Purpose

Prevent activation of clients whose identity, legal existence, ownership, control or authority has not been adequately established.

Objective

Every accepted client file contains complete, reliable and approved verification evidence appropriate to client type and risk.

Normative

Bitkaya shall not activate a relationship before required identity, entity, beneficial-ownership, representative, screening and approval evidence is complete. For natural persons, individuals must provide a valid passport, national identity card, cedula, or driving licence, and complete any required liveness, biometric, or authenticity checks. For legal entities, verification may include registry extracts, incorporation documents, constitutional documents, authorized signatory evidence, ownership documentation, and supporting identification records for relevant natural persons. Only clients whose identity, legal existence, and control structure can be adequately established and understood are permitted to access Bitkaya’s services.

Control Activity

Operations completes the onboarding checklist and verification evidence. The designated approver confirms completeness before activation. High-risk and unresolved cases require Compliance review. For low-risk corporate clients the minimum file should ordinarily include at least: a recent registry extract or equivalent official corporate record; a signed UBO declaration; identification of the authorized signatory or representative; sanctions and PEP screening results for the entity, authorized signatory, and declared UBOs; and documentation of the purpose and intended nature of the relationship. For medium-risk and high-risk corporate clients, additional measures proportionate to risk may include supporting ownership evidence, additional verification of controllers and signatories, financial background information, source of funds or source of wealth review, and enhanced adverse information screening. No individual or corporate client relationship may be activated until the applicable due diligence requirements, approvals, and sanctions checks have been completed.

Evidence

  • Expected evidence: client onboarding checklist.
  • Expected evidence: identification and verification report (passport, national ID, cedula, or driving licence for individuals; registry extracts, incorporation documents, constitutional documents, authorized signatory evidence for entities).
  • Expected evidence: registry, ownership and authority records where applicable.
  • Expected evidence: screening results (sanctions, PEP, adverse information).
  • Expected evidence: source-of-funds or source-of-wealth evidence proportionate to risk classification (self-declaration minimum for medium-risk; full source-of-wealth assessment for high-risk).
  • Expected evidence: approval record preceding activation (management approval for low/medium-risk; Compliance approval for high-risk).
  • Evidence location: compliance evidence repository and applicable operating system.
  • Retention: at least five years or longer where another applicable requirement controls.
  • Testing method: Sample individual and corporate clients and confirm required evidence and approval existed before activation.
  • Testing frequency: annual and after material onboarding changes.

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved KYC & CDD Manual version 1.1

Assurance Assertions

  • No sampled client was activated with mandatory verification incomplete.
  • Beneficial owners and authorized persons are identified and verified where required.
  • Verification exceptions are documented and approved.

Relationships

History

  • 2026-07-26: Created from the approved KYC & CDD Manual version 1.1.