Methodology

How we structure a fintech control engagement

A transparent sequence from scoping workshop to graded management letter — designed so finance sponsors know what access and hours we will need.

Professionals reviewing printed reports in a meeting

Scoping workshop

We map product flows, licensing status, and the control areas under review with your finance and compliance leads. Sample sizes, on-site days, and report recipients are written into the engagement letter before fieldwork starts.

Sample design

Selection rules are fixed in advance and stratified by product, corridor, and exception flag. We avoid mid-test rule changes; unexpected issues open a separately labelled inquiry sample.

Fieldwork

Walkthroughs sit with operations and finance. We retrace reconciliations, approval matrices, and exception escalations against your documented policies, collecting working papers that an outsider can follow.

Findings discussion

Draft observations are graded and shared with management before the letter is final. Factual corrections are welcome; severity grades remain our independent judgement.

Reporting and handover

You receive a management letter, findings register with owners and target dates, and a short board summary in English. Optional follow-up can verify remediation on closed high findings.

What we need from you

  • A named finance sponsor with weekly availability during fieldwork
  • Reconciliation packs for the agreed lookback period
  • Organisation charts and current policy versions
  • Read-only access to transaction extracts under NDA

Where this method fits

The sequence underpins our Fintech Control Audit and adapts for shorter AML assessments and licence readiness reviews. Diligence support compresses the same discipline into a data-room sprint.