Purpose

Ensure material VASP risks and obligations are covered by owned, documented and evidenced controls without duplicating the detailed operating manuals.

Steps

  1. Reconcile the control inventory to current risk assessments, requirements, processes and material systems.
  2. Confirm coverage of the five core internal control domains per the manual’s section 3:
    • Financial Crime Compliance: KYC, KYV, KYT, sanctions screening (onboarding, periodic review, list-refresh, transaction/wallet-level), transaction monitoring, internal case escalation, external reporting to FIU Curaçao via UTR process, and recordkeeping of CDD files, screening results, internal classifications, escalation records, UTR records and supporting documentation.
    • Custody and Asset Protection: segregation of client vs. corporate funds, multi-signature and HSM key management, daily reconciliations between on-chain balances and internal ledgers, insurance coverage and operational runbooks for loss events.
    • IT and Cybersecurity Controls: access management (least privilege, MFA, periodic reviews), data security (encryption in transit and at rest, secure data location), incident response (triage within 1h, initial report in 24h, RCA in 5d), business continuity (RTO/RPO targets per BCM §1.4).
    • Operations and Client Protection: client complaints handled per defined SLAs with trends monitored as KRIs, fee transparency through New Product Approval process, service level monitoring (uptime, custody breaks, cyber tickets tracked in weekly Ops Pack).
    • Third-Party and VASP Oversight: risk-based due diligence on third parties, VASPs and counterparties; KYV measures on a documented risk basis (licence/supervisor information, registry evidence, incorporation documents, ownership and control information, sanctions screening results, independent source checks); simplified treatment not applied automatically solely because a counterparty is regulated or in a particular jurisdiction.
  3. Record each control objective, owner, frequency, evidence, dependencies and testing method.
  4. Confirm segregation of duties, access control, approval and escalation where relevant.
  5. Identify missing, duplicate, conflicting or unevidenced controls and record an issue.
  6. Coordinate changes with the applicable detailed policy and process owner.
  7. Review coverage after material product, system, regulatory, incident or outsourcing change.
  8. Report coverage gaps and residual risk to management.

Exceptions and Escalation

A manual or policy statement alone is not evidence that a control operates. Material uncovered obligations require interim protection and an accountable remediation plan.

Records

  • Risk and requirement to control mapping
  • Control inventory and ownership
  • Evidence and testing specifications
  • Gap and overlap analysis
  • Management decisions and remediation

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: quarterly and after material change

History

  • 2026-07-26: Created from section 3 of the approved ICA Manual.