Purpose
Assess provider suitability and outsourcing risk before Bitkaya commits to an outsourcing arrangement or accepts a material change.
Scope
This procedure applies to outsourcing arrangements and material changes to outsourcing arrangements as defined in the Bitkaya Outsourcing Risk Management Manual.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Identify the service scope, provider, service location and data location where relevant | Determine what the provider does and how important the service is to Bitkaya | Service scope and provider profile note |
| 2 | Assess provider legal existence and registration, reputation and integrity, financial soundness, technical capability and staffing | — | Provider due diligence evidence pack |
| 3 | Assess confidentiality and data protection, information security and resilience, concentration risk, and whether the service can be replaced or reintegrated if necessary | — | Risk assessment record |
| 4 | Review subcontracting permissions and provider oversight arrangements | — | Subcontracting review note |
| 5 | For standardized large providers such as Microsoft, AWS, Google, or similar providers, collect proportionate evidence from a combination of: provider standard terms; platform documentation; certifications; audit reports; internal controls; restricted use cases; and formal internal approval | Bitkaya recognizes that not all contractual terms will be negotiable. CBCS permits use of pooled audits, third-party certifications, and audit reports, although critical or essential outsourcing should not rely only on these sources over time | Collected provider evidence pack |
| 6 | Document residual gaps, risk acceptances and compensating internal controls | The review should be proportionate to the nature, scale, and risk of the arrangement: for standard outsourcing the review may be simple; for material outsourcing it must be more deliberate; for critical or essential outsourcing it must be more complete and clearly documented | Residual gap and risk acceptance record |
| 7 | Escalate material or critical residual risks for approval before engagement | CBCS requires due diligence and risk assessment before outsourcing and in case of material change. Bitkaya does not perform expensive enhanced review for every provider; simpler evidence is used for standard outsourcing; deepest review and strongest escalation are reserved for material and critical outsourcing. Cost can affect the form of the review, but not whether basic regulatory safeguards are addressed | Risk escalation and approval record |
Evidence
- due diligence record
- risk assessment
- provider evidence pack
- risk acceptance or escalation record
Relationships
- Requirements: REQ-OUT-003 Assess Outsourcing Criticality Materiality and Risk, REQ-OUT-004 Perform Service Provider Due Diligence, REQ-OUT-006 Protect Outsourced Data and Confidential Information, REQ-OUT-011 Control Sub-Outsourcing
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Controls: CTRL-OUT-002 Ensure Due Diligence and Risk Assessment Is Completed, CTRL-OUT-004 Ensure Written Agreement Contains Outsourcing Safeguards, CTRL-OUT-007 Ensure Continuity Exit and Sub-Outsourcing Safeguards Exist
- System: SYS-OUT-001 Outsourcing Register
- Publication: PUB-OUT-001 Outsourcing Risk Management Manual
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: drafted from approved manual
History
- 2026-07-25: Created procedure from the Bitkaya Outsourcing Risk Management Manual version 1.0.
- 2026-07-25: Set procedure status to implemented based on Board approval of the Outsourcing Risk Management Manual on 2026-04-16.