Purpose

Screen clients, counterparties, wallets, transactions and related parties for sanctions exposure and escalate unresolved or confirmed matches before activity proceeds.

Scope

This procedure applies before onboarding, before relationship activation, during periodic review, after sanctions list updates, upon trigger events and before relevant transaction execution, settlement, release or completion.

Steps

#ActionDetailsEvidence
1Identify screening scopeIdentify all parties and identifiers requiring screening: client, beneficial owners, directors, authorized representatives, signatories, intermediaries, VASP counterparties, wallet addresses, blockchain identifiers, fiat payment counterparties, and any other linked party where sanctions exposure may ariseScreening scope record
2Screen applicable partiesScreen clients, UBOs, directors, representatives, intermediaries, VASP counterparties, wallet addresses, blockchain identifiers and fiat payment counterpartiesScreening report
3Apply screening timingScreen before onboarding, before activation, during periodic review, after trigger events, after sanctions-list refresh, and before execution, settlement, release or completion of relevant transactionsScreening log
4Use reliable tools and listsCover at minimum UN and EU sanctions lists. Where applicable to Bitkaya’s exposure, also screen OFAC, CFATF, Curaçao/Kingdom/local sanctions or restricted lists, and internal restricted-party or restricted-jurisdiction listsSanctions-list coverage record
5Classify prohibited jurisdictionsClassify jurisdictions subject to comprehensive UN, EU, applicable Kingdom sanctions, or any regime legally prohibiting or materially restricting services as Prohibited Jurisdictions — outside Bitkaya’s risk appetiteProhibited-jurisdiction decision
6Enforce prohibitionDo not establish or maintain relationships, process transactions, provide wallet services, facilitate transfers, or provide services where doing so would violate applicable sanctions legislation or involve a prohibited jurisdiction. EDD or management approval cannot override the prohibitionRefusal/blocking record
7Escalate prohibited-jurisdiction exposureWhere a client, UBO, counterparty, transaction, wallet, or relationship becomes associated with a prohibited jurisdiction, escalate immediately to Compliance for assessment and implementation of required restrictive measures (blocking, freezing, refusal, termination, reporting, notification)Escalation record
8Review and clear alertsReview alerts promptly; document identifiers checked, sources used, investigation, and false-positive rationale where clearedAlert disposition
9Block unresolved alertsPrevent onboarding, settlement, wallet setup, transfer, payment, release or completion while a material alert remains unresolved until appropriately resolved or escalatedHold/stop record
10Apply restrictive measuresWhere a sanctions alert is confirmed as a true match, immediately apply legally required restrictive measures (blocking, freezing, rejecting, refusing, restricting). Escalate true matches, prohibited-jurisdiction exposure and unresolved alerts to Compliance without delayRestrictive measure record
11Assess FIU and CBCS obligationsApply required blocking/freezing/rejecting/refusing/terminating/reporting/notification measures and separately assess FIU Curaçao and CBCS reporting or notification obligationsReporting evidence
12Retain screening recordsRetain results, investigation, timing, owner, rationale, restrictive measures, escalation decisions, and reporting or notification records per Bitkaya’s recordkeeping requirementsRetained screening file

Evidence

  • screening report
  • alert disposition
  • false-positive rationale
  • restrictive measure record
  • escalation or reporting evidence
  • sanctions-list coverage and refresh record
  • prohibited-jurisdiction decision

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Expanded lifecycle timing, list coverage, prohibited-jurisdiction treatment and FIU/CBCS decision evidence after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.