Purpose
Maintain the operating steps for IT business continuity planning, testing and review. Bitkaya’s continuity arrangements must cover the continued or recoverable operation of critical compliance and control systems, including onboarding, sanctions screening, transaction monitoring, case management, and secure access to supporting records.
Scope
This procedure applies to continuity context, business impact analysis, plan maintenance, testing, review and training for critical technology services. Bitkaya applies the CBCS 2021 BCM principles and ISO 22301 framework, scaled to its startup profile. The company maintains a single integrated Business Continuity and Disaster Recovery Plan (BCP/DRP) rather than multiple departmental subplans, reflecting its size.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm continuity owner and critical service scope | Verify the BCM Coordinator (part of the Compliance function) ensures resilience and readiness, with escalation to the Board in case of incidents. | BCM Coordinator escalation record |
| 2 | Review impact analysis, RTO/RPO and continuity plans | Confirm RPO/RTO metrics are proportionate to Bitkaya’s cloud-based architecture, which offers redundancy without large on-premise investment. | business impact analysis |
| 3 | Verify business continuity planning for disruptions | Confirm that during a disruption, Bitkaya can still: restrict or delay onboarding where screening cannot be completed reliably; preserve and access sanctions and monitoring data; escalate material alerts and incidents appropriately; maintain secure records of ongoing investigations or reporting decisions; and support legal or regulatory response expectations. | single integrated BCP/DRP |
| 4 | Confirm resilience planning for operational dependencies | Verify resilience planning considers the operational dependency of the compliance framework on IT systems and external vendors. | business impact analysis |
| 5 | Record tests, exercises and remediation actions | Verify testing is proportionate: tabletop exercises and crypto-specific simulations (e.g., wallet access outage, cloud provider disruption) are conducted annually. | continuity plan or test record |
| 6 | Retain evidence of plan approval and periodic review | For full details, see the Bitkaya Business Continuity Manual. | continuity plan or test record |
| 7 | Escalate continuity gaps or failed exercises | Escalate continuity gaps or failed exercises. | remediation or lessons-learned record |
Evidence
- business impact analysis
- single integrated BCP/DRP (not multiple departmental subplans)
- continuity plan or test record, including annual tabletop exercises and crypto-specific simulations (wallet access outage, cloud provider disruption)
- remediation or lessons-learned record where needed
- BCM Coordinator escalation record to Board where applicable
Relationships
- Requirement: REQ-IT-006 Maintain Business Continuity Management
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-IT-006 Ensure Business Continuity Management Is Maintained
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from REQ-IT-006.