Objective

Ensure receipts, payments, withdrawals, transfers and disbursements are properly recorded, traceable, authenticated, authorized, screened, documented and permitted. Client money movements must not proceed where there is an unresolved sanctions concern, legal restriction, or material compliance alert affecting the transaction, client, or destination.

Control Activity

Operations verifies instructions and destinations, performs applicable sanctions and wallet exposure screening, fraud review, unusual-activity review and risk-based transaction review, applies maker-checker or dual-authorization processes, and prevents movement while unresolved legal, sanctions, fraud, AML or safeguarding restrictions exist. All receipts and payments of client money are promptly recorded with date of transaction, unique client identifier, amount received or disbursed, and transaction reference number. Withdrawals from client accounts are supported by appropriate documentation and authorized by designated personnel. For client VA transfers, wallet ownership verification, address whitelisting or destination controls, and documented authorization steps are applied. Where a transfer cannot be completed in a manner consistent with Bitkaya’s legal, compliance, or safeguarding obligations, the transfer must not proceed until the matter has been appropriately resolved or escalated. All decisions, authorizations, holds, restrictions, and exceptions are documented.

Verification Requirements

  • Verify that all receipts and payments of client money are promptly recorded with: date of transaction, unique client identifier, amount received or disbursed, and transaction reference number.
  • Verify that client instructions are authenticated and the client, instruction, asset, amount, source and destination are verified.
  • Verify that wallet ownership verification, address whitelisting or destination controls are applied to client VA transfers where applicable.
  • Verify that sanctions and wallet exposure screening, fraud review, unusual-activity review and risk-based transaction review are performed.
  • Verify that maker-checker or dual-authorization processes are applied and role separation is enforced for elevated-risk movements.
  • Verify that withdrawals from client accounts are supported by appropriate documentation and authorized by designated personnel.
  • Verify that no client money movement proceeds where there is an unresolved sanctions concern, legal restriction, or material compliance alert affecting the transaction, client, or destination.
  • Verify that no client VA transfer proceeds where the transfer cannot be completed consistent with Bitkaya’s legal, compliance, or safeguarding obligations until the matter is resolved or escalated.
  • Verify that all decisions, authorizations, holds, restrictions, and exceptions are documented.
  • Verify that rejected, delayed, restricted, unusual or failed movements are escalated and the full audit trail is preserved.

Evidence

  • Expected evidence: Instruction, identity and destination verification
  • Expected evidence: Screening and risk review
  • Expected evidence: Maker-checker authorization
  • Expected evidence: Hold, escalation and execution record
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample movements and verify authentication, screening, authorization, restrictions and audit trail
  • Testing frequency: per movement

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved SAFU Manual.