Purpose

Translate the CBCS computer-risk memorandum into a testable BCMS requirement for managing automation-related risks and core controls.

Normative

Bitkaya shall identify and manage computer risks affecting banking operations, including development risk, processing errors, business interruption, unauthorized disclosure, fraud and control weaknesses, through preventive, containment and audit controls.

Descriptive

This requirement captures the computer risk memorandum themes of development risk, errors, interruption, confidentiality breaches, fraud and the general classes of control and audit expected in the computer environment.

Source reference: Policy Memorandum: Management of Computer Risks.

Assurance Assertions

  • Computer risks are assessed and classified.
  • Preventive and containment controls are defined for material automation risks.
  • Inspection and audit oversight exist for computer-related controls.

Relationships

Assurance

  • Source verified: yes
  • Implementation linked: yes
  • Wording unambiguous: review

History

  • 2026-07-26: Created from SRC-IT-001.
  • 2026-07-26: Linked to the IT process, procedure and control set.
  • 2026-07-26: Added the missing IT policy metadata mapping.