Purpose
Provide parent-level assurance over the Enterprise Compliance Manual and the framework-management process, while leaving domain-specific controls to later detailed manuals.
Objective
Ensure material regulatory, supervisory or operating changes receive documented impact assessment and affected-object updates.
Normative
Bitkaya shall maintain evidence that this control is performed, reviewed and escalated where gaps are identified. The control must support traceability from the Enterprise Compliance Manual to affected BCMS objects, approved publications, operational evidence and remediation actions.
Descriptive
This control is a parent-framework control. It confirms that the enterprise compliance governance layer is operating, but it does not replace detailed AML/CFT/CPF, privacy, BCM, IT, finance, complaints, market conduct, outsourcing or other domain controls.
Operational Details from the Manual
Regulatory change monitoring covers key instruments: Penal Code, NORUT, NOIS, Sanctions Ordinances, NOSVASP, applicable CBCS Procedures and Guidelines, FATF’s 40 Recommendations, and GDF codes (Chapter 7.2). The framework is reviewed at least annually or whenever regulatory, business, or operational changes occur (Chapter 5.15).
Where material AML/CFT/CPF changes are made following legal developments, regulator feedback, internal findings, or control enhancements, related subordinate manuals, SOPs, and operational guidance shall be updated in parallel to maintain consistency across the compliance framework (Chapter 7.10).
The manual change log documents the regulatory implementation trajectory: NOSVASP implementation (v1.1–2.0), finalization (v2.1), ABC and Outsourcing chapters added (v2.2), and cross-manual harmonization following AML/CTF/CPF Manual v2.1 (v2.3).
New product and significant change proposals require prior risk assessment including a business case, legal and compliance review, security assessment, and operational readiness plan. Decisions are recorded in the new-product register with a post-launch review within 30 days (Chapter 5.7).
Evidence
- Expected evidence: Regulatory change assessment, impact decision, update ticket or issue.
- Evidence location: SYS-ECM-001 Compliance Framework Library or SYS-ECM-002 Compliance Reporting and Evidence Repository, with links to the relevant operating system where applicable.
- Retention: according to Bitkaya compliance record-retention requirements and applicable regulatory obligations.
- Testing method: Sample changes and verify documented assessment, owner assignment and closure.
- Testing frequency: annual, and after material regulatory, manual, framework or operating changes where applicable.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved Enterprise Compliance Manual version 2.3
Assurance Assertions
- The control has an accountable owner.
- The control is linked to the parent compliance policy and framework-management process.
- Evidence can be retrieved for management, Board, audit or regulatory review.
- Detailed-domain controls should be added when subordinate manuals are implemented.
Relationships
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Parent process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-ECM-002 Assess Regulatory Change and Framework Impact
- Systems: SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository
- Publication: PUB-ECM-001 Enterprise Compliance Manual
History
- 2026-07-25: Created parent-framework control from Bitkaya Compliance Manual version 2.3.
- 2026-07-25: Corrected control frontmatter to use scoped ECM relationships.