Purpose

Monitor client, transaction, wallet and VASP-counterparty risk throughout the relationship and refresh CDD on schedule or when risk changes.

Preconditions

  • The approved client profile, expected activity, risk rating and review date are recorded.
  • Monitoring, wallet-analysis and screening outputs are available where applicable.

Steps

  1. Compare fiat and virtual-asset activity with expected size, frequency, velocity, purpose, source, destination and client profile. Monitoring is calibrated to the client’s risk profile and includes review of transaction size, frequency, velocity, pattern, source, destination, exposure to higher-risk wallets or services, suspicious wallet connections, unusual routing behaviour, and consistency with known client information, expected activity, and the stated purpose and nature of the relationship.
  2. Review red flags including: large or unusual transactions; repeated smaller transactions that may indicate structuring; sudden changes in transaction size, velocity, or pattern; activity inconsistent with the client’s known profile or expected behaviour; unusual routing of funds or assets; exposure to higher-risk wallets, services, typologies, or counterparties; suspicious off-ramping or on-ramping behaviour; and wallet links to sanctions exposure, darknet markets, mixers, stolen assets, fraud typologies, ransomware, terrorism financing, or other elevated-risk indicators.
  3. Fiat Red Flags: Transaction Structuring / Smurfing (multiple small deposits within a short time frame to avoid detection thresholds); Sudden Activity Spikes (large trades inconsistent with history); Unknown Deposit Origin (deposit from bank account not in the name of client); any other red flags as indicated by the compliance officer from time to time.
  4. Onchain Monitoring: Crypto transaction monitoring provider scans non-custodial client wallets against over 20 different risk sources (e.g. mixer/tumbler usage, sanctions exposure, stolen coins, scam proceeds, ransomware/extortion, terrorism financing, child exploitation content, darknet markets, high-risk exchanges, P2P platforms, and obfuscation smart contracts). Provider assigns proprietary crypto risk score of 0-25% (minimal risk), 25-75% (moderate caution advised) and >75% (strongly advice to reject).
  5. Apply tracing depth sufficient to understand relevant source and destination risk. As a practical rule of thumb, tracing depth should ordinarily extend sufficiently to understand the relevant source and destination profile of funds or assets. In escalated or higher-risk cases, enhanced tracing may extend materially further where necessary to support a reasonable compliance conclusion. The level of tracing performed and the rationale for any conclusion reached must be documented.
  6. For higher-risk activity, apply additional controls such as enhanced review, transaction limits, additional supporting documentation, temporary holds, or escalation to Compliance.
  7. For relevant VASP counterparties, assess licensing or supervision, jurisdiction, ownership, services, transaction flows, screening and independent information. The Know Your VASP compliance file contains, as appropriate to risk: licence and/or information regarding the regulatory supervisor; company registry extract; certificate of incorporation or equivalent registration document; ownership and control information where relevant; sanctions screening results; independent data sources, including electronic business information sources; and any additional supporting information required to understand the counterparty’s role, risk, and control environment. Bitkaya does not apply simplified treatment automatically solely because a VASP is established in a particular jurisdiction or claims to be regulated.
  8. Capture required Travel Rule originator and beneficiary information and wallet-control evidence before relevant transfers proceed.
  9. Perform periodic review: low-risk every 3 years; medium-risk every 2 years; high-risk annually or whenever significant red flags arise. In addition to periodic file reviews, ongoing monitoring includes sanctions-list refresh screening, relevant transaction- or wallet-level screening where required by the control framework, and trigger-based reassessment where red flags, material changes, or unusual activity arise.
  10. Reassess immediately after material profile, ownership, wallet, transaction, adverse-information, sanctions or regulatory triggers.
  11. Update risk classification, CDD level, approvals, monitoring intensity and next review date.
  12. Escalate unusual, suspicious, prohibited or unresolved activity. Alerts generated through automated tools or manual review are subject to further assessment, escalation, and documentation in accordance with Bitkaya’s AML/CTF/CPF procedures.

Exceptions and Escalation

Monitoring alerts must not be closed without rationale. Simplified monitoring must be supported by documented low risk. Unresolved high-risk activity must be escalated before further service.

Records Created

  • monitoring alert and disposition;
  • blockchain or wallet analysis;
  • counterparty VASP assessment;
  • Travel Rule and wallet-control record;
  • periodic or trigger review;
  • updated risk classification and approval.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved KYC & CDD Manual version 1.1

History

  • 2026-07-26: Created from sections 2.2, 2.3, 7 and 8 of the approved KYC & CDD Manual.