Objective
Ensure relevant third parties are risk-classified, checked, approved, contracted and reviewed before they expose Bitkaya to bribery or corruption risk.
Control Activity
The business owner completes documented risk-based due diligence before engagement. Due diligence covers, where appropriate: identity and legal status; ownership and control structure; qualifications and business rationale; adverse information and reputation checks; sanctions and watchlist screening; conflicts of interest; compensation model and commercial rationale; subcontracting or agency arrangements; and enforcement history or misconduct concerns. Enhanced review is required when the third party interacts with public officials, compensation is unusually high, success-based, or opaque, the services are vague or difficult to evidence, the third party operates in a higher-risk jurisdiction, or there are material reputation, ownership, or transparency concerns. Compliance reviews medium, unclear, public-official and high-risk exposure; Senior Management approves high-risk cases. If the third party will interact with a public official or regulator on Bitkaya’s behalf, Compliance approval is always mandatory. Relevant contracts include proportionate ABC safeguards — ABC compliance undertakings, information and audit rights, restrictions on subcontracting without approval, breach notification obligations, and termination rights in the event of misconduct or non-cooperation. Trigger or renewal reviews reassess risk when ownership changes, scope changes, payment behavior becomes unusual, adverse media appears, misconduct concerns arise, or the contract is renewed.
Evidence
- Expected evidence: Risk classification and business rationale
- Expected evidence: Identity, ownership, sanctions, adverse-media and conflict checks
- Expected evidence: Compensation and red-flag review
- Expected evidence: Required approvals
- Expected evidence: ABC contract clauses
- Expected evidence: Trigger and renewal review
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample relevant third parties and trace due diligence, approval, contract safeguards and monitoring to the risk classification
- Testing frequency: before engagement and on material trigger or renewal
Relationships
- Requirements: REQ-VASP-005 Maintain Integrity Based Business Operations, REQ-OUT-004 Perform Service Provider Due Diligence
- Policy: POL-ABC-001 Anti-Bribery and Corruption Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedure: PROC-ABC-002 Perform Third-Party and Intermediary ABC Due Diligence
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-28: Enriched control activity with the full 9-point due diligence scope (section 8), enhanced-review triggers (section 8.1), contractual safeguard list (section 8.2) and ongoing-monitoring triggers (section 8.3).
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved ABC Manual version 1.0.