Anti-Bribery & Corruption (ABC) Manual
Anti-Bribery & Corruption (ABC) Manual
Version: 1.0
Status: FINAL
Date: 2026-04-16
BCMS Object: POL-ABC-001
BCMS Version: 2.0.0
Source: bitkaya/bcms @ 7d9a5eb
Bitkaya B.V.
Julianaplein 36
Willemstad, Curaçao, Dutch Caribbean
www.bitkaya.io
Change Log
Bitkaya — Change Log
| Version | Date | Summary of Changes | Approvers | Impacted | Notes |
|---|---|---|---|---|---|
| 1.0 | 2026-04-16 | Initial manual — all 23 chapters | Board (Cees Quirijns, Managing Director) | POL-ABC-001 and all linked procedures/controls | Approved ABC Manual version 1.0, FINAL, April 2026 |
| 2.0.0 | 2026-07-28 | Enriched the policy body to reproduce the full approved ABC Manual (all 23 chapters) for 100% PDF coverage | Cees Quirijns (Managing Director) | POL-ABC-001, PROC-ABC-001–007, CTRL-ABC-001–007 | BCMS normalization; operating-effectiveness testing pending |
Table of Contents
- Purpose and Scope
- Legal and Governance Framework
- ABC Policy Statement
- Roles and Responsibilities
- 4.1 Board of Directors
- 4.2 Executive Management
- 4.3 Compliance Officer / Designated ABC Officer
- 4.4 Finance Function
- 4.5 Department Heads
- 4.6 Employees and Associated Persons
- 4.7 Internal Audit / Independent Review
- Core ABC Principles
- 5.1 Integrity
- 5.2 Transparency
- 5.3 Accountability
- 5.4 Risk-Based Application
- 5.5 Documentation and Auditability
- 5.6 Independent Oversight
- Prohibited Conduct
- Risk-Based ABC Framework
- Third-Party and Intermediary Risk Management
- 8.1 Enhanced Review
- 8.2 Contractual Safeguards
- 8.3 Ongoing Monitoring
- Gifts, Hospitality, Travel, and Entertainment
- 9.1 Prohibited Examples
- 9.2 Register and Approval
- Public Officials and State-Linked Exposure
- Charitable Donations, Sponsorships, and Political Contributions
- Conflicts of Interest and Personal Benefits
- Books, Records, and Financial Controls
- Speak-Up, Escalation, and Investigation
- Monitoring, Testing, and Quality Assurance
- Training and Awareness
- Reporting to Senior Management and the Board
- Recordkeeping and Documentation
- Disciplinary Measures and External Reporting
- Proportionality Implementation
- 20.1 Purpose and Rationale
- 20.2 Guiding Principles
- 20.2.1 Risk-Based Application
- 20.2.2 Scalability
- 20.2.3 Accountability and Traceability
- 20.2.4 Efficiency Without Compromising Control
- 20.3 Application in Practice
- 20.4 Continuous Development
- Review and Continuous Improvement
- Bitkaya Gifts and Hospitality SOP
- 22.1 Purpose
- 22.2 Scope
- 22.3 Basic Rule
- 22.4 Always Prohibited
- 22.5 Simple Decision Rule
- 22.6 Approval Rules
- 22.7 Public Officials
- 22.8 Unsolicited Gifts
- 22.9 Escalation Triggers
- 22.10 Records
- Bitkaya Third-Party ABC Due Diligence SOP
- 23.1 Purpose
- 23.2 Who This Applies To
- 23.3 Basic Rule
- 23.4 Step 1 – Decide Whether ABC DD Is Really Needed
- 23.5 Step 2 – Classify the Third Party
- 23.6 Step 3 – Minimum Checks
- 23.7 Step 4 – Red Flag Review
- 23.8 Step 5 – Approval Rules
- 23.9 Step 6 – Contract Controls
- 23.10 Step 7 – Ongoing Review
- Implementing Procedures
- Implementing Controls
- Relationships and Cross-References
- Review and Continuous Improvement
- Appendix A — Cross-Reference Register
- Appendix B — Change History
1 Purpose and Scope
This manual establishes Bitkaya’s Anti-Bribery & Corruption (ABC) framework and sets out the principles, standards, and procedures designed to prevent, detect, and respond to bribery and corruption risk across the organization.
As a regulated Virtual Asset Service Provider (VASP), Bitkaya recognizes that bribery and corruption undermine trust, distort decision-making, expose the company and its staff to legal, regulatory, financial, and reputational harm, and are incompatible with the company’s commitment to integrity, accountability, and transparent business conduct.
The purpose of this manual is to:
- establish a clear zero-tolerance position on bribery and corruption;
- define governance, ownership, and escalation responsibilities;
- implement risk-based controls over third parties, benefits, approvals, and financial flows;
- strengthen internal accountability, documentation, and auditability; and
- support Bitkaya’s broader compliance, risk management, and governance framework.
This manual applies to all:
- employees;
- officers and directors;
- contractors, consultants, and temporary staff; and
- third parties acting on behalf of Bitkaya.
It applies across all business lines and support functions, including compliance, finance, operations, commercial activity, IT, HR, and management. It also applies in all jurisdictions in which Bitkaya operates or seeks to operate.
This manual should be read together with the Enterprise Compliance Manual, Employee Handbook, Risk Management Framework Manual, Internal Controls and Audit Manual, Finance and Tax Compliance Manual, Regulatory Reporting & Communication Manual, and Training and Awareness Manual.
