Objective

Ensure AML/CTF/CPF records are complete, secure and retrievable for audit, management and regulatory purposes.

Control Activity

Compliance confirms required client, transaction, screening, monitoring, case, UTR, restrictive-measure, decision, training and assurance records are complete and retained in approved systems. Records are protected through role-based access, logging, audit trails and regular backup; five-year and conditional ten-year periods are applied; and records can be reconstructed and produced without undue delay.

What Bitkaya Retains

Record TypeDescription
KYC and CDD FilesIdentification documents, UBO declarations, proof of address, onboarding notes, etc.
Client Risk AssessmentsRisk scores, profiling justifications, review history
Transaction RecordsFiat and crypto transaction logs, timestamps, wallet addresses, counterparties
Sanctions Screening ResultsMatches, resolution outcomes, freezing actions
UTR ReportsSubmitted reports, internal alerts, supporting documentation
Monitoring Logs (KYT)Alerts, case reviews, and escalation notes
Compliance DecisionsApprovals, rejections, EDD files, onboarding committee minutes
Training and Staff RecordsAttendance logs, course content, certifications

Retention Periods

  • All client and transaction records must be kept for at least five (5) years from the end of the relationship or the last transaction, whichever is later.
  • If a transaction is reported to investigative authorities (such as the FIU, Public Prosecutor, or Police), records must instead be kept for ten (10) years if instructed by the FIU.
  • CDD information must also be retained for at least five (5) years after the end of the business relationship.

Security and Integrity

  • All records are stored digitally in Bitkaya’s secure compliance archive, integrated with the ERP system
  • Access is role-based and logged
  • Monthly backups are maintained and stored off-site
  • Audit trails are preserved to document every critical access, update, or deletion attempt

Review and Oversight

  • The Compliance Officer is responsible for overseeing the recordkeeping framework
  • Internal audits are conducted at least annually to verify the integrity and completeness of records
  • Bitkaya ensures that all retained data is available for inspection by the CBCS and FIU Curaçao upon request, without undue delay

Evidence

  • Expected evidence: record inventory.
  • Expected evidence: sample retrieved records.
  • Expected evidence: access-control evidence.
  • Expected evidence: gap remediation record.
  • Expected evidence: retention calculation and disposal hold.
  • Expected evidence: audit log, monthly off-site backup and restore evidence.
  • Evidence location: compliance evidence repository and applicable operating system.
  • Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
  • Testing method: Select representative records across all AML categories and confirm completeness, linkage, five- or ten-year retention calculation, role-based access, audit trail, monthly off-site backup, restoration evidence and timely retrieval for CBCS or FIU inspection.
  • Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Added record-category, retention-period, access, audit-trail, backup, restore and reconstruction testing after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.