Purpose
Protect client fiat, virtual assets, access means and related data through the detailed SAFU segregation, movement, reconciliation, reporting, provider, technology and resolution controls, consistent with the approved Market Conduct & Trading Compliance Manual v1.1 section 6.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Maintain client fiat in segregated bank accounts and client virtual assets in wallets distinct from company holdings | Client fiat funds must be held in segregated bank accounts and virtual assets maintained in distinct wallets separate from company holdings | MCT 6.1 Dedicated Accounts |
| 2 | Prohibit commingling or use of client assets for company operations, lending or proprietary trading | Under no circumstances shall client assets be used to finance company operations, lending or proprietary trading | MCT 6.1 No Commingling |
| 3 | Place client money in designated accounts within three calendar days, maintain one-to-one virtual-asset holdings and reconcile client entitlements at least weekly under the current model | Segregation practices will comply with jurisdiction-specific custody and safeguarding requirements including reporting to regulators where mandated; accurate records must be maintained to demonstrate full reconciliation of client balances at all times and independent audits may be conducted to verify compliance | MCT 6.1 Regulatory Compliance, Auditability |
| 4 | Apply approved wallet architecture, access controls, multifactor authentication, role-based permissions and approval workflows | The firm will use a combination of multi-signature wallets, hardware security modules (HSMs) and cold storage solutions to safeguard client assets; only authorized personnel may access custody systems subject to multi-factor authentication, role-based permissions and approval workflows | MCT 6.2 Wallet Management, Access Controls |
| 5 | Maintain secure backup, recovery, incident response, redundancy and business-continuity arrangements | Custody processes will include redundancies, secure backups and contingency procedures to ensure asset recovery in the event of technical failures or breaches (MCT 6.2 Operational Resilience); Bitkaya will maintain firewalls, intrusion detection systems, penetration testing and security monitoring to protect against cyber threats; client information and transaction records will be encrypted in transit and at rest with strict access controls applied; a formal incident response plan will be maintained including escalation procedures, forensic investigation and mandatory reporting of material breaches to regulators and affected clients; disaster recovery protocols, offsite backups and redundancy systems will ensure resilience | MCT 6.4 |
| 6 | Assess third-party custodians through due diligence, contract safeguards, information and audit rights and ongoing monitoring | Where third-party custodians are used, they will be subject to rigorous due diligence, contractual safeguards and ongoing monitoring | MCT 6.2 Vendor Oversight |
| 7 | Assess insurance availability, scope, limitations and adequacy regularly and disclose material protection limitations to clients | Policies may include protection against cyberattacks, fraud, employee misconduct and operational failures; clients will be informed of the extent and limitations of any insurance coverage to ensure clarity about protections; the firm will regularly assess the adequacy of insurance arrangements in line with evolving risks, market conditions and regulatory guidance | MCT 6.3 |
| 8 | Apply documented holds or restrictions where law, sanctions, unusual-activity review, fraud or safeguarding concerns require them | Client assets must be safeguarded, but may also need to be restricted, held or prevented from moving where applicable law, sanctions controls, unusual activity review, fraud concerns or other legal restrictions require this; such matters must be managed through documented escalation and decision-making procedures | MCT 6 intro |
| 9 | Issue monthly client statements within 25 calendar days of the statement date and investigate client discrepancies promptly | ||
| 10 | Investigate reconciliation, access, security or asset exceptions immediately and escalate material matters |
Exceptions and Escalation
Any unexplained reconciliation difference, unauthorized access, commingling, custody weakness or failed recovery control requires immediate escalation and restriction of affected activity.
Records
- Segregated account and wallet inventory
- Reconciliations and exception resolution
- Access and approval records
- Custody design and third-party oversight
- Insurance assessment and disclosure
- Incident, restriction and recovery evidence
Relationships
- Policy: POL-MCT-001 Market Conduct and Trading Compliance Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Control: CTRL-MCT-005 Ensure Client Assets and Custody Are Safeguarded
- Related IT process: PRC-RSA-001 Resilience Systems and Assurance
- Related BCM process: PRC-RSA-001 Resilience Systems and Assurance
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: continuous safeguards, scheduled reconciliation and periodic risk review
History
- 2026-07-26: Created from section 6 of the approved MCT Manual.
- 2026-07-26: Linked to the detailed SAFU framework and aligned explicit operating frequencies.