PDF-Derived Verification Requirements

The PDF’s Fraud Risk and Monitoring SOP requires: if there is a credible fraud concern, the case must not continue as normal — the employee must stop the relevant step, preserve available evidence, and escalate it. Fraud concerns must never be ignored because the transaction is urgent, commercially important, or requested by a senior person. Main fraud risk areas: impersonation of clients or authorized persons; account takeover or unauthorized access; false payment instructions; suspicious withdrawal requests; forged or manipulated onboarding documents; social engineering against staff; misuse of internal access by employees or contractors; third-party fraud involving vendors, introducers, or service providers; unusual transaction behavior inconsistent with the client profile. Operational fraud triggers: sudden change in withdrawal instructions; request to send funds to a new or unrelated account or wallet; unusual urgency or pressure; failed authentication attempts or suspicious login behavior; mismatch between client identity details and transaction behavior; unusual device, location, IP, or session behavior; contradictory explanations or evasive behavior; suspicious document quality or signs of tampering; client claims that they did not authorize activity; repeated failed or blocked transactions followed by a manual override request. When a fraud concern appears, staff must: stop the relevant process step; avoid tipping off the client or third party; preserve records, screenshots, messages, logs, and transaction references; escalate immediately to Compliance and the relevant responsible function; and wait for direction before releasing funds, changing account details, or clearing the case. First-line users identify the concern, stop the process, document what they saw, and escalate quickly — they are not expected to perform full investigations. Compliance reviews whether the case may involve fraud, AML/suspicious activity issues, sanctions concerns, client protection issues, or internal misconduct. Operations/Finance/IT support by checking account activity, payment instructions, wallet details, access logs, system behavior, or prior incidents. Senior Management involvement is required where: there is material client impact; a significant financial loss may occur; multiple clients may be affected; an internal staff issue is involved; or the case has regulatory, legal, or reputational significance. Immediate protective actions: pause onboarding; block or delay a withdrawal; freeze a transaction pending review; require renewed client verification; disable or restrict access; reset credentials or authentication methods; escalate to AML review; escalate to management; or contact the client through a trusted channel for verification. For internal misuse or staff fraud: escalate immediately to Compliance and management; restrict access where needed; preserve logs and records; do not allow the individual to review or control the case alone. Fraud Incident Log minimum information: date; case reference; client/account/transaction reference where relevant; summary of concern; action taken; who reviewed the case; outcome; and whether further escalation, reporting, or remediation was required. If a case also suggests suspicious activity, sanctions exposure, cybersecurity compromise, or data breach risk, it must also be handled under the relevant Bitkaya procedures. Fraud cases should be reviewed periodically to identify: repeated patterns; control weaknesses; training needs; process weaknesses; and whether thresholds, authentication, or approval controls need improvement.

Objective

Ensure credible fraud concerns result in immediate protective action, evidence preservation, independent review, cross-framework handling and documented learning.

Control Activity

Compliance reviews the fraud incident log and material cases for prompt stop and escalation, preserved evidence, proportionate protective action, segregation, cross-framework handling and completed remediation. The review verifies that: the basic rule was applied (case stopped, evidence preserved, escalated); fraud concerns were not ignored due to urgency, commercial importance, or seniority; first-line handling was correct (identify, stop, document, escalate); Compliance assessed all applicable implications (fraud, AML/suspicious activity, sanctions, client protection, internal misconduct); Operations/Finance/IT support was obtained where needed; Senior Management was involved where required; protective actions were proportionate and documented; internal misuse cases were handled confidentially with segregation of review; the Fraud Incident Log contains all required minimum information; cases overlapping with AML, sanctions, cybersecurity, or data breach were also handled under the relevant procedures; and cases were reviewed periodically for repeated patterns, control weaknesses, training needs, process weaknesses, and threshold/authentication/approval control improvements.

Evidence

  • Expected evidence: Fraud incident log containing date, case reference, client/account/transaction reference where relevant, summary of concern, action taken, who reviewed the case, outcome, and whether further escalation, reporting, or remediation was required
  • Expected evidence: Preserved messages, documents, screenshots, logs, and transaction references
  • Expected evidence: Protective actions and approvals verifying proportionate response (pause onboarding; block/delay withdrawal; freeze transaction; require renewed verification; disable/restrict access; reset credentials; escalate to AML review; escalate to management; contact client through trusted channel) documented and proportionate
  • Expected evidence: Review, escalation and reporting verifying Compliance assessed fraud, AML/suspicious activity, sanctions, client protection, internal misconduct; Operations/Finance/IT checked account activity, payment instructions, wallet details, access logs, system behavior, prior incidents; Senior Management involved where material client impact, significant loss, multiple clients, internal staff issue, or regulatory/legal/reputational significance; cross-framework handling for AML, sanctions, cybersecurity, data breach overlaps; internal misuse handled confidentially with segregation of review
  • Expected evidence: Outcome, remediation and learning verifying periodic review for repeated patterns, control weaknesses, training needs, process weaknesses, and threshold/authentication/approval control improvements
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: inspect all or a risk-based sample of cases for timely stop (basic rule applied, concerns not ignored due to urgency/commercial importance/seniority), preservation, independent review (Compliance assessment of all implications, Ops/Finance/IT support, Senior Management involvement where required), required reporting (cross-framework handling for AML/sanctions/cybersecurity/data breach), proportionate protective action, segregation for internal misuse, complete Fraud Incident Log entries, and control improvement from periodic review
  • Testing frequency: quarterly and after each material case

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved RMF version 1.1.