Objective
Ensure onboarding, review, delay and restriction communications are clear without promising outcomes or revealing protected information.
Control Activity
Staff use approved wording for identity verification, screening, documentation, risk assessment and restrictions. Sensitive communications receive Compliance review and do not disclose or imply suspicious-activity reporting, sanctions review, FIU requests, reporting decisions or internal risk conclusions. Personal data is sent through approved secure channels.
Verification Requirements (Section 6 and Section 9 of the Approved Manual)
Verify that onboarding communications are transparent, fair, and operationally realistic. Clients must be informed that onboarding is subject to:
- identity verification;
- screening;
- risk assessment;
- supporting documentation requirements;
- approval steps; and
- where applicable, enhanced due diligence.
Verify that onboarding communications do not imply automatic acceptance, guaranteed timelines, or unconditional service access.
Where higher-risk characteristics, incomplete documentation, unresolved alerts, or legal restrictions apply, verify that communication explains the need for further review without disclosing internal compliance conclusions inappropriately or breaching anti-tipping-off requirements.
Verify that no staff communication inappropriately discloses, confirms, or implies the existence of a sanctions review, unusual activity assessment, or internal reporting process — such communication may constitute a serious control breach. Where communication issues touch on sanctions, unusual activity review, legal restrictions, or internal compliance handling, verify the matter was escalated and assessed in coordination with the relevant control functions.
Evidence
- Expected evidence: Approved wording and delivered communication
- Expected evidence: Compliance review and escalation
- Expected evidence: Information-request rationale
- Expected evidence: Confidentiality and anti-tipping-off assessment
- Expected evidence: Secure delivery record
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample sensitive client communications and verify approved wording, non-disclosure, approval, data minimization and secure delivery
- Testing frequency: per sensitive communication with periodic sample review
Relationships
- Policy: POL-COMM-001 Client Communication and Promotion Compliance Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Procedure: PROC-COMM-004 Communicate Onboarding Reviews and Restrictions Safely
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved COMM Manual.