Purpose

Classify a proposed or changed outsourcing arrangement before it starts so Bitkaya knows the approval, due diligence, monitoring and CBCS engagement path that applies.

Scope

This procedure applies to outsourcing arrangements and material changes to outsourcing arrangements as defined in the Bitkaya Outsourcing Risk Management Manual.

Steps

#ActionDetailsEvidence
1Confirm whether the engagement is outsourcing, contractor support, or another third-party arrangementA contractor engagement is generally not outsourcing where: the contractor works under Bitkaya’s day-to-day direction and oversight; the contractor uses Bitkaya’s systems, controls, and reporting lines; the contractor is integrated into Bitkaya’s governance and approval structure; the contractor does not deliver a separate managed service; the contractor may not freely substitute another person or subcontract the work; and Bitkaya retains direct control over the function. A contractor arrangement should be assessed as potential outsourcing where: the contractor delivers a separate managed service; the provider controls the method of service delivery independently; the arrangement relies on the provider’s own systems, infrastructure, or processes; the provider may substitute staff or subcontract performance; Bitkaya is relying on the provider to perform an ongoing function rather than using the person as embedded staff; or the contractor supports a key control or regulated function in a way that resembles an external service arrangementEngagement-type determination note
2Identify whether the arrangement is standard, material, or critical or essentialStandard outsourcing supports operations but whose failure would not materially impair Bitkaya’s licensed activities, regulatory compliance, core control environment, or continuity of service. Material outsourcing is where failure, disruption, or breach could materially affect Bitkaya’s operations, continuity, compliance, reputation, profitability, risk management, or customer information, but would not necessarily rise to the level of a critical or essential function. Critical or essential outsourcing is where failure, disruption, or poor performance would materially impair Bitkaya’s continuing compliance with licensing or regulatory obligations, materially weaken the soundness or continuity of its functions, or create a serious inability to continue regulated operations in an orderly wayClassification decision record
3Document the rationale using the practical indicators in the outsourcing manualAn outsourced function should generally be treated as critical or essential where: failure would likely place Bitkaya in breach of a regulatory or licensing requirement; failure would seriously disrupt Bitkaya’s ability to continue core operations; failure would materially impair AML/CFT, sanctions, safeguarding, cybersecurity, or another key control function; failure would create a serious client protection or service continuity issue; or the function is difficult to replace or bring back in-house within a reasonable time. Operational activities of internal control functions are generally treated as critical or essential unless assessment shows otherwiseClassification rationale note
4Assign one named internal owner for the arrangementThat person keeps the file complete, monitors the service, manages the relationship, and escalates issuesOwner assignment record
5Escalate material and critical or essential classifications to management and ComplianceRisk and Compliance support classification, check regulatory implications, and help decide whether CBCS approval or engagement is neededEscalation record
6Record the classification in the outsourcing register before the arrangement starts—Outsourcing register entry
7Review the classification at least annually, and sooner where there is a material changeCBCS requires periodic reassessmentPeriodic reassessment record

Evidence

  • classification record
  • owner assignment
  • register entry
  • escalation record where applicable

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: drafted from approved manual

History

  • 2026-07-25: Created procedure from the Bitkaya Outsourcing Risk Management Manual version 1.0.
  • 2026-07-25: Set procedure status to implemented based on Board approval of the Outsourcing Risk Management Manual on 2026-04-16.