2 Legal and Governance Framework
Bitkaya’s ABC framework forms part of its wider governance, ethics, risk, and internal control environment. It is designed to align with applicable Curaçao law, general corporate governance expectations, and international anti-corruption good practice, while also reflecting Bitkaya’s three-lines-of-defense model and proportionality-based compliance approach as a growing VASP.
Where a legal or regulatory requirement is stricter than the standards set out in this manual, the stricter requirement shall apply.
3 ABC Policy Statement
Bitkaya maintains a zero-tolerance approach to bribery and corruption.
No employee, officer, contractor, or associated person may offer, promise, give, request, agree to receive, or accept a bribe, whether directly or indirectly. Likewise, no person acting for or on behalf of Bitkaya may provide anything of value in order to improperly influence a decision, secure an undue advantage, avoid a regulatory consequence, or distort a commercial outcome.
This prohibition applies regardless of:
- whether the recipient is in the public or private sector;
- whether the benefit is financial or non-financial;
- whether the conduct is considered customary in a particular market; or
- whether the attempt is successful.
Bitkaya further prohibits the concealment of improper payments through false invoices, sham agreements, inflated commissions, undocumented reimbursements, misleading accounting entries, or the use of third parties to do indirectly what Bitkaya could not lawfully or ethically do directly.
Retaliation against any person who raises a good-faith concern regarding suspected bribery or corruption is strictly prohibited.
4 Roles and Responsibilities
4.1 Board of Directors
The Board of Directors has ultimate responsibility for oversight of Bitkaya’s ABC framework. The Board shall:
- approve this manual and any material updates;
- review Bitkaya’s ABC risk profile at least annually;
- receive periodic reporting on ABC incidents, control effectiveness, and remediation; and
- challenge management on the adequacy of resources, controls, and oversight.
4.2 Executive Management
Executive Management is responsible for implementation of the ABC framework. Management shall:
- ensure appropriate resources, staffing, and internal coordination;
- support escalation, investigation, and remediation of ABC concerns;
- embed ethical conduct into business planning, incentives, growth initiatives, and third-party relationships; and
- ensure that commercial pressure does not override ABC controls.
4.3 Compliance Officer / Designated ABC Officer
The Compliance Officer, or another formally designated person with sufficient experience and expertise, is responsible for coordinating the ABC program. Responsibilities include:
- maintaining the ABC framework and procedures;
- advising business units on ABC risks and control requirements;
- reviewing escalations, higher-risk arrangements, and exceptions;
- coordinating management and Board reporting;
- supporting investigations;
- coordinating training, testing, and remediation tracking; and
- maintaining the ABC Enterprise-Wide Risk Assessment.
4.4 Finance Function
The Finance function supports the ABC framework by:
- maintaining accurate books and records;
- operating payment, expense, and reimbursement controls;
- reviewing unusual invoices, commissions, credits, and payment requests; and
- escalating financial irregularities, unsupported payments, or suspicious documentation.
4.5 Department Heads
Department heads are responsible for first-line application of this manual within their teams. They shall:
- identify ABC risks in their area;
- ensure staff complete required training;
- escalate red flags promptly; and
- ensure staff do not bypass approval or documentation requirements.
4.6 Employees and Associated Persons
All employees and associated persons must:
- comply with this manual;
- avoid prohibited conduct;
- escalate concerns immediately;
- maintain accurate and transparent records; and
- cooperate with monitoring, reviews, and investigations.
4.7 Internal Audit / Independent Review
Internal Audit or another competent independent reviewer may periodically assess the design and effectiveness of Bitkaya’s ABC controls, governance, monitoring, and reporting.
5 Core ABC Principles
The foundation of Bitkaya’s ABC framework rests on a set of core principles that guide every decision, transaction, relationship, and interaction undertaken by the company and its representatives. These principles ensure that Bitkaya conducts business with integrity, protects its stakeholders, and maintains trust in the broader financial and digital asset ecosystem.
As a VASP operating in a highly regulated environment, Bitkaya acknowledges that bribery and corruption risk can arise not only through direct misconduct, but also through third-party relationships, commercial pressure, poor documentation, weak oversight, or unmanaged conflicts of interest. The principles set out below therefore establish the benchmark for professional conduct expected from all employees, officers, contractors, and third parties acting on behalf of the company.
5.1 Integrity
Bitkaya is committed to conducting business honestly, ethically, and in good faith. No employee or representative may seek advantage through improper influence, hidden arrangements, or conduct that compromises independent judgment.
5.2 Transparency
All material decisions, approvals, payments, benefits, and third-party arrangements must be transparent, explainable, and capable of review. Bitkaya will maintain records sufficient to demonstrate the legitimacy and rationale of its actions.
5.3 Accountability
Individuals are accountable for their decisions, actions, omissions, and escalation responsibilities. Management and the Board are responsible for ensuring that the ABC framework is effectively implemented, monitored, and improved where necessary.
5.4 Risk-Based Application
Controls must be proportionate to the level of bribery and corruption risk presented by a jurisdiction, relationship, transaction, benefit, or business activity. Higher-risk arrangements require stronger scrutiny, clearer approvals, and enhanced documentation.
5.5 Documentation and Auditability
Bitkaya must be able to evidence what was decided, by whom, on what basis, and with what supporting records. Proper documentation is a core anti-corruption safeguard.
5.6 Independent Oversight
Risk review, compliance challenge, and testing must not be compromised by commercial pressure, role concentration, or unmanaged conflicts of interest.
