Purpose
Detect suspected fraud early, stop affected activity, preserve evidence, coordinate review and learn from cases and near misses.
PDF-Derived Operational Detail
This SOP explains how Bitkaya identifies, reviews, escalates, and responds to fraud risk in a practical and proportionate way. It is intended to help staff recognize fraud indicators early, stop suspicious activity where necessary, and ensure that cases are reviewed by the right people before losses, client harm, or regulatory issues increase. Bitkaya applies this SOP on a proportional basis — as a small VASP, the company does not need a large standalone fraud department, but it does need a clear process for detecting and escalating fraud concerns.
Scope of fraud risk. This SOP applies to fraud risk affecting: client onboarding; account access and authentication; fiat and crypto payments; wallet addresses and withdrawal requests; internal misuse or staff misconduct; phishing, impersonation, and social engineering; vendor or third-party related fraud concerns; and any suspicious activity that may cause financial loss, client harm, or misuse of Bitkaya’s systems.
Basic rule. If there is a credible fraud concern, the case must not continue as normal. The employee handling the case must stop the relevant step, preserve the available evidence, and escalate it. Fraud concerns must never be ignored because the transaction is urgent, commercially important, or requested by a senior person.
Main fraud risk areas. Impersonation of clients or authorized persons; account takeover or unauthorized access; false payment instructions; suspicious withdrawal requests; forged or manipulated onboarding documents; social engineering against staff; misuse of internal access by employees or contractors; third-party fraud involving vendors, introducers, or service providers; and unusual transaction behavior inconsistent with the client profile.
Operational fraud triggers. Sudden change in withdrawal instructions; request to send funds to a new or unrelated account or wallet; unusual urgency or pressure; failed authentication attempts or suspicious login behavior; mismatch between client identity details and transaction behavior; unusual device, location, IP, or session behavior; contradictory explanations or evasive behavior; suspicious document quality or signs of tampering; client claims that they did not authorize activity; repeated failed or blocked transactions followed by a manual override request.
Review and escalation — Compliance. Compliance reviews whether the case may involve fraud; AML / suspicious activity issues; sanctions concerns; client protection issues; or internal misconduct.
Review and escalation — Operations / Finance / IT. Depending on the case, Operations, Finance, or IT should support the review by checking: account activity; payment instructions; wallet details; access logs; system behavior; or prior incidents.
Review and escalation — Senior Management. Senior Management only needs to be involved where: there is material client impact; a significant financial loss may occur; multiple clients may be affected; an internal staff issue is involved; or the case has regulatory, legal, or reputational significance.
Immediate protective actions. Pause onboarding; block or delay a withdrawal; freeze a transaction pending review; require renewed client verification; disable or restrict access; reset credentials or authentication methods; escalate to AML review; escalate to management; or contact the client through a trusted channel for verification. Protective action should be proportionate to the risk and documented.
Internal misuse or staff fraud. If the concern involves an employee, contractor, or internal access misuse: escalate immediately to Compliance and management; restrict access where needed; preserve logs and records; and do not allow the individual to review or control the case alone. Cases involving internal misuse should be handled confidentially and with clear segregation of review.
Recordkeeping. Bitkaya should keep a simple Fraud Incident Log or equivalent record. Minimum information: date; case reference; client / account / transaction reference, where relevant; summary of concern; action taken; who reviewed the case; outcome; and whether further escalation, reporting, or remediation was required. A simple spreadsheet or secure internal log is sufficient at Bitkaya’s current scale.
Links to AML, sanctions, and cybersecurity. Fraud cases may overlap with other control areas. If a case also suggests suspicious activity, sanctions exposure, cybersecurity compromise, or data breach risk, it must also be handled under the relevant Bitkaya procedures. This SOP does not replace AML, sanctions, cybersecurity, incident, or complaints processes — it works alongside them.
Review and learning. Fraud cases should be reviewed periodically to identify: repeated patterns; control weaknesses; training needs; process weaknesses; and whether thresholds, authentication, or approval controls need improvement. Bitkaya does not need a large fraud analytics function at this stage, but it should still learn from incidents and near misses.
Steps
- Monitor onboarding, authentication, payments, wallets, withdrawals, staff access and third-party activity for fraud indicators. Specific fraud risk areas: impersonation of clients or authorized persons; account takeover or unauthorized access; false payment instructions; suspicious withdrawal requests; forged or manipulated onboarding documents; social engineering against staff; misuse of internal access by employees or contractors; third-party fraud involving vendors, introducers, or service providers; unusual transaction behavior inconsistent with the client profile.
- When a credible concern appears, stop the relevant step and avoid tipping off the client or third party. The case must not continue as normal — the employee handling the case must stop the relevant step, preserve available evidence, and escalate it. Fraud concerns must never be ignored because the transaction is urgent, commercially important, or requested by a senior person.
- Preserve messages, documents, screenshots, logs, account, wallet and transaction references.
- Escalate immediately to Compliance and the responsible Operations, Finance or Technology function. Compliance reviews whether the case may involve fraud, AML/suspicious activity issues, sanctions concerns, client protection issues, or internal misconduct. Operations, Finance, or IT should support the review by checking account activity, payment instructions, wallet details, access logs, system behavior, or prior incidents.
- Assess fraud, suspicious activity, sanctions, client-protection, cybersecurity, data-breach and internal-misuse implications. If a case also suggests suspicious activity, sanctions exposure, cybersecurity compromise, or data breach risk, it must also be handled under the relevant Bitkaya procedures. This SOP does not replace AML, sanctions, cybersecurity, incident, or complaints processes.
- Apply proportionate protective action such as: pausing onboarding; blocking or delaying a withdrawal; freezing a transaction pending review; requiring renewed client verification; disabling or restricting access; resetting credentials or authentication methods; escalating to AML review; escalating to management; or contacting the client through a trusted channel for verification. Protective action should be proportionate to the risk and documented.
- Segregate review and restrict access where an employee or contractor may be involved. Escalate immediately to Compliance and management; restrict access where needed; preserve logs and records; and do not allow the individual to review or control the case alone. Handle cases involving internal misuse confidentially and with clear segregation of review.
- Escalate material client impact, loss, multiple-client exposure or legal, regulatory or reputational significance to Senior Management. Senior Management involvement is required where: there is material client impact; a significant financial loss may occur; multiple clients may be affected; an internal staff issue is involved; or the case has regulatory, legal, or reputational significance.
- Record the case in the Fraud Incident Log with: date; case reference; client / account / transaction reference, where relevant; summary of concern; action taken; who reviewed the case; outcome; and whether further escalation, reporting, or remediation was required. A simple spreadsheet or secure internal log is sufficient at Bitkaya’s current scale.
- Review patterns and near misses periodically to identify: repeated patterns; control weaknesses; training needs; process weaknesses; and whether thresholds, authentication, or approval controls need improvement. Update authentication, thresholds, controls, training or procedures accordingly.
Exceptions and Escalation
Commercial importance, urgency or seniority shall not override a credible fraud concern. Funds, access or case clearance shall not be released without authorized direction.
Records
- Fraud incident log
- Preserved evidence and transaction references
- Review, protective action and approval
- AML, sanctions, cyber or employee escalation
- Outcome, reporting, remediation and learning
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Control: CTRL-RMF-009 Ensure Fraud Concerns Are Stopped Escalated and Recorded
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: continuous and event-driven
History
- 2026-07-26: Created from section 17 of the approved RMF.