1 Purpose and Scope
A strong training and awareness framework is essential to safeguard client assets, support sound operations, and ensure compliance with applicable legal and regulatory requirements.
This manual establishes Bitkaya’s framework for training and awareness and is designed to:
- ensure all employees understand their roles in maintaining compliance, ethical conduct, cybersecurity, and operational resilience;
- support effective implementation of Bitkaya’s AML/CTF/CPF, sanctions, safeguarding, privacy, risk, and governance frameworks;
- ensure employees and relevant associated persons understand how to identify, escalate, and document risk events, control issues, unusual activity, and compliance concerns; and
- promote a culture of integrity, accountability, and continuous improvement.
This manual applies to all employees and, where relevant, contractors, consultants, temporary staff, and other persons acting on behalf of Bitkaya. Training content and frequency shall be proportionate to the individual’s role, responsibilities, and exposure to regulatory, operational, financial crime, cybersecurity, or client protection risk.
2 Roles and Responsibilities
Clearly defined responsibilities help ensure training is consistent, effective, documented, and aligned with Bitkaya’s risk profile and regulatory obligations.
Human Resources (HR) Department
Coordinates the overall training programme across the organization. Maintains attendance, completion, and certification records. Supports onboarding training logistics and follow-up on overdue training.
Compliance Officer
Ensures that compliance-related training content is accurate, current, and aligned with Bitkaya’s legal and regulatory obligations. Oversees AML/CTF/CPF, sanctions, conduct, and regulatory reporting training content. Monitors whether employees understand escalation obligations, documentation standards, and internal reporting procedures.
Department Heads
Identify role-specific training needs within their teams and ensure employees complete mandatory and function-specific training on time. Reinforce the practical application of training in day-to-day work and escalate capability gaps where identified.
Risk, IT, and Other Subject Matter Owners
Support the development and delivery of specialist training content relevant to their control areas, including cybersecurity, business continuity, safeguarding, transaction monitoring, tooling, and incident response.
Employees and Relevant Associated Persons
Must complete all mandatory training in a timely manner, participate actively, apply the training in practice, remain alert to regulatory and operational risks, and escalate issues where required.
3 Training Programs
Training programmes form the foundation of employee readiness. Bitkaya applies a structured training programme that is risk-based, practical, and scalable.
Training is delivered through a combination of onboarding modules, annual refreshers, role-specific sessions, ad hoc updates, awareness communications, and practical exercises.
At a minimum, the programme covers:
- AML/CTF/CPF and sanctions compliance;
- ethical conduct and anti-bribery / anti-corruption;
- client due diligence and escalation responsibilities;
- cybersecurity and information security awareness;
- safeguarding of client assets and sensitive information;
- complaints handling and client communication standards;
- operational resilience, incident reporting, and business continuity awareness; and
- documentation, recordkeeping, and internal control expectations.
3.1 Introduction Training
Introduction training provides new employees with the foundational knowledge required to begin their roles responsibly and in line with Bitkaya’s compliance and control framework.
All new employees must receive onboarding training covering, as relevant to their role:
- Bitkaya’s business model, services, governance structure, and compliance culture;
- core conduct expectations, including ethics, conflicts of interest, speak-up obligations, and accountability;
- AML/CTF/CPF fundamentals, including client due diligence, sanctions awareness, unusual activity escalation, and the importance of timely documentation;
- the distinction between internal escalation and external regulatory reporting;
- data protection, confidentiality, and information handling obligations;
- cybersecurity hygiene, authentication, phishing awareness, and secure system use; and
- reporting lines, approval requirements, and key operational procedures relevant to the employee’s role.
Introduction training must be completed within a reasonable onboarding period defined by management and HR, and completion must be documented.
3.2 Ongoing Training
Ongoing training ensures that employees remain up to date with changes in law, regulation, internal policy, risk exposure, systems, and business activity.
At a minimum, all employees must complete annual refresher training covering the key policies and procedures relevant to their responsibilities.
Ongoing training shall reinforce:
- updates to laws, regulations, and internal policies;
- changes in Bitkaya’s risk profile or control environment;
- lessons learned from incidents, findings, control failures, or near misses;
- changes to systems, onboarding tools, screening tools, monitoring tools, or workflows; and
- practical expectations regarding escalation, documentation, client treatment, and control compliance.
Where policy or tool changes materially affect control operation, targeted refresher training or operational guidance shall be delivered without waiting for the next annual cycle.
3.3 Specialized Training
Certain roles require enhanced or function-specific training because they involve elevated regulatory, operational, or client risk.
