Objective
Ensure IT continuity plans, tests and review records remain current for critical services. Bitkaya’s continuity arrangements must cover the continued or recoverable operation of critical compliance and control systems, including onboarding, sanctions screening, transaction monitoring, case management, and secure access to supporting records.
Control Activity
Review business impact analysis, continuity plans, tests and lessons learned. Verify that business continuity planning ensures that, during a disruption, Bitkaya can still: restrict or delay onboarding where screening cannot be completed reliably; preserve and access sanctions and monitoring data; escalate material alerts and incidents appropriately; maintain secure records of ongoing investigations or reporting decisions; and support legal or regulatory response expectations. Confirm resilience planning considers the operational dependency of the compliance framework on IT systems and external vendors. Verify Bitkaya applies CBCS 2021 BCM principles and ISO 22301 framework scaled to its startup profile. Confirm a single integrated BCP/DRP is maintained (not multiple departmental subplans). Verify testing is proportionate: tabletop exercises and crypto-specific simulations (wallet access outage, cloud provider disruption) are conducted annually. Confirm the BCM Coordinator (part of the Compliance function) ensures resilience and readiness with escalation to the Board. Escalate failed tests or overdue reviews and retain approval and remediation evidence.
Evidence
- Expected evidence: continuity plan or test record, including annual tabletop exercises and crypto-specific simulations (wallet access outage, cloud provider disruption)
- Expected evidence: single integrated BCP/DRP (not multiple departmental subplans)
- Expected evidence: business impact analysis
- Expected evidence: BCM Coordinator escalation record to Board where applicable
- Expected evidence: remediation or lessons-learned record where needed
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample continuity updates and confirm plans, tests and review evidence exist. Verify the BCP/DRP is a single integrated plan. Confirm annual tabletop exercises and crypto-specific simulations are conducted. Check that continuity planning covers onboarding restrictions, sanctions/monitoring data preservation, alert escalation, secure records, and legal/regulatory response during disruption.
- Testing frequency: annual and after material continuity change
Relationships
- Requirement: REQ-IT-006 Maintain Business Continuity Management
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-006 Maintain Business Continuity Management
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Added the evidence-system relationship required for Hermes assessment mapping.
- 2026-07-26: Created from REQ-IT-006.