Purpose
Deliver current recurring and specialist training at the frequency and depth required by each role’s responsibilities and risk exposure.
Preconditions
- The approved matrix identifies the audience, content, frequency, due date and assessment.
- Subject-matter owners have confirmed that the materials reflect current policy, procedures, tools and risks.
- Personnel population and prior completion records are current.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Assign refresher training | Assign annual refresher training to all personnel and semiannual training to documented high-risk functions. Ongoing training shall reinforce updates to laws, regulations and internal policies; changes in Bitkaya’s risk profile or control environment; lessons learned from incidents, findings, control failures or near misses; changes to systems, onboarding tools, screening tools, monitoring tools or workflows; and practical expectations regarding escalation, documentation, client treatment and control compliance. | Assignment and audience list |
| 2 | Assign role-specific modules | Compliance and Risk Management — AML/CTF/CPF obligations, sanctions screening, internal case handling, unusual transaction escalation, UTR reporting requirements, client risk scoring, KYV expectations, false positive closure, unresolved alert handling and documentation standards. Operations, Trading and Client-Facing Teams — onboarding controls, required file content, source of funds and source of wealth expectations, transaction-monitoring escalation, wallet and payment red flags, sanctions stop rules, client communications and when to escalate to Compliance. Cybersecurity and IT — secure access controls, privileged access, system logging, security monitoring, cyber incident escalation, data confidentiality, system resilience and support for compliance tooling. Finance Function — financial controls, payment anomalies, suspicious payment patterns, recordkeeping, escalation of unusual reimbursement or invoice activity and interaction with AML/CTF/CPF and ABC controls. Senior Management and Board — governance responsibilities, oversight obligations, reporting expectations, approval thresholds and the relationship between Bitkaya’s control frameworks and regulatory accountability. | Role-specific module assignments |
| 3 | Deliver targeted training after change | Deliver targeted training promptly after material legal, policy, system, workflow, incident or risk change. Where policy or tool changes materially affect control operation, targeted refresher training or operational guidance shall be delivered without waiting for the next annual cycle. Specialized training shall be proportionate to the role and refreshed as necessary when responsibilities, systems or risk exposures materially change. | Delivered material version and trainer record |
| 4 | Include practical expectations | Include practical stop, escalation, documentation and evidence expectations relevant to the role. | Module content with practical expectations |
| 5 | Conduct knowledge checks | Conduct a knowledge check after each module and retain results. | Knowledge-check results |
| 6 | Monitor completion | Monitor completion against due dates and escalate overdue or unsuccessful items. | Reminder, overdue and escalation record |
| 7 | Feed gaps into programme review | Feed content defects, repeated questions and observed gaps into assessment, remediation and programme review. | Content issue and update record |
Exceptions and Escalation
Substitute delivery methods must cover the same approved learning outcomes and assessment. Material delay, repeated non-completion or inaccurate content shall be escalated to Compliance, the Department Head and management.
Records Created
- Assignment and audience list
- Delivered material version and trainer record
- Attendance, completion and knowledge-check results
- Reminder, overdue and escalation record
- Content issue and update record
Relationships
- Policy: POL-TRAIN-001 Training and Awareness Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- AML training: PROC-AML-008 Deliver AML Training and Awareness
- Control: CTRL-TRAIN-003 Ensure Recurring and Role Specific Training Is Completed
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: annual for all personnel, semiannual for high-risk functions and after material change
History
- 2026-07-26: Created from sections 3.2, 3.3 and 6.3.1 of the approved Training & Awareness Manual.