Objective
Ensure safeguarding has accountable ownership, competent staff, quarterly oversight and approved risk-based scalability. Safeguarding governance must ensure that client asset protection is managed not only as an accounting or custody function, but also as a legal, compliance, operational, and client protection responsibility.
Control Activity
Compliance maintains roles, inventories and risk assessments; provides mandatory onboarding and annual role-based training covering client asset protection principles, integration of AML and CFT requirements, and safeguarding protocols and escalation procedures; implements ongoing awareness initiatives; reports quarterly to management and the Board with visibility over segregation and reconciliation performance, safeguarding incidents and near misses, withdrawal and transfer exceptions, unresolved restrictions, holds, or breaks, third-party dependency risk, interaction between safeguarding and compliance controls, and remediation actions following incidents, findings, or control failures; and completes an annual and change-triggered proportionality review. The DSO oversees client asset protection, reconciliations, and custody integrity. The Head of Risk & Compliance periodically reviews proportionality justifications and reports to the Board. The Board of Directors approves proportionality adjustments annually or after material changes. All proportionality-based decisions are documented and retained for at least five (5) years. Material control changes require Board approval. A version control log records all manual changes, effective dates, and approving authorities.
Verification Requirements
- Verify that a Designated Safeguarding Officer (DSO) and backup are designated with documented responsibilities and segregation-of-duties safeguards.
- Verify that a client-asset service, account, wallet, provider, system and risk inventory is maintained and current.
- Verify that quarterly Board reporting covers segregation and reconciliation performance, safeguarding incidents and near misses, withdrawal and transfer exceptions, unresolved restrictions, holds, or breaks, third-party dependency risk, interaction between safeguarding and compliance controls, and remediation actions following incidents, findings, or control failures.
- Verify that all staff have completed mandatory training covering client asset protection principles, AML/CFT integration, and safeguarding protocols and escalation procedures.
- Verify that annual training refresh and certification or acknowledgment of completion is current for all staff.
- Verify that employees in sensitive roles (finance, custody operations, compliance, IT security) have received enhanced role-specific training.
- Verify that ongoing awareness initiatives are implemented, emphasizing clear separation between client assets and Bitkaya’s own assets.
- Verify that training completion and staff acknowledgment records are maintained and subject to audit.
- Verify that an annual proportionality review has been completed, covering business scale, regulatory updates, operational or cybersecurity incidents, new custody providers, and expansion to new jurisdictions.
- Verify that material proportionality adjustments have Board of Directors approval.
- Verify that proportionality decisions, justifications, control adjustments and related audit evidence are retained for at least five (5) years.
- Verify that a version control log records all manual changes, effective dates, and approving authorities.
Evidence
- Expected evidence: Role matrix, inventory and risk assessment
- Expected evidence: Quarterly safeguarding report
- Expected evidence: Training, acknowledgment and competence evidence
- Expected evidence: Annual proportionality review and Board approval
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect governance cycles, training coverage and approved changes
- Testing frequency: quarterly reporting, annual training and annual/change-triggered review
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved SAFU Manual.