Objective

Ensure AML systems accurately identify risk, protect sensitive information, preserve traceable decisions and operate under controlled access, configuration, change and vendor governance.

Control Activity

Compliance and Technology review the AML system inventory and authoritative configurations at least annually and after major changes. They confirm complete inputs, failure handling, list refresh and calibration; least-privilege access, MFA, encryption and audit trails; approved testing, release and rollback; backup and restoration; and current vendor due diligence. Material failures, unauthorized changes and unsupported coverage are escalated and remediated.

Key Objectives

  • Ensure accurate, real-time risk identification (KYC/KYT/sanctions)
  • Automate key compliance processes to reduce human error
  • Maintain secure handling and storage of sensitive client data
  • Enable consistent auditability and escalation tracking

Core Technology Components

  1. KYC/IDV Integration — Use of third-party tools for ID verification, biometric checks, and liveness detection
  2. KYT & Wallet Risk Analytics — Real-time blockchain risk scoring; automated wallet alerts based on mixer use, darknet exposure, or sanctions proximity
  3. Sanctions Screening Tools — Screening of relationships against sanctions lists; automatic refresh of list data
  4. Case Management System (CMS) — Tracks alerts, escalations, approvals, and STR/FFR/PNMR decisions; includes timestamps, roles, and resolution status for full traceability
  5. ERP & Compliance Dashboard — Centralized visibility into compliance KPIs, outstanding alerts, and risk exposure; supports internal reporting and audit prep

Security & Access Controls

  • Role-based access to compliance platforms
  • Multi-factor authentication (MFA) and encryption at rest and in transit
  • Tamper-proof audit trails for all compliance decisions
  • Regular data backups and off-site encrypted storage

Oversight & Review

  • Compliance Officer oversees system effectiveness and tool calibration
  • Systems are reviewed annually or upon major updates
  • Vendor due diligence is conducted for third-party tools

Evidence

  • Expected evidence: AML system and integration inventory.
  • Expected evidence: approved configuration and calibration exports.
  • Expected evidence: access matrix, MFA, access review and audit logs.
  • Expected evidence: change tests, release approval and rollback record.
  • Expected evidence: exception monitoring, backup and restoration evidence.
  • Expected evidence: vendor due-diligence and annual suitability review.
  • Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring and SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to Bitkaya AML/CTF/CPF and technology record-retention requirements.
  • Testing method: sample each material AML component and integration; verify input completeness, failure-path blocking, approved calibration, access and encryption, audit trail, list refresh, positive/negative/boundary testing, release and rollback, backup restoration and vendor review.
  • Testing frequency: annual, after each material AML system change and after a material incident or control failure.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved AML/CTF/CPF Compliance Manual version 2.2

History

  • 2026-07-26: Created after a full AML manual rescreen to implement and test the dedicated technology and systems chapter.