Purpose

Plan compliance reviews, record findings, track remediation and preserve evidence for audit and regulatory review.

Preconditions

  • The Enterprise Compliance Manual is the parent approved framework.
  • The procedure is performed at parent-framework level and does not replace detailed operating procedures in subordinate manuals.
  • Relevant owners, approval authority, evidence locations and affected BCMS objects are identified before execution.

Steps

#ActionDetailsEvidence
1Identify trigger and ownerDetermine the trigger event, affected framework area, and responsible owner.Trigger record or owner assignment.
2Check current BCMS objectReview the current BCMS object, approved manual, artifact, register, or evidence record.Current BCMS object, manual, or artifact reference.
3Determine update scopeDecide whether a parent-framework update is sufficient or whether a detailed subordinate manual, procedure, or control must be created later.Decision rationale and scope determination.
4Record action and decisionDocument the action taken, decision rationale, owner, date, and evidence reference.Action record with date and evidence reference.
5Escalate material gapsEscalate material gaps, overdue actions, regulatory matters, or approval needs to Compliance and management.Escalation record to Compliance and management.
6Update BCMS relationshipsUpdate affected BCMS relationships, review dates, publications, dashboards, or issues.Updated BCMS objects, publications, or dashboards.
7Retain evidenceRetain evidence in the approved framework library or evidence repository.Evidence repository or framework library entry.

Exceptions and Escalation

Exceptions must be documented and approved by Compliance and the appropriate authority. Exceptions must not override legal, regulatory, CBCS, FIU, sanctions, recordkeeping or Board approval requirements.

Records Created

  • Framework action record or issue.
  • Updated BCMS object or publication artifact where applicable.
  • Evidence reference, approval record, escalation record or training record where applicable.

Operational Details from the Manual

Assurance and review follows a multi-layered approach (Chapter 5.13):

  • Second-line testing: The Risk and Compliance teams perform quarterly reviews of control effectiveness and follow up on remediation actions.
  • Independent audit: An internal or external audit team performs an annual review of the Risk Management and Compliance frameworks.
  • Regulatory readiness: All evidence — policies, registers, logs, and reports — is maintained in a structured library to demonstrate compliance at any time.

The Audit Framework (Chapter 19.4) includes:

  • Internal Audit: Conducts annual, risk-based audits covering AML/CFT compliance, ABC, custody operations, IT and cybersecurity, BCM, and governance. Reports findings directly to the Audit & Risk Committee and the Board.
  • Second Line Testing: Quarterly compliance reviews and control testing by the Risk & Compliance function. Tracks remediation actions and verifies completion of corrective measures.
  • External and Regulatory Audits: Annual AML/CFT audit by an independent external reviewer; evidence libraries maintained for regulatory readiness; full cooperation with CBCS and other supervisory authorities.
  • Financial Statement Audit: Annual external audit under IFRS or GAAP standards; focus areas include custody asset valuation, safeguarding, and revenue recognition.

Reporting & Escalation (Chapter 19.5):

  • Weekly Operations Pack: Key control metrics and exceptions.
  • Monthly Risk & Compliance Committee (RCC): Thematic findings and trend analysis.
  • Quarterly Board Reports: Summary of risk trends, audit outcomes, and control improvements.
  • Immediate Escalation: Material breaches or systemic risks reported without delay to senior management and regulators when required.

Incident management (Chapter 5.8):

  • Incidents: Classified when detected, with an initial report within 24 hours and a full root-cause analysis within five business days. Regulators are notified if required.
  • Issues: Each issue has an assigned owner, action plan, and due date for resolution.
  • Complaints: Logged and monitored under the company’s complaint-handling policy. Trends are analyzed as part of the regular risk reporting cycle.

IT incident response protocol (Chapter 19.3.3): 1-hour triage, 24-hour reporting, 5-day root cause analysis.

Training & Culture (Chapter 19.6): Mandatory onboarding and annual refresher training for all staff; specialized training for high-risk functions (custody, AML, IT); culture metrics include “speak-up” participation rates, phishing test results, and remediation timeliness.

Document Management (Chapter 19.7): The policy is reviewed annually or upon material changes; a version-controlled log records all updates, approvals, and effective dates.

Future Detailed Manuals

This procedure intentionally stays at enterprise-framework level. When detailed manuals are added for AML/CFT/CPF, privacy, BCM, IT and cybersecurity, finance and tax, complaints, market conduct or other domains, those manuals should add their own procedures for domain-specific operating steps.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved Enterprise Compliance Manual version 2.3

History

  • 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
  • 2026-07-25: Created parent-framework procedure from Bitkaya Compliance Manual version 2.3.
  • 2026-07-25: Corrected procedure frontmatter to use scoped ECM relationships.