Purpose

Prevent a new product, service, jurisdiction, channel, system or material process change from proceeding without complete risk assessment and approval.

PDF-Derived Operational Detail

New products, services, jurisdictions, channels, system changes, or material process changes must be assessed before implementation to ensure Bitkaya understands the associated risks and has adequate controls in place.

The assessment must consider, where relevant:

  • legal and licensing implications;
  • AML/CTF/CPF and sanctions impact;
  • operational and safeguarding risks;
  • cybersecurity implications;
  • client disclosure and conduct risk;
  • recordkeeping and reporting impact;
  • training and staffing needs; and
  • whether related manuals, SOPs, and controls require updating.

No material change should proceed without the required governance review and approval.

Steps

  1. Describe the proposal, owner, objectives, scope, clients, jurisdictions, dependencies and implementation date.
  2. Determine legal, licensing, regulatory and permitted-service implications.
  3. Assess AML/CTF/CPF and sanctions impact; operational and safeguarding risks; cybersecurity implications; client disclosure and conduct risk; recordkeeping and reporting impact; and training and staffing needs.
  4. Identify required controls, testing, monitoring, disclosures, contracts, procedures and evidence. Determine whether related manuals, SOPs, and controls require updating.
  5. Confirm technology and release assurance and assess third-party or outsourcing implications.
  6. Record inherent and residual risk, unresolved assumptions and acceptance authority.
  7. Obtain required Compliance, Technology, Operations, management and Board approval before implementation. No material change should proceed without the required governance review and approval.
  8. Define go-live conditions, post-implementation monitoring and review date.
  9. Update affected manuals, procedures, controls, training and registers.

Exceptions and Escalation

No material change shall proceed where permission, risk ownership, testing, critical controls or required approval is absent or uncertain.

Records

  • Proposal and applicability assessment
  • Multi-domain risk assessment
  • Control and testing evidence
  • Approval and go-live decision
  • Post-implementation review and updates

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: before implementation and after material change

History

  • 2026-07-26: Created from section 7 of the approved RMF.