Controls

Building audit-ready controls in early-stage startups

Enough structure to answer questions—without a 200-page manual nobody reads.

Team planning with notes on a glass wall

Early-stage fintechs hear “controls” and imagine enterprise GRC suites. Auditors asking ITGC-oriented questions usually want something narrower: who can change production, who can move money, and whether those rights are reviewed.

Three artifacts that punch above their weight

  1. Access review log — quarterly export of admin roles across GL, banking, and core product, with initials and dates.
  2. Change ticket sample — a handful of deploys showing request, approval, and release evidence.
  3. Vendor report index — SOC reports or bridge letters you actually read, with gaps noted.

Separate duties without hiring a cast of dozens

With a five-person finance-plus-ops team, perfect segregation is fantasy. Document compensating reviews: the founder who can initiate a payout should not be the only person reconciling the bank. Write the exception; do not hide it.

Tie controls to reporting assertions

A control that does not reduce a reporting risk is theater. When you add a checklist, name the assertion—completeness of revenue, accuracy of reserves, cut-off of settlements. That habit is core to Softwareinfrastructure’s Foundations module on ITGC-lite briefings.

What not to do

Do not invent policies the week before fieldwork. Auditors notice ink that is still wet. Prefer six months of imperfect evidence over a pristine binder created overnight.

See how Foundations covers control conversations