Purpose

Assess provider suitability and outsourcing risk before Bitkaya commits to an outsourcing arrangement or accepts a material change.

Scope

This procedure applies to outsourcing arrangements and material changes to outsourcing arrangements as defined in the Bitkaya Outsourcing Risk Management Manual.

Steps

#ActionDetailsEvidence
1Identify the service scope, provider, service location and data location where relevantDetermine what the provider does and how important the service is to BitkayaService scope and provider profile note
2Assess provider legal existence and registration, reputation and integrity, financial soundness, technical capability and staffing—Provider due diligence evidence pack
3Assess confidentiality and data protection, information security and resilience, concentration risk, and whether the service can be replaced or reintegrated if necessary—Risk assessment record
4Review subcontracting permissions and provider oversight arrangements—Subcontracting review note
5For standardized large providers such as Microsoft, AWS, Google, or similar providers, collect proportionate evidence from a combination of: provider standard terms; platform documentation; certifications; audit reports; internal controls; restricted use cases; and formal internal approvalBitkaya recognizes that not all contractual terms will be negotiable. CBCS permits use of pooled audits, third-party certifications, and audit reports, although critical or essential outsourcing should not rely only on these sources over timeCollected provider evidence pack
6Document residual gaps, risk acceptances and compensating internal controlsThe review should be proportionate to the nature, scale, and risk of the arrangement: for standard outsourcing the review may be simple; for material outsourcing it must be more deliberate; for critical or essential outsourcing it must be more complete and clearly documentedResidual gap and risk acceptance record
7Escalate material or critical residual risks for approval before engagementCBCS requires due diligence and risk assessment before outsourcing and in case of material change. Bitkaya does not perform expensive enhanced review for every provider; simpler evidence is used for standard outsourcing; deepest review and strongest escalation are reserved for material and critical outsourcing. Cost can affect the form of the review, but not whether basic regulatory safeguards are addressedRisk escalation and approval record

Evidence

  • due diligence record
  • risk assessment
  • provider evidence pack
  • risk acceptance or escalation record

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: drafted from approved manual

History

  • 2026-07-25: Created procedure from the Bitkaya Outsourcing Risk Management Manual version 1.0.
  • 2026-07-25: Set procedure status to implemented based on Board approval of the Outsourcing Risk Management Manual on 2026-04-16.