Purpose

Maintain approved risk governance, taxonomy, appetite, tolerance, authority and escalation arrangements.

PDF-Derived Operational Detail

Effective risk management depends on clear ownership, credible challenge, timely escalation, and documented decision-making. The governance framework assigns specific responsibilities as follows:

  • Board of Directors: Approves the RMF, risk appetite, and material risk policies. Receives regular reporting on Bitkaya’s overall risk profile, material incidents, control weaknesses, and remediation status.
  • Risk & Compliance Committee (or equivalent management forum): Reviews the risk profile, limit breaches, incident trends, remediation status, new product risks, and material control issues. Challenges management where needed and ensures that cross-functional risk matters are addressed in a coordinated manner.
  • Executive Management: Owns execution of the RMF and ensures that Bitkaya has appropriate staffing, tools, systems, reporting, and governance to manage risk effectively.
  • First Line Functions: Business, operations, finance, and technology teams own the risks arising from their activities and are responsible for operating controls effectively and escalating issues in a timely manner.
  • Second Line Functions: Risk and Compliance establish policy standards, advise the business, monitor adherence, perform challenge, review escalations, and support reporting to management and the Board.
  • Third Line / Independent Review: Internal audit or independent external assurance provides periodic review of the effectiveness of governance, risk management, and controls.

Bitkaya maintains a low or very low appetite for risks that could result in regulatory breaches, client harm, misuse of client assets, sanctions violations, bribery or corruption, serious cybersecurity compromise, or material failures in AML/CTF/CPF controls.

Risk appetite is expressed through both qualitative statements and quantitative indicators, supported by escalation thresholds and management information. Where thresholds are breached or control effectiveness deteriorates, management must assess whether additional controls, temporary restrictions, enhanced monitoring, or remediation actions are required.

The full risk taxonomy covers: financial crime risks (money laundering, terrorist financing, proliferation financing, sanctions exposure, bribery and corruption, fraud, market abuse); market and liquidity risks; operational risks (people, processes, systems, external events); technology and cybersecurity risks; safeguarding and custody risks; legal and regulatory compliance risks; counterparty, third-party, and outsourcing risks; strategic and business model risks; reputational risks; business continuity and resilience risks. Risk events may affect more than one category and should be assessed holistically.

Steps

  1. Maintain Board, management, committee, first-line, second-line and independent-assurance responsibilities per the governance framework above, ensuring each role has documented accountability for its assigned decisions and escalations.
  2. Maintain a taxonomy covering financial crime (including ML, TF, PF, sanctions, bribery, corruption, fraud, market abuse), market, liquidity, operational, technology, cybersecurity, safeguarding, custody, legal, regulatory, counterparty, third-party, outsourcing, strategic, business model, reputational and resilience risk. Assess risk events holistically across categories rather than in isolation.
  3. Define qualitative appetite statements (low or very low for regulatory breaches, client harm, misuse of client assets, sanctions violations, bribery/corruption, cybersecurity compromise, AML/CTF/CPF failures) and quantitative indicators with tolerances and escalation thresholds supported by management information.
  4. Set delegated authority for risk acceptance, treatment and exceptions, ensuring clear accountability through the three lines model.
  5. Assign an accountable owner to each material risk, indicator, control and remediation action.
  6. Escalate breaches or deteriorating control effectiveness and document restrictions, enhanced monitoring or treatment. Where thresholds are breached or control effectiveness deteriorates, management must assess whether additional controls, temporary restrictions, enhanced monitoring, or remediation actions are required.
  7. Review governance and appetite at least annually and after material business or risk-profile change.
  8. Obtain Board approval and retain decision evidence.

Exceptions and Escalation

Risks outside appetite shall not be accepted through informal practice. They require immediate escalation, documented interim protection and approval by the authority specified in the framework.

Records

  • Governance and responsibility matrix
  • Risk taxonomy and appetite statement
  • Limits, thresholds and delegated authorities
  • Breach, escalation and decision records
  • Board approval and review evidence

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual and after material change

History

  • 2026-07-26: Created from sections 2 and 3 of the approved RMF.