Objective

Ensure computer risk classification and control design remain in place for material automation risks. Bitkaya’s IT and cyber risk management includes risks arising from compromise, failure, misuse, misconfiguration, or poor governance of systems that support AML/CTF/CPF, sanctions, onboarding, case handling, and regulatory reporting.

Control Activity

Review identified development, processing, interruption, confidentiality and fraud risks. Verify the risk register covers: unauthorized access to onboarding, screening, or monitoring systems; improper changes to screening logic, alert settings, or workflow rules; loss or corruption of client due diligence, sanctions, or case data; failure of list refresh or screening integrations; insufficient logging of critical user activity; exposure of compliance-sensitive documents or records; over-reliance on third-party tooling without appropriate validation; and operational disruption affecting compliance control execution. Confirm controls are proportionate to the materiality of the system and include strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery measures. Confirm preventive and containment controls exist and that issues are escalated and tracked. Where risks could impair onboarding, sanctions screening, transaction monitoring, or escalation handling, verify Compliance is informed.

Evidence

  • Expected evidence: computer-risk assessment including AML/CTF/CPF, sanctions, onboarding, case handling, and regulatory reporting risk categories
  • Expected evidence: control design or testing record evidencing strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery measures
  • Expected evidence: remediation or escalation record where needed
  • Expected evidence: Compliance notification record where risks affect AML/CTF/CPF capabilities
  • Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: sample computer-risk updates and confirm control evidence exists. Verify risk register covers all relevant risk categories (unauthorized access, screening logic changes, data loss, integration failures, logging gaps, exposure of sensitive records, third-party over-reliance, operational disruption). Confirm controls are proportionate and include strong authentication, least-privilege access, logging, change governance, vendor oversight, and backup/recovery.
  • Testing frequency: annual and after material automation change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented from approved IT and Cybersecurity Manual version 1.1

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from REQ-IT-005.