Objective
Ensure software testing and release assurance evidence exists for material changes. Testing must cover not only business functionality and security, but also the reliable operation of key compliance and control systems. Bitkaya targets TMMi (Test Maturity Model Integration) Level 2 compliance as indicated in CBCS “Provisions and Guidelines for Software Testing” (2024).
Control Activity
Review test plans, execution evidence, security testing and release approval before production use. Verify testing covers: correct onboarding workflow behaviour; integrity of identity verification integrations; accurate sanctions screening and list refresh behaviour; correct alert generation and routing; case-management traceability and workflow integrity; preservation of logs and audit trails; correct access restrictions and role permissions; and resilience of critical compliance-related interfaces and data flows. Confirm changes to compliance-related tools, rules, workflows, integrations, or critical system settings are tested before release and approvals are documented. Verify testing follows CBCS Provisions for Software Testing (2024) and TMMi Level 2 maturity expectations, scaled to Bitkaya’s operational footprint. Confirm automated testing tools and external QA reviews replace full-scale in-house testing departments. Verify focus is placed on high-risk crypto functions (wallet integrations, blockchain APIs, AML transaction filters) rather than exhaustive platform-wide testing. Escalate failed tests or unapproved releases and retain defect closure evidence.
Evidence
- Expected evidence: test plan and execution record covering compliance and control system testing (onboarding workflows, identity verification integrations, sanctions screening, alert generation, case-management traceability, audit trails, access restrictions, data flow resilience)
- Expected evidence: defect or security-test log
- Expected evidence: release approval record
- Expected evidence: TMMi Level 2 compliance evidence per CBCS Provisions for Software Testing (2024)
- Expected evidence: external QA review record where applicable
- Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample releases and confirm test and approval evidence exists. Verify compliance-related tools, rules, workflows, integrations, and critical system settings are tested before release. Confirm focus on high-risk crypto functions (wallet integrations, blockchain APIs, AML transaction filters). Check TMMi Level 2 compliance evidence.
- Testing frequency: annual and after each material release
Relationships
- Requirement: REQ-IT-007 Maintain Software Testing and Release Assurance
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-007 Maintain Software Testing and Release Assurance
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from REQ-IT-007.