Controls
Building audit-ready controls in early-stage startups
Early-stage fintechs hear “controls” and imagine enterprise GRC suites. Auditors asking ITGC-oriented questions usually want something narrower: who can change production, who can move money, and whether those rights are reviewed.
Three artifacts that punch above their weight
- Access review log — quarterly export of admin roles across GL, banking, and core product, with initials and dates.
- Change ticket sample — a handful of deploys showing request, approval, and release evidence.
- Vendor report index — SOC reports or bridge letters you actually read, with gaps noted.
Separate duties without hiring a cast of dozens
With a five-person finance-plus-ops team, perfect segregation is fantasy. Document compensating reviews: the founder who can initiate a payout should not be the only person reconciling the bank. Write the exception; do not hide it.
Tie controls to reporting assertions
A control that does not reduce a reporting risk is theater. When you add a checklist, name the assertion—completeness of revenue, accuracy of reserves, cut-off of settlements. That habit is core to Softwareinfrastructure’s Foundations module on ITGC-lite briefings.
What not to do
Do not invent policies the week before fieldwork. Auditors notice ink that is still wet. Prefer six months of imperfect evidence over a pristine binder created overnight.