Purpose
Ensure that third-party banks, payment providers, custodians, wallet providers and similar infrastructure do not undermine safeguarding, control, transparency, or legal compliance. Ensure third-party safeguarding arrangements preserve segregation, legal protection, security, resilience and recoverability.
Scope
Applies to all banks, payment providers, custodians, wallet providers and material safeguarding dependencies used by Bitkaya.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Identify all safeguarding providers and dependencies | Identify all banks, payment providers, custodians, wallet providers and material safeguarding dependencies in a provider inventory. | Provider inventory |
| 2 | Perform risk-based due diligence before use and at least annually | Consider operational reliability and resilience; control environment and security; segregation capability; reporting and statement quality; sanctions and jurisdictional exposure; incident and breach notification arrangements; support for restriction or hold measures; ability to retrieve records and maintain continuity during disruption. | Due diligence and annual review records |
| 3 | Ensure Client Accounts are maintained with duly authorized banks | Banks must be authorized to accept deposits and operate independently from Bitkaya’s corporate group, ensuring objectivity, reduced conflicts of interest, and enhanced security. | Bank authorization and independence evidence |
| 4 | Obtain formal written confirmations from each banking partner | Confirming client money is held in trust for the benefit of clients and is not subject to set-off, liens, or any other claims by the bank. Address set-off, liens and competing claims through approved legal terms. | Bank acknowledgment confirming trust status and no set-off, liens or competing claims; legal review |
| 5 | Ensure Client VA Wallets are managed through reliable, secure wallet providers | Providers must meet stringent due diligence standards, demonstrating strong security protocols, operational resilience, and transparent governance, protecting against theft, hacking, and operational failures. | Wallet provider due diligence and security assessment |
| 6 | Contract for service, control, access, audit, incident, continuity, termination, data-return and exit | Perform regular due diligence reviews and monitoring to ensure ongoing compliance with Bitkaya’s standards and regulatory expectations. | Contracts and control obligations |
| 7 | Monitor service, statements, control changes, incidents and risk | Escalate material deterioration. | Monitoring and escalation records |
| 8 | Maintain tested continuity, provider transition and orderly exit arrangements | Ensure continuity and exit capabilities are tested and effective. | Continuity and exit test evidence |
| 9 | Update the outsourcing register | Retain approvals, reviews and remediation. | Outsourcing register with approvals and reviews |
Records
- Provider inventory and risk assessment
- Due diligence and annual review covering operational reliability, security, segregation, reporting, sanctions exposure, incidents, record retrieval and continuity
- Bank acknowledgment confirming trust status and no set-off, liens or competing claims
- Legal review of bank acknowledgments
- Contract and control obligations including access, audit, incident, continuity, termination, data-return and exit
- Monitoring, continuity and exit test evidence
Relationships
- Policy: POL-SAFU-001 Client Asset Protection and Safeguarding Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Control: CTRL-SAFU-005 Ensure Safeguarding Providers and Continuity Are Controlled
History
- 2026-07-26: Created from sections 8, 12 and 15 of the approved SAFU Manual.