6 Prohibited Conduct
The following conduct is strictly prohibited:
- bribery of public officials or private-sector counterparties;
- kickbacks, secret commissions, or undisclosed referral payments;
- facilitation payments, unless there is an immediate threat to health or safety and the matter is escalated immediately afterward;
- improper gifts, travel, hospitality, or benefits designed to influence a decision;
- sham consulting arrangements, inflated invoices, fake expense claims, or off-book arrangements;
- donations, sponsorships, hiring, or internships used to obtain an improper advantage;
- concealment or falsification of records;
- use of third parties to bypass ABC controls; and
- retaliation against whistleblowers or persons raising concerns in good faith.
7 Risk-Based ABC Framework
Bitkaya applies a risk-based ABC framework to identify, assess, manage, monitor, and report bribery and corruption risk across the organization.
This framework recognizes that corruption risk may arise through jurisdictions, third-party relationships, dealings with public officials or state-linked entities, products and services, commissions and reimbursements, gifts and hospitality, charitable or sponsorship activity, governance weaknesses, and periods of business change or growth.
Bitkaya therefore applies controls in a manner proportionate to the level of risk presented. Higher-risk arrangements require enhanced review, stronger evidence of rationale, additional approvals, and closer monitoring.
Bitkaya documents its overall ABC risk profile through an Anti-Bribery & Corruption Enterprise-Wide Risk Assessment (ABC EWRA), which is reviewed at least annually and whenever a material change occurs.
8 Third-Party and Intermediary Risk Management
Third parties can create substantial corruption risk where they interact with clients, counterparties, public officials, vendors, or other decision-makers on Bitkaya’s behalf. Before onboarding a relevant third party, Bitkaya shall conduct proportionate due diligence covering, where appropriate:
- identity and legal status;
- ownership and control structure;
- qualifications and business rationale;
- adverse information and reputation checks;
- sanctions and watchlist screening;
- conflicts of interest;
- compensation model and commercial rationale;
- subcontracting or agency arrangements; and
- enforcement history or misconduct concerns.
8.1 Enhanced Review
Enhanced review is required when:
- the third party interacts with public officials;
- compensation is unusually high, success-based, or opaque;
- the services are vague or difficult to evidence;
- the third party operates in a higher-risk jurisdiction; or
- there are material reputation, ownership, or transparency concerns.
8.2 Contractual Safeguards
Where appropriate, contracts shall include:
- ABC compliance undertakings;
- information and audit rights;
- restrictions on subcontracting without approval;
- breach notification obligations; and
- termination rights in the event of misconduct or non-cooperation.
8.3 Ongoing Monitoring
Relevant third-party relationships must be reassessed periodically and when trigger events occur.
9 Gifts, Hospitality, Travel, and Entertainment
Bitkaya recognizes that modest and legitimate business courtesies may be permissible in limited circumstances. However, gifts, hospitality, travel, and entertainment must never be used to influence a decision improperly or create the appearance of impropriety. Any gift, hospitality, or benefit must be:
- lawful;
- reasonable and proportionate;
- related to a legitimate business purpose;
- transparent and properly recorded; and
- not intended to influence an outcome improperly.
9.1 Prohibited Examples
- cash or cash equivalents;
- luxury travel unrelated to a legitimate business purpose;
- hospitality during an active approval, licensing, tender, or decision process;
- personal benefits to family members of a decision-maker; and
- repeated benefits that cumulatively create the appearance of influence.
9.2 Register and Approval
Bitkaya shall maintain a Gifts and Hospitality Register.
Pre-approval is required above thresholds set by management or when the recipient is:
- a public official;
- a regulator or supervisory contact;
- an employee of a state-owned entity; or
- a person involved in a live approval, negotiation, or decision process affecting Bitkaya.
10 Public Officials and State-Linked Exposure
Interactions involving public officials, regulators, supervisors, tax authorities, law enforcement, licensing authorities, or state-owned entities present elevated corruption risk. These interactions must be conducted with heightened care. Minimum requirements include:
- a legitimate business purpose for each interaction;
- appropriate documentation of material meetings or requests;
- enhanced review of gifts, travel, hospitality, reimbursements, or benefits involving public officials; and
- immediate escalation of any request for unofficial payments, favors, expedited treatment, or off-record arrangements.
Under no circumstances may Bitkaya provide anything of value to obtain or retain business improperly, influence a regulatory outcome, avoid a penalty, or secure preferential treatment.
11 Charitable Donations, Sponsorships, and Political Contributions
Charitable donations and sponsorships must not be used as substitutes for bribery. They are permitted only where:
- the recipient is legitimate and verifiable;
- the purpose is documented;
- there is no link to an improper advantage;
- the payment is appropriately approved; and
- the donation or sponsorship is accurately recorded.
Bitkaya prohibits political contributions made on behalf of the company unless expressly approved by the Board and permitted by applicable law. No political contribution may be used to influence regulatory treatment or obtain a business advantage.
12 Conflicts of Interest and Personal Benefits
Conflicts of interest may create or conceal corruption risk.
All employees and associated persons must disclose actual, potential, or perceived conflicts, including:
- outside business interests;
- financial interests in vendors, service providers, or counterparties;
- family or personal relationships with decision-makers or public officials; and
- personal benefits linked to company transactions.
Bitkaya shall record, assess, and manage conflicts through proportionate disclosure, escalation, restriction, or prohibition measures.
13 Books, Records, and Financial Controls
Accurate books and records are a core anti-corruption control.
Bitkaya prohibits any falsification, concealment, or mischaracterization of:
- payments;
- invoices;
- commissions;
- reimbursements;
- contracts;
- approvals; or
- supporting documents.
