Objective
Ensure internal audits follow an approved risk-based plan and produce independent, evidence-supported conclusions.
Control Activity
The Board forum approves the annual audit plan and receives engagement reports; Compliance monitors plan completion, independence, scope limitations and transfer of findings to remediation tracking. Internal Audit is independent from management and reports to the Audit and Risk Committee of the Board. The annual risk-based audit covers AML/CFT/CPF framework, custody and reconciliation controls, IT/cybersecurity, business continuity, and governance and reporting. For a small VASP, internal audits are conducted annually on high-risk areas and biannually for low-risk domains. Internal audits may be supplemented by independent third-party reviews when in-house capacity is limited. Findings are consolidated into a single quarterly report to the Board.
Evidence
- Expected evidence: Audit universe and risk ranking
- Expected evidence: Approved annual plan and changes
- Expected evidence: Independence, scope and workpapers demonstrating independence from management
- Expected evidence: Audit reports and management responses
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect annual approval and sample engagements for planned coverage of AML/CFT/CPF, custody, IT/cybersecurity, business continuity and governance; verify sufficient evidence, independent conclusion and finding transfer to remediation tracking
- Testing frequency: quarterly monitoring and annual plan review
Relationships
- Policy: POL-ICA-001 Internal Controls and Audit Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-ICA-003 Plan and Conduct Risk Based Internal Audits
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved ICA Manual version 1.1.