Purpose

Ensure staff competence, proportionality decisions, governance reporting and independent KYC assurance remain current.

Objective

The KYC framework scales with risk and operations without compromising legal minimums or control effectiveness.

Normative

Bitkaya shall train relevant personnel, document proportionality decisions, report to the Board and independently review KYC/CDD effectiveness. Annual AML/KYC training for all employees, including case studies on crypto-related financial crime. Specialized training for onboarding, risk, and compliance teams on blockchain forensics tools (e.g., Chainalysis, Elliptic). Awareness initiatives to reinforce vigilance, e.g., newsletters on emerging ML/TF risks in crypto markets. Proportionality determinations must include: justification for simplified or enhanced CDD; reference to applicable CBCS and FATF guidance; risk-based rationale supported by EWRA scoring; and Board or Compliance approval record. These records are retained for five years and are available for regulatory review by CBCS or FIU Curaçao upon request.

Control Activity

Compliance monitors annual and role-specific training, reviews proportionality at least annually and after material change, reports quarterly to the Board and tracks independent-review findings to closure. The Board approves the proportional KYC/CDD framework and ensures resource allocation and staffing remain adequate. The Compliance Officer (MLRO) oversees proportionality assessments, maintains the CDD risk matrix, and ensures simplified measures do not create residual risks. Internal/External Audit reviews proportionality justifications, testing that simplified CDD processes remain effective and risk thresholds are correctly applied. Management and staff implement and document all proportional controls, ensuring auditability and traceability. Proportionality is re-evaluated during the annual compliance review and upon any significant operational change. As the company matures, staffing, technology, and policies will scale; manual controls will transition to automated, integrated compliance workflows; CBCS feedback and external audit results will directly inform proportionality adjustments. Internal Audit conducts independent reviews of KYC/CDD effectiveness and regulatory compliance.

Evidence

  • Expected evidence: training plan, materials and completion (annual AML/KYC training with crypto case studies; specialized blockchain forensics training for onboarding/risk/compliance teams).
  • Expected evidence: role-specific competency evidence.
  • Expected evidence: proportionality assessment and approval (justification, CBCS/FATF guidance reference, EWRA rationale, Board/Compliance approval; retained 5 years).
  • Expected evidence: Board compliance reporting (quarterly updates).
  • Expected evidence: independent review report (KYC/CDD effectiveness and regulatory compliance).
  • Expected evidence: remediation and closure evidence.
  • Evidence location: compliance framework library and evidence repository.
  • Retention: according to the approved AML/KYC recordkeeping framework.
  • Testing method: Inspect the latest training cycle, proportionality review, Board reports and independent-review remediation.
  • Testing frequency: annual and after material framework changes.

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved KYC & CDD Manual version 1.1

Assurance Assertions

  • Required staff completed current training.
  • Simplified measures have documented risk rationale.
  • Independent findings have owners, due dates and closure evidence.

Relationships

History

  • 2026-07-26: Created from the approved KYC & CDD Manual version 1.1.