Objective

Ensure AML/CTF/CPF training is assigned, completed and remediated according to role and risk.

Control Activity

Compliance maintains the in-scope population and tracks onboarding training for new personnel, annual refresher training for all employees, role-specific training for AML-impacting roles and event-driven updates. Attendance, content versions and assessments are retained; failed comprehension requires retake or targeted remediation; and effectiveness is evaluated through feedback, incidents and assurance.

Who Must Be Trained

  • All staff involved in client onboarding, transaction processing, compliance, trading, and IT/security
  • Senior management and directors (to understand oversight responsibilities)
  • Third-party contractors or vendors with AML-related functions (as applicable)

Training Schedule

Type of TrainingFrequencyAudience
AML Onboarding TrainingUpon hireAll new employees
Annual Refresher TrainingOnce per yearAll employees
Role-Specific TrainingAs needed or annuallyCompliance, Trading, IT
Ad Hoc UpdatesUpon policy/tool changesRelevant departments

Training Topics

Training modules cover both legal/regulatory concepts and internal procedures, including:

  • Overview of AML/CFT/CFP laws and CBCS regulations
  • Understanding of money laundering and terrorist financing typologies
  • Customer Due Diligence (CDD), Enhanced Due Diligence (EDD), and Risk Profiling
  • Sanctions screening procedures and red flag indicators
  • STR/FFR/PNMR reporting obligations
  • Use of KYT tools, transaction monitoring systems, and alert handling
  • Escalation workflows and documentation standards

Delivery & Assessment

  • Training is delivered via a combination of e-learning, live sessions, and scenario-based workshops
  • Knowledge checks and quizzes are used to assess comprehension
  • Attendance and test results are logged in Bitkaya’s compliance system
  • Staff who fail to meet minimum comprehension thresholds must retake training

Documentation & Oversight

  • Training logs, course materials, and attendance records are retained
  • The Compliance Officer is responsible for designing, updating, and monitoring the training program
  • Training effectiveness is evaluated through audits, feedback, and incident reviews
  • Program is updated regularly to reflect new regulations, typologies, or internal policy changes

Evidence

  • Expected evidence: training roster.
  • Expected evidence: completion report.
  • Expected evidence: assessment result.
  • Expected evidence: remediation record.
  • Expected evidence: role matrix, training schedule and content version.
  • Expected evidence: effectiveness review and improvement action.
  • Evidence location: compliance evidence repository and applicable operating system.
  • Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
  • Testing method: Reconcile employees, directors, senior management and relevant contractors or vendors to the required onboarding, annual, role-specific and event-driven training; sample curriculum, assessment, retake, overdue escalation and effectiveness evidence.
  • Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Added complete audience, schedule, curriculum, assessment, retake and effectiveness testing after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.