Objective
Ensure backup failures, provider dependencies, system changes and accepted recovery risks are identified, escalated and reviewed.
Verification Requirements
The control must verify:
- Exception handling: if backup download fails, retry once; if failure persists, notify responsible IT/Admin and log incident. If upload fails, retry upload and escalate if unresolved.
- Limitations and risk acknowledgement: monthly backups may result in potential data gaps of up to one month; this risk is accepted under the proportionality principle; additional backups may be triggered if risk profile increases.
- Additional backup triggers: high transaction periods, system changes, prior to major releases.
- Review frequency: the policy is reviewed annually, upon system changes and upon regulatory updates.
Control Activity
Operations, Technology and Compliance review open exceptions, relevant provider or system changes and backup performance quarterly and complete an annual design and proportionality review.
Evidence
- Expected evidence: Exception, incident and remediation log
- Expected evidence: Odoo and Microsoft 365 monitoring evidence
- Expected evidence: Change and additional-backup assessments
- Expected evidence: Annual review and risk-acceptance decisions
- Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository, SYS-OUT-001 Outsourcing Register; target Hermes assessment record in Odoo under ISS-HERMES-001.
- Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
- Testing method: inspect open and closed exceptions, material changes and annual review for timely escalation, accountable decisions and closure
- Testing frequency: quarterly and annual
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: documented; approval pending
History
- 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.