Purpose

Escalate unusual or suspicious KYC matters, support required FIU reporting and retain complete, secure and retrievable KYC records.

Preconditions

  • The concern, supporting data and client or transaction identifiers are available.
  • Access is restricted to authorized personnel.

Steps

  1. Record unusual or suspicious matters arising from onboarding, sanctions screening, transaction monitoring, staff escalation, or other control activities. Bitkaya maintains a documented internal escalation and case-handling process for such matters.
  2. Preserve the relevant client, transaction, wallet, screening and analytical evidence.
  3. Escalate the case promptly to Compliance or the MLRO.
  4. Compliance reviews the facts, records the internal classification and determines whether external reporting is required. For internal purposes, Bitkaya may use case classifications such as SAR, STR, FFR, or PNMR to support review, prioritization, escalation, and recordkeeping.
  5. Submit any required external report to FIU Curaçao exclusively through a Unusual Transaction Report (UTR), where reporting is required, with complete and accurate information.
  6. Protect the existence and content of internal and external reporting and prevent tipping off. Confidential reporting information must not be disclosed to the client or unauthorized persons.
  7. Respond to lawful FIU or CBCS requests and suspension instructions through the authorized process.
  8. Retain KYC files, customer profiles, blockchain wallet analytics, transaction records, reports and decisions securely for at least 5 years or longer where another applicable requirement controls. All internal escalation steps, review decisions, supporting analysis, and external reporting outcomes must be documented and retained in accordance with Bitkaya’s recordkeeping framework.
  9. Ensure records are encrypted, with strict access controls, and easily retrievable for audits, compliance reviews, and regulator inspections.

Exceptions and Escalation

Operational personnel must not decide that an escalated case is non-reportable without Compliance review. Confidential reporting information must not be disclosed to the client or unauthorized persons.

Records Created

  • internal case and escalation;
  • Compliance analysis and decision;
  • UTR and acknowledgement where applicable;
  • FIU or CBCS request and response;
  • retained KYC and transaction evidence;
  • access and retrieval evidence.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved KYC & CDD Manual version 1.1

History

  • 2026-07-26: Created from sections 9 and 10 of the approved KYC & CDD Manual.