Purpose
Translate the VASP Ordinance into a testable BCMS requirement for governance, management suitability, reliability and oversight.
Normative
Bitkaya shall maintain governance arrangements that ensure suitable, reliable and competent policymakers, co-policymakers, supervisory board members, staff and outsourced service providers for regulated VASP activities.
Descriptive
The governance framework should address daily policy determination by at least two natural persons, local presence where required, board and supervisory responsibilities, fit-and-proper evidence, reliability assessments, competent staffing, oath or promise requirements if applicable, corporate governance, strategy, risk policy, decision-making, remuneration, independence and transparency of control structures.
Source reference: VASP Ordinance, Articles 20 through 27 and 56 through 58; commencement instrument Publicatieblad A 2025 No. 91, Article 1.
Assurance Assertions
- Governance responsibilities for VASP activities are documented.
- Required fit-and-proper, reliability and competence evidence is maintained.
- CBCS prior permission is obtained where required before relevant appointments take effect.
Relationships
- Source: SRC-VASP-001 Landsverordening toezicht virtuele activa dienstverleners
- Policies: POL-AML-001 AML CTF CPF Compliance Manual, POL-ECM-001 Enterprise Compliance Manual
- Processes: PRC-FCI-001 Financial Crime and Integrity, PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-AML-001 Maintain AML Risk Assessment and SARA Calibration, PROC-AML-002 Perform Client Acceptance CDD EDD and Risk Classification, PROC-AML-006 Apply Travel Rule and Counterparty VASP Due Diligence, PROC-AML-008 Deliver AML Training and Awareness, PROC-AML-009 Perform AML Independent Review and Remediation, PROC-AML-010 Review AML Policy and Proportionality Implementation
- Controls: CTRL-ABC-001 Ensure ABC Governance and EWRA Are Maintained, CTRL-ABC-004 Ensure Sensitive Interactions Contributions and Conflicts Are Controlled, CTRL-ABC-007 Ensure ABC Monitoring Training Reporting and Improvement Are Maintained, CTRL-MCT-001 Ensure Market Conduct Governance Permissions and Risk Are Current, CTRL-MCT-002 Ensure Market Abuse and Personal Trading Controls Operate, CTRL-MCT-007 Ensure Market Conduct Surveillance Reporting and Improvement Operate, CTRL-EMP-001 Ensure Employee Handbook Acknowledgments Are Complete, CTRL-EMP-002 Ensure Mandatory Employee Training Is Completed, CTRL-EMP-003 Ensure Employee Conduct Conflicts Assets and Data Are Controlled, CTRL-EMP-004 Ensure Whistleblower Reports Are Protected and Investigated, CTRL-EMP-005 Ensure Employee Violations Receive Consistent Disciplinary Action, CTRL-EMP-006 Ensure Employees Cooperate With Reviews and Audits, CTRL-EMP-007 Ensure Ethics Certification and Handbook Review Are Current, CTRL-RMF-001 Ensure Risk Governance Appetite and Taxonomy Are Current, CTRL-RMF-002 Ensure Risk Assessments Are Complete and Current, CTRL-RMF-003 Ensure Controls Indicators and Remediation Are Monitored, CTRL-RMF-008 Ensure Risk Data Reporting Assurance and Policy Are Governed, CTRL-ICA-001 Ensure Control Governance and Assurance Independence, CTRL-ICA-003 Ensure Risk Based Internal Audits Are Independent and Complete, CTRL-ICA-004 Ensure Second Line Control Testing Is Effective, CTRL-ICA-006 Ensure Findings Are Escalated and Remediated, CTRL-ICA-007 Ensure Assurance Competence Evidence and Proportionality, CTRL-REG-001 Ensure Regulatory Obligations and Calendar Are Current, CTRL-REG-004 Ensure CBCS Reporting and Notifications Are Controlled, CTRL-REG-007 Ensure Reporting Breaches Training and Proportionality Are Managed, CTRL-ESG-001 Ensure ESG Governance Strategy and Oversight Are Current, CTRL-ESG-003 Ensure Employee Wellbeing Inclusion and Human Rights Are Supported, CTRL-ESG-005 Ensure Ethical Conduct and Governance Standards Operate, CTRL-ESG-006 Ensure ESG Risk Is Integrated Into Material Decisions, CTRL-ESG-007 Ensure ESG Reporting Proportionality and Improvement Are Current, CTRL-PRIV-001 Ensure Processing Activities Legal Bases and Privacy Risks Are Current, CTRL-PRIV-007 Ensure Privacy Governance Training and Proportionality Are Reviewed, CTRL-ODOO-001 Ensure Odoo Backup Strategy Responsibilities and Objectives Are Approved, CTRL-ODOO-006 Ensure Backup Exceptions Dependencies and Changes Are Reviewed, CTRL-COMP-001 Ensure Complaints Governance Channels and Information Are Current, CTRL-COMP-003 Ensure Complaints Are Risk Triaged and Assigned Impartially, CTRL-COMP-007 Ensure Complaint Trends Reporting Training and Improvement Are Maintained, CTRL-COMM-001 Ensure Communication Standards and Approved Wording Are Current, CTRL-COMM-007 Ensure Communication Training and Proportionality Review Occur, CTRL-SAFU-001 Ensure Safeguarding Governance Training and Proportionality Are Maintained, CTRL-SAFU-008 Ensure Safeguarding Breaches Resolution and Assurance Are Effective, CTRL-FIN-001 Ensure Finance Tax Governance Calendar and Proportionality Are Current, CTRL-FIN-005 Ensure Payroll Social Security and Withholding Obligations Are Met, CTRL-FIN-007 Ensure Authority Requests Reporting Assurance and Remediation Are Managed, CTRL-TRAIN-001 Ensure Training Needs Matrix and Calendar Are Complete, CTRL-TRAIN-002 Ensure Onboarding and Role Readiness Are Completed, CTRL-TRAIN-003 Ensure Recurring and Role Specific Training Is Completed, CTRL-TRAIN-005 Ensure Competence Is Assessed and Gaps Are Remediated
- Systems: not yet assigned; tracked under ISS-COMP-001, ISS-COMM-001, ISS-SAFU-001, ISS-FIN-001, ISS-TRAIN-001, ISS-OTC-001
- Issues: ISS-COMP-001 Confirm Complaints Channels Register and CBCS Source, ISS-COMM-001 Confirm Licensing Claims Approval Workflow and Operating Evidence, ISS-SAFU-001 Confirm Safeguarding Architecture Legal Protections and Operating Evidence, ISS-FIN-001 Confirm Finance and Tax Sources Thresholds Systems and Operating Evidence, ISS-TRAIN-001 Confirm Training Governance Completion Assessment and Operating Evidence, ISS-OTC-001 Review and Complete Principal OTC Service Flow Controls
- Publications: PUB-TRAIN-001 Compliance Framework Onboarding for New Employees, PUB-TRAIN-002 Compliance Department Training, PUB-OTC-001 Bitkaya Principal OTC Service Flows Memo
Assurance
- Source verified: yes
- Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
- Wording unambiguous: review
History
- 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
- 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.