Purpose
Establish the FATF-based requirement for customer due diligence and ongoing monitoring in virtual asset services.
Normative
Bitkaya shall perform risk-based customer due diligence and ongoing monitoring for customers using virtual asset services, including identification, verification, risk assessment, sanctions screening, enhanced due diligence where required and periodic review.
Descriptive
The future AML/CFT/CPF manual should define detailed operating rules. This BCMS requirement captures the FATF baseline that VASPs apply preventive measures comparable to financial institutions, adapted to VA/VASP risks and local law.
Source reference: SRC-FATF-001 FATF Virtual Assets and VASP Standards.
Assurance Assertions
- Customer identification and verification are completed according to risk.
- Customer risk rating drives monitoring and review cadence.
- Enhanced due diligence is applied for higher-risk customers or circumstances.
Relationships
- Source: SRC-FATF-001 FATF Virtual Assets and VASP Standards
- Parent policy: POL-ECM-001 Enterprise Compliance Manual
- Process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Regulatory-change procedure: PROC-ECM-002 Assess Regulatory Change and Framework Impact
- Regulatory-change control: CTRL-ECM-002 Ensure Regulatory Change Impact Assessment Is Completed
- Framework library: SYS-ECM-001 Compliance Framework Library
- Related VASP requirements: REQ-VASP-001 through REQ-VASP-015, where applicable
- Detailed AML/CFT/CPF manual objects: pending
Assurance
- Source verified: yes
- Implementation linked: parent-framework only
- Wording unambiguous: review
- Detailed operating procedure linked: pending future detailed manuals where applicable
History
- 2026-07-25: Created from consolidated FATF VA/VASP source object.