Purpose

Ensure that third-party banks, payment providers, custodians, wallet providers and similar infrastructure do not undermine safeguarding, control, transparency, or legal compliance. Ensure third-party safeguarding arrangements preserve segregation, legal protection, security, resilience and recoverability.

Scope

Applies to all banks, payment providers, custodians, wallet providers and material safeguarding dependencies used by Bitkaya.

Steps

#ActionDetailsEvidence
1Identify all safeguarding providers and dependenciesIdentify all banks, payment providers, custodians, wallet providers and material safeguarding dependencies in a provider inventory.Provider inventory
2Perform risk-based due diligence before use and at least annuallyConsider operational reliability and resilience; control environment and security; segregation capability; reporting and statement quality; sanctions and jurisdictional exposure; incident and breach notification arrangements; support for restriction or hold measures; ability to retrieve records and maintain continuity during disruption.Due diligence and annual review records
3Ensure Client Accounts are maintained with duly authorized banksBanks must be authorized to accept deposits and operate independently from Bitkaya’s corporate group, ensuring objectivity, reduced conflicts of interest, and enhanced security.Bank authorization and independence evidence
4Obtain formal written confirmations from each banking partnerConfirming client money is held in trust for the benefit of clients and is not subject to set-off, liens, or any other claims by the bank. Address set-off, liens and competing claims through approved legal terms.Bank acknowledgment confirming trust status and no set-off, liens or competing claims; legal review
5Ensure Client VA Wallets are managed through reliable, secure wallet providersProviders must meet stringent due diligence standards, demonstrating strong security protocols, operational resilience, and transparent governance, protecting against theft, hacking, and operational failures.Wallet provider due diligence and security assessment
6Contract for service, control, access, audit, incident, continuity, termination, data-return and exitPerform regular due diligence reviews and monitoring to ensure ongoing compliance with Bitkaya’s standards and regulatory expectations.Contracts and control obligations
7Monitor service, statements, control changes, incidents and riskEscalate material deterioration.Monitoring and escalation records
8Maintain tested continuity, provider transition and orderly exit arrangementsEnsure continuity and exit capabilities are tested and effective.Continuity and exit test evidence
9Update the outsourcing registerRetain approvals, reviews and remediation.Outsourcing register with approvals and reviews

Records

  • Provider inventory and risk assessment
  • Due diligence and annual review covering operational reliability, security, segregation, reporting, sanctions exposure, incidents, record retrieval and continuity
  • Bank acknowledgment confirming trust status and no set-off, liens or competing claims
  • Legal review of bank acknowledgments
  • Contract and control obligations including access, audit, incident, continuity, termination, data-return and exit
  • Monitoring, continuity and exit test evidence

Relationships

History

  • 2026-07-26: Created from sections 8, 12 and 15 of the approved SAFU Manual.