Purpose

Capture the April 2024 CBCS Circulaire requiring supervised institutions subject to the National Ordinance on Identification before Rendering Services (NOIS/LID) to conduct independent testing of their AML/CFT/CFP compliance program.

Authority

Summary

In April 2024, the CBCS issued a Circulaire requiring supervised institutions subject to the National Ordinance on Identification before Rendering Services (NOIS/LID) to conduct independent testing of their AML/CFT/CFP compliance program. The circulaire mandates that the independent testing must be conducted at least annually by the internal audit department or by an outside independent party such as the external auditor.

The requirement applies to all service providers supervised under NOIS/LID, which includes VASPs since the May 2024 expansion of the service perimeter. The independent testing must evaluate the adequacy and effectiveness of the institution’s AML/CFT/CPF policies, procedures, controls, and risk assessment, and must cover all relevant business units and activities.

Currentness and Operational Status

The independent AML testing obligation is already operationally satisfied:

  • POL-ICA-001 Internal Controls and Audit Manual Section 4.1 (Internal Audit) states: “Conducts risk-based audits annually, covering: AML/CFT/CPF framework, Custody and reconciliation controls…”
  • POL-AML-001 AML CTF CPF Compliance Manual references independent testing (line 181: “independent testing and proportionate governance”; line 208: “Independent review and testing”; line 235: “independently tested by Bitkaya’s internal audit personnel or competent external sources”).
  • The existing PROC-ICA-001 through PROC-ICA-007 and CTRL-ICA-001 through CTRL-ICA-007 already cover the annual audit cycle.

Relevant Provisions

  • Conduct independent testing of the AML/CFT/CFP compliance program at least annually
  • Testing must be performed by internal audit or an external independent party (e.g., external auditor)
  • Testing must evaluate adequacy and effectiveness of AML/CFT/CPF policies, procedures, controls, and risk assessment
  • Testing must cover all relevant business units and activities
  • Results must be documented and made available to CBCS upon request
  • Applies to all NOIS-supervised institutions, including VASPs

Relationships

Assurance

  • Official CBCS URL verified: yes
  • Circulaire reviewed: yes
  • Operational implementation confirmed: yes — POL-ICA-001 Section 4.1 already requires annual independent audits covering AML/CFT/CPF
  • Applicability confirmed: applicable to Bitkaya as a VASP subject to NOIS/LID

History

  • 2026-07-29: Created source object for the April 2024 Circulaire on Independent AML Testing (CHG-RES-003). Independent testing obligation already operationally implemented via POL-ICA-001 Section 4.1.