation, targeted refresher training or operational guidance shall be delivered without waiting for the next annual cycle.

3.3 Specialized Training

Certain roles require enhanced or function-specific training because they involve elevated regulatory, operational, or client risk.

Targeted training shall be provided to relevant employees, including where applicable:

Compliance and Risk Management

Training on AML/CTF/CPF obligations, sanctions screening, internal case handling, unusual transaction escalation, UTR reporting requirements, client risk scoring, KYV expectations, false positive closure, unresolved alert handling, and documentation standards.

Operations, Trading, and Client-Facing Teams

Training on onboarding controls, required file content, source of funds and source of wealth expectations, transaction-monitoring escalation, wallet and payment red flags, sanctions stop rules, client communications, and when to escalate to Compliance.

Cybersecurity and Information Technology

Training on secure access controls, privileged access, system logging, security monitoring, cyber incident escalation, data confidentiality, system resilience, and support for compliance tooling.

Finance Function

Training on financial controls, payment anomalies, suspicious payment patterns, recordkeeping, escalation of unusual reimbursement or invoice activity, and interaction with AML/CTF/CPF and ABC controls.

Senior Management and Board Members

Training on governance responsibilities, oversight obligations, reporting expectations, approval thresholds, and the relationship between Bitkaya’s control frameworks and regulatory accountability.

Specialized training shall be proportionate to the role and refreshed as necessary when responsibilities, systems, or risk exposures materially change.

3.4 Awareness Initiatives

Awareness initiatives support a proactive culture by keeping employees engaged with emerging risks, lessons learned, and control expectations between formal training sessions.

Awareness measures may include:

  • security bulletins on cyber threats, phishing, fraud patterns, and operational vulnerabilities;
  • short compliance updates on regulatory changes, sanctions developments, and control reminders;
  • thematic awareness campaigns on topics such as insider risk, fraud, client protection, escalation quality, and documentation discipline;
  • scenario-based reminders based on actual incidents, near misses, audit findings, or regulatory observations; and
  • targeted reminders following material updates to systems, procedures, sanctions lists, onboarding requirements, or escalation workflows.

Where relevant, awareness communications should reinforce the distinction between internal case escalation, internal case classification, external UTR reporting, and other regulatory or supervisory notification obligations.

4 Competency Assessment

Competency assessment helps ensure that employees do not merely complete training, but also understand and apply it appropriately in practice.

Competence should be assessed using one or more of the following methods, depending on role and risk:

  • onboarding knowledge checks;
  • annual refresher assessments;
  • supervisor review and observation;
  • practical case review;
  • quality assurance sampling;
  • control testing outcomes;
  • incident or error analysis; and
  • audit or compliance findings.

Where relevant, assessments should test whether employees understand:

  • their escalation obligations;
  • when a matter must be referred to Compliance;
  • key onboarding and screening controls;
  • documentation expectations;
  • sanctions stop rules;
  • the difference between internal handling and external reporting; and
  • how to operate within their delegated authority.

4.1 Initial Assessment

Upon hiring or role transfer, Bitkaya assesses the employee’s baseline knowledge and the training required for the role.

This assessment may consider prior experience, qualifications, regulatory exposure, control responsibilities, and system access level.

Where a role involves elevated risk, client onboarding, transaction handling, approval authority, or access to compliance-sensitive systems, role readiness should be confirmed before the employee performs the function unsupervised.

4.2 Ongoing Assessment

Competencies must be reassessed periodically to ensure the employee remains fit to perform their responsibilities effectively.

Ongoing assessment may be supported by:

  • annual training completion and test results;
  • file reviews and quality checks;
  • review of escalation quality and timeliness;
  • observed adherence to procedures;
  • incident involvement or control breaches;
  • management feedback; and
  • internal audit, second line, or compliance testing results.

Where recurring misunderstandings, poor escalation quality, weak documentation, or repeated control failures are identified, targeted remediation must be initiated.

4.3 Remedial Actions

Where competency gaps are identified, Bitkaya must apply proportionate remedial measures.

These may include:

  • refresher or supplementary training;
  • role-specific coaching or mentoring;
  • closer supervision;
  • temporary restriction of authority or access;
  • reassignment of tasks; or
  • formal performance management where appropriate.

Where competency deficiencies create material compliance, operational, safeguarding, or client risk, management must escalate the matter and ensure corrective action is documented and tracked.

