Purpose
Classify, coordinate, escalate and remediate incidents, issues and complaints while preserving any separate legal or regulatory handling obligation.
PDF-Derived Operational Detail
Bitkaya distinguishes between incidents, issues, and complaints, while recognizing that a single event may trigger more than one of these categories.
Incidents are events that have caused, or could reasonably have caused, operational disruption, control failure, client harm, legal or regulatory exposure, financial loss, or reputational damage.
Issues are identified weaknesses, deficiencies, or gaps in controls, governance, documentation, systems, staffing, or procedures that require remediation.
Complaints are expressions of dissatisfaction from clients or other stakeholders that require fair assessment and response under the complaints framework.
Where relevant, matters should also be assessed for separate handling under AML/CTF/CPF escalation, sanctions procedures, safeguarding procedures, cybersecurity response, or regulatory communication requirements.
Internal classification for management purposes does not replace any separate legal or regulatory obligation to report, escalate, restrict, or remediate.
Steps
- Record the event, source, time, owner, affected clients, systems, assets and processes.
- Classify it as an incident (operational disruption, control failure, client harm, legal/regulatory exposure, financial loss, reputational damage), an issue (weakness, deficiency, or gap in controls, governance, documentation, systems, staffing, or procedures), a complaint (expression of dissatisfaction from clients or stakeholders), or multiple categories and assess severity and urgency.
- Contain immediate harm and preserve records.
- Determine whether AML/CTF/CPF escalation, sanctions procedures, safeguarding procedures, cybersecurity response, regulatory communication, or other separate obligations also apply. Internal classification for management purposes does not replace any separate legal or regulatory obligation to report, escalate, restrict, or remediate.
- Notify accountable owners and escalate material events to management, the Board or regulator as required.
- Investigate cause, impact, control failure and recurrence risk.
- Define remediation, compensation, communication, reporting and monitoring actions.
- Track actions to evidence-based closure and update risk assessments and controls.
- Review trends and repeat events for systemic weakness.
Exceptions and Escalation
Internal classification shall never delay a mandatory report, restriction, client-protection action or regulatory communication.
Records
- Incident, issue and complaint record
- Severity and applicability assessment
- Containment, investigation and root cause
- Communications, reporting and decisions
- Remediation and closure evidence
Relationships
- Policy: POL-RMF-001 Risk Management Framework Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Control: CTRL-RMF-006 Ensure Incidents Issues and Complaints Are Coordinated
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Frequency: continuous and event-driven
History
- 2026-07-26: Created from section 8 of the approved RMF.