PDF Source Sections

  • Section 4 (Rights of Data Subjects), Section 5 (Legal Bases), Section 8 (Security & Risk Management), Section 9 (FATF-Specific Data Handling)

Objective

Ensure compliance-sensitive data is restricted, disclosed only with authority and protected against tipping off.

Control Activity

Compliance reviews access to AML, sanctions, case and reporting records quarterly and approves disclosures, data-subject restrictions and confidentiality exceptions under documented legal and regulatory duties. The review verifies that: access to data relating to sanctions screening, internal compliance escalations, wallet identifiers, transaction monitoring, and regulatory reporting is restricted strictly to those with an operational, legal, or control need to know per Section 8; false positives, alerts, case notes, escalation rationale, restrictive measures, UTR records, and related supporting documentation are handled with heightened confidentiality and control per Section 8; the eight FATF data categories from Section 9 (identification and verification data, source of funds and source of wealth information, beneficial ownership and control information, sanctions and PEP screening results, blockchain wallet identifiers and risk indicators, unusual activity review records, internal case-management records and internal classifications, external UTR reporting records) are properly restricted; data subjects are not informed in a manner that would breach applicable confidentiality or anti-tipping-off obligations per Section 4; and where data is processed for sanctions screening, beneficial ownership review, unusual activity handling, internal case classification, or UTR reporting, the primary legal basis is legal obligation and related compliance necessity rather than consent per Section 5.

Evidence

  • Expected evidence: Access matrix, approvals and logs verifying need-to-know restriction per Section 8
  • Expected evidence: Case and reporting confidentiality records covering the eight FATF data categories from Section 9
  • Expected evidence: Disclosure authority and secure transmission evidence with legal obligation basis per Section 5
  • Expected evidence: Rights-request restriction and anti-tipping-off decisions per Section 4
  • Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample users, records, disclosures and requests for justified need-to-know access per Section 8, coverage of the eight FATF data categories per Section 9, legal obligation basis per Section 5, authorization, secure handling, anti-tipping-off review per Section 4, and protected information
  • Testing frequency: quarterly

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-28: Enriched with verification requirements from PDF sections 4, 5, 8, and 9 — added eight FATF data categories, compliance-sensitive record handling, anti-tipping-off verification, and legal-obligation basis check.
  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.