Objective

Ensure gifts, hospitality, travel, entertainment and similar benefits are legitimate, proportionate, approved where required and transparently recorded.

Control Activity

Employees apply the ABC decision rules before offering or accepting a benefit. Any gift, hospitality, or benefit must be lawful, reasonable and proportionate, related to a legitimate business purpose, transparent and properly recorded, and not intended to influence an outcome improperly. Always-prohibited items include cash or cash equivalents, luxury travel unrelated to a legitimate business purpose, hospitality during an active approval, licensing, tender, or decision process, personal benefits to family members of a decision-maker, and repeated benefits that cumulatively create the appearance of influence. Managers approve non-sensitive above-routine items, and Compliance pre-approves threshold, public-official, travel, repeated, sensitive or uncertain items. Pre-approval is required above thresholds set by management or when the recipient is a public official, a regulator or supervisory contact, an employee of a state-owned entity, or a person involved in a live approval, negotiation, or decision process affecting Bitkaya. For an unsolicited gift received unexpectedly, the recipient does not use it immediately, tells their manager and Compliance, and Compliance decides whether it may be kept, returned, surrendered, or donated. Required activity is recorded in the Gifts and Hospitality Register, and approvals, refusals, and register entries are retained under Bitkaya’s normal recordkeeping rules.

Evidence

  • Expected evidence: Request and business purpose
  • Expected evidence: Manager or Compliance approval
  • Expected evidence: Refusal, return, surrender or donation decision
  • Expected evidence: Gifts and Hospitality Register entry
  • Expected evidence: Supporting receipt or communication
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: review the register and sample entries for purpose, timing, threshold, sensitive-party assessment, approval and disposition
  • Testing frequency: periodic risk-based review and per identified exception

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-28: Enriched control activity with the full always-prohibited list (section 9.1), pre-approval recipient categories (section 9.2), unsolicited-gift handling (section 22.8) and register retention rule (section 22.10).
  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ABC Manual version 1.0.