Objective

Ensure findings and material failures are escalated, owned, remediated and independently verified before closure.

Control Activity

Compliance maintains the findings register, reports material and overdue items, challenges extensions and requires independent follow-up evidence before closure. Material control failures, sanctions true matches, unresolved material sanctions issues, UTR-reportable cases, and significant AML/CFT/CPF control weaknesses must be escalated through the appropriate governance channels. Reporting distinguishes between internal management escalation, operational restrictive measures, external UTR reporting status, and CBCS notification or reporting status. Findings are consolidated into a single quarterly report to the Board, supported by corrective action tracking within existing compliance registers.

Evidence

  • Expected evidence: Findings register and severity
  • Expected evidence: Management responses and action plans
  • Expected evidence: Escalation and regulatory status distinguishing internal management escalation, operational restrictive measures, external UTR reporting status, and CBCS notification or reporting status
  • Expected evidence: Overdue and trend reporting
  • Expected evidence: Follow-up testing and closure approval
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample open and closed findings for timely escalation, accountable action, evidence-based completion and independent verification; verify reporting distinguishes the four reporting categories
  • Testing frequency: monthly monitoring and quarterly reporting

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ICA Manual version 1.1.