Objective

Ensure relevant third parties are risk-classified, checked, approved, contracted and reviewed before they expose Bitkaya to bribery or corruption risk.

Control Activity

The business owner completes documented risk-based due diligence before engagement. Due diligence covers, where appropriate: identity and legal status; ownership and control structure; qualifications and business rationale; adverse information and reputation checks; sanctions and watchlist screening; conflicts of interest; compensation model and commercial rationale; subcontracting or agency arrangements; and enforcement history or misconduct concerns. Enhanced review is required when the third party interacts with public officials, compensation is unusually high, success-based, or opaque, the services are vague or difficult to evidence, the third party operates in a higher-risk jurisdiction, or there are material reputation, ownership, or transparency concerns. Compliance reviews medium, unclear, public-official and high-risk exposure; Senior Management approves high-risk cases. If the third party will interact with a public official or regulator on Bitkaya’s behalf, Compliance approval is always mandatory. Relevant contracts include proportionate ABC safeguards — ABC compliance undertakings, information and audit rights, restrictions on subcontracting without approval, breach notification obligations, and termination rights in the event of misconduct or non-cooperation. Trigger or renewal reviews reassess risk when ownership changes, scope changes, payment behavior becomes unusual, adverse media appears, misconduct concerns arise, or the contract is renewed.

Evidence

  • Expected evidence: Risk classification and business rationale
  • Expected evidence: Identity, ownership, sanctions, adverse-media and conflict checks
  • Expected evidence: Compensation and red-flag review
  • Expected evidence: Required approvals
  • Expected evidence: ABC contract clauses
  • Expected evidence: Trigger and renewal review
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample relevant third parties and trace due diligence, approval, contract safeguards and monitoring to the risk classification
  • Testing frequency: before engagement and on material trigger or renewal

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-28: Enriched control activity with the full 9-point due diligence scope (section 8), enhanced-review triggers (section 8.1), contractual safeguard list (section 8.2) and ongoing-monitoring triggers (section 8.3).
  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ABC Manual version 1.0.