Purpose
Translate the CBCS IT governance guidance into a testable BCMS requirement for board-level oversight, value delivery and stakeholder communication.
Normative
Bitkaya shall maintain an IT governance framework that assigns clear board and management responsibility, aligns IT with business objectives, manages IT-related risk and supports effective communication and audit.
Descriptive
This requirement is drawn primarily from the IT Governance memorandum and the IT Framework Memorandum, including governance framework, value contribution, risk management, capability, communication and audit themes.
Source reference: Provisions and Guidelines for the Governance of Enterprise Information Technology; IT Framework Memorandum for Supervised Institutions.
Assurance Assertions
- IT governance responsibilities are defined and approved.
- IT risk, value and performance oversight are documented.
- IT governance is subject to audit and periodic review.
Relationships
- Source: SRC-IT-001 CBCS IT Governance, Security, Continuity and Testing Guidelines
- Policy: POL-IT-001 IT and Cybersecurity Manual
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Procedure: PROC-IT-001 Maintain IT Governance and Oversight
- Control: CTRL-IT-001 Ensure IT Governance and Oversight Is Maintained
- Systems: not yet assigned; tracked under ISS-TRAIN-001
- Publications: PUB-TRAIN-005 IT Compliance Training
Assurance
- Source verified: yes
- Implementation linked: yes
- Wording unambiguous: review
History
- 2026-07-26: Created from SRC-IT-001.
- 2026-07-26: Linked to the IT process, procedure and control set.
- 2026-07-26: Added the missing IT policy metadata mapping.