Purpose

Maintain accountable market-conduct governance, approved service and jurisdictional permissions, current risk assessment and documented proportionality decisions, consistent with the approved Market Conduct & Trading Compliance Manual v1.1 sections 1, 2, 3.5, 9.1, 9.4, 11 and 12.

Steps

#ActionDetailsEvidence
1Confirm Board, management, Compliance, Trading, Operations and Technology responsibilities and escalation pathsThe Board retains ultimate responsibility for ensuring conduct and trading oversight remain effective; the Compliance Officer monitors adherence to the Market Conduct Manual and calibrates procedures in line with company size and regulatory expectations; Trading and Operations apply conduct rules daily ensuring fair order handling, client-first execution and transparencyMCT 2.5, 12.3
2Maintain a jurisdictional licensing matrix covering services, registrations, permissions, exemptions, renewal dates, filing obligations and restrictionsThe Compliance team maintains the matrix to identify and track applicable requirements across regions; all licenses must be renewed timely and required filings submitted accurately and within statutory deadlines; services offered in each jurisdiction must align strictly with regulator-granted permissions; employees and contractors are prohibited from conducting regulated activities in jurisdictions where Bitkaya lacks authorizationMCT 9.1
3Verify that products, services, communications and target jurisdictions remain within approved permissions before launch or material changeEmployees must not conduct or promote regulated services in jurisdictions where Bitkaya lacks licenses, registrations or exemptions, including exchange operations, custodial wallet services, advisory functions or token issuance where authorization is required; uncertainty must be escalated immediately to Legal and ComplianceMCT 3.5
4Assess market-conduct, trading, client, financial-crime, safeguarding, operational, technology, conflict and reputational risksAs a small startup-stage VASP, Bitkaya designs controls to be practical, scalable and risk-based, ensuring compliance with CBCS supervisory expectations, FATF Recommendations and NOSVASPMCT 12.1
5Apply stronger review and monitoring to higher-risk clients, transactions, products, venues, counterparties and jurisdictionsEnhanced due diligence is applied to international clients and transactions; policies and procedures are designed to meet the strictest applicable standards to mitigate conflicts between regulatory regimes; activities are assessed for compliance with laws that may apply outside the home jurisdiction, including securities regulations, sanctions and anti-corruption lawsMCT 9.4, 11.1
6Document proportionality decisions concerning manual review, automation, surveillance, separation of duties and reporting frequencyProportionality decisions are documented in internal compliance memoranda and version-controlled policy updates, supported by evidence of rationale (risk assessments, resource constraints, operational complexity) and reviewed annually by the Compliance Officer to confirm alignment with CBCS expectations and evolving market conditions; all proportionality-based adjustments are subject to internal audit or external review ensuring traceability and regulatory readinessMCT 12.5
7Apply the guiding proportionality principles: risk-based application (controls proportionate to material risks, higher-risk areas receive enhanced oversight); startup-appropriate design (integrated small-team structure with clear separation of duties and escalation paths to CEO or Compliance Officer); regulatory alignment (CBCS, GDF Code of Conduct, FATF Recommendation 15); efficiency and focus (prevent material risks rather than overly complex mechanisms); and scalability and evolution (additional layers introduced progressively as Bitkaya grows)MCT 12.2
8Obtain annual management approval of proportionality decisions concerning automation level in monitoring or frequency of trade reviews and escalate material changes or permission uncertaintyDecisions are documented in compliance reportsMCT 12.3
9Review governance, permissions and risk at least annually and after material product, jurisdiction, ownership, service, volume or regulatory changeCommit to periodic reassessment of proportionality as Bitkaya expands product offerings, client base or trading volumes; incremental automation of monitoring, reporting and compliance processes; feedback integration from audits, regulator communications and client feedback; and progressive maturity from manual principle-based controls to structured system-supported compliance processes as the firm scalesMCT 12.6

Exceptions and Escalation

No regulated activity may proceed where permission is absent or uncertain. Material licensing, governance or risk concerns shall be escalated to Compliance, Legal, management and the Board as appropriate.

Records

  • Jurisdictional licensing matrix
  • Risk and proportionality assessment
  • Responsibility and separation-of-duties record
  • Management and Board approvals
  • Regulatory filing and renewal evidence
  • Change and escalation records

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual and after material change

History

  • 2026-07-26: Created from sections 1, 2, 3.5, 9.1, 9.4, 11 and 12 of the approved MCT Manual.