Methodology

How a control engagement moves from scoping call to findings memo

This page is the practical map behind our audits for fintech operators. It is not a product tour—it is the sequence your finance coordinator will recognise once fieldwork starts.

Open notebooks and printed schedules used during audit planning
  1. Scoping call

    We confirm the legal entity, product line, reporting period, and whether the deliverable is a full control memo, a settlement-only report, or a board briefing. You leave with a draft document request, not a vague promise to “look around.”

  2. Evidence room setup

    Your coordinator gathers reconciliations, approval matrices, exception logs, and custody or float reports into labelled folders by rail. We refuse to begin sampling from a shared drive dump without an index.

  3. Walkthroughs

    Short interviews with the people who post and approve. We ask what happens when a partner file is late, who holds the force-post authority, and how suspense items age.

  4. Sampling & exception analysis

    We select ordinary days, month-end, and stress windows. Each exception is tied to population, sample, and residual risk language before it enters the draft memo.

  5. Factual clearance & closing

    Management reviews facts for accuracy. We then deliver the ranked memo and a closing briefing. Remediation ownership stays with your team; we can return later for a follow-up check.

What we deliberately do not do here

  • Statutory financial statement audits
  • Source-code or penetration testing
  • Software implementation or “control platform” sales

Those boundaries keep the methodology honest. If your need sits outside them, we will say so on the scoping call.

Ready to place an engagement on the calendar?

Start with the flagship Fintech Control Audit, or choose a narrower settlement or follow-up assignment if that matches your constraint.