PDF-Derived Verification Requirements
The PDF requires reliable data and records sufficient to support risk assessments, approvals, monitoring, client treatment, internal escalations, control testing, remediation, and management oversight. Where tools, scoring models, rule engines, or automated decision-support mechanisms are used, Bitkaya must understand their purpose, limitations, calibration, ownership, and review requirements. Changes to risk-scoring models, monitoring scenarios, sanctions tooling, onboarding logic, or other material compliance-related automation must be reviewed and governed appropriately. Risk reporting must be timely, accurate, comprehensible, and useful for decision-making. Management information should provide visibility over material risks, control performance, incidents, trends, breaches, unresolved issues, and remediation progress. Reporting should distinguish between: operational incidents; control issues; sanctions matters; internal compliance escalations; external reporting matters; safeguarding incidents; third-party failures; and training or capability weaknesses. Assurance activities should evaluate whether: risks are identified and assessed appropriately; controls are designed and operating effectively; reporting and escalation are timely and accurate; remediation actions are tracked and completed; cross-manual consistency is maintained; and significant legal, regulatory, or governance changes are reflected in subordinate manuals, SOPs, and control operation. Findings must be documented, tracked, and reported through the governance framework. Each policy or manual must have a designated owner responsible for periodic review, update following change, consistency with parent and subordinate frameworks, and accurate reflection of current control operation. Cross-manual inconsistencies should be treated as control weaknesses and addressed promptly. Proportionality determinations, compensating controls, and rationales are documented in the RMF appendix for regulatory review; templates and registers are simplified but maintained to CBCS standards of traceability and auditability. Bitkaya re-assesses proportionality annually as part of the EWRA and whenever significant changes occur.
Objective
Ensure risk data, models, reporting, assurance, policy review, proportionality decisions and cross-manual consistency remain reliable and controlled.
Control Activity
Compliance reviews risk data quality, material models and changes, management reporting, assurance coverage, findings, annual policy review and documented proportionality. The review verifies that: records are sufficient to support risk assessments, approvals, monitoring, client treatment, internal escalations, control testing, remediation, and management oversight; tools/models/engines have documented purpose, limitations, calibration, ownership, and review requirements; changes to risk-scoring models, monitoring scenarios, sanctions tooling, onboarding logic, or other compliance automation are reviewed and governed; reporting is timely, accurate, comprehensible, and distinguishes between operational incidents, control issues, sanctions matters, internal compliance escalations, external reporting matters, safeguarding incidents, third-party failures, and training or capability weaknesses; assurance evaluates all required areas; findings are documented, tracked, and reported through the governance framework; each policy has a designated owner; cross-manual inconsistencies are treated as control weaknesses; and proportionality determinations are documented and reassessed annually.
Evidence
- Expected evidence: Data requirements and quality checks verifying records are sufficient to support risk assessments, approvals, monitoring, client treatment, internal escalations, control testing, remediation, and management oversight
- Expected evidence: Model and rule inventory and reviews documenting purpose, limitations, calibration, ownership, and review requirements; changes to risk-scoring models, monitoring scenarios, sanctions tooling, onboarding logic, or other compliance automation reviewed and governed
- Expected evidence: Management and Board risk reports that are timely, accurate, comprehensible, and useful for decision-making, distinguishing between operational incidents, control issues, sanctions matters, internal compliance escalations, external reporting matters, safeguarding incidents, third-party failures, and training or capability weaknesses
- Expected evidence: Assurance plan, findings and closure verifying risks are identified/assessed appropriately; controls are designed and operating effectively; reporting and escalation are timely and accurate; remediation actions are tracked and completed; cross-manual consistency is maintained; and significant legal, regulatory, or governance changes are reflected in subordinate manuals, SOPs, and control operation. Findings documented, tracked, and reported through the governance framework.
- Expected evidence: Policy, consistency and proportionality review verifying each policy has a designated owner; cross-manual inconsistencies treated as control weaknesses and addressed promptly; proportionality determinations, compensating controls, and rationales documented in RMF appendix for regulatory review; templates and registers simplified but maintained to CBCS standards of traceability and auditability; proportionality reassessed annually as part of EWRA and whenever significant changes occur
- Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample reports and models for controlled data and review, inspect annual assurance and policy actions for approval and closure, verify reporting distinguishes all required categories, and verify proportionality determinations are documented and reassessed annually
- Testing frequency: quarterly and annual
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedure: PROC-RMF-008 Govern Risk Data Models Reporting Assurance and Policy
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved RMF version 1.1.