Objective
Ensure in-scope external communications receive documented review and approval and only the approved version is released and retained.
Control Activity
Compliance reviews the final approval package and obtains specialist and management approval where required. Licensing and supervision claims require current verification. Released content is reconciled to the approved version, assigned ownership and review dates, and retained with substantiation, comments, approvals and correction history.
Verification Requirements (Section 7 of the Approved Manual)
Verify that no external communication relating to products, services, onboarding, risk disclosures, restrictions, or operational capabilities has been published without appropriate internal review. Confirm that Compliance review was obtained where content touches on:
- onboarding and due diligence expectations;
- client acceptance or approval language;
- sanctions, legal, or compliance restrictions;
- safeguarding or asset access language;
- complaints or escalation channels;
- regulatory status or reporting obligations; or
- representations about the certainty, speed, or permissibility of transactions or withdrawals.
Verify that final versions have been retained in accordance with Bitkaya’s recordkeeping requirements.
Proportionality Verification (Section 11.3–11.4)
For a small VASP such as Bitkaya, verify that communication approval may rest with a single Compliance Officer and one member of management. Confirm that for low-risk products and audiences, streamlined reviews apply, while communications about higher-risk or innovative virtual asset services undergo enhanced compliance scrutiny. Verify that use of pre-approved templates, disclaimers, and concise communication reduces operational burden while ensuring compliance with Articles 42, 45, and 46 of the LvT VAD.
Evidence
- Expected evidence: Approval package and substantiation
- Expected evidence: Specialist, Compliance and management approvals
- Expected evidence: Regulatory-status verification
- Expected evidence: Approved and released versions
- Expected evidence: Release, correction and withdrawal evidence
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample released communications and trace each to complete approval, version reconciliation and retained evidence
- Testing frequency: before release with quarterly sample testing
Relationships
- Policy: POL-COMM-001 Client Communication and Promotion Compliance Manual
- Process: PRC-CPO-001 Client Protection and Operations
- Procedure: PROC-COMM-005 Review Approve Publish and Retain External Communications
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved COMM Manual.