How an ISO 27001-certified fintech closed historical findings, strengthened surveillance-audit readiness and learned to run its own internal audits — over a twelve-month program.
ISO/IEC 27001 · Annex A controls · surveillance audit readiness · customer due diligence
An Australian fintech running a data-sharing platform for the financial-services sector. Their customers are banks, lenders and the businesses that need to move regulated financial data between them safely, which means every customer runs security due diligence before signing and repeats it at renewal. The company holds ISO/IEC 27001 certification, has a CISO, and runs a small engineering team that has to keep shipping while staying audit-ready.
Certification is not the finish line for a business like this: surveillance audits come every year, recertification every three, and customer questionnaires every month.
Sector: financial services (data-sharing platform) · Certification: ISO/IEC 27001 · Team: CISO + small engineering team · Engagement: 12 months
The business needed an independent internal audit against ISO/IEC 27001 to prepare for surveillance audits and the due diligence its customers run. Internal audit has to be genuinely independent of the people who own the controls — certification auditors look for that first — and the findings had to be evidence-backed and reproducible, not opinions. Earlier reviews had left major findings open, and evidence was hard to trace back to the control it supported.
We planned and executed an internal audit program across the Annex A control set, then went below the policy layer to check that the controls actually operate:
Independence preserved throughout, every finding evidence-backed, and no dependence on Securitribe tooling left behind.
Internal audit only has value if it is independent, so we kept it that way: no involvement in operating the controls we audited, and every finding backed by evidence the client can show an external auditor. We wrote remediation as tasks an engineer can pick up, not as a report that sits on a shelf. Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it.
Holding ISO 27001 means surveillance audits every year and recertification every three, on top of the questionnaires enterprise customers send. The internal audit is where most certified businesses are weakest: it gets done by the same people who run the controls, it samples the easy things, and findings are recorded without evidence. When an auditor raises that as a nonconformance, the fix is an independent program — which is exactly what this engagement delivered.
Related: all case studies
Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.