Objective
Ensure the COTS governance structure, owner assignments and approval status remain current.
Control Activity
At least annually, Compliance confirms documented COTS ownership, Board review of COTS risk exposure, adequate testing resources, independent CORF challenge and Internal Audit coverage. Exceptions and remediation actions are recorded and tracked to closure.
Evidence
- Expected evidence: governance record
- Expected evidence: board or management review note
- Expected evidence: CORF challenge record
- Expected evidence: internal audit scope or assessment record
- Expected evidence: issue or remediation record where applicable
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect the annual governance package and sample evidence of challenge and follow-up
- Testing frequency: annual and after a material governance change
Relationships
- Requirements: REQ-IT-001 Maintain IT Governance and Oversight, REQ-IT-007 Maintain Software Testing and Release Assurance
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-COTS-001 Maintain COTS Governance and Oversight
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented design; runtime effectiveness pending system-derived assessment
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.