Purpose

Provide parent-level assurance over the Enterprise Compliance Manual and the framework-management process, while leaving domain-specific controls to later detailed manuals.

Objective

Ensure management, Board and regulatory reporting is prepared, reviewed, escalated and retained according to the framework.

Normative

Bitkaya shall maintain evidence that this control is performed, reviewed and escalated where gaps are identified. The control must support traceability from the Enterprise Compliance Manual to affected BCMS objects, approved publications, operational evidence and remediation actions.

Descriptive

This control is a parent-framework control. It confirms that the enterprise compliance governance layer is operating, but it does not replace detailed AML/CFT/CPF, privacy, BCM, IT, finance, complaints, market conduct, outsourcing or other domain controls.

Operational Details from the Manual

Risk information is reported at three levels (Chapter 5.12):

  • Weekly to Executive Management: Key alerts, sanctions results, custody breaks, cybersecurity incidents, complaints, and exceptions.
  • Monthly to the Risk and Compliance Committee: Risk heatmaps, breaches, vendor metrics, new product updates, outstanding issues, and staff training.
  • Quarterly to the Board: Overall trends, progress against appetite limits, results of stress tests, regulatory feedback, and major incidents.

Reporting requirements to key authorities (Chapter 20):

  • CBCS: Quarterly AML/CFT and governance reports; annual audited financial statements and management letters; notifications of material changes; incident and breach reports within specified timelines.
  • FIU Curaçao: UTRs submitted via the FIU online portal; immediate internal escalation of suspicious activity; tipping off is prohibited.
  • Tax Authorities: Annual CIT return; monthly or quarterly TOT returns; monthly payroll and social security filings.

All regulatory correspondence must be securely archived for at least 5 years. Urgent or sensitive requests (≤72 hours response time) must be escalated to the Compliance Officer immediately (Chapter 20.4). Internal escalation of reporting breaches or material control failures to senior management within 24 hours (Chapter 20.7).

Incident reporting: initial report within 24 hours; full root-cause analysis within five business days; regulators notified if required (Chapter 5.8).

Evidence

  • Expected evidence: Management report, Board report, regulator correspondence, escalation log.
  • Evidence location: SYS-ECM-001 Compliance Framework Library or SYS-ECM-002 Compliance Reporting and Evidence Repository, with links to the relevant operating system where applicable.
  • Retention: according to Bitkaya compliance record-retention requirements and applicable regulatory obligations.
  • Testing method: Sample reporting periods and verify completeness, review, escalation and retention.
  • Testing frequency: annual, and after material regulatory, manual, framework or operating changes where applicable.

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved Enterprise Compliance Manual version 2.3

Assurance Assertions

  • The control has an accountable owner.
  • The control is linked to the parent compliance policy and framework-management process.
  • Evidence can be retrieved for management, Board, audit or regulatory review.
  • Detailed-domain controls should be added when subordinate manuals are implemented.

Relationships

History

  • 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
  • 2026-07-25: Created parent-framework control from Bitkaya Compliance Manual version 2.3.
  • 2026-07-25: Corrected control frontmatter to use scoped ECM relationships.