Purpose
Translate the VASP Ordinance into a testable BCMS requirement for integrity risk management and prevention of misuse.
Normative
Bitkaya shall maintain policies, procedures and controls for an integrity-conscious VASP business operation based on systematic analysis of integrity risks.
Descriptive
The integrity framework should address integrity culture, conflicts of interest, AML/CFT and proliferation-financing compliance, sanctions compliance, prevention of criminal conduct and legal breaches, customer and market integrity risks, and alignment with related laws referenced by the VASP Ordinance.
Source reference: VASP Ordinance, Article 35; commencement instrument Publicatieblad A 2025 No. 91, Article 1.
Assurance Assertions
- A documented integrity risk analysis exists for VASP activities.
- Integrity policies and controls address conflicts, AML/CFT, sanctions and misuse risks.
- Integrity incidents and control weaknesses are escalated and remediated.
Relationships
- Source: SRC-VASP-001 Landsverordening toezicht virtuele activa dienstverleners
- Policies: POL-AML-001 AML CTF CPF Compliance Manual, POL-ECM-001 Enterprise Compliance Manual
- Processes: PRC-FCI-001 Financial Crime and Integrity, PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-AML-001 Maintain AML Risk Assessment and SARA Calibration, PROC-AML-002 Perform Client Acceptance CDD EDD and Risk Classification, PROC-AML-003 Perform Sanctions Screening and Restrictive Measures Escalation, PROC-AML-004 Perform Transaction Monitoring and Alert Review, PROC-AML-005 Perform FIU Reporting and Case Escalation, PROC-AML-006 Apply Travel Rule and Counterparty VASP Due Diligence, PROC-AML-008 Deliver AML Training and Awareness, PROC-AML-009 Perform AML Independent Review and Remediation, PROC-AML-010 Review AML Policy and Proportionality Implementation
- Controls: CTRL-ABC-001 Ensure ABC Governance and EWRA Are Maintained, CTRL-ABC-002 Ensure Third-Party ABC Due Diligence Is Completed, CTRL-ABC-003 Ensure Gifts and Hospitality Are Approved and Recorded, CTRL-ABC-004 Ensure Sensitive Interactions Contributions and Conflicts Are Controlled, CTRL-ABC-005 Ensure ABC Books Records and Payments Are Controlled, CTRL-ABC-006 Ensure ABC Concerns Are Escalated and Investigated, CTRL-ABC-007 Ensure ABC Monitoring Training Reporting and Improvement Are Maintained, CTRL-MCT-002 Ensure Market Abuse and Personal Trading Controls Operate, CTRL-MCT-003 Ensure Best Execution and Order Handling Are Controlled, CTRL-MCT-007 Ensure Market Conduct Surveillance Reporting and Improvement Operate, CTRL-EMP-001 Ensure Employee Handbook Acknowledgments Are Complete, CTRL-EMP-002 Ensure Mandatory Employee Training Is Completed, CTRL-EMP-003 Ensure Employee Conduct Conflicts Assets and Data Are Controlled, CTRL-EMP-004 Ensure Whistleblower Reports Are Protected and Investigated, CTRL-EMP-005 Ensure Employee Violations Receive Consistent Disciplinary Action, CTRL-EMP-007 Ensure Ethics Certification and Handbook Review Are Current, CTRL-RMF-001 Ensure Risk Governance Appetite and Taxonomy Are Current, CTRL-RMF-002 Ensure Risk Assessments Are Complete and Current, CTRL-RMF-003 Ensure Controls Indicators and Remediation Are Monitored, CTRL-RMF-006 Ensure Incidents Issues and Complaints Are Coordinated, CTRL-RMF-009 Ensure Fraud Concerns Are Stopped Escalated and Recorded, CTRL-ICA-001 Ensure Control Governance and Assurance Independence, CTRL-ICA-002 Ensure Core Internal Control Coverage Is Complete, CTRL-ICA-003 Ensure Risk Based Internal Audits Are Independent and Complete, CTRL-ICA-004 Ensure Second Line Control Testing Is Effective, CTRL-ICA-006 Ensure Findings Are Escalated and Remediated, CTRL-ICA-007 Ensure Assurance Competence Evidence and Proportionality, CTRL-REG-003 Ensure FIU and Sanctions Reporting Is Complete and Confidential, CTRL-REG-004 Ensure CBCS Reporting and Notifications Are Controlled, CTRL-REG-007 Ensure Reporting Breaches Training and Proportionality Are Managed, CTRL-ESG-001 