Types of Policies (Client Controlled vs. BitGo Enforced)

Modified on Wed, 15 Jul at 3:50 PM

Types of Policies (Client Controlled vs. BitGo Enforced)

Policies that clients can fully create, customize, and manage as outlined above are client controlled policies

Separately there are policies enforced by BitGo to ensure the highest levels of security and regulatory compliance. These are BitGo enforced policies

Certain aspects of BitGo enforced policies may not be customizable or removable due to regulatory and security requirements. These policies include:  

  • Video identity verification policies 

  • Unverified address policies

  • FIat liveness check policies

BitGo Enforced Policies

Video Identity Verification Policies 

For custody withdrawals, after the transaction has been approved as necessary, you may need to complete additional security verifications before BitGo will complete the signing of the transaction. The two possible verification methods are (1) a video ID call with BitGo Support or (2) a Selfie Liveness Check.

If a withdrawal requires a video ID call, you will be notified on the platform and can schedule your Video ID call from there. Only pre-approved Video ID Users who have completed identity verification with BitGo's Trust team can authorize operations that require Video ID approval. To grant this permission, an Org Admin can assign the user the Video ID User role in the Roles tab of the Admin Console.

Additionally, if you'd prefer to verify a new whitelisted address via Video ID call with BitGo instead of a selfie liveness check, this can be adjusted within the Policies tab on the BitGo platform.

By default, the following verification processes will be triggered:

Action

Default Verification Method

Withdrawing to a new whitelisted address for the first time

Selfie Liveness Check

Withdrawal greater than $250,000 USD in a rolling 24-hour period

Video ID Call

These policies can be customized depending on your use case and risk appetite. This is completely optional. To implement any changes, your existing policies must first be unlocked by completing a video ID call and any other applicable approvals with BitGo support.

  • You may increase the transaction limit for video ID policies to any amount that suits your workflow

  • You may remove video ID requirements for any transaction by archiving the existing video ID policy

Unverified Address

This policy dictates what identity verification is required when sending to an unverified address. 

  • Unverified Address: an address that has been added to a wallet whitelist but you have never made any withdrawals to it. When withdrawing to that address for the first time, there is a requirement for additional verification.

  • Verified Address: once you’ve completed a verification and withdrawal for an address, all future withdrawals will not require additional verification. Note: a withdrawal may still require a Video ID if the trust velocity limit is exceeded.

The way that you verify a new address is by completing a liveness check from the user that initiated the transaction. Using the policy engine, you can change who is required to complete the selfie (wallet admin, video ID user), or you can opt in to a full Video ID verification call with BitGo, if you prefer. 

Fiat Liveness Check Policies

For fiat policy withdrawals, the following verification policies will be automatically triggered if applicable:

Action

Default Verification Method

Withdrawals exceeding $100,000 within 24 hours 

Liveness Check

Withdrawals exceeding $1,000,000 within 24 hours

Manual review by BitGo


These policies can be customized depending on your use case and risk appetite. This is completely optional. To implement any changes, your existing policies must first be unlocked by completing a video ID call and any other applicable approvals with BitGo support.

  • You may increase fiat transaction limits for a liveness check to a maximum of $1,000,000

  • This policy cannot be archived

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article