Purpose
Perform risk-based client acceptance, customer due diligence, enhanced due diligence and client risk classification before a relationship is activated.
Scope
This procedure applies to individual and corporate client onboarding, periodic review, trigger-based review and material profile changes.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Capture lead | Store in CRM Leads module from approved intake channel | CRM lead record |
| 2 | Collect client information | Identity, contact, purpose, intended nature of relationship, expected transaction volume/frequency, products, delivery channel, jurisdiction, bank details, requested service | CRM contact record |
| 3 | Verify identity (individuals) | Obtain valid passport, identity card (cédula), or driver’s licence + liveness test via approved IDV service (AMLBot KYC/AML). Approved successor must be documented through controlled change | Identity verification report |
| 4 | Verify entity (legal entities) | Establish legal existence, authorized representatives, beneficial ownership and control using current registry, incorporation, ownership and representative evidence. Use Simplified.ID; approved successor must be documented through controlled change | Entity verification documents |
| 5 | Screen for sanctions and PEP | Screen client, entity, UBOs, directors, representatives, signatories for sanctions, PEP, and adverse-information exposure. Retain reports in CRM file | Screening report |
| 6 | Block unresolved sanctions cases | Do not convert or activate. Escalate under PROC-AML-003 Perform Sanctions Screening and Restrictive Measures Escalation | Escalation record |
| 7 | Convert lead to opportunity | After successful verification, assign responsible representative, update CRM contact record and attachments | CRM opportunity record |
| 8 | Complete SARA risk profile | Operations completes preliminary assessment and client SARA profile using approved methodology. Documents discrepancies; Compliance documents any judgement or override | SARA client risk profile |
| 9 | Apply risk classification and review cycle | Low-risk: every 3 years. Medium-risk: every 2 years. High-risk: annually. Earlier review if documented trigger requires it | Risk classification record |
| 10 | Low-risk evidence requirements | Individuals: identity/liveness, sanctions/PEP, basic profile, relationship-purpose. Entities: registry, UBO declaration, representative ID, screening, relationship-purpose | Risk-tier file checklist |
| 11 | Medium-risk evidence requirements | Add: proof of residence or corporate ownership records, source-of-funds info, expected-activity detail, adverse-information review | Risk-tier file checklist |
| 12 | High-risk evidence requirements (EDD) | Complete EDD: enhanced ownership/control review, verified source-of-funds and source-of-wealth, enhanced transaction controls, blockchain tracing if required | EDD file |
| 13 | Apply SDD where eligible | Only where low risk is documented. Continue core identification, beneficial-ownership, relationship-purpose, and ongoing-monitoring measures | SDD documentation |
| 14 | Supplementary background research | When risk indicators warrant it. Register material findings in a compliance case | Compliance case file |
| 15 | Add bank details and price list | Add verified bank details and approved client/vendor price list where applicable. Preserve supporting CRM record | CRM bank/price record |
| 16 | Obtain approval | Low- and medium-risk: management approval. High-risk: both Compliance and management approval | Approval record |
| 17 | Record decision and activate | Record acceptance decision, approvers, rationale, date, risk tier, next review date. Apply Client tag, enable portal access, send welcome communication | Client activation record |
Detailed Requirements
SARA Risk Scoring Model
Bitkaya’s client-level risk assessment is built on the Enterprise-Wide Risk Assessment (EWRA) model, aligned with the CBCS SARA (Systematic AML/CTF/CPF Risk Assessment) methodology. Each client is assigned a residual risk score based on the following EWRA/SARA factors:
- Client type, ownership structure and PEP exposure — nature of the client (individual vs. entity), complexity of ownership layers, and whether the client or any associated person is a Politically Exposed Person
