Purpose
Provide parent-level assurance over the Enterprise Compliance Manual and the framework-management process, while leaving domain-specific controls to later detailed manuals.
Objective
Ensure compliance reviews, control tests, audit findings and remediation actions are logged, owned, tracked and closed with evidence.
Normative
Bitkaya shall maintain evidence that this control is performed, reviewed and escalated where gaps are identified. The control must support traceability from the Enterprise Compliance Manual to affected BCMS objects, approved publications, operational evidence and remediation actions.
Descriptive
This control is a parent-framework control. It confirms that the enterprise compliance governance layer is operating, but it does not replace detailed AML/CFT/CPF, privacy, BCM, IT, finance, complaints, market conduct, outsourcing or other domain controls.
Operational Details from the Manual
The audit framework is multi-layered (Chapter 19.4):
- Internal Audit: Annual, risk-based audits covering AML/CFT compliance, ABC, custody operations, IT and cybersecurity, BCM, and governance. Reports findings directly to the Audit & Risk Committee and the Board.
- Second Line Testing: Quarterly compliance reviews and control testing by the Risk & Compliance function. Tracks remediation actions and verifies completion.
- External and Regulatory Audits: Annual AML/CFT audit by independent external reviewer; evidence libraries maintained for regulatory readiness; full cooperation with CBCS.
- Financial Statement Audit: Annual external audit under IFRS or GAAP; focus areas include custody asset valuation, safeguarding, and revenue recognition.
Assurance and review (Chapter 5.13):
- Second-line testing: quarterly reviews of control effectiveness with follow-up on remediation.
- Independent audit: annual review of Risk Management and Compliance frameworks.
- Regulatory readiness: all evidence maintained in a structured library.
Incident management (Chapter 5.8): Incidents classified when detected; initial report within 24 hours; full root-cause analysis within five business days; regulators notified if required. Each issue has assigned owner, action plan, and due date for resolution.
Reporting & Escalation (Chapter 19.5): Weekly Operations Pack (key control metrics and exceptions); Monthly RCC (thematic findings and trend analysis); Quarterly Board Reports (risk trends, audit outcomes, control improvements); Immediate Escalation (material breaches or systemic risks reported without delay).
Training & Culture (Chapter 19.6): Mandatory onboarding and annual refresher training; specialized training for high-risk functions (custody, AML, IT); culture metrics include “speak-up” participation rates, phishing test results, and remediation timeliness.
Document Management (Chapter 19.7): Policy reviewed annually or upon material changes; version-controlled log records all updates, approvals, and effective dates.
Evidence
- Expected evidence: Assurance plan, testing record, issue log, closure evidence.
- Evidence location: SYS-ECM-001 Compliance Framework Library or SYS-ECM-002 Compliance Reporting and Evidence Repository, with links to the relevant operating system where applicable.
- Retention: according to Bitkaya compliance record-retention requirements and applicable regulatory obligations.
- Testing method: Sample findings and verify owner, due date, status, evidence and closure approval.
- Testing frequency: annual, and after material regulatory, manual, framework or operating changes where applicable.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved Enterprise Compliance Manual version 2.3
Assurance Assertions
- The control has an accountable owner.
- The control is linked to the parent compliance policy and framework-management process.
- Evidence can be retrieved for management, Board, audit or regulatory review.
- Detailed-domain controls should be added when subordinate manuals are implemented.
Relationships
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Parent process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-ECM-006 Perform Compliance Assurance and Remediation
- Systems: SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository
- Publication: PUB-ECM-001 Enterprise Compliance Manual
History
- 2026-07-26: Added explicit regulatory requirement relationships for handover traceability.
- 2026-07-25: Created parent-framework control from Bitkaya Compliance Manual version 2.3.
- 2026-07-25: Corrected control frontmatter to use scoped ECM relationships.