1. Purpose and Scope

This manual establishes Bitkaya’s Business Continuity Management (BCM) framework, ensuring resilience against disruptions, protection of stakeholders, and compliance with the Centrale Bank van Curaçao en Sint Maarten’s provisions and ISO 22301 standards. It provides a comprehensive structure for preparing, responding to, and recovering from disruptive incidents.

The scope of this manual applies to:

  • All departments, units, and business lines.
  • All employees, contractors, and consultants.
  • Critical suppliers, vendors, and outsourcing partners.
  • External stakeholders including regulators, auditors, and customers.

It sets out processes for governance, business impact analysis, risk assessment, continuity strategies, sub-plans, testing, training, and continuous improvement.

2. BCM Policy Statement

The Board of Directors formally approves this BCM Policy, which defines Bitkaya’s commitment to resilience. This policy:

  • States Bitkaya’s principles of resilience, preparedness, and accountability.
  • Outlines objectives for BCM implementation, ongoing monitoring, and continuous improvement.
  • Allocates resources: financial (budget), human (staffing, training), and physical (facilities, alternate sites).
  • Establishes governance, reporting, and oversight structures to ensure effectiveness.
  • Commits to compliance with legal, regulatory, and contractual requirements.

The BCM Policy is reviewed annually and after any major disruption to ensure continued relevance.

3. Objectives

The BCM framework is guided by four primary objectives:

  1. Ensure safety of personnel and stakeholders by prioritizing human life and well-being during any disruption.
  2. Maintain and restore critical business functions within defined RTOs and RPOs, ensuring clients can access essential services.
  3. Minimize financial, legal, and reputational damage through proactive risk management and transparent communication.
  4. Ensure compliance with supervisory requirements, international standards, and contractual obligations.

4. Context and Stakeholder Analysis

Bitkaya’s BCM framework is informed by its operating context and stakeholder requirements.

External Context

  • Political and regulatory environment (local laws, CBCS provisions, FATF standards).
  • Economic and technological environment (crypto market volatility, emerging fintech).
  • Social and cultural factors influencing stakeholder trust.
  • Natural and environmental risks (storms, flooding, earthquakes).
  • Competitive pressures in global virtual asset services.

Internal Context

  • Products and services: trading platform, wallets, compliance systems.
  • Resources: IT systems, skilled personnel, financial capital.
  • Organizational structure and governance systems.
  • Dependencies on third-party vendors, banking partners, and cloud services.

Interested Parties

  • Regulators (CBCS, FATF-aligned authorities).
  • Clients and investors.
  • Employees and contractors.
  • Suppliers, IT service providers, and external partners.
  • Insurers, auditors, and emergency services.

5. Governance and Responsibilities

Board of Directors

  • Approves BCM policy, reviews plans annually, ensures resource allocation.
  • Oversees BCM audits, corrective actions, and compliance reports.

Department Heads

  • Identify critical functions, dependencies, and recovery needs.
  • Maintain departmental continuity sub-plans.
  • Ensure staff are trained and aware of BCM obligations.

Employees

  • Participate in training and drills.
  • Execute BCM responsibilities as assigned.

Audit

  • Internal and external audits are conducted annually.
  • Findings are reviewed by the Board and corrective actions are tracked.

6. Business Impact Analysis (BIA)

The Business Impact Analysis (BIA) identifies the impact of disruptions on critical functions. It defines:

  • Critical functions necessary for survival and compliance.
  • Maximum tolerable period of disruption (MTPD) for each function.
  • Recovery Time Objectives (RTOs) to restore operations.
  • Recovery Point Objectives (RPOs) to determine acceptable data loss.

The BIA is reviewed annually and after significant organizational or technological changes.

7. Risk Assessment

The BCM risk assessment process includes:

  • Identification of threats: cybersecurity attacks, natural disasters, system failures, regulatory risks, operational dependencies.
  • Single point of failure analysis: data centers, network providers, key staff expertise, supply chains.
  • Risk treatment strategies:
    • Reduction (preventive controls).
    • Transfer (insurance, outsourcing).
    • Avoidance (ceasing risky activities).
    • Acceptance (low-impact risks).

