Objective
Ensure independent AML/CTF/CPF review occurs and findings are assigned, escalated and closed with evidence.
Control Activity
Management and Compliance confirm independent AML testing occurs at least annually and after material triggers, is performed by a competent reviewer with no day-to-day compliance involvement, covers the manual’s required risk-based scope and samples, reports directly to senior management or the Board, and tracks every finding through independently verified closure.
Scope of Testing
Independent AML/CTF/CPF testing must assess whether Bitkaya’s policies, procedures, controls and risk-management framework are effective and comply with applicable requirements, including NOIS, NORUT, CBCS Provisions & Guidelines, sanctions obligations and Bitkaya’s internal manuals. The testing must be risk-based, proportionate to Bitkaya’s size and business model, and must include sample testing where relevant. The scope includes, at minimum:
- Evaluation of Bitkaya’s AML/CTF/CPF manual(s), procedures and control framework, including sanctions screening
- Review of the most recent AML/CTF/CPF risk assessment, including EWRA/SARA methodology, annual performance, trigger-based updates and alignment between enterprise-level and client-level risk assessment
- Customer file review, including KYC/CDD, EDD, beneficial ownership, authorized representatives, source of funds, source of wealth, client acceptance decisions and approval requirements by risk category
- Interviews with employees who handle onboarding, transactions, monitoring, escalation or reporting, and with their supervisors where applicable
- Sample testing of unusual transactions and alerts, including transactions on or beyond applicable thresholds, internal escalation, investigation quality, decision rationale and compliance with internal and external reporting requirements
- Review of freezing, unfreezing, blocking, restriction, refusal and release decisions, including sanctions-related restrictive measures and supporting documentation
- Review of corrective actions taken based on the previous independent testing report, internal review findings, regulatory feedback or material control issues
- Review of the documented Know Your Employee / employee screening policy and related implementation evidence
- Review of transaction monitoring and escalation processes, including on-ramp and off-ramp monitoring, alert scenarios, thresholds, calibration, escalation, investigation and documentation
- Review of sanctions-list monitoring, list coverage, list refresh, alert handling, false-positive closure rationale, unresolved-alert stop controls, freezing of assets and sanctions-related reporting or notification process
- Review of FIU Curaçao UTR decisioning and reporting controls, including timeliness, completeness, rationale, confidentiality and anti-tipping-off controls
- Review of wallet screening, wallet ownership verification, blockchain analytics and transaction tracing practices, including handling of high-risk wallet exposure
- Review of VASP counterparty due diligence and KYV controls where relevant
- Assessment of the adequacy of record retention, audit trails and retrievability of client files, screening results, monitoring alerts, case records, UTR files, freezing records, escalation records and training records
- Review of AML/CTF/CPF training coverage, role-based training content, completion records and remediation of overdue or failed training
- Review of AML/CTF/CPF technology and systems controls relevant to onboarding, screening, transaction monitoring, case handling, reporting, access rights, audit logs, tool calibration, list refresh, change management and vendor oversight
Documentation and Remediation
The reviewer must document the scope, methodology, sample basis, limitations, findings, ratings, recommendations, management responses and remediation actions. Findings must be reported to Senior Management and the Board. Remediation actions must be assigned an owner, target date and status, and must be tracked to completion. High-priority issues are addressed through documented remediation plans, with clear owners and deadlines.
Proportionality in Independent Review
Under the proportionality framework, independent review is conducted annually by an independent consultant or internal auditor not involved in daily operations. Review scope and depth are scaled to the volume and complexity of transactions and number of clients.
Evidence
- Expected evidence: independent review report.
- Expected evidence: management response.
- Expected evidence: remediation tracker.
- Expected evidence: closure evidence.
- Expected evidence: reviewer competence and independence record.
- Expected evidence: scope, methodology, sample, limitations and working papers.
- Evidence location: compliance evidence repository and applicable operating system.
- Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
- Testing method: Inspect the latest annual and any trigger-based review; confirm independence, direct reporting, required domain coverage, interviews and sampling, documented limitations and ratings, management responses, Board reporting, action owners and dates, and independently verified closure evidence.
- Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.
Relationships
- Policy: POL-AML-001 AML CTF CPF Compliance Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedures: PROC-AML-009 Perform AML Independent Review and Remediation
- Manual coverage: sections 1.2 and 10.1-10.6.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2
History
- 2026-07-26: Expanded independence, annual frequency, mandatory scope, sample, reporting and closure-verification testing after a full manual rescreen.
- 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.