Methodology
How a control engagement moves from scoping call to findings memo
This page is the practical map behind our audits for fintech operators. It is not a product tour—it is the sequence your finance coordinator will recognise once fieldwork starts.
-
Scoping call
We confirm the legal entity, product line, reporting period, and whether the deliverable is a full control memo, a settlement-only report, or a board briefing. You leave with a draft document request, not a vague promise to “look around.”
-
Evidence room setup
Your coordinator gathers reconciliations, approval matrices, exception logs, and custody or float reports into labelled folders by rail. We refuse to begin sampling from a shared drive dump without an index.
-
Walkthroughs
Short interviews with the people who post and approve. We ask what happens when a partner file is late, who holds the force-post authority, and how suspense items age.
-
Sampling & exception analysis
We select ordinary days, month-end, and stress windows. Each exception is tied to population, sample, and residual risk language before it enters the draft memo.
-
Factual clearance & closing
Management reviews facts for accuracy. We then deliver the ranked memo and a closing briefing. Remediation ownership stays with your team; we can return later for a follow-up check.
What we deliberately do not do here
- Statutory financial statement audits
- Source-code or penetration testing
- Software implementation or “control platform” sales
Those boundaries keep the methodology honest. If your need sits outside them, we will say so on the scoping call.
Ready to place an engagement on the calendar?
Start with the flagship Fintech Control Audit, or choose a narrower settlement or follow-up assignment if that matches your constraint.