Minimum control standards include:
- documented payment approval workflows;
- legitimate invoices and supporting evidence for payments;
- no off-book accounts or side arrangements;
- commercially justifiable commissions and consulting fees;
- accurate and reviewable expense claims; and
- escalation of unusual invoices, duplicate claims, round-sum charges, or vague service descriptions.
14 Speak-Up, Escalation, and Investigation
All employees and associated persons must report ABC concerns promptly. Examples of red flags include:
- requests for unusual commissions or success fees;
- pressure to use a specific consultant without a clear rationale;
- invoices lacking sufficient detail;
- requests to pay through unrelated entities or offshore accounts without justification;
- offers of gifts or favors during a decision-making process;
- suggestions to keep arrangements informal, off-record, or undocumented; and
- requests by a public official, intermediary, or counterparty for a personal favor or unofficial payment.
Reports may be made through:
- line management;
- Compliance;
- HR; or
- whistleblower channels.
Bitkaya shall investigate credible concerns in a timely, fair, risk-sensitive, and documented manner. Good-faith reporters must be protected from retaliation.
15 Monitoring, Testing, and Quality Assurance
Bitkaya shall maintain controls to monitor the effectiveness of its ABC program. Monitoring activities may include:
- review of the Gifts and Hospitality Register;
- review of third-party due diligence and renewal files;
- review of commissions, invoices, reimbursements, and unusual payments;
- exception reporting from finance and approval processes;
- thematic reviews of higher-risk activities or relationships; and
- tracking of incidents, allegations, and remediation actions.
Compliance or Risk may conduct periodic second-line testing of ABC controls, including documentation quality, operating effectiveness, and timeliness of approvals and escalations. Internal Audit or a competent independent party may periodically review the ABC program and report findings to the appropriate governance body.
16 Training and Awareness
Bitkaya shall provide mandatory ABC training that is risk-based and appropriate to role. Training shall be provided, where appropriate, to:
- Board members and senior management;
- first-line staff;
- second-line staff;
- third-line or independent review functions;
- contractors and consultants; and
- outsourced parties where ABC exposure exists.
Training topics may include:
- definitions and examples of bribery and corruption;
- public-official risk;
- gifts and hospitality rules;
- third-party risk;
- books-and-records expectations;
- escalation and whistleblower obligations; and
- role-specific case studies and red flags.
Training completion must be documented and refreshed periodically.
17 Reporting to Senior Management and the Board
Senior Management and the Board shall receive regular reporting on the status of the ABC program. Reporting may include:
- ABC EWRA results and changes in residual risk;
- incidents, allegations, and investigations;
- gifts and hospitality trends;
- third-party risk issues;
- training completion;
- testing results; and
- remediation status.
The Board must receive sufficient information to assess and challenge the effectiveness of the ABC framework.
18 Recordkeeping and Documentation
Bitkaya shall maintain adequate records to evidence compliance with this manual. Records may include:
- ABC EWRA documentation;
- gifts and hospitality entries;
- third-party due diligence files;
- investigation files;
- training records;
- testing and review outputs;
- management and Board reporting packs; and
- remediation trackers.
Records must be retained for at least the period required by applicable law or internal policy, and longer where there is litigation, investigation, audit, or regulatory need.
19 Disciplinary Measures and External Reporting
Breaches of this manual may result in disciplinary action up to and including termination of employment or contract.
Where appropriate, Bitkaya may also:
- terminate third-party relationships;
- report matters to regulators or competent authorities;
- refer matters to law enforcement; and
- seek recovery of losses or other legal remedies.
The severity of response shall reflect the seriousness of the conduct, management responsibility, intent, harm caused, and cooperation during investigation.
20 Proportionality Implementation
20.1 Purpose and Rationale
Bitkaya applies the principle of proportionality to its Anti-Bribery & Corruption framework to ensure that governance, controls, monitoring, and documentation requirements are commensurate with the company’s size, nature, complexity, and risk profile as a growing Virtual Asset Service Provider.
The proportionality principle recognizes that the sound management of bribery and corruption risk applies regardless of size, but that the extent and formality of implementation should be aligned with the organization’s operational scale, geographic footprint, third-party exposure, and governance maturity.
20.2 Guiding Principles
Bitkaya’s proportionality approach to ABC is based on the following principles:
20.2.1 Risk-Based Application
More intensive controls apply where the risk of improper influence is higher, including dealings involving public officials, higher-risk third parties, opaque payment structures, or unusual benefits.
20.2.2 Scalability
The ABC framework is designed to evolve as Bitkaya grows. Initial controls may be lean and centrally coordinated, while additional specialization, tooling, and formalization may be added as the business expands.
20.2.3 Accountability and Traceability
Even where roles are consolidated, ownership remains clear. All material decisions, approvals, exceptions, and escalations must remain documented and traceable.
20.2.4 Efficiency Without Compromising Control
Bitkaya seeks to maintain an effective ABC framework without creating unnecessary bureaucracy. Controls must be practical, credible, and capable of standing up to management, audit, and regulatory review.
20.3 Application in Practice
This means, for example, that:
- the Compliance Officer may coordinate the ABC framework within a consolidated structure, provided independence and escalation remain credible;
- a central register may be used for gifts and hospitality;
- third-party ABC review may be integrated into broader vendor and compliance processes; and
- training may initially be delivered through integrated compliance modules, with additional targeting where risk justifies it.
