Purpose
Translate the VASP Ordinance into a testable BCMS requirement for agents, branches and outsourced VASP activities.
Normative
Bitkaya shall control agents, branches and outsourced activities so that customers are properly informed and Bitkaya remains responsible for compliance with the VASP Ordinance.
Descriptive
The outsourcing and third-party framework should ensure customer disclosures for agents, branches and outsourced third parties, written outsourcing agreements for structural outsourcing, information-sharing rights, CBCS access and on-site investigation rights, termination and exit arrangements, competence of service providers, prohibition of unsuitable outsourcing, and notification of material outsourcing changes where required.
Source reference: VASP Ordinance, Articles 38, 40 and 60; commencement instrument Publicatieblad A 2025 No. 91, Article 1.
Assurance Assertions
- VASP outsourcing and agency arrangements are inventoried and assessed.
- Written agreements preserve Bitkaya responsibility, CBCS access and exit rights.
- Customers are informed when agents, branches or outsourced third parties are involved.
Relationships
- Source: SRC-VASP-001 Landsverordening toezicht virtuele activa dienstverleners
- Policies: POL-ECM-001 Enterprise Compliance Manual, POL-OUT-001 Outsourcing Risk Management Manual
- Processes: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery, PRC-GRO-001 Governance Risk and Outsourcing
- Procedures: PROC-OUT-001 Classify Outsourcing Arrangement, PROC-OUT-002 Perform Outsourcing Due Diligence and Risk Assessment, PROC-OUT-003 Obtain Outsourcing Approval and CBCS Engagement, PROC-OUT-004 Review and Execute Outsourcing Agreement, PROC-OUT-005 Monitor Outsourcing Arrangement, PROC-OUT-006 Maintain Outsourcing Register and Reporting, PROC-OUT-007 Manage Outsourcing Continuity Exit and Sub-Outsourcing
- Controls: CTRL-ABC-002 Ensure Third-Party ABC Due Diligence Is Completed, CTRL-MCT-005 Ensure Client Assets and Custody Are Safeguarded, CTRL-SAFU-005 Ensure Safeguarding Providers and Continuity Are Controlled, CTRL-RMF-007 Ensure Third Party Counterparty and Resilience Risks Are Controlled, CTRL-ICA-002 Ensure Core Internal Control Coverage Is Complete, CTRL-PRIV-004 Ensure Transfers Processors and Data Agreements Are Controlled, CTRL-ODOO-006 Ensure Backup Exceptions Dependencies and Changes Are Reviewed
- Systems: not yet assigned; tracked under ISS-SAFU-001
- Issues: ISS-SAFU-001 Confirm Safeguarding Architecture Legal Protections and Operating Evidence
- Publications: pending
Assurance
- Source verified: yes
- Implementation linked: partial; outsourcing implementation is mapped while VASP-specific agent and branch coverage remains planned
- Wording unambiguous: review
History
- 2026-07-25: Created from SRC-VASP-001, including embedded commencement details.
- 2026-07-26: Added enterprise and outsourcing policy, process and procedure mappings; VASP-specific agent and branch coverage remains planned.