- Onboarding method — digital/remote onboarding vs. face-to-face, and the verification tools employed
- Geographic and jurisdictional exposure — client residence, incorporation jurisdiction, banking jurisdiction, counterparty jurisdictions, and transaction routing through high-risk or prohibited jurisdictions
- Nature of products/services used — virtual asset trading, wallet services, transfers, fiat on/off-ramping, and higher-risk product features
- Transactional behavior — expected volume, frequency, value, and patterns relative to the client profile and peer group
- Delivery channel — remote vs. face-to-face, and the channel through which services are delivered (portal, API, OTC)
The SARA model distinguishes between individual risk-factor scores and the final client risk score:
- For each applicable factor, inherent risk is calculated by multiplying likelihood × impact
- Residual risk is then calculated by applying the relevant control-effectiveness factor
- Applicable residual factor risks are aggregated by category and weighted according to the SARA category weights across: Geographical Risk, Customer Risk, Product Risk, Transaction Risk, and Delivery Channel Risk
- The final weighted residual score determines the client risk rating, subject to documented Compliance judgement and any mandatory escalation, refusal, restriction, or prohibited-relationship rule
- Individual risk factors may show raw or residual scores above 25 where the factor represents a high-severity risk indicator (e.g. sanctions exposure, PEP exposure, cash activity, complex structures, fiat red flags, high-risk wallet exposure)
Note: Risk rating thresholds are under reconciliation — see ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds. The SARA methodology section defines Low ≤ 6, Medium > 6 to ≤ 12, High > 12; the Risk Classification Outcomes table defines Low 4–6, Medium 7–10, High 11–20.
Risk Rating Outcomes
The client risk rating determined by the SARA scoring model drives:
- Depth of CDD or need for EDD — low risk qualifies for Simplified Due Diligence (SDD), medium risk requires standard CDD, high risk requires Enhanced Due Diligence (EDD)
- Frequency of reviews — low-risk every 3 years, medium-risk every 2 years, high-risk annually
- KYT monitoring thresholds — transaction monitoring rules, alert thresholds, and blockchain analytics sensitivity are calibrated to the client’s risk tier
- Escalation criteria for STRs and sanctions matches — higher-risk clients are subject to lower escalation thresholds and stricter escalation paths to Compliance and the MLRO
- Enhanced control measures — transaction limits, additional review steps, and other risk-commensurate controls applied during onboarding and throughout the relationship
Prohibited Jurisdictions
Bitkaya distinguishes between high-risk jurisdictions and prohibited jurisdictions:
- Jurisdictions subject to comprehensive United Nations sanctions, European Union sanctions, applicable Kingdom sanctions measures, or any other sanctions regime that legally prohibits or materially restricts the provision of services are classified as Prohibited Jurisdictions — not merely high-risk
- Prohibited jurisdictions are outside Bitkaya’s risk appetite
- Bitkaya shall not establish or maintain relationships, process transactions, provide wallet services, facilitate transfers, or otherwise provide services involving a prohibited jurisdiction
- Prohibited jurisdictions are not eligible for risk acceptance through enhanced due diligence, risk mitigation measures, or management approval where applicable sanctions laws prohibit the activity
- Where a client, beneficial owner, counterparty, transaction, wallet, or relationship becomes associated with a prohibited jurisdiction, the matter must be escalated immediately to Compliance for assessment and implementation of required restrictive measures, including blocking, freezing, refusal, termination, reporting, or notification obligations
Sanctions Screening Scope
Sanctions screening is a mandatory control applied before onboarding, before activation, during periodic review, upon trigger events, when sanctions lists are updated or refreshed, and before execution, settlement, release, or completion of any relevant transaction. See PROC-AML-003 Perform Sanctions Screening and Restrictive Measures Escalation for the escalation procedure.
