Purpose
Complete identity, legal-existence, ownership, authority and initial screening checks before a client relationship is activated.
Preconditions
- The requested service and client type are known.
- The approved onboarding channel and verification tools are available.
- The applicable file requirements are selected.
Steps
- Record the prospective client, requested service, purpose and expected activity.
- For an individual, collect valid identification (passport, national identity card, cedula, or driving licence) and required proof of residential address; perform authenticity, liveness or biometric checks applied through Bitkaya’s onboarding process.
- For a legal entity, collect registry and constitutional records (certificate of incorporation, chamber/company registry extract, articles of association or equivalent constitutional documents, register of directors or shareholders, authorized signatory evidence), identify directors, authorized representatives and natural-person beneficial owners, and understand the ownership and control structure.
- Verify identity, legal existence and authority using reliable independent information and approved tools. The extent of verification and supporting evidence required is determined on a documented risk basis and may include registry extracts, incorporation documents, constitutional documents, authorized signatory evidence, ownership documentation, and supporting identification records for relevant natural persons.
- Screen the client, entity, beneficial owners, directors and representatives for sanctions, PEP and relevant adverse information. For low-risk corporate clients the minimum file should ordinarily include at least: a recent registry extract or equivalent official corporate record; a signed UBO declaration; identification of the authorized signatory or representative; sanctions and PEP screening results for the entity, authorized signatory, and declared UBOs; and documentation of the purpose and intended nature of the relationship.
- Collect source-of-funds information and, where risk requires, source-of-wealth evidence, proportionate to risk classification:
- Low-risk: collect the minimum information necessary to understand the purpose and intended nature of the relationship and the expected level of activity.
- Medium-risk: source of funds must be collected, at minimum on a self-declaration basis, supported by additional information where required by the facts and circumstances.
- High-risk: source of wealth must be assessed before approval. Supporting documentation must be obtained where necessary to substantiate the client’s source of wealth and source of funds, and enhanced review must be performed where the circumstances require deeper understanding of the client’s financial profile or transaction activity.
- For digital onboarding via BitKaya.io, use biometric verification, liveness detection, and AI-driven fraud detection (eKYC); ensure document uploads are cross-checked with government databases and document authenticity checks; verify proof of address with geolocation metadata and trusted third-party databases; and ensure real-time sanctions/PEP screening against OFAC, UN, EU, and CFATF lists.
- Where virtual asset activity forms part of the funding profile, use blockchain tracing, wallet review, and other transaction analysis tools to support the assessment. The extent of tracing and review must be documented in the client file where enhanced review is required.
- Record all evidence and unresolved questions in the client file.
- Do not activate the relationship until verification, screening, risk classification and approval are complete. No individual or corporate client relationship may be activated until the applicable due diligence requirements, approvals, and sanctions checks have been completed.
Exceptions and Escalation
Unverifiable identity, unexplained ownership, unresolved screening alerts or missing mandatory evidence must stop onboarding and be escalated to Compliance. No commercial exception may override a legal identification requirement. BitKaya.io complies with GDPR-style data protection standards and multi-layer encryption safeguards client data both during transmission and storage.
Records Created
- onboarding checklist;
- identification and verification results;
- entity, ownership and authority evidence;
- screening results;
- source-of-funds or source-of-wealth evidence;
- approval or rejection record.
Relationships
- Policy: POL-KYC-001 KYC and CDD Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Parent procedure: PROC-AML-002 Perform Client Acceptance CDD EDD and Risk Classification
- Control: CTRL-KYC-001 Ensure Client Identity Ownership and Authority Are Verified
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved KYC & CDD Manual version 1.1
History
- 2026-07-26: Created from sections 2 and 3 of the approved KYC & CDD Manual.