Targeted training shall be provided to relevant employees, including where applicable:
Compliance and Risk Management
Training on AML/CTF/CPF obligations, sanctions screening, internal case handling, unusual transaction escalation, UTR reporting requirements, client risk scoring, KYV expectations, false positive closure, unresolved alert handling, and documentation standards.
Operations, Trading, and Client-Facing Teams
Training on onboarding controls, required file content, source of funds and source of wealth expectations, transaction-monitoring escalation, wallet and payment red flags, sanctions stop rules, client communications, and when to escalate to Compliance.
Cybersecurity and Information Technology
Training on secure access controls, privileged access, system logging, security monitoring, cyber incident escalation, data confidentiality, system resilience, and support for compliance tooling.
Finance Function
Training on financial controls, payment anomalies, suspicious payment patterns, recordkeeping, escalation of unusual reimbursement or invoice activity, and interaction with AML/CTF/CPF and ABC controls.
Senior Management and Board Members
Training on governance responsibilities, oversight obligations, reporting expectations, approval thresholds, and the relationship between Bitkaya’s control frameworks and regulatory accountability.
Specialized training shall be proportionate to the role and refreshed as necessary when responsibilities, systems, or risk exposures materially change.
3.4 Awareness Initiatives
Awareness initiatives support a proactive culture by keeping employees engaged with emerging risks, lessons learned, and control expectations between formal training sessions.
Awareness measures may include:
- security bulletins on cyber threats, phishing, fraud patterns, and operational vulnerabilities;
- short compliance updates on regulatory changes, sanctions developments, and control reminders;
- thematic awareness campaigns on topics such as insider risk, fraud, client protection, escalation quality, and documentation discipline;
- scenario-based reminders based on actual incidents, near misses, audit findings, or regulatory observations; and
- targeted reminders following material updates to systems, procedures, sanctions lists, onboarding requirements, or escalation workflows.
Where relevant, awareness communications should reinforce the distinction between internal case escalation, internal case classification, external UTR reporting, and other regulatory or supervisory notification obligations.
4 Competency Assessment
Competency assessment helps ensure that employees do not merely complete training, but also understand and apply it appropriately in practice.
Competence should be assessed using one or more of the following methods, depending on role and risk:
- onboarding knowledge checks;
- annual refresher assessments;
- supervisor review and observation;
- practical case review;
- quality assurance sampling;
- control testing outcomes;
- incident or error analysis; and
- audit or compliance findings.
Where relevant, assessments should test whether employees understand:
- their escalation obligations;
- when a matter must be referred to Compliance;
- key onboarding and screening controls;
- documentation expectations;
- sanctions stop rules;
- the difference between internal handling and external reporting; and
- how to operate within their delegated authority.
4.1 Initial Assessment
Upon hiring or role transfer, Bitkaya assesses the employee’s baseline knowledge and the training required for the role.
This assessment may consider prior experience, qualifications, regulatory exposure, control responsibilities, and system access level.
Where a role involves elevated risk, client onboarding, transaction handling, approval authority, or access to compliance-sensitive systems, role readiness should be confirmed before the employee performs the function unsupervised.
4.2 Ongoing Assessment
Competencies must be reassessed periodically to ensure the employee remains fit to perform their responsibilities effectively.
Ongoing assessment may be supported by:
- annual training completion and test results;
- file reviews and quality checks;
- review of escalation quality and timeliness;
- observed adherence to procedures;
- incident involvement or control breaches;
- management feedback; and
- internal audit, second line, or compliance testing results.
Where recurring misunderstandings, poor escalation quality, weak documentation, or repeated control failures are identified, targeted remediation must be initiated.
4.3 Remedial Actions
Where competency gaps are identified, Bitkaya must apply proportionate remedial measures.
These may include:
- refresher or supplementary training;
- role-specific coaching or mentoring;
- closer supervision;
- temporary restriction of authority or access;
- reassignment of tasks; or
- formal performance management where appropriate.
Where competency deficiencies create material compliance, operational, safeguarding, or client risk, management must escalate the matter and ensure corrective action is documented and tracked.
5 Continuous Improvement
Bitkaya is committed to continuously improving its training and awareness framework in line with legal developments, regulatory expectations, internal findings, and business change.
Training content and delivery methods shall be reviewed and updated periodically, taking into account:
- changes in laws, regulations, and supervisory expectations;
- updates to internal policies and procedures;
- incidents, near misses, and lessons learned;
- internal audit, compliance testing, and control review outcomes;
- employee feedback and identified knowledge gaps; and
- material changes to tools, systems, products, services, or operating model.
Where regulator findings or internal remediation require control changes, associated training materials and awareness communications shall be updated promptly.
