1. Purpose and Scope
This manual establishes Bitkaya’s Business Continuity Management (BCM) framework, ensuring resilience against disruptions, protection of stakeholders, and compliance with the Centrale Bank van Curaçao en Sint Maarten’s provisions and ISO 22301 standards. It provides a comprehensive structure for preparing, responding to, and recovering from disruptive incidents.
The scope of this manual applies to:
- All departments, units, and business lines.
- All employees, contractors, and consultants.
- Critical suppliers, vendors, and outsourcing partners.
- External stakeholders including regulators, auditors, and customers.
It sets out processes for governance, business impact analysis, risk assessment, continuity strategies, sub-plans, testing, training, and continuous improvement.
2. BCM Policy Statement
The Board of Directors formally approves this BCM Policy, which defines Bitkaya’s commitment to resilience. This policy:
- States Bitkaya’s principles of resilience, preparedness, and accountability.
- Outlines objectives for BCM implementation, ongoing monitoring, and continuous improvement.
- Allocates resources: financial (budget), human (staffing, training), and physical (facilities, alternate sites).
- Establishes governance, reporting, and oversight structures to ensure effectiveness.
- Commits to compliance with legal, regulatory, and contractual requirements.
The BCM Policy is reviewed annually and after any major disruption to ensure continued relevance.
3. Objectives
The BCM framework is guided by four primary objectives:
- Ensure safety of personnel and stakeholders by prioritizing human life and well-being during any disruption.
- Maintain and restore critical business functions within defined RTOs and RPOs, ensuring clients can access essential services.
- Minimize financial, legal, and reputational damage through proactive risk management and transparent communication.
- Ensure compliance with supervisory requirements, international standards, and contractual obligations.
4. Context and Stakeholder Analysis
Bitkaya’s BCM framework is informed by its operating context and stakeholder requirements.
External Context
- Political and regulatory environment (local laws, CBCS provisions, FATF standards).
- Economic and technological environment (crypto market volatility, emerging fintech).
- Social and cultural factors influencing stakeholder trust.
- Natural and environmental risks (storms, flooding, earthquakes).
- Competitive pressures in global virtual asset services.
Internal Context
- Products and services: trading platform, wallets, compliance systems.
- Resources: IT systems, skilled personnel, financial capital.
- Organizational structure and governance systems.
- Dependencies on third-party vendors, banking partners, and cloud services.
Interested Parties
- Regulators (CBCS, FATF-aligned authorities).
- Clients and investors.
- Employees and contractors.
- Suppliers, IT service providers, and external partners.
- Insurers, auditors, and emergency services.
5. Governance and Responsibilities
Board of Directors
- Approves BCM policy, reviews plans annually, ensures resource allocation.
- Oversees BCM audits, corrective actions, and compliance reports.
Department Heads
- Identify critical functions, dependencies, and recovery needs.
- Maintain departmental continuity sub-plans.
- Ensure staff are trained and aware of BCM obligations.
Employees
- Participate in training and drills.
- Execute BCM responsibilities as assigned.
Audit
- Internal and external audits are conducted annually.
- Findings are reviewed by the Board and corrective actions are tracked.
6. Business Impact Analysis (BIA)
The Business Impact Analysis (BIA) identifies the impact of disruptions on critical functions. It defines:
- Critical functions necessary for survival and compliance.
- Maximum tolerable period of disruption (MTPD) for each function.
- Recovery Time Objectives (RTOs) to restore operations.
- Recovery Point Objectives (RPOs) to determine acceptable data loss.
The BIA is reviewed annually and after significant organizational or technological changes.
7. Risk Assessment
The BCM risk assessment process includes:
- Identification of threats: cybersecurity attacks, natural disasters, system failures, regulatory risks, operational dependencies.
- Single point of failure analysis: data centers, network providers, key staff expertise, supply chains.
- Risk treatment strategies:
- Reduction (preventive controls).
- Transfer (insurance, outsourcing).
- Avoidance (ceasing risky activities).
- Acceptance (low-impact risks).
Risk assessments are conducted annually and updated when new threats or dependencies emerge.
8. Business Continuity Strategies
To mitigate disruptions, Bitkaya implements the following strategies:
- Alternate Worksites: secondary offices and reciprocal arrangements.
