PDF-Derived Verification Requirements

The PDF requires that new products, services, jurisdictions, channels, system changes, or material process changes be assessed before implementation. The assessment must consider, where relevant: legal and licensing implications; AML/CTF/CPF and sanctions impact; operational and safeguarding risks; cybersecurity implications; client disclosure and conduct risk; recordkeeping and reporting impact; training and staffing needs; and whether related manuals, SOPs, and controls require updating. No material change should proceed without the required governance review and approval.

Objective

Ensure material products, services, jurisdictions, channels, systems and process changes receive complete risk assessment and approval before implementation.

Control Activity

Compliance maintains a change-risk gate requiring documented multi-domain assessment, control and testing readiness, approval and post-implementation review before go-live. The assessment must consider all applicable areas: legal and licensing implications; AML/CTF/CPF and sanctions impact; operational and safeguarding risks; cybersecurity implications; client disclosure and conduct risk; recordkeeping and reporting impact; training and staffing needs; and whether related manuals, SOPs, and controls require updating. No material change should proceed without the required governance review and approval.

Evidence

  • Expected evidence: Proposal and applicability record
  • Expected evidence: Risk, control and testing assessment covering all applicable areas (legal and licensing; AML/CTF/CPF and sanctions; operational and safeguarding; cybersecurity; client disclosure and conduct; recordkeeping and reporting; training and staffing; manual/SOP/control updates)
  • Expected evidence: Approval and go-live decision confirming no material change proceeded without required governance review and approval
  • Expected evidence: Updated policies, procedures and training
  • Expected evidence: Post-implementation review
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample implemented changes for prior assessment covering all applicable areas, required approval, satisfied conditions, updated manuals/SOPs/controls, and completed post-implementation review
  • Testing frequency: quarterly

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved RMF version 1.1.