Methodology
How a controls audit moves from scope letter to signed memo
This page describes the working method behind our audits for fintech. It is the custom engagement guide clients receive before fieldwork begins.
-
Scope confirmation
We name product lines, material processors, bank accounts, and the sample window in the engagement letter. Anything outside that list waits for a change order.
-
Document request
The first pack asks for reconciliation exports, exception aging, access listings, and approval trails for funds movement. Marketing materials stay off the list.
-
Fieldwork
Reviewers test samples, interview control owners, and observe how exceptions are cleared. On-site days in Taiwan are scheduled around your close calendar when possible.
-
Findings validation
Draft findings are shared with management for factual correction. Judgment on severity remains with Elm Harbor Controls.
-
Remediation sequencing
The final memo orders open items by residual risk to customer funds and by effort, so teams know what to fix before the next supervisory or investor conversation.
What clients prepare
Organization charts for finance and operations, policy manuals that claim to govern funds, the last two reconciliation packs, and a vendor list for processors and banks. Incomplete packs slow fieldwork more than difficult findings do.
What we will not do
We do not certify regulatory approval, rewrite your license file, or staff your compliance desk after delivery. Those boundaries keep the audit independent.