Objective

Ensure authorized FIU and sanctions reports are submitted without delay, kept confidential and coordinated with separate restrictive and CBCS duties, in accordance with the FIU Curaçao reporting obligations, the escalation framework (section 4.3), the recordkeeping requirements for AML/CFT/CPF and sanctions matters (section 4.4), and the sanctions-hits handling requirements (section 7.4).

Control Activity

Compliance reviews each report for decision authority, required data, portal receipt, anti-tipping-off, restrictive measures and follow-up. Specifically:

FIU reporting verification: UTRs must be filed electronically via the FIU system without delay for all transactions meeting objective or subjective indicators, in compliance with NORUT. The Compliance Officer must be immediately notified for escalations.

Confidentiality verification: Strict confidentiality must be maintained — non-disclosure to customer (tipping-off prohibition) must be confirmed for each case.

Escalation verification (section 4.3): Each matter must be assessed across separate dimensions: (1) internal escalation and management visibility, (2) external FIU reporting obligations, (3) CBCS supervisory reporting or notification obligations, and (4) operational restrictive measures including blocking, freezing, or holding transactions or relationships. These must be documented separately, not treated as a single generic event type.

Recordkeeping verification (section 4.4): The retained record must include, where applicable: the alert or trigger, internal classification, review notes and rationale, basis for false-positive closure, status and outcome of escalation, restrictive measures taken, UTR filing details, and any CBCS notification or reporting record.

Sanctions-hits verification (section 7.4): Confirmed sanctions matches must be assessed for immediate legal obligations relating to restrictive measures, asset blocking or freezing, FIU reporting, and CBCS notification — each considered separately and documented clearly.

Evidence

  • Expected evidence: Reporting decision and supporting case
  • Expected evidence: FIU submission and receipt
  • Expected evidence: Restrictive-action and CBCS assessment
  • Expected evidence: Request and follow-up records
  • Evidence location: source evidence in SYS-IT-001 Odoo Automated Compliance Monitoring, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: inspect all or a risk-based sample of reports for timeliness, completeness, confidentiality and separate obligation assessment
  • Testing frequency: quarterly and after each material case

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.