Client
A north-eastern European fintech company that turned to us for consulting services built a leading-edge payment and money transferring mobile application aimed at facilitating electronic payments, peer-to-peer transfers, and international remittances by enabling QR code scanning, mobile number-based money transfers, and a set of other financial solutions rare for the country of their location. Being well-aware of the uncompromising nature of European requirements and standards that fintech software products must comply with, the client decided to turn to Modsen for comprehensive application audit to ensure it’ll obtain a certificate of compliance and launch seamlessly into the market.
Challenge
The finance technology company we partnered up with for the software audit faced a complex challenge of ensuring the compliance of their product to a number of European and international regulations, including:
- Compliance with GDPR data protection law;
- Fulfilment of KYC standards;
- Adherence to PCI-DSS guidelines;
- Conformity to EFTA;
- Compliance with AES standard;
- Fulfilment of ISO 27001 information security management standard.
By turning to an expert IT consultancy vendor in the face of Modsen team, the client hoped to identify and eliminate any possible fintech app regulation compliance gaps and get certified by independent regulatory experts afterwards.
Consulting process
Consultation inquiry analysis
After receiving an IT consulting request, industry relevant Modsen experts dived in to promptly assess the inquiry and get ready for a preliminary client meetup.
Client requirements gathering
During the pre-audit stage Modsen CTO, assisted by several consulting specialists held 2 online meetups to collect and precisely document the project requirements articulated by the client, specify the key audit steps, deadlines, and team monitoring formats.
Team assembly
To ensure 100% compliance with the client requirements, Modsen CTO handpicked 4 seasoned finance industry consultant engineers with an extensive hands-on experience in the development and auditing of fintech applications.
Project auditing
The process of the finance app auditing took our team 3,5 weeks, during which we conducted the initial product assessment and audit planning, performed comprehensive project data analysis, and regularly provided our partner with interim audit results and findings via daily progress calls and reports’ submission.
Audit results delivery
To abstain from unfounded verdicts, we provided our partner with a clear and concise way of addressing the gaps and inefficiencies identified during the software audit in the form of a comprehensive document outlining the project team’s recommendations on issue fixing.
Provision of documented recommendations and remediation plan
The project gap-bridging action plan encompassed 15+ pages of clear-cut technical recommendations tailored to the client’s goal of achieving the certificate of compliance for the fintech application.
Results and impact
Enhanced app security architecture
The 7+ years' experience of
Modsen fintech consultants engaged in the project allowed them to give the client’s development team valuable security strengthening recommendations and suggest future adjustments to the product’s architecture that would significantly lower breach risks.
Compliance certification obtaining
Following the recommendations documented in Modsen project remedy plan, the client got their fintech mobile application certification-ready and obtained ISO 27001 certification, alongside proving compliance with GDPR, KYC, PCI-DSS, EFTA, and AES standards within 9 months since our cooperation was finalized.
45%
Lowering of security breach risks
9
Months to a certificate of compliance
100%
Elimination of fintech regulatory compliance gaps