The Protocol CollectiveAll guides

Guide

The 12-question audit-readiness scorecard most fintechs aren't running

Audit readiness isn't a state you enter the month before the audit starts. It's a state you maintain continuously. Most fintech compliance teams treat audits as events. The teams who treat them as the visible tip of an underlying state — readiness — find audits trivial. Building that state takes one tool: a quarterly self-assessment scorecard, run consistently. Here's the 12-question version I run with fintech CCOs.

The 12 questions

  1. Is the policy library current within 90 days?
  2. Are vendor reviews current within 12 months for Tier 1?
  3. Is the findings register live and ageing reported?
  4. Are training records 100% current?
  5. Are board reports filed each quarter?
  6. Is the BSA officer documented and accessible?
  7. Are SAR/CTR processes evidenced?
  8. Is the IRP tested in the last 12 months?
  9. Are model risk validations current?
  10. Is the third-party risk inventory complete?
  11. Is the change-management log live?
  12. Is the regulator-relationship calendar current?
  13. Each question is binary: yes (1 point) or no (0 points). Score: 12 = audit-ready. 9-11 = mostly ready, two-week gap-close. 6-8 = remediation required, 4-week sprint. <6 = systematic readiness work needed before any audit cycle is responsibly accepted.

    The questions that score lowest first

    Across the programmes this scorecard was built against, the questions that score lowest first time someone runs the scorecard are predictable. Question 8 (IRP tested in last 12 months) — most fintechs have an IRP but never test it. Question 11 (change-management log live) — most have ad-hoc change logging but no continuous register. Question 12 (regulator-relationship calendar current) — most fintechs don't have a formal regulator-relationship calendar at all.

    This pattern is itself diagnostic. The questions reveal which functions are mature (vendor management, board reporting) and which are immature (incident response, change management, regulator relationships).

    Running the scorecard quarterly

    The scorecard works because it's run quarterly, not annually. Quarterly cadence means each remediation cycle is 90 days, not 12 months. The compounding shows up in the trend line:

    Q1: score 6. Identify 6 gaps. Q2: focus on 2 gaps. Score 7-8 by quarter end. Q2: identify 4 remaining gaps. Q3: focus on 2 more. Score 9-10. Q3: identify 2-3 remaining gaps. Q4: focus on those. Score 11-12.

    Most fintechs reach score 11-12 within 4 quarters. After that, it's about maintaining the score, which is a different (easier) problem than reaching it.

    What about specific frameworks (SOC 2, PCI, BSA)?

    The 12-question scorecard is framework-agnostic. It tests the foundational hygiene that every framework cares about. Specific framework prep — SOC 2 Type II evidence collection, PCI DSS scoping, BSA program review — is a layer on top of the foundation. Without the foundation, framework-specific prep is fragile. With the foundation, framework-specific prep becomes incremental.

    The companion document: workpaper templates

    The scorecard answers the "are we ready" question. Workpaper templates answer the "can we evidence it" question. Audit-ready isn't just a state — it's an evidenced state. Workpapers are the evidence trail. The Critical Auditor Mastery includes both: the scorecard + workpaper templates + the QC procedures that hold them together. $697.

    The Examination Readiness Toolkit

    General information about compliance and programme structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks; the professional judgement is yours.