20.4 Continuous Development
As Bitkaya grows, enters new markets, or increases reliance on third parties, the ABC framework shall become more detailed and formalized where required to remain effective.
21 Review and Continuous Improvement
This manual shall be reviewed at least annually and whenever there is a material change in:
- law or regulation;
- business activities or jurisdictions;
- governance structure or ownership;
- third-party operating model; or
- findings from incidents, investigations, audits, or regulator feedback.
Bitkaya is committed to continuous improvement of its ABC framework through lessons learned, internal review, independent testing, and changes in the company’s risk profile.
22 Bitkaya Gifts and Hospitality SOP
22.1 Purpose
This SOP explains what Bitkaya staff must do before offering, accepting, or recording any gift, meal, hospitality, travel, entertainment, or similar benefit.
Bitkaya applies this SOP on a proportional basis. As a small VASP, the company does not require heavy approval layers for ordinary low-risk situations. However, anything sensitive, unusual, repeated, high-value, or connected to a public official or live decision must be escalated.
22.2 Scope
This SOP applies to:
- employees;
- directors and officers;
- contractors and consultants; and
- third parties acting on behalf of Bitkaya, where relevant.
It covers both:
- gifts or hospitality offered by Bitkaya; and
- gifts or hospitality offered to Bitkaya personnel.
22.3 Basic Rule
A gift or hospitality item may only proceed if it is:
- lawful;
- modest and reasonable;
- linked to a legitimate business purpose;
- not intended to influence a decision; and
- capable of being openly disclosed and recorded if needed.
If you are unsure, stop and ask Compliance.
22.4 Always Prohibited
Never offer or accept:
- cash or cash equivalents;
- personal loans or personal reimbursements;
- luxury travel or accommodation;
- anything intended to influence a business, regulatory, or commercial outcome;
- anything during a live licensing, approval, procurement, audit, enforcement, complaint, or investigation process;
- anything for a family member of a decision-maker; or
- anything that would be difficult to explain in an audit or to the Board.
22.5 Simple Decision Rule
Before proceeding, ask:
- Is there a real business purpose?
- Is it modest and reasonable?
- Is a public official, regulator, or state-linked party involved?
- Is there any live decision, negotiation, complaint, audit, or approval process connected to this?
- Would I be comfortable if this were reviewed later by Compliance, Audit, or a regulator?
If any answer gives concern, escalate.
22.6 Approval Rules
22.6.1 No formal pre-approval normally needed
Routine low-value refreshments or modest business meals may proceed without formal Compliance approval if:
- no public official is involved;
- no live decision process is involved; and
- the item is clearly modest.
22.6.2 Manager approval
If the item is above the ordinary routine level but still not sensitive, line manager approval is sufficient, with register entry where required.
22.6.3 Compliance approval required before proceeding
Compliance pre-approval is required if:
- the item is above the internal threshold;
- a public official, regulator, or state-owned entity is involved;
- travel or accommodation is included;
- the same external party has offered repeated benefits;
- the timing is sensitive; or
- there is any uncertainty.
22.7 Public Officials
If a public official, regulator, tax authority, licensing authority, law enforcement body, or state-owned entity is involved:
- do not proceed without Compliance approval;
- document the business purpose clearly; and
- refuse anything that appears unofficial, personal, or influence-based.
22.8 Unsolicited Gifts
If something is received unexpectedly:
- Do not use it immediately.
- Tell your manager and Compliance.
- Compliance decides whether it may be kept, returned, surrendered, or donated.
22.9 Escalation Triggers
Escalate immediately if:
- the item feels excessive;
- the timing is sensitive;
- the giver appears to expect a favor;
- the item is being kept off-record;
- travel, accommodation, or unusual payment is involved; or
- a regulator or public official is involved.
22.10 Records
Approvals, refusals, and register entries must be retained under Bitkaya’s normal recordkeeping rules.
23 Bitkaya Third-Party ABC Due Diligence SOP
23.1 Purpose
This SOP explains the minimum ABC checks required before Bitkaya may onboard or continue using a third party that could create bribery or corruption risk.
Bitkaya applies this SOP on a proportional basis. As a small VASP, the company should not run a heavy multinational-style approval process for every ordinary vendor. The focus should be on third parties that can actually create corruption exposure.
23.2 Who This Applies To
Use this SOP mainly for:
- consultants;
- introducers and referral partners;
- agents and representatives;
- outsourced providers with influence or control risk;
- strategic partners; and
- any third party that may interact with regulators, public officials, clients, or counterparties on Bitkaya’s behalf.
This SOP does not require a full ABC file for every ordinary low-risk supplier. Standard low-risk vendors can usually be handled through normal vendor onboarding unless something makes them sensitive.
23.3 Basic Rule
No relevant third party may be approved until the required due diligence is completed, reviewed, and documented.
Commercial urgency is not a reason to skip due diligence.
23.4 Step 1 – Decide Whether ABC DD Is Really Needed
Use this SOP where the third party:
- can influence a decision;
- can interact with regulators or public officials;
- can introduce business through personal networks or influence;
- will be paid commissions, success fees, or unusual compensation; or
- presents any integrity or corruption concern.
If none of the above applies and the third party is an ordinary low-risk supplier, normal onboarding may be enough.
23.5 Step 2 – Classify the Third Party
23.5.1 Low risk
Usually low risk if:
- services are clear and ordinary;
- no public officials are involved;
- no unusual payment structure exists; and
- there are no integrity concerns.