Risk assessments are conducted annually and updated when new threats or dependencies emerge.

8. Business Continuity Strategies

To mitigate disruptions, Bitkaya implements the following strategies:

  • Alternate Worksites: secondary offices and reciprocal arrangements.
  • Remote Work: VPN access, MFA, encrypted communication.
  • Data Backup & Recovery: geographically distributed backups, real-time replication for mission-critical data.
  • Supplier & Vendor Management: continuity clauses in SLAs, backup vendors identified.

9. Business Continuity Sub-Plans

  • Principal BCM Plan: outlines crisis command structure, emergency roles, call trees, directories of vendors and emergency responders, and decision-making protocols.
  • IT Disaster Recovery Plan: specifies procedures for restoring IT infrastructure, applications, and data, with annual testing.
  • Cybersecurity Recovery Plan: detailed incident playbooks for ransomware, DDoS attacks, and insider threats.
  • Building Evacuation Plan: includes routes, muster points, responsibilities, and quarterly drills.

10. Incident Response Plan

  • Activation criteria: thresholds for declaring incidents (system outage, breach, natural disaster).
  • Roles and responsibilities: defined Incident Response Team (IRT) with leads in IT, compliance, operations, and communications.
  • Escalation procedures: clear pathways from departmental level to Board-level decision-making.
  • Regulatory obligations: immediate notification to CBCS in line with local requirements.

11. Communication Protocols

  • Spokesperson: designated Communications Officer.
  • Internal communication: secure chat, call trees, SMS alerts, email groups.
  • External communication: customer notifications, regulator reporting, media updates.
  • Alternate modes: satellite phones, handheld radios, WhatsApp/Teams groups.
  • Testing: communication call-trees updated and tested quarterly.

12. Training, Awareness, and Resource Allocation

  • Training: annual BCM training sessions, tabletop drills, phishing awareness, simulation exercises.
  • Awareness: posters, intranet campaigns, newsletters.
  • Resource allocation: annual budget includes BCM training, alternate sites, emergency communication systems, and insurance premiums.

13. Testing and Exercises

  • Quarterly tabletop tests of critical scenarios.
  • Semi-annual data recovery drills for IT systems.
  • Annual full-scale IT disaster recovery test.
  • Biennial organization-wide simulation to test end-to-end resilience.

Test results are documented, reviewed by the Board, and corrective measures tracked. Serious deficiencies are re-tested.

14. Maintenance, Review, and Audit

  • Periodic reviews triggered by system changes, new regulations, mergers, relocations, or major incidents.
  • Annual Board Review of updated BCM plans.
  • Audit: annual independent internal and external BCM audits, with findings documented and actions followed up.

15. Documentation and Records

Bitkaya maintains the following records:

  • BCM policy, plans, and sub-plans.
  • Training attendance, awareness programs, and materials.
  • Test scripts, schedules, results, and corrective action plans.
  • Incident reports, severity ratings, root cause analyses, and regulatory reports.

All records are securely stored and retained for regulator and auditor review.

16. Proportionality Implementation

16.1 Purpose

This chapter establishes how the principle of proportionality is applied to Bitkaya’s Business Continuity Management (BCM) framework, ensuring that the scope, depth, and complexity of BCM measures remain appropriate for a small, growing Virtual Asset Service Provider (VASP). Proportionality ensures that controls, resources, and recovery strategies are scaled to the company’s size, nature, risk profile, and operational maturity while maintaining compliance with CBCS standards.

