Purpose

Identify and manage employee conduct, conflicts and risks to clients, assets, confidential information and access credentials.

Steps

#ActionDetailsEvidence
1Require professional conductRequire honest, fair, client-first and professional behavior in all duties and communications, both inside and outside the company; employees represent Bitkaya in all professional interactions, including with clients, partners, regulators, and the public.Conduct acknowledgment
2Require conflict disclosureRequire prompt disclosure of actual, potential or perceived conflicts to Compliance or HR for proper management; examples include trading digital assets using inside knowledge, having a financial interest in a supplier, vendor, or competitor, and accepting gifts or favors that could influence decisions.Conflict disclosure
3Assess and mitigate each conflictDocument recusal, restriction, approval, monitoring or other mitigation.Conflict assessment
4Protect client and company assetsRequire employees to protect client funds, virtual assets, company property, confidential information and credentials; client money and digital assets must be handled with the highest level of care and never used for company operations or personal benefit.Asset-handling acknowledgment
5Prohibit unauthorized use of assets and dataProhibit unauthorized use, disclosure, transfer, commingling or bypass of access and compliance controls; safeguard sensitive information by following data security protocols, encryption rules, and access controls.Access-control record
6Report loss, theft or breach immediatelyRequire immediate reporting of any loss, theft, or breach involving assets or data.Incident report
7Coordinate incident containment and escalationWith AML, ABC, market conduct, IT or business continuity processes as applicable.Incident escalation record
8Record decisions and closure evidenceRecord decisions, actions and closure evidence.Case closure record

Exceptions and Escalation

Suspected fraud, bribery, market abuse, client-asset misuse, material data loss or deliberate concealment shall be preserved and escalated immediately without waiting for routine review.

Records

  • Conflict disclosures and decisions
  • Recusal, restriction and monitoring evidence
  • Asset, data and access incident records
  • Escalation and remediation evidence

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: continuous and event-driven

History

  • 2026-07-26: Created from sections 2, 5, 7 and 11 of the approved Employee Handbook.