Purpose
Keep the inventory of compliance manuals, BCMS objects, owners, approval status, review dates and evidence locations current.
Preconditions
- The Enterprise Compliance Manual is the parent approved framework.
- The procedure is performed at parent-framework level and does not replace detailed operating procedures in subordinate manuals.
- Relevant owners, approval authority, evidence locations and affected BCMS objects are identified before execution.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Identify trigger and owner | Determine the trigger event, affected framework area, and responsible owner. | Trigger record or owner assignment. |
| 2 | Check current BCMS object | Review the current BCMS object, approved manual, artifact, register, or evidence record. | Current BCMS object, manual, or artifact reference. |
| 3 | Determine update scope | Decide whether a parent-framework update is sufficient or whether a detailed subordinate manual, procedure, or control must be created later. | Decision rationale and scope determination. |
| 4 | Record action and decision | Document the action taken, decision rationale, owner, date, and evidence reference. | Action record with date and evidence reference. |
| 5 | Escalate material gaps | Escalate material gaps, overdue actions, regulatory matters, or approval needs to Compliance and management. | Escalation record to Compliance and management. |
| 6 | Update BCMS relationships | Update affected BCMS relationships, review dates, publications, dashboards, or issues. | Updated BCMS objects, publications, or dashboards. |
| 7 | Retain evidence | Retain evidence in the approved framework library or evidence repository. | Evidence repository or framework library entry. |
Operational Details from the Manual
The Enterprise Compliance Manual (v2.3) is the parent policy that governs the creation, implementation, and monitoring of all subordinate compliance manuals and frameworks (Chapter 1). The inventory must cover the full set of 21 chapters:
- Chapter 1: About this Manual — governance framework purpose and scope.
- Chapter 2: Business Overview — services (Principal Brokerage, Agency Exchange, Digital Asset Consulting), group structure, organizational structure, compliance structure.
- Chapter 3: Proportionality and Scalability — consolidation of functions, organizational standards, scalability.
- Chapter 4: Governance, Ethics & ESG — ESG governance, environmental responsibility, social responsibility, governance practices.
- Chapter 5: Risk Management Framework — governance and roles, risk appetite, risk assessment, controls and monitoring, stress testing, new product risk, incidents, third-party risk, BCM/DR, data and records management, reporting, assurance, training, policy maintenance.
- Chapter 6: Outsourcing Risk Management — classification and approval, core controls, proportionality.
- Chapter 7: AML/CFT/CPF — policy statement, scope and regulatory framework, RBA, CDD, FIU reporting, Travel Rule, recordkeeping, training, technology and controls, independent testing, policy management.
- Chapter 8: Anti-Bribery & Corruption — purpose, policy statement, governance, risk-based approach, core control areas, training and escalation.
- Chapter 9: KYC & CDD — KYC/KYT/KYV, client onboarding, sanctions screening, risk profiling, CDD levels, transaction monitoring, ongoing monitoring cadence, suspicious activity reporting, record-keeping, training, governance and oversight.
- Chapter 10: Client Asset Protection & Safeguarding — key definitions, segregation, handling client money and virtual assets, reconciliation, client reporting, third-party custodians, compliance and audit, client agreements, governance, risk management, cybersecurity, withdrawals, insolvency protection, training, breach management, policy review.
- Chapter 11: Data Protection & Privacy — principles, roles, data subject rights, legal bases, special categories, data transfers, security, FATF-specific handling, third-party processing, oversight, sanctions and liabilities.
- Chapter 12: Business Continuity Management — BCM policy statement, objectives, context, governance, BIA, risk assessment, continuity strategies, sub-plans, incident response plan, training, testing, maintenance, documentation.
- Chapter 13: Market Conduct and Trading — core principles (integrity, transparency, compliance, accountability, client-centricity, innovation), prohibited practices, trading conduct, communication and promotion, client asset protection, complaint handling, monitoring and enforcement, regulatory compliance, GDF code alignment, risk management and conflicts of interest.
- Chapter 14: Client Complaints Handling — definitions, governance, complaints function, submission channels, acknowledgment, register and recordkeeping, investigation, resolution, reporting and follow-up, information to clients, escalation, continuous improvement.
- Chapter 15: IT & Cybersecurity — governance and oversight, information security management, IT and cyber risk management, software testing and QA, IT service management, safe and sound electronic banking, BCM and DR, IT framework and integration, training and awareness, continuous improvement.
- Chapter 16: COTS Software Acceptance & Testing — governance and responsibilities, COTS acceptance process, testing requirements, ongoing testing and maintenance, training and competence, continuity and outsourcing, review cycle.
- Chapter 17: Finance & Tax Compliance — legal and corporate governance framework, taxation framework (CIT, TOT, payroll and social security, WHT), record-keeping and reporting, interaction with authorities, compliance checklist.
- Chapter 18: Employee Handbook — employee responsibilities, consequences of non-compliance, commitment from leadership, ABC, whistleblower policy, code of ethics, conclusion.
- Chapter 19: Internal Controls & Audit — governance and accountability, core internal control domains (financial crime compliance, custody and asset protection, IT and cybersecurity, operations and client protection, third-party and VASP oversight), audit framework (internal audit, second line testing, external and regulatory audits, financial statement audit), reporting and escalation, training and culture, document management.
- Chapter 20: Regulatory Reporting & Communication — key regulatory authorities (CBCS, FIU Curaçao, Tax Authorities), internal roles and responsibilities, communication framework, reporting calendar, training and awareness, breach management and regulator interaction.
- Chapter 21: Training and Awareness — roles and responsibilities, training programs (induction, ongoing, specialized, awareness campaigns), competency assessment, continuous improvement.
Each manual in the inventory must record: title, version, approval status, approval date, owner, review cadence, evidence location, and relationship to subordinate manuals. The manual change log tracks all version updates from 1.0 (June 2025) through 2.3 (April 2026), including the addition of ABC and Outsourcing chapters (v2.2) and cross-manual harmonization (v2.3). Records must be securely retained for at least five years and up to ten years where required by law. All evidence is maintained in a structured library to demonstrate compliance at any time (Chapter 5.11, 5.13).
Exceptions and Escalation
Exceptions must be documented and approved by Compliance and the appropriate authority. Exceptions must not override legal, regulatory, CBCS, FIU, sanctions, recordkeeping or Board approval requirements.
Records Created
- Framework action record or issue.
- Updated BCMS object or publication artifact where applicable.
- Evidence reference, approval record, escalation record or training record where applicable.
Future Detailed Manuals
This procedure intentionally stays at enterprise-framework level. When detailed manuals are added for AML/CFT/CPF, privacy, BCM, IT and cybersecurity, finance and tax, complaints, market conduct or other domains, those manuals should add their own procedures for domain-specific operating steps.
Relationships
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Controls: CTRL-ECM-001 Ensure Compliance Framework Inventory Is Current
- Systems: SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository
- Publication: PUB-ECM-001 Enterprise Compliance Manual
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved Enterprise Compliance Manual version 2.3
History
- 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
- 2026-07-25: Created parent-framework procedure from Bitkaya Compliance Manual version 2.3.
- 2026-07-25: Corrected procedure frontmatter to use scoped ECM relationships.