Purpose
Translate FATF VA/VASP standards into a testable requirement for a risk-based AML/CFT/CPF framework covering Bitkaya virtual asset services.
Normative
Bitkaya shall maintain a documented, risk-based AML/CFT/CPF framework for virtual asset activities and VASP operations that identifies, assesses, mitigates, monitors and reports relevant money laundering, terrorist financing and proliferation-financing risks.
Descriptive
The framework should use FATF Recommendation 15, INR.15 and the FATF VA/VASP guidance as international baseline material, while applying Curaçao law, CBCS requirements and Bitkaya-specific risk appetite. It should cover customers, products, services, delivery channels, jurisdictions, counterparties, technology, outsourcing, stablecoins, unhosted wallets, peer-to-peer exposure and emerging threats.
Source reference: SRC-FATF-001 FATF Virtual Assets and VASP Standards.
Assurance Assertions
- A documented VA/VASP risk assessment exists and is reviewed periodically.
- Controls are proportionate to assessed VA/VASP risks.
- Framework changes are tracked when FATF or local regulatory expectations change.
Relationships
- Source: SRC-FATF-001 FATF Virtual Assets and VASP Standards
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Regulatory-change procedure: PROC-ECM-002 Assess Regulatory Change and Framework Impact
- Regulatory-change control: CTRL-ECM-002 Ensure Regulatory Change Impact Assessment Is Completed
- Framework library: SYS-ECM-001 Compliance Framework Library
- Related VASP requirements: REQ-VASP-001 through REQ-VASP-015, where applicable
- Detailed AML/CFT/CPF manual objects: pending
Assurance
- Source verified: yes
- Implementation linked: parent-framework only
- Wording unambiguous: review
- Detailed operating procedure linked: pending future detailed manuals where applicable
History
- 2026-07-25: Created from consolidated FATF VA/VASP source object.