Purpose
Protect client assets during breaches, distress and resolution and obtain independent assurance over safeguarding effectiveness. Compliance and audit processes are essential to ensuring that Bitkaya consistently upholds its obligations to safeguard client assets, reinforcing accountability, transparency, and adherence to regulatory requirements.
Scope
Applies to all safeguarding breaches, near misses, unauthorized movements, reconciliation failures, unexplained shortfalls, unauthorized access events, material control failures, insolvency or resolution events, and internal or external audit activities.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Escalate any safeguarding breach, near miss, or control failure immediately | Covers unauthorized movement, reconciliation failure, unexplained shortfall, unauthorized access event, or material control failure affecting client assets. | Incident, restriction, isolation and evidence record |
| 2 | Isolate or restrict affected assets and preserve records and evidence | Assess whether client assets must be restricted, isolated, or otherwise protected. | Restriction, isolation and evidence preservation records |
| 3 | Assess the safeguarding impact and associated dimensions | Assess immediate safeguarding impact; any associated fraud, cybersecurity, AML/CTF/CPF, or sanctions dimension; regulatory reporting or notification obligations; and whether client communication is required and legally permissible. | Impact assessment covering safeguarding, fraud, cybersecurity, AML, sanctions, regulatory reporting and communication |
| 4 | Notify management, the Board, regulators (including CBCS) and clients | Notify immediately in line with applicable legal requirements. Clients promptly where authorized, providing transparent communication on asset status and recovery process. | Notification and reporting decisions (management, Board, CBCS, clients) |
| 5 | Investigate breaches, discrepancies, or deficiencies without delay | Perform root-cause analysis, assign remediation, and verify closure and effectiveness. Follow-up monitoring must ensure the issue is fully resolved. | Root cause analysis, corrective actions and remediation tracking |
| 6 | Document corrective actions, root cause analysis, and remediation tracking | Monitor to closure. | Remediation tracking and closure records |
| 7 | Maintain and test contingency plans for orderly return of client assets in insolvency | Resolution plan includes documented procedures for asset distribution, communication protocols, and regulator coordination. Client assets legally and operationally segregated from Bitkaya’s own estate and excluded from creditor claims. Maintain trust or equivalent legal structures establishing clients as beneficial owners. | Resolution and orderly-return contingency plan and test results |
| 8 | Establish and maintain comprehensive policies, procedures, and systems | Align with this manual and applicable regulatory frameworks, covering all aspects of client asset safeguarding from segregation to reporting. | Policy and procedure maintenance records |
| 9 | Obtain scheduled independent reviews | Performed internally or by external auditors on a scheduled basis. Audits assess compliance, test safeguard effectiveness, and provide improvement recommendations. Independent audit coverage initially focused on custody and reconciliation, later broadened to automated systems and third-party integrations. | Audit plan, independent review report and follow-up to closure |
| 10 | Feed lessons learned into policy, training, and system enhancements | Ensure Bitkaya continually strengthens its safeguarding framework and adapts to evolving regulatory and operational risks. | Continuous improvement inputs (policy, training, system enhancements) |
Records
- Incident, restriction, isolation and evidence record
- Impact assessment covering safeguarding, fraud, cybersecurity, AML, sanctions, regulatory reporting and communication
- Notification and reporting decisions (management, Board, CBCS, clients)
- Root cause analysis, corrective actions and remediation tracking
- Resolution and orderly-return contingency plan and test results
- Audit plan, independent review report and follow-up to closure
- Continuous improvement inputs (policy, training, system enhancements)
Relationships
- Policy: POL-SAFU-001 Client Asset Protection and Safeguarding Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Control: CTRL-SAFU-008 Ensure Safeguarding Breaches Resolution and Assurance Are Effective
History
- 2026-07-26: Created from sections 9, 15 and 17-18 of the approved SAFU Manual.