16.2 Principles of Proportionality

Bitkaya adopts a risk-based approach to business continuity, ensuring all measures are commensurate with the scale of operations and the potential impact of disruptions. Proportionality is implemented through:

  1. Right-Sized Controls – BCM strategies, recovery objectives, and alternate site provisions are scaled to critical business functions rather than blanket coverage across all operations.
  2. Resource Efficiency – Personnel, financial, and technological resources allocated to continuity planning are proportionate to identified critical activities and potential risk exposure.
  3. Regulatory Alignment – Compliance measures follow CBCS guidelines, FATF expectations, and international best practices appropriate for small and medium VASPs.
  4. Progressive Maturity – Controls evolve in line with organizational growth, new products, and technological adoption.

16.3 Scalability and Continuous Improvement

As Bitkaya grows, BCM provisions are designed to scale dynamically without requiring a full redesign of the framework. Scalability is achieved through:

  • Modular BCM Components – Each sub-plan (e.g., IT Disaster Recovery, Cybersecurity Response) can be independently updated as new services or vendors are added.
  • Cloud-Based Infrastructure – Use of scalable, cloud-hosted environments allows expansion of data backup and redundancy capabilities as transaction volumes increase.
  • Vendor and Partner Reviews – Vendor continuity clauses and SLAs are re-evaluated annually to ensure that partners’ capacity aligns with Bitkaya’s evolving scale.
  • Gradual Automation – As resources permit, manual continuity procedures will be progressively replaced with automated monitoring, alerting, and failover systems.

16.4 Proportional Application in BCM Components

BCM ComponentProportionality Measure for Small VASP
Governance & OversightA single BCM Officer reports to the Board instead of a dedicated BCM department.
Risk & Impact AssessmentsConducted annually using simplified risk scoring and prioritization matrices.
Continuity StrategiesFocused on remote operations, third-party backups, and data recovery rather than physical relocation.
Testing & DrillsScaled to simulate only the most critical systems and business processes.
Training & AwarenessConducted annually and supplemented with targeted refreshers for high-risk roles.
Documentation & RecordsCentralized digital repository; streamlined templates for plans and reports.

16.5 Review and Adaptation

Bitkaya will re-assess proportionality annually as part of the Compliance Review and Audit cycle, or whenever there is:

  • Significant operational growth or new service introduction,
  • Expansion into new jurisdictions or regulatory regimes,
  • Changes in technology architecture or outsourcing arrangements.

Adjustments to proportionality ensure that the BCM remains fit-for-purpose, cost-effective, and responsive to organizational evolution.

Bitkaya’s proportionality framework ensures that:

  • The BCM system remains practical, adaptable, and scalable.
  • Controls are tailored to real operational risks rather than excessive or minimal.
  • Growth and innovation occur without compromising resilience or compliance.

As Bitkaya transitions from startup to maturity, proportionality justifications will be recalibrated to reflect increased complexity and expectations. Continuous learning from audits, stress tests, and CBCS supervisory feedback will inform revisions, ensuring that proportionality remains both compliant and operationally sound.

Operating Layer

This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-BCM-* procedures and CTRL-BCM-* controls.

It specializes the continuity requirements in POL-IT-001 IT and Cybersecurity Manual and coordinates supplier continuity with POL-OUT-001 Outsourcing Risk Management Manual.

Implementing Procedures and Controls

Procedures

Controls

Source Document

  • Document title: Bitkaya Business Continuity Manual
  • Version: 1.0
  • Status in source document: FINAL
  • Date shown in source document: October 2025
  • Approver shown in change log: Board
  • Exact BCMS approval and effective date: 2026-04-16, taken from the approved PDF metadata because the visible document states only October 2025
  • Permanent approved artifact: Bitkaya Business Continuity Manual v10 Approved.pdf

Assurance

  • Design status: implemented from approved Business Continuity Manual version 1.0
  • Operating status: implemented
  • Evidence status: operating evidence is retained through linked systems and control records
  • Review cadence: annual and after material change, disruption or failed exercise

History

  • 2026-07-26: Registered the approved Business Continuity Manual and established its operating process, procedures and controls.
  • 2026-07-28: Enriched policy body to full 100% PDF coverage — every section, paragraph, and proportionality table from Business Continuity Manual version 1.0.