Objective
Ensure technology change, acquisition and outsourced IT services remain approved and traceable. Bitkaya integrates IT areas into a VASP-specific framework that includes Third-Party Risk Management (custody, cloud, fintech partners) and outsourced services.
Control Activity
Review change requests, risk assessments, approvals and third-party records before implementation or renewal. Verify changes to critical compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities are subject to appropriate governance, testing, approval, and documentation controls. Confirm that where an incident or change could impair Bitkaya’s ability to perform onboarding, sanctions screening, transaction monitoring, or escalation handling, Compliance is informed as appropriate. For outsourced non-core technical services (penetration testing, vulnerability scanning), verify reliance on certified providers with vendor oversight rather than in-house duplication. Verify the request falls within the VASP-specific IT framework (Crypto Custody and Key Management, Information Security ISO 27001, Business Continuity ISO 22301, IT Governance COBIT, IT Service Management ISO 20000/ITIL v3, AML/CFT and FATF Compliance, Third-Party Risk Management). Escalate unapproved changes or unmanaged supplier risk and retain the supporting evidence.
Evidence
- Expected evidence: change or acquisition request
- Expected evidence: approval or due diligence record
- Expected evidence: vendor oversight record for outsourced services (certified providers for penetration testing, vulnerability scanning)
- Expected evidence: change governance record for compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities
- Expected evidence: Compliance notification record where changes affect AML/CTF/CPF capabilities
- Expected evidence: outsourcing or supplier record where relevant
- Evidence location: source evidence in SYS-KYT-001 Crystal Intelligence Blockchain Analytics, SYS-IT-001 Odoo Automated Compliance Monitoring; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: sample changes and third-party arrangements and confirm approval evidence exists. Verify changes to compliance-related systems, screening tools, rule sets, workflows, integrations, and case-management capabilities have governance, testing, approval, and documentation controls. Check vendor oversight for outsourced services. Confirm Compliance notification where AML/CTF/CPF capabilities are affected.
- Testing frequency: annual and after material technology change
Relationships
- Requirement: REQ-IT-008 Manage Technology Change Acquisition and Outsourced IT Services
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-008 Manage Technology Change Acquisition and Outsourced IT Services
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: implemented from approved IT and Cybersecurity Manual version 1.1
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
- 2026-07-26: Created from REQ-IT-008.