23.5.2 Higher risk
Treat as higher risk if one or more of the following apply:
- the third party deals with public officials or regulators;
- success fees, commissions, or unusually high payments are proposed;
- ownership is unclear;
- the services are vague;
- adverse media or misconduct concerns exist;
- the relationship involves a higher-risk jurisdiction; or
- the third party was introduced through political or regulatory connections.
If in doubt, classify higher and escalate.
23.6 Step 3 – Minimum Checks
Before onboarding, obtain and review at least:
- legal name and registration details;
- ownership / control information;
- business rationale for why Bitkaya needs the third party;
- description of services and deliverables;
- sanctions screening;
- adverse media screening where relevant;
- proposed fee / commission structure; and
- conflicts of interest check.
Bitkaya does not need an overly complex file. The goal is to be able to explain clearly:
- who the third party is;
- what they will do;
- why they are needed;
- how they are paid; and
- why the arrangement is clean.
23.7 Step 4 – Red Flag Review
Escalate to Compliance immediately if you find:
- vague deliverables;
- unusual or inflated fees;
- request for payment to another entity or country without a clear reason;
- refusal to provide ownership details;
- links to public officials or regulators;
- pressure to onboard quickly without paperwork;
- resistance to compliance questions or contract clauses; or
- corruption, bribery, fraud, or misconduct allegations.
23.8 Step 5 – Approval Rules
23.8.1 Low risk
Business owner approval may be sufficient, provided minimum checks are completed and documented.
23.8.2 Medium or unclear risk
Business owner plus Compliance approval required.
23.8.3 High risk
Business owner, Compliance, and Senior Management approval required.
If the third party will interact with a public official or regulator on Bitkaya’s behalf, Compliance approval is always mandatory.
Bitkaya does not require unnecessary committee structures for normal low-risk cases.
23.9 Step 6 – Contract Controls
Before work starts, ensure the contract includes where relevant:
- ABC compliance language;
- audit / information rights;
- breach notification requirements;
- limits on subcontracting without approval; and
- termination rights for misconduct or non-cooperation.
For ordinary low-risk suppliers, standard contract language may be sufficient. Stronger clauses are most important for higher-risk relationships.
23.10 Step 7 – Ongoing Review
After onboarding, review the relationship if:
- ownership changes;
- scope changes;
- payment behavior becomes unusual;
- adverse media appears;
- misconduct concerns arise; or
- the contract is renewed.
24 Implementing Procedures
| Procedure ID | Title | Purpose | Steps Summary |
|---|---|---|---|
| PROC-ABC-001 | Govern ABC and Maintain the Enterprise-Wide Risk Assessment | Maintain accountable ABC governance and a current enterprise-wide assessment of bribery and corruption risk. | 1. Confirm ABC scope and roles. 2. Identify bribery and corruption risk. 3. Assess inherent and residual risk. 4. Apply enhanced controls to higher risk. 5. Assign risk treatment actions. 6. Present risk profile to Board. 7. Review EWRA annually or on change. |
| PROC-ABC-002 | Perform Third-Party and Intermediary ABC Due Diligence | Apply the manual’s risk-based due diligence and approval rules before engaging or continuing a third party capable of creating bribery or corruption exposure. | 1. Determine if ABC due diligence required. 2. Classify third-party risk level. 3. Obtain identity and ownership info. 4. Document business rationale and fees. 5. Perform screening checks. 6. Review red flags. 7. Obtain tiered approvals. 8. Require Compliance approval for officials. 9. Include ABC contract clauses. 10. Reassess on triggers. |
| PROC-ABC-003 | Manage Gifts Hospitality Travel and Entertainment | Assess, approve, refuse and record gifts, meals, hospitality, travel, entertainment and similar benefits offered by or to Bitkaya personnel. | 1. Confirm business purpose. 2. Prohibit excluded items. 3. Allow routine modest refreshments. 4. Obtain line-manager approval. 5. Obtain Compliance pre-approval. 6. Handle unsolicited gifts. 7. Record in Gifts and Hospitality Register. 8. Escalate sensitive items. |
| PROC-ABC-004 | Manage Sensitive Interactions Contributions and Conflicts | Control corruption risk arising from public officials, state-linked parties, donations, sponsorships, political contributions, conflicts of interest and personal benefits. | 1. Document public-official interactions. 2. Obtain Compliance approval for benefits. 3. Escalate unofficial payment requests. 4. Verify donations and sponsorships. 5. Restrict political contributions. 6. Require conflict disclosures. 7. Assess and manage conflicts. 8. Retain decisions and evidence. |
| PROC-ABC-005 | Apply ABC Books Records and Financial Controls | Prevent concealment of bribery or corruption through inaccurate, unsupported or misleading financial and business records. | 1. Require documented approval workflows. 2. Confirm payment legitimacy. 3. Confirm fees are justifiable. 4. Prohibit off-book arrangements. 5. Review unusual financial items. 6. Escalate irregularities before payment. 7. Correct inaccurate records transparently. 8. Retain records per policy. |
| PROC-ABC-006 | Handle ABC Speak-Up Escalation and Investigations | Receive, protect, assess, investigate, remediate and report suspected bribery, corruption, financial irregularity or ABC-control circumvention. | 1. Accept reports through channels. 2. Record and protect reporter. 3. Triage the concern. 4. Assign independent investigator. 5. Preserve relevant evidence. 6. Conduct documented investigation. 7. Escalate material matters. 8. Determine remedial actions. 9. Assign root-cause remediation. 10. Close after documentation approved. |
