PDF-Derived Verification Requirements
The PDF distinguishes incidents (events causing or potentially causing operational disruption, control failure, client harm, legal/regulatory exposure, financial loss, or reputational damage), issues (weaknesses, deficiencies, or gaps in controls, governance, documentation, systems, staffing, or procedures requiring remediation), and complaints (expressions of dissatisfaction from clients or stakeholders requiring fair assessment and response). A single event may trigger multiple categories. Where relevant, matters should also be assessed for separate handling under AML/CTF/CPF escalation, sanctions procedures, safeguarding procedures, cybersecurity response, or regulatory communication requirements. Internal classification for management purposes does not replace any separate legal or regulatory obligation to report, escalate, restrict, or remediate.
Objective
Ensure incidents, issues and complaints are classified, contained, escalated and remediated without missing other applicable obligations, including AML/CTF/CPF escalation, sanctions procedures, safeguarding procedures, cybersecurity response, or regulatory communication requirements.
Control Activity
Compliance reviews event records for severity, cross-framework applicability, required reporting, root cause, remediation and evidence-based closure. The review verifies that: incidents are correctly identified (operational disruption, control failure, client harm, legal/regulatory exposure, financial loss, reputational damage); issues are correctly identified (weaknesses, deficiencies, gaps in controls, governance, documentation, systems, staffing, procedures); complaints are correctly identified (expressions of dissatisfaction requiring fair assessment and response); and where relevant, matters are assessed for separate handling under AML/CTF/CPF escalation, sanctions procedures, safeguarding procedures, cybersecurity response, or regulatory communication requirements. Internal classification must not replace any separate legal or regulatory obligation to report, escalate, restrict, or remediate.
Evidence
- Expected evidence: Event register and classification distinguishing incidents (operational disruption, control failure, client harm, legal/regulatory exposure, financial loss, reputational damage), issues (weaknesses, deficiencies, gaps in controls, governance, documentation, systems, staffing, procedures), and complaints (expressions of dissatisfaction from clients or stakeholders)
- Expected evidence: Containment and applicability assessment verifying where relevant that matters are assessed for separate handling under AML/CTF/CPF escalation, sanctions procedures, safeguarding procedures, cybersecurity response, or regulatory communication requirements
- Expected evidence: Investigation and root cause
- Expected evidence: Communications and reporting confirming internal classification does not replace separate legal or regulatory obligations to report, escalate, restrict, or remediate
- Expected evidence: Remediation and closure evidence
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample events for timely classification (incident/issue/complaint distinctions), cross-framework escalation (AML/CTF/CPF, sanctions, safeguarding, cybersecurity, regulatory communication), required reporting, root cause, and verified closure
- Testing frequency: quarterly
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedure: PROC-RMF-006 Manage Risk Incidents Issues and Complaints
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved RMF version 1.1.