Purpose

Escalate reporting breaches, remediate causes, maintain competence and keep the framework proportionate and scalable. This procedure implements the Training & Awareness (section 6), Breach Management & Regulator Interaction (section 7), and Proportionality Implementation (section 8) of the approved Regulatory Reporting & Communication Manual.

Breach Management & Regulator Interaction (Section 7)

Despite robust internal controls, there may be instances where reporting deadlines are missed, compliance obligations are not fully met, or operational breaches occur. To maintain regulatory trust and safeguard the integrity of Bitkaya B.V., all such incidents must be handled with urgency, transparency, and accountability.

Reporting to Senior Management (7.1): Any breach, delay, or non-compliance must be escalated to senior management within 24 hours of detection. This ensures that:

  • Leadership is promptly aware of compliance risks that may have financial, reputational, or legal implications.
  • Decisions regarding resource allocation, risk mitigation, and communication strategies can be taken swiftly.
  • A centralized record of incidents is maintained for oversight and governance purposes.

Proactive Regulator Notification (7.2): The Compliance Officer is responsible for evaluating whether a breach or delay must be disclosed to regulators. Where required, the officer will:

  • Notify the relevant authority (CBCS, FIU, or Tax Authorities) without undue delay, ensuring transparency and good faith communication.
  • Provide factual details, including the nature of the breach, its root cause, and steps already taken to contain it.
  • Coordinate with the Management Board for regulator interactions involving strategic or reputational risks.

Corrective Actions and Tracking (7.3): All corrective actions arising from a breach must be formally documented and tracked until resolution. This process includes:

  • Assigning responsibility to a designated staff member or department.
  • Establishing timelines for remediation and follow-up.
  • Monitoring progress through compliance logs and management oversight.
  • Conducting a post-incident review to identify lessons learned and strengthen internal controls to prevent recurrence.

Sanctions Hits (7.4): Not all sanctions or financial crime matters should be treated solely as generic breach events. Confirmed sanctions matches may create immediate legal obligations relating to restrictive measures, asset blocking or freezing, FIU reporting, and CBCS notification or reporting. These obligations must be considered separately and documented clearly.

Training & Awareness (Section 6)

A strong culture of compliance is built on continuous education and awareness across the organization.

Annual AML/CFT Training for All Employees (6.1): All employees, regardless of their role, must participate in mandatory annual AML/CFT training. This ensures that:

  • Staff are familiar with the requirements of the National Ordinance on the Reporting of Unusual Transactions (NORUT), CBCS provisions, and FIU guidance.
  • Employees can recognize unusual or suspicious activities and understand escalation procedures.
  • Practical case studies and scenarios are used to reinforce learning and link policies to real-world risks.
  • Attendance is tracked and completion is documented to demonstrate compliance to regulators.

Periodic Refreshers for Finance and Compliance Staff (6.2): Employees directly involved in regulatory reporting, specifically those in the Finance Department and Compliance function, must undergo refresher training sessions on a periodic basis (at least semi-annually). These refreshers will:

  • Provide updates on new CBCS circulars, FIU reporting requirements, or tax authority guidelines.
  • Address lessons learned from recent internal audits, inspections, or regulatory findings.
  • Ensure staff remain confident in preparing, reviewing, and submitting reports accurately and on time.
  • Emphasize the importance of cross-departmental collaboration for regulatory compliance.

Quarterly Reinforcement of Internal Communication Protocols (6.3): To maintain consistency and prevent miscommunication, internal communication protocols will be reinforced every quarter. This process includes:

  • Reminders to staff on escalation procedures, reporting lines, and documentation requirements.
  • Internal briefings led by the Compliance Officer to highlight emerging regulatory risks or changes in reporting standards.
  • Simulated communication drills (e.g., mock regulator requests) to ensure staff can respond promptly and appropriately.
  • Documentation of each reinforcement session in the company’s training log.

Training on regulatory communication must include AML/CFT/CPF reporting obligations, internal case classification, UTR reporting procedures, sanctions-related escalation, documentation standards, confidentiality requirements, and circumstances in which CBCS supervisory notification or reporting may also be required.

Proportionality Implementation (Section 8)

Purpose and Rationale (8.1): Bitkaya applies the principle of proportionality to ensure that the company’s systems, controls, and governance arrangements are commensurate with its size, nature, complexity, and risk profile. This approach aligns with CBCS supervisory expectations, the National Ordinance on the Supervision of Virtual Asset Service Providers (NOSVASP), and FATF risk-based principles. As a small and startup-stage VASP, the framework emphasizes practicality, efficiency, and scalability.

Guiding Principles (8.2):

  • Risk-Based Application: The scope, frequency, and depth of reporting and communication are determined by the materiality and risk level of activities. High-impact domains receive greater attention and formality than low-risk, routine interactions.
  • Clarity and Simplicity: Communications are designed to be clear, structured, and easily reviewable by regulators. Templates, standardized correspondence formats, and concise reporting summaries are used to ensure transparency and consistency without overcomplexity.
  • Efficiency and Scalability: Processes are streamlined to match the company’s resource capacity. As the company grows, communication and reporting mechanisms will scale in granularity and automation — evolving from manual registers to structured digital dashboards or RegTech solutions.
  • Accountability and Traceability: All regulatory correspondence and submissions are tracked in a central log managed by the Compliance Officer. Documentation evidences who prepared, reviewed, and approved each report, ensuring transparency and audit readiness.
  • Continuous Alignment: The proportionality assessment is reviewed annually or when there are material changes to the company’s size, risk exposure, or supervisory expectations.

