Purpose

Maintain accountable safeguarding governance, competence, oversight and risk-based scalability for the protection, handling, safeguarding, recording, and controlled movement of client money and virtual assets. Safeguarding governance must ensure that client asset protection is managed not only as an accounting or custody function, but also as a legal, compliance, operational, and client protection responsibility.

Scope

This procedure applies to all employees, officers, directors, contractors, and relevant third parties involved in client asset handling, wallet operations, payment flows, reconciliations, authorizations, monitoring, or reporting.

Steps

#ActionDetailsEvidence
1Designate the DSO and a documented backupThe DSO oversees client asset protection, reconciliations, and custody integrity. Maintain a role and segregation-of-duties matrix documenting responsibilities for all safeguarding functions.Role and segregation-of-duties matrix; DSO designation record
2Maintain the client-asset inventoryLiving register of services, accounts, wallets, providers, systems and risks; updated when new items are introduced.Client-asset inventory register
3Report to management and the Board at least quarterlyCover segregation and reconciliation performance; safeguarding incidents and near misses; withdrawal and transfer exceptions; unresolved restrictions, holds, or breaks; third-party dependency risk; interaction between safeguarding and compliance controls; and remediation actions.Quarterly Board reporting
4Provide mandatory safeguarding onboarding trainingCover client asset protection principles; AML and CFT integration; safeguarding protocols and escalation procedures. Refresh annually with certification or acknowledgment.Training, certification and acknowledgment records
5Provide enhanced role-specific trainingFor employees in sensitive roles (finance, custody operations, compliance, IT security), tailored to their safeguarding responsibilities.Role-specific training records
6Implement ongoing awareness initiativesReinforce key safeguarding principles, emphasizing clear separation between client assets and Bitkaya’s own assets.Awareness initiative records
7Record training completion and competenceRecord training completion, staff acknowledgments and competence assessment results; maintain subject to audit.Training, acknowledgment and competence assessment records
8Review proportionality annually or after significant changesTriggered by business scale changes, regulatory updates or CBCS guidance, operational or cybersecurity incidents, new custody providers, or new jurisdictions. Head of Risk & Compliance reviews and reports to Board.Annual proportionality review and Board report
9Obtain Board approval for material proportionality adjustmentsCovers frequency of reconciliations, staffing allocation, automation thresholds, or other control changes.Board approval record
10Document and approve proportionality decisionsApproved by DSO and Board. Retain justifications, control adjustments and audit evidence for at least five (5) years.Proportionality decision records with justifications and audit evidence (5-year retention)
11Maintain version control logRecord all manual changes, effective dates and approving authorities. Manual updates approved by Board and communicated to all staff.Version control log

Records

  • Role and segregation-of-duties matrix
  • Safeguarding inventory and risk assessment
  • Quarterly Board reporting covering segregation, reconciliation, incidents, exceptions, third-party risks and remediation
  • Training, acknowledgment, certification and competence assessment records
  • Annual proportionality review, Board approval and supporting justifications
  • Version control log for manual changes

Relationships

History

  • 2026-07-26: Created from sections 11-12, 16 and 18 of the approved SAFU Manual.