Objective
Ensure IT service management arrangements for support, assets, configuration, backup and restore remain in place. Critical IT services include not only custody, wallet, and trading infrastructure, but also compliance-related systems supporting onboarding, sanctions screening, transaction monitoring, internal case handling, and regulatory support.
Control Activity
Review service levels, asset and configuration records, backup and restore evidence and supplier issues. Verify that incidents affecting critical services are logged centrally and assessed for operational, security, compliance, and regulatory impact. Confirm change management applies to material updates involving: compliance system configuration; screening tools or list sources; monitoring logic or rule tuning; case-management workflow changes; access rights to sensitive compliance systems; and integrations that affect alerting, screening, or documentation. Verify that where an incident or change could impair Bitkaya’s ability to perform onboarding, sanctions screening, transaction monitoring, or escalation handling, Compliance is informed as appropriate. Confirm ITSM aligns with CBCS 2014 ITSM provisions with a lean and automated structure. Verify incident and change management processes are centralized in a single system managed by the IT and Compliance function. Confirm RPO/RTO metrics are proportionate to Bitkaya’s cloud-based architecture. Escalate material service weaknesses and retain support evidence.
Evidence
- Expected evidence: service review record
- Expected evidence: asset or configuration record
- Expected evidence: backup or restore record
- Expected evidence: incident log with operational, security, compliance, and regulatory impact assessment
- Expected evidence: change management record for material updates to compliance systems, screening tools, monitoring logic, and integrations
- Expected evidence: Compliance notification record where incidents or changes affect AML/CTF/CPF capabilities
- Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample service management updates and confirm service and recovery evidence exists. Verify incidents are logged centrally with impact assessments. Confirm change management covers compliance system configuration, screening tools, monitoring logic, case-management workflows, access rights, and integrations. Check Compliance notification where AML/CTF/CPF capabilities are affected.
- Testing frequency: annual and after material service change
Relationships
- Requirement: REQ-IT-003 Maintain IT Service Management
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-003 Maintain IT Service Management
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from REQ-IT-003.