The Protocol CollectiveAll guides

Guide

How fintech CCOs run a 13-week quarterly compliance cadence (and why most don't)

If you've been a fintech CCO for more than two audit cycles, you've felt the rhythm: six weeks of light work, four weeks of moderate work, two weeks of full panic before the SOC 2 Type II window opens. The fourth week is consumed by emergency policy refreshes that should have been done in February. The fifth is a vendor SOC chase. The sixth is a board pack thrown together with stale data.

This isn't a shortage of effort. It's a shortage of cadence.

The 13-week quarterly cadence is the simplest fix. It allocates partner time across the quarter so every audit-readiness lever is moving slowly forward, every week, instead of all at once at the wrong time.

What the 13 weeks actually look like

Week 1 — quarter open. Read prior-quarter regulatory updates. Map them to your control catalog. Update your audit-readiness scorecard. Set 3 OKRs.

Weeks 2-4 — evidence sweep. Run the SOC 2 evidence-freshness sweep. Anything older than 90 days that should be quarterly — refresh now, not in fieldwork. Update vendor risk register. Re-test 3 random controls.

Weeks 5-8 — product compliance gate. Partner with product on the next quarter's roadmap. Pre-flight every new feature against your compliance surface. Flag features needing new controls before code ships.

Weeks 9-10 — vendor + sanctions cycle. Re-screen all vendors against OFAC SDN. Refresh vendor risk classifications. Issue annual SOC report requests to top-tier vendors.

Weeks 11-12 — board pack + executive review. Compile the quarterly board pack. KPIs: open audit findings, vendor risk distribution, KYC false-positive rate, sanctions hits, AML SAR volume.

Week 13 — quarter close + next-quarter setup. Review the audit-readiness scorecard year-on-year. Document one win, one miss, one surprise. Set next quarter's calendar. Take 2 days off.

Why this works (and why most CCOs resist it)

The cadence works for one reason: it's boring. There are no surprises. The board pack in week 11 reflects work that happened in weeks 1-10. The audit window in Q2 finds evidence that was already filed in Q1. The product team isn't surprised by compliance feedback because they're getting it weekly, not quarterly.

Most CCOs resist this because it requires giving up the dopamine of heroic last-minute saves. The CCO who pulls off a panicked SOC 2 prep at midnight feels like a hero. The CCO who runs the cadence cleanly looks like nothing happened. Look at year-over-year results, though, and the cadence-runner outperforms 4-to-1 on audit-readiness scorecards.

Heroes don't compound. Cadence does.

The Fintech CCO Quarterly Operating System

General information about compliance and programme structure, not regulatory, legal, tax or financial advice, and no promise of any examination or audit outcome. Built from public frameworks; the professional judgement is yours.