Purpose
Maintain the enterprise-wide AML/CTF/CPF risk assessment and keep the SARA model aligned with Bitkaya risk exposure, CBCS expectations and FATF VA/VASP guidance.
Scope
This procedure applies to annual EWRA/SARA updates and trigger-based reviews after material changes in products, clients, jurisdictions, transaction patterns, outsourcing, technology, regulations, typologies, findings or incidents.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Perform annual EWRA/SARA | At least annually and after a material trigger event; EWRA is the foundation of Bitkaya’s risk-based AML/CFT program | EWRA/SARA assessment |
| 2 | Identify trigger events | Treat changes in products, services, client base, jurisdictions, transaction volumes, delivery channels, wallet arrangements, outsourcing, technology, regulation, sanctions exposure, typologies, incidents, findings, or CBCS/FIU feedback as potential triggers for SARA review | Trigger-event assessment |
| 3 | Collect EWRA inputs | Gather current inputs for five key risk domains: (1) customer base, (2) nature of services/products, (3) geographic exposure, (4) delivery channels, (5) transactional behavior — including wallet and counterparty exposure | Risk scoring worksheet |
| 4 | Score inherent and residual risk | Score inherent likelihood × impact per domain, assess control effectiveness, calculate residual risk under approved SARA methodology. Requires systematic risk identification, control adequacy evaluation, mitigation prioritization by residual risk, and ongoing enterprise- and client-level rating updates | Risk scoring worksheet |
| 5 | Maintain enterprise and client assessments | Calculate organization-wide residual risk view; reconcile assumptions, risk factors and downstream control consequences. Company-level average residual score calibrates the entire AML/CFT framework, policies, resource allocation, procedures, thresholds and alerts | Risk register update |
| 6 | Document methodology and rationale | Document data sources, rationale, evidence, assumptions, limitations, overrides, and material differences between raw output, weighted residual score and final classification. Individual risk factors may score above 25 for high-severity indicators (sanctions, PEP, cash, complex structures, fiat red flags, high-risk wallet exposure). Final client risk = weighted residual across five categories: Geographical, Customer, Product, Transaction, Delivery Channel Risk | SARA/EWRA assessment |
| 7 | Obtain governance review | Compliance Officer/MLRO review, Compliance Committee review (proportionality), and Board of Directors review/approval as applicable; maintain the risk register. Adjust to align with emerging risks, CBCS expectations, and risk appetite | Approval or escalation record |
| 8 | Calibrate downstream controls | Use approved results to calibrate risk appetite, client segmentation, CDD/EDD requirements, review cycles, sanctions controls, KYT thresholds, alert scenarios, training priorities, independent-testing scope, resources and management reporting | Model calibration notes |
| 9 | Apply risk rating thresholds | Low Risk: final weighted residual ≤ 6; Medium Risk: > 6 to 12; High Risk: > 12. Where raw SARA output, weighted residual score and final classification differ materially, document the rationale. Thresholds may be adjusted with documented Compliance approval | Risk classification record |
| 10 | Escalate risk outside appetite | Escalate residual risk outside appetite and track mitigation to an accountable owner and target date | Escalation record |
| 11 | Retain assessment records | Retain assessment, scoring records, approvals, risk-register changes and downstream calibration evidence in the controlled compliance library | Retained assessment records |
Evidence
- SARA/EWRA assessment
- risk scoring worksheet
- risk register update
- approval or escalation record
- model calibration notes
- trigger-event assessment
- evidence of downstream control calibration
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Controls: CTRL-AML-001 Ensure AML Risk Assessment and SARA Calibration Are Current, CTRL-AML-010 Ensure AML Policy Review and Proportionality Are Maintained
- Threshold discrepancy: ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds
- Manual coverage: sections 3.1-3.6 and 14.4-14.5.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Expanded annual and trigger-based SARA steps, governance, documentation and downstream calibration requirements after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.