Purpose

Maintain accountable internal-control governance and objective separation between operation, second-line testing and independent assurance.

Steps

  1. Define Board, committee, management, first-line, Risk and Compliance, MLRO and internal-audit responsibilities per the manual’s section 2.1:
    • The Board of Directors holds ultimate responsibility for oversight of the internal control framework, ensuring it is effective, adequately resourced, and aligned with regulatory obligations.
    • The Head of Risk and Compliance (2nd Line of Defense) designs, tests, and monitors the risk and control framework, providing independent oversight of business operations and escalating issues to the Board and committees.
    • The Money Laundering Reporting Officer (MLRO) is accountable for AML/CFT/CPF compliance, including suspicious activity reporting, regulatory engagement, and ensuring that financial crime controls remain effective and up to date.
    • Internal Audit (3rd Line of Defense) provides independent assurance on the adequacy and effectiveness of internal controls, risk management, and governance, reporting directly to the Audit and Risk Committee.
    • All Staff are required to adhere to policies and control procedures, actively report breaches or weaknesses, and contribute to a culture of compliance and operational discipline.
  2. Assign accountable owners to each material control and assurance activity.
  3. Document reporting lines, delegated authority, access rights and escalation channels.
  4. Confirm that testers do not independently assure controls they operate.
  5. Use an independent third party where internal capacity or conflicts prevent objective assurance. As a small VASP, the Head of Risk and Compliance may also serve as Audit Coordinator, reporting results directly to the Board or Audit and Risk Committee.
  6. Align assurance priorities to the RMF risk assessment and regulatory obligations, including CBCS supervisory expectations, FATF risk-based guidance, and the National Ordinance on the Supervision of Virtual Asset Service Providers (NOSVASP) requirements.
  7. Review resources, competence, access and independence at least annually and upon material regulatory, organizational, product, incident, control or assurance change.
  8. Obtain Board approval of the framework and material changes. The Board or Audit and Risk Committee assesses whether proportionality justifications remain appropriate annually.

Exceptions and Escalation

Any impairment of independence, evidence access or authority shall be disclosed before work begins and resolved or documented in the assurance conclusion.

Records

  • Governance and responsibility matrix
  • Control and assurance ownership
  • Independence and conflict assessments
  • Resource and competence review
  • Board approval and decisions

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual and after material change

History

  • 2026-07-26: Created from sections 1 and 2 of the approved ICA Manual.