Governance and Oversight (8.3): The Compliance Officer serves as the primary point of contact and custodian of the regulatory reporting framework. The Finance Department and Management Board provide supporting oversight proportional to their responsibilities. For a small VASP, combined oversight roles are acceptable provided that segregation of duties and Board visibility are maintained. As Bitkaya grows, oversight functions will expand into more specialized compliance and finance sub-departments.

Application Across Domains (8.4):

DomainProportionality Measures for a Small VASP
CBCS Prudential & AML ReportsUse simplified quarterly reporting templates. Reporting frequency remains per CBCS schedule, but content is concise and focused on key metrics (capital, governance, AML controls).
FIU Curaçao SubmissionsThe Compliance Officer manages filings manually via the FIU portal, supported by internal tracking sheets. Automated RegTech solutions will be adopted as transaction volumes increase.
Tax & Fiscal ReportingAnnual CIT filings and monthly/quarterly tax declarations are prepared by Finance using standardized checklists. External audit support is engaged as needed.
Incident & Breach NotificationsImmediate notification to the Compliance Officer and escalation to management; only material events are reported to the CBCS or FIU to maintain proportionality and focus.
Communication & RecordkeepingRegulatory contact logs maintained in digital format (Excel or secure shared drive) to document all communications. Migration to compliance management software planned upon operational scaling.
Training & AwarenessAnnual training sessions focused on communication protocols and regulatory expectations. As the company expands, specialized training modules will be introduced.

Continuous Improvement and Scalability (8.6): Proportionality does not imply static simplicity; it requires dynamic evolution. Continuous improvement measures include:

  • Annual proportionality review by the Compliance Officer.
  • Technology integration (e.g., automated filing and dashboard tools).
  • Independent assessment during internal audits to ensure adequacy of communication protocols.
  • Feedback incorporation from regulators and auditors to refine processes.

Steps

#ActionDetailsEvidence
1Escalate breach to senior managementEscalate a detected breach, delay or non-compliance to senior management within 24 hours of detection, ensuring leadership is promptly aware of compliance risks and a centralized record of incidents is maintained.Breach escalation record with 24-hour notification evidence
2Assess breachAssess authority, materiality, legal deadline, client impact and required notification.Breach assessment record
3Notify regulatorNotify the regulator (CBCS, FIU, or Tax Authorities) without undue delay where required, stating facts, cause, containment and corrective action; coordinate with the Management Board for regulator interactions involving strategic or reputational risks.Regulator notification and correspondence
4Assign and track remediationAssign remediation to a designated staff member or department; establish timelines for remediation and follow-up; monitor progress through compliance logs and management oversight; conduct a post-incident review to identify lessons learned and strengthen internal controls to prevent recurrence.Corrective action tracking and post-incident review
5Handle confirmed sanctions matchesFor confirmed sanctions matches, consider separately and document: restrictive measures, asset blocking or freezing, FIU reporting, and CBCS notification or reporting.Sanctions-hits documentation
6Deliver annual AML/CFT trainingDeliver annual AML/CFT training for all employees (covering NORUT, CBCS provisions, FIU guidance, recognition of unusual/suspicious activities, escalation procedures, practical case studies, with attendance tracked and completion documented).Annual training attendance and completion records
7Deliver semiannual refresher trainingDeliver semiannual refresher training for Finance and Compliance staff (covering new CBCS circulars, FIU reporting requirements, tax authority guidelines, lessons learned from audits/inspections, and cross-departmental collaboration).Semiannual refresher training records
8Deliver quarterly protocol reinforcementDeliver quarterly reinforcement of internal communication protocols (reminders on escalation procedures, internal briefings on emerging regulatory risks, simulated communication drills, and documentation in the training log).Quarterly reinforcement session logs and drill results
9Ensure comprehensive training coverageEnsure training covers AML/CFT/CPF reporting obligations, internal case classification, UTR reporting procedures, sanctions-related escalation, documentation standards, confidentiality requirements, and circumstances requiring CBCS supervisory notification or reporting.Training curriculum documentation
10Review proportionalityReview proportionality annually or when there are material changes to the company’s size, risk exposure, or supervisory expectations, assessing segregation of duties, tools, templates, and reporting capacity against the proportionality table above.Annual proportionality assessment and review records
11Scale specialization and automationIncrease specialization, automation and assurance as volume, licensing or risk grows — evolving from manual registers to structured digital dashboards or RegTech solutions, with technology integration and independent assessment during internal audits.Scaling plan and internal audit assessment

Records

  • Breach escalation records (with 24-hour notification evidence)
  • Regulator notification and correspondence
  • Corrective action tracking and post-incident reviews
  • Sanctions-hits documentation (restrictive measures, FIU reporting, CBCS notification assessed separately)
  • Annual training attendance and completion records
  • Semiannual refresher training records
  • Quarterly reinforcement session logs and drill results
  • Annual proportionality assessment and review records

Relationships

History

  • 2026-07-26: Created from sections 6 through 8 of the approved REG Manual.
  • 2026-07-28: Enriched with full Breach Management framework (7.1–7.4), Training & Awareness program (6.1–6.3), Proportionality Implementation (8.1–8.6 including domain table), and continuous improvement measures from PDF sections 6, 7, and 8.