Purpose
Classify a proposed or changed outsourcing arrangement before it starts so Bitkaya knows the approval, due diligence, monitoring and CBCS engagement path that applies.
Scope
This procedure applies to outsourcing arrangements and material changes to outsourcing arrangements as defined in the Bitkaya Outsourcing Risk Management Manual.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm whether the engagement is outsourcing, contractor support, or another third-party arrangement | A contractor engagement is generally not outsourcing where: the contractor works under Bitkaya’s day-to-day direction and oversight; the contractor uses Bitkaya’s systems, controls, and reporting lines; the contractor is integrated into Bitkaya’s governance and approval structure; the contractor does not deliver a separate managed service; the contractor may not freely substitute another person or subcontract the work; and Bitkaya retains direct control over the function. A contractor arrangement should be assessed as potential outsourcing where: the contractor delivers a separate managed service; the provider controls the method of service delivery independently; the arrangement relies on the provider’s own systems, infrastructure, or processes; the provider may substitute staff or subcontract performance; Bitkaya is relying on the provider to perform an ongoing function rather than using the person as embedded staff; or the contractor supports a key control or regulated function in a way that resembles an external service arrangement | Engagement-type determination note |
| 2 | Identify whether the arrangement is standard, material, or critical or essential | Standard outsourcing supports operations but whose failure would not materially impair Bitkaya’s licensed activities, regulatory compliance, core control environment, or continuity of service. Material outsourcing is where failure, disruption, or breach could materially affect Bitkaya’s operations, continuity, compliance, reputation, profitability, risk management, or customer information, but would not necessarily rise to the level of a critical or essential function. Critical or essential outsourcing is where failure, disruption, or poor performance would materially impair Bitkaya’s continuing compliance with licensing or regulatory obligations, materially weaken the soundness or continuity of its functions, or create a serious inability to continue regulated operations in an orderly way | Classification decision record |
| 3 | Document the rationale using the practical indicators in the outsourcing manual | An outsourced function should generally be treated as critical or essential where: failure would likely place Bitkaya in breach of a regulatory or licensing requirement; failure would seriously disrupt Bitkaya’s ability to continue core operations; failure would materially impair AML/CFT, sanctions, safeguarding, cybersecurity, or another key control function; failure would create a serious client protection or service continuity issue; or the function is difficult to replace or bring back in-house within a reasonable time. Operational activities of internal control functions are generally treated as critical or essential unless assessment shows otherwise | Classification rationale note |
| 4 | Assign one named internal owner for the arrangement | That person keeps the file complete, monitors the service, manages the relationship, and escalates issues | Owner assignment record |
| 5 | Escalate material and critical or essential classifications to management and Compliance | Risk and Compliance support classification, check regulatory implications, and help decide whether CBCS approval or engagement is needed | Escalation record |
| 6 | Record the classification in the outsourcing register before the arrangement starts | — | Outsourcing register entry |
| 7 | Review the classification at least annually, and sooner where there is a material change | CBCS requires periodic reassessment | Periodic reassessment record |
Evidence
- classification record
- owner assignment
- register entry
- escalation record where applicable
Relationships
- Requirements: REQ-OUT-002 Obtain CBCS Approval for Critical or Material Outsourcing, REQ-OUT-003 Assess Outsourcing Criticality Materiality and Risk, REQ-OUT-007 Maintain Outsourcing Governance and Accountability, REQ-OUT-010 Maintain Outsourcing Register and Compliance Notifications
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Controls: CTRL-OUT-001 Ensure Outsourcing Is Classified Before Engagement, CTRL-OUT-005 Ensure Outsourcing Register Is Complete and Current, CTRL-OUT-008 Ensure CBCS Outsourcing Reporting Is Completed
- System: SYS-OUT-001 Outsourcing Register
- Publication: PUB-OUT-001 Outsourcing Risk Management Manual
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: drafted from approved manual
History
- 2026-07-25: Created procedure from the Bitkaya Outsourcing Risk Management Manual version 1.0.
- 2026-07-25: Set procedure status to implemented based on Board approval of the Outsourcing Risk Management Manual on 2026-04-16.