Purpose
Coordinate timely CBCS reports, material-change and incident notifications, licensing communication and supervisory inquiries. This procedure implements the CBCS reporting obligations (section 2.1), the Management Board’s approval and representation role (section 3.3), and the breach management and regulator interaction framework (section 7) of the approved Regulatory Reporting & Communication Manual.
CBCS Authority Profile
The Central Bank of Curaçao and Sint Maarten (CBCS) is the supervisory authority for financial institutions, including Virtual Asset Service Providers (VASPs) such as Bitkaya B.V.
Key Responsibilities:
- Licensing and registration of the entity.
- Ongoing prudential and integrity supervision.
- AML/CFT compliance oversight.
- Fit & Proper testing of key persons.
Reporting Obligations:
- Periodic compliance reports (AML/CFT, governance, risk management) — quarterly, due 30 days after quarter-end.
- Annual audited financial statements — due 5 months after year-end.
- Notifications of material changes (ownership, management, business model).
- Incident reporting (cybersecurity, fraud, operational failures).
Management Board Role (Section 3.3)
The Management Board carries ultimate accountability for governance and ensures that Bitkaya B.V. maintains strategic compliance while fostering trust with regulators and stakeholders:
- Approval Authority: Reviews and formally approves key regulatory submissions, including license applications, audited financial statements, compliance reports, and responses to official inquiries.
- Official Representation: Acts as the formal point of contact for regulators in cases requiring executive-level dialogue, such as licensing, enforcement actions, or strategic supervisory matters.
Breach Management Context (Section 7)
Where a CBCS-related breach, delay, or non-compliance occurs:
- Any breach must be escalated to senior management within 24 hours of detection.
- The Compliance Officer evaluates whether a breach or delay must be disclosed to CBCS without undue delay, providing factual details including the nature of the breach, its root cause, and steps already taken to contain it.
- Coordinate with the Management Board for regulator interactions involving strategic or reputational risks.
- All corrective actions must be formally documented and tracked until resolution, with a post-incident review to identify lessons learned and strengthen internal controls.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Identify CBCS report or inquiry | Identify the CBCS report, notification or inquiry and applicable deadline, referencing the reporting calendar for the report type (prudential/AML report quarterly, audited financials annually, or ad hoc material-change/incident notifications). | Filing record with scope and deadline |
| 2 | Assign ownership | Assign Compliance ownership and required Finance, Technology, Operations or management contributors. | Responsibility assignment record |
| 3 | Assess materiality and impacts | Assess materiality, licensing, prudential, governance, AML, incident and client impacts. | Materiality assessment record |
| 4 | Prepare factual content | Prepare content, supporting evidence, cause and corrective action; present information objectively without speculation; use clear and precise language; disclose all relevant facts even if adverse while highlighting corrective measures. | Draft report with supporting evidence |
| 5 | Obtain management or Board approval | Obtain management or Board approval for material submissions — the Management Board reviews and formally approves key regulatory submissions including license applications, audited financial statements, compliance reports, and responses to official inquiries. | Board approval or sign-off record |
| 6 | Submit via required channel | Submit through the required channel (CBCS portal or formal letter signed by authorized representatives) and retain proof. | Submission confirmation or portal receipt |
| 7 | Document meetings and calls | Document meetings and calls with CBCS immediately in writing — in-person or telephone conversations should be minimized and documented immediately afterward. | Written documentation of meetings and calls |
| 8 | Track follow-up and remediation | Track commitments, follow-up requests and remediation to closure. | Follow-up and remediation log |
Records
- Applicability and materiality assessment
- Approved report or notification (with Board approval for material submissions)
- Submission and communication log (including written documentation of any in-person or telephone communications)
- Follow-up and corrective actions (with post-incident review where applicable)
Relationships
- Policy: POL-REG-001 Regulatory Reporting and Communication Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-REG-004 Ensure CBCS Reporting and Notifications Are Controlled
History
- 2026-07-26: Created from sections 2.1, 3 and 7 of the approved REG Manual.
- 2026-07-28: Enriched with full CBCS authority profile, Management Board approval/representation role, breach management context, and reporting calendar deadlines from PDF sections 2.1, 3.3, 5, and 7.