Purpose
Translate the VASP Ordinance into a testable BCMS requirement for cooperation with CBCS supervision, expert reviews, supervisory costs and enforcement measures.
Normative
Bitkaya shall cooperate with CBCS supervision, provide requested information and access, support expert reviews, pay required supervisory costs and comply with lawful supervisory or enforcement measures.
Descriptive
The supervisory-cooperation framework should address CBCS information requests, inspection access, books and records, copies, on-site examination, use of external experts, expert reports, appointment of experts at CBCS request, supervisory cost assessments, instructions, orders, penalty or administrative fine processes, curator arrangements and preservation of confidentiality duties.
Source reference: VASP Ordinance, Articles 68 through 80, 81 through 127 and 129 through 130; commencement instrument Publicatieblad A 2025 No. 91, Article 1.
Assurance Assertions
- CBCS requests, inspections and supervisory actions are logged and assigned.
- Required information, access and expert cooperation are provided within required timelines.
- Enforcement, penalty, cost and confidentiality obligations are escalated and tracked.
Relationships
- Source: SRC-VASP-001 Landsverordening toezicht virtuele activa dienstverleners
- Policies: POL-AML-001 AML CTF CPF Compliance Manual, POL-ECM-001 Enterprise Compliance Manual
- Processes: PRC-FCI-001 Financial Crime and Integrity, PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery
- Procedures: PROC-AML-001 Maintain AML Risk Assessment and SARA Calibration, PROC-AML-004 Perform Transaction Monitoring and Alert Review, PROC-AML-005 Perform FIU Reporting and Case Escalation, PROC-AML-006 Apply Travel Rule and Counterparty VASP Due Diligence, PROC-AML-007 Maintain AML Records and Data Retention, PROC-AML-009 Perform AML Independent Review and Remediation, PROC-AML-010 Review AML Policy and Proportionality Implementation
- Controls: CTRL-ABC-006 Ensure ABC Concerns Are Escalated and Investigated, CTRL-ABC-007 Ensure ABC Monitoring Training Reporting and Improvement Are Maintained, CTRL-MCT-001 Ensure Market Conduct Governance Permissions and Risk Are Current, CTRL-MCT-004 Ensure Market Communications Are Accurate and Approved, CTRL-MCT-006 Ensure Market Conduct Complaints Are Handled Fairly, CTRL-MCT-007 Ensure Market Conduct Surveillance Reporting and Improvement Operate, CTRL-EMP-004 Ensure Whistleblower Reports Are Protected and Investigated, CTRL-EMP-005 Ensure Employee Violations Receive Consistent Disciplinary Action, CTRL-EMP-006 Ensure Employees Cooperate With Reviews and Audits, CTRL-EMP-007 Ensure Ethics Certification and Handbook Review Are Current, CTRL-RMF-001 Ensure Risk Governance Appetite and Taxonomy Are Current, CTRL-RMF-003 Ensure Controls Indicators and Remediation Are Monitored, CTRL-RMF-004 Ensure Material Risk Scenarios Are Tested, CTRL-RMF-006 Ensure Incidents Issues and Complaints Are Coordinated, CTRL-RMF-007 Ensure Third Party Counterparty and Resilience Risks Are Controlled, CTRL-RMF-008 Ensure Risk Data Reporting Assurance and Policy Are Governed, CTRL-RMF-009 Ensure Fraud Concerns Are Stopped Escalated and Recorded, CTRL-ICA-003 Ensure Risk Based Internal Audits Are Independent and Complete, CTRL-ICA-004 Ensure Second Line Control Testing Is Effective, CTRL-ICA-005 Ensure External and Regulatory Audits Are Supported, CTRL-ICA-006 Ensure Findings Are Escalated and Remediated, CTRL-ICA-007 Ensure Assurance Competence Evidence and Proportionality, CTRL-REG-001 Ensure Regulatory Obligations and Calendar Are Current, CTRL-REG-002 Ensure Regulatory Submissions Are Complete Accurate and Timely, CTRL-REG-003 Ensure FIU and Sanctions Reporting Is Complete and Confidential, CTRL-REG-004 