Objective
Ensure regulatory interactions are authorized, factual, logged, secure and retrievable, in accordance with the Communication Framework (section 4) and the Documentation and Audit Trail requirements (section 8.5).
Control Activity
Compliance maintains the regulatory communication log and performs quarterly completeness and retention review. Specifically:
Tone verification: Communications must be professional, transparent, factual, and timely — presenting information objectively without speculation, avoiding jargon, disclosing all relevant facts (even if adverse) with corrective measures highlighted, and delivered within regulatory deadlines.
Format verification: Written correspondence is the preferred format (formal letters signed by authorized representatives, emails, or regulatory portals). In-person or telephone conversations must be minimized and documented in writing immediately afterward.
Centralized Regulatory Communication Log verification (section 8.5): The log must record for each communication: date and type of communication, counterparty regulator, subject and summary, responsible preparer and approver, and follow-up or corrective action (if applicable).
AML/CFT/CPF recordkeeping verification (section 4.4): For AML/CFT/CPF and sanctions matters, verify the record includes, where applicable: the alert or trigger, internal classification, review notes and rationale, basis for false-positive closure, status and outcome of escalation, restrictive measures taken, UTR filing details, and any CBCS notification or reporting record.
Retention verification: All records must be retained for at least five (5) years, or longer when required by regulators or ongoing reviews. AML, FIU and sanctions records must be restricted to prevent unauthorized disclosure (tipping-off prohibition).
Evidence
- Expected evidence: Communication log and correspondence
- Expected evidence: Requests, responses and approvals
- Expected evidence: Meeting and call records
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample communications for authorization, factual response, contemporaneous logging and secure retention
- Testing frequency: quarterly
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.