PDF-Derived Verification Requirements

The PDF requires stress testing and scenario analysis to assess the resilience of the business model, control environment, and decision-making under adverse conditions. Specific scenario types: severe cyber incidents; safeguarding or custody failures; sanctions true-match scenarios affecting operations or assets; material transaction-monitoring or screening failures; third-party or vendor outages; banking or settlement disruption; operational fraud scenarios; and significant regulatory or supervisory intervention scenarios. The purpose is not only to test continuity, but also to test the adequacy of escalation, governance, communication, regulatory handling, and remediation decision-making. At Bitkaya’s current scale, scenarios are simplified but realistic, covering core exposures such as custody breach, liquidity stress, and sanctions incidents. External subject-matter experts may be engaged for validation instead of maintaining a large in-house stress testing team.

Objective

Ensure severe but plausible material-risk scenarios test resilience, escalation, governance, communication, regulatory handling, and remediation decision-making — not just continuity.

Control Activity

Risk and Compliance coordinate an annual risk-based scenario program, record results and require accountable remediation and retesting of material weaknesses. The program must cover: severe cyber incidents; safeguarding or custody failures; sanctions true-match scenarios affecting operations or assets; material transaction-monitoring or screening failures; third-party or vendor outages; banking or settlement disruption; operational fraud scenarios; and significant regulatory or supervisory intervention scenarios. At Bitkaya’s current scale, scenarios are simplified but realistic, and external subject-matter experts may be engaged for validation.

Evidence

  • Expected evidence: Scenario plan covering all required types (severe cyber incidents; safeguarding or custody failures; sanctions true-match scenarios; material transaction-monitoring or screening failures; third-party or vendor outages; banking or settlement disruption; operational fraud scenarios; significant regulatory or supervisory intervention scenarios), with assumptions and criteria
  • Expected evidence: Exercise attendance and decisions, including escalation, governance, communication, regulatory handling, and remediation decision-making
  • Expected evidence: Results and impact assessment
  • Expected evidence: Reporting, remediation and retest
  • Evidence location: source evidence in SYS-ECM-002 Compliance Reporting and Evidence Repository; target Hermes assessment record in Odoo under ISS-HERMES-001.
  • Retention: according to the applicable approved policy and Bitkaya record-retention requirements.
  • Testing method: inspect the annual program for risk coverage (all required scenario types), escalation/governance/communication/regulatory handling adequacy, and sample actions for ownership, timely closure and retest
  • Testing frequency: annual and after material incident or change

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Design status: implemented

History

  • 2026-07-26: Normalized evidence metadata and separated design status from runtime effectiveness.
  • 2026-07-26: Created from the approved RMF version 1.1.