Compliance
Advanced
55 minISO 27001 Gap Analysis
Pro
Map an existing control set to Annex A and produce a remediation roadmap.
Company brief
Trellis Pay
Fintech · United States + EU
Description
Cross-border B2B payments startup, 90 employees, money-transmission licenses in 12 US states plus an EMI in Ireland.
Analyst task
Design a control universe to underpin an ISO 27001 certification attempt within 12 months. Show how PCI, SOC 2, and ISO controls overlap and where Annex A adds policies that are not yet in the program.
Systems
- Card vault (tokenization vendor)
- Postgres + Kafka event log
- Ledger service
- Customer-facing API
Regulatory exposure
- PCI DSS (SAQ A)
- State money-transmission rules
- EU EMI rules
- AML/KYC obligations
Top risks
- Sanctions screening miss
- Card-tokenization vendor outage
- Ledger reconciliation drift
- Insider fraud
Audit concerns
- Quarterly access review evidence
- AML investigation trail
- Vendor SOC 2 currency for the tokenization vendor
Write your answer
Pro
Loading lab…