Purpose

Maintain the enterprise-wide AML/CTF/CPF risk assessment and keep the SARA model aligned with Bitkaya risk exposure, CBCS expectations and FATF VA/VASP guidance.

Scope

This procedure applies to annual EWRA/SARA updates and trigger-based reviews after material changes in products, clients, jurisdictions, transaction patterns, outsourcing, technology, regulations, typologies, findings or incidents.

Steps

#ActionDetailsEvidence
1Perform annual EWRA/SARAAt least annually and after a material trigger event; EWRA is the foundation of Bitkaya’s risk-based AML/CFT programEWRA/SARA assessment
2Identify trigger eventsTreat changes in products, services, client base, jurisdictions, transaction volumes, delivery channels, wallet arrangements, outsourcing, technology, regulation, sanctions exposure, typologies, incidents, findings, or CBCS/FIU feedback as potential triggers for SARA reviewTrigger-event assessment
3Collect EWRA inputsGather current inputs for five key risk domains: (1) customer base, (2) nature of services/products, (3) geographic exposure, (4) delivery channels, (5) transactional behavior — including wallet and counterparty exposureRisk scoring worksheet
4Score inherent and residual riskScore inherent likelihood × impact per domain, assess control effectiveness, calculate residual risk under approved SARA methodology. Requires systematic risk identification, control adequacy evaluation, mitigation prioritization by residual risk, and ongoing enterprise- and client-level rating updatesRisk scoring worksheet
5Maintain enterprise and client assessmentsCalculate organization-wide residual risk view; reconcile assumptions, risk factors and downstream control consequences. Company-level average residual score calibrates the entire AML/CFT framework, policies, resource allocation, procedures, thresholds and alertsRisk register update
6Document methodology and rationaleDocument data sources, rationale, evidence, assumptions, limitations, overrides, and material differences between raw output, weighted residual score and final classification. Individual risk factors may score above 25 for high-severity indicators (sanctions, PEP, cash, complex structures, fiat red flags, high-risk wallet exposure). Final client risk = weighted residual across five categories: Geographical, Customer, Product, Transaction, Delivery Channel RiskSARA/EWRA assessment
7Obtain governance reviewCompliance Officer/MLRO review, Compliance Committee review (proportionality), and Board of Directors review/approval as applicable; maintain the risk register. Adjust to align with emerging risks, CBCS expectations, and risk appetiteApproval or escalation record
8Calibrate downstream controlsUse approved results to calibrate risk appetite, client segmentation, CDD/EDD requirements, review cycles, sanctions controls, KYT thresholds, alert scenarios, training priorities, independent-testing scope, resources and management reportingModel calibration notes
9Apply risk rating thresholdsLow Risk: final weighted residual ≤ 6; Medium Risk: > 6 to 12; High Risk: > 12. Where raw SARA output, weighted residual score and final classification differ materially, document the rationale. Thresholds may be adjusted with documented Compliance approvalRisk classification record
10Escalate risk outside appetiteEscalate residual risk outside appetite and track mitigation to an accountable owner and target dateEscalation record
11Retain assessment recordsRetain assessment, scoring records, approvals, risk-register changes and downstream calibration evidence in the controlled compliance libraryRetained assessment records

Evidence

  • SARA/EWRA assessment
  • risk scoring worksheet
  • risk register update
  • approval or escalation record
  • model calibration notes
  • trigger-event assessment
  • evidence of downstream control calibration

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Expanded annual and trigger-based SARA steps, governance, documentation and downstream calibration requirements after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.