Purpose

Maintain the operating steps for IT business continuity planning, testing and review. Bitkaya’s continuity arrangements must cover the continued or recoverable operation of critical compliance and control systems, including onboarding, sanctions screening, transaction monitoring, case management, and secure access to supporting records.

Scope

This procedure applies to continuity context, business impact analysis, plan maintenance, testing, review and training for critical technology services. Bitkaya applies the CBCS 2021 BCM principles and ISO 22301 framework, scaled to its startup profile. The company maintains a single integrated Business Continuity and Disaster Recovery Plan (BCP/DRP) rather than multiple departmental subplans, reflecting its size.

Steps

#ActionDetailsEvidence
1Confirm continuity owner and critical service scopeVerify the BCM Coordinator (part of the Compliance function) ensures resilience and readiness, with escalation to the Board in case of incidents.BCM Coordinator escalation record
2Review impact analysis, RTO/RPO and continuity plansConfirm RPO/RTO metrics are proportionate to Bitkaya’s cloud-based architecture, which offers redundancy without large on-premise investment.business impact analysis
3Verify business continuity planning for disruptionsConfirm that during a disruption, Bitkaya can still: restrict or delay onboarding where screening cannot be completed reliably; preserve and access sanctions and monitoring data; escalate material alerts and incidents appropriately; maintain secure records of ongoing investigations or reporting decisions; and support legal or regulatory response expectations.single integrated BCP/DRP
4Confirm resilience planning for operational dependenciesVerify resilience planning considers the operational dependency of the compliance framework on IT systems and external vendors.business impact analysis
5Record tests, exercises and remediation actionsVerify testing is proportionate: tabletop exercises and crypto-specific simulations (e.g., wallet access outage, cloud provider disruption) are conducted annually.continuity plan or test record
6Retain evidence of plan approval and periodic reviewFor full details, see the Bitkaya Business Continuity Manual.continuity plan or test record
7Escalate continuity gaps or failed exercisesEscalate continuity gaps or failed exercises.remediation or lessons-learned record

Evidence

  • business impact analysis
  • single integrated BCP/DRP (not multiple departmental subplans)
  • continuity plan or test record, including annual tabletop exercises and crypto-specific simulations (wallet access outage, cloud provider disruption)
  • remediation or lessons-learned record where needed
  • BCM Coordinator escalation record to Board where applicable

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved IT and Cybersecurity Manual version 1.1

History

  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from REQ-IT-006.