Purpose
Provide parent-level assurance over the Enterprise Compliance Manual and the framework-management process, while leaving domain-specific controls to later detailed manuals.
Objective
Ensure compliance manuals and subordinate framework documents are reviewed, approved, published and archived under version control.
Normative
Bitkaya shall maintain evidence that this control is performed, reviewed and escalated where gaps are identified. The control must support traceability from the Enterprise Compliance Manual to affected BCMS objects, approved publications, operational evidence and remediation actions.
Descriptive
This control is a parent-framework control. It confirms that the enterprise compliance governance layer is operating, but it does not replace detailed AML/CFT/CPF, privacy, BCM, IT, finance, complaints, market conduct, outsourcing or other domain controls.
Operational Details from the Manual
The Enterprise Compliance Manual v2.3 was approved by the Board with status FINAL and effective date 21 April 2026. All policies, SOPs, and risk assessments are maintained in a version-controlled library. Reviews occur annually or upon significant changes (Chapter 7.10).
The framework is reviewed at least annually or whenever regulatory, business, or operational changes occur. A version log records all updates, their rationale, approval dates, and related procedures affected (Chapter 5.15).
The manual serves as the parent policy governing creation, implementation, and monitoring of all subordinate compliance manuals and frameworks (Chapter 1). Each “Further Details” section in the manual references a standalone subordinate manual, establishing the full hierarchy of approved compliance documentation.
The Board of Directors approves this framework and the company’s overall risk appetite, receiving quarterly risk reports and an annual summary of trends (Chapter 5.2.1).
Evidence
- Expected evidence: Approved manual, publication artifact, approval record, version history.
- Evidence location: SYS-ECM-001 Compliance Framework Library or SYS-ECM-002 Compliance Reporting and Evidence Repository, with links to the relevant operating system where applicable.
- Retention: according to Bitkaya compliance record-retention requirements and applicable regulatory obligations.
- Testing method: Compare published artifacts to metadata, approval evidence and repository history.
- Testing frequency: annual, and after material regulatory, manual, framework or operating changes where applicable.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved Enterprise Compliance Manual version 2.3
Assurance Assertions
- The control has an accountable owner.
- The control is linked to the parent compliance policy and framework-management process.
- Evidence can be retrieved for management, Board, audit or regulatory review.
- Detailed-domain controls should be added when subordinate manuals are implemented.
Relationships
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Parent process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-ECM-003 Review Approve and Publish Compliance Manuals
- Systems: SYS-ECM-001 Compliance Framework Library
- Publication: PUB-ECM-001 Enterprise Compliance Manual
History
- 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
- 2026-07-25: Created parent-framework control from Bitkaya Compliance Manual version 2.3.
- 2026-07-25: Corrected control frontmatter to use scoped ECM relationships.