| PROC-ABC-007 | Monitor Test Train Report and Improve ABC | Monitor and test the ABC framework, train relevant persons, report to governance bodies, retain evidence and improve the program. | 1. Establish monitoring and testing plan. 2. Perform second-line testing. 3. Arrange independent review. 4. Deliver ABC training. 5. Record and refresh training. 6. Report to management and Board. 7. Retain ABC evidence. 8. Review manual annually. 9. Apply lessons and improve. |
25 Implementing Controls
| Control ID | Objective | Testing Method | Frequency |
|---|---|---|---|
| CTRL-ABC-001 | Ensure ABC responsibilities, resources, risk assessment, treatment and Board oversight remain current and proportionate. | Inspect annual approval and sample material risks through treatment, escalation and closure. | Annual and after material change |
| CTRL-ABC-002 | Ensure relevant third parties are risk-classified, checked, approved, contracted and reviewed before they expose Bitkaya to bribery or corruption risk. | Sample relevant third parties and trace due diligence, approval, contract safeguards and monitoring to the risk classification. | Before engagement and on material trigger or renewal |
| CTRL-ABC-003 | Ensure gifts, hospitality, travel, entertainment and similar benefits are legitimate, proportionate, approved where required and transparently recorded. | Review the register and sample entries for purpose, timing, threshold, sensitive-party assessment, approval and disposition. | Periodic risk-based review and per identified exception |
| CTRL-ABC-004 | Ensure elevated corruption risks involving public-sector parties, contributions and personal conflicts receive documented review, approval and restriction. | Sample sensitive interactions and disclosures for complete review, approval, accounting and treatment. | Per event and periodic conflict review |
| CTRL-ABC-005 | Ensure payments, invoices, commissions, expenses and related records are legitimate, supported, approved, accurate and auditable. | Sample payments and exceptions for valid support, approval, payee, rationale, recording and escalation. | Per transaction with periodic risk-based sample testing |
| CTRL-ABC-006 | Ensure credible ABC concerns are protected, assessed, independently investigated, reported and remediated. | Sample closed and open matters for timely triage, confidentiality, independence, evidence, escalation and remediation. | Per concern with periodic case-file review |
| CTRL-ABC-007 | Ensure the ABC framework is monitored, tested, understood, reported, evidenced and improved. | Inspect the annual program pack and sample monitoring, training and findings through reporting and verified closure. | Periodic risk-based monitoring and training; annual framework review; event-driven improvement |
26 Relationships and Cross-References
Regulatory Sources
- SRC-VASP-001 — VASP regulatory source
- SRC-OUT-001 — Outsourcing regulatory source
Regulatory Requirements
- REQ-VASP-003 — Maintain Governance and Fit and Proper Oversight
- REQ-VASP-005 — Maintain Integrity Based Business Operations
- REQ-VASP-006 — (VASP requirement)
- REQ-VASP-007 — (VASP requirement)
- REQ-VASP-008 — Retain Transaction Records and Regulatory Data
- REQ-VASP-014 — Cooperate With CBCS Supervision and Enforcement
- REQ-OUT-003 — (Outsourcing requirement)
- REQ-OUT-004 — Perform Service Provider Due Diligence
- REQ-OUT-005 — (Outsourcing requirement)
- REQ-OUT-007 — (Outsourcing requirement)
- REQ-OUT-009 — Monitor Audit and Control Outsourcing Arrangements
Related Policies
- POL-ECM-001 — Enterprise Compliance Manual
- POL-OUT-001 — Outsourcing Risk Management Manual
- POL-TRAIN-001 — Training and Awareness Manual
Related Processes
- PRC-OTC-001 — (OTC process)
- PRC-FCI-001 — Financial Crime and Integrity
Related Procedures
- PROC-ABC-001 — Govern ABC and Maintain the Enterprise-Wide Risk Assessment
- PROC-ABC-002 — Perform Third-Party and Intermediary ABC Due Diligence
- PROC-ABC-003 — Manage Gifts Hospitality Travel and Entertainment
- PROC-ABC-004 — Manage Sensitive Interactions Contributions and Conflicts
- PROC-ABC-005 — Apply ABC Books Records and Financial Controls
- PROC-ABC-006 — Handle ABC Speak-Up Escalation and Investigations
- PROC-ABC-007 — Monitor Test Train Report and Improve ABC
- PROC-TRAIN-003 — (Training procedure)
- PROC-TRAIN-004 — (Training procedure)
Related Controls
- CTRL-ABC-001 — Ensure ABC Governance and EWRA Are Maintained
- CTRL-ABC-002 — Ensure Third-Party ABC Due Diligence Is Completed
- CTRL-ABC-003 — Ensure Gifts and Hospitality Are Approved and Recorded
- CTRL-ABC-004 — Ensure Sensitive Interactions Contributions and Conflicts Are Controlled
- CTRL-ABC-005 — Ensure ABC Books Records and Payments Are Controlled
- CTRL-ABC-006 — Ensure ABC Concerns Are Escalated and Investigated
- CTRL-ABC-007 — Ensure ABC Monitoring Training Reporting and Improvement Are Maintained
- CTRL-TRAIN-003 — (Training control)
- CTRL-TRAIN-004 — (Training control)
Related Systems
- SYS-ECM-001 — Compliance Framework Library
- SYS-ECM-002 — Compliance Reporting and Evidence Repository
- SYS-OUT-001 — Outsourcing Register
Publications
- PUB-TRAIN-001 — (Training publication)
- PUB-TRAIN-004 — (Training publication)
Decisions
- ADR-003 — (Architecture decision record)
Open Issues
- None currently open
27 Review and Continuous Improvement
Assurance
- Design status: implemented from approved ABC Manual version 1.0
- Operating assurance: pending system-derived assessment
- Evidence status: expected evidence is defined in the implementing controls
- Review cadence: annual and after material legal, business, jurisdictional, governance, third-party or assurance change
- Overall status: implemented design; operating-effectiveness testing pending
Continuous Improvement
Bitkaya is committed to continuous improvement of its ABC framework through lessons learned, internal review, independent testing, and changes in the company’s risk profile. The manual shall be reviewed at least annually and whenever there is a material change in law or regulation, business activities or jurisdictions, governance structure or ownership, third-party operating model, or findings from incidents, investigations, audits, or regulator feedback.
