Objective
Ensure second-line tests are independent, risk-based, reproducible and followed by verified remediation.
Control Activity
Compliance maintains a testing plan and methodology, reviews completed tests for population, sample, evidence, conclusion and finding quality, and monitors follow-up testing. Second line testing includes thematic and control effectiveness reviews over key AML/CFT/CPF controls: onboarding approval controls by risk tier; source of funds and source of wealth requirements; sanctions screening coverage and tool governance; false-positive closure rationale; unresolved-alert stop controls; internal escalation and case-classification processes; UTR decisioning and reporting controls; wallet or transaction tracing practices in escalated cases; and periodic review cadence and file completeness by risk classification. Testing outcomes, remediation actions, and overdue items must be tracked and reported through the governance framework.
Evidence
- Expected evidence: Risk-based testing plan
- Expected evidence: Test design, population and sample
- Expected evidence: Testing sheets and evidence covering the nine AML/CFT/CPF thematic areas
- Expected evidence: Findings and management responses
- Expected evidence: Follow-up verification
- Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: quality-review a sample of completed tests for independence, reproducibility, supported conclusions and closure verification; verify coverage of all nine thematic AML/CFT/CPF control areas
- Testing frequency: quarterly
Relationships
- Policy: POL-ICA-001 Internal Controls and Audit Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-ICA-004 Perform Second Line Control Testing
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved ICA Manual version 1.1.