Purpose

Assign, track and evidence mandatory compliance training, role-specific training and employee attestations.

Preconditions

  • The Enterprise Compliance Manual is the parent approved framework.
  • The procedure is performed at parent-framework level and does not replace detailed operating procedures in subordinate manuals.
  • Relevant owners, approval authority, evidence locations and affected BCMS objects are identified before execution.

Steps

#ActionDetailsEvidence
1Identify trigger and ownerDetermine the trigger event, affected framework area, and responsible owner.Trigger record or owner assignment.
2Check current BCMS objectReview the current BCMS object, approved manual, artifact, register, or evidence record.Current BCMS object, manual, or artifact reference.
3Determine update scopeDecide whether a parent-framework update is sufficient or whether a detailed subordinate manual, procedure, or control must be created later.Decision rationale and scope determination.
4Record action and decisionDocument the action taken, decision rationale, owner, date, and evidence reference.Action record with date and evidence reference.
5Escalate material gapsEscalate material gaps, overdue actions, regulatory matters, or approval needs to Compliance and management.Escalation record to Compliance and management.
6Update BCMS relationshipsUpdate affected BCMS relationships, review dates, publications, dashboards, or issues.Updated BCMS objects, publications, or dashboards.
7Retain evidenceRetain evidence in the approved framework library or evidence repository.Evidence repository or framework library entry.

Exceptions and Escalation

Exceptions must be documented and approved by Compliance and the appropriate authority. Exceptions must not override legal, regulatory, CBCS, FIU, sanctions, recordkeeping or Board approval requirements.

Records Created

  • Framework action record or issue.
  • Updated BCMS object or publication artifact where applicable.
  • Evidence reference, approval record, escalation record or training record where applicable.

Operational Details from the Manual

Training is tailored to each role (Chapter 5.14):

  • Directors and executives focus on governance and oversight.
  • Product and technology teams receive risk and cybersecurity training.
  • Operational and client teams are trained on daily controls and incident response.

Cultural health is measured through staff participation in training, reporting of issues, and time taken to close them.

The Training and Awareness Framework (Chapter 21) defines:

  • HR: Coordinates all training programs, tracks completion rates, and maintains employee learning records.
  • Compliance Officer: Ensures all training aligns with regulatory requirements and monitors overall program effectiveness.
  • Department Heads: Identify role-specific needs, recommend additional learning, and ensure participation in refresher programs.
  • Employees: Complete assigned training on time, apply knowledge in daily work, and report any misconduct or suspicious activity.

Training programs include:

  1. Induction Training: Bitkaya’s structure, products, and VASP license obligations; AML/CFT fundamentals, sanctions compliance, ABC and whistleblower policies; cybersecurity, data protection, and safe handling of client information.
  2. Ongoing Training: Regular sessions reinforce updates on laws, internal policies, emerging risks, and typologies.
  3. Specialized Training: Compliance & Risk Teams (AML/CFT, ABC, Travel Rule, reporting protocols); IT & Security Staff (access control, threat mitigation, incident response); Client-Facing Roles (KYC, client communication, and ethical standards).
  4. Awareness Campaigns: Bulletins on fraud trends, phishing, and cybersecurity best practices; phishing simulations and “crypto hygiene” initiatives.

Competency Assessment (Chapter 21.4): Initial Evaluation during onboarding; Periodic Review via audits, reviews, and incident response; Remediation triggers refresher courses, coaching, or reassignment. Completion rates and assessment results are reviewed regularly by HR and Compliance.

Continuous Improvement (Chapter 21.5): Training materials updated regularly; employee feedback and audit results used to refine future sessions; benchmarked annually against CBCS, FATF, and industry best practices; annual program review approved by the Board.

Staff receive AML/CTF/CPF training appropriate to their role, including training on sanctions screening, transaction monitoring, escalation procedures, internal case classification, external UTR reporting obligations, and documentation standards (Chapter 7.7).

All employees receive annual AML and KYC training. Staff working in onboarding, risk management, or compliance also complete specialized modules, including blockchain forensics and typology recognition (Chapter 9.11).

ABC training is provided on a risk-based basis; relevant personnel must understand their responsibilities, applicable red flags, escalation obligations, and conduct expectations (Chapter 8.6).

All relevant employees must complete mandatory training on anti-money laundering, counter-terrorist financing, and safeguarding responsibilities. Training is refreshed annually and tailored to specific roles. Records of completion are maintained and reviewed by Compliance (Chapter 10.16).

Mandatory cybersecurity and wallet security training for all staff; specialized modules for technical teams on password management, YubiKeys, and custody security; client education on MFA setup and fraud prevention (Chapter 15.10).

All staff must complete annual cybersecurity and wallet security training. Regular phishing simulations, visual reminders, and awareness initiatives promote continuous vigilance and “crypto hygiene” (Chapter 15.10).

Future Detailed Manuals

This procedure intentionally stays at enterprise-framework level. When detailed manuals are added for AML/CFT/CPF, privacy, BCM, IT and cybersecurity, finance and tax, complaints, market conduct or other domains, those manuals should add their own procedures for domain-specific operating steps.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved Enterprise Compliance Manual version 2.3

History

  • 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
  • 2026-07-25: Created parent-framework procedure from Bitkaya Compliance Manual version 2.3.
  • 2026-07-25: Corrected procedure frontmatter to use scoped ECM relationships.