Purpose

Translate the VASP Ordinance into a testable BCMS requirement for controlled operations, operational risk management, information systems integrity and client security.

Normative

Bitkaya shall maintain controlled VASP operations and security controls that protect clients, sensitive information, payment traffic and the integrity of systems supporting regulated VASP activities.

Descriptive

The control framework should address systematic operational risk analysis, business processes, financial and other risks, recovery and resolution planning, payment traffic, compliance and risk management functions, information systems integrity, written security policy, authentication, client security credentials, access restriction and security statistics. Article 37(2)(b) is excluded from commencement and should not be treated as effective unless later brought into force.

Source reference: VASP Ordinance, Articles 36, 37 and 39; commencement instrument Publicatieblad A 2025 No. 91, Article 1.

Assurance Assertions

  • Controlled operations and security policies exist for VASP services.
  • Operational, security and information-system risks are assessed and controlled.
  • Strong client authentication and protection of personal security credentials are implemented where applicable.

Relationships

Assurance

  • Source verified: yes
  • Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
  • Wording unambiguous: review

History

  • 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
  • 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.