Purpose
Represent Bitkaya’s approved IT and Cybersecurity Manual as the BCMS policy object governing technology, cyber, resilience and software-change controls.
This manual provides a unified IT and cybersecurity governance framework that safeguards digital assets, client data, and regulatory control systems through secure, auditable, and resilient technology practices.
Policy Statement
Bitkaya shall maintain a risk-based IT and cybersecurity framework that protects its systems, customer data, compliance tooling and critical technology services and that supports secure, auditable and resilient operations.
The framework must address governance and oversight, information security management, IT and cyber risk management, software testing and quality assurance, IT service management, safe and sound electronic banking, business continuity, framework integration, training, continuous improvement and proportionality.
Scope
This policy applies to all systems, infrastructure, applications, tools, employees, contractors and third parties supporting Bitkaya’s operations as a virtual asset service provider.
It governs:
- information security, access control, and system resilience;
- security of client asset and custody-related systems;
- continuity of critical business and compliance systems;
- secure operation of onboarding, sanctions screening, transaction monitoring, case-management, and regulatory reporting tooling; and
- protection of customer, employee, transaction, and compliance-sensitive data.
Roles
- Board of Directors: Retains ultimate accountability for ensuring that proportional implementation upholds regulatory standards while remaining suitable for the company’s current operational size.
- IT Steering Committee: Reviews proportionality justifications to ensure critical risks (cyber, operational, AML/CFT) are fully mitigated.
- Management and Technology: Implement the framework and maintain the control environment. Strategic IT decisions are made at the executive level, with oversight by the Board.
- Compliance and Risk function: Coordinates regulatory alignment and cross-manual consistency. Management and staff implement and monitor proportional controls under the oversight of the Compliance and Risk function.
- Internal or Independent Audit: Confirms that proportionality measures are appropriate and do not introduce unacceptable residual risks.
1 Purpose and Scope
This manual applies to all systems, infrastructure, applications, tools, employees, contractors, and third parties supporting Bitkaya’s operations as a Virtual Asset Service Provider.
The purpose of this manual is to provide a unified IT and cybersecurity governance framework that safeguards digital assets, client data, and regulatory control systems through secure, auditable, and resilient technology practices.
2 Governance and Oversight
Bitkaya’s IT and cybersecurity governance must support not only platform security and operational resilience, but also the integrity of regulatory and compliance control systems.
Governance oversight therefore includes systems and tools used for:
- digital onboarding and identity verification;
- sanctions screening;
- blockchain analytics and transaction monitoring;
- internal case management and escalation;
- regulatory reporting support; and
- secure storage of due diligence, screening, and escalation records.
Changes to critical compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities must be subject to appropriate governance, testing, approval, and documentation controls.
3 Information Security Management (ISM)
Bitkaya applies information security controls to all critical business and control systems, including platforms and tools used for client onboarding, sanctions screening, transaction monitoring, compliance case handling, and regulatory support.
Security controls must ensure:
- confidentiality of client and compliance-sensitive data;
- integrity of screening and monitoring outputs;
- secure authentication and access management;
- protection against unauthorized alteration of rules, settings, or workflows;
- logging and traceability of system use and key actions; and
- resilience against cyber threats and operational misuse.
Because compliance systems may contain screening results, internal classifications, escalation notes, UTR-related materials, and legally sensitive information, access must be tightly controlled and logged.
4 Risk Management of IT and Cyber Threats
Bitkaya’s IT and cyber risk management includes risks arising from compromise, failure, misuse, misconfiguration, or poor governance of systems that support AML/CTF/CPF, sanctions, onboarding, case handling, and regulatory reporting.
Relevant risks include:
- unauthorized access to onboarding, screening, or monitoring systems;
- improper changes to screening logic, alert settings, or workflow rules;
- loss or corruption of client due diligence, sanctions, or case data;
- failure of list refresh or screening integrations;
- insufficient logging of critical user activity;
- exposure of compliance-sensitive documents or records;
- over-reliance on third-party tooling without appropriate validation; and
- operational disruption affecting compliance control execution.
