Purpose
Maintain vigilance between formal training cycles through timely, targeted and evidenced awareness activity.
Preconditions
- Current threats, regulatory updates, incidents, findings and control changes are available.
- Target audiences and communication channels are approved.
- Awareness content has an accountable subject-matter owner.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Maintain quarterly awareness calendar | Maintain a quarterly awareness calendar covering relevant cyber, privacy, fraud, AML/CFT, sanctions, conduct, safeguarding and resilience topics. Proportional awareness efforts include quarterly awareness campaigns on topics such as phishing, data privacy and fraud prevention; targeted memos or posters reinforcing key compliance messages; and all-hands sessions to discuss regulatory updates or new operational risks. | Awareness calendar |
| 2 | Select topics | Select topics using current threats, incidents, near misses, audit findings, regulator observations and control weaknesses. Awareness measures may include security bulletins on cyber threats, phishing, fraud patterns and operational vulnerabilities; short compliance updates on regulatory changes, sanctions developments and control reminders; thematic awareness campaigns on topics such as insider risk, fraud, client protection, escalation quality and documentation discipline; scenario-based reminders based on actual incidents, near misses, audit findings or regulatory observations; and targeted reminders following material updates to systems, procedures, sanctions lists, onboarding requirements or escalation workflows. | Topic selection rationale |
| 3 | Prepare concise content | Prepare concise content with the required action, escalation route and policy or procedure reference. Where relevant, awareness communications should reinforce the distinction between internal case escalation, internal case classification, external UTR reporting and other regulatory or supervisory notification obligations. | Approved communication and version |
| 4 | Obtain review before release | Obtain subject-matter and Compliance review before release. | Review and approval record |
| 5 | Distribute and retain evidence | Distribute through approved channels and retain the content, date, audience and delivery evidence. | Audience and distribution evidence |
| 6 | Issue event-driven updates | Issue event-driven updates promptly after material regulatory, sanctions-list, system, procedure or risk change. | Event trigger and response record |
| 7 | Escalate to formal training where required | Escalate topics requiring formal assessed training to PROC-TRAIN-003 rather than relying on awareness alone. As Bitkaya scales, awareness programs will expand to include ESG, data ethics and cross-border regulatory awareness. | Escalation to formal training record |
Exceptions and Escalation
Missed quarterly activity, incomplete audience coverage or material inaccuracies shall be escalated to Compliance and management and corrected promptly.
Records Created
- Awareness calendar
- Approved communication and version
- Audience and distribution evidence
- Event trigger and response record
- Escalation to formal training where required
Relationships
- Policy: POL-TRAIN-001 Training and Awareness Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-TRAIN-004 Ensure Quarterly Awareness Activity Occurs
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: at least quarterly and after material events
History
- 2026-07-26: Created from sections 3.4 and 6.3.2 of the approved Training & Awareness Manual.