Purpose

Maintain competent staff, documented proportionality decisions, Board and management oversight, independent review and continuous improvement of KYC/CDD.

Preconditions

  • Current policies, risk methodology, control evidence and regulatory changes are available.
  • Training and review owners are assigned.

Steps

  1. Deliver annual AML/KYC training to all employees, including case studies on crypto-related financial crime.
  2. Deliver specialized training for onboarding, risk, and compliance teams on blockchain forensics tools (e.g., Chainalysis, Elliptic).
  3. Deliver awareness initiatives to reinforce vigilance, e.g., newsletters on emerging ML/TF risks in crypto markets.
  4. Retain attendance, content, completion and competency evidence.
  5. Document each simplified or enhanced approach with its risk rationale, applicable CBCS and FATF guidance, EWRA/SARA support and Board or Compliance approval record. Retain proportionality determinations for five years, available for regulatory review by CBCS or FIU Curaçao upon request.
  6. Reassess proportionality during Bitkaya’s annual compliance review and upon any significant operational change (e.g., customer base expansion, product introduction, or system integration).
  7. Ensure proportionality is reflected in the depth of file requirements, source of funds or source of wealth review, screening intensity, KYV measures, and frequency of review. Low-risk clients may be subject to simplified measures only where their low-risk status has been assessed and documented. Medium-risk and high-risk clients are subject to progressively stronger controls, evidence requirements, monitoring measures, and approval thresholds.
  8. Ensure external FIU reporting remains centralized through the UTR process under the responsibility of the Compliance function / MLRO.
  9. Provide quarterly compliance updates to the Board. The Board approves the proportional KYC/CDD framework and ensures resource allocation and staffing remain adequate for Bitkaya’s risk profile.
  10. Plan independent review of KYC/CDD design and operating effectiveness. Internal Audit conducts independent reviews of KYC/CDD effectiveness and regulatory compliance.
  11. Record findings, owners, due dates, management responses and closure evidence.
  12. Scale staffing, technology, and policies as the company matures. Manual controls will transition to automated, integrated compliance workflows. CBCS feedback and external audit results will directly inform proportionality adjustments.

Exceptions and Escalation

Proportionality may simplify process form but not reduce legal minimums or control effectiveness. Simplified measures are not applied automatically solely because a client, legal entity, or counterparty is regulated or established in a particular jurisdiction. Any reduced control approach must be justified by the documented risk assessment and remain consistent with applicable law and supervisory expectations. Overdue training, unresolved assurance findings or inadequate resources must be escalated to management and the Board.

Records Created

  • training plan, materials and completion records;
  • proportionality assessment and approval;
  • Board reporting;
  • independent review report;
  • remediation and closure evidence.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved KYC & CDD Manual version 1.1

History

  • 2026-07-26: Created from sections 11, 12 and 13 of the approved KYC & CDD Manual.