Controls must be proportionate to the materiality of the system and should include strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery measures.
5 Software Testing and Quality Assurance
Testing must cover not only business functionality and security, but also the reliable operation of key compliance and control systems.
Where relevant, testing should verify:
- correct onboarding workflow behaviour;
- integrity of identity verification integrations;
- accurate sanctions screening and list refresh behaviour;
- correct alert generation and routing;
- case-management traceability and workflow integrity;
- preservation of logs and audit trails;
- correct access restrictions and role permissions; and
- resilience of critical compliance-related interfaces and data flows.
Changes to compliance-related tools, rules, workflows, integrations, or critical system settings must be tested before release, and approvals must be documented.
Bitkaya targets TMMi (Test Maturity Model Integration) Level 2 compliance as indicated in Centrale Bank van Curaçao en Sint Maarten (CBCS) “Provisions and Guidelines for Software Testing” (2024).
6 IT Service Management (ITSM)
Critical IT services include not only custody, wallet, and trading infrastructure, but also compliance-related systems supporting onboarding, sanctions screening, transaction monitoring, internal case handling, and regulatory support.
Incidents affecting these services must be logged centrally and assessed for operational, security, compliance, and regulatory impact.
Change management must apply to material updates involving:
- compliance system configuration;
- screening tools or list sources;
- monitoring logic or rule tuning;
- case-management workflow changes;
- access rights to sensitive compliance systems; and
- integrations that affect alerting, screening, or documentation.
Where an incident or change could impair Bitkaya’s ability to perform onboarding, sanctions screening, transaction monitoring, or escalation handling, Compliance must be informed as appropriate.
7 Safe and Sound Electronic Banking
Systems supporting client authentication, transaction execution, wallet interaction, and digital onboarding must operate in a secure and controlled manner.
Where such systems interface with AML/CTF/CPF or sanctions controls, Bitkaya must ensure that:
- customer and privileged access controls are appropriately designed;
- sensitive onboarding and screening data is encrypted and protected;
- anomalous activity is monitored and escalated;
- transaction controls support sanctions and monitoring requirements where applicable; and
- outages or control failures affecting digital channels are assessed for compliance and regulatory impact.
8 Business Continuity Management (BCM)
Bitkaya’s continuity arrangements must cover the continued or recoverable operation of critical compliance and control systems, including onboarding, sanctions screening, transaction monitoring, case management, and secure access to supporting records.
Business continuity planning should ensure that, during a disruption, Bitkaya can still:
- restrict or delay onboarding where screening cannot be completed reliably;
- preserve and access sanctions and monitoring data;
- escalate material alerts and incidents appropriately;
- maintain secure records of ongoing investigations or reporting decisions; and
- support legal or regulatory response expectations.
Resilience planning must therefore consider the operational dependency of the compliance framework on IT systems and external vendors.
For full details, see the Bitkaya Business Continuity Manual.
9 IT Framework and Integration
Bitkaya integrates IT areas into a VASP-specific framework:
- Crypto Custody and Key Management
- Information Security (ISO 27001)
- Business Continuity (ISO 22301)
- IT Governance (COBIT)
- IT Service Management (ISO 20000/ITIL v3)
- AML/CFT and FATF Compliance
- Third-Party Risk Management (custody, cloud, fintech partners)
10 Training and Awareness
Personnel with access to critical systems must receive training appropriate to their role, including secure use of systems, change control expectations, privileged access responsibilities, and handling of compliance-sensitive data.
Where IT personnel support onboarding, screening, monitoring, or case-management systems, training should also cover the control significance of those systems, escalation expectations, and the importance of preserving auditability and data integrity.
11 Continuous Improvement
- KPIs: incident response times, withdrawal fraud detection, wallet uptime, AML alert resolution.
- Governance Review: Board annually reviews IT and Cybersecurity Manual against CBCS and FATF updates.
