Objective
Ensure safeguarding agreements and communications accurately explain asset handling, ownership, risks, restrictions and protection limitations. Clear and transparent client agreements are essential for building trust and ensuring that clients fully understand how their assets are safeguarded, while meeting regulatory and fiduciary responsibilities.
Control Activity
Compliance reviews safeguarding terms through the COMM workflow, blocks unsupported guarantees, confirms required consent and ensures incident or restriction communications comply with confidentiality and anti-tipping-off duties. All client agreements include comprehensive provisions covering how client money and virtual assets are handled and safeguarded, the rights and obligations of both Bitkaya and the client, and risk disclosures and protections. Clients are informed in writing of how and where their assets are held, the safeguards and controls applied, and any potential risks. Agreements use clear, concise language avoiding ambiguity or misleading terms. Agreements comply with all applicable legal and regulatory requirements. No communication is made in a manner that breaches anti-tipping-off, confidentiality, or regulatory restrictions. Client communication is handled carefully, consistently, and in accordance with applicable legal and confidentiality constraints where transactions, withdrawals, or transfers are delayed or restricted.
Verification Requirements
- Verify that all client agreements include comprehensive provisions covering how client money and virtual assets are handled and safeguarded, the rights and obligations of both Bitkaya and the client, and risk disclosures and protections in place.
- Verify that clients are informed in writing of how and where their assets are held (e.g., client accounts, segregated VA wallets), the safeguards and controls applied, and any potential risks associated with Bitkaya’s services.
- Verify that agreements use clear, concise language that avoids ambiguity or misleading terms.
- Verify that agreements comply with all applicable legal and regulatory requirements, ensuring enforceability and alignment with client asset protection obligations.
- Verify that no absolute guarantees unsupported by legal and operating evidence are included in agreements or communications.
- Verify that required consent for any lawful use outside ordinary safeguarding is obtained, and that exceptions for proceeds accrual are explicitly agreed in writing.
- Verify that safeguarding statements are reviewed through the COMM approval workflow before release.
- Verify that no communication is made in a manner that breaches anti-tipping-off, confidentiality, or regulatory restrictions.
- Verify that where transactions, withdrawals, or transfers are delayed or restricted due to legal, compliance, fraud, sanctions, or safeguarding concerns, client communication is handled carefully, consistently, and in accordance with applicable legal and confidentiality constraints.
- Verify that client-reported discrepancies are investigated promptly and complaints are routed through the COMP framework.
Evidence
- Expected evidence: Approved terms, disclosures and legal review
- Expected evidence: Consent and delivery evidence
- Expected evidence: Incident or restriction communications
- Expected evidence: Complaint and correction records
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample agreements and communications for accuracy, approval, delivery and restricted-information handling
- Testing frequency: before release and on material change or event
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved SAFU Manual.