Purpose
Translate the CBCS outsourcing guideline into a testable BCMS requirement for outsourcing governance and control.
Normative
Bitkaya shall develop, implement and maintain an outsourcing policy that defines the principles, responsibilities, lifecycle processes and contract expectations used to manage outsourcing risk.
Descriptive
The policy should cover planning, identification of critical or essential functions, risk assessment, due diligence, conflict management, business continuity, approval, implementation, monitoring, record-keeping, renewal, termination and exit planning.
Source reference: CBCS Guideline on Outsourcing, Article 1, Article 4 and Appendix 3.
Assurance Assertions
- An approved outsourcing policy exists and is maintained.
- The policy covers the outsourcing lifecycle and distinguishes critical or essential outsourcing from other arrangements.
- Policy ownership, approval and review responsibilities are defined.
Relationships
- Source: SRC-OUT-001 CBCS Guideline for the Sound Management of Outsourcing
- Policies: POL-OUT-001 Outsourcing Risk Management Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedure: PROC-ECM-003 Review Approve and Publish Compliance Manuals
- Controls: not yet assigned; tracked under ISS-OUT-001
- Systems: not yet assigned; tracked under ISS-OUT-001
- Publications: PUB-OUT-001 Outsourcing Risk Management Manual
- Issues: ISS-OUT-001 Complete Outsourcing Operating Artifacts and Evidence
Assurance
- Source verified: yes
- Implementation linked: yes; remaining operational follow-up is tracked in ISS-OUT-001 where applicable
- Wording unambiguous: approved
History
- 2026-07-25: Created from SRC-OUT-001.
- 2026-07-25: Linked outsourcing operational implementation objects derived from the Bitkaya outsourcing manual.
- 2026-07-25: Approved outsourcing requirement for BCMS use.
- 2026-07-26: Linked the enterprise procedure governing review, approval and publication of the outsourcing policy.