Appendix A — Cross-Reference Register
| BCMS ID | Type | Title | Reference |
|---|---|---|---|
| POL-ABC-001 | Policy | Anti-Bribery and Corruption Manual | This document |
| POL-ECM-001 | Policy | Enterprise Compliance Manual | Section 2, 26 |
| POL-OUT-001 | Policy | Outsourcing Risk Management Manual | Section 8, 26 |
| POL-TRAIN-001 | Policy | Training and Awareness Manual | Section 16, 26 |
| PROC-ABC-001 | Procedure | Govern ABC and Maintain the Enterprise-Wide Risk Assessment | Section 24 |
| PROC-ABC-002 | Procedure | Perform Third-Party and Intermediary ABC Due Diligence | Section 24 |
| PROC-ABC-003 | Procedure | Manage Gifts Hospitality Travel and Entertainment | Section 24 |
| PROC-ABC-004 | Procedure | Manage Sensitive Interactions Contributions and Conflicts | Section 24 |
| PROC-ABC-005 | Procedure | Apply ABC Books Records and Financial Controls | Section 24 |
| PROC-ABC-006 | Procedure | Handle ABC Speak-Up Escalation and Investigations | Section 24 |
| PROC-ABC-007 | Procedure | Monitor Test Train Report and Improve ABC | Section 24 |
| PROC-TRAIN-003 | Procedure | Training procedure | Section 26 |
| PROC-TRAIN-004 | Procedure | Training procedure | Section 26 |
| CTRL-ABC-001 | Control | Ensure ABC Governance and EWRA Are Maintained | Section 25 |
| CTRL-ABC-002 | Control | Ensure Third-Party ABC Due Diligence Is Completed | Section 25 |
| CTRL-ABC-003 | Control | Ensure Gifts and Hospitality Are Approved and Recorded | Section 25 |
| CTRL-ABC-004 | Control | Ensure Sensitive Interactions Contributions and Conflicts Are Controlled | Section 25 |
| CTRL-ABC-005 | Control | Ensure ABC Books Records and Payments Are Controlled | Section 25 |
| CTRL-ABC-006 | Control | Ensure ABC Concerns Are Escalated and Investigated | Section 25 |
| CTRL-ABC-007 | Control | Ensure ABC Monitoring Training Reporting and Improvement Are Maintained | Section 25 |
| CTRL-TRAIN-003 | Control | Training control | Section 26 |
| CTRL-TRAIN-004 | Control | Training control | Section 26 |
| REQ-VASP-003 | Requirement | Maintain Governance and Fit and Proper Oversight | Section 26 |
| REQ-VASP-005 | Requirement | Maintain Integrity Based Business Operations | Section 26 |
| REQ-VASP-006 | Requirement | VASP requirement | Section 26 |
| REQ-VASP-007 | Requirement | VASP requirement | Section 26 |
| REQ-VASP-008 | Requirement | Retain Transaction Records and Regulatory Data | Section 26 |
| REQ-VASP-014 | Requirement | Cooperate With CBCS Supervision and Enforcement | Section 26 |
| REQ-OUT-003 | Requirement | Outsourcing requirement | Section 26 |
| REQ-OUT-004 | Requirement | Perform Service Provider Due Diligence | Section 26 |
| REQ-OUT-005 | Requirement | Outsourcing requirement | Section 26 |
| REQ-OUT-007 | Requirement | Outsourcing requirement | Section 26 |
| REQ-OUT-009 | Requirement | Monitor Audit and Control Outsourcing Arrangements | Section 26 |
| SRC-VASP-001 | Source | VASP regulatory source | Section 26 |
| SRC-OUT-001 | Source | Outsourcing regulatory source | Section 26 |
| PRC-OTC-001 | Process | OTC process | Section 26 |
| PRC-FCI-001 | Process | Financial Crime and Integrity | Section 26 |
| SYS-ECM-001 | System | Compliance Framework Library | Section 26 |
| SYS-ECM-002 | System | Compliance Reporting and Evidence Repository | Section 26 |
| SYS-OUT-001 | System | Outsourcing Register | Section 26 |
| PUB-TRAIN-001 | Publication | Training publication | Section 26 |
| PUB-TRAIN-004 | Publication | Training publication | Section 26 |
| ADR-003 | Decision | Architecture decision record | Section 26 |
Appendix B — Change History
| Date | Summary |
|---|---|
| 2026-07-28 | Enriched the policy body to reproduce the full approved ABC Manual (all 23 chapters) for 100% PDF coverage. |
| 2026-07-26 | Aligned assurance wording with the system-derived Hermes/Odoo result model. |
| 2026-07-26 | Registered the approved ABC Manual and established its operating process, procedures and controls. |
Generated from BCMS vault commit 7d9a5eb on 2026-07-28. BCMS object: POL-ABC-001 v2.0.0.