Objective

Ensure material risks and obligations have owned, documented, evidenced and testable controls.

Control Activity

Risk and Compliance reconcile the control inventory to risks, requirements, processes and systems quarterly and record and escalate gaps, overlaps and unevidenced controls. Coverage verification includes the five core domains: (1) Financial Crime Compliance — KYC, KYV, KYT, sanctions screening (onboarding, periodic review, list-refresh, transaction/wallet-level), transaction monitoring, internal case escalation, UTR reporting to FIU Curaçao, and recordkeeping; (2) Custody and Asset Protection — segregation of client vs. corporate funds, multi-signature and HSM key management, daily on-chain reconciliations, insurance and loss-event runbooks; (3) IT and Cybersecurity — access management (least privilege, MFA, periodic reviews), data security (encryption in transit and at rest), incident response (triage 1h, report 24h, RCA 5d), business continuity (RTO/RPO per BCM §1.4); (4) Operations and Client Protection — complaints SLAs and KRI monitoring, fee transparency via New Product Approval, service level monitoring in weekly Ops Pack; (5) Third-Party and VASP Oversight — risk-based due diligence, KYV on documented risk basis, no automatic simplified treatment for regulated counterparties.

Evidence

  • Expected evidence: Risk and requirement mapping covering all five core internal control domains
  • Expected evidence: Control inventory and specifications with owner, objective, frequency, evidence and testing method
  • Expected evidence: Coverage and overlap analysis
  • Expected evidence: Gap issues and remediation
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample material risks and requirements for complete control mapping, ownership, evidence and testing expectations; verify sanctions screening coverage includes onboarding, periodic review, list-refresh and transaction/wallet-level screening; verify daily reconciliation between on-chain balances and internal ledgers
  • Testing frequency: quarterly and after material change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ICA Manual version 1.1.