PDF Source Sections

  • Section 1 (Purpose and Scope), Section 2 (Key Principles), Section 5 (Legal Bases), Section 11 (Governance & Oversight), Section 13.4.1 (Data Governance and Documentation)

Objective

Ensure material processing is inventoried, supported by documented purpose and legal basis, risk-assessed and approved.

Control Activity

Compliance reviews the processing inventory and related legal-basis and privacy-risk assessments annually and before high-risk or materially changed processing is approved. The review verifies that: the inventory covers all data categories listed in Section 1 (customer due diligence, beneficial ownership, sanctions screening, wallet and blockchain identifiers, transaction-monitoring, internal case-management, unusual transaction reporting, regulatory correspondence, access logs, and third-party processing); each processing purpose is mapped to one of the five lawful grounds from Section 5 (contractual necessity, legal obligation, legitimate interests, public interest, or consent) and consent is not used where legal obligation is the true basis; documentation requirements are scaled by risk per Section 13.4.1 (simplified registers for low-risk data, comprehensive DPIAs for high-risk processing); and the Section 11 review criteria are addressed (privacy controls appropriateness, new system/vendor/product/jurisdiction risk, role-based access, retention alignment, cross-manual consistency).

Evidence

  • Expected evidence: Processing inventory covering all Section 1 data categories with data-flow records
  • Expected evidence: Legal-basis assessments documenting one of the five lawful grounds from Section 5 with no consent misuse for AML/sanctions processing
  • Expected evidence: Privacy impact assessments and approvals scaled by risk per Section 13.4.1 (simplified for low-risk, comprehensive DPIA for high-risk)
  • Expected evidence: Electronic repository records with version-controlled logs for traceability and accountability
  • Expected evidence: Annual review and remediation records addressing the five Section 11 review criteria
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample material processing and changes for complete inventory fields (all Section 1 categories), appropriate basis (five lawful grounds from Section 5), risk-scaled risk assessment per Section 13.4.1, and approval with Section 11 review criteria documented
  • Testing frequency: annual and per high-risk or material change

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-28: Enriched with verification requirements from PDF sections 1, 2, 5, 11, and 13.4.1 — expanded inventory scope, five lawful grounds verification, risk-scaled DPIA check, and five Section 11 review criteria.
  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.