Objective
Ensure CBCS reports, notifications and inquiry responses are timely, factual, approved and traceable, in accordance with CBCS reporting obligations (section 2.1) and the Management Board’s approval authority (section 3.3).
Control Activity
Compliance maintains a CBCS submission and communication register and checks applicability, approval, evidence, receipt and follow-up. Specifically:
Reporting obligation verification: The register must cover all CBCS reporting obligations: periodic compliance reports (AML/CFT, governance, risk management) filed quarterly (due 30 days after quarter-end), annual audited financial statements (due 5 months after year-end), notifications of material changes (ownership, management, business model), and incident reporting (cybersecurity, fraud, operational failures).
Board approval verification: Material submissions — including license applications, audited financial statements, compliance reports, and responses to official inquiries — must be formally reviewed and approved by the Management Board, which carries ultimate accountability for governance and acts as the formal point of contact for regulators in cases requiring executive-level dialogue.
Communication format verification: Submissions must use the required channel (CBCS portal or formal letters signed by authorized representatives). In-person or telephone conversations must be minimized and documented in writing immediately afterward.
Breach notification verification: Where a CBCS-related breach occurs, verify escalation to senior management within 24 hours and proactive regulator notification without undue delay, including factual details of the breach, root cause, and containment steps.
Evidence
- Expected evidence: Applicability and materiality assessment
- Expected evidence: Approved submission or response
- Expected evidence: Receipt and communication log
- Expected evidence: Follow-up and corrective action
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample CBCS matters for timely assessment, approval, submission and completed follow-up
- Testing frequency: quarterly
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.