Purpose
Assess resilience, escalation and decision-making under severe but plausible adverse conditions.
PDF-Derived Operational Detail
Stress testing and scenario analysis help Bitkaya assess the resilience of its business model, control environment, and decision-making under adverse conditions.
Specific scenario types include: severe cyber incidents; safeguarding or custody failures; sanctions true-match scenarios affecting operations or assets; material transaction-monitoring or screening failures; third-party or vendor outages; banking or settlement disruption; operational fraud scenarios; and significant regulatory or supervisory intervention scenarios.
The purpose is not only to test continuity, but also to test the adequacy of escalation, governance, communication, regulatory handling, and remediation decision-making.
Proportionality. At Bitkaya’s current scale, scenarios are simplified but realistic, covering core exposures such as custody breach, liquidity stress, and sanctions incidents. External subject-matter experts may be engaged for validation instead of maintaining a large in-house stress testing team.
Steps
- Select risk-based scenarios covering: severe cyber incidents; safeguarding or custody failures; sanctions true-match scenarios affecting operations or assets; material transaction-monitoring or screening failures; third-party or vendor outages; banking or settlement disruption; operational fraud scenarios; and significant regulatory or supervisory intervention scenarios.
- Define assumptions, severity, duration, affected functions, dependencies and expected decisions.
- Establish objectives and success criteria for resilience, communication, escalation, client protection and remediation. The purpose is not only to test continuity, but also to test the adequacy of escalation, governance, communication, regulatory handling, and remediation decision-making.
- Conduct a proportionate tabletop, simulation, data analysis or specialist review. At Bitkaya’s current scale, scenarios are simplified but realistic; external subject-matter experts may be engaged for validation.
- Record participant decisions, timing, information gaps, control failures and cross-framework dependencies.
- Assess financial, operational, client, legal, regulatory and reputational impact.
- Define corrective actions, owners and due dates.
- Report material results to management and the Board and track remediation to verified closure.
- Update continuity plans, controls, scenarios and risk assessments.
Exceptions and Escalation
Significant unresolved weakness shall be treated as a current risk issue and may require restrictions or interim controls before normal activity continues.
Records
- Scenario selection and assumptions
- Exercise plan and attendance
- Decisions, observations and results
- Management and Board reporting
- Remediation and retest evidence
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Control: CTRL-RMF-004 Ensure Material Risk Scenarios Are Tested
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: annual and after material change or incident
History
- 2026-07-26: Created from section 6 of the approved RMF.