Purpose

Ensure each client receives a documented, risk-based CDD level, approval path and review cycle.

Objective

Risk classification drives proportionate evidence, monitoring and approval without weakening mandatory requirements.

Normative

Bitkaya shall document EWRA/SARA inputs and apply simplified, standard or enhanced measures only in accordance with approved thresholds and authority. Within a building block the highest applicable score is always chosen. The resulting risk rating determines the depth of due diligence, frequency of review, intensity of transaction monitoring, escalation thresholds, and any enhanced control measures. Risk Classification is formally documented as either Initial Risk Classification (onboarding) or Recurring Risk Classification (periodic review, or red flag/transaction monitoring trigger-based), and is prepared by Operations.

Low-Risk: Simplified Due Diligence may only be applied where the client has been assessed and documented as low risk. The file must still contain sufficient information to establish identity, understand the purpose and intended nature of the relationship, confirm screening outcomes, and support the risk classification. Review at least every three years.

Medium-Risk: Standard Due Diligence applies. Source of funds at least on a self-declaration basis. Review at least every two years.

High-Risk: Enhanced Due Diligence applies. Source of wealth must be assessed before approval. Enhanced monitoring and escalation thresholds apply. Review at least annually. No high-risk client may be approved before source of wealth has been assessed.

Control Activity

Operations prepares the risk classification. Management approves low- and medium-risk clients. Compliance additionally approves high-risk clients and verifies source-of-wealth assessment before approval. Low-risk and medium-risk clients require management approval before activation. High-risk clients require Compliance approval in addition before onboarding may be completed. Where high-risk classification triggers enhanced due diligence requirements, including source of wealth assessment, those requirements must be completed before approval is granted.

Evidence

  • Expected evidence: completed EWRA/SARA assessment with documented inputs and rationale (highest applicable score within each building block).
  • Expected evidence: CDD or EDD checklist.
  • Expected evidence: source-of-funds or source-of-wealth evidence (self-declaration minimum for medium-risk; full assessment for high-risk).
  • Expected evidence: proportionality rationale (justification for simplified or enhanced CDD, reference to applicable CBCS and FATF guidance, risk-based rationale supported by EWRA scoring, Board or Compliance approval record).
  • Expected evidence: approval and review date (low-risk every 3 years; medium-risk every 2 years; high-risk annually).
  • Evidence location: compliance evidence repository and applicable operating system.
  • Retention: at least five years or longer where required.
  • Testing method: Sample each risk tier and verify scoring, evidence, approval and review frequency.
  • Testing frequency: annual and after methodology changes.

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved KYC & CDD Manual version 1.1

Assurance Assertions

  • Simplified measures are supported by documented low risk.
  • High-risk clients have source-of-wealth assessment and Compliance approval.
  • Review cycles match the approved risk tier.

Relationships

History

  • 2026-07-26: Created from the approved KYC & CDD Manual version 1.1.