Objective

Ensure substantiated employee violations receive documented, proportionate and consistent disciplinary and escalation decisions.

Control Activity

Human Resources and Compliance review substantiated matters against severity, impact, intent, prior conduct and comparable cases, obtain appropriate approval and track disciplinary, remediation and reporting actions. Verification requirements include confirming the correct classification:

  • Minor Mistakes: Missing a training deadline, forgetting to update a compliance form, or minor administrative oversights — may result in verbal or written warnings, mandatory retraining, or closer supervision, documented as learning opportunities.
  • Serious Violations: Failing to follow AML/CFT procedures, ignoring cybersecurity protocols, mishandling confidential client data, or failing to disclose conflicts — may lead to suspension, demotion, reassignment, or termination, and may be reported to regulators depending on severity.
  • Gross Misconduct: Insider trading, fraud, bribery, market manipulation, theft, or misusing client funds — almost always results in immediate dismissal, with possible criminal prosecution, civil penalties, or regulatory enforcement actions; Bitkaya cooperates fully with law enforcement and regulators.

Personal liability (fines, bans from working in financial services, imprisonment) and company liability (heavy fines, sanctions, reputational damage, loss of licenses) must be documented. Leadership is bound by the same rules; senior leaders violating policy face the same disciplinary procedures and regulatory reporting obligations.

Evidence

  • Expected evidence: Investigation findings and classification
  • Expected evidence: Consistency and proportionality assessment
  • Expected evidence: Decision and approval record
  • Expected evidence: Disciplinary and remediation evidence
  • Expected evidence: Legal or regulatory escalation
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample substantiated cases for supported classification, appropriate approval, consistent action and completed remediation
  • Testing frequency: semiannual and after each gross-misconduct case

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved Employee Handbook version 1.0.