Purpose

Prepare, review, escalate and retain compliance reporting for management, the Board, regulators and internal stakeholders.

Preconditions

  • The Enterprise Compliance Manual is the parent approved framework.
  • The procedure is performed at parent-framework level and does not replace detailed operating procedures in subordinate manuals.
  • Relevant owners, approval authority, evidence locations and affected BCMS objects are identified before execution.

Steps

#ActionDetailsEvidence
1Identify trigger and ownerDetermine the trigger event, affected framework area, and responsible owner.Trigger record or owner assignment.
2Check current BCMS objectReview the current BCMS object, approved manual, artifact, register, or evidence record.Current BCMS object, manual, or artifact reference.
3Determine update scopeDecide whether a parent-framework update is sufficient or whether a detailed subordinate manual, procedure, or control must be created later.Decision rationale and scope determination.
4Record action and decisionDocument the action taken, decision rationale, owner, date, and evidence reference.Action record with date and evidence reference.
5Escalate material gapsEscalate material gaps, overdue actions, regulatory matters, or approval needs to Compliance and management.Escalation record to Compliance and management.
6Update BCMS relationshipsUpdate affected BCMS relationships, review dates, publications, dashboards, or issues.Updated BCMS objects, publications, or dashboards.
7Retain evidenceRetain evidence in the approved framework library or evidence repository.Evidence repository or framework library entry.

Exceptions and Escalation

Exceptions must be documented and approved by Compliance and the appropriate authority. Exceptions must not override legal, regulatory, CBCS, FIU, sanctions, recordkeeping or Board approval requirements.

Records Created

  • Framework action record or issue.
  • Updated BCMS object or publication artifact where applicable.
  • Evidence reference, approval record, escalation record or training record where applicable.

Operational Details from the Manual

Risk information is reported at three levels (Chapter 5.12):

  • Weekly to Executive Management: Key alerts, sanctions results, custody breaks, cybersecurity incidents, complaints, and exceptions.
  • Monthly to the Risk and Compliance Committee: Risk heatmaps, breaches, vendor metrics, new product updates, outstanding issues, and staff training.
  • Quarterly to the Board: Overall trends, progress against appetite limits, results of stress tests, regulatory feedback, and major incidents.

Key regulatory authorities and reporting requirements (Chapter 20):

  • CBCS: Quarterly AML/CFT and governance reports; annual audited financial statements and management letters; notifications of material changes in ownership, management, or operations; incident and breach reports within specified timelines.
  • FIU Curaçao: Unusual Transaction Reports (UTRs) submitted via the FIU online portal; immediate internal escalation of suspicious activity to the Compliance Officer. All staff are prohibited from tipping off clients or external parties.
  • Tax Authorities: Annual CIT return; monthly or quarterly TOT returns; monthly payroll and social security filings.

The Compliance Officer acts as primary contact for CBCS and FIU. The Finance Department manages tax filings, financial records, audits, and submissions. The Management Board provides strategic oversight and approves all regulatory submissions (Chapter 20.3).

All regulatory correspondence, reports, and responses must be securely archived for at least 5 years and be retrievable upon request (Chapter 20.4). Any urgent or sensitive request (≤72 hours response time) must be escalated to the Compliance Officer immediately.

Incident reporting requirements (Chapter 5.8): Incidents are classified when detected, with an initial report within 24 hours and a full root-cause analysis within five business days. Regulators are notified if required. Each issue has an assigned owner, action plan, and due date for resolution.

Internal escalation: All reporting breaches or material control failures must be reported to senior management within 24 hours. The Compliance Officer promptly informs CBCS, FIU, or Tax Authorities if a reportable incident occurs, including remedial actions taken (Chapter 20.7).

Future Detailed Manuals

This procedure intentionally stays at enterprise-framework level. When detailed manuals are added for AML/CFT/CPF, privacy, BCM, IT and cybersecurity, finance and tax, complaints, market conduct or other domains, those manuals should add their own procedures for domain-specific operating steps.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved Enterprise Compliance Manual version 2.3

History

  • 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
  • 2026-07-25: Created parent-framework procedure from Bitkaya Compliance Manual version 2.3.
  • 2026-07-25: Corrected procedure frontmatter to use scoped ECM relationships.