Objective
Ensure Bitkaya maintains a current AML/CTF/CPF risk assessment and uses SARA outcomes to calibrate risk-based controls.
Control Activity
Compliance confirms at least annually and after material trigger events that the enterprise and client SARA assessments are complete, formally scored, reconciled, approved and retained. The review must document rationale, evidence, limitations and overrides, update the risk register, and show how residual risk changed client classification, CDD/EDD, review cycles, sanctions, KYT thresholds, training, independent testing, resources and management reporting.
EWRA Risk Domains
The EWRA assesses inherent risk and control effectiveness across five key domains:
- Customer base
- Nature of services and products
- Geographic exposure
- Delivery channels
- Transactional behavior
Each domain is scored for inherent likelihood and impact, with control effectiveness applied to determine residual risk.
SARA Scoring Methodology
The SARA model distinguishes between individual risk-factor scores and the final client risk score. Individual risk factors may show raw or residual scores above 25 where the factor represents a high-severity risk indicator (sanctions exposure, PEP exposure, cash activity, complex structures, fiat red flags, high-risk wallet exposure). The final client risk score is calculated as a weighted residual score across five main risk categories:
- Geographical Risk
- Customer Risk
- Product Risk
- Transaction Risk
- Delivery Channel Risk
For each applicable factor, inherent risk is calculated by multiplying likelihood by impact. Residual risk is then calculated by applying the relevant control-effectiveness factor. Applicable residual factor risks are aggregated by category and weighted according to the category weights in the SARA model. The final weighted residual score determines the client risk rating, subject to documented Compliance judgement and any mandatory escalation, refusal, restriction, or prohibited-relationship rule.
Risk Rating Thresholds
Unless otherwise approved by Compliance and documented in the SARA methodology:
- Low Risk: final weighted residual score of 6 or below
- Medium Risk: final weighted residual score above 6 and up to 12
- High Risk: final weighted residual score above 12
Where the raw SARA output, final weighted residual score and final client classification differ materially, the rationale must be documented. Any threshold discrepancy is tracked under ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds.
SARA Governance
SARA requires systematic identification and documentation of risks, evaluation of control adequacy and effectiveness, prioritization of mitigation efforts based on residual risk levels, and ongoing update of risk ratings at both the enterprise and client levels. SARA emphasizes formal scoring methods, maintenance of a risk register, independent testing of controls, and documentation of rationale and evidence for ratings. Risk assessment results are reviewed by the Compliance Officer/MLRO, the Compliance Committee (based on proportionality principle), and the Board of Directors.
Trigger Events
Trigger events requiring SARA review or update include, where relevant, material changes in Bitkaya’s business model, products, services, client base, jurisdictions, transaction volumes, delivery channels, wallet arrangements, outsourcing or technology arrangements, regulatory requirements, sanctions exposure, typologies, significant incidents, internal control findings, independent testing results, CBCS or FIU feedback, or other material changes affecting AML/CTF/CPF risk.
Proportionality in EWRA
Under the proportionality framework, the EWRA process follows the CBCS SARA model but uses simplified quantitative scoring suitable for a startup structure. Data-driven tools automate client and transaction risk classification. Annual EWRA updates suffice unless there is a significant change in product scope, volume, or jurisdictional exposure.
Evidence
- Expected evidence: SARA/EWRA assessment.
- Expected evidence: risk register.
- Expected evidence: approval record.
- Expected evidence: control calibration evidence.
- Expected evidence: trigger-event assessment and documented overrides.
- Expected evidence: enterprise-to-client risk alignment and downstream implementation record.
- Evidence location: compliance evidence repository and applicable operating system.
- Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
- Testing method: Sample the latest annual and any material trigger-based assessment; confirm all five risk domains (customer base, nature of services/products, geographic exposure, delivery channels, transactional behavior), inherent and residual scoring, control-effectiveness input, rationale, approvals, risk-register changes and downstream calibration. Confirm the configured client thresholds agree with the separately approved SARA methodology and investigate any variance under ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds.
- Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedures: PROC-AML-001 Maintain AML Risk Assessment and SARA Calibration
- Manual coverage: sections 3.1-3.6 and 14.4-14.5.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Expanded SARA governance, trigger, documentation, downstream calibration and threshold-consistency testing after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.