Objective
Ensure AML/CTF/CPF records are complete, secure and retrievable for audit, management and regulatory purposes.
Control Activity
Compliance confirms required client, transaction, screening, monitoring, case, UTR, restrictive-measure, decision, training and assurance records are complete and retained in approved systems. Records are protected through role-based access, logging, audit trails and regular backup; five-year and conditional ten-year periods are applied; and records can be reconstructed and produced without undue delay.
What Bitkaya Retains
| Record Type | Description |
|---|---|
| KYC and CDD Files | Identification documents, UBO declarations, proof of address, onboarding notes, etc. |
| Client Risk Assessments | Risk scores, profiling justifications, review history |
| Transaction Records | Fiat and crypto transaction logs, timestamps, wallet addresses, counterparties |
| Sanctions Screening Results | Matches, resolution outcomes, freezing actions |
| UTR Reports | Submitted reports, internal alerts, supporting documentation |
| Monitoring Logs (KYT) | Alerts, case reviews, and escalation notes |
| Compliance Decisions | Approvals, rejections, EDD files, onboarding committee minutes |
| Training and Staff Records | Attendance logs, course content, certifications |
Retention Periods
- All client and transaction records must be kept for at least five (5) years from the end of the relationship or the last transaction, whichever is later.
- If a transaction is reported to investigative authorities (such as the FIU, Public Prosecutor, or Police), records must instead be kept for ten (10) years if instructed by the FIU.
- CDD information must also be retained for at least five (5) years after the end of the business relationship.
Security and Integrity
- All records are stored digitally in Bitkaya’s secure compliance archive, integrated with the ERP system
- Access is role-based and logged
- Monthly backups are maintained and stored off-site
- Audit trails are preserved to document every critical access, update, or deletion attempt
Review and Oversight
- The Compliance Officer is responsible for overseeing the recordkeeping framework
- Internal audits are conducted at least annually to verify the integrity and completeness of records
- Bitkaya ensures that all retained data is available for inspection by the CBCS and FIU Curaçao upon request, without undue delay
Evidence
- Expected evidence: record inventory.
- Expected evidence: sample retrieved records.
- Expected evidence: access-control evidence.
- Expected evidence: gap remediation record.
- Expected evidence: retention calculation and disposal hold.
- Expected evidence: audit log, monthly off-site backup and restore evidence.
- Evidence location: compliance evidence repository and applicable operating system.
- Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
- Testing method: Select representative records across all AML categories and confirm completeness, linkage, five- or ten-year retention calculation, role-based access, audit trail, monthly off-site backup, restoration evidence and timely retrieval for CBCS or FIU inspection.
- Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedures: PROC-AML-007 Maintain AML Records and Data Retention
- Manual coverage: sections 7.1-7.6 and 13.4.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Added record-category, retention-period, access, audit-trail, backup, restore and reconstruction testing after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.