Objective

Ensure market-conduct risks and misconduct are detected, escalated, independently reviewed, reported, remediated and reflected in improved controls, consistent with the approved Market Conduct & Trading Compliance Manual v1.1 sections 8 through 12.

Control Activity

Compliance performs risk-based surveillance and quarterly reporting, coordinates annual training and periodic independent review, tracks discipline and external-reporting decisions, supports regulatory inquiries and verifies findings and proportionality actions to closure. Bitkaya maintains surveillance and monitoring processes proportionate to the risks arising from its trading and market-facing activity; surveillance may include review of unusual pricing or execution patterns, front running or market abuse indicators, suspicious or inconsistent client behaviour, unusual wallet destinations or settlement routes, elevated-risk off-ramping or on-ramping behaviour, activity inconsistent with the client’s profile, and repeated, structured or otherwise unusual transactions that may require escalation under Bitkaya’s AML/CTF/CPF framework; where review identifies a material concern, the matter must be documented and escalated appropriately (MCT 8.1). Internal audits will be conducted at defined intervals to evaluate compliance with market conduct, AML/CFT, custody and data protection policies; internal audit functions will remain independent of day-to-day business operations to ensure impartial assessments; audit scope and frequency will reflect the firm’s risk profile, business growth and regulatory requirements; findings will be reported to senior management and the Board with corrective actions tracked to completion (MCT 8.2). Depending on the severity of misconduct, disciplinary actions may include verbal/written warnings, mandatory training, reassignment, suspension or termination; serious violations may be reported to regulators, law enforcement or other authorities as required by law; managers and supervisors will also be held accountable if they fail to detect or respond to misconduct within their oversight responsibilities; employees who report suspected misconduct in good faith will be protected from retaliation (MCT 8.3). Bitkaya maintains an internal process for escalation and review of unusual or suspicious matters arising from trading activity, settlement activity, client behaviour, wallet exposure or related conduct; internal classifications may be used for case handling, prioritization and recordkeeping; external FIU reporting, where required by law, is made through the UTR process; where a matter also involves sanctions, client asset restrictions, fraud concerns or cybersecurity issues, those dimensions must be assessed separately and managed in coordination with the relevant control functions (MCT 9.2). Bitkaya will cooperate fully with supervisory authorities, providing timely access to records, systems and personnel upon request; regulatory inquiries, inspections or audits must be escalated immediately to the Compliance and Legal teams who will coordinate responses; where appropriate, Bitkaya will participate in industry and regulatory consultations contributing to the development of balanced digital asset regulation; a Regulatory Affairs function will oversee ongoing relationships with supervisory bodies ensuring consistency in communication (MCT 9.3). Bitkaya aligns its practices with the Global Digital Finance (GDF) Code of Conduct, reinforcing adherence to international standards of ethical behavior, transparency, accountability and consumer protection (MCT 10). Proportionality is applied across trading surveillance and best execution (manual reviews of a sample of trades; automated systems introduced as trade volume increases), market manipulation and insider trading detection (behavioral red-flag triggers with escalation to Compliance; transition to automated blockchain analytics as activity scales), conflicts of interest (simplified register; formal matrix introduced as products or partnerships are added), order handling and client fairness (standardized manual checklists; audit logs and automated alerts added later), client communication and promotion (all marketing material pre-approved by Compliance; future scalability through templated automated review workflows), training and awareness (annual training sessions covering fair dealing, insider trading and conduct ethics), and monitoring and reporting (quarterly compliance reports to management summarizing breaches, complaints or anomalies) (MCT 12.4).

Evidence

  • Expected evidence: Surveillance plan, alerts and reviews (covering unusual pricing/execution patterns, front running/market abuse indicators, suspicious/inconsistent client behaviour, unusual wallet destinations/settlement routes, elevated-risk off-ramping/on-ramping, profile-inconsistent activity, repeated/structured transactions requiring AML/CTF/CPF escalation)
  • Expected evidence: Investigation and disciplinary action (graduated sanctions: verbal/written warnings, mandatory training, reassignment, suspension, termination; regulatory reporting for serious violations; manager accountability; whistleblower protection)
  • Expected evidence: Independent audit report (defined-interval reviews of market conduct, AML/CFT, custody and data protection; independent of day-to-day operations; risk-based scope and frequency; findings reported to senior management and Board with corrective actions tracked to completion)
  • Expected evidence: Regulatory inquiry and response (full cooperation with supervisory authorities; timely access to records, systems and personnel; immediate escalation to Compliance and Legal; Regulatory Affairs function for relationship management)
  • Expected evidence: Annual training completion (fair dealing, insider trading, conduct ethics; frequency and content expanding as staffing and products diversify)
  • Expected evidence: Quarterly compliance reports (breaches, complaints, anomalies; frequency and depth scaling with business volume)
  • Expected evidence: Remediation and proportionality review (proportionality across all market-conduct domains; periodic reassessment; incremental automation; feedback integration; progressive maturity from manual to system-supported controls)
  • Expected evidence: AML/CFT escalation and UTR reporting evidence (internal process for escalation and review; internal classifications; external FIU reporting through UTR process; coordination with sanctions, fraud, cybersecurity control functions)
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample alerts and findings through investigation, escalation, reporting and verified closure and inspect quarterly reporting and annual training; verify surveillance covers all listed review categories; confirm disciplinary actions are proportionate and graduated; confirm regulatory cooperation and ADR/UTR reporting; verify proportionality application across all market-conduct domains and continuous-improvement commitments.
  • Testing frequency: ongoing surveillance, quarterly reporting, annual training and proportionality review

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved MCT Manual version 1.1.