Purpose
Apply the manual’s risk-based due diligence and approval rules before engaging or continuing a third party capable of creating bribery or corruption exposure.
Scope
Use this procedure primarily for consultants, introducers, referral partners, agents, representatives, influential outsourced providers, strategic partners and parties interacting with regulators, public officials, clients or counterparties on Bitkaya’s behalf.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Determine if ABC due diligence required | Decide whether dedicated ABC due diligence is required based on influence, public-sector contact, introductions, commissions, unusual compensation or integrity concerns. If none of the criteria apply and the third party is an ordinary low-risk supplier, normal onboarding may be enough — the focus should be on third parties that can actually create corruption exposure. | Due-diligence decision record |
| 2 | Classify third-party risk level | Classify the third party as low, medium or unclear, or high risk. Low risk: services clear and ordinary, no public officials involved, no unusual payment structure, no integrity concerns. Higher risk if one or more apply: deals with public officials or regulators, success fees or unusually high payments, ownership unclear, services vague, adverse media or misconduct concerns, higher-risk jurisdiction, or introduced through political or regulatory connections. If in doubt, classify higher and escalate. | Risk classification record |
| 3 | Obtain identity and ownership info | Obtain legal identity, registration, ownership and control information — legal name and registration details, ownership / control information. | Identity and ownership evidence |
| 4 | Document business rationale and fees | Document the business rationale, services, deliverables and proposed fee or commission structure — description of services and deliverables, proposed fee / commission structure. | Service and fee documentation |
| 5 | Perform screening checks | Perform sanctions, adverse-media, reputation, conflict and misconduct checks proportionate to risk — sanctions screening, adverse media screening where relevant, conflicts of interest check. | Screening results |
| 6 | Review red flags | Review red flags including vague services, inflated fees, unusual payees or jurisdictions, opaque ownership, public-official links, onboarding pressure or resistance to ABC clauses — specifically: vague deliverables, unusual or inflated fees, request for payment to another entity or country without a clear reason, refusal to provide ownership details, links to public officials or regulators, pressure to onboard quickly without paperwork, resistance to compliance questions or contract clauses, or corruption / bribery / fraud / misconduct allegations. | Red-flag review record |
| 7 | Obtain tiered approvals | Obtain business-owner approval for low risk; business-owner and Compliance approval for medium or unclear risk; and business-owner, Compliance and Senior Management approval for high risk. | Approval records |
| 8 | Require Compliance approval for officials | Require Compliance approval whenever the third party will interact with a public official or regulator on Bitkaya’s behalf — Compliance approval is always mandatory in those cases; Bitkaya does not require unnecessary committee structures for normal low-risk cases. | Compliance approval record |
| 9 | Include ABC contract clauses | Include proportionate ABC undertakings, information and audit rights, breach notification, subcontracting restrictions and termination rights before work starts — ABC compliance language, audit / information rights, breach notification requirements, limits on subcontracting without approval, termination rights for misconduct or non-cooperation. For ordinary low-risk suppliers, standard contract language may be sufficient; stronger clauses are most important for higher-risk relationships. | Executed contract with safeguards |
| 10 | Reassess on triggers | Reassess on ownership, scope, payment, adverse-media, misconduct or renewal triggers — ownership changes, scope changes, payment behavior becomes unusual, adverse media appears, misconduct concerns arise, or the contract is renewed — and take restriction, remediation or termination action where needed. | Trigger or renewal review record |
Exceptions and Escalation
Commercial urgency does not permit bypassing due diligence. Unresolved red flags, incomplete ownership, unexplained payment instructions or refusal of necessary controls require escalation and no engagement until approved.
Records
- Risk classification and rationale
- Identity, ownership and screening evidence
- Service and compensation rationale
- Red-flag review and approvals
- Contract safeguards
- Trigger and renewal reviews
Relationships
- Policy: POL-ABC-001 Anti-Bribery and Corruption Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Control: CTRL-ABC-002 Ensure Third-Party ABC Due Diligence Is Completed
- Related outsourcing process: PRC-GRO-001 Governance Risk and Outsourcing
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: before engagement and on material trigger or renewal
History
- 2026-07-28: Enriched steps with the full 7-step Third-Party ABC Due Diligence SOP (section 23): classification criteria, minimum checks, red-flag list, tiered approval rules, contract clauses and ongoing-review triggers.
- 2026-07-26: Created from sections 8 and 23 of the approved ABC Manual.