Methodology
A fieldwork rhythm supervisors recognise
Our method is built for audits for fintech institutions: map the milestone, request evidence that matches it, sample what actually runs day to day, then leave a calendar leadership can own.
-
01
Milestone scoping
We confirm whether you are preparing a licensing file, an investor diligence room, or a supervisory visit. The milestone decides the evidence map — not a generic checklist recycled from another product line.
-
02
Evidence request and intake
You receive a dated request list: policies, registers, samples, board packs, and system extracts. We note gaps early so fieldwork does not stall on missing folders.
-
03
Sampling and walkthroughs
Files and alerts are sampled by risk stratum. Walkthroughs with control owners test whether playbooks match the desks that use them. We record exceptions with enough context for remediation, not slogans.
-
04
Graded memo and closing brief
Findings carry severity grades, owners (where known), and suggested dates. The closing brief is for founders and the compliance officer together, so priorities are not lost between teams.
Boundaries
What this methodology does not include
We do not issue legal opinions, file suspicious transaction reports for you, or act as an outsourced compliance officer. Software testing, penetration tests, and financial statement attestation sit outside our audits for fintech controls work.
- No software product sales
- No continuous outsourcing
- Independent challenge only
Ready to map your next milestone?
Browse engagements or ask for a scoping call timed to your licensing or diligence date.