Purpose
Maintain the operating steps for identifying and managing computer risk and control weaknesses. Bitkaya’s IT and cyber risk management includes risks arising from compromise, failure, misuse, misconfiguration, or poor governance of systems that support AML/CTF/CPF, sanctions, onboarding, case handling, and regulatory reporting.
Scope
This procedure applies to development risk, processing errors, interruption, confidentiality breaches, fraud and other computer-related control weaknesses. Relevant risks include unauthorized access to onboarding, screening, or monitoring systems; improper changes to screening logic, alert settings, or workflow rules; loss or corruption of client due diligence, sanctions, or case data; failure of list refresh or screening integrations; insufficient logging of critical user activity; exposure of compliance-sensitive documents or records; over-reliance on third-party tooling without appropriate validation; and operational disruption affecting compliance control execution.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Review risk classification and control design | Identify and classify risks including unauthorized access, improper changes to screening logic, data loss or corruption, integration failures, insufficient logging, exposure of sensitive records, third-party over-reliance, and operational disruption. | computer-risk assessment |
| 2 | Confirm preventive and containment controls | Verify controls are proportionate to the materiality of the system and include strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery measures. | control design or testing record |
| 3 | Record issues, exceptions and control weaknesses | Track risks specific to compliance systems (screening logic changes, alert settings, workflow rules, list refresh failures, logging gaps). | computer-risk assessment |
| 4 | Escalate unresolved risk items to management and Compliance | Where risks could impair onboarding, sanctions screening, transaction monitoring, or escalation handling, ensure Compliance is informed. | Compliance notification record; remediation or escalation record |
| 5 | Retain risk and control record for review | Retain the risk and control record for review. | control design or testing record |
Evidence
- computer-risk assessment including AML/CTF/CPF, sanctions, onboarding, case handling, and regulatory reporting risk categories
- control design or testing record evidencing strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery measures
- remediation or escalation record where needed
- Compliance notification record where risks affect AML/CTF/CPF capabilities
Relationships
- Requirement: REQ-IT-005 Manage Computer Risk and Control Environment
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-IT-005 Ensure Computer Risk and Control Environment Is Maintained
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Created from REQ-IT-005.