Purpose

Prevent release of inaccurate, misleading, unbalanced, unauthorized or legally restricted external communications.

Steps

#ActionDetailsEvidence
1Submit final draft and supporting materialsSubmit the final draft, intended channel, audience, jurisdiction, release date, claims substantiation and disclosure rationaleApproval package and claims substantiation
2Confirm content quality and suitabilityConfirm factual accuracy, readability, balance, fee transparency, limitations, target-audience suitability and consistency with actual operating capabilitySpecialist and Compliance review
3Obtain specialist reviewObtain specialist review for AML, sanctions, safeguarding, privacy, complaints, legal, advice, white-paper or regulatory-status contentSpecialist and Compliance review
4Verify licensing and regulatory claimsVerify that licensing, authorization, registration and supervision claims reflect the current confirmed statusSpecialist and Compliance review
5Obtain Compliance and management approvalObtain Compliance approval and required Senior Management or other approval before releaseApproval authority and decision
6Assign version and publishAssign a version, owner, effective date and next review date and publish only the approved versionApproved and released versions
7Verify released communicationVerify the released communication against the approved version and record channel and publication evidencePublication, correction and withdrawal evidence
8Retain recordsRetain the draft, evidence, comments, approvals, final version, release evidence and subsequent correction or withdrawal historyPublication, correction and withdrawal evidence

Compliance Review Triggers (Section 7 of the Approved Manual)

No external communication relating to products, services, onboarding, risk disclosures, restrictions, or operational capabilities may be published without appropriate internal review. Compliance review is required where content touches on:

  • onboarding and due diligence expectations;
  • client acceptance or approval language;
  • sanctions, legal, or compliance restrictions;
  • safeguarding or asset access language;
  • complaints or escalation channels;
  • regulatory status or reporting obligations; or
  • representations about the certainty, speed, or permissibility of transactions or withdrawals.

Recordkeeping Requirement

Final versions must be retained in accordance with Bitkaya’s recordkeeping requirements. The retention package includes the draft, evidence, comments, approvals, final version, release evidence and subsequent correction or withdrawal history.

Proportionality in Approval

For a small VASP such as Bitkaya, communication approval may rest with a single Compliance Officer and one member of management. Internal approval workflows are scaled to operational size; Compliance and Senior Management jointly approve key public communications. For low-risk products and audiences, streamlined reviews apply, while communications about higher-risk or innovative virtual asset services undergo enhanced compliance scrutiny.

Exceptions and Escalation

No external communication within scope may be released without the required approval. Unresolved factual, licensing, jurisdictional, confidentiality or disclosure concerns block release.

Records

  • Approval package and claims substantiation
  • Specialist and Compliance review
  • Approval authority and decision
  • Approved and released versions
  • Publication, correction and withdrawal evidence

Relationships

History

  • 2026-07-26: Created from sections 5-7 and 10-11 of the approved COMM Manual.