- Remote Work: VPN access, MFA, encrypted communication.
- Data Backup & Recovery: geographically distributed backups, real-time replication for mission-critical data.
- Supplier & Vendor Management: continuity clauses in SLAs, backup vendors identified.
9. Business Continuity Sub-Plans
- Principal BCM Plan: outlines crisis command structure, emergency roles, call trees, directories of vendors and emergency responders, and decision-making protocols.
- IT Disaster Recovery Plan: specifies procedures for restoring IT infrastructure, applications, and data, with annual testing.
- Cybersecurity Recovery Plan: detailed incident playbooks for ransomware, DDoS attacks, and insider threats.
- Building Evacuation Plan: includes routes, muster points, responsibilities, and quarterly drills.
10. Incident Response Plan
- Activation criteria: thresholds for declaring incidents (system outage, breach, natural disaster).
- Roles and responsibilities: defined Incident Response Team (IRT) with leads in IT, compliance, operations, and communications.
- Escalation procedures: clear pathways from departmental level to Board-level decision-making.
- Regulatory obligations: immediate notification to CBCS in line with local requirements.
11. Communication Protocols
- Spokesperson: designated Communications Officer.
- Internal communication: secure chat, call trees, SMS alerts, email groups.
- External communication: customer notifications, regulator reporting, media updates.
- Alternate modes: satellite phones, handheld radios, WhatsApp/Teams groups.
- Testing: communication call-trees updated and tested quarterly.
12. Training, Awareness, and Resource Allocation
- Training: annual BCM training sessions, tabletop drills, phishing awareness, simulation exercises.
- Awareness: posters, intranet campaigns, newsletters.
- Resource allocation: annual budget includes BCM training, alternate sites, emergency communication systems, and insurance premiums.
13. Testing and Exercises
- Quarterly tabletop tests of critical scenarios.
- Semi-annual data recovery drills for IT systems.
- Annual full-scale IT disaster recovery test.
- Biennial organization-wide simulation to test end-to-end resilience.
Test results are documented, reviewed by the Board, and corrective measures tracked. Serious deficiencies are re-tested.
14. Maintenance, Review, and Audit
- Periodic reviews triggered by system changes, new regulations, mergers, relocations, or major incidents.
- Annual Board Review of updated BCM plans.
- Audit: annual independent internal and external BCM audits, with findings documented and actions followed up.
15. Documentation and Records
Bitkaya maintains the following records:
- BCM policy, plans, and sub-plans.
- Training attendance, awareness programs, and materials.
- Test scripts, schedules, results, and corrective action plans.
- Incident reports, severity ratings, root cause analyses, and regulatory reports.
All records are securely stored and retained for regulator and auditor review.
16. Proportionality Implementation
16.1 Purpose
This chapter establishes how the principle of proportionality is applied to Bitkaya’s Business Continuity Management (BCM) framework, ensuring that the scope, depth, and complexity of BCM measures remain appropriate for a small, growing Virtual Asset Service Provider (VASP). Proportionality ensures that controls, resources, and recovery strategies are scaled to the company’s size, nature, risk profile, and operational maturity while maintaining compliance with CBCS standards.
16.2 Principles of Proportionality
Bitkaya adopts a risk-based approach to business continuity, ensuring all measures are commensurate with the scale of operations and the potential impact of disruptions. Proportionality is implemented through:
- Right-Sized Controls – BCM strategies, recovery objectives, and alternate site provisions are scaled to critical business functions rather than blanket coverage across all operations.
- Resource Efficiency – Personnel, financial, and technological resources allocated to continuity planning are proportionate to identified critical activities and potential risk exposure.
- Regulatory Alignment – Compliance measures follow CBCS guidelines, FATF expectations, and international best practices appropriate for small and medium VASPs.
- Progressive Maturity – Controls evolve in line with organizational growth, new products, and technological adoption.
16.3 Scalability and Continuous Improvement
As Bitkaya grows, BCM provisions are designed to scale dynamically without requiring a full redesign of the framework. Scalability is achieved through:
- Modular BCM Components – Each sub-plan (e.g., IT Disaster Recovery, Cybersecurity Response) can be independently updated as new services or vendors are added.
- Cloud-Based Infrastructure – Use of scalable, cloud-hosted environments allows expansion of data backup and redundancy capabilities as transaction volumes increase.
