How we audit

A fieldwork sequence your compliance calendar can hold

This page maps the rhythm of a North Harbor engagement — from scoping workshop to close-out briefing — so fintech teams know what weeks look like before they commit.

Team collaborating around printed plans on a table

Scope map

We chart products, customer journeys, and the obligations tied to your license. Out-of-scope items are written down so sampling stays honest.

Evidence intake

Policies, MI packs, and sample files arrive under NDA. We confirm anonymisation rules and who can answer follow-ups during fieldwork.

Testing days

Interviews and file sampling test whether procedures match practice. Gaps are logged with exhibits, not vague impressions.

Findings workshop

Severity grades, owners, and remediation order are debated with your team before the memo is finalised for directors or partners.

What a typical week feels like

Week one is quiet on your side if intake is ready: we read. Week two brings interviews that rarely exceed ninety minutes per control owner. Week three concentrates on drafting and challenge sessions. Larger product stacks stretch the middle — we say so at scoping rather than discovering it mid-sample.

On-site days in Taiwan are scheduled when file rooms or operations floors matter; otherwise secure remote sessions keep travel light for island and mainland teams alike.

Natural next step

If this sequence matches the pressure you face — examination, partner visit, or board challenge — review the flagship Fintech Control Audit or ask for a scoping call.

Professionals in a structured meeting around a conference table

Boundaries we keep

  • No legal opinions presented as audit findings
  • No software configuration or vendor selection mandates
  • No fake urgency — timelines come from your examination date, not our marketing
  • No continuing outsourced officer role after close-out unless separately agreed in writing