Purpose

Perform risk-based client acceptance, customer due diligence, enhanced due diligence and client risk classification before a relationship is activated.

Scope

This procedure applies to individual and corporate client onboarding, periodic review, trigger-based review and material profile changes.

Steps

#ActionDetailsEvidence
1Capture leadStore in CRM Leads module from approved intake channelCRM lead record
2Collect client informationIdentity, contact, purpose, intended nature of relationship, expected transaction volume/frequency, products, delivery channel, jurisdiction, bank details, requested serviceCRM contact record
3Verify identity (individuals)Obtain valid passport, identity card (cédula), or driver’s licence + liveness test via approved IDV service (AMLBot KYC/AML). Approved successor must be documented through controlled changeIdentity verification report
4Verify entity (legal entities)Establish legal existence, authorized representatives, beneficial ownership and control using current registry, incorporation, ownership and representative evidence. Use Simplified.ID; approved successor must be documented through controlled changeEntity verification documents
5Screen for sanctions and PEPScreen client, entity, UBOs, directors, representatives, signatories for sanctions, PEP, and adverse-information exposure. Retain reports in CRM fileScreening report
6Block unresolved sanctions casesDo not convert or activate. Escalate under PROC-AML-003 Perform Sanctions Screening and Restrictive Measures EscalationEscalation record
7Convert lead to opportunityAfter successful verification, assign responsible representative, update CRM contact record and attachmentsCRM opportunity record
8Complete SARA risk profileOperations completes preliminary assessment and client SARA profile using approved methodology. Documents discrepancies; Compliance documents any judgement or overrideSARA client risk profile
9Apply risk classification and review cycleLow-risk: every 3 years. Medium-risk: every 2 years. High-risk: annually. Earlier review if documented trigger requires itRisk classification record
10Low-risk evidence requirementsIndividuals: identity/liveness, sanctions/PEP, basic profile, relationship-purpose. Entities: registry, UBO declaration, representative ID, screening, relationship-purposeRisk-tier file checklist
11Medium-risk evidence requirementsAdd: proof of residence or corporate ownership records, source-of-funds info, expected-activity detail, adverse-information reviewRisk-tier file checklist
12High-risk evidence requirements (EDD)Complete EDD: enhanced ownership/control review, verified source-of-funds and source-of-wealth, enhanced transaction controls, blockchain tracing if requiredEDD file
13Apply SDD where eligibleOnly where low risk is documented. Continue core identification, beneficial-ownership, relationship-purpose, and ongoing-monitoring measuresSDD documentation
14Supplementary background researchWhen risk indicators warrant it. Register material findings in a compliance caseCompliance case file
15Add bank details and price listAdd verified bank details and approved client/vendor price list where applicable. Preserve supporting CRM recordCRM bank/price record
16Obtain approvalLow- and medium-risk: management approval. High-risk: both Compliance and management approvalApproval record
17Record decision and activateRecord acceptance decision, approvers, rationale, date, risk tier, next review date. Apply Client tag, enable portal access, send welcome communicationClient activation record

Detailed Requirements

SARA Risk Scoring Model

Bitkaya’s client-level risk assessment is built on the Enterprise-Wide Risk Assessment (EWRA) model, aligned with the CBCS SARA (Systematic AML/CTF/CPF Risk Assessment) methodology. Each client is assigned a residual risk score based on the following EWRA/SARA factors:

  • Client type, ownership structure and PEP exposure — nature of the client (individual vs. entity), complexity of ownership layers, and whether the client or any associated person is a Politically Exposed Person
  • Onboarding method — digital/remote onboarding vs. face-to-face, and the verification tools employed
  • Geographic and jurisdictional exposure — client residence, incorporation jurisdiction, banking jurisdiction, counterparty jurisdictions, and transaction routing through high-risk or prohibited jurisdictions
  • Nature of products/services used — virtual asset trading, wallet services, transfers, fiat on/off-ramping, and higher-risk product features
  • Transactional behavior — expected volume, frequency, value, and patterns relative to the client profile and peer group
  • Delivery channel — remote vs. face-to-face, and the channel through which services are delivered (portal, API, OTC)

The SARA model distinguishes between individual risk-factor scores and the final client risk score:

  • For each applicable factor, inherent risk is calculated by multiplying likelihood × impact
  • Residual risk is then calculated by applying the relevant control-effectiveness factor
  • Applicable residual factor risks are aggregated by category and weighted according to the SARA category weights across: Geographical Risk, Customer Risk, Product Risk, Transaction Risk, and Delivery Channel Risk
  • The final weighted residual score determines the client risk rating, subject to documented Compliance judgement and any mandatory escalation, refusal, restriction, or prohibited-relationship rule
  • Individual risk factors may show raw or residual scores above 25 where the factor represents a high-severity risk indicator (e.g. sanctions exposure, PEP exposure, cash activity, complex structures, fiat red flags, high-risk wallet exposure)

Note: Risk rating thresholds are under reconciliation — see ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds. The SARA methodology section defines Low ≤ 6, Medium > 6 to ≤ 12, High > 12; the Risk Classification Outcomes table defines Low 4–6, Medium 7–10, High 11–20.

