PDF-Derived Verification Requirements
The PDF requires risk-based due diligence, contractual controls, performance monitoring, and escalation procedures for vendors, service providers, liquidity providers, banks, custodians, VASPs, and other counterparties. Due diligence areas: legal status and authority; reputation and financial soundness; control environment and resilience; regulatory and supervisory standing; sanctions exposure; data protection and confidentiality implications; subcontracting or sub-processing arrangements; dependency concentration; and exit feasibility. For VASP relationships, KYV measures must be applied on a documented risk basis and aligned with Bitkaya’s AML/CTF/CPF control framework. The RMF supports business continuity by ensuring critical functions are identified and prioritized; dependencies and single points of failure are understood; resilience controls are tested; recovery assumptions are documented; crisis decision-making is supported by escalation criteria; and material incidents are assessed for legal, client, financial crime, safeguarding, and regulatory consequences. Proportionality: outsourcing is used strategically with formal vendor oversight replacing internal redundancy; vendor due diligence follows a tiered risk approach proportionate to the criticality of the service.
Objective
Ensure material third-party, counterparty, concentration and resilience risks receive due diligence, safeguards, monitoring and exit planning, with KYV measures for VASP relationships aligned with the AML/CTF/CPF control framework.
Control Activity
Compliance and relationship owners reconcile material relationships to approved risk assessments, contracts, registers, ongoing monitoring, resilience evidence and escalation or exit decisions. Due diligence must cover: legal status and authority; reputation and financial soundness; control environment and resilience; regulatory and supervisory standing; sanctions exposure; data protection and confidentiality implications; subcontracting or sub-processing arrangements; dependency concentration; and exit feasibility. For VASP relationships, KYV measures must be applied on a documented risk basis and aligned with Bitkaya’s AML/CTF/CPF control framework. Vendor due diligence follows a tiered risk approach proportionate to the criticality of the service.
Evidence
- Expected evidence: Relationship inventory and criticality
- Expected evidence: Due diligence covering legal status and authority; reputation and financial soundness; control environment and resilience; regulatory and supervisory standing; sanctions exposure; data protection and confidentiality implications; subcontracting or sub-processing arrangements; dependency concentration; and exit feasibility. For VASP relationships, KYV measures on a documented risk basis aligned with AML/CTF/CPF control framework. Vendor due diligence on a tiered risk approach proportionate to service criticality.
- Expected evidence: Contracts and control safeguards
- Expected evidence: Monitoring, continuity and exit evidence verifying critical functions are identified and prioritized, dependencies and single points of failure are understood, resilience controls are tested, recovery assumptions are documented, and crisis decision-making is supported by escalation criteria
- Expected evidence: Escalations and remediation, with material incidents assessed for legal, client, financial crime, safeguarding, and regulatory consequences
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample material relationships for complete assessment covering all due diligence areas, KYV for VASP relationships, current approval, monitoring, resilience (critical functions, dependencies/SPOF, tested controls, documented recovery assumptions, escalation criteria), and exit feasibility
- Testing frequency: quarterly and annual review
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedure: PROC-RMF-007 Manage Third Party Counterparty and Resilience Risk
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved RMF version 1.1.