Objective

Ensure the AML/CTF/CPF manual and proportionality rationale are reviewed, approved and updated when required.

Control Activity

Compliance confirms AML policies, procedures, SOPs and risk assessments are reviewed at least annually and after material triggers; affected subordinate documents and controls are updated together; and MLRO and Board approvals, staff communication, versioning and secure archiving are complete. Compliance accountability and direct CEO reporting remain documented and independent assurance stays separate. Proportionality decisions must remain risk-based, preserve mandatory controls and include approved compensating controls where roles are combined.

Proportionality Purpose and Rationale

Bitkaya B.V., as a small and startup-stage Virtual Asset Service Provider (VASP), applies the principle of proportionality to ensure that all AML/CFT controls, governance measures, and compliance processes are commensurate with the nature, size, and risk profile of the institution. This approach is in line with:

  • The Landsverordening toezicht virtuele activa dienstverleners (2025), which requires integrity and risk-based operations proportionate to business size
  • The CBCS SARA and Risk-Based Supervision frameworks, emphasizing scalable control measures
  • FATF and CFATF expectations for smaller VASPs to implement proportionate and effective compliance programs without unnecessary administrative burdens

The principle of proportionality does not reduce the company’s responsibility for compliance. Instead, it ensures that Bitkaya achieves full adherence to AML/CFT obligations through fit-for-purpose systems, lean governance, and risk-prioritized resource allocation.

Proportionality Guiding Principles

  1. Risk-Based Application — AML/CFT controls are applied based on the level of ML/TF risk rather than organizational size alone. Higher-risk services (e.g., wallet transfers or high-value virtual asset exchanges) receive enhanced monitoring and due diligence.
  2. Scalability and Efficiency — Processes, documentation, and control structures are designed to scale with business growth. Core compliance tools (KYC, KYT, sanctions screening) are centralized and automated to minimize manual workload.
  3. Practical Governance — Governance roles may be consolidated where appropriate (e.g., the Compliance Officer also serves as the MLRO), provided that checks and balances and escalation mechanisms are maintained.
  4. Resource Optimization — Use of external providers for independent audit, transaction monitoring, and sanctions screening allows Bitkaya to meet CBCS standards without internal duplication of complex technical functions.
  5. Continuous Alignment — The proportionality approach is reviewed annually or upon any material business change, regulatory update, or audit finding, ensuring that the AML/CFT framework evolves alongside operational growth.

Governance and Oversight

  • Board of Directors: Retains full accountability for the AML/CFT framework and for ensuring that proportional implementation does not weaken control effectiveness
  • Compliance Officer / MLRO: Ensures proportional application of policies and reports on adequacy to the Board and CBCS
  • Independent Reviewer: Conducts periodic reviews of proportionality justifications to ensure residual risks remain within acceptable limits

Where functions are combined due to scale, compensating controls — such as independent audit or CEO-level oversight — are documented and approved by the Board.

Proportionality Application Across AML/CFT Domains

a. EWRA: The EWRA process follows the CBCS SARA model but uses simplified quantitative scoring suitable for a startup structure. Data-driven tools automate client and transaction risk classification. Annual EWRA updates suffice unless there is a significant change in product scope, volume, or jurisdictional exposure.

b. CDD and EDD: Simplified CDD may only be applied where the client has been assessed and documented as low-risk. Even where SDD is applied, Bitkaya will still apply the core CDD measures appropriate to the client type and risk, including identifying the client, identifying the beneficial owner where applicable, understanding the purpose and intended nature of the relationship, and conducting ongoing monitoring. EDD applies only where objective indicators (PEP, high-risk jurisdiction, transaction behavior) warrant additional scrutiny. Digital onboarding with automated ID and sanctions verification ensures proportional yet compliant KYC.

c. Transaction Monitoring and Reporting: Outsourced blockchain analytics and rule-based KYT systems provide automated alerts without requiring a large in-house monitoring team. Alert review frequency and escalation are risk-based: daily for high-risk, weekly for low/medium. UTR reporting remains centralized under the MLRO for consistency and efficiency.

d. Training and Awareness: All employees receive AML/CFT onboarding and annual refresher training. Specialized training is delivered only to roles with direct AML/CFT impact (Operations, Compliance). External e-learning and CBCS guidance materials are used in place of developing training materials internally.

e. Independent Review: Conducted annually by an independent consultant or internal auditor not involved in daily operations. Review scope and depth are scaled to the volume and complexity of transactions and number of clients.

Continuous Improvement and Scalability

Bitkaya continuously evaluates the adequacy of proportionality measures through:

  • Annual (compliance) review of risk exposure and resource capacity
  • Feedback from internal audits, regulatory inspections, and FIU interactions
  • Integration of lessons learned into policy revisions

As Bitkaya grows, proportionality will transition into a fully structured three-lines-of-defense model, expanding dedicated compliance and audit staffing, independent control testing, and enhanced governance reporting.

Policy Management Scope

Policies and procedures covered include (but are not limited to): AML/CFT Program Charter; KYC, KYT, and KYV Policies; Sanctions Screening Policy; Risk Profiling and EDD Guidelines; STR/FFR/PNMR Reporting Procedures; Training & Awareness Program; Technology & System Controls; Recordkeeping, Governance, and Testing Frameworks.

Review Frequency

Document TypeReview FrequencyResponsible Party
Core AML/CFT PoliciesAnnuallyCompliance Officer (MLRO)
SOPs and ManualsAt least annually or upon material changeDepartment Heads / Compliance
Risk Assessments (EWRA, client scoring)Annually or upon changeCompliance / Risk

Review & Approval Workflow

  1. Policy Drafting or Update — Initiated by Compliance or relevant function
  2. Internal Review — Circulated for feedback (Legal, Risk, Operations)
  3. MLRO Sign-Off — Ensures regulatory alignment and consistency
  4. Board/Committee Approval — Final endorsement of high-level policies
  5. Staff Communication — Updated policies shared with impacted staff
  6. Version Control — Each policy is versioned and archived

Governance & Oversight

  • The Chief Compliance Officer (MLRO) is responsible for maintaining the master compliance policy library
  • All approved versions are stored securely, access-controlled, and backed up
  • Outdated or superseded versions are retained to support audits and regulatory requests

Continuous Improvement

  • Policies are informed by findings from: internal audits and independent reviews; regulatory inspections and CBCS guidance updates; lessons learned from STRs, alerts, or incident investigations
  • Bitkaya continuously benchmarks its policy framework against FATF standards, CBCS Provisions, and Global Digital Finance principles

Evidence

  • Expected evidence: policy review record.
  • Expected evidence: change log.
  • Expected evidence: approval evidence.
  • Expected evidence: proportionality rationale.
  • Expected evidence: communication record.
  • Expected evidence: subordinate-document consistency and source review.
  • Expected evidence: compensating-control, resource-capacity and scalability assessment.
  • Evidence location: compliance evidence repository and applicable operating system.
  • Retention: according to Bitkaya AML/CTF/CPF record-retention requirements.
  • Testing method: Review the current manual, annual review and material-trigger changes; confirm legal/source alignment, parallel subordinate updates, MLRO and Board approval, communication, secure version archive, combined-role compensating controls, annual resource review and scaling decisions.
  • Testing frequency: annual, and after material AML/CTF/CPF changes where applicable.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Added review cadence, subordinate consistency, governance, compensating-control and scalability testing after a full manual rescreen.
  • 2026-07-26: Created from the approved AML/CTF/CPF Compliance Manual version 2.2.