Objective
Ensure e-banking risk management, customer security and transparency controls remain documented and current. Systems supporting client authentication, transaction execution, wallet interaction, and digital onboarding must operate in a secure and controlled manner.
Control Activity
Review e-banking risk assessments, countermeasures, internal control and customer-protection evidence. Verify that where e-banking systems interface with AML/CTF/CPF or sanctions controls: customer and privileged access controls are appropriately designed; sensitive onboarding and screening data is encrypted and protected; anomalous activity is monitored and escalated; transaction controls support sanctions and monitoring requirements where applicable; and outages or control failures affecting digital channels are assessed for compliance and regulatory impact. Escalate unresolved cross-border or customer-security issues and retain approval records.
Evidence
- Expected evidence: e-banking risk review
- Expected evidence: customer-security or transparency record
- Expected evidence: encryption and access control evidence for onboarding and screening data
- Expected evidence: anomalous activity monitoring and escalation record
- Expected evidence: outage or control failure compliance impact assessment
- Expected evidence: escalation or remediation record where relevant
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample e-banking updates and confirm risk and control evidence exists. Verify customer and privileged access controls are designed appropriately. Confirm sensitive onboarding and screening data is encrypted. Check anomalous activity monitoring and escalation. Verify outage or control failure compliance impact assessments are performed.
- Testing frequency: annual and after material e-banking change
Relationships
- Requirement: REQ-IT-004 Maintain Safe and Sound Electronic Banking
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-004 Maintain Safe and Sound Electronic Banking
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from REQ-IT-004.