- Drills and Feedback: lessons from wallet drills, recovery tests, and incident reports are integrated.
- Audit and Transparency: independent audits of crypto custody, key management, and AML systems.
12 Proportionality Implementation
Bitkaya’s proportionality implementation recognizes its current status as a small, startup-stage institution and applies CBCS’s proportionality principle to ensure governance, security, and resilience measures are fit-for-purpose, scalable, and risk-based. This enables Bitkaya to maintain regulatory compliance and operational soundness while evolving toward a more complex, mature operational model.
12.1 Purpose and Rationale
Bitkaya applies proportionality across all areas of its IT and cybersecurity governance. The principle of proportionality ensures that governance structures, technical safeguards, and internal controls are commensurate with the company’s current size, operational complexity, and risk exposure, as required by the CBCS IT Framework and related supervisory guidelines.
As a startup-stage and relatively small organization, Bitkaya acknowledges that it does not yet possess the scale or resource base of larger financial institutions. Consequently, Bitkaya’s IT and cybersecurity framework focuses on risk-appropriate controls, lean governance, and scalable practices that still meet CBCS’s core expectations for safety, soundness, and resilience.
This approach ensures that:
- Controls are fit-for-purpose and effective within a startup environment.
- Resources are directed toward highest-risk activities such as wallet management, platform integrity, and AML/CFT systems.
- The governance framework remains scalable, supporting the transition from startup to a mature institution without structural redesign.
- Proportionality does not dilute accountability or compliance, but rather prioritizes practical implementation of supervisory expectations.
12.2 Guiding Principles
In line with CBCS’s expectations for proportional implementation of IT, ISM, and BCM controls, Bitkaya adopts the following principles:
- Risk-Based Application — The scope and formality of IT governance, testing, and cybersecurity measures are determined based on inherent and residual risk, not organization size alone.
- Startup Proportionality — As a small entity, Bitkaya consolidates roles and responsibilities (e.g., combining IT Security and Compliance functions) while maintaining oversight and avoiding conflicts of interest.
- Scalability — Every policy and process is designed to scale seamlessly as transaction volume, staff, and technology infrastructure expand.
- Efficiency and Practicality — Controls are streamlined to be achievable within startup resource constraints, with reliance on automation and secure third-party systems where appropriate.
- Continuous Alignment — Proportionality is re-evaluated annually and whenever significant changes occur in risk exposure, technology, or regulation.
12.3 Governance and Oversight
- IT Steering Committee: Reviews proportionality justifications to ensure critical risks (cyber, operational, AML/CFT) are fully mitigated.
- Internal or Independent Audit: Confirms that proportionality measures are appropriate and do not introduce unacceptable residual risks.
- Management and Staff: Implement and monitor proportional controls under the oversight of the Compliance and Risk function.
12.4 Proportional Application Across IT Domains
Information Security Management (ISM)
- Bitkaya implements CBCS-aligned ISM principles proportionate to its startup profile, focusing on essential ISO 27001 control areas such as access control, encryption, and incident management.
- Security measures emphasize protection of private keys, wallet infrastructure, and client data through multi-factor authentication, hardware keys, and encrypted storage.
- Given limited staffing, Bitkaya outsources non-core technical services (e.g., penetration testing, vulnerability scanning) to certified providers, maintaining vendor oversight rather than in-house duplication.
- Policies, standards, and training are simplified but cover all mandatory CBCS ISM objectives for confidentiality, integrity, and availability.
IT Service Management (ITSM)
- Bitkaya’s ITSM aligns with the CBCS 2014 ITSM provisions, applying a lean and automated structure consistent with its small-scale operations.
- Incident and change management processes are centralized in a single system managed by the IT and Compliance function, ensuring traceability and efficiency.
- RPO/RTO metrics are proportionate to Bitkaya’s cloud-based architecture, which offers redundancy without large on-premise investment.
