Objective
Ensure clients are not activated until required CDD, EDD, risk classification and approvals are complete.
Control Activity
Before CRM activation or portal access, Operations and Compliance confirm the client file contains the identity, liveness or legal-existence, ownership, authority, screening, relationship-purpose, expected-activity, risk-profile and approval evidence required for the applicable tier. Medium-risk files include the additional residence or corporate, source-of-funds and expected-activity evidence; high-risk files include EDD, verified source-of-funds/source-of-wealth, enhanced ownership and both Compliance and management approval. The next review date must reflect the approved three-year, two-year or annual cycle.
Detailed Control Requirements
Pre-Activation Gates
Before a client is tagged as “Client” in the CRM, granted portal access, or sent a welcome email, the following must be verified:
- Identity verification complete — individual liveness/ID verification report on file, or entity legal-existence documentation on file
- Sanctions screening clear — all required parties screened, no unresolved alerts or true matches pending escalation
- SARA risk profile completed — risk score calculated, risk tier assigned, and any Compliance judgement or override documented
- Tier-specific evidence complete — all minimum file requirements for the assigned risk tier are present in the CRM
- Approval obtained — management approval for low/medium risk; both Compliance and management approval for high risk
- Acceptance decision recorded — client acceptance status, approvers, rationale, date, risk tier, and next review date logged by the approving function
- No prohibited-jurisdiction exposure — client, UBOs, counterparties, and transaction routing are not associated with any prohibited jurisdiction
Tier-Specific Evidence Requirements
Low-risk clients:
- Identity: valid passport, ID card, or driver’s license (individuals); corporate registry extract (entities)
- Liveness: identity/liveness verification result (individuals)
- Legal existence: registration documentation (entities)
- Ownership: signed UBO declaration (entities)
- Authority: ID of authorized signatory/representative (entities)
- Screening: sanctions/PEP screening results for client, signatory, and declared UBOs
- Relationship purpose: documented purpose and intended nature of the relationship
- Expected activity: basic client profile on file
- Risk profile: completed SARA risk profile with low-risk classification
- Approval: management approval
Medium-risk clients (all low-risk items plus):
- Residence/ownership: proof of residence (individuals); articles of incorporation, shareholder register (entities)
- Source of funds: self-declaration on file
- Expected activity: additional detail on expected transaction activity
- Adverse information: adverse-information review where relevant
- Risk profile: completed SARA risk profile with medium-risk classification
- Approval: management approval
High-risk clients (all medium-risk items plus):
- Source of wealth: information and supporting documentation, assessed before approval
- Enhanced source of funds: enhanced review where appropriate
- Enhanced ownership: ownership and control documentation for all relevant layers
- Blockchain tracing: standard (up to 3 hops) or enhanced (up to 6 hops) tracing where required, with approach and rationale documented
- Enhanced transaction controls: applied during onboarding and throughout the relationship
- Risk profile: completed SARA risk profile with high-risk classification
- Approval: both Compliance and management approval before onboarding
Sanctions Screening Verification
Before activation, verify that sanctions screening has been conducted against all required parties and lists:
- Parties screened: client, UBOs, directors/authorized representatives/signatories, intermediaries, VASP counterparties, wallet addresses/blockchain identifiers, bank-account holders/payment counterparties (where applicable)
- Lists covered: UN and EU sanctions lists (minimum); OFAC, CFATF, Curaçao/Kingdom/local lists, and internal restricted-party lists where applicable to the business, client base, counterparties, jurisdictions, or risk profile
- No unresolved alerts: all alerts either resolved (with false-positive closure documented) or escalated; no unresolved alert remains that would block activation
- True-match handling: where a true match was identified, verify that restrictive measures (blocking, freezing, refusal) were applied and FIU Curaçao/CBCS reporting obligations were met
See PROC-AML-003 Perform Sanctions Screening and Restrictive Measures Escalation for the full escalation procedure.
SARA Profile Verification
Verify that the client SARA risk profile is completed with the correct factors:
- EWRA factors assessed: client type/ownership/PEP exposure, onboarding method, geographic/jurisdictional exposure, products/services, transactional behavior, delivery channel
- Scoring methodology applied: inherent risk (likelihood × impact) → residual risk (with control-effectiveness factor) → weighted category aggregation across Geographical, Customer, Product, Transaction, and Delivery Channel Risk
- Risk tier assigned: Low (≤ 6), Medium (> 6 to ≤ 12), High (> 12) per SARA methodology — subject to documented threshold reconciliation under ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds
- Discrepancies documented: where the raw SARA output, final weighted residual score, and final client classification differ materially, the rationale is documented
- Compliance judgement recorded: any Compliance override or judgement is documented in the CRM file
Approval Requirements
Verify that the correct approval level was obtained before activation:
- Low-risk clients: management approval required
- Medium-risk clients: management approval required
- High-risk clients: both Compliance and management approval required — source of wealth must be assessed before approval
The approval record must include approver identity, approval date, rationale, risk tier, and next review date.
Review Cycle Verification
Confirm that the next review date in the CRM matches the client’s assigned risk tier:
- Low-risk: next review 3 years from acceptance date
- Medium-risk: next review 2 years from acceptance date
- High-risk: next review 1 year (annually) from acceptance date
Verify that any documented trigger event (material profile change, sanctions list update, adverse information, suspicious activity) has been assessed for whether an earlier review is required regardless of the scheduled cycle.
Evidence
- Expected evidence: client file checklist.
- Expected evidence: verification report.
- Expected evidence: screening result.
- Expected evidence: risk profile.
- Expected evidence: approval record.
- Expected evidence: preliminary-to-final risk comparison and documented overrides.
- Expected evidence: risk-tier checklist, acceptance date and next-review date.
- Evidence location: compliance evidence repository and applicable operating system.
- Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
- Testing method: Sample individual and corporate clients across all risk tiers and confirm the tier-specific file, screening, SARA, approval and review-cycle requirements were completed before Client tagging, portal access or service activation. Confirm SDD retains core CDD and that any threshold discrepancy is tracked under ISS-AML-001 Reconcile AML Manual Client Risk Rating Thresholds.
- Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedures: PROC-AML-002 Perform Client Acceptance CDD EDD and Risk Classification
- Manual coverage: sections 4.1-4.4, 12 and 14.4.1.2.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Expanded risk-tier file, approval, activation-gate and periodic-review testing after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.