Risk Rating Outcomes

The client risk rating determined by the SARA scoring model drives:

  • Depth of CDD or need for EDD — low risk qualifies for Simplified Due Diligence (SDD), medium risk requires standard CDD, high risk requires Enhanced Due Diligence (EDD)
  • Frequency of reviews — low-risk every 3 years, medium-risk every 2 years, high-risk annually
  • KYT monitoring thresholds — transaction monitoring rules, alert thresholds, and blockchain analytics sensitivity are calibrated to the client’s risk tier
  • Escalation criteria for STRs and sanctions matches — higher-risk clients are subject to lower escalation thresholds and stricter escalation paths to Compliance and the MLRO
  • Enhanced control measures — transaction limits, additional review steps, and other risk-commensurate controls applied during onboarding and throughout the relationship

Prohibited Jurisdictions

Bitkaya distinguishes between high-risk jurisdictions and prohibited jurisdictions:

  • Jurisdictions subject to comprehensive United Nations sanctions, European Union sanctions, applicable Kingdom sanctions measures, or any other sanctions regime that legally prohibits or materially restricts the provision of services are classified as Prohibited Jurisdictions — not merely high-risk
  • Prohibited jurisdictions are outside Bitkaya’s risk appetite
  • Bitkaya shall not establish or maintain relationships, process transactions, provide wallet services, facilitate transfers, or otherwise provide services involving a prohibited jurisdiction
  • Prohibited jurisdictions are not eligible for risk acceptance through enhanced due diligence, risk mitigation measures, or management approval where applicable sanctions laws prohibit the activity
  • Where a client, beneficial owner, counterparty, transaction, wallet, or relationship becomes associated with a prohibited jurisdiction, the matter must be escalated immediately to Compliance for assessment and implementation of required restrictive measures, including blocking, freezing, refusal, termination, reporting, or notification obligations

Sanctions Screening Scope

Sanctions screening is a mandatory control applied before onboarding, before activation, during periodic review, upon trigger events, when sanctions lists are updated or refreshed, and before execution, settlement, release, or completion of any relevant transaction. See PROC-AML-003 Perform Sanctions Screening and Restrictive Measures Escalation for the escalation procedure.

Required sanctions lists (minimum coverage):

  • United Nations sanctions lists
  • European Union sanctions lists

Additional lists where applicable to Bitkaya’s business, client base, counterparties, jurisdictions, payment flows, or risk profile:

  • OFAC (US Treasury Office of Foreign Assets Control)
  • CFATF (Caribbean Financial Action Task Force)
  • Curaçao / Kingdom / local sanctions or restricted lists
  • Internal restricted-party or restricted-jurisdiction lists

Parties that must be screened (at minimum, where applicable):

  • The client
  • Beneficial owner(s) (UBOs)
  • Directors, authorized representatives and signatories
  • Intermediary entities or persons involved in the relationship or transaction
  • VASP counterparties and other relevant institutional counterparties
  • Wallet addresses, blockchain identifiers and relevant blockchain exposure
  • Bank-account holders or payment counterparties where relevant to the transaction
  • Any other party linked to a relationship or transaction where sanctions exposure may arise

True-match handling: Where a sanctions alert is confirmed as a true match, Bitkaya must immediately apply legally required restrictive measures (blocking, freezing, rejecting, refusing, or restricting), escalate to Compliance without delay, and execute applicable FIU Curaçao and CBCS reporting or notification obligations. Unresolved alerts block all onboarding, activation, transaction execution, settlement, or release until resolved or escalated.

KYC Requirements

Individuals:

  • Must upload a valid passport, identity card (cédula), or driving license
  • Must complete a liveness test through the approved third-party digital ID verification tool
  • The approved manual identifies AMLBot’s KYC/AML service for identity verification and sanctions screening; an approved successor must be documented through controlled system and procedure change

Legal entities:

  • Bitkaya collects and reviews documentation sufficient to establish the entity’s legal existence
  • Verification of authorized representatives who may act on behalf of the entity
  • Verification of beneficial ownership — identifying the natural persons who ultimately own or control the entity
  • The approved manual identifies Simplified.ID for entity and related-party screening; an approved successor must be documented through controlled change

KYT Monitoring

Bitkaya monitors client activity across both fiat and virtual asset transactions using:

  • Blockchain analytics — third-party crypto transaction monitoring provider scans non-custodial client wallets against 20+ risk sources
  • Rule-based monitoring scenarios — calibrated to the client’s risk profile and adjusted by risk category
  • Internal review — trained personnel review all generated alerts

Risk indicators monitored:

  • Transaction size — unusually large or small transactions relative to client profile
  • Frequency — unusual velocity or patterns of repeated transactions
  • Pattern — structuring, smurfing, or anomalous routing through multiple wallets/chains/counterparties
  • Destination — exposure to high-risk wallets, services, or typologies
  • Source — deposits from bank accounts not in the client’s name, or from unknown origins
  • Mixer/darknet exposure — suspicious wallet connections including mixers, tumblers, darknet markets, and obfuscation smart contracts

Alerts are generated for further review or escalation. Escalation decisions, investigation steps, outcomes, and any related reporting action must be documented.

