Purpose
Translate the VASP Ordinance into a testable BCMS requirement for controlled operations, operational risk management, information systems integrity and client security.
Normative
Bitkaya shall maintain controlled VASP operations and security controls that protect clients, sensitive information, payment traffic and the integrity of systems supporting regulated VASP activities.
Descriptive
The control framework should address systematic operational risk analysis, business processes, financial and other risks, recovery and resolution planning, payment traffic, compliance and risk management functions, information systems integrity, written security policy, authentication, client security credentials, access restriction and security statistics. Article 37(2)(b) is excluded from commencement and should not be treated as effective unless later brought into force.
Source reference: VASP Ordinance, Articles 36, 37 and 39; commencement instrument Publicatieblad A 2025 No. 91, Article 1.
Assurance Assertions
- Controlled operations and security policies exist for VASP services.
- Operational, security and information-system risks are assessed and controlled.
- Strong client authentication and protection of personal security credentials are implemented where applicable.
Relationships
- Source: SRC-VASP-001 Landsverordening toezicht virtuele activa dienstverleners
- Policies: POL-AML-001 AML CTF CPF Compliance Manual, POL-ECM-001 Enterprise Compliance Manual
- Processes: PRC-FCI-001 Financial Crime and Integrity, PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-AML-001 Maintain AML Risk Assessment and SARA Calibration, PROC-AML-002 Perform Client Acceptance CDD EDD and Risk Classification, PROC-AML-003 Perform Sanctions Screening and Restrictive Measures Escalation, PROC-AML-004 Perform Transaction Monitoring and Alert Review, PROC-AML-005 Perform FIU Reporting and Case Escalation, PROC-AML-006 Apply Travel Rule and Counterparty VASP Due Diligence, PROC-AML-008 Deliver AML Training and Awareness, PROC-AML-009 Perform AML Independent Review and Remediation, PROC-AML-010 Review AML Policy and Proportionality Implementation
- Controls: CTRL-ABC-001 Ensure ABC Governance and EWRA Are Maintained, CTRL-ABC-003 Ensure Gifts and Hospitality Are Approved and Recorded, CTRL-ABC-004 Ensure Sensitive Interactions Contributions and Conflicts Are Controlled, CTRL-ABC-005 Ensure ABC Books Records and Payments Are Controlled, CTRL-ABC-006 Ensure ABC Concerns Are Escalated and Investigated, CTRL-ABC-007 Ensure ABC Monitoring Training Reporting and Improvement Are Maintained, CTRL-MCT-002 Ensure Market Abuse and Personal Trading Controls Operate, CTRL-MCT-003 Ensure Best Execution and Order Handling Are Controlled, CTRL-MCT-005 Ensure Client Assets and Custody Are Safeguarded, CTRL-SAFU-003 Ensure Client Asset Movements Are Authorized and Permitted, CTRL-SAFU-005 Ensure Safeguarding Providers and Continuity Are Controlled, CTRL-SAFU-006 Ensure Custody Technology Access Keys and Recovery Are Secure, CTRL-SAFU-008 Ensure Safeguarding Breaches Resolution and Assurance Are Effective, CTRL-MCT-007 Ensure Market Conduct Surveillance Reporting and Improvement Operate, CTRL-EMP-002 Ensure Mandatory Employee Training Is Completed, CTRL-EMP-003 Ensure Employee Conduct Conflicts Assets and Data Are Controlled, CTRL-EMP-004 Ensure Whistleblower Reports Are Protected and Investigated, CTRL-EMP-007 Ensure Ethics Certification and Handbook Review Are Current, CTRL-RMF-002 Ensure Risk Assessments Are Complete and Current, CTRL-RMF-003 Ensure Controls Indicators and Remediation Are Monitored, CTRL-RMF-004 Ensure Material