Objective

Ensure the COTS governance structure, owner assignments and approval status remain current.

Control Activity

At least annually, Compliance confirms documented COTS ownership, Board review of COTS risk exposure, adequate testing resources, independent CORF challenge and Internal Audit coverage. Exceptions and remediation actions are recorded and tracked to closure.

Evidence

  • Expected evidence: governance record
  • Expected evidence: board or management review note
  • Expected evidence: CORF challenge record
  • Expected evidence: internal audit scope or assessment record
  • Expected evidence: issue or remediation record where applicable
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: inspect the annual governance package and sample evidence of challenge and follow-up
  • Testing frequency: annual and after a material governance change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented design; runtime effectiveness pending system-derived assessment

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from the approved COTS manual and mapped to CBCS-derived IT requirements.