PDF Source Sections
- Section 1 (Purpose and Scope), Section 2 (Key Principles), Section 5 (Legal Bases), Section 11 (Governance & Oversight), Section 13.4.1 (Data Governance and Documentation)
Objective
Ensure material processing is inventoried, supported by documented purpose and legal basis, risk-assessed and approved.
Control Activity
Compliance reviews the processing inventory and related legal-basis and privacy-risk assessments annually and before high-risk or materially changed processing is approved. The review verifies that: the inventory covers all data categories listed in Section 1 (customer due diligence, beneficial ownership, sanctions screening, wallet and blockchain identifiers, transaction-monitoring, internal case-management, unusual transaction reporting, regulatory correspondence, access logs, and third-party processing); each processing purpose is mapped to one of the five lawful grounds from Section 5 (contractual necessity, legal obligation, legitimate interests, public interest, or consent) and consent is not used where legal obligation is the true basis; documentation requirements are scaled by risk per Section 13.4.1 (simplified registers for low-risk data, comprehensive DPIAs for high-risk processing); and the Section 11 review criteria are addressed (privacy controls appropriateness, new system/vendor/product/jurisdiction risk, role-based access, retention alignment, cross-manual consistency).
Evidence
- Expected evidence: Processing inventory covering all Section 1 data categories with data-flow records
- Expected evidence: Legal-basis assessments documenting one of the five lawful grounds from Section 5 with no consent misuse for AML/sanctions processing
- Expected evidence: Privacy impact assessments and approvals scaled by risk per Section 13.4.1 (simplified for low-risk, comprehensive DPIA for high-risk)
- Expected evidence: Electronic repository records with version-controlled logs for traceability and accountability
- Expected evidence: Annual review and remediation records addressing the five Section 11 review criteria
- Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample material processing and changes for complete inventory fields (all Section 1 categories), appropriate basis (five lawful grounds from Section 5), risk-scaled risk assessment per Section 13.4.1, and approval with Section 11 review criteria documented
- Testing frequency: annual and per high-risk or material change
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-28: Enriched with verification requirements from PDF sections 1, 2, 5, 11, and 13.4.1 — expanded inventory scope, five lawful grounds verification, risk-scaled DPIA check, and five Section 11 review criteria.
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.