Purpose

Translate the CBCS outsourcing guideline into a testable BCMS requirement for outsourcing governance and control.

Normative

Bitkaya shall assess the criticality, materiality and risk of outsourcing arrangements before entering into them and whenever material changes occur.

Descriptive

The assessment should consider complexity, materiality, operational impact, customer impact, data sensitivity, ICT and cyber risk, concentration risk, conflicts of interest, jurisdictional risk, business continuity impact and the ability to maintain regulatory compliance.

Source reference: CBCS Guideline on Outsourcing, Article 2, Article 3, Article 15 and Appendix 4.

Assurance Assertions

  • Each outsourcing arrangement has a documented criticality or materiality assessment.
  • Risk assessment is completed before approval and refreshed after material changes.
  • The assessment covers data, ICT, operational, legal, compliance, reputational and concentration risks.

Relationships

Assurance

  • Source verified: yes
  • Implementation linked: yes; remaining operational follow-up is tracked in ISS-OUT-001 where applicable
  • Wording unambiguous: approved

History

  • 2026-07-25: Created from SRC-OUT-001.
  • 2026-07-25: Linked outsourcing operational implementation objects derived from the Bitkaya outsourcing manual.
  • 2026-07-25: Approved outsourcing requirement for BCMS use.