Purpose
Maintain the operating steps for technology change, acquisition and outsourced IT service arrangements. Bitkaya integrates IT areas into a VASP-specific framework that includes Third-Party Risk Management (custody, cloud, fintech partners) and outsourced services. Given limited staffing, Bitkaya outsources non-core technical services (e.g., penetration testing, vulnerability scanning) to certified providers, maintaining vendor oversight rather than in-house duplication.
Scope
This procedure applies to technology development or acquisition, major change approval, outsourced services and related governance records. Changes to critical compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities must be subject to appropriate governance, testing, approval, and documentation controls.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm change, acquisition or outsourcing request and owner | Verify the request falls within the VASP-specific IT framework (Crypto Custody and Key Management, Information Security ISO 27001, Business Continuity ISO 22301, IT Governance COBIT, IT Service Management ISO 20000/ITIL v3, AML/CFT and FATF Compliance, Third-Party Risk Management). | change or acquisition request |
| 2 | Check risk assessment, approval and third-party due diligence | For outsourced non-core technical services (e.g., penetration testing, vulnerability scanning), verify reliance on certified providers with vendor oversight rather than in-house duplication. | approval or due diligence record; vendor oversight record |
| 3 | Verify change governance for compliance-related systems | Confirm changes to compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities are subject to appropriate governance, testing, approval, and documentation controls. | change governance record |
| 4 | Notify Compliance of impairment risk | Where an incident or change could impair Bitkaya’s ability to perform onboarding, sanctions screening, transaction monitoring, or escalation handling, ensure Compliance is informed as appropriate. | Compliance notification record |
| 5 | Record implementation, vendor or change evidence | Record implementation, vendor or change evidence and any required escalation. | outsourcing or supplier record |
| 6 | Retain approval and monitoring records | Retain approval and monitoring records for review. | approval or due diligence record |
| 7 | Escalate unapproved changes or unmanaged third-party risk | Escalate any unapproved change or unmanaged third-party risk. | change governance record |
Evidence
- change or acquisition request
- approval or due diligence record
- vendor oversight record for outsourced services (certified providers for penetration testing, vulnerability scanning)
- change governance record for compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities
- Compliance notification record where changes affect AML/CTF/CPF capabilities
- outsourcing or supplier record where relevant
Relationships
- Requirement: REQ-IT-008 Manage Technology Change Acquisition and Outsourced IT Services
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-IT-008 Ensure Technology Change Acquisition and Outsourced IT Services Are Controlled
- Odoo system: SYS-IT-001 Odoo Automated Compliance Monitoring
- Implementation SOP: PUB-IT-001 Automated Compliance Monitoring Controls in Odoo SOP
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Created from REQ-IT-008.
- 2026-07-26: Added the Odoo automated compliance monitoring implementation SOP.