5 Continuous Improvement

Bitkaya is committed to continuously improving its training and awareness framework in line with legal developments, regulatory expectations, internal findings, and business change.

Training content and delivery methods shall be reviewed and updated periodically, taking into account:

  • changes in laws, regulations, and supervisory expectations;
  • updates to internal policies and procedures;
  • incidents, near misses, and lessons learned;
  • internal audit, compliance testing, and control review outcomes;
  • employee feedback and identified knowledge gaps; and
  • material changes to tools, systems, products, services, or operating model.

Where regulator findings or internal remediation require control changes, associated training materials and awareness communications shall be updated promptly.

6 Proportionality Implementation

6.1 Purpose

This chapter outlines how Bitkaya applies the principle of proportionality within its Training and Awareness Framework, ensuring that all education, communication, and capacity-building measures are appropriate to the company’s size, complexity, and risk profile as a small but growing Virtual Asset Service Provider (VASP).

The proportionality principle ensures that Bitkaya’s training and awareness programs are fit-for-purpose, risk-based, and scalable, balancing regulatory expectations from the Centrale Bank van Curaçao en Sint Maarten (CBCS) with the realities of a startup-stage organization.

The objective is to maintain an effective compliance culture while allocating resources efficiently and preparing the company for future growth.

6.2 Guiding Principles of Proportionality

Bitkaya’s approach to proportionality in training and awareness is founded on the following key principles, aligned with those established across other operational manuals (Compliance, Internal Controls, ESG, IT & Cybersecurity, and Business Continuity):

  1. Risk-Based Application — Training and awareness measures are determined by each function’s exposure to regulatory, operational, or cybersecurity risk.
    • Compliance, Operations, and IT receive enhanced and frequent training.
    • Support functions receive core compliance and awareness modules.
  2. Scalability — The framework is designed to evolve as Bitkaya grows. Initial training is lean and cross-functional, with structured specialization added as new departments and systems are established.
  3. Efficiency and Accessibility — Digital and hybrid delivery methods (e-learning, webinars, and micro-learning sessions) ensure proportional resource use without compromising quality.
  4. Accountability and Traceability — Training completion and comprehension are documented and maintained in Bitkaya’s compliance evidence library for CBCS and audit review.
  5. Continuous Improvement — Lessons from internal audits, incident reviews, and regulatory feedback are incorporated into each annual training cycle to ensure ongoing alignment with emerging risks and supervisory expectations.

6.3 Application of Proportionality Across Training and Awareness Components

6.3.1 (a) Employee Training

Training content and intensity are structured proportionally by role and risk exposure:

  • Tier 1 – Foundational: Mandatory for all employees. Covers AML/CFT, cybersecurity hygiene, Code of Ethics, whistleblowing, and client asset safeguarding.
  • Tier 2 – Functional: Delivered to Compliance, Operations, and IT teams, emphasizing transaction monitoring, data security, and risk management.
  • Tier 3 – Leadership: Focuses on governance, CBCS regulatory frameworks, decision-making ethics, and oversight responsibilities.

Training frequency follows proportional logic:

  • High-risk functions: semi-annual.
  • Medium/low-risk functions: annual or upon material policy changes.

6.3.2 (b) Awareness Activities

Proportional awareness efforts maintain employee vigilance between training cycles:

  • Quarterly awareness campaigns on topics such as phishing, data privacy, and fraud prevention.
  • Targeted memos or posters reinforcing key compliance messages.
  • All-hands sessions to discuss regulatory updates or new operational risks.

As Bitkaya scales, awareness programs will expand to include ESG, data ethics, and cross-border regulatory awareness.

6.3.3 (c) Competence Assessment

Competence assessments are tailored to proportional exposure levels:

  • Knowledge checks after every module to confirm comprehension.
  • Scenario-based assessments for AML/CFT, data breaches, and continuity response.
  • Annual competence reviews incorporated into HR and compliance performance appraisals.

6.3.4 (d) Resource Allocation

Bitkaya allocates training resources based on proportional materiality and compliance obligations:

  • Highest priority to regulatory-mandated and risk-sensitive topics (AML/CFT, cybersecurity, client safeguarding).
  • Use of shared training resources and cloud-based learning management tools for efficiency.
  • Annual review by the Compliance Officer and HR to ensure adequacy and cost-effectiveness.

