Objective

Ensure breaches are escalated and remediated and reporting competence and proportionality remain current, in accordance with the Training & Awareness (section 6), Breach Management & Regulator Interaction (section 7), and Proportionality Implementation (section 8) of the approved Regulatory Reporting & Communication Manual.

Control Activity

Compliance monitors 24-hour breach escalation, regulator notification, remediation, training completion and annual proportionality review. Specifically:

Breach escalation verification (section 7.1): Verify that any breach, delay, or non-compliance is escalated to senior management within 24 hours of detection, ensuring leadership is promptly aware of compliance risks and a centralized record of incidents is maintained.

Regulator notification verification (section 7.2): Verify that the Compliance Officer has evaluated whether a breach or delay must be disclosed to regulators (CBCS, FIU, or Tax Authorities) and, where required, has notified without undue delay with factual details including the nature of the breach, its root cause, and steps taken to contain it. Verify coordination with the Management Board for regulator interactions involving strategic or reputational risks.

Corrective action verification (section 7.3): Verify that corrective actions are formally documented and tracked until resolution, with responsibility assigned, timelines established, progress monitored through compliance logs, and post-incident reviews conducted to identify lessons learned and strengthen internal controls.

Sanctions-hits verification (section 7.4): Verify that confirmed sanctions matches are assessed separately for restrictive measures, asset blocking or freezing, FIU reporting, and CBCS notification — each documented clearly rather than treated as a single generic breach event.

Training verification (section 6):

  • Annual AML/CFT training for all employees — verify attendance is tracked and completion is documented, covering NORUT, CBCS provisions, FIU guidance, recognition of unusual/suspicious activities, and escalation procedures.
  • Semiannual refresher training for Finance and Compliance staff — verify coverage of new CBCS circulars, FIU reporting requirements, tax authority guidelines, lessons learned from audits/inspections, and cross-departmental collaboration.
  • Quarterly reinforcement of internal communication protocols — verify reminders on escalation procedures, internal briefings on emerging regulatory risks, simulated communication drills (mock regulator requests), and documentation in the training log.
  • Verify training content covers AML/CFT/CPF reporting obligations, internal case classification, UTR reporting procedures, sanctions-related escalation, documentation standards, confidentiality requirements, and circumstances requiring CBCS supervisory notification or reporting.

Proportionality verification (section 8): Verify annual proportionality review by the Compliance Officer, assessing: risk-based application of reporting scope/frequency/depth, clarity and simplicity of communications, efficiency and scalability of processes, accountability and traceability of submissions, and continuous alignment with the company’s size, risk exposure, and supervisory expectations. Verify the proportionality domain assessment (CBCS prudential/AML reports, FIU submissions, tax/fiscal reporting, incident/breach notifications, communication/recordkeeping, training/awareness) and that continuous improvement measures (technology integration, independent audit assessment, regulator/auditor feedback incorporation) are tracked.

Evidence

  • Expected evidence: Breach and notification records
  • Expected evidence: Remediation and post-incident review
  • Expected evidence: Training, refresher and drill logs
  • Expected evidence: Annual proportionality assessment
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample breaches and reconcile training and annual review to required populations and approvals
  • Testing frequency: quarterly and annual

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.