Purpose
Identify and manage employee conduct, conflicts and risks to clients, assets, confidential information and access credentials.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Require professional conduct | Require honest, fair, client-first and professional behavior in all duties and communications, both inside and outside the company; employees represent Bitkaya in all professional interactions, including with clients, partners, regulators, and the public. | Conduct acknowledgment |
| 2 | Require conflict disclosure | Require prompt disclosure of actual, potential or perceived conflicts to Compliance or HR for proper management; examples include trading digital assets using inside knowledge, having a financial interest in a supplier, vendor, or competitor, and accepting gifts or favors that could influence decisions. | Conflict disclosure |
| 3 | Assess and mitigate each conflict | Document recusal, restriction, approval, monitoring or other mitigation. | Conflict assessment |
| 4 | Protect client and company assets | Require employees to protect client funds, virtual assets, company property, confidential information and credentials; client money and digital assets must be handled with the highest level of care and never used for company operations or personal benefit. | Asset-handling acknowledgment |
| 5 | Prohibit unauthorized use of assets and data | Prohibit unauthorized use, disclosure, transfer, commingling or bypass of access and compliance controls; safeguard sensitive information by following data security protocols, encryption rules, and access controls. | Access-control record |
| 6 | Report loss, theft or breach immediately | Require immediate reporting of any loss, theft, or breach involving assets or data. | Incident report |
| 7 | Coordinate incident containment and escalation | With AML, ABC, market conduct, IT or business continuity processes as applicable. | Incident escalation record |
| 8 | Record decisions and closure evidence | Record decisions, actions and closure evidence. | Case closure record |
Exceptions and Escalation
Suspected fraud, bribery, market abuse, client-asset misuse, material data loss or deliberate concealment shall be preserved and escalated immediately without waiting for routine review.
Records
- Conflict disclosures and decisions
- Recusal, restriction and monitoring evidence
- Asset, data and access incident records
- Escalation and remediation evidence
Relationships
- Policy: POL-EMP-001 Employee Handbook
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-EMP-003 Ensure Employee Conduct Conflicts Assets and Data Are Controlled
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: continuous and event-driven
History
- 2026-07-26: Created from sections 2, 5, 7 and 11 of the approved Employee Handbook.