Purpose

Provide parent-level assurance over the Enterprise Compliance Manual and the framework-management process, while leaving domain-specific controls to later detailed manuals.

Objective

Ensure the enterprise compliance framework inventory identifies current manuals, BCMS objects, owners, approval status, review dates and evidence locations.

Normative

Bitkaya shall maintain evidence that this control is performed, reviewed and escalated where gaps are identified. The control must support traceability from the Enterprise Compliance Manual to affected BCMS objects, approved publications, operational evidence and remediation actions.

Descriptive

This control is a parent-framework control. It confirms that the enterprise compliance governance layer is operating, but it does not replace detailed AML/CFT/CPF, privacy, BCM, IT, finance, complaints, market conduct, outsourcing or other domain controls.

Operational Details from the Manual

The inventory must track the full set of 21 chapters of the Enterprise Compliance Manual v2.3, each with subordinate manuals, owners, approval status, review dates, and evidence locations. The manual is the parent policy governing creation, implementation, and monitoring of all subordinate compliance manuals and frameworks (Chapter 1).

All records — including client data, risk logs, and reports — are securely stored for at least five years, and up to ten years where required by law (Chapter 5.11). All evidence — policies, registers, logs, and reports — is maintained in a structured library to demonstrate compliance at any time (Chapter 5.13).

The framework is reviewed at least annually or whenever regulatory, business, or operational changes occur. A version log records all updates, their rationale, approval dates, and related procedures affected (Chapter 5.15).

Evidence

  • Expected evidence: Inventory extract, owner review record, outdated-item remediation log.
  • Evidence location: SYS-ECM-001 Compliance Framework Library or SYS-ECM-002 Compliance Reporting and Evidence Repository, with links to the relevant operating system where applicable.
  • Retention: according to Bitkaya compliance record-retention requirements and applicable regulatory obligations.
  • Testing method: Compare the inventory to approved manuals, BCMS objects and publication artifacts.
  • Testing frequency: annual, and after material regulatory, manual, framework or operating changes where applicable.

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved Enterprise Compliance Manual version 2.3

Assurance Assertions

  • The control has an accountable owner.
  • The control is linked to the parent compliance policy and framework-management process.
  • Evidence can be retrieved for management, Board, audit or regulatory review.
  • Detailed-domain controls should be added when subordinate manuals are implemented.

Relationships

History

  • 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
  • 2026-07-25: Created parent-framework control from Bitkaya Compliance Manual version 2.3.
  • 2026-07-25: Corrected control frontmatter to use scoped ECM relationships.