Service model

How an audit engagement runs

A fixed sequence so documentation work ends with artefacts your team owns—not a slide deck that expires when the consultant leaves.

Team reviewing documents together in a bright office
  1. Scope — name the review pressure

    We begin with the reason the library must be ready: an upcoming partner bank questionnaire, an internal audit cycle, a product launch that created new controls, or an examiner window. Breadth stays intentionally narrow.

  2. Access — read-only by default

    You grant temporary read access to policy repositories, sample tickets, and relevant folders. We do not need write access to production systems for inventory or narrative work.

  3. Inventory — surface orphans and contradictions

    Documents, owners, version dates, and cross-references are listed before recommendations. Missing annexes and duplicate procedures appear here, not as a Friday surprise.

  4. Plan — rank by exposure

    Remediation is ordered by how soon a reviewer is likely to ask. Cosmetic renames wait behind unsigned procedures and narrative gaps that fail a walkthrough.

  5. Handoff — artefacts stay with you

    You leave with registers, gap memos, pack indexes, and a walkthrough. We do not keep editing your library unless you separately book Documentation Office Hours.

Ready to start?

Most regulated fintech teams begin with a Documentation Inventory Audit. If a partner request letter already lists specific artefacts, tell us which letter and we will suggest Evidence Pack Readiness instead.

Request an audit scope View audit services