Purpose

Maintain the operating steps for technology change, acquisition and outsourced IT service arrangements. Bitkaya integrates IT areas into a VASP-specific framework that includes Third-Party Risk Management (custody, cloud, fintech partners) and outsourced services. Given limited staffing, Bitkaya outsources non-core technical services (e.g., penetration testing, vulnerability scanning) to certified providers, maintaining vendor oversight rather than in-house duplication.

Scope

This procedure applies to technology development or acquisition, major change approval, outsourced services and related governance records. Changes to critical compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities must be subject to appropriate governance, testing, approval, and documentation controls.

Steps

#ActionDetailsEvidence
1Confirm change, acquisition or outsourcing request and ownerVerify the request falls within the VASP-specific IT framework (Crypto Custody and Key Management, Information Security ISO 27001, Business Continuity ISO 22301, IT Governance COBIT, IT Service Management ISO 20000/ITIL v3, AML/CFT and FATF Compliance, Third-Party Risk Management).change or acquisition request
2Check risk assessment, approval and third-party due diligenceFor outsourced non-core technical services (e.g., penetration testing, vulnerability scanning), verify reliance on certified providers with vendor oversight rather than in-house duplication.approval or due diligence record; vendor oversight record
3Verify change governance for compliance-related systemsConfirm changes to compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities are subject to appropriate governance, testing, approval, and documentation controls.change governance record
4Notify Compliance of impairment riskWhere an incident or change could impair Bitkaya’s ability to perform onboarding, sanctions screening, transaction monitoring, or escalation handling, ensure Compliance is informed as appropriate.Compliance notification record
5Record implementation, vendor or change evidenceRecord implementation, vendor or change evidence and any required escalation.outsourcing or supplier record
6Retain approval and monitoring recordsRetain approval and monitoring records for review.approval or due diligence record
7Escalate unapproved changes or unmanaged third-party riskEscalate any unapproved change or unmanaged third-party risk.change governance record

Evidence

  • change or acquisition request
  • approval or due diligence record
  • vendor oversight record for outsourced services (certified providers for penetration testing, vulnerability scanning)
  • change governance record for compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities
  • Compliance notification record where changes affect AML/CTF/CPF capabilities
  • outsourcing or supplier record where relevant

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved IT and Cybersecurity Manual version 1.1

History

  • 2026-07-26: Created from REQ-IT-008.
  • 2026-07-26: Added the Odoo automated compliance monitoring implementation SOP.