Risk Scenarios Are Tested, CTRL-RMF-005 Ensure New Products and Material Changes Are Approved, CTRL-RMF-006 Ensure Incidents Issues and Complaints Are Coordinated, CTRL-RMF-007 Ensure Third Party Counterparty and Resilience Risks Are Controlled, CTRL-RMF-008 Ensure Risk Data Reporting Assurance and Policy Are Governed, CTRL-RMF-009 Ensure Fraud Concerns Are Stopped Escalated and Recorded, CTRL-ICA-001 Ensure Control Governance and Assurance Independence, CTRL-ICA-002 Ensure Core Internal Control Coverage Is Complete, CTRL-ICA-003 Ensure Risk Based Internal Audits Are Independent and Complete, CTRL-ICA-004 Ensure Second Line Control Testing Is Effective, CTRL-ICA-006 Ensure Findings Are Escalated and Remediated, CTRL-ICA-007 Ensure Assurance Competence Evidence and Proportionality, CTRL-REG-004 Ensure CBCS Reporting and Notifications Are Controlled, CTRL-REG-007 Ensure Reporting Breaches Training and Proportionality Are Managed, CTRL-ESG-002 Ensure Environmental Metrics and Resource Actions Are Monitored, CTRL-ESG-003 Ensure Employee Wellbeing Inclusion and Human Rights Are Supported, CTRL-ESG-005 Ensure Ethical Conduct and Governance Standards Operate, CTRL-ESG-006 Ensure ESG Risk Is Integrated Into Material Decisions, CTRL-PRIV-001 Ensure Processing Activities Legal Bases and Privacy Risks Are Current, CTRL-PRIV-005 Ensure Personal Data Security Access and Incidents Are Controlled, CTRL-ODOO-001 Ensure Odoo Backup Strategy Responsibilities and Objectives Are Approved, CTRL-ODOO-002 Ensure Monthly Odoo External Backup Is Completed, CTRL-ODOO-003 Ensure Odoo Backup Storage Access Retention and Disposal Are Controlled, CTRL-ODOO-004 Ensure Odoo Backups Are Verified Logged and Evidenced, CTRL-ODOO-005 Ensure Odoo Backups Are Restored and Recovery Is Tested, CTRL-FIN-006 Ensure Finance Movements Reconciliations and Exceptions Are Controlled, CTRL-TRAIN-001 Ensure Training Needs Matrix and Calendar Are Complete, CTRL-TRAIN-002 Ensure Onboarding and Role Readiness Are Completed, CTRL-TRAIN-003 Ensure Recurring and Role Specific Training Is Completed, CTRL-TRAIN-004 Ensure Quarterly Awareness Activity Occurs, CTRL-TRAIN-005 Ensure Competence Is Assessed and Gaps Are Remediated
- Systems: SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-FIN-001 Odoo Accounting ERP, SYS-IT-001 Odoo Automated Compliance Monitoring
- Issues: ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration, ISS-SAFU-001 Confirm Safeguarding Architecture Legal Protections and Operating Evidence, ISS-FIN-001 Confirm Finance and Tax Sources Thresholds Systems and Operating Evidence, ISS-IT-001 Confirm Odoo Compliance Automation Security Testing and Operating Evidence, ISS-TRAIN-001 Confirm Training Governance Completion Assessment and Operating Evidence, ISS-OTC-001 Review and Complete Principal OTC Service Flow Controls
- Publications: PUB-KYT-002 Crystal Intelligence Calibration and Change Record, PUB-FIN-001 Bitkaya Accounting Treatment in Odoo SOP, PUB-IT-001 Automated Compliance Monitoring Controls in Odoo SOP, PUB-TRAIN-001 Compliance Framework Onboarding for New Employees, PUB-TRAIN-002 Compliance Department Training, PUB-TRAIN-003 Front Office AML and Sanctions Training, PUB-TRAIN-004 Finance Department Compliance Training, PUB-TRAIN-005 IT Compliance Training, PUB-KYT-001 Odoo Pre-Trade and Post-Trade KYT Controls SOP, PUB-OTC-001 Bitkaya Principal OTC Service Flows Memo
Assurance
- Source verified: yes
- Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
- Wording unambiguous: review
History
- 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
- 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.