Service model
How an audit engagement runs
A fixed sequence so documentation work ends with artefacts your team owns—not a slide deck that expires when the consultant leaves.
-
Scope — name the review pressure
We begin with the reason the library must be ready: an upcoming partner bank questionnaire, an internal audit cycle, a product launch that created new controls, or an examiner window. Breadth stays intentionally narrow.
-
Access — read-only by default
You grant temporary read access to policy repositories, sample tickets, and relevant folders. We do not need write access to production systems for inventory or narrative work.
-
Inventory — surface orphans and contradictions
Documents, owners, version dates, and cross-references are listed before recommendations. Missing annexes and duplicate procedures appear here, not as a Friday surprise.
-
Plan — rank by exposure
Remediation is ordered by how soon a reviewer is likely to ask. Cosmetic renames wait behind unsigned procedures and narrative gaps that fail a walkthrough.
-
Handoff — artefacts stay with you
You leave with registers, gap memos, pack indexes, and a walkthrough. We do not keep editing your library unless you separately book Documentation Office Hours.
Ready to start?
Most regulated fintech teams begin with a Documentation Inventory Audit. If a partner request letter already lists specific artefacts, tell us which letter and we will suggest Evidence Pack Readiness instead.