Objective

Ensure provider due diligence and outsourcing risk assessment are completed before engagement and after material change.

Control Activity

Before the relevant outsourcing step is completed, the responsible owner and Compliance confirm that the required evidence exists, that material gaps are escalated, and that unresolved gaps are recorded for management decision or remediation. The review must be proportionate to the nature, scale, and risk of the arrangement: for standard outsourcing the review may be simple; for material outsourcing it must be more deliberate; for critical or essential outsourcing it must be more complete and clearly documented. The assessment must consider, where relevant: what the provider does; how important the service is; legal existence and registration; reputation and integrity; financial soundness; technical capability and staffing; information security and resilience; subcontracting; confidentiality and data protection; concentration risk; and whether the service can be replaced or reintegrated. CBCS requires due diligence and risk assessment before outsourcing and in case of material change. For standardized large providers such as Microsoft, AWS, Google, or similar, Bitkaya may rely on provider standard terms, platform documentation, certifications, audit reports, internal controls, restricted use cases, and formal internal approval. CBCS permits pooled audits, third-party certifications, and audit reports, although critical or essential outsourcing should not rely only on these sources over time. Cost can affect the form of the review, but not whether basic regulatory safeguards are addressed.

Evidence

  • Expected evidence: due diligence record.
  • Expected evidence: risk assessment.
  • Expected evidence: provider certifications or assurance reports.
  • Expected evidence: risk acceptance record.
  • Evidence location: outsourcing register and related outsourcing evidence file.
  • Retention: according to Bitkaya compliance record-retention requirements.
  • Testing method: Sample arrangements and confirm risk-based due diligence evidence exists and residual gaps were approved.
  • Testing frequency: annual, and after material outsourcing changes where applicable.

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: approved

History

  • 2026-07-25: Created control from the Bitkaya Outsourcing Risk Management Manual version 1.0.
  • 2026-07-25: Control design approved by Managing Director.