Purpose
Keep the IT governance structure current and aligned with the approved BCMS manual. Bitkaya’s IT and cybersecurity governance must support not only platform security and operational resilience, but also the integrity of regulatory and compliance control systems.
Scope
This procedure applies to board oversight, management review, ownership assignment and governance reporting for IT and cybersecurity. Governance oversight includes systems and tools used for digital onboarding and identity verification, sanctions screening, blockchain analytics and transaction monitoring, internal case management and escalation, regulatory reporting support, and secure storage of due diligence, screening, and escalation records.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm active manual, source and requirement mapping | Verify the manual version (currently 1.1, April 2026) and the source artifact are current. | governance register entry |
| 2 | Verify named owners, review dates and approval records | Confirm the Board of Directors retains ultimate accountability for proportional implementation and that the IT Steering Committee reviews proportionality justifications to ensure critical risks (cyber, operational, AML/CFT) are fully mitigated. | board or management review record |
| 3 | Ensure change governance for critical compliance-related systems | Verify changes to critical compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities are subject to appropriate governance, testing, approval, and documentation controls. Record governance decisions, escalations and updates in BCMS. | governance register entry |
| 4 | Confirm executive-level strategic IT decisions | Verify that strategic IT decisions are made at the executive level with oversight by the Board. Confirm formal IT governance documentation is concise, focusing on decision-making accountability, vendor oversight, and cybersecurity assurance. | board or management review record |
| 5 | Confirm proportionality governance | Verify the Board reviews proportionality justifications, Internal or Independent Audit confirms proportionality measures are appropriate and do not introduce unacceptable residual risks, and management and staff implement and monitor proportional controls under the oversight of the Compliance and Risk function. | proportionality determination documentation |
| 6 | Retain board or management evidence | Include the annual Board review of the IT and Cybersecurity Manual against CBCS and FATF updates. | board or management review record |
| 7 | Raise and escalate governance gaps | Escalate any unresolved governance gap to management and Compliance. | escalation or remediation record |
Evidence
- governance register entry
- board or management review record, including annual IT and Cybersecurity Manual review against CBCS and FATF updates
- proportionality determination documentation (justification based on operational risk and size, compensating controls, references to CBCS or ISO guidance)
- escalation or remediation record where needed
Relationships
- Requirement: REQ-IT-001 Maintain IT Governance and Oversight
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-IT-001 Ensure IT Governance and Oversight Is Maintained
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from REQ-IT-001.