Purpose

Maintain complete, secure and retrievable AML/CTF/CPF records for audit, management review and regulatory access.

Scope

This procedure applies to client files, screening records, monitoring alerts, case records, FIU reports, freezing records, escalation records, training records and review evidence.

Steps

#ActionDetailsEvidence
1Identify record typeIdentify the record type and required retention location. Bitkaya stores all records necessary to demonstrate compliance with AML/CFT obligationsRecord inventory
2Retain required recordsRetain KYC/CDD and UBO files (identification documents, UBO declarations, proof of address, onboarding notes), client risk assessments (risk scores, profiling justifications, review history), transaction records (fiat and crypto logs, timestamps, wallet addresses, counterparties), sanctions screening results (matches, resolution outcomes, freezing actions), UTR reports (submitted reports, internal alerts, supporting documentation), monitoring logs (KYT alerts, case reviews, escalation notes), Compliance decisions (approvals, rejections, EDD files, committee minutes), and training/staff records (attendance logs, course content, certifications)Client file
3Ensure record qualityEach record must be complete, dated, attributable, versioned where relevant, and linked to the appropriate client, transaction, wallet, case, report or control activityClient file
4Store in approved archiveStore records in the approved digital compliance archive integrated with the ERP system or designated evidence systemRetention record
5Apply access controlsApply role-based access, access logging, audit trails, and protection against unauthorized alteration, deletion or disclosure. Audit trails preserved for every critical access, update, or deletion attemptAccess and audit-log evidence
6Maintain backupsMaintain regular backups including the monthly off-site backup required by the manual. Retain backup and restoration evidence under applicable technology controlsBackup and restoration evidence
7Retain client/transaction recordsRetain client and transaction records for at least five (5) years from the end of the relationship or the last transaction, whichever is later. Must be accessible for transaction reconstruction and available to CBCS or authorized bodies upon requestRetention-period calculation
8Retain CDD informationRetain CDD information for at least five (5) years after the end of the business relationship and make it available to CBCS or authorized bodies when requiredRetention-period calculation
9Retain reported-transaction recordsWhere a transaction is reported to investigative authorities (FIU, Public Prosecutor, Police), retain records for ten (10) years when instructed by the FIURetention-period calculation
10Ensure retrievabilityPreserve enough information to reconstruct customer profiles and financial activity and produce it to CBCS, FIU Curaçao, or another authorized body without undue delayRetrieval test
11Oversee recordkeeping frameworkCompliance Officer oversees the recordkeeping framework and coordinates at least annual integrity and completeness testing with independent audit or assuranceRemediation record
12Escalate and remediate gapsEscalate and remediate missing, incomplete, inaccessible or improperly protected records and retain closure evidenceRemediation record

Evidence

  • record inventory
  • client file
  • case file
  • screening and monitoring evidence
  • retrieval test
  • remediation record
  • access and audit-log evidence
  • backup and restoration evidence
  • retention-period calculation

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Added record categories, five- and ten-year rules, access logging, monthly off-site backup, retrieval and annual integrity review after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.