Required sanctions lists (minimum coverage):
- United Nations sanctions lists
- European Union sanctions lists
Additional lists where applicable to Bitkaya’s business, client base, counterparties, jurisdictions, payment flows, or risk profile:
- OFAC (US Treasury Office of Foreign Assets Control)
- CFATF (Caribbean Financial Action Task Force)
- Curaçao / Kingdom / local sanctions or restricted lists
- Internal restricted-party or restricted-jurisdiction lists
Parties that must be screened (at minimum, where applicable):
- The client
- Beneficial owner(s) (UBOs)
- Directors, authorized representatives and signatories
- Intermediary entities or persons involved in the relationship or transaction
- VASP counterparties and other relevant institutional counterparties
- Wallet addresses, blockchain identifiers and relevant blockchain exposure
- Bank-account holders or payment counterparties where relevant to the transaction
- Any other party linked to a relationship or transaction where sanctions exposure may arise
True-match handling: Where a sanctions alert is confirmed as a true match, Bitkaya must immediately apply legally required restrictive measures (blocking, freezing, rejecting, refusing, or restricting), escalate to Compliance without delay, and execute applicable FIU Curaçao and CBCS reporting or notification obligations. Unresolved alerts block all onboarding, activation, transaction execution, settlement, or release until resolved or escalated.
KYC Requirements
Individuals:
- Must upload a valid passport, identity card (cédula), or driving license
- Must complete a liveness test through the approved third-party digital ID verification tool
- The approved manual identifies AMLBot’s KYC/AML service for identity verification and sanctions screening; an approved successor must be documented through controlled system and procedure change
Legal entities:
- Bitkaya collects and reviews documentation sufficient to establish the entity’s legal existence
- Verification of authorized representatives who may act on behalf of the entity
- Verification of beneficial ownership — identifying the natural persons who ultimately own or control the entity
- The approved manual identifies Simplified.ID for entity and related-party screening; an approved successor must be documented through controlled change
KYT Monitoring
Bitkaya monitors client activity across both fiat and virtual asset transactions using:
- Blockchain analytics — third-party crypto transaction monitoring provider scans non-custodial client wallets against 20+ risk sources
- Rule-based monitoring scenarios — calibrated to the client’s risk profile and adjusted by risk category
- Internal review — trained personnel review all generated alerts
Risk indicators monitored:
- Transaction size — unusually large or small transactions relative to client profile
- Frequency — unusual velocity or patterns of repeated transactions
- Pattern — structuring, smurfing, or anomalous routing through multiple wallets/chains/counterparties
- Destination — exposure to high-risk wallets, services, or typologies
- Source — deposits from bank accounts not in the client’s name, or from unknown origins
- Mixer/darknet exposure — suspicious wallet connections including mixers, tumblers, darknet markets, and obfuscation smart contracts
Alerts are generated for further review or escalation. Escalation decisions, investigation steps, outcomes, and any related reporting action must be documented.
KYV File Requirements
The Know Your VASP (KYV) compliance file contains, as appropriate to risk:
- License and/or information about the regulatory supervisor
- Company registry extract
- Certificate of incorporation (or other appropriate certificate of registration or licensing)
- Ownership and control information where relevant
- Sanctions screening results
- Independent data sources, including electronic sources (e.g. business information services)
The extent of KYV measures is determined on a documented risk basis. KYV helps prevent indirect exposure to illicit actors through VASP-to-VASP transfers or routing of assets.
