Purpose

Register Crystal Intelligence as the restricted blockchain-analytics system used for Bitkaya’s internal VASP wallet and virtual-asset transaction screening.

Description

Crystal Intelligence provides wallet and transaction attribution, counterparty risk scores, risky-entity connections and material-exposure alerts. Compliance uses the output as a decision trigger within the approved AML, sanctions, KYT and escalation procedures. A Crystal alert is not by itself a finding of illicit activity, a client rejection decision or an FIU reporting decision.

Crystal is separate from AMLBot under ADR-002 Separate Crystal and AMLBot Use. Crystal supports regulated internal VASP screening; AMLBot supports the separate external Treasury Monitoring service.

Responsibilities

  • Compliance owns the risk appetite, alert treatment, investigation criteria, calibration approval and periodic effectiveness review.
  • Technology administers access, configuration, availability, change execution, logging, backup and vendor support, subject to confirmation of the named administrator.
  • Operations records complete transaction and wallet inputs and must not treat PROCESSING, REVIEW, HIGH or SEVERE results as clearance.
  • The MLRO or authorized Compliance delegate retains suspicion assessment and FIU reporting authority.
  • Independent assurance tests configuration, population completeness, alert disposition and change evidence.

Runtime

  • Platform: Crystal Intelligence blockchain analytics.
  • Environment: Operational use is stated in the calibration reports; the production tenant and environment identifier have not been independently inspected.
  • Profile: Bitkaya - KYT Default.
  • Code repository: Vendor-managed service; Bitkaya configuration exports must be retained in an approved restricted evidence location.
  • Approved version: Not evidenced.
  • Deployed version: Not evidenced.
  • Last verification: 2026-07-26, document and artifact review only.
  • Current configuration baseline: Not established. The 2026-07-13 report describes a proposed change and does not evidence approval or production deployment.

Functional Scope

  • Wallet and virtual-asset transaction screening.
  • Counterparty Risk Score alerts for deposits and withdrawals.
  • Counterparty Connection rules for attributed risky entities.
  • Risky Amount rules based on exposure relative to transaction value.
  • Direct blocklist, sanctions and terrorism-financing escalation.
  • Review support for remote, historical, repeated, recent and material exposure.
  • Evidence supporting hold, escalation, disposition and possible reporting decisions.

Configuration Governance

  1. Maintain a dated export or controlled screenshots of the complete pre-change configuration.
  2. Document the risk rationale, expected effect, affected categories, distances, thresholds and alert grades.
  3. Obtain Compliance and Managing Director approval before production deployment.
  4. Test positive, negative, boundary, unavailable-service, duplicate and regression scenarios before release.
  5. Record the deployment date, implementer, reviewer and post-change configuration export.
  6. Reconcile alerts and dispositions after change, including cases closed as immaterial and material exposure not captured automatically.
  7. Perform the 30-day or other approved post-implementation review and document any further calibration.
  8. Preserve every superseded baseline and decision record; do not overwrite configuration history.

Dependencies

  • Complete customer, wallet, asset, network, direction, amount and transaction-hash data.
  • Approved Odoo pre-trade and post-trade KYT integration and exception handling.
  • Vendor availability, attribution quality, supported networks and current risky-entity data.
  • Restricted alert, investigation, escalation and disposition records.
  • Change, access, incident, retention, continuity and independent-testing controls.

Data and Security

Crystal processes restricted wallet addresses, transaction hashes, attribution, risk scores, alert results and potentially client-linked investigation data. Access must be least-privilege and periodically reviewed. Credentials, API keys and raw client evidence must not be stored in BCMS. Configuration exports and operating evidence must be retained in an approved restricted repository with an auditable reference.

Boundaries

  • Thresholds do not replace case-specific professional judgment or mandatory sanctions, legal, AML, KYC and FIU requirements.
  • Falling below a percentage threshold is not automatic acceptance where direct exposure, repeated activity, recent high-risk flow, adverse intelligence or client inconsistency exists.
  • Management must not override a mandatory sanctions restriction, AML escalation, legal hold or MLRO/FIU decision.
  • The reports do not evidence the complete deployed configuration, user-access design, supported-network coverage, integration logic or operating effectiveness.

Relationships

Assurance

  • System existence and operational use supported by the supplied reports: yes.
  • Current approved production baseline evidenced: no.
  • Approval and deployment evidence evidenced: no.
  • Post-change test and 30-day validation evidenced: no.
  • Access and integration independently inspected: no.
  • Overall status: current system registered for review; operating effectiveness not assessed.

History

  • 2026-07-26: Added reciprocal procedure and control evidence relationships for Hermes handover.
  • 2026-07-26: Registered Crystal Intelligence from the 5 July, 7 July and 13 July 2026 calibration records.