Purpose

Translate the VASP Ordinance into a testable BCMS requirement for integrity risk management and prevention of misuse.

Normative

Bitkaya shall maintain policies, procedures and controls for an integrity-conscious VASP business operation based on systematic analysis of integrity risks.

Descriptive

The integrity framework should address integrity culture, conflicts of interest, AML/CFT and proliferation-financing compliance, sanctions compliance, prevention of criminal conduct and legal breaches, customer and market integrity risks, and alignment with related laws referenced by the VASP Ordinance.

Source reference: VASP Ordinance, Article 35; commencement instrument Publicatieblad A 2025 No. 91, Article 1.

Assurance Assertions

  • A documented integrity risk analysis exists for VASP activities.
  • Integrity policies and controls address conflicts, AML/CFT, sanctions and misuse risks.
  • Integrity incidents and control weaknesses are escalated and remediated.

Relationships

Assurance

  • Source verified: yes
  • Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
  • Wording unambiguous: review

History

  • 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
  • 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.