Purpose

Provide parent-level assurance over the Enterprise Compliance Manual and the framework-management process, while leaving domain-specific controls to later detailed manuals.

Objective

Ensure required compliance training and attestations are assigned, completed, monitored and escalated when overdue.

Normative

Bitkaya shall maintain evidence that this control is performed, reviewed and escalated where gaps are identified. The control must support traceability from the Enterprise Compliance Manual to affected BCMS objects, approved publications, operational evidence and remediation actions.

Descriptive

This control is a parent-framework control. It confirms that the enterprise compliance governance layer is operating, but it does not replace detailed AML/CFT/CPF, privacy, BCM, IT, finance, complaints, market conduct, outsourcing or other domain controls.

Operational Details from the Manual

The Training and Awareness Framework (Chapter 21) defines roles: HR coordinates programs and tracks completion; Compliance Officer ensures alignment with regulatory requirements; Department Heads identify role-specific needs; Employees complete assigned training on time.

Training programs include induction (AML/CFT fundamentals, sanctions compliance, ABC, whistleblower policies, cybersecurity, data protection), ongoing (updates on laws, policies, emerging risks, typologies), specialized (Compliance & Risk: AML/CFT, ABC, Travel Rule; IT & Security: access control, threat mitigation, incident response; Client-Facing: KYC, client communication, ethics), and awareness campaigns (fraud trends, phishing simulations, crypto hygiene).

Competency assessment: initial evaluation during onboarding; periodic review via audits, reviews, and incident response; remediation triggers refresher courses, coaching, or reassignment. Completion rates and assessment results reviewed regularly by HR and Compliance (Chapter 21.4).

Continuous improvement: training materials updated regularly; benchmarked annually against CBCS, FATF, and industry best practices; annual program review approved by the Board (Chapter 21.5).

Cultural health is measured through staff participation in training, reporting of issues, and time taken to close them (Chapter 5.14).

Evidence

  • Expected evidence: Training register, attestation record, overdue escalation, remediation evidence.
  • Evidence location: SYS-ECM-001 Compliance Framework Library or SYS-ECM-002 Compliance Reporting and Evidence Repository, with links to the relevant operating system where applicable.
  • Retention: according to Bitkaya compliance record-retention requirements and applicable regulatory obligations.
  • Testing method: Compare required population to completion evidence and overdue follow-up.
  • Testing frequency: annual, and after material regulatory, manual, framework or operating changes where applicable.

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved Enterprise Compliance Manual version 2.3

Assurance Assertions

  • The control has an accountable owner.
  • The control is linked to the parent compliance policy and framework-management process.
  • Evidence can be retrieved for management, Board, audit or regulatory review.
  • Detailed-domain controls should be added when subordinate manuals are implemented.

Relationships

History

  • 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
  • 2026-07-25: Created parent-framework control from Bitkaya Compliance Manual version 2.3.
  • 2026-07-25: Corrected control frontmatter to use scoped ECM relationships.