Objective
Ensure material virtual-asset risks and service limitations are complete, understandable and at least as prominent as promotional benefits.
Control Activity
Compliance confirms that applicable volatility, loss-of-capital, regulatory-change, technology, access and AML/CTF monitoring risks are included. Communications explain relevant review, delay, restriction, refusal, blocking and reporting possibilities and do not imply automatic acceptance, guaranteed timelines or certain outcomes.
Verification Requirements (Section 4 of the Approved Manual)
Risk warnings are not optional — they are mandatory and must be visible in all marketing and client materials. Verify that the following five Mandatory Risk Statements are present with exact approved wording where applicable:
- Volatility: “The value of virtual assets may rise or fall quickly.”
- Loss of Capital: “You could lose your entire investment.”
- Regulatory Changes: “Rules and laws may change, affecting your holdings.”
- Technology Risks: “Hacking, system failures, or loss of access may lead to total loss.”
- AML/CTF Monitoring: “Transactions may be monitored and reported under Curaçao law.”
Verify compliance with Best Practice rules: risk warnings must appear in the same font size as promotional claims, and must not be buried in footnotes.
Verify that service limitation disclosures are present where relevant: services, onboarding, transactions, withdrawals, transfers, or account functionality may be subject to legal, regulatory, sanctions, safeguarding, fraud prevention, or compliance controls, which may result in additional review, delays, restrictions, refusal, or reporting where required by law.
For advice-related communications (Article 63 LvT VAD), verify that disclosures confirm the client understands the risks and can bear losses.
Evidence
- Expected evidence: Product and audience risk assessment
- Expected evidence: Approved risk and limitation statements
- Expected evidence: Prominence and readability check
- Expected evidence: Service-specific disclosure review
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample released content and compare risk completeness, wording and visual prominence with benefits and claims
- Testing frequency: before release with quarterly sample testing
Relationships
- Policy: POL-COMM-001 Client Communication and Promotion Compliance Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Procedure: PROC-COMM-003 Apply Balanced Risk Disclosures and Service Limitations
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved COMM Manual.