Objective

Ensure board and management oversight for IT and cybersecurity remains documented, current and reviewable. Bitkaya’s IT and cybersecurity governance must support not only platform security and operational resilience, but also the integrity of regulatory and compliance control systems.

Control Activity

Review the governance owner, reporting cadence, approval status and open actions before the operating cycle closes. Verify that governance oversight includes systems and tools used for digital onboarding and identity verification, sanctions screening, blockchain analytics and transaction monitoring, internal case management and escalation, regulatory reporting support, and secure storage of due diligence, screening, and escalation records. Confirm that changes to critical compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities are subject to appropriate governance, testing, approval, and documentation controls. Verify that the Board annually reviews the IT and Cybersecurity Manual against CBCS and FATF updates. Confirm proportionality governance: Board retains ultimate accountability, IT Steering Committee reviews proportionality justifications, and Internal or Independent Audit confirms measures are appropriate. Escalate unresolved gaps and retain evidence of decisions and follow-up.

Evidence

  • Expected evidence: governance record
  • Expected evidence: board or management review note, including annual IT and Cybersecurity Manual review against CBCS and FATF updates
  • Expected evidence: proportionality determination documentation (justification based on operational risk and size, compensating controls, references to CBCS or ISO guidance)
  • Expected evidence: issue or remediation record where applicable
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample governance updates and confirm owner, approval and review dates are current. Verify that changes to compliance-related systems, screening tools, rule sets, workflows, and integrations have governance, testing, approval, and documentation controls. Confirm proportionality documentation is reviewed by the Board annually and maintained for regulatory inspection.
  • Testing frequency: annual and after material governance change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved IT and Cybersecurity Manual version 1.1

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
  • 2026-07-26: Created from REQ-IT-001.