Field notes
Scoping an audit when your fintech has three licences
Multi-licence groups often ask for “one audit that covers everything.” That impulse is understandable; boards dislike fragmented reports. The risk is a shallow pass that samples none of the licences deeply enough to stand up in examination.
A better scoping pattern starts with shared controls — access administration, incident management, outsourcing oversight — then picks one licence for deep product-flow testing in the same cycle, rotating depth in later years.
Tell your auditor which examination window is nearest. If remittance supervision is six weeks away and lending is quiet, weight the fieldwork toward remittance cash cycles and keep lending at a higher-level design review. Document that trade-off in the planning memo so the board knows what was and was not stress-tested.
Web Service Connect writes planning memos this way on purpose: a clear boundary today beats an ambiguous “full coverage” claim that cannot be evidenced later.