Objective

Ensure second-line tests are independent, risk-based, reproducible and followed by verified remediation.

Control Activity

Compliance maintains a testing plan and methodology, reviews completed tests for population, sample, evidence, conclusion and finding quality, and monitors follow-up testing. Second line testing includes thematic and control effectiveness reviews over key AML/CFT/CPF controls: onboarding approval controls by risk tier; source of funds and source of wealth requirements; sanctions screening coverage and tool governance; false-positive closure rationale; unresolved-alert stop controls; internal escalation and case-classification processes; UTR decisioning and reporting controls; wallet or transaction tracing practices in escalated cases; and periodic review cadence and file completeness by risk classification. Testing outcomes, remediation actions, and overdue items must be tracked and reported through the governance framework.

Evidence

  • Expected evidence: Risk-based testing plan
  • Expected evidence: Test design, population and sample
  • Expected evidence: Testing sheets and evidence covering the nine AML/CFT/CPF thematic areas
  • Expected evidence: Findings and management responses
  • Expected evidence: Follow-up verification
  • Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: quality-review a sample of completed tests for independence, reproducibility, supported conclusions and closure verification; verify coverage of all nine thematic AML/CFT/CPF control areas
  • Testing frequency: quarterly

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ICA Manual version 1.1.