PDF-Derived Verification Requirements
The PDF requires a control environment with preventive, detective, corrective, manual, automated, or governance-based measures. Illustrative control categories: CDD, KYV, sanctions screening, transaction monitoring, escalation; safeguarding (client money, virtual assets, keys, wallets, reconciliations); cybersecurity and access; approval and segregation-of-duties; incident and issue management; third-party due diligence and monitoring; reporting, recordkeeping, documentation; and business continuity and resilience. Monitoring should focus on both whether controls exist and whether they operate effectively in practice. Monitoring tools: management information, KRIs, KCIs, dashboards, file reviews, exception reporting, thematic reviews. Specific monitoring areas: onboarding approval breaches; overdue periodic reviews; sanctions alerts and unresolved-alert aging; false positive rates and closure quality; unusual transaction escalation volumes and conversion to external reporting; custody or reconciliation breaks; cyber incidents and control exceptions; third-party review status; outstanding remediation items; training completion and competency gaps. Indicators should have a defined owner, frequency, escalation threshold, and response expectation. Where a metric indicates a material control weakness or emerging risk trend, management must assess and document the required response.
Objective
Ensure control performance, indicators, exceptions and remediation are monitored and escalated, covering both control existence and operating effectiveness.
Control Activity
Compliance maintains the risk-linked control inventory and KRI/KCI catalogue, reviews dashboards and exceptions, escalates breaches and verifies remediation before closure. The control inventory must cover the illustrative control categories (CDD/KYV/sanctions/transaction monitoring/escalation; safeguarding; cybersecurity/access; approval/segregation-of-duties; incident/issue management; third-party due diligence/monitoring; reporting/recordkeeping/documentation; business continuity/resilience). KRIs and KCIs must have defined owner, frequency, escalation threshold, and response expectation. Where a metric indicates a material control weakness or emerging risk trend, management must assess and document the required response.
Evidence
- Expected evidence: Control inventory covering all illustrative categories (CDD, KYV, sanctions screening, transaction monitoring, escalation; safeguarding over client money, virtual assets, keys, wallets, reconciliations; cybersecurity and access; approval and segregation-of-duties; incident and issue management; third-party due diligence and monitoring; reporting, recordkeeping, documentation; business continuity and resilience) and KRI/KCI catalogue with defined owner, frequency, escalation threshold, and response expectation
- Expected evidence: Dashboards, file reviews and exceptions covering: onboarding approval breaches; overdue periodic reviews; sanctions alerts and unresolved-alert aging; false positive rates and closure quality; unusual transaction escalation volumes and conversion to external reporting; custody or reconciliation breaks; cyber incidents and control exceptions; third-party review status; outstanding remediation items; training completion and competency gaps
- Expected evidence: Threshold breaches and decisions with documented management response where a metric indicates a material control weakness or emerging risk trend
- Expected evidence: Remediation and closure testing verifying both control existence and operating effectiveness
- Expected evidence: Management and Board reporting
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample indicators and open actions for timely production, threshold response, ownership, escalation, evidence-based closure, and documented management response to material control weakness or emerging risk trends
- Testing frequency: quarterly
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedure: PROC-RMF-003 Monitor Controls Indicators and Remediation
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved RMF version 1.1.