Purpose

Assess legal, regulatory, supervisory and operational changes for impact on the Enterprise Compliance Manual and subordinate compliance framework.

Preconditions

  • The Enterprise Compliance Manual is the parent approved framework.
  • The procedure is performed at parent-framework level and does not replace detailed operating procedures in subordinate manuals.
  • Relevant owners, approval authority, evidence locations and affected BCMS objects are identified before execution.

Steps

#ActionDetailsEvidence
1Identify trigger and ownerDetermine the trigger event, affected framework area, and responsible owner.Trigger record or owner assignment.
2Check current BCMS objectReview the current BCMS object, approved manual, artifact, register, or evidence record.Current BCMS object, manual, or artifact reference.
3Determine update scopeDecide whether a parent-framework update is sufficient or whether a detailed subordinate manual, procedure, or control must be created later.Decision rationale and scope determination.
4Record action and decisionDocument the action taken, decision rationale, owner, date, and evidence reference.Action record with date and evidence reference.
5Escalate material gapsEscalate material gaps, overdue actions, regulatory matters, or approval needs to Compliance and management.Escalation record to Compliance and management.
6Update BCMS relationshipsUpdate affected BCMS relationships, review dates, publications, dashboards, or issues.Updated BCMS objects, publications, or dashboards.
7Retain evidenceRetain evidence in the approved framework library or evidence repository.Evidence repository or framework library entry.

Exceptions and Escalation

Exceptions must be documented and approved by Compliance and the appropriate authority. Exceptions must not override legal, regulatory, CBCS, FIU, sanctions, recordkeeping or Board approval requirements.

Records Created

  • Framework action record or issue.
  • Updated BCMS object or publication artifact where applicable.
  • Evidence reference, approval record, escalation record or training record where applicable.

Operational Details from the Manual

Regulatory change impact assessment follows the framework maintenance and version control requirements established in Chapter 5.15: the framework is reviewed at least annually or whenever regulatory, business, or operational changes occur. A version log records all updates, their rationale, approval dates, and related procedures affected.

Key regulatory instruments to monitor for changes include (Chapter 7.2): the Penal Code, NORUT, NOIS, Sanctions Ordinances, NOSVASP, applicable CBCS Procedures and Guidelines, FATF’s 40 Recommendations, and the Global Digital Finance (GDF) codes. Bitkaya’s regulatory supervisor is the Central Bank of Curaçao and Sint Maarten (CBCS).

Where material AML/CFT/CPF changes are made following legal developments, regulator feedback, internal findings, or control enhancements, related subordinate manuals, SOPs, and operational guidance shall be updated in parallel to maintain consistency across the compliance framework (Chapter 7.10).

The change log from the manual records the evolution of regulatory implementation:

  • v1.0 (June 2025): Initial Compliance manual before NOSVASP.
  • v1.1–2.0 (July–September 2025): Implementation of NOSVASP requirements and CBCS guidelines.
  • v2.1 (October 2025): Finalization of NOSVASP requirements and CBCS guidelines; legacy client dossiers reviewed against updated manual.
  • v2.2 (April 2026): Added standalone ABC and Outsourcing chapters; ABC EWRA and Outsourcing Register implemented.
  • v2.3 (April 2026): Cross-manual harmonization following AML/CTF/CPF Manual v2.1; impacted Chapters 7 (AML/CFT/CPF) and 9 (KYC & CDD).

CBCS requires prior approval for critical or essential outsourcing arrangements (Chapter 6.3). New product or significant change proposals must include a business case, legal and compliance review, security assessment, and operational readiness plan, with decisions recorded in the new-product register and a post-launch review within 30 days (Chapter 5.7).

Future Detailed Manuals

This procedure intentionally stays at enterprise-framework level. When detailed manuals are added for AML/CFT/CPF, privacy, BCM, IT and cybersecurity, finance and tax, complaints, market conduct or other domains, those manuals should add their own procedures for domain-specific operating steps.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved Enterprise Compliance Manual version 2.3

History

  • 2026-07-25: Created parent-framework procedure from Bitkaya Compliance Manual version 2.3.
  • 2026-07-25: Corrected procedure frontmatter to use scoped ECM relationships.