Objective

Ensure disruptions are assessed, escalated and managed under documented activation and communication arrangements.

Control Activity

For each material disruption, the incident lead records activation, role assignments, decisions, actions, service status, Board escalation and any required CBCS notification. The control verifies that activation criteria thresholds are documented (system outage, breach, natural disaster), an Incident Response Team (IRT) with leads in IT, compliance, operations, and communications is convened, escalation procedures follow clear pathways from departmental level to Board-level decision-making, and regulatory obligations include immediate notification to CBCS. Communications must use the designated Communications Officer as spokesperson, with internal communication via secure chat, call trees, SMS alerts, email groups; external communication via customer notifications, regulator reporting, media updates; and alternate modes including satellite phones, handheld radios, WhatsApp/Teams groups. Compliance verifies quarterly that communication call-trees are updated and tested.

Evidence

  • Expected evidence: Incident and activation log
  • Expected evidence: Incident response team assignments
  • Expected evidence: Decision, action and communication records
  • Expected evidence: Board and CBCS notifications
  • Expected evidence: Quarterly call-tree test
  • Evidence location: source evidence in SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: inspect incidents for complete activation and escalation records and verify a quarterly communication test
  • Testing frequency: per material incident and quarterly for call trees

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved Business Continuity Manual version 1.0.