- Vendor and Partner Reviews – Vendor continuity clauses and SLAs are re-evaluated annually to ensure that partners’ capacity aligns with Bitkaya’s evolving scale.
- Gradual Automation – As resources permit, manual continuity procedures will be progressively replaced with automated monitoring, alerting, and failover systems.
16.4 Proportional Application in BCM Components
| BCM Component | Proportionality Measure for Small VASP |
|---|---|
| Governance & Oversight | A single BCM Officer reports to the Board instead of a dedicated BCM department. |
| Risk & Impact Assessments | Conducted annually using simplified risk scoring and prioritization matrices. |
| Continuity Strategies | Focused on remote operations, third-party backups, and data recovery rather than physical relocation. |
| Testing & Drills | Scaled to simulate only the most critical systems and business processes. |
| Training & Awareness | Conducted annually and supplemented with targeted refreshers for high-risk roles. |
| Documentation & Records | Centralized digital repository; streamlined templates for plans and reports. |
16.5 Review and Adaptation
Bitkaya will re-assess proportionality annually as part of the Compliance Review and Audit cycle, or whenever there is:
- Significant operational growth or new service introduction,
- Expansion into new jurisdictions or regulatory regimes,
- Changes in technology architecture or outsourcing arrangements.
Adjustments to proportionality ensure that the BCM remains fit-for-purpose, cost-effective, and responsive to organizational evolution.
Bitkaya’s proportionality framework ensures that:
- The BCM system remains practical, adaptable, and scalable.
- Controls are tailored to real operational risks rather than excessive or minimal.
- Growth and innovation occur without compromising resilience or compliance.
As Bitkaya transitions from startup to maturity, proportionality justifications will be recalibrated to reflect increased complexity and expectations. Continuous learning from audits, stress tests, and CBCS supervisory feedback will inform revisions, ensuring that proportionality remains both compliant and operationally sound.
Operating Layer
This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-BCM-* procedures and CTRL-BCM-* controls.
It specializes the continuity requirements in POL-IT-001 IT and Cybersecurity Manual and coordinates supplier continuity with POL-OUT-001 Outsourcing Risk Management Manual.
Implementing Procedures and Controls
Procedures
- PROC-BCM-001 Govern BCM Context Responsibilities and Resources
- PROC-BCM-002 Perform Business Impact Analysis and Set Recovery Objectives
- PROC-BCM-003 Assess Continuity Risks and Treatment
- PROC-BCM-004 Develop and Maintain Continuity Strategies and Sub-Plans
- PROC-BCM-005 Activate Incident Response and Communications
- PROC-BCM-006 Train and Exercise Business Continuity
- PROC-BCM-007 Review Audit and Improve BCM
Controls
- CTRL-BCM-001 Ensure BCM Governance Responsibilities and Resources Are Maintained
- CTRL-BCM-002 Ensure BIA and Recovery Objectives Are Current
- CTRL-BCM-003 Ensure Continuity Risks and Treatments Are Current
- CTRL-BCM-004 Ensure Continuity Strategies and Sub-Plans Are Maintained
- CTRL-BCM-005 Ensure Incident Response and Communications Are Activated and Tested
- CTRL-BCM-006 Ensure BCM Training and Exercises Are Completed
- CTRL-BCM-007 Ensure BCM Review Audit Records and Improvements Are Maintained
Source Document
- Document title: Bitkaya Business Continuity Manual
- Version: 1.0
- Status in source document: FINAL
- Date shown in source document: October 2025
- Approver shown in change log: Board
- Exact BCMS approval and effective date: 2026-04-16, taken from the approved PDF metadata because the visible document states only October 2025
- Permanent approved artifact: Bitkaya Business Continuity Manual v10 Approved.pdf
Assurance
- Design status: implemented from approved Business Continuity Manual version 1.0
- Operating status: implemented
- Evidence status: operating evidence is retained through linked systems and control records
- Review cadence: annual and after material change, disruption or failed exercise
History
- 2026-07-26: Registered the approved Business Continuity Manual and established its operating process, procedures and controls.
- 2026-07-28: Enriched policy body to full 100% PDF coverage — every section, paragraph, and proportionality table from Business Continuity Manual version 1.0.