Business Continuity Management (BCM)
- Bitkaya applies the CBCS 2021 BCM principles and ISO 22301 framework, scaled to its startup profile.
- The company maintains a single integrated Business Continuity and Disaster Recovery Plan (BCP/DRP) rather than multiple departmental subplans, reflecting its size.
- Testing is proportionate: tabletop exercises and crypto-specific simulations (e.g., wallet access outage, cloud provider disruption) are conducted annually.
- The BCM Coordinator (part of the Compliance function) ensures resilience and readiness, with escalation to the Board in case of incidents.
IT Governance
- Governance follows the CBCS IT Framework (2011), applying oversight mechanisms suitable for smaller supervised institutions.
- Strategic IT decisions are made at the executive level, with oversight by the Board.
- Formal IT governance documentation is concise, focusing on decision-making accountability, vendor oversight, and cybersecurity assurance.
Software Testing and Quality Assurance
- Testing follows the CBCS Provisions for Software Testing (2024) and TMMi (Test Maturity Model Integration) Level 2 maturity expectations but scaled to Bitkaya’s operational footprint.
- Automated testing tools and external QA reviews replace full-scale in-house testing departments.
- Focus is placed on high-risk crypto functions (wallet integrations, blockchain APIs, AML transaction filters) rather than exhaustive platform-wide testing.
12.5 Documentation and Audit Trail
- All proportionality determinations are formally documented, including:
- Justification based on operational risk and size.
- Compensating controls (e.g., independent audit in lieu of segregation).
- References to CBCS or ISO guidance supporting proportionality.
- Documentation is reviewed by the Board annually and maintained for regulatory inspection.
12.6 Continuous Improvement
- Bitkaya re-evaluates proportionality during the annual IT and Cybersecurity Review, integrating lessons learned from incidents, audits, and CBCS supervisory feedback.
- As the company grows, controls and staffing structures will be progressively strengthened to align with increasing operational scale and CBCS maturity expectations.
- Proportionality decisions will be tracked on a digital platform for approvals and change tracking to ensure transparency, accountability, and readiness for expansion.
13 References
- Provisions and Guidelines for Software Testing (23 Aug 2024) — Centrale Bank van Curaçao en Sint Maarten. Basis for Chapter 5: Software Testing and QA.
- Provisions and Guidelines for IT Governance (2nd edition) (18 Oct 2021) — Centrale Bank van Curaçao en Sint Maarten. Basis for Chapter 2: Governance and Oversight and Chapter 9: IT Framework and Integration.
- Policy Memorandum — Management of Computer Risks (20 Jan 2019, updated Apr 2011) — Centrale Bank van Curaçao en Sint Maarten. Basis for Chapter 4: Risk Management of IT and Cyber Threats.
- IT Framework Memorandum for Supervised Institutions (20 Jan 2019, updated Apr 2011) — Centrale Bank van Curaçao en Sint Maarten. Provided the overall IT framework (Governance, ISM, BCM, ITSM, Outsourcing) referenced across chapters.
- Provisions and Guidelines for Information Security Management (20 Jan 2019, updated Apr 2011) — Centrale Bank van Curaçao en Sint Maarten. Basis for Chapter 3: Information Security Management (ISM).
- Provisions and Guidelines for Safe and Sound Electronic Banking (20 Jan 2019, updated Apr 2011) — Centrale Bank van Curaçao en Sint Maarten. Basis for Chapter 7: Safe and Sound Electronic Banking (adapted to VASP context).
- Provisions and Guidelines for Information Technology Service Management (July 2014 draft) — Centrale Bank van Curaçao en Sint Maarten. Basis for Chapter 6: IT Service Management (ITSM).
- Provisions and Guidelines for Business Continuity Management (27 Aug 2021) — Centrale Bank van Curaçao en Sint Maarten. Basis for Chapter 8: BCM (aligned with ISO 22301).
