Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Financial services

Security for the systems banks and financial institutions run.

F Creative Studio 360 reviews core platforms, payment channels and supplier paths for financial institutions wherever they are licensed. The work is scoped. It is not a surprise exercise.

Core banking is still in scope.

A modern channel often sits on an older core. Leaving that core out of the programme does not make it safe. Where the platform is IBM i, that review is its own engagement.

Institutions that use SWIFT can include the Customer Security Programme in scope. F Creative Studio 360 does not claim to be an appointed examiner, and we do not certify the institution.

Channels and the core
Internet and mobile banking, payment APIs and the system of record are reviewed as one estate when that is what the scope says.
Authorised testing only
Payment and API testing happens with written authorisation, an approved environment and a stop condition. It is not a denial-of-service test.
The rule follows the licence
Findings can be mapped to the prudential standard that institution already reports under, whether that is DORA, an FFIEC expectation, or another supervisor’s rule. One country’s standard is not the default.
Resilience exercises are separate
An intelligence-led exercise is a different engagement. It is written on its own, and only when the institution asks for it.

What can be in scope

You choose the systems. We do not assume every channel, or every country the group operates in.

Core platforms
System values, access and audit logging on the platforms that post the transactions, including IBM i where that is the core.
Payment channels
Gateways and APIs the institution exposes, tested only inside the written scope.
Identity and operations
How staff, vendors and services reach the core, and how that access is removed.
Evidence for the board
A record of what was reviewed. It is not a prudential certificate.

How an engagement runs

The same shape works on site or remotely, including when the core and the channels sit in different countries.

  1. 1

    Set the estate

    Which legal entities, which platforms, and which countries.

  2. 2

    Agree the method

    Review, authorised testing, or both. Testing is never a surprise.

  3. 3

    Do the work

    Findings are tied to the system and the business effect, not to a tool name.

  4. 4

    Hand back the order

    What to fix first. Implementation stays with your team unless it is written in.

What you receive

  • A scope that names the platforms and the countries.
  • Findings with the business effect, not a raw scan.
  • A note of what was not tested.
  • A prioritised list. No claim that a regulator has accepted it.

This is not the only financial page

Prudential mapping sits on the CPS page when that is the question. IBM i has its own page. A fintech that is not a bank starts at fintech compliance.

Common questions

Which banks is this for?+

Banks, credit unions, insurers and payments firms in any country. The review follows the platforms you run and the supervisor that licenses you.

Will you connect to the live core without notice?+

No. Access, timing and a stop condition are agreed before the work starts.

Where do you deliver this?+

For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.

How much does it cost, and how long does it take?+

It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Name the platforms before the tools.

F Creative Studio 360 will look at the core and the channels, then say what a sensible review includes.