Purpose
Provide assurance that every in-scope person and role is included in a current, risk-based and approved training programme.
Objective
Ensure the training matrix and calendar completely map personnel and roles to required modules, frequencies, assessments, owners, due dates and evidence locations.
Normative
Compliance and HR shall reconcile the in-scope population to the approved training matrix at least annually and after material personnel, role, access, regulatory, policy, system or risk change.
Descriptive
The control classifies foundational, functional and leadership training, identifies high-risk functions, assigns subject-matter owners and prevents new or temporary roles from falling outside the programme. Training content and intensity are structured proportionally by role and risk exposure: Tier 1 — Foundational (mandatory for all employees, covers AML/CFT, cybersecurity hygiene, Code of Ethics, whistleblowing, and client asset safeguarding); Tier 2 — Functional (Compliance, Operations, and IT teams, emphasizing transaction monitoring, data security, and risk management); Tier 3 — Leadership (governance, CBCS regulatory frameworks, decision-making ethics, and oversight responsibilities). Training frequency follows proportional logic: high-risk functions semiannual, medium/low-risk functions annual or upon material policy changes.
Evidence
- Expected evidence: Personnel and contractor population extract
- Expected evidence: Role-risk and tiering assessment
- Expected evidence: Approved training matrix and annual calendar
- Expected evidence: Content-owner, frequency and assessment mapping
- Expected evidence: Change and exception records
- Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: reconcile the complete population and a sample of role changes to matrix coverage and approval
- Testing frequency: annual and after material change
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented
Assurance Assertions
- Every in-scope person and role is mapped.
- High-risk functions have semiannual assignments.
- All personnel have annual training and applicable onboarding.
- Materials, owners, assessments and evidence locations are specified.
Relationships
- Policy: POL-TRAIN-001 Training and Awareness Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-TRAIN-001 Govern Training Needs Curriculum Matrix and Calendar
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from the approved Training & Awareness Manual version 1.1.