Purpose

Maintain the governance, context, responsibilities and resources required for an effective and proportionate BCM program that ensures resilience against disruptions, protection of stakeholders, and compliance with the Centrale Bank van Curaçao en Sint Maarten (CBCS) provisions and ISO 22301 standards.

Preconditions

  • Current organization, service, regulatory and stakeholder information is available.
  • BCM roles have named incumbents or accountable functions.

Steps

#ActionDetailsEvidence
1Review external contextPolitical/regulatory (local laws, CBCS provisions, FATF standards); economic/technological (crypto volatility, fintech); social/cultural factors; natural/environmental risks (storms, flooding, earthquakes); competitive pressures in global VASP servicesContext review record
2Review internal contextProducts/services (trading platform, wallets, compliance systems); resources (IT, personnel, capital); org structure and governance; dependencies on vendors, banking partners, cloud servicesContext review record
3Identify interested partiesRegulators (CBCS, FATF-aligned); clients and investors; employees/contractors; suppliers, IT providers, partners; insurers, auditors, emergency servicesStakeholder register
4Confirm BCM scopeDocument scope and justified exclusions; applies to all departments, employees, contractors, consultants, critical suppliers, vendors, outsourcing partners, and external stakeholdersScope document
5Assign Board responsibilitiesApproves BCM policy, reviews plans annually, ensures resource allocation, oversees audits, corrective actions, compliance reportsResponsibility assignment
6Assign Department Head responsibilitiesIdentify critical functions, dependencies, recovery needs; maintain departmental continuity sub-plans; ensure staff training and BCM awarenessResponsibility assignment
7Assign Employee responsibilitiesParticipate in training and drills; execute BCM responsibilities as assignedResponsibility assignment
8Confirm audit arrangementsInternal and external audits conducted annually; findings reviewed by Board; corrective actions trackedAudit schedule and findings
9Confirm resource availabilityCompetent personnel, budget, systems, premises, supplier resources; financial (budget), human (staffing, training), physical (facilities, alternate sites)Resource assessment
10Obtain Board approvalAt least annually and after material change; BCM Policy reviewed annually and after major disruptionBoard approval minutes
11Record and escalate constraintsRecord decisions, actions, unresolved resource constraints; escalate to management and BoardEscalation records
12Apply proportionalitySingle BCM Officer reports to Board instead of dedicated BCM department; governance right-sized for small, growing VASPGovernance decision record

Exceptions and Escalation

Any unassigned critical role, material resource constraint or unapproved scope exclusion shall be escalated promptly to management and the Board.

Records

  • BCM context and scope review
  • Responsibility assignment or contact list
  • Resource assessment
  • Board approval and oversight minutes
  • Escalation and remediation records

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual and after material organizational or regulatory change

History

  • 2026-07-26: Created from sections 4, 5, 12 and 16 of the approved Business Continuity Manual.