Purpose
Maintain service-management practices for IT support, assets, configuration, backup and restore. Critical IT services include not only custody, wallet, and trading infrastructure, but also compliance-related systems supporting onboarding, sanctions screening, transaction monitoring, internal case handling, and regulatory support.
Scope
This procedure applies to service levels, support functions, asset and configuration control, backup and restoration, third-party service coordination and user support. Bitkaya’s ITSM aligns with the CBCS 2014 ITSM provisions, applying a lean and automated structure consistent with its small-scale operations.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm service owner, levels and support expectations | Verify that incident and change management processes are centralized in a single system managed by the IT and Compliance function, ensuring traceability and efficiency. | service review record |
| 2 | Verify RPO/RTO metrics | Confirm RPO/RTO metrics are proportionate to Bitkaya’s cloud-based architecture, which offers redundancy without large on-premise investment. | backup or restore evidence |
| 3 | Log and assess incidents affecting critical services | Ensure incidents affecting critical services (custody, wallet, trading, onboarding, sanctions screening, transaction monitoring, case handling, regulatory support) are logged centrally and assessed for operational, security, compliance, and regulatory impact. | incident log with impact assessment |
| 4 | Verify change management for material updates | Confirm change management applies to material updates involving: compliance system configuration; screening tools or list sources; monitoring logic or rule tuning; case-management workflow changes; access rights to sensitive compliance systems; and integrations that affect alerting, screening, or documentation. | change management record |
| 5 | Notify Compliance of impairment risk | Where an incident or change could impair Bitkaya’s ability to perform onboarding, sanctions screening, transaction monitoring, or escalation handling, ensure Compliance is informed as appropriate. | Compliance notification record |
| 6 | Check asset, configuration and backup records | Record service incidents, changes or supplier issues and track them to closure. | asset or configuration record |
| 7 | Retain service review and restore evidence | Retain evidence of service reviews, restores and support actions. | service review record; backup or restore evidence |
| 8 | Escalate material service weakness or outage risk | Escalate any material service weakness or outage risk. | supplier or support escalation |
Evidence
- service review record
- asset or configuration record
- backup or restore evidence
- incident log with operational, security, compliance, and regulatory impact assessment
- change management record for material updates to compliance systems, screening tools, monitoring logic, and integrations
- Compliance notification record where incidents or changes affect AML/CTF/CPF capabilities
- supplier or support escalation where needed
Relationships
- Requirement: REQ-IT-003 Maintain IT Service Management
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-IT-003 Ensure IT Service Management Is Maintained
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Created from REQ-IT-003.