Objective

Ensure that third-party banks, payment providers, custodians, wallet providers and similar infrastructure do not undermine safeguarding, control, transparency, or legal compliance. Ensure banks, custodians and wallet providers preserve client protection and remain resilient and recoverable.

Control Activity

Compliance performs pre-engagement and at least annual provider review. Due diligence and ongoing monitoring consider: operational reliability and resilience; control environment and security; segregation capability; reporting and statement quality; sanctions and jurisdictional exposure; incident and breach notification arrangements; support for restriction or hold measures where legally required; and the ability to retrieve records and maintain continuity during disruption. Client Accounts are maintained exclusively with banks duly authorized to accept deposits and operating independently from Bitkaya’s corporate group. Formal written confirmations are obtained from each banking partner stating that client money is held in trust for the benefit of clients and is not subject to set-off, liens, or any other claims by the bank. Client VA Wallets are managed through reliable, secure, and well-established wallet providers meeting stringent due diligence standards to protect against theft, hacking, and operational failures. Wallet providers demonstrate strong security protocols, operational resilience, and transparent governance. Contracts cover service, control, access, audit, incident, continuity, termination, data-return and exit requirements. Regular due diligence reviews and monitoring ensure ongoing compliance with Bitkaya’s standards and regulatory expectations. Tested continuity and exit arrangements are maintained.

Verification Requirements

  • Verify that a provider inventory identifies all banks, payment providers, custodians, wallet providers and material safeguarding dependencies.
  • Verify that risk-based due diligence is performed before use and at least annually, covering operational reliability, security, segregation capability, reporting quality, sanctions and jurisdictional exposure, incident and breach notification, restriction or hold support, and record retrieval and continuity.
  • Verify that Client Accounts are maintained exclusively with banks duly authorized to accept deposits and operating independently from Bitkaya’s corporate group.
  • Verify that formal written confirmations are obtained from each banking partner stating that client money is held in trust for clients and is not subject to set-off, liens, or any other claims by the bank.
  • Verify that Client VA Wallets are managed through reliable, secure, and well-established wallet providers meeting stringent due diligence standards.
  • Verify that wallet providers demonstrate strong security protocols, operational resilience, and transparent governance.
  • Verify that contracts cover service, control, access, audit, incident, continuity, termination, data-return and exit requirements.
  • Verify that regular due diligence reviews and monitoring are performed to ensure ongoing compliance with Bitkaya’s standards and regulatory expectations.
  • Verify that tested continuity and exit arrangements are maintained.
  • Verify that the outsourcing register is updated and approvals, reviews and remediation are retained.

Evidence

  • Expected evidence: Provider inventory, due diligence and annual review
  • Expected evidence: Bank acknowledgment and legal review
  • Expected evidence: Contract, monitoring and remediation
  • Expected evidence: Continuity and exit test
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample providers and inspect authorization, segregation, security, contract and continuity evidence
  • Testing frequency: before engagement, annual review and ongoing monitoring

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved SAFU Manual.