Purpose
Ensure risk-based monitoring, counterparty review and CDD refresh continue throughout the relationship.
Objective
Client, transaction, wallet and VASP risks are detected, investigated and reflected in current risk classifications and review schedules.
Normative
Bitkaya shall monitor relevant activity, complete scheduled and trigger-based reviews, and escalate material inconsistencies or red flags. Monitoring is calibrated to the client’s risk profile and includes review of transaction size, frequency, velocity, pattern, source, destination, exposure to higher-risk wallets or services, suspicious wallet connections, unusual routing behaviour, and consistency with known client information, expected activity, and the stated purpose and nature of the relationship.
Control Activity
Monitoring tools and reviewers compare activity with the approved profile, assess relevant wallet and counterparty exposure, complete Travel Rule or wallet checks, and update CDD when a review or trigger occurs. Monitoring includes review of: large or unusual transactions; repeated smaller transactions indicating structuring; sudden changes in transaction size, velocity, or pattern; activity inconsistent with known profile; unusual routing; exposure to higher-risk wallets, services, typologies, or counterparties; suspicious off-ramping or on-ramping; and wallet links to sanctions exposure, darknet markets, mixers, stolen assets, fraud, ransomware, terrorism financing, or other elevated-risk indicators. Fiat red flags: Transaction Structuring/Smurfing; Sudden Activity Spikes; Unknown Deposit Origin. Onchain monitoring: crypto transaction monitoring provider scans non-custodial client wallets against over 20 risk sources and assigns proprietary crypto risk score of 0-25% (minimal), 25-75% (moderate caution), >75% (strongly advise reject). Tracing depth should ordinarily extend sufficiently to understand the relevant source and destination profile; enhanced tracing may extend materially further in escalated or higher-risk cases; the level of tracing and rationale must be documented. For relevant VASP counterparties, the KYV compliance file contains: licence/regulatory supervisor information; company registry extract; certificate of incorporation; ownership and control information; sanctions screening results; independent data sources; and any additional supporting information. Periodic review: low-risk every 3 years; medium-risk every 2 years; high-risk annually or when significant red flags arise. Ongoing monitoring includes sanctions-list refresh screening, transaction/wallet-level screening where required, and trigger-based reassessment for red flags, material changes, or unusual activity.
Evidence
- Expected evidence: alert queue and dispositions.
- Expected evidence: blockchain or wallet analysis (including crypto risk score from monitoring provider).
- Expected evidence: counterparty VASP assessment (KYV compliance file contents).
- Expected evidence: Travel Rule or wallet-control record.
- Expected evidence: periodic and trigger-review records (low-risk every 3 years; medium-risk every 2 years; high-risk annually).
- Expected evidence: updated risk score, approval and next-review date.
- Expected evidence: tracing depth documentation and rationale for conclusions reached.
- Evidence location: compliance evidence repository and applicable operating system.
- Retention: at least five years or longer where required.
- Testing method: Sample each risk tier, monitoring alerts, wallet or VASP cases and trigger reviews for timeliness and quality.
- Testing frequency: annual and after material monitoring changes.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved KYC & CDD Manual version 1.1
Assurance Assertions
- Reviews occur at the required frequency.
- Material triggers cause prompt reassessment.
- Monitoring and counterparty conclusions are documented.
Relationships
- Policy: POL-KYC-001 KYC and CDD Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedure: PROC-KYC-005 Perform Ongoing KYT KYV Monitoring and Periodic Review
- Blockchain analytics system: SYS-KYT-001 Crystal Intelligence Blockchain Analytics
- Calibration record: PUB-KYT-002 Crystal Intelligence Calibration and Change Record
History
- 2026-07-26: Created from the approved KYC & CDD Manual version 1.1.