Purpose

Maintain reliable risk records, controlled models, decision-useful reporting, independent assurance and consistent policy management.

PDF-Derived Operational Detail

Reliable data and records are essential to sound risk management, regulatory compliance, and auditability. Bitkaya must maintain records sufficient to support risk assessments, approvals, monitoring, client treatment, internal escalations, control testing, remediation, and management oversight.

Model risk. Where tools, scoring models, rule engines, or automated decision-support mechanisms are used, Bitkaya must understand their purpose, limitations, calibration, ownership, and review requirements. Changes to risk-scoring models, monitoring scenarios, sanctions tooling, onboarding logic, or other material compliance-related automation must be reviewed and governed appropriately.

Reporting. Risk reporting must be timely, accurate, comprehensible, and useful for decision-making. Management information should provide visibility over material risks, control performance, incidents, trends, breaches, unresolved issues, and remediation progress. Where relevant, reporting should distinguish between: operational incidents; control issues; sanctions matters; internal compliance escalations; external reporting matters; safeguarding incidents; third-party failures; and training or capability weaknesses. Material matters should be reported in a manner that supports escalation, accountability, and traceable management action.

Assurance. Bitkaya’s RMF is supported by second line review, internal audit, and, where appropriate, independent external assurance. Assurance activities should evaluate whether: risks are identified and assessed appropriately; controls are designed and operating effectively; reporting and escalation are timely and accurate; remediation actions are tracked and completed; cross-manual consistency is maintained; and significant legal, regulatory, or governance changes are reflected in subordinate manuals, SOPs, and control operation. Findings must be documented, tracked, and reported through the governance framework.

Policy management. Each policy or manual must have a designated owner responsible for: periodic review; update following legal, regulatory, operational, or governance change; consistency with parent and subordinate frameworks; and accurate reflection of current control operation. Where a material change is made to one core manual, the owner must assess whether related manuals, SOPs, forms, templates, registers, training materials, and operational guidance must also be updated. Cross-manual inconsistencies should be treated as control weaknesses and addressed promptly.

Proportionality. Proportionality determinations, compensating controls, and rationales are documented in the RMF appendix for regulatory review. Templates and registers are simplified but maintained to CBCS standards of traceability and auditability. Bitkaya re-assesses proportionality annually as part of the Enterprise-Wide Risk Assessment and whenever significant changes occur. As Bitkaya transitions from startup to maturity: governance structures will expand (dedicated Risk and Audit functions); manual control testing will evolve into automated workflows; reporting and assurance cycles will increase in frequency and granularity; proportionality justifications will be recalibrated. Continuous learning from audits, stress tests, and CBCS supervisory feedback will inform revisions.

Steps

  1. Define required risk records, owners, data sources, retention, access and quality checks. Records must be sufficient to support risk assessments, approvals, monitoring, client treatment, internal escalations, control testing, remediation, and management oversight.
  2. Document the purpose, ownership, inputs, logic, limitations, calibration and review of material scoring models, rules and decision-support tools. Understand purpose, limitations, calibration, ownership, and review requirements for all tools, scoring models, rule engines, or automated decision-support mechanisms.
  3. Review material changes to risk scoring, monitoring scenarios, sanctions tooling, onboarding logic or other compliance automation, governed appropriately.
  4. Produce timely, accurate and comprehensible management information covering risks, controls, incidents, breaches, trends and remediation. Where relevant, distinguish reporting between: operational incidents; control issues; sanctions matters; internal compliance escalations; external reporting matters; safeguarding incidents; third-party failures; and training or capability weaknesses.
  5. Route material information to accountable management and the Board with clear decisions and follow-up. Material matters should be reported in a manner that supports escalation, accountability, and traceable management action.
  6. Plan second-line monitoring, internal audit or independent external assurance according to risk. Assurance activities should evaluate whether risks are identified and assessed appropriately; controls are designed and operating effectively; reporting and escalation are timely and accurate; remediation actions are tracked and completed; cross-manual consistency is maintained; and significant legal, regulatory, or governance changes are reflected in subordinate manuals, SOPs, and control operation.
  7. Record findings, owners, due dates and verified closure. Findings must be documented, tracked, and reported through the governance framework.
  8. Review the RMF and related policies annually and after material change. Each policy or manual must have a designated owner responsible for periodic review; update following change; consistency with parent and subordinate frameworks; and accurate reflection of current control operation.
  9. Assess cross-manual consistency and update procedures, forms, registers, training and guidance. Where a material change is made to one core manual, assess whether related manuals, SOPs, forms, templates, registers, training materials, and operational guidance must also be updated. Cross-manual inconsistencies should be treated as control weaknesses and addressed promptly.
  10. Document proportionality decisions and reassess them annually as part of the EWRA and whenever significant changes occur (product expansion, regulatory update, or growth in transaction volume). Document proportionality determinations, compensating controls, and rationales in the RMF appendix for regulatory review. Recalibrate proportionality justifications as Bitkaya transitions from startup to maturity.

Exceptions and Escalation

Unreliable data, ungoverned models, material reporting omissions or cross-manual inconsistency shall be recorded and remediated as control weaknesses.

Records

  • Data and record requirements
  • Model and rule inventory and reviews
  • Risk reports and decisions
  • Assurance plans, findings and closure
  • Policy, proportionality and consistency review

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: quarterly reporting, annual review and event-driven updates

History

  • 2026-07-26: Created from sections 11 through 16 of the approved RMF.