Objective
Ensure whistleblower reports are accessible, confidential, acknowledged promptly, investigated impartially and protected from retaliation.
Control Activity
Compliance maintains protected reporting channels and a restricted case register, checks 5-business-day acknowledgments, independence, evidence preservation, outcome documentation and retaliation monitoring, and escalates material matters. Specific verification requirements include:
- Reports can be made internally to the Operational Manager, Human Resources Manager, or Board of Directors, and externally to the Centrale Bank of Curacao and St. Maarten (CBCS) where internal reporting is not feasible or appropriate.
- Reports can be submitted anonymously; providing contact information may facilitate a more thorough investigation.
- The identity of the whistleblower must be protected unless disclosure is required by law; all reports and investigations handled confidentially to the extent possible.
- Retaliation — including dismissal, demotion, harassment, or any adverse employment action — is strictly prohibited and will result in disciplinary action up to and including termination.
- Reports made in bad faith or with knowledge that allegations are false are not protected and may result in disciplinary action.
- Reportable conduct covers fraud, corruption, financial misconduct, violation of laws or regulations, unethical behavior, health and safety violations, environmental damage, harassment, discrimination, bullying, and any conduct that may cause financial or reputational harm.
Evidence
- Expected evidence: Reporting-channel and access records
- Expected evidence: Restricted report register and acknowledgments
- Expected evidence: Conflict checks, investigation plans and findings
- Expected evidence: Outcome, remediation and escalation evidence
- Expected evidence: Retaliation monitoring
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect all or a risk-based sample of reports for timely acknowledgment, investigator independence, confidentiality, documented outcome and non-retaliation follow-up
- Testing frequency: quarterly and after each material case
Relationships
- Requirements: REQ-VASP-005 Maintain Integrity Based Business Operations, REQ-VASP-014 Cooperate With CBCS Supervision and Enforcement
- Policy: POL-EMP-001 Employee Handbook
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-EMP-004 Receive and Investigate Whistleblower Reports
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved Employee Handbook version 1.0.