Purpose

Coordinate timely CBCS reports, material-change and incident notifications, licensing communication and supervisory inquiries. This procedure implements the CBCS reporting obligations (section 2.1), the Management Board’s approval and representation role (section 3.3), and the breach management and regulator interaction framework (section 7) of the approved Regulatory Reporting & Communication Manual.

CBCS Authority Profile

The Central Bank of Curaçao and Sint Maarten (CBCS) is the supervisory authority for financial institutions, including Virtual Asset Service Providers (VASPs) such as Bitkaya B.V.

Key Responsibilities:

  • Licensing and registration of the entity.
  • Ongoing prudential and integrity supervision.
  • AML/CFT compliance oversight.
  • Fit & Proper testing of key persons.

Reporting Obligations:

  • Periodic compliance reports (AML/CFT, governance, risk management) — quarterly, due 30 days after quarter-end.
  • Annual audited financial statements — due 5 months after year-end.
  • Notifications of material changes (ownership, management, business model).
  • Incident reporting (cybersecurity, fraud, operational failures).

Management Board Role (Section 3.3)

The Management Board carries ultimate accountability for governance and ensures that Bitkaya B.V. maintains strategic compliance while fostering trust with regulators and stakeholders:

  • Approval Authority: Reviews and formally approves key regulatory submissions, including license applications, audited financial statements, compliance reports, and responses to official inquiries.
  • Official Representation: Acts as the formal point of contact for regulators in cases requiring executive-level dialogue, such as licensing, enforcement actions, or strategic supervisory matters.

Breach Management Context (Section 7)

Where a CBCS-related breach, delay, or non-compliance occurs:

  • Any breach must be escalated to senior management within 24 hours of detection.
  • The Compliance Officer evaluates whether a breach or delay must be disclosed to CBCS without undue delay, providing factual details including the nature of the breach, its root cause, and steps already taken to contain it.
  • Coordinate with the Management Board for regulator interactions involving strategic or reputational risks.
  • All corrective actions must be formally documented and tracked until resolution, with a post-incident review to identify lessons learned and strengthen internal controls.

Steps

#ActionDetailsEvidence
1Identify CBCS report or inquiryIdentify the CBCS report, notification or inquiry and applicable deadline, referencing the reporting calendar for the report type (prudential/AML report quarterly, audited financials annually, or ad hoc material-change/incident notifications).Filing record with scope and deadline
2Assign ownershipAssign Compliance ownership and required Finance, Technology, Operations or management contributors.Responsibility assignment record
3Assess materiality and impactsAssess materiality, licensing, prudential, governance, AML, incident and client impacts.Materiality assessment record
4Prepare factual contentPrepare content, supporting evidence, cause and corrective action; present information objectively without speculation; use clear and precise language; disclose all relevant facts even if adverse while highlighting corrective measures.Draft report with supporting evidence
5Obtain management or Board approvalObtain management or Board approval for material submissions — the Management Board reviews and formally approves key regulatory submissions including license applications, audited financial statements, compliance reports, and responses to official inquiries.Board approval or sign-off record
6Submit via required channelSubmit through the required channel (CBCS portal or formal letter signed by authorized representatives) and retain proof.Submission confirmation or portal receipt
7Document meetings and callsDocument meetings and calls with CBCS immediately in writing — in-person or telephone conversations should be minimized and documented immediately afterward.Written documentation of meetings and calls
8Track follow-up and remediationTrack commitments, follow-up requests and remediation to closure.Follow-up and remediation log

Records

  • Applicability and materiality assessment
  • Approved report or notification (with Board approval for material submissions)
  • Submission and communication log (including written documentation of any in-person or telephone communications)
  • Follow-up and corrective actions (with post-incident review where applicable)

Relationships

History

  • 2026-07-26: Created from sections 2.1, 3 and 7 of the approved REG Manual.
  • 2026-07-28: Enriched with full CBCS authority profile, Management Board approval/representation role, breach management context, and reporting calendar deadlines from PDF sections 2.1, 3.3, 5, and 7.