Objective

Ensure assurance personnel are competent, records are retained and risk-based proportionality remains justified.

Control Activity

Compliance monitors training and pass rates, evidence retention, annual document review, audit frequency, combined-role safeguards and Board approval of proportionality. Role-based training is provided for Board, Product/Tech, and Ops/Client-facing staff with onboarding plus annual refresh and a minimum 90 percent pass rate; remediation is required for failed assessments. Culture KPIs tracked include speak-up rates, phishing test results, time-to-close issues, and training completion. Document management is owned by the Head of Risk (with Compliance and MLRO) with annual review cadence or upon material regulatory/product/incident change; change log captures version, date, summary, approvers, and impacted procedures. All audit and testing activities are supported by evidence-based documentation (control testing sheets, management responses, follow-up verification logs) retained in a central digital repository for a minimum of five years. Proportionality is applied per the five guiding principles: risk-based application, startup-appropriate design, scalability, efficiency and resource alignment, and continuous alignment. The Board or Audit and Risk Committee assesses annually whether proportionality justifications remain appropriate, ensuring the framework remains fit-for-purpose, efficient, and compliant with CBCS standards.

Evidence

  • Expected evidence: Training assignments, results and remediation with 90 percent pass rate verification
  • Expected evidence: Culture indicators (speak-up rates, phishing test results, time-to-close issues, training completion)
  • Expected evidence: Audit and testing retention records (minimum five years in central digital repository)
  • Expected evidence: Policy and version review with change log (version, date, summary, approvers, impacted procedures)
  • Expected evidence: Proportionality, independence and Board assessment covering the five guiding principles and the proportionality domain table
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: minimum five years for audit and testing evidence; according to the applicable approved policy and Bitkaya record-retention requirements for other records.
  • Testing method: reconcile training to in-scope roles and verify 90 percent pass rate; inspect annual retention, policy and proportionality review for supported decisions; verify the five guiding principles and proportionality domain table are documented and Board-assessed
  • Testing frequency: annual

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved ICA Manual version 1.1.