Purpose
Translate the CBCS outsourcing guideline into a testable BCMS requirement for outsourcing governance and control.
Normative
Bitkaya shall perform and document risk-based due diligence before selecting an outsourcing service provider and during ongoing monitoring of the provider.
Descriptive
Due diligence should address the provider reputation, expertise, capacity, financial and organizational resources, infrastructure, regulatory status, data protection controls, AML/CFT/CFP considerations where relevant, jurisdictional risks and reliance on subcontractors.
Source reference: CBCS Guideline on Outsourcing, Article 6, Article 11, Article 12, Article 13, Article 14 and Appendix 4.
Assurance Assertions
- Due diligence is completed before onboarding a service provider.
- Due diligence evidence supports the provider selection decision.
- Due diligence is refreshed during monitoring or when relevant changes occur.
Relationships
- Source: SRC-OUT-001 CBCS Guideline for the Sound Management of Outsourcing
- Policies: POL-OUT-001 Outsourcing Risk Management Manual
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedures: PROC-OUT-002 Perform Outsourcing Due Diligence and Risk Assessment
- Controls: CTRL-OUT-002 Ensure Due Diligence and Risk Assessment Is Completed
- Systems: SYS-OUT-001 Outsourcing Register
- Publications: PUB-OUT-001 Outsourcing Risk Management Manual
- Issues: ISS-OUT-001 Complete Outsourcing Operating Artifacts and Evidence
Assurance
- Source verified: yes
- Implementation linked: yes; remaining operational follow-up is tracked in ISS-OUT-001 where applicable
- Wording unambiguous: approved
History
- 2026-07-25: Created from SRC-OUT-001.
- 2026-07-25: Linked outsourcing operational implementation objects derived from the Bitkaya outsourcing manual.
- 2026-07-25: Approved outsourcing requirement for BCMS use.