Audit process

A clear path from first call to a control map and evidence pack your product and compliance leads can defend together.

Two colleagues reviewing notes during a working session

Scope the product surface

We agree which apps, regions, and journeys are in scope—onboarding, lending, wallet, collections, support—and who owns each control. No open-ended fishing expedition.

Map data and controls

Fieldwork traces personal data through screens, APIs, vendors, and retention stores. Each flow gets a control owner, evidence source, and residual risk note.

Sample live evidence

Consent artefacts, preference logs, rights tickets, and exception lists are sampled for the agreed period—not invented for the report.

Rank findings and rehearse

You receive a ranked remediation backlog and, when booked, a walkthrough rehearsal so system owners can narrate the pack under pressure.

Start with a scoping call Browse audit types