6 Proportionality Implementation
6.1 Purpose
This chapter outlines how Bitkaya applies the principle of proportionality within its Training and Awareness Framework, ensuring that all education, communication, and capacity-building measures are appropriate to the company’s size, complexity, and risk profile as a small but growing Virtual Asset Service Provider (VASP).
The proportionality principle ensures that Bitkaya’s training and awareness programs are fit-for-purpose, risk-based, and scalable, balancing regulatory expectations from the Centrale Bank van Curaçao en Sint Maarten (CBCS) with the realities of a startup-stage organization.
The objective is to maintain an effective compliance culture while allocating resources efficiently and preparing the company for future growth.
6.2 Guiding Principles of Proportionality
Bitkaya’s approach to proportionality in training and awareness is founded on the following key principles, aligned with those established across other operational manuals (Compliance, Internal Controls, ESG, IT & Cybersecurity, and Business Continuity):
- Risk-Based Application — Training and awareness measures are determined by each function’s exposure to regulatory, operational, or cybersecurity risk.
- Compliance, Operations, and IT receive enhanced and frequent training.
- Support functions receive core compliance and awareness modules.
- Scalability — The framework is designed to evolve as Bitkaya grows. Initial training is lean and cross-functional, with structured specialization added as new departments and systems are established.
- Efficiency and Accessibility — Digital and hybrid delivery methods (e-learning, webinars, and micro-learning sessions) ensure proportional resource use without compromising quality.
- Accountability and Traceability — Training completion and comprehension are documented and maintained in Bitkaya’s compliance evidence library for CBCS and audit review.
- Continuous Improvement — Lessons from internal audits, incident reviews, and regulatory feedback are incorporated into each annual training cycle to ensure ongoing alignment with emerging risks and supervisory expectations.
6.3 Application of Proportionality Across Training and Awareness Components
6.3.1 (a) Employee Training
Training content and intensity are structured proportionally by role and risk exposure:
- Tier 1 – Foundational: Mandatory for all employees. Covers AML/CFT, cybersecurity hygiene, Code of Ethics, whistleblowing, and client asset safeguarding.
- Tier 2 – Functional: Delivered to Compliance, Operations, and IT teams, emphasizing transaction monitoring, data security, and risk management.
- Tier 3 – Leadership: Focuses on governance, CBCS regulatory frameworks, decision-making ethics, and oversight responsibilities.
Training frequency follows proportional logic:
- High-risk functions: semi-annual.
- Medium/low-risk functions: annual or upon material policy changes.
6.3.2 (b) Awareness Activities
Proportional awareness efforts maintain employee vigilance between training cycles:
- Quarterly awareness campaigns on topics such as phishing, data privacy, and fraud prevention.
- Targeted memos or posters reinforcing key compliance messages.
- All-hands sessions to discuss regulatory updates or new operational risks.
As Bitkaya scales, awareness programs will expand to include ESG, data ethics, and cross-border regulatory awareness.
6.3.3 (c) Competence Assessment
Competence assessments are tailored to proportional exposure levels:
- Knowledge checks after every module to confirm comprehension.
- Scenario-based assessments for AML/CFT, data breaches, and continuity response.
- Annual competence reviews incorporated into HR and compliance performance appraisals.
6.3.4 (d) Resource Allocation
Bitkaya allocates training resources based on proportional materiality and compliance obligations:
- Highest priority to regulatory-mandated and risk-sensitive topics (AML/CFT, cybersecurity, client safeguarding).
- Use of shared training resources and cloud-based learning management tools for efficiency.
- Annual review by the Compliance Officer and HR to ensure adequacy and cost-effectiveness.
6.4 Governance and Oversight
Governance responsibilities for proportional implementation in training and awareness are as follows:
- Board of Directors: Approves the Training & Awareness Policy and ensures sufficient resources are allocated to training across the organization.
- Compliance Officer: Designs, updates, and monitors the proportionality framework for training. Tracks completion rates and ensures CBCS compliance evidence is available for inspection.
- Department Heads: Ensure all staff within their functions complete applicable training and apply the knowledge operationally.
- All Employees: Maintain responsibility for completing training on time, applying learned principles in daily work, and reporting compliance concerns.
Oversight aligns with Bitkaya’s “three lines of defense” model, integrating compliance monitoring and internal audit validation of training adequacy.
6.5 Documentation and Review
Bitkaya maintains a complete audit trail of training and awareness initiatives, including:
- Attendance sheets, completion certificates, and test results.
- Version-controlled training materials.
- Annual proportionality evaluations confirming adequacy and alignment with the company’s scale and risk exposure.
These records are stored in the compliance repository and reviewed during internal audits and CBCS inspections.
