Fintech
United States + EU

Trellis Pay

Cross-border B2B payments startup, 90 employees, money-transmission licenses in 12 US states plus an EMI in Ireland.

Systems
  • Card vault (tokenization vendor)
  • Postgres + Kafka event log
  • Ledger service
  • Customer-facing API
Regulatory exposure
  • PCI DSS (SAQ A)
  • State money-transmission rules
  • EU EMI rules
  • AML/KYC obligations
Relevant frameworks
  • PCI DSS
  • ISO 27001
  • SOC 2 (Type II in progress)
Top risks
  • Sanctions screening miss
  • Card-tokenization vendor outage
  • Ledger reconciliation drift
  • Insider fraud
Control priorities
  • Sanctions screening tuning
  • Dual-control on ledger adjustments
  • AML transaction monitoring
  • Quarterly access reviews
Audit concerns
  • Quarterly access review evidence
  • AML investigation trail
  • Vendor SOC 2 currency for the tokenization vendor
Your task
Design a control universe to underpin an ISO 27001 certification attempt within 12 months. Show how PCI, SOC 2, and ISO controls overlap and where Annex A adds policies that are not yet in the program.
Vendor risk
Tokenization, screening, and cloud providers all critical; concentration varied across states.
BCP/DR
RTO 4 hours declared; quarterly tabletop, no full failover test in 12 months.