Purpose
Maintain complete, secure and retrievable AML/CTF/CPF records for audit, management review and regulatory access.
Scope
This procedure applies to client files, screening records, monitoring alerts, case records, FIU reports, freezing records, escalation records, training records and review evidence.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Identify record type | Identify the record type and required retention location. Bitkaya stores all records necessary to demonstrate compliance with AML/CFT obligations | Record inventory |
| 2 | Retain required records | Retain KYC/CDD and UBO files (identification documents, UBO declarations, proof of address, onboarding notes), client risk assessments (risk scores, profiling justifications, review history), transaction records (fiat and crypto logs, timestamps, wallet addresses, counterparties), sanctions screening results (matches, resolution outcomes, freezing actions), UTR reports (submitted reports, internal alerts, supporting documentation), monitoring logs (KYT alerts, case reviews, escalation notes), Compliance decisions (approvals, rejections, EDD files, committee minutes), and training/staff records (attendance logs, course content, certifications) | Client file |
| 3 | Ensure record quality | Each record must be complete, dated, attributable, versioned where relevant, and linked to the appropriate client, transaction, wallet, case, report or control activity | Client file |
| 4 | Store in approved archive | Store records in the approved digital compliance archive integrated with the ERP system or designated evidence system | Retention record |
| 5 | Apply access controls | Apply role-based access, access logging, audit trails, and protection against unauthorized alteration, deletion or disclosure. Audit trails preserved for every critical access, update, or deletion attempt | Access and audit-log evidence |
| 6 | Maintain backups | Maintain regular backups including the monthly off-site backup required by the manual. Retain backup and restoration evidence under applicable technology controls | Backup and restoration evidence |
| 7 | Retain client/transaction records | Retain client and transaction records for at least five (5) years from the end of the relationship or the last transaction, whichever is later. Must be accessible for transaction reconstruction and available to CBCS or authorized bodies upon request | Retention-period calculation |
| 8 | Retain CDD information | Retain CDD information for at least five (5) years after the end of the business relationship and make it available to CBCS or authorized bodies when required | Retention-period calculation |
| 9 | Retain reported-transaction records | Where a transaction is reported to investigative authorities (FIU, Public Prosecutor, Police), retain records for ten (10) years when instructed by the FIU | Retention-period calculation |
| 10 | Ensure retrievability | Preserve enough information to reconstruct customer profiles and financial activity and produce it to CBCS, FIU Curaçao, or another authorized body without undue delay | Retrieval test |
| 11 | Oversee recordkeeping framework | Compliance Officer oversees the recordkeeping framework and coordinates at least annual integrity and completeness testing with independent audit or assurance | Remediation record |
| 12 | Escalate and remediate gaps | Escalate and remediate missing, incomplete, inaccessible or improperly protected records and retain closure evidence | Remediation record |
Evidence
- record inventory
- client file
- case file
- screening and monitoring evidence
- retrieval test
- remediation record
- access and audit-log evidence
- backup and restoration evidence
- retention-period calculation
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Controls: CTRL-AML-007 Ensure AML Records Are Retained and Retrievable
- Backup controls: PROC-ODOO-002 Execute Monthly Odoo SaaS External Backup, PROC-ODOO-004 Verify Backup Integrity Logging and Evidence, PROC-ODOO-005 Test Odoo Restore and Perform Data Recovery
- Manual coverage: sections 7.1-7.6 and 13.4.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Added record categories, five- and ten-year rules, access logging, monthly off-site backup, retrieval and annual integrity review after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.