Purpose

Maintain the operating steps for identifying and managing computer risk and control weaknesses. Bitkaya’s IT and cyber risk management includes risks arising from compromise, failure, misuse, misconfiguration, or poor governance of systems that support AML/CTF/CPF, sanctions, onboarding, case handling, and regulatory reporting.

Scope

This procedure applies to development risk, processing errors, interruption, confidentiality breaches, fraud and other computer-related control weaknesses. Relevant risks include unauthorized access to onboarding, screening, or monitoring systems; improper changes to screening logic, alert settings, or workflow rules; loss or corruption of client due diligence, sanctions, or case data; failure of list refresh or screening integrations; insufficient logging of critical user activity; exposure of compliance-sensitive documents or records; over-reliance on third-party tooling without appropriate validation; and operational disruption affecting compliance control execution.

Steps

#ActionDetailsEvidence
1Review risk classification and control designIdentify and classify risks including unauthorized access, improper changes to screening logic, data loss or corruption, integration failures, insufficient logging, exposure of sensitive records, third-party over-reliance, and operational disruption.computer-risk assessment
2Confirm preventive and containment controlsVerify controls are proportionate to the materiality of the system and include strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery measures.control design or testing record
3Record issues, exceptions and control weaknessesTrack risks specific to compliance systems (screening logic changes, alert settings, workflow rules, list refresh failures, logging gaps).computer-risk assessment
4Escalate unresolved risk items to management and ComplianceWhere risks could impair onboarding, sanctions screening, transaction monitoring, or escalation handling, ensure Compliance is informed.Compliance notification record; remediation or escalation record
5Retain risk and control record for reviewRetain the risk and control record for review.control design or testing record

Evidence

  • computer-risk assessment including AML/CTF/CPF, sanctions, onboarding, case handling, and regulatory reporting risk categories
  • control design or testing record evidencing strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery measures
  • remediation or escalation record where needed
  • Compliance notification record where risks affect AML/CTF/CPF capabilities

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved IT and Cybersecurity Manual version 1.1

History

  • 2026-07-26: Created from REQ-IT-005.