Purpose
Monitor whether controls exist and operate effectively and ensure indicator breaches, weaknesses and remediation receive timely action.
PDF-Derived Operational Detail
Bitkaya maintains a control environment designed to manage risks proportionately and support timely detection, escalation, and remediation of issues. Controls may include preventive, detective, corrective, manual, automated, or governance-based measures.
Illustrative control categories include: client due diligence, KYV, sanctions screening, transaction monitoring, and escalation controls; safeguarding controls over client money, client virtual assets, keys, wallets, and reconciliations; cybersecurity and access controls; approval and segregation-of-duties controls; incident and issue management controls; third-party due diligence and monitoring controls; reporting, recordkeeping, and documentation controls; and business continuity and resilience measures. Monitoring should focus both on whether controls exist and whether they operate effectively in practice.
Monitoring tools. Bitkaya uses management information, key risk indicators (KRIs), key control indicators (KCIs), dashboards, file reviews, exception reporting, and thematic reviews to monitor risk and control performance.
Specific monitoring areas include: onboarding approval breaches; overdue periodic reviews; sanctions alerts and unresolved-alert aging; false positive rates and closure quality; unusual transaction escalation volumes and conversion to external reporting where applicable; custody or reconciliation breaks; cyber incidents and control exceptions; third-party review status; outstanding remediation items; and training completion and competency gaps.
Indicators should have a defined owner, frequency, escalation threshold, and response expectation. Where a metric indicates a material control weakness or emerging risk trend, management must assess and document the required response.
Steps
- Maintain a risk-linked control inventory identifying owner, type (preventive, detective, corrective, manual, automated, or governance-based), frequency, evidence and testing expectation. Ensure coverage of the illustrative control categories: CDD/KYV/sanctions screening/transaction monitoring/escalation; safeguarding (client money, virtual assets, keys, wallets, reconciliations); cybersecurity and access; approval and segregation-of-duties; incident and issue management; third-party due diligence and monitoring; reporting/recordkeeping/documentation; and business continuity/resilience.
- Define KRIs and KCIs with data source, owner, frequency, threshold and required response. Specific monitoring areas include: onboarding approval breaches; overdue periodic reviews; sanctions alerts and unresolved-alert aging; false positive rates and closure quality; unusual transaction escalation volumes and conversion to external reporting where applicable; custody or reconciliation breaks; cyber incidents and control exceptions; third-party review status; outstanding remediation items; and training completion and competency gaps.
- Produce dashboards, exception reports, file reviews and thematic monitoring at the defined cadence using management information, KRIs, KCIs, dashboards, file reviews, exception reporting, and thematic reviews.
- Validate data completeness and distinguish normal variation from control deterioration or emerging risk.
- Escalate threshold breaches, repeat exceptions, overdue actions and material control weaknesses. Where a metric indicates a material control weakness or emerging risk trend, management must assess and document the required response.
- Record the response, temporary restrictions, enhanced monitoring and accountable remediation.
- Verify corrective action with evidence rather than accepting self-declared closure.
- Report trends, open issues and residual exposure to management and the Board.
- Update risks, controls, training or procedures when monitoring identifies a systemic weakness.
Exceptions and Escalation
Missing or unreliable indicator data is itself a control issue. Material weaknesses shall be assessed for client, legal, regulatory and reporting consequences.
Records
- Control inventory and ownership
- KRI and KCI definitions
- Dashboards and exception reports
- Escalations and management decisions
- Remediation and closure-testing evidence
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Control: CTRL-RMF-003 Ensure Controls Indicators and Remediation Are Monitored
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: monthly or quarterly according to indicator risk
History
- 2026-07-26: Created from section 5 of the approved RMF.