Purpose
Confirm each outsourcing arrangement is documented in writing and includes safeguards proportionate to the risk of the outsourced service.
Scope
This procedure applies to outsourcing arrangements and material changes to outsourcing arrangements as defined in the Bitkaya Outsourcing Risk Management Manual.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Confirm the agreement or standard terms identify service scope and responsibilities | Every outsourcing arrangement must be documented in writing | Agreement review checklist |
| 2 | Review start, renewal, end, and notice terms, and service levels where relevant | — | Terms review note |
| 3 | Review confidentiality and data protection, and incident notification terms | — | Confidentiality and incident terms review |
| 4 | Review access and audit rights where relevant, business continuity expectations, subcontracting rules, and termination and exit support terms | CBCS requires written agreements that clearly set out material aspects of the arrangement and preserve access and audit rights | Access, audit, continuity, subcontracting and exit terms review |
| 5 | For large standardized providers, document where Bitkaya relies on a combination of standard terms, provider documentation, certifications, internal controls, and risk acceptance | Bitkaya does not require every provider to accept a fully bespoke contract, as long as the arrangement remains acceptable in light of the service’s risk | Standard terms reliance and risk acceptance record |
| 6 | Escalate important gaps for risk acceptance before execution | Any important gap in a material or critical arrangement must be documented, assessed, and approved at the appropriate level | Gap escalation and risk acceptance record |
| 7 | Store the signed agreement or approved standard terms reference in the evidence file | — | Signed agreement or standard terms reference in evidence file |
Evidence
- agreement review checklist
- contract or standard terms reference
- risk acceptance record
- signed or approved agreement evidence
Relationships
- Requirements: REQ-OUT-005 Execute Written Outsourcing Agreements, REQ-OUT-006 Protect Outsourced Data and Confidential Information, REQ-OUT-008 Maintain Outsourcing Business Continuity and Exit Plans, REQ-OUT-011 Control Sub-Outsourcing
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Controls: CTRL-OUT-004 Ensure Written Agreement Contains Outsourcing Safeguards, CTRL-OUT-007 Ensure Continuity Exit and Sub-Outsourcing Safeguards Exist
- System: SYS-OUT-001 Outsourcing Register
- Publication: PUB-OUT-001 Outsourcing Risk Management Manual
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: drafted from approved manual
History
- 2026-07-25: Created procedure from the Bitkaya Outsourcing Risk Management Manual version 1.0.
- 2026-07-25: Set procedure status to implemented based on Board approval of the Outsourcing Risk Management Manual on 2026-04-16.