Objective

Ensure material decisions identify, assess, approve and monitor relevant ESG impacts and risks, incorporating ESG criteria into investment, product development, and business decisions, identifying and assessing ESG-related risks regularly (e.g., environmental impacts, reputational risks, regulatory changes), integrating ESG considerations into the overall enterprise risk management framework, ensuring compliance with AML/CFT regulations, data protection laws, and other applicable legislation, and establishing incident reporting, escalation, and remediation protocols.

Control Activity

Compliance or Risk reviews documented ESG screening for material products, investments, suppliers, partnerships and changes before approval and tracks conditions and residual risk. This includes verifying that ESG criteria are incorporated into investment, product development, and business decisions, stakeholders (including customers, regulators, employees, and partners) are engaged in ESG discussions and initiatives, ESG-related risks are identified and assessed regularly, ESG considerations are integrated into the enterprise risk management framework, compliance with AML/CFT regulations and data protection laws is ensured, and incident reporting, escalation, and remediation protocols are established. Innovation in digital assets and blockchain applications that support sustainable finance and inclusion is encouraged.

Verification Requirements

  • Verify that ESG criteria are incorporated into investment, product development, and business decisions.
  • Verify that stakeholders, including customers, regulators, employees, and partners, are engaged in ESG discussions and initiatives.
  • Verify that ESG-related risks are identified and assessed regularly (e.g., environmental impacts, reputational risks, regulatory changes).
  • Verify that ESG considerations are integrated into the overall enterprise risk management framework.
  • Verify compliance with AML/CFT regulations, data protection laws, and other applicable legislation.
  • Verify that incident reporting, escalation, and remediation protocols are established.
  • Verify that innovation in digital assets and blockchain applications supporting sustainable finance and inclusion is encouraged.
  • Verify proportionality: ESG measures are prioritized by materiality and impact; areas with higher exposure receive more structured oversight.

Evidence

  • Expected evidence: Screening criteria and completed assessments
  • Expected evidence: Risk register and stakeholder analysis
  • Expected evidence: Decision papers, approvals and conditions
  • Expected evidence: Post-decision monitoring and reassessment
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample material decisions for complete assessment, appropriate authority and monitored approval conditions
  • Testing frequency: per material decision and quarterly condition review

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.