- Bitkaya Business Continuity Manual (2025) — Centrale Bank van Curaçao en Sint Maarten. Directly used and linked in Chapter 8: BCM for Bitkaya-specific plans, roles, testing, and governance.
Operating Layer
The approved manual is implemented through the IT framework process and the detailed procedure and control set:
- PRC-RSA-001 Resilience Systems and Assurance
- PROC-IT-001 Maintain IT Governance and Oversight
- PROC-IT-002 Maintain Information Security Management
- PROC-IT-003 Maintain IT Service Management
- PROC-IT-004 Maintain Safe and Sound Electronic Banking
- PROC-IT-005 Manage Computer Risk and Control Environment
- PROC-IT-006 Maintain Business Continuity Management
- PROC-IT-007 Maintain Software Testing and Release Assurance
- PROC-IT-008 Manage Technology Change Acquisition and Outsourced IT Services
- CTRL-IT-001 Ensure IT Governance and Oversight Is Maintained
- CTRL-IT-002 Ensure Information Security Management Is Maintained
- CTRL-IT-003 Ensure IT Service Management Is Maintained
- CTRL-IT-004 Ensure Safe and Sound Electronic Banking Is Maintained
- CTRL-IT-005 Ensure Computer Risk and Control Environment Is Maintained
- CTRL-IT-006 Ensure Business Continuity Management Is Maintained
- CTRL-IT-007 Ensure Software Testing and Release Assurance Is Maintained
- CTRL-IT-008 Ensure Technology Change Acquisition and Outsourced IT Services Are Controlled
The detailed COTS specialization is maintained in POL-COTS-001 Commercial Off-The Shelf Software Acceptance and Testing Manual as a specialized operating layer within PRC-RSA-001 Resilience Systems and Assurance.
The detailed business continuity specialization is maintained in POL-BCM-001 Business Continuity Manual as another operating layer within PRC-RSA-001 Resilience Systems and Assurance. Neither specialization creates a subordinate Process object.
Implementing Procedures and Controls
Procedures
- PROC-IT-001 Maintain IT Governance and Oversight
- PROC-IT-002 Maintain Information Security Management
- PROC-IT-003 Maintain IT Service Management
- PROC-IT-004 Maintain Safe and Sound Electronic Banking
- PROC-IT-005 Manage Computer Risk and Control Environment
- PROC-IT-006 Maintain Business Continuity Management
- PROC-IT-007 Maintain Software Testing and Release Assurance
- PROC-IT-008 Manage Technology Change Acquisition and Outsourced IT Services
Controls
- CTRL-IT-001 Ensure IT Governance and Oversight Is Maintained
- CTRL-IT-002 Ensure Information Security Management Is Maintained
- CTRL-IT-003 Ensure IT Service Management Is Maintained
- CTRL-IT-004 Ensure Safe and Sound Electronic Banking Is Maintained
- CTRL-IT-005 Ensure Computer Risk and Control Environment Is Maintained
- CTRL-IT-006 Ensure Business Continuity Management Is Maintained
- CTRL-IT-007 Ensure Software Testing and Release Assurance Is Maintained
- CTRL-IT-008 Ensure Technology Change Acquisition and Outsourced IT Services Are Controlled
Change Log
| Version | Date | Summary of Changes | Approvers | Impacted Policies/Procedures |
|---|---|---|---|---|
| 1.0 | October 2025 | Initial Manual | Board | All |
| 1.1 | April 2026 | Cross-manual harmonization following AML/CTF/CPF Manual v2.1 | Board | Sections 1–8, 10 |
Source Document
- Document title: Bitkaya IT and Cybersecurity Manual
- Version: 1.1
- Status in source document: FINAL
- Date in source document: April 2026
- Board approval and effective date: 2026-04-21, inferred from the approved artifact metadata and filename; the visible pages do not state an exact day
- Source file reviewed:
Bitkaya IT and Cybersecurity Manual v11 Approved (1).pdf - Permanent approved artifact location: Bitkaya IT and Cybersecurity Manual v11 Approved.pdf