KYV File Requirements

The Know Your VASP (KYV) compliance file contains, as appropriate to risk:

  • License and/or information about the regulatory supervisor
  • Company registry extract
  • Certificate of incorporation (or other appropriate certificate of registration or licensing)
  • Ownership and control information where relevant
  • Sanctions screening results
  • Independent data sources, including electronic sources (e.g. business information services)

The extent of KYV measures is determined on a documented risk basis. KYV helps prevent indirect exposure to illicit actors through VASP-to-VASP transfers or routing of assets.

CDD/EDD/SDD Levels

Simplified Due Diligence (SDD) — low risk only:

  • SDD may only be applied where the client has been assessed and documented as low risk
  • Core CDD measures are still applied: identifying the client, identifying the beneficial owner where applicable, understanding the purpose and intended nature of the relationship, and conducting ongoing monitoring
  • The extent of documentation and verification is determined on a risk-based basis

Standard CDD — medium risk:

  • All low-risk requirements plus:
    • Proof of residence (individuals)
    • Articles of incorporation, shareholder register or equivalent ownership document (entities)
    • Source of funds information (self-declaration)
    • Additional information on expected transaction activity
    • Adverse information review where relevant

Enhanced Due Diligence (EDD) — high risk:

  • All medium-risk requirements plus:
    • Source of wealth information and supporting documentation — assessed before approval of the relationship
    • Enhanced source of funds review where appropriate
    • Enhanced ownership and control documentation for all relevant layers
    • Enhanced transaction controls
    • Blockchain tracing where required (standard tracing up to 3 hops; high-risk/escalated cases up to 6 hops)
    • Formal Compliance and management approval before onboarding

Individual client file — minimum requirements by tier:

Risk tierMinimum file requirements
LowValid passport/ID/driver’s license; liveness/identity verification; sanctions/PEP screening; basic client profile; purpose and intended nature of relationship
MediumAll low-risk items; plus proof of residence; source of funds (self-declaration); expected transaction activity detail; adverse information review
HighAll medium-risk items; plus source of wealth with supporting documentation; enhanced source of funds review; formal compliance and management approval

Corporate client file — minimum requirements by tier:

Risk tierMinimum file requirements
LowRecent corporate registry extract; signed UBO declaration; ID of authorized signatory/representative; sanctions/PEP screening for entity, signatory, and UBOs; purpose and intended nature of relationship
MediumAll low-risk items; plus articles of incorporation; shareholder register or equivalent ownership document; source of funds (self-declaration); expected transaction activity detail; adverse information review
HighAll medium-risk items; plus enhanced ownership and control documentation for all relevant layers; verified source of wealth/source of funds; formal compliance and management approval

Review Cycles

The approved risk classification and review cycle:

  • Low-risk clients: review every 3 years (SDD)
  • Medium-risk clients: review every 2 years (standard CDD)
  • High-risk clients: review annually (EDD)

A documented trigger (material profile change, sanctions list update, adverse information, suspicious activity, or other risk-relevant event) may require earlier review regardless of the scheduled cycle.

Fiat Red Flags

Examples of fiat-related red flags requiring investigation and potential escalation:

  • Transaction structuring / smurfing — multiple small deposits within a short time frame to avoid detection thresholds
  • Sudden activity spikes — large trades inconsistent with the client’s transaction history
  • Unknown deposit origin — deposit from a bank account not in the name of the client
  • Any other red flags as indicated by the Compliance Officer or FATF Red Flag documentation from time to time

Onchain Monitoring Indicators

The crypto transaction monitoring provider scans non-custodial client wallets against 20+ risk sources, including:

  • Mixer/tumbler usage
  • Sanctions exposure
  • Stolen coins
  • Scam proceeds
  • Ransomware/extortion
  • Terrorism financing
  • Child exploitation content
  • Darknet markets
  • High-risk exchanges
  • P2P platforms
  • Obfuscation smart contracts

The provider assigns a proprietary crypto risk score:

  • 0–25% — minimal risk
  • 25–75% — moderate, caution advised
  • >75% — strongly advised to reject

These indicators feed into KYT monitoring, EDD investigations, and the client’s ongoing risk assessment. See CTRL-AML-002 Ensure CDD EDD and Client Acceptance Are Completed for the control verification of these requirements.

Evidence

  • client file checklist
  • identity verification report
  • screening result
  • SARA client risk profile
  • approval record
  • CDD/EDD evidence
  • preliminary-to-final risk comparison
  • source-of-funds and source-of-wealth evidence where applicable
  • CRM activation and next-review record
  • bank and price-list record where applicable

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Expanded the client-acceptance workflow, risk-tier files, review cycles, approvals and CRM activation gates after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.