Objective
Ensure Odoo backup scope, responsibilities, frequency, retention, recovery objectives and accepted data-loss exposure are documented and approved.
Verification Requirements
The control must verify that the approved strategy documents:
- The scope: Odoo SaaS database and filestore, client (KYC/KYB) data, transaction and financial records, operational and administrative data.
- The responsibility split: Odoo SaaS provides automatic daily backups, internal redundancy and short-term recovery (managed by Odoo, not directly controlled by Bitkaya, not a standalone compliance backup solution); Bitkaya is responsible for independent backup control, long-term retention, regulatory compliance and data recovery capability.
- The proportionality principle: backup volume and frequency reflect business size, transaction volume and risk exposure; Odoo daily backups mitigate short-term operational risk; Bitkaya external backups mitigate vendor dependency risk, data loss scenarios and audit/regulatory requirements; the approach balances operational efficiency, cost and compliance obligations.
- The accepted data-loss exposure: monthly backups may result in potential data gaps of up to one month, accepted under the proportionality principle; additional backups may be triggered if the risk profile increases.
- Review triggers: annually, upon system changes and upon regulatory updates.
Control Activity
Operations, Technology, Compliance and the continuity owner review the backup strategy annually and after material change; the accountable authority approves recovery objectives and residual risk.
Evidence
- Expected evidence: Responsibility matrix and backup scope
- Expected evidence: BIA, recovery objectives and risk assessment
- Expected evidence: Frequency, retention and provider-dependency rationale
- Expected evidence: Risk acceptance and approval
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect current strategy for complete responsibilities, BIA alignment, approved recovery exposure and annual review
- Testing frequency: annual and after material change
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: documented; approval pending
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.