Field Notes
What Taiwanese supervisors usually ask first in a fintech file review
When a supervisory team sits down with a payment or lending fintech in Taiwan, the first hour rarely opens with exotic product questions. It opens with ownership of the control environment: who signed the latest risk assessment, when the board last reviewed the AML programme, and whether the documented thresholds match the rules still running in production.
Start with governance artefacts
Bring the current board and risk committee packs, not last year’s glossy summary. Supervisors compare dates on minutes against the effective dates on policies. A three-month lag between a threshold change and a board note is a common tripwire, even when the change itself was sensible.
Then follow a live case
Expect a request to walk one monitoring alert from generation to closure. Strong case notes explain why the risk was accepted or escalated; weak ones simply paste system fields. If your analysts rely on tribal knowledge, that gap shows up quickly under questioning.
Close with remediation honesty
Open findings from prior reviews should appear with owners and dates. Hiding unfinished items until asked creates more friction than admitting a delayed control fix with a clear plan. In our readiness audits we often rebuild this narrative before the visit so leadership is not improvising under the clock.