PDF-Derived Verification Requirements

The PDF requires a structured methodology assessing inherent risk, control effectiveness, and residual risk at enterprise, business/process, client, product, project, or event level. The methodology supports: annual and trigger-based EWRA; process and control reviews; client risk scoring interfaces with AML/CTF/CPF and KYC/CDD frameworks; change and release risk assessment; new product approval; third-party risk assessment; and incident, issue, and complaint assessment. The rationale, evidence, scoring basis, assumptions, and conclusions for material risk assessments must be documented. The EWRA assesses inherent risk and control effectiveness across domains: client base, services and products, geography and jurisdiction, delivery channels, transaction activity, technology, outsourcing, and governance. EWRA outputs inform control design and enhancement, risk appetite calibration, monitoring and escalation thresholds, staffing and tooling priorities, review frequencies, and management and Board reporting. Where EWRA outcomes require changes to specific controls or procedures, related subordinate manuals and operational guidance must be updated. Risk assessments shall include RCSA processes, change risk assessments, and product risk evaluations — no material change shall be implemented without prior risk assessment. Client-level risk scoring informs: depth of due diligence; approval thresholds; frequency of periodic review; monitoring intensity; escalation thresholds; and supporting documentation level. Client risk classification is not static and must be reassessed when material changes, red flags, sanctions events, unusual activity, or other trigger events arise. All operational risk events, including losses and near misses, shall be recorded in a centralized database. Root cause analysis shall be performed for material events.

Objective

Ensure material risks are assessed consistently using evidence, approved methodology and documented treatment across enterprise, process, product, project, client, and event levels.

Control Activity

Risk and Compliance maintain the assessment methodology, complete the annual EWRA, challenge material assessments and monitor trigger-based reassessment, treatment and event records. The methodology must assess inherent risk, control effectiveness, and residual risk, with documented rationale, evidence, scoring basis, assumptions, and conclusions. The EWRA must cover the domains of client base, services and products, geography and jurisdiction, delivery channels, transaction activity, technology, outsourcing, and governance, and its outputs must inform control design, appetite calibration, monitoring thresholds, staffing, review frequencies, and reporting. Where EWRA outcomes require changes to controls or procedures, subordinate manuals must be updated.

Evidence

  • Expected evidence: Approved methodology and scoring scales covering inherent risk, control effectiveness, and residual risk with documented rationale, evidence, scoring basis, assumptions, and conclusions
  • Expected evidence: EWRA covering domains: client base, services and products, geography and jurisdiction, delivery channels, transaction activity, technology, outsourcing, and governance; RCSA and event assessments; no material change implemented without prior risk assessment
  • Expected evidence: Evidence, assumptions and control evaluation including client-level risk scoring interfaces with AML/CTF/CPF and KYC/CDD frameworks (depth of due diligence, approval thresholds, frequency of periodic review, monitoring intensity, escalation thresholds, supporting documentation)
  • Expected evidence: Treatment, acceptance and approvals with trigger-based reassessment when material changes, red flags, sanctions events, unusual activity, or other trigger events arise
  • Expected evidence: Loss, near-miss and root-cause records in a centralized database, with root cause analysis for material events
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample assessments for complete scope (all EWRA domains), supported scoring, documented rationale/evidence/assumptions/conclusions, residual-risk decision, ownership, timely treatment, client-risk reassessment triggers, and centralized event recording with root-cause analysis for material events
  • Testing frequency: quarterly monitoring and annual EWRA review

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved RMF version 1.1.