6.4 Governance and Oversight

Governance responsibilities for proportional implementation in training and awareness are as follows:

  • Board of Directors: Approves the Training & Awareness Policy and ensures sufficient resources are allocated to training across the organization.
  • Compliance Officer: Designs, updates, and monitors the proportionality framework for training. Tracks completion rates and ensures CBCS compliance evidence is available for inspection.
  • Department Heads: Ensure all staff within their functions complete applicable training and apply the knowledge operationally.
  • All Employees: Maintain responsibility for completing training on time, applying learned principles in daily work, and reporting compliance concerns.

Oversight aligns with Bitkaya’s “three lines of defense” model, integrating compliance monitoring and internal audit validation of training adequacy.

6.5 Documentation and Review

Bitkaya maintains a complete audit trail of training and awareness initiatives, including:

  • Attendance sheets, completion certificates, and test results.
  • Version-controlled training materials.
  • Annual proportionality evaluations confirming adequacy and alignment with the company’s scale and risk exposure.

These records are stored in the compliance repository and reviewed during internal audits and CBCS inspections.

6.6 Scalability and Continuous Improvement

Bitkaya’s training and awareness proportionality framework is designed for progressive scalability:

PhaseFocusCharacteristics
StartupCore compliance cultureLean structure, cross-role training, simplified awareness campaigns
GrowthFunction-specific enhancementDedicated modules for new departments and roles, LMS integration
MaturityAdvanced specializationContinuous professional development, external certifications, and predictive learning analytics

The Compliance Officer and HR jointly review training effectiveness annually, incorporating feedback from internal audits, employee surveys, and post-incident reviews to continuously refine the proportional approach.

Exceptions

Training deferral, substitution or frequency variation requires documented risk assessment, approval by Compliance and the responsible manager, a fixed completion date and appropriate interim supervision or access restriction. No exception may remove a legal training obligation, permit an unready person to perform higher-risk work unsupervised, or treat awareness communication as a substitute for required assessed training.

Operating Layer

This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-TRAIN-* procedures and CTRL-TRAIN-* controls. Domain policies and procedures remain authoritative for the accuracy of their subject matter; the TRAIN framework governs assignment, delivery, assessment, evidence and enterprise oversight.

Implementing Procedures and Controls

Procedures

Controls

Source Document

  • Document title: Training & Awareness Manual
  • Version: 1.1
  • Status in source document: FINAL
  • Date shown in source document: April 2026
  • Approver shown in change log: Board
  • Exact BCMS approval and effective date: 2026-04-21, taken from the approved PDF metadata because the visible document states only April 2026
  • Permanent approved artifact: Bitkaya Training and Awareness Manual v11 Approved.pdf
  • Artifact SHA-256: dc01c2e5e8be1f69082387626cc5120cb00e399c8523b091a7e38c7acc59e883
  • Note: this manual is an internal policy artifact and is not registered as a regulatory source.

Interpretation Notes

  • The cover and change log identify the approved document as version 1.1, while the page footers identify version 1.0. BCMS treats version 1.1 as controlling and records the footer as a source-document formatting defect.
  • The manual requires onboarding within a “reasonable” period but does not set one enterprise deadline. The training matrix must set a measurable due date for each audience.
  • The manual states that high-risk functions train semiannually and medium- or low-risk functions annually or after material change. The role-risk classification and resulting assignments must be documented.
  • The manual mentions cloud-based learning management tools but does not designate an approved LMS. Until one is approved, SYS-ECM-002 Compliance Reporting and Evidence Repository is the controlled evidence location.
  • The supplied training decks do not contain explicit approval records. They are registered as publications in review pending content-owner and approver confirmation.

Relationships

Assurance

  • Design status: implemented from approved Training & Awareness Manual version 1.1
  • Operating assurance: pending system-derived assessment
  • Training material status: registered; explicit approval not evidenced in the supplied decks
  • Evidence status: expected evidence is defined in the implementing controls
  • Overall status: implemented design; governance details and operating effectiveness remain subject to ISS-TRAIN-001 Confirm Training Governance Completion Assessment and Operating Evidence

History

  • 2026-07-28: Enriched policy body to 100% PDF coverage — all six sections and every paragraph from the approved manual now represented.
  • 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
  • 2026-07-26: Registered the approved Training & Awareness Manual and established its operating process, procedures, controls and training publications.