Methodology

How an audit for fintech controls actually runs

This page walks the delivery model behind our engagements: scoping, fieldwork, severity, and the evidence pack you take into supervisory conversations.

  1. Scope against the license. We map product lines, corridors, and regulatory touchpoints before writing a document request. Scope creep is recorded as a change order, not absorbed silently.
  2. Name a document liaison. One person gathers policies, board packs, KYC extracts, and monitoring inventories so versions do not multiply mid-fieldwork.
  3. Agree severity before testing. Critical, high, medium, and low definitions are written into the engagement letter so later debates stay factual.
  4. Sample with intent. KYC files, alerts, and settlement breaks are selected to test written rules under volume pressure—not to fill a neat percentage.
  5. Validate with owners. Draft findings are walked with control owners before the board sees them. Factual corrections are welcome; severity lobbying is recorded.
  6. Deliver the pack. Final report, remediation owners, and supporting exhibits ship together so compliance is not left assembling a binder overnight.
Auditor annotating control testing worksheets

What we refuse

We will not rate our own remediation work in the same period. We will not soft-write findings to protect a sales relationship. We will not compress a multi-corridor readiness review into a two-week tour that only skims policies.

If those boundaries do not fit your timeline, we will say so early rather than deliver a thin report.

View engagements Request a brief

Artifacts you should expect

Engagement letter

Scope, independence terms, severity scale, deposit, and fieldwork dates in one signed document.

Document request list

Versioned list of policies, packs, extracts, and access needed before day one of fieldwork.

Findings report

Issue statements with evidence references, severity, and named remediation owners.