Purpose
Review, approve, version, publish and archive compliance manuals and related BCMS objects in a controlled manner.
Preconditions
- The Enterprise Compliance Manual is the parent approved framework.
- The procedure is performed at parent-framework level and does not replace detailed operating procedures in subordinate manuals.
- Relevant owners, approval authority, evidence locations and affected BCMS objects are identified before execution.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Identify trigger and owner | Determine the trigger event, affected framework area, and responsible owner. | Trigger record or owner assignment. |
| 2 | Check current BCMS object | Review the current BCMS object, approved manual, artifact, register, or evidence record. | Current BCMS object, manual, or artifact reference. |
| 3 | Determine update scope | Decide whether a parent-framework update is sufficient or whether a detailed subordinate manual, procedure, or control must be created later. | Decision rationale and scope determination. |
| 4 | Record action and decision | Document the action taken, decision rationale, owner, date, and evidence reference. | Action record with date and evidence reference. |
| 5 | Escalate material gaps | Escalate material gaps, overdue actions, regulatory matters, or approval needs to Compliance and management. | Escalation record to Compliance and management. |
| 6 | Update BCMS relationships | Update affected BCMS relationships, review dates, publications, dashboards, or issues. | Updated BCMS objects, publications, or dashboards. |
| 7 | Retain evidence | Retain evidence in the approved framework library or evidence repository. | Evidence repository or framework library entry. |
Exceptions and Escalation
Exceptions must be documented and approved by Compliance and the appropriate authority. Exceptions must not override legal, regulatory, CBCS, FIU, sanctions, recordkeeping or Board approval requirements.
Records Created
- Framework action record or issue.
- Updated BCMS object or publication artifact where applicable.
- Evidence reference, approval record, escalation record or training record where applicable.
Operational Details from the Manual
The Enterprise Compliance Manual v2.3 was approved by the Board with status FINAL and effective date 21 April 2026. The manual is version-controlled with a complete change log tracking all updates from v1.0 through v2.3.
The manual establishes the governance framework for AML/CFT/CPF controls, data protection, client asset safeguarding, corporate governance, risk management, anti-bribery and cybersecurity (Chapter 1). It serves as the parent policy that governs the creation, implementation, and monitoring of all subordinate compliance manuals and frameworks.
All policies, SOPs, and risk assessments are maintained in a version-controlled library (Chapter 7.10). Reviews occur annually or upon significant changes. The framework is reviewed at least annually or whenever regulatory, business, or operational changes occur, and a version log records all updates, their rationale, approval dates, and related procedures affected (Chapter 5.15).
Subordinate manuals referenced in “Further Details” sections include:
- Governance, Ethics & ESG Manual (Chapter 4.6)
- Risk Management Framework Manual (Chapter 5.16)
- Outsourcing Risk Management Manual (Chapter 6.6)
- AML/CFT/CPF Compliance Manual (Chapter 7.11)
- Anti-Bribery & Corruption (ABC) Manual (Chapter 8.7)
- KYC & CDD Manual (Chapter 9.13)
- Client Asset Protection & Safeguarding Manual (Chapter 10.19)
- Data Protection & Privacy Manual (Chapter 11.13)
- Business Continuity Management Manual (Chapter 12.15)
- Market Conduct & Trading Compliance Manual (Chapter 13.12)
- Client Complaints Handling Manual (Chapter 14.14)
- IT & Cybersecurity Manual (Chapter 15.12)
- COTS Software Acceptance & Testing Manual (Chapter 16.9)
- Finance & Tax Compliance Manual (Chapter 17.7)
- Employee Handbook (Chapter 18.9)
- Internal Controls & Audit Manual (Chapter 19.8)
- Regulatory Reporting & Communication Manual (Chapter 20.8)
- Training & Awareness Manual (Chapter 21.6)
Future Detailed Manuals
This procedure intentionally stays at enterprise-framework level. When detailed manuals are added for AML/CFT/CPF, privacy, BCM, IT and cybersecurity, finance and tax, complaints, market conduct or other domains, those manuals should add their own procedures for domain-specific operating steps.
Relationships
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Controls: CTRL-ECM-003 Ensure Compliance Manuals Are Approved and Version Controlled
- Systems: SYS-ECM-001 Compliance Framework Library
- Publication: PUB-ECM-001 Enterprise Compliance Manual
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved Enterprise Compliance Manual version 2.3
History
- 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
- 2026-07-25: Created parent-framework procedure from Bitkaya Compliance Manual version 2.3.
- 2026-07-25: Corrected procedure frontmatter to use scoped ECM relationships.