Fintech
United States + EU
Trellis Pay
Cross-border B2B payments startup, 90 employees, money-transmission licenses in 12 US states plus an EMI in Ireland.
Systems
- Card vault (tokenization vendor)
- Postgres + Kafka event log
- Ledger service
- Customer-facing API
Regulatory exposure
- PCI DSS (SAQ A)
- State money-transmission rules
- EU EMI rules
- AML/KYC obligations
Relevant frameworks
- PCI DSS
- ISO 27001
- SOC 2 (Type II in progress)
Top risks
- Sanctions screening miss
- Card-tokenization vendor outage
- Ledger reconciliation drift
- Insider fraud
Control priorities
- Sanctions screening tuning
- Dual-control on ledger adjustments
- AML transaction monitoring
- Quarterly access reviews
Audit concerns
- Quarterly access review evidence
- AML investigation trail
- Vendor SOC 2 currency for the tokenization vendor
Your task
Design a control universe to underpin an ISO 27001 certification attempt within 12 months. Show how PCI, SOC 2, and ISO controls overlap and where Annex A adds policies that are not yet in the program.
Vendor risk
Tokenization, screening, and cloud providers all critical; concentration varied across states.
BCP/DR
RTO 4 hours declared; quarterly tabletop, no full failover test in 12 months.