Compliance
Advanced
55 min

ISO 27001 Gap Analysis

Pro

Map an existing control set to Annex A and produce a remediation roadmap.

Company brief
Trellis Pay

Fintech · United States + EU

Description

Cross-border B2B payments startup, 90 employees, money-transmission licenses in 12 US states plus an EMI in Ireland.

Analyst task

Design a control universe to underpin an ISO 27001 certification attempt within 12 months. Show how PCI, SOC 2, and ISO controls overlap and where Annex A adds policies that are not yet in the program.

Systems

  • Card vault (tokenization vendor)
  • Postgres + Kafka event log
  • Ledger service
  • Customer-facing API

Regulatory exposure

  • PCI DSS (SAQ A)
  • State money-transmission rules
  • EU EMI rules
  • AML/KYC obligations

Top risks

  • Sanctions screening miss
  • Card-tokenization vendor outage
  • Ledger reconciliation drift
  • Insider fraud

Audit concerns

  • Quarterly access review evidence
  • AML investigation trail
  • Vendor SOC 2 currency for the tokenization vendor

Write your answer

Pro
Loading lab…