Purpose
Ensure suspicious KYC matters are escalated and reported correctly and that supporting records remain secure and retrievable.
Objective
Compliance can reconstruct the client, decision, transaction and reporting history while protecting confidential FIU information.
Normative
Bitkaya shall document internal review, submit required UTRs to FIU Curaçao, prevent tipping off and retain relevant KYC and transaction records for at least five years. For internal purposes, Bitkaya may use case classifications such as SAR, STR, FFR, or PNMR to support review, prioritization, escalation, and recordkeeping. For external purposes, Bitkaya reports to the FIU Curaçao exclusively through a Unusual Transaction Report (UTR), where reporting is required. All internal escalation steps, review decisions, supporting analysis, and external reporting outcomes must be documented and retained in accordance with Bitkaya’s recordkeeping framework. All KYC files, customer profiles, blockchain wallet analytics, and transaction records must be stored securely for at least 5 years. Digital records must be encrypted, with strict access controls. Records should be easily retrievable for audits, compliance reviews, and regulator inspections.
Control Activity
Compliance reviews escalated matters, records its decision and external report where required. The evidence repository retains the complete file under access controls and supports retrieval testing. Bitkaya maintains a documented internal escalation and case-handling process for unusual or suspicious matters identified through onboarding, sanctions screening, transaction monitoring, staff escalation, or other control activities.
Evidence
- Expected evidence: internal case and escalation.
- Expected evidence: Compliance analysis and decision (with internal classification such as SAR, STR, FFR, or PNMR where used).
- Expected evidence: UTR and acknowledgement where applicable (submitted to FIU Curaçao exclusively through UTR process).
- Expected evidence: FIU or CBCS request and response.
- Expected evidence: retained client, wallet and transaction records (stored securely for at least 5 years, encrypted, with strict access controls).
- Expected evidence: access and retrieval test (records easily retrievable for audits, compliance reviews, and regulator inspections).
- Evidence location: compliance evidence repository and applicable operating system.
- Retention: at least five years or longer where required.
- Testing method: Sample escalations, reports and closed files; verify completeness, confidentiality, retention and retrieval.
- Testing frequency: annual.
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved KYC & CDD Manual version 1.1
Assurance Assertions
- Reportable matters were escalated and reported without delay.
- Confidential reporting information was access-controlled.
- Sampled records were complete and retrievable.
Relationships
- Policy: POL-KYC-001 KYC and CDD Manual
- Process: PRC-FCI-001 Financial Crime and Integrity
- Procedure: PROC-KYC-006 Escalate Suspicious Activity and Retain KYC Records
History
- 2026-07-26: Created from the approved KYC & CDD Manual version 1.1.