CDD/EDD/SDD Levels
Simplified Due Diligence (SDD) — low risk only:
- SDD may only be applied where the client has been assessed and documented as low risk
- Core CDD measures are still applied: identifying the client, identifying the beneficial owner where applicable, understanding the purpose and intended nature of the relationship, and conducting ongoing monitoring
- The extent of documentation and verification is determined on a risk-based basis
Standard CDD — medium risk:
- All low-risk requirements plus:
- Proof of residence (individuals)
- Articles of incorporation, shareholder register or equivalent ownership document (entities)
- Source of funds information (self-declaration)
- Additional information on expected transaction activity
- Adverse information review where relevant
Enhanced Due Diligence (EDD) — high risk:
- All medium-risk requirements plus:
- Source of wealth information and supporting documentation — assessed before approval of the relationship
- Enhanced source of funds review where appropriate
- Enhanced ownership and control documentation for all relevant layers
- Enhanced transaction controls
- Blockchain tracing where required (standard tracing up to 3 hops; high-risk/escalated cases up to 6 hops)
- Formal Compliance and management approval before onboarding
Individual client file — minimum requirements by tier:
| Risk tier | Minimum file requirements |
|---|---|
| Low | Valid passport/ID/driver’s license; liveness/identity verification; sanctions/PEP screening; basic client profile; purpose and intended nature of relationship |
| Medium | All low-risk items; plus proof of residence; source of funds (self-declaration); expected transaction activity detail; adverse information review |
| High | All medium-risk items; plus source of wealth with supporting documentation; enhanced source of funds review; formal compliance and management approval |
Corporate client file — minimum requirements by tier:
| Risk tier | Minimum file requirements |
|---|---|
| Low | Recent corporate registry extract; signed UBO declaration; ID of authorized signatory/representative; sanctions/PEP screening for entity, signatory, and UBOs; purpose and intended nature of relationship |
| Medium | All low-risk items; plus articles of incorporation; shareholder register or equivalent ownership document; source of funds (self-declaration); expected transaction activity detail; adverse information review |
| High | All medium-risk items; plus enhanced ownership and control documentation for all relevant layers; verified source of wealth/source of funds; formal compliance and management approval |
Review Cycles
The approved risk classification and review cycle:
- Low-risk clients: review every 3 years (SDD)
- Medium-risk clients: review every 2 years (standard CDD)
- High-risk clients: review annually (EDD)
A documented trigger (material profile change, sanctions list update, adverse information, suspicious activity, or other risk-relevant event) may require earlier review regardless of the scheduled cycle.
Fiat Red Flags
Examples of fiat-related red flags requiring investigation and potential escalation:
- Transaction structuring / smurfing — multiple small deposits within a short time frame to avoid detection thresholds
- Sudden activity spikes — large trades inconsistent with the client’s transaction history
- Unknown deposit origin — deposit from a bank account not in the name of the client
- Any other red flags as indicated by the Compliance Officer or FATF Red Flag documentation from time to time
Onchain Monitoring Indicators
The crypto transaction monitoring provider scans non-custodial client wallets against 20+ risk sources, including:
- Mixer/tumbler usage
- Sanctions exposure
- Stolen coins
- Scam proceeds
- Ransomware/extortion
- Terrorism financing
- Child exploitation content
- Darknet markets
- High-risk exchanges
- P2P platforms
- Obfuscation smart contracts
The provider assigns a proprietary crypto risk score:
- 0–25% — minimal risk
- 25–75% — moderate, caution advised
- >75% — strongly advised to reject
These indicators feed into KYT monitoring, EDD investigations, and the client’s ongoing risk assessment. See CTRL-AML-002 Ensure CDD EDD and Client Acceptance Are Completed for the control verification of these requirements.
Evidence
- client file checklist
- identity verification report
- screening result
- SARA client risk profile
- approval record
- CDD/EDD evidence
- preliminary-to-final risk comparison
- source-of-funds and source-of-wealth evidence where applicable
- CRM activation and next-review record
- bank and price-list record where applicable
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Controls: CTRL-AML-002 Ensure CDD EDD and Client Acceptance Are Completed, CTRL-AML-006 Ensure Travel Rule KYV and Wallet Verification Are Applied
- Threshold discrepancy: ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds
- Manual coverage: sections 3.2-3.4, 4.1-4.5, 12 and 14.4.1.2 — SARA risk scoring model, risk rating outcomes, prohibited jurisdictions, sanctions screening scope, KYC/KYT/KYV requirements, CDD/EDD/SDD levels, review cycles, fiat red flags, and onchain monitoring indicators.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Expanded the client-acceptance workflow, risk-tier files, review cycles, approvals and CRM activation gates after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.