Purpose

Maintain the AML/CTF/CPF manual, proportionality rationale and related documentation so the framework stays current and scalable.

Scope

This procedure applies to annual policy review, regulator feedback, control gaps, manual updates, proportionality decisions and material business or risk changes.

Steps

#ActionDetailsEvidence
1Review policies annuallyReview core AML policies, the EWRA/SARA and related procedures and SOPs at least annuallyManual review record
2Initiate trigger-based reviewInitiate prompt review after legal/regulatory change, material business-model/product/service/client/jurisdiction/technology change, regulator or FIU feedback, audit finding, incident, policy gap or control weaknessManual review record
3Assess regulatory alignmentAssess alignment with applicable Curaçao law, CBCS guidance, FATF standards, sanctions obligations, Bitkaya operations and current risk appetite. Use Global Digital Finance principles as a non-binding benchmark where relevantSource comparison record
4Update subordinate documentsWhere required, update affected subordinate manuals, procedures, controls, training, system configurations and BCMS relationships in parallel to maintain consistency across the compliance frameworkChange log
5Review proportionalityReview proportionality across governance, staffing, role consolidation, CDD/EDD, technology, outsourcing, alert cadence, training and independent review. Proportionality allows Bitkaya to maintain an effective, risk-based AML/CFT framework aligned with CBCS expectations while ensuring efficiency, accountability, and scalabilityProportionality rationale
6Confirm risk-based proportionalityConfirm proportionality is based on risk rather than size alone and does not reduce mandatory identification, beneficial-ownership, sanctions, reporting, recordkeeping or Board-accountability obligationsProportionality rationale
7Apply guiding principlesApply the five proportionality guiding principles: (1) Risk-Based Application — controls applied based on ML/TF risk level, not org size alone; higher-risk services receive enhanced monitoring/EDD. (2) Scalability and Efficiency — processes, documentation and control structures designed to scale; core tools (KYC, KYT, sanctions) centralized and automated. (3) Practical Governance — governance roles may be consolidated (e.g. Compliance Officer also serves as MLRO) provided checks/balances and escalation mechanisms are maintained. (4) Resource Optimization — use of external providers for independent audit, transaction monitoring and sanctions screening to meet CBCS standards without internal duplication. (5) Continuous Alignment — reviewed annually or upon material business change, regulatory update, or audit findingProportionality rationale
8Review proportionality applicationReview proportionality application across AML/CFT domains: EWRA (simplified quantitative scoring, data-driven tools, annual updates unless significant change); CDD/EDD (SDD only for documented low-risk, EDD only where objective indicators warrant, digital onboarding with automated ID and sanctions verification); Transaction Monitoring (outsourced blockchain analytics and rule-based KYT, risk-based alert review: daily for high-risk, weekly for low/medium, UTR centralized under MLRO); Training (all employees receive onboarding and annual refresher, specialized training only for direct AML/CFT impact roles, external e-learning and CBCS guidance materials); Independent Review (annually by independent consultant or internal auditor, scope and depth scaled to volume and complexity)Proportionality rationale
9Document compensating controlsWhere roles are combined, document and obtain Board approval for compensating controls such as independent assurance, segregation of approval, CEO oversight or enhanced reportingCompensating-control assessment
10Reassess resource capacityReassess resource capacity, client and transaction volumes, product scope and jurisdictional exposure annually. Scale staffing, systems, testing and three-lines-of-defence arrangements as Bitkaya grows. Proportionality transitions into a fully structured three-lines-of-defense model with expanding dedicated compliance and audit staffingResource-capacity assessment
11Confirm accountabilityConfirm Compliance remains accountable for the AML framework, reports directly to the CEO under the approved model, and remains operationally separate from independent audit or testing. Board retains full accountability for the AML/CFT frameworkApproval record
12Draft and review updatesDraft updates, circulate to Legal, Risk, Operations and other relevant functions for internal review, obtain MLRO sign-off to ensure regulatory alignment and consistency, and obtain Board or committee approval for high-level policiesApproval record
13Communicate changesCommunicate approved changes to affected staff and arrange targeted training where required. Updated policies shared with impacted staffCommunication evidence
14Version and archiveVersion and archive approved and superseded documents in an access-controlled, backed-up master compliance library. MLRO is responsible for maintaining the master compliance policy library. Outdated/superseded versions retained to support audits and regulatory requestsArchived version
15Retain review evidenceRetain the review record, source comparison, change log, proportionality rationale, approvals, communication and version-control evidenceManual review record
16Benchmark and integrate lessonsPolicies informed by findings from internal audits and independent reviews, regulatory inspections and CBCS guidance updates, and lessons learned from STRs, alerts, or incident investigations. Continuously benchmark against FATF standards, CBCS Provisions, and Global Digital Finance principles. Evaluate proportionality adequacy through annual review of risk exposure and resource capacity, feedback from internal audits, regulatory inspections, FIU interactions, and integration of lessons learnedEffectiveness review and improvement record

Evidence

  • manual review record
  • change log
  • approval record
  • proportionality rationale
  • communication evidence
  • archived version
  • source and subordinate-document consistency review
  • compensating-control and resource-capacity assessment

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Added review frequencies, parallel subordinate updates, governance workflow, compensating controls and scalability assessment after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.