Objective

Ensure safeguarding failures are contained, reported and remediated and that resolution readiness and independent assurance remain effective. Compliance and audit processes must reinforce accountability, transparency, and adherence to regulatory requirements.

Control Activity

Material events—any safeguarding breach, near miss, unauthorized movement, reconciliation failure, unexplained shortfall, unauthorized access event, or material control failure affecting client assets—are immediately restricted and escalated. Escalation assesses the immediate safeguarding impact, whether client assets must be restricted or isolated, whether there is an associated fraud, cybersecurity, AML/CTF/CPF, or sanctions dimension, whether regulatory reporting or notification obligations may arise, and whether client communication is required and legally permissible. Incidents are investigated without delay, root causes determined, corrective actions implemented, and follow-up monitoring ensures full resolution. Management notifies regulators (including CBCS) immediately in line with applicable legal requirements and clients promptly where authorized. Corrective actions, root cause analysis, and remediation tracking are documented and monitored to closure. Contingency plans facilitate orderly return of client assets in the event of insolvency, including asset distribution procedures, communication protocols, and regulator coordination. All client assets are legally and operationally segregated from Bitkaya’s own estate and excluded from creditor claims, with trust or equivalent legal structures establishing clients as beneficial owners. Management obtains scheduled independent reviews (internal or external) that assess compliance, test safeguarding effectiveness, and provide recommendations for improvement. Independent audit coverage is initially focused on custody and reconciliation, later broadened to include automated systems and third-party integrations. Lessons learned feed into policy updates, staff training, and system enhancements.

Verification Requirements

  • Verify that any safeguarding breach, near miss, unauthorized movement, reconciliation failure, unexplained shortfall, unauthorized access event, or material control failure affecting client assets is escalated immediately.
  • Verify that affected assets are isolated or restricted and records and evidence are preserved.
  • Verify that escalation assesses: the immediate safeguarding impact; whether client assets must be restricted, isolated, or otherwise protected; whether there is an associated fraud, cybersecurity, AML/CTF/CPF, or sanctions dimension; whether regulatory reporting or notification obligations may arise; and whether client communication is required and legally permissible.
  • Verify that regulators (including CBCS) are notified immediately in line with applicable legal requirements and clients are notified promptly where authorized.
  • Verify that breaches, discrepancies, or deficiencies are investigated without delay, with root causes determined, corrective actions implemented, and follow-up monitoring ensuring full resolution.
  • Verify that corrective actions, root cause analysis, and remediation tracking are documented and monitored to closure.
  • Verify that contingency plans facilitate orderly return of client assets, including documented procedures for asset distribution, communication protocols, and regulator coordination.
  • Verify that all client assets are legally and operationally segregated from Bitkaya’s own estate and excluded from creditor claims, with trust or equivalent legal structures establishing clients as beneficial owners.
  • Verify that scheduled independent reviews (internal or external) are performed on a scheduled basis, assessing compliance, testing safeguarding effectiveness, and providing recommendations for improvement.
  • Verify that independent audit coverage is initially focused on custody and reconciliation and later broadened to include automated systems and third-party integrations.
  • Verify that lessons learned from audits and breach investigations feed into policy updates, staff training, and system enhancements.

Evidence

  • Expected evidence: Incident, restriction and impact assessment
  • Expected evidence: Reporting and communication decision
  • Expected evidence: Root cause and remediation
  • Expected evidence: Resolution-plan test
  • Expected evidence: Audit report and follow-up
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample incidents and assurance findings and trace containment, decisions, remediation and closure
  • Testing frequency: per event, scheduled resolution test and risk-based assurance

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved SAFU Manual.