Objective

Ensure client assets remain segregated, reconciled, access-controlled, resilient and protected from misuse or loss, consistent with the approved Market Conduct & Trading Compliance Manual v1.1 section 6.

Control Activity

Operations and Technology maintain segregated accounts and wallets, complete three-day client-money placement, maintain one-to-one VA holdings, perform at least weekly reconciliation under the current model, issue monthly statements within 25 calendar days, restrict access, test recovery and review safeguarding providers at least annually. Material exceptions are restricted and escalated. Client fiat funds must be held in segregated bank accounts and virtual assets maintained in distinct wallets separate from company holdings; segregation practices will comply with jurisdiction-specific custody and safeguarding requirements including reporting to regulators where mandated; accurate records must be maintained to demonstrate full reconciliation of client balances at all times and independent audits may be conducted to verify compliance; under no circumstances shall client assets be used to finance company operations, lending or proprietary trading (MCT 6.1). The firm will use a combination of multi-signature wallets, hardware security modules (HSMs) and cold storage solutions to safeguard client assets; only authorized personnel may access custody systems subject to multi-factor authentication, role-based permissions and approval workflows; custody processes will include redundancies, secure backups and contingency procedures to ensure asset recovery in the event of technical failures or breaches; where third-party custodians are used, they will be subject to rigorous due diligence, contractual safeguards and ongoing monitoring (MCT 6.2). Insurance policies may include protection against cyberattacks, fraud, employee misconduct and operational failures; clients will be informed of the extent and limitations of any insurance coverage to ensure clarity about protections; the firm will regularly assess the adequacy of insurance arrangements in line with evolving risks, market conditions and regulatory guidance (MCT 6.3). Bitkaya will maintain firewalls, intrusion detection systems, penetration testing and security monitoring to protect against cyber threats; client information and transaction records will be encrypted in transit and at rest with strict access controls applied; a formal incident response plan will be maintained including escalation procedures, forensic investigation and mandatory reporting of material breaches to regulators and affected clients; disaster recovery protocols, offsite backups and redundancy systems will ensure resilience (MCT 6.4). Client assets must be safeguarded, but may also need to be restricted, held or prevented from moving where applicable law, sanctions controls, unusual activity review, fraud concerns or other legal restrictions require this; such matters must be managed through documented escalation and decision-making procedures (MCT 6 intro).

Evidence

  • Expected evidence: Segregated account and wallet inventory (client fiat in segregated bank accounts; virtual assets in distinct wallets separate from company holdings)
  • Expected evidence: Reconciliation and exception resolution (accurate records demonstrating full reconciliation of client balances at all times; independent audit evidence where conducted)
  • Expected evidence: Access and approval records (multi-factor authentication, role-based permissions, approval workflows)
  • Expected evidence: Custody and recovery control evidence (multi-signature wallets, HSMs, cold storage, redundancies, secure backups, contingency procedures)
  • Expected evidence: Third-party custodian review (due diligence, contractual safeguards, ongoing monitoring)
  • Expected evidence: Insurance assessment and client disclosure (scope, limitations, adequacy review, client notification)
  • Expected evidence: Safeguarding measures evidence (firewalls, intrusion detection, penetration testing, security monitoring, encryption in transit and at rest, incident response plan, disaster recovery)
  • Expected evidence: Documented escalation and decision-making where client assets are restricted, held or prevented from moving due to law, sanctions, unusual activity review, fraud or safeguarding concerns
  • Expected evidence: No-commingling evidence (client assets not used for company operations, lending or proprietary trading)
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample client balances and trace them to segregated holdings, reconciliation, access controls and resolved exceptions; verify no commingling; confirm custody controls (multi-sig, HSMs, cold storage, MFA, role-based permissions, approval workflows); verify insurance disclosure to clients; confirm safeguarding measures (cybersecurity, data protection, incident response, business continuity); confirm documented escalation for asset restrictions.
  • Testing frequency: scheduled reconciliation, continuous access control and periodic custody review

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved MCT Manual version 1.1.
  • 2026-07-26: Linked to the detailed SAFU controls and aligned explicit operating frequencies.