Ensure CBCS Reporting and Notifications Are Controlled, CTRL-REG-005 Ensure Tax and Audited Financial Reports Are Timely, CTRL-REG-006 Ensure Regulatory Communications and Records Are Traceable, CTRL-REG-007 Ensure Reporting Breaches Training and Proportionality Are Managed, CTRL-ESG-001 Ensure ESG Governance Strategy and Oversight Are Current, CTRL-ESG-005 Ensure Ethical Conduct and Governance Standards Operate, CTRL-ESG-006 Ensure ESG Risk Is Integrated Into Material Decisions, CTRL-ESG-007 Ensure ESG Reporting Proportionality and Improvement Are Current, CTRL-PRIV-001 Ensure Processing Activities Legal Bases and Privacy Risks Are Current, CTRL-PRIV-005 Ensure Personal Data Security Access and Incidents Are Controlled, CTRL-PRIV-006 Ensure AML Sanctions and Regulatory Data Remain Confidential, CTRL-PRIV-007 Ensure Privacy Governance Training and Proportionality Are Reviewed, CTRL-ODOO-004 Ensure Odoo Backups Are Verified Logged and Evidenced, CTRL-ODOO-006 Ensure Backup Exceptions Dependencies and Changes Are Reviewed, CTRL-COMP-006 Ensure Complaint Escalations and External Cooperation Are Controlled, CTRL-COMP-007 Ensure Complaint Trends Reporting Training and Improvement Are Maintained, CTRL-COMM-001 Ensure Communication Standards and Approved Wording Are Current, CTRL-COMM-005 Ensure External Communications Are Approved Versioned and Retained, CTRL-COMM-006 Ensure Communications Are Monitored and Breaches Corrected, CTRL-SAFU-001 Ensure Safeguarding Governance Training and Proportionality Are Maintained, CTRL-SAFU-007 Ensure Safeguarding Terms and Client Communications Are Accurate, CTRL-SAFU-008 Ensure Safeguarding Breaches Resolution and Assurance Are Effective, CTRL-FIN-001 Ensure Finance Tax Governance Calendar and Proportionality Are Current, CTRL-FIN-003 Ensure Annual Financial Statements Are Approved Reviewed Submitted and Published, CTRL-FIN-004 Ensure CIT and TOT Are Calculated Filed and Paid on Time, CTRL-FIN-005 Ensure Payroll Social Security and Withholding Obligations Are Met, CTRL-FIN-007 Ensure Authority Requests Reporting Assurance and Remediation Are Managed, CTRL-TRAIN-006 Ensure Training Records Reporting and Improvement Are Maintained
- Systems: SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-FIN-001 Odoo Accounting ERP, SYS-IT-001 Odoo Automated Compliance Monitoring
- Issues: ISS-KYT-001 Approve and Validate Crystal Intelligence Calibration, ISS-COMP-001 Confirm Complaints Channels Register and CBCS Source, ISS-COMM-001 Confirm Licensing Claims Approval Workflow and Operating Evidence, ISS-SAFU-001 Confirm Safeguarding Architecture Legal Protections and Operating Evidence, ISS-FIN-001 Confirm Finance and Tax Sources Thresholds Systems and Operating Evidence, ISS-IT-001 Confirm Odoo Compliance Automation Security Testing and Operating Evidence, ISS-TRAIN-001 Confirm Training Governance Completion Assessment and Operating Evidence, ISS-OTC-001 Review and Complete Principal OTC Service Flow Controls
- Publications: PUB-KYT-002 Crystal Intelligence Calibration and Change Record, PUB-FIN-001 Bitkaya Accounting Treatment in Odoo SOP, PUB-IT-001 Automated Compliance Monitoring Controls in Odoo SOP, PUB-TRAIN-002 Compliance Department Training, PUB-TRAIN-004 Finance Department Compliance Training, PUB-TRAIN-005 IT Compliance Training, PUB-KYT-001 Odoo Pre-Trade and Post-Trade KYT Controls SOP, PUB-OTC-001 Bitkaya Principal OTC Service Flows Memo
Assurance
- Source verified: yes
- Implementation linked: partial; mapped to current BCMS implementation objects while detailed VASP coverage remains planned
- Wording unambiguous: review
History
- 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
- 2026-07-26: Added policy, process and procedure mappings; detailed VASP implementation remains planned.