Ensure ESG Governance Strategy and Oversight Are Current, CTRL-ESG-002 Ensure Environmental Metrics and Resource Actions Are Monitored, CTRL-ESG-003 Ensure Employee Wellbeing Inclusion and Human Rights Are Supported, CTRL-ESG-004 Ensure Community and Partnership Activities Are Responsible, CTRL-ESG-005 Ensure Ethical Conduct and Governance Standards Operate, CTRL-ESG-006 Ensure ESG Risk Is Integrated Into Material Decisions, CTRL-ESG-007 Ensure ESG Reporting Proportionality and Improvement Are Current, CTRL-PRIV-001 Ensure Processing Activities Legal Bases and Privacy Risks Are Current, CTRL-PRIV-002 Ensure Data Subject Requests and Privacy Information Are Controlled, CTRL-PRIV-006 Ensure AML Sanctions and Regulatory Data Remain Confidential, CTRL-PRIV-007 Ensure Privacy Governance Training and Proportionality Are Reviewed, CTRL-ODOO-006 Ensure Backup Exceptions Dependencies and Changes Are Reviewed, CTRL-COMP-001 Ensure Complaints Governance Channels and Information Are Current, CTRL-COMP-003 Ensure Complaints Are Risk Triaged and Assigned Impartially, CTRL-COMP-004 Ensure Complaint Investigations Are Fair Complete and Evidenced, CTRL-COMP-005 Ensure Complaints Are Resolved Remediated and Answered on Time, CTRL-COMP-007 Ensure Complaint Trends Reporting Training and Improvement Are Maintained, CTRL-COMM-001 Ensure Communication Standards and Approved Wording Are Current, CTRL-COMM-006 Ensure Communications Are Monitored and Breaches Corrected, CTRL-COMM-007 Ensure Communication Training and Proportionality Review Occur, CTRL-SAFU-001 Ensure Safeguarding Governance Training and Proportionality Are Maintained, CTRL-SAFU-003 Ensure Client Asset Movements Are Authorized and Permitted, CTRL-SAFU-008 Ensure Safeguarding Breaches Resolution and Assurance Are Effective, CTRL-FIN-002 Ensure Books Records and Financial Close Are Complete and Accurate, CTRL-FIN-004 Ensure CIT and TOT Are Calculated Filed and Paid on Time, CTRL-FIN-005 Ensure Payroll Social Security and Withholding Obligations Are Met, CTRL-FIN-006 Ensure Finance Movements Reconciliations and Exceptions Are Controlled, CTRL-TRAIN-001 Ensure Training Needs Matrix and Calendar Are Complete, CTRL-TRAIN-002 Ensure Onboarding and Role Readiness Are Completed, CTRL-TRAIN-003 Ensure Recurring and Role Specific Training Is Completed, CTRL-TRAIN-004 Ensure Quarterly Awareness Activity Occurs, CTRL-TRAIN-005 Ensure Competence Is Assessed and Gaps Are Remediated
- Systems: SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-FIN-001 Odoo Accounting ERP, SYS-IT-001 Odoo Automated Compliance Monitoring
- Issues: ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration, ISS-COMP-001 Confirm Complaints Channels Register and CBCS Source, ISS-COMM-001 Confirm Licensing Claims Approval Workflow and Operating Evidence, ISS-SAFU-001 Confirm Safeguarding Architecture Legal Protections and Operating Evidence, ISS-FIN-001 Confirm Finance and Tax Sources Thresholds Systems and Operating Evidence, ISS-IT-001 Confirm Odoo Compliance Automation Security Testing and Operating Evidence, ISS-TRAIN-001 Confirm Training Governance Completion Assessment and Operating Evidence, ISS-OTC-001 Review and Complete Principal OTC Service Flow Controls
- Publications: PUB-KYT-002 Crystal Intelligence Calibration and Change Record, PUB-FIN-001 Bitkaya Accounting Treatment in Odoo SOP, PUB-IT-001 Automated Compliance Monitoring Controls in Odoo SOP, PUB-TRAIN-001 Compliance Framework Onboarding for New Employees, PUB-TRAIN-002 Compliance Department Training, PUB-TRAIN-003 Front Office AML and Sanctions Training, PUB-TRAIN-004 Finance Department Compliance Training, PUB-KYT-001 Odoo Pre-Trade and Post-Trade KYT Controls SOP, PUB-OTC-001 Bitkaya Principal OTC Service Flows Memo
Assurance
- Source verified: yes
- Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
- Wording unambiguous: review
History
- 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
- 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.