Objective

Ensure ethical conduct, anti-bribery, transparency, privacy and security expectations are communicated, monitored and enforced, adhering to a strict Code of Ethics and Conduct covering integrity, accountability, and respect, enforcing anti-corruption and anti-bribery policies with mandatory staff training, maintaining transparent financial and operational reporting aligned with international standards, and enforcing data privacy and cybersecurity standards to protect customer assets and information.

Control Activity

Compliance reviews acknowledgements, training, declared conflicts, concerns, investigations and material governance communications periodically and reports material exceptions to management or the Board. This includes verifying adherence to the Code of Ethics and Conduct, enforcement of anti-corruption and anti-bribery policies with mandatory staff training, maintenance of transparent financial and operational reporting aligned with international standards, and enforcement of data privacy and cybersecurity standards to protect customer assets and information. The code of ethics is documented in the employee handbook, and the Risk Management Framework Manual is referenced for risk management.

Verification Requirements

  • Verify adherence to a strict Code of Ethics and Conduct, covering integrity, accountability, and respect.
  • Verify that anti-corruption and anti-bribery policies are enforced with mandatory staff training.
  • Verify that financial and operational reporting is transparent and aligned with international standards.
  • Verify that data privacy and cybersecurity standards are enforced to protect customer assets and information.
  • Verify that the code of ethics is documented in the employee handbook and acknowledged by staff.
  • Verify proportionality: maintain concise, principle-based governance policies; introduce board committees, independent oversight, and ESG audits progressively as complexity increases.

Evidence

  • Expected evidence: Policy acknowledgements and training records
  • Expected evidence: Conflict, gift and third-party records
  • Expected evidence: Concern, investigation and remediation logs
  • Expected evidence: Approved communications and escalation evidence
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample personnel and matters for current training, declaration, investigation, approval and remediation evidence
  • Testing frequency: quarterly

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.