Purpose

Register the supplied SOP as the operating guide for Odoo pre-trade and post-trade know-your-transaction controls used for Bitkaya OTC virtual-asset trades.

This publication is subordinate to PROC-AML-004 Perform Transaction Monitoring and Alert Review. It supplements the broader transaction-monitoring and Odoo automation publications and does not replace sanctions, KYC/CDD, FIU-reporting, wallet-verification, recordkeeping or independent-assurance procedures.

Audience

  • Operations personnel handling OTC Sales Orders, Purchase Orders and related inventory transfers in Odoo.
  • Compliance personnel reviewing non-clear KYT outcomes.
  • Management personnel reviewing business-risk decisions after mandatory compliance requirements are resolved.
  • Technology and assurance personnel responsible for automation, configuration, testing and evidence.

Source Objects

Control Design

Pre-Trade

Before release or execution, the Odoo control checks the client KYC status, bank-account presence, expected transaction profile, seven-day OTC activity, wallet presence and Crystal wallet-risk result. For Purchase Orders, this wallet check is an exposure proxy and does not replace the post-trade transaction check.

Post-Trade

After the blockchain transaction occurs, Operations records the transaction hash on the relevant inventory transfer. The control checks asset and network mapping, Crystal transaction KYT, expected wallet role, token amount within the configured tolerance and reconciliation exceptions.

Outcomes

  • CLEAR: the automated checks found no blocking issue; activity may continue only when no separate manual red flag, hold or restriction exists.
  • PROCESSING: no final conclusion; it is not approval and the trade or case must not be treated as cleared.
  • REVIEW: human assessment and documented disposition are required; it is not equivalent to clear.
  • ESCALATE: activity must be paused where still possible and escalated for authorized disposition.

If a post-trade result is non-clear after the transaction has already occurred, Operations must preserve the evidence, prevent further avoidable processing, escalate promptly and support assessment of restrictions, FIU reporting, client action, retrospective review and control remediation.

Publication Rules

  • Do not use Management approval to override a sanctions restriction, mandatory AML escalation, unresolved KYC prohibition, legal hold, FIU decision, tipping-off safeguard or other non-discretionary compliance requirement.
  • Compliance shall determine whether a non-clear KYT outcome is resolved for AML purposes. The MLRO or authorized Compliance delegate retains FIU-reporting decision authority.
  • Management may approve a residual business-risk exception only after Compliance confirms that no mandatory legal, sanctions, AML or regulatory prohibition remains.
  • Record the approver, date, scope, rationale, conditions and follow-up in the restricted Helpdesk ticket or Odoo chatter before release or closure.
  • Keep client followers and unauthorized users out of restricted KYT, suspicion and escalation records.
  • Use asset-specific transaction-hash fields where available and treat generic fields as controlled exceptions.
  • Permit reruns only for an approved reason, by authorized roles, with the original and rerun results retained.
  • A rerun must not erase or obscure the original alert, exception, evidence or decision trail.

Controlled Configuration Requiring Approval

Before this SOP moves from review to implemented or operational, approve and test:

  • the current legal basis and operational use of the 30,000 XCG threshold;
  • the seven-day aggregation logic, client-linking method, transaction statuses, direction coverage and currency conversion;
  • Crystal alert grades, risk-score thresholds and unavailable or failed-result handling;
  • the exact approved Crystal production baseline and its post-change validation;
  • supported assets, tokens, networks, wallet roles and transaction-hash fields;
  • amount-match tolerance and rounding rules;
  • Helpdesk routing, stages, access, client-follower removal and closure criteria;
  • approval roles and segregation between Operations, Compliance, Management and Technology;
  • manual-rerun permission, reason, logging and retry limits; and
  • positive, negative, boundary, duplicate, mapping, timeout, failure and retrospective-lookback scenarios.

Approval

  • Document title: SOP: Odoo Pre-Trade and Post-Trade KYT Controls
  • Version: 1.0
  • Date shown in document: 2026-07-06
  • Author from PDF metadata: Cees Quirijns
  • Approval shown in document: none
  • Required content owners: Compliance, Operations and Technology
  • Required approver: Managing Director
  • BCMS status remains review until the control configuration, approval hierarchy and acceptance evidence are confirmed.

Published Artifact

  • Permanent artifact: SOP Pre and Post Trade KYT v10.pdf
  • Pages: 9
  • PDF metadata creation and modification date: 2026-07-06
  • Artifact SHA-256: 3d318b6b760475b7388e8b1732413bd74e5caff45ab1a6326f188d2610027d50

Evidence

  • Odoo order, inventory transfer, client and wallet records
  • Pre-trade and post-trade result, timestamp and automation version
  • Crystal wallet and transaction KYT results
  • Helpdesk ticket, chatter, investigation and disposition
  • Approval, restriction, FIU decision and follow-up evidence where applicable
  • Original and rerun input, reason, result and audit trail
  • Configuration export, test results, exceptions and remediation

Relationships

Assurance

  • Artifact registered and visually inspected: yes
  • Document approval evidenced: no
  • Configuration and thresholds independently verified: no
  • Acceptance and operating-effectiveness testing evidenced: no
  • Management-override wording compatible with mandatory compliance controls: no; qualification recorded in this publication and ISS-IT-001 Confirm Odoo Compliance Automation Security Testing and Operating Evidence
  • Overall status: current implementation SOP registered for review; operating effectiveness not assessed

History

  • 2026-07-26: Registered the Odoo Pre-Trade and Post-Trade KYT Controls SOP version 1.0 under PROC-AML-004 and recorded approval, configuration and override-governance gaps.