Objective
Ensure suspected unusual or suspicious activity is escalated, restricted where needed, reported where required and handled without tipping off.
Control Activity
The MLRO or designated Compliance Officer reviews escalated onboarding, sanctions and monitoring cases, determines and documents clearance, information, EDD, refusal, restriction, senior-management and external-reporting actions, and files required UTRs through the secure FIU portal without delay. Internal SAR, STR, FFR and PNMR labels must remain distinct from the external UTR; FIU, CBCS and sanctions measures are assessed separately and communications prevent tipping off.
FIU Reporting Domains
The reporting process spans three critical compliance domains: Client Onboarding, Sanctions Screening, and Transaction Monitoring (KYT).
Internal Case Classification
Bitkaya may internally classify cases as SAR (Suspicious Activity Report), STR (Suspicious Transaction Report), FFR (Fund Freeze Report), or PNMR (Partial Name Match Report) for case handling, escalation, and recordkeeping purposes. These classifications are internal only. For external purposes, Bitkaya reports to the FIU Curaçao exclusively through a UTR (Unusual Transaction Report), in the prescribed format and through the prescribed channel.
Onboarding Reporting Path
During onboarding, if the customer presents suspicious documentation, behavior, or risk factors inconsistent with their profile:
- Operations requests Compliance to initiate internal review and collects additional documentation if required within 10 days
- If warranted based on the collected information, a UTR is submitted to the FIU Curaçao within 24 hours
Sanctions True-Match Reporting
Where a sanctions alert is confirmed as a true match, Bitkaya shall:
- Immediately apply legally required restrictive measures, including blocking or freezing where applicable
- Escalate the matter internally to Compliance without delay
- Assess and execute applicable external reporting obligations, including to the FIU Curaçao
- Assess and execute applicable notification or reporting obligations to the CBCS
- Document all actions taken, including timing, ownership, rationale, and outcome
Bitkaya distinguishes between: internal sanctions escalation; FIU reporting obligations; CBCS supervisory reporting or notification obligations; and operational freezing or blocking measures. The MLRO or designated Compliance Officer is responsible for coordinating these steps and ensuring that a complete record is maintained.
Temporary Holds, Refusals and Restrictions
Where unusual or suspicious activity is identified through onboarding, sanctions screening, transaction monitoring, wallet review, staff escalation, adverse information, or any other control activity, Bitkaya may temporarily pause, hold, refuse, restrict, or decline a client relationship, transaction, payment, transfer, settlement, wallet setup, or release while Compliance reviews the matter. This may apply where there are unresolved concerns relating to money laundering, terrorist financing, proliferation financing, sanctions evasion, fraud, false or inconsistent information, unexplained source of funds, suspicious wallet exposure, third-party payments, unusual transaction behavior, or other material financial-crime concerns.
The measure must be proportionate to the risk, documented, and escalated to Compliance without delay. Compliance shall review the available information and determine whether the matter can be cleared, requires additional information, requires enhanced due diligence, should be refused or restricted, should be escalated to Senior Management, or should be assessed for external reporting to FIU Curaçao and/or CBCS.
Reporting Principles
- All reports are filed by the MLRO or delegate
- Submissions are made through the FIU Curaçao secure reporting portal
- Documentation includes all internal notes, alerts, and escalation records
- Reports are filed without delay upon determination of suspicion
Anti-Tipping-Off Controls
Where a transaction or relationship is subject to review, staff must avoid tipping off the client or any unauthorized person. Client communication must remain factual, limited, and consistent with Bitkaya’s legal and regulatory obligations.
Evidence
- Expected evidence: case file.
- Expected evidence: MLRO decision.
- Expected evidence: UTR report confirmation.
- Expected evidence: hold/refusal/restriction evidence.
- Expected evidence: communication record.
- Expected evidence: case chronology and reporting-timeliness record.
- Expected evidence: separate FIU, CBCS and sanctions decision records.
- Evidence location: compliance evidence repository and applicable operating system.
- Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
- Testing method: Sample onboarding, sanctions and KYT cases and confirm internal classification, additional-information handling, MLRO decision, any 24-hour post-determination onboarding UTR timing, secure submission, restrictions, FIU/CBCS separation, complete chronology and anti-tipping-off controls.
- Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedures: PROC-AML-005 Perform FIU Reporting and Case Escalation
- Manual coverage: sections 5.1-5.7 and 14.4.1.3.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Expanded classification, timing, restriction, FIU/CBCS separation and anti-tipping-off testing after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.