Purpose
Prevent a new product, service, jurisdiction, channel, system or material process change from proceeding without complete risk assessment and approval.
PDF-Derived Operational Detail
New products, services, jurisdictions, channels, system changes, or material process changes must be assessed before implementation to ensure Bitkaya understands the associated risks and has adequate controls in place.
The assessment must consider, where relevant:
- legal and licensing implications;
- AML/CTF/CPF and sanctions impact;
- operational and safeguarding risks;
- cybersecurity implications;
- client disclosure and conduct risk;
- recordkeeping and reporting impact;
- training and staffing needs; and
- whether related manuals, SOPs, and controls require updating.
No material change should proceed without the required governance review and approval.
Steps
- Describe the proposal, owner, objectives, scope, clients, jurisdictions, dependencies and implementation date.
- Determine legal, licensing, regulatory and permitted-service implications.
- Assess AML/CTF/CPF and sanctions impact; operational and safeguarding risks; cybersecurity implications; client disclosure and conduct risk; recordkeeping and reporting impact; and training and staffing needs.
- Identify required controls, testing, monitoring, disclosures, contracts, procedures and evidence. Determine whether related manuals, SOPs, and controls require updating.
- Confirm technology and release assurance and assess third-party or outsourcing implications.
- Record inherent and residual risk, unresolved assumptions and acceptance authority.
- Obtain required Compliance, Technology, Operations, management and Board approval before implementation. No material change should proceed without the required governance review and approval.
- Define go-live conditions, post-implementation monitoring and review date.
- Update affected manuals, procedures, controls, training and registers.
Exceptions and Escalation
No material change shall proceed where permission, risk ownership, testing, critical controls or required approval is absent or uncertain.
Records
- Proposal and applicability assessment
- Multi-domain risk assessment
- Control and testing evidence
- Approval and go-live decision
- Post-implementation review and updates
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Control: CTRL-RMF-005 Ensure New Products and Material Changes Are Approved
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: before implementation and after material change
History
- 2026-07-26: Created from section 7 of the approved RMF.