Purpose
Apply a consistent method to enterprise, process, product, project and event risk and document inherent risk, control effectiveness and residual risk.
PDF-Derived Operational Detail
Bitkaya applies a structured methodology to assess inherent risk, control effectiveness, and residual risk across the business. Risk assessment may take place at enterprise level, business or process level, client level, product level, project level, or event level depending on the nature of the matter.
The methodology supports: annual and trigger-based enterprise-wide risk assessment; process and control reviews; client risk scoring interfaces with the AML/CTF/CPF and KYC/CDD frameworks; change and release risk assessment; new product approval; third-party risk assessment; and incident, issue, and complaint assessment. The rationale, evidence, scoring basis, assumptions, and conclusions for material risk assessments must be documented.
EWRA domains. The EWRA assesses inherent risk and control effectiveness across relevant domains: client base, services and products, geography and jurisdiction, delivery channels, transaction activity, technology, outsourcing, and governance. EWRA outputs inform control design and enhancement, risk appetite calibration, monitoring and escalation thresholds, staffing and tooling priorities, review frequencies, and management and Board reporting. Where EWRA outcomes require changes to specific controls or procedures, related subordinate manuals and operational guidance must be updated accordingly.
Operational risk assessments. Risk assessments shall include RCSA processes, change risk assessments, and product risk evaluations. No material change shall be implemented without prior risk assessment.
Client-level risk scoring. Client-level risk scoring is governed primarily by Bitkaya’s AML/CTF/CPF and KYC/CDD frameworks, but forms part of the broader RMF because client risk directly affects operational, legal, reputational, and financial crime exposure. Client-level scoring informs: the depth of due diligence; approval thresholds; frequency of periodic review; monitoring intensity; escalation thresholds; and the level of supporting documentation required. Client risk classification is not static and must be reassessed when material changes, red flags, sanctions events, unusual activity, or other trigger events arise.
Risk event management. All operational risk events, including losses and near misses, shall be recorded in a centralized database. Root cause analysis shall be performed for material events.
Steps
- Define scope, owner, decision purpose, assessment level and applicable risk domains.
- Gather evidence on clients, products, services, jurisdictions, channels, transactions, technology, outsourcing and governance — these correspond to the EWRA domains of client base, services and products, geography and jurisdiction, delivery channels, transaction activity, technology, outsourcing, and governance.
- Identify threats, vulnerabilities, events, causes and potential client, regulatory, financial and operational impacts.
- Score inherent likelihood and impact using the approved methodology, documenting the rationale, evidence, scoring basis, assumptions, and conclusions.
- Identify controls and assess design and actual operating evidence.
- Determine residual risk, compare it with appetite and document assumptions, limitations and rationale.
- Define treatment, ownership, due dates, monitoring and approval.
- Perform the EWRA annually and trigger reassessment after material change, incident, red flag, sanctions event, unusual activity or emerging risk. Where EWRA outcomes require changes to specific controls or procedures, update related subordinate manuals and operational guidance accordingly.
- Record losses and near misses in a centralized database and perform root-cause analysis for material events. Include RCSA processes, change risk assessments, and product risk evaluations — no material change shall be implemented without prior risk assessment.
- For client-level risk, interface with the AML/CTF/CPF and KYC/CDD frameworks to determine depth of due diligence, approval thresholds, frequency of periodic review, monitoring intensity, escalation thresholds, and supporting documentation level. Reassess when material changes, red flags, sanctions events, unusual activity, or other trigger events arise.
Exceptions and Escalation
Incomplete evidence or unsupported scoring shall be identified as an uncertainty and escalated. Material changes shall not proceed on an undocumented risk assumption.
Records
- EWRA and RCSA records
- Product, project and event assessments
- Scoring evidence and control evaluation
- Risk treatment and acceptance decisions
- Loss, near-miss and root-cause records
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Control: CTRL-RMF-002 Ensure Risk Assessments Are Complete and Current
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: annual and trigger-based
History
- 2026-07-26: Created from section 4 of the approved RMF.