Objective
Ensure each outsourcing arrangement is documented in writing and includes safeguards proportionate to the service risk.
Control Activity
Before the relevant outsourcing step is completed, the responsible owner and Compliance confirm that the required evidence exists, that material gaps are escalated, and that unresolved gaps are recorded for management decision or remediation. Every outsourcing arrangement must be documented in writing. The agreement must address, in a manner appropriate to the risk of the service: service scope and responsibilities; start, renewal, end, and notice terms; service levels where relevant; confidentiality and data protection; incident notification; access and audit rights where relevant; business continuity expectations; subcontracting rules; and termination and exit support. CBCS requires written agreements that clearly set out material aspects of the arrangement and preserve access and audit rights. For large standardized providers, Bitkaya does not require every provider to accept a fully bespoke contract and may rely on standard terms, provider documentation, certifications, internal controls, and risk acceptance, as long as the arrangement remains acceptable in light of the service’s risk.
Evidence
- Expected evidence: agreement review checklist.
- Expected evidence: contract or standard terms reference.
- Expected evidence: gap assessment.
- Expected evidence: risk acceptance record.
- Evidence location: outsourcing register and related outsourcing evidence file.
- Retention: according to Bitkaya compliance record-retention requirements.
- Testing method: Review sampled contracts against required safeguard categories and confirm exceptions are documented and approved.
- Testing frequency: annual, and after material outsourcing changes where applicable.
Relationships
- Requirements: REQ-OUT-005 Execute Written Outsourcing Agreements, REQ-OUT-006 Protect Outsourced Data and Confidential Information, REQ-OUT-008 Maintain Outsourcing Business Continuity and Exit Plans, REQ-OUT-011 Control Sub-Outsourcing
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedures: PROC-OUT-004 Review and Execute Outsourcing Agreement, PROC-OUT-007 Manage Outsourcing Continuity Exit and Sub-Outsourcing
- System: SYS-OUT-001 Outsourcing Register
Assurance
Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.
- Design status: approved
History
- 2026-07-25: Created control from the Bitkaya Outsourcing Risk Management Manual version 1.0.
- 2026-07-25: Control design approved by Managing Director.