Purpose
Assign a documented EWRA/SARA-based client risk classification and apply the corresponding CDD, approval, monitoring and review requirements.
Preconditions
- Initial onboarding information and screening results are available.
- The current risk-scoring methodology is approved.
Steps
- Score client type, ownership, PEP exposure, onboarding method, geography, product and behavioral risk, expected activity and delivery channel using the EWRA/SARA model.
- Use the highest applicable score within each building block and document the inputs and rationale. For example, a client engaging in simple fiat transfers via a local bank, but trades more than Cg. 30.000, gets a risk score of 3 (not 1) on Product & Behavioral Risk.
- Compare the resulting classification with the preliminary assessment and explain discrepancies. Risk Classification is prepared by Operations. In case of onboarding, the Risk Classification is compared to the Preliminary Risk Assessment that followed from the Data Collection phase. Any discrepancies are clearly indicated.
- Document the Risk Classification formally as either Initial Risk Classification (onboarding) or Recurring Risk Classification (periodic review, or red flag/transaction monitoring trigger-based).
- For low risk, apply Simplified Due Diligence only when low risk is documented. The file must still contain sufficient information to establish identity, understand the purpose and intended nature of the relationship, confirm screening outcomes, and support the risk classification. Retain identity, purpose, screening and risk evidence and set review at least every three years.
- For medium risk, apply Standard Due Diligence. Collect sufficient information to establish identity, understand expected activity, assess source of funds at least on a self-declaration basis, and monitor the relationship using risk-appropriate controls. Set review at least every two years.
- For high risk, perform Enhanced Due Diligence. Additional information, documentation, and review must be obtained sufficient to understand the client’s ownership, control, source of wealth, source of funds, activity profile, counterparties, and transactional behaviour. Assess source of wealth before approval. Obtain supporting evidence as needed and set review at least annually. Enhanced monitoring and escalation thresholds apply throughout the relationship. No high-risk client may be approved before source of wealth has been assessed.
- For medium-risk and high-risk corporate clients, apply additional measures proportionate to risk, which may include supporting ownership evidence, additional verification of controllers and signatories, financial background information, source of funds or source of wealth review where relevant, and enhanced adverse information screening.
- Obtain management approval for low and medium risk and Compliance plus management approval for high risk. Low-risk and medium-risk clients require management approval before activation. High-risk clients require Compliance approval in addition before onboarding may be completed.
- Record the classification, CDD level, approvers, approval date, review date and any enhanced controls.
Exceptions and Escalation
Simplified measures must not be applied automatically because a party is regulated or located in a particular jurisdiction. Bitkaya does not apply simplified treatment automatically solely because a VASP is established in a particular jurisdiction or claims to be regulated. Any simplified approach must be justified by documented risk assessment. Unclear risk, inconsistent information or residual high risk must be escalated to Compliance.
Records Created
- EWRA/SARA client risk assessment;
- CDD or EDD checklist;
- source-of-funds and source-of-wealth evidence;
- proportionality rationale;
- approval and review-cycle record.
Relationships
- Policy: POL-KYC-001 KYC and CDD Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Control: CTRL-KYC-002 Ensure Risk Classification and CDD Level Are Approved
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved KYC & CDD Manual version 1.1
History
- 2026-07-26: Created from sections 5, 6 and 13 of the approved KYC & CDD Manual.