Purpose
Ensure new and transferred personnel receive foundational and role-specific training and demonstrate readiness before working independently in higher-risk activities.
Preconditions
- The person, role, manager, start or transfer date and system access are recorded.
- Required modules and readiness criteria are defined in the approved training matrix.
- Current approved materials and assessors are available.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Assign onboarding modules | Assign foundational onboarding and applicable role-specific modules with explicit due dates. Introduction training must be completed within a reasonable onboarding period defined by management and HR, and completion must be documented. | Training assignment and due date record |
| 2 | Cover required onboarding topics | Cover Bitkaya’s business model, services, governance structure and compliance culture; core conduct expectations including ethics, conflicts of interest, speak-up obligations and accountability; AML/CTF/CPF fundamentals including client due diligence, sanctions awareness, unusual activity escalation and timely documentation; the distinction between internal escalation and external regulatory reporting; data protection, confidentiality and information handling obligations; cybersecurity hygiene, authentication, phishing awareness and secure system use; and reporting lines, approval requirements and key operational procedures relevant to the employee’s role. | Module content and attendance record |
| 3 | Deliver modules and retain evidence | Deliver the modules and retain attendance or completion evidence. | Attendance and completion record |
| 4 | Conduct knowledge checks | Perform knowledge checks and practical or scenario exercises proportionate to role risk. The initial assessment may consider prior experience, qualifications, regulatory exposure, control responsibilities and system access level. | Knowledge-check and scenario results |
| 5 | Confirm role readiness for higher-risk work | For higher-risk work — roles involving elevated risk, client onboarding, transaction handling, approval authority, or access to compliance-sensitive systems — observe practical performance and confirm role readiness before the employee performs the function unsupervised. Require manager sign-off before unsupervised activity or privileged access. | Manager observation and readiness sign-off |
| 6 | Record outcomes | Record completion, results, readiness, restrictions and follow-up actions. | Completion and readiness record |
| 7 | Escalate overdue or unready personnel | Escalate overdue, unsuccessful or unready personnel and apply supervision, access restriction or remediation until readiness is confirmed. | Escalation and remediation record |
Exceptions and Escalation
A temporary onboarding extension requires documented approval and an interim supervision and access plan. Higher-risk work may not be performed unsupervised while readiness is unconfirmed.
Records Created
- Training assignment and due date
- Attendance and completion record
- Knowledge-check and scenario results
- Manager observation and readiness sign-off
- Interim restriction, exception and remediation record
Relationships
- Policy: POL-TRAIN-001 Training and Awareness Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Employee procedure: PROC-EMP-002 Assign Complete and Refresh Employee Training
- Control: CTRL-TRAIN-002 Ensure Onboarding and Role Readiness Are Completed
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: on engagement, transfer, material role change or new higher-risk access
History
- 2026-07-26: Created from sections 3.1, 4.1 and 6.3.1 of the approved Training & Awareness Manual.