6.6 Scalability and Continuous Improvement
Bitkaya’s training and awareness proportionality framework is designed for progressive scalability:
| Phase | Focus | Characteristics |
|---|---|---|
| Startup | Core compliance culture | Lean structure, cross-role training, simplified awareness campaigns |
| Growth | Function-specific enhancement | Dedicated modules for new departments and roles, LMS integration |
| Maturity | Advanced specialization | Continuous professional development, external certifications, and predictive learning analytics |
The Compliance Officer and HR jointly review training effectiveness annually, incorporating feedback from internal audits, employee surveys, and post-incident reviews to continuously refine the proportional approach.
Exceptions
Training deferral, substitution or frequency variation requires documented risk assessment, approval by Compliance and the responsible manager, a fixed completion date and appropriate interim supervision or access restriction. No exception may remove a legal training obligation, permit an unready person to perform higher-risk work unsupervised, or treat awareness communication as a substitute for required assessed training.
Operating Layer
This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-TRAIN-* procedures and CTRL-TRAIN-* controls. Domain policies and procedures remain authoritative for the accuracy of their subject matter; the TRAIN framework governs assignment, delivery, assessment, evidence and enterprise oversight.
Implementing Procedures and Controls
Procedures
- PROC-TRAIN-001 Govern Training Needs Curriculum Matrix and Calendar
- PROC-TRAIN-002 Deliver Onboarding and Confirm Role Readiness
- PROC-TRAIN-003 Deliver Recurring and Role Specific Training
- PROC-TRAIN-004 Conduct Quarterly Awareness and Event Driven Updates
- PROC-TRAIN-005 Assess Competence and Remediate Gaps
- PROC-TRAIN-006 Maintain Training Records Report and Improve
Controls
- CTRL-TRAIN-001 Ensure Training Needs Matrix and Calendar Are Complete
- CTRL-TRAIN-002 Ensure Onboarding and Role Readiness Are Completed
- CTRL-TRAIN-003 Ensure Recurring and Role Specific Training Is Completed
- CTRL-TRAIN-004 Ensure Quarterly Awareness Activity Occurs
- CTRL-TRAIN-005 Ensure Competence Is Assessed and Gaps Are Remediated
- CTRL-TRAIN-006 Ensure Training Records Reporting and Improvement Are Maintained
Source Document
- Document title: Training & Awareness Manual
- Version: 1.1
- Status in source document: FINAL
- Date shown in source document: April 2026
- Approver shown in change log: Board
- Exact BCMS approval and effective date: 2026-04-21, taken from the approved PDF metadata because the visible document states only April 2026
- Permanent approved artifact: Bitkaya Training and Awareness Manual v11 Approved.pdf
- Artifact SHA-256:
dc01c2e5e8be1f69082387626cc5120cb00e399c8523b091a7e38c7acc59e883 - Note: this manual is an internal policy artifact and is not registered as a regulatory source.
Interpretation Notes
- The cover and change log identify the approved document as version 1.1, while the page footers identify version 1.0. BCMS treats version 1.1 as controlling and records the footer as a source-document formatting defect.
- The manual requires onboarding within a “reasonable” period but does not set one enterprise deadline. The training matrix must set a measurable due date for each audience.
- The manual states that high-risk functions train semiannually and medium- or low-risk functions annually or after material change. The role-risk classification and resulting assignments must be documented.
- The manual mentions cloud-based learning management tools but does not designate an approved LMS. Until one is approved, SYS-ECM-002 Compliance Reporting and Evidence Repository is the controlled evidence location.
- The supplied training decks do not contain explicit approval records. They are registered as publications in
reviewpending content-owner and approver confirmation.
Relationships
- Parent framework: POL-ECM-001 Enterprise Compliance Manual
- Employee obligations: POL-EMP-001 Employee Handbook
- Operating process: PRC-RSA-001 Resilience Systems and Assurance
- Evidence repository: SYS-ECM-002 Compliance Reporting and Evidence Repository
- Implementation issue: ISS-TRAIN-001 Confirm Training Governance Completion Assessment and Operating Evidence
Assurance
- Design status: implemented from approved Training & Awareness Manual version 1.1
- Operating assurance: pending system-derived assessment
- Training material status: registered; explicit approval not evidenced in the supplied decks
- Evidence status: expected evidence is defined in the implementing controls
- Overall status: implemented design; governance details and operating effectiveness remain subject to ISS-TRAIN-001 Confirm Training Governance Completion Assessment and Operating Evidence
History
- 2026-07-28: Enriched policy body to 100% PDF coverage — all six sections and every paragraph from the approved manual now represented.
- 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
- 2026-07-26: Registered the approved Training & Awareness Manual and established its operating process, procedures, controls and training publications.