Objective
Ensure employee conduct, conflicts and threats to client or company assets, information and credentials are identified and controlled.
Control Activity
Compliance and management require conflict disclosure and prompt incident reporting, document mitigation and coordinate containment, escalation and remediation under the relevant compliance and technology frameworks. Specific verification requirements include:
- Conflicts must be disclosed immediately to Compliance or HR; examples to verify for include trading digital assets using inside knowledge, having a financial interest in a supplier, vendor, or competitor, and accepting gifts or favors that could influence decisions.
- Client money and digital assets must be handled with the highest level of care; never used for company operations or personal benefit.
- Sensitive information must be safeguarded by following data security protocols, encryption rules, and access controls.
- Any loss, theft, or breach involving assets or data must be immediately reported.
- All gifts and hospitality must be of nominal value, infrequent, transparent, and not intended to secure an improper advantage.
- No accounts may be kept “off-book” to facilitate or conceal improper payments, nor may they be falsified.
Evidence
- Expected evidence: Conflict disclosures and mitigation decisions
- Expected evidence: Asset, data and access incident records
- Expected evidence: Restriction, recusal and monitoring evidence
- Expected evidence: Escalation and remediation records
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample conflict and incident records for timely reporting, appropriate assessment, approved action and verified closure
- Testing frequency: quarterly
Relationships
- Requirements: REQ-VASP-005 Maintain Integrity Based Business Operations, REQ-VASP-011 Control Client Data and Account Access
- Policy: POL-EMP-001 Employee Handbook
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-EMP-003 Manage Employee Conduct Conflicts Assets and Data
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved Employee Handbook version 1.0.