Objective

Ensure external, regulatory and financial-statement audits receive complete, accurate, approved and traceable evidence.

Control Activity

The audit coordinator maintains a request register and controlled evidence room, assigns owners, quality-checks submissions and records reports and resulting actions. Regulatory readiness is maintained through organized evidence libraries including policies, client due diligence records, screening outputs, internal case-management records, UTR files, escalation packs, restrictive-measure records, remediation evidence, and relevant control documentation. For financial statement audits, support covers crypto assets and liabilities, revenue recognition, custody and safeguarding, IT and cyber controls, financial crime and compliance, and disclosures. Key audit risks addressed include existence and rights (cryptographic proof), valuation, completeness, revenue recognition, and safeguarding. Procedures and evidence include wallet proofs, on-chain reconciliation, independent price testing, revenue recalculations, confirmations from banks/custodians/stablecoin issuers, and IT control testing. Deliverables include audit opinion, management letter, and audit committee report.

Evidence

  • Expected evidence: Scope, authority and request register
  • Expected evidence: Evidence ownership and quality review
  • Expected evidence: Approved submissions and interviews
  • Expected evidence: Audit opinions, reports and management letters (clean, qualified, adverse, or disclaimer)
  • Expected evidence: Management letter with control gaps and remediation recommendations
  • Expected evidence: Audit committee report if applicable (key matters, adjustments, uncorrected misstatements)
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample audit requests for timely ownership, complete approved evidence, traceable submission and captured findings; verify evidence libraries include policies, CDD records, screening outputs, case-management records, UTR files, escalation packs, restrictive-measure records, and remediation evidence
  • Testing frequency: after each audit and annual review

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ICA Manual version 1.1.