Objective

Ensure internal-control accountability and assurance independence remain defined, approved and effective.

Control Activity

Compliance coordinates annual review of control ownership, reporting lines, tester independence, authority, resources and competence and escalates impairments to the Board. The Board of Directors holds ultimate responsibility for oversight of the internal control framework, ensuring it is effective, adequately resourced, and aligned with regulatory obligations. The Head of Risk and Compliance (2nd Line of Defense) designs, tests, and monitors the risk and control framework. Internal Audit (3rd Line of Defense) provides independent assurance reporting directly to the Audit and Risk Committee. As a small VASP, the Head of Risk and Compliance may also serve as Audit Coordinator, reporting results directly to the Board or Audit and Risk Committee.

Evidence

  • Expected evidence: Governance and ownership matrix documenting Board, Head of Risk and Compliance, MLRO, Internal Audit and All Staff responsibilities
  • Expected evidence: Independence and conflict assessments confirming testers do not independently assure controls they operate
  • Expected evidence: Resource and competence review
  • Expected evidence: Board approval and decisions, including annual proportionality assessment
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: inspect annual review and sample assurance engagements for separation from control operation and resolved conflicts; verify that the Board has assessed whether proportionality justifications remain appropriate
  • Testing frequency: annual and before each material assurance engagement

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ICA Manual version 1.1.