Enterprise AI, cybersecurity, cloud and software for organizations worldwide.
Financial services

Security for fintechs, and for the institutions that rely on them.

F Creative Studio 360 helps fintechs in any country show how APIs, cloud platforms and suppliers are controlled. A prudential duty applies only when that fintech, or its partner, is actually subject to it.

The partner’s rule can become yours.

A fintech may not hold a banking licence and still process data for an institution that does. That partner’s prudential rule, whether DORA, an FFIEC expectation or another supervisor’s standard, often reaches the suppliers that manage information assets.

Open-banking and data-sharing duties are in scope only when the product is actually subject to that scheme. Examples include the UK Open Banking Standard and, where it applies, the Consumer Data Right.

Suppliers are part of the product
Cloud platforms, API partners and outsourced processors are assessed because they hold or move the data. A questionnaire with no evidence is not an assessment.
APIs are tested only when authorised
Payment, open-banking and customer APIs are tested with written permission. The work is not a surprise, and it is not a denial-of-service test.
Cloud is the client’s account
We review the accounts you run. We do not require a named cloud-security product.
We do not issue the attestation
Support for SOC 2 or ISO/IEC 27001 is preparation. The certificate or report is issued by someone else.

What can be in scope

A fintech engagement is sized to the product, not to a package.

API and product security
The interfaces customers and partners call, including authorisation and data returned in error.
Supplier oversight
Who holds data, what evidence you have, and what you will do if that evidence is thin.
Cloud configuration
The accounts the product runs in, against the control set you name.
Duties you actually have
The partner’s prudential rule, or a data-sharing scheme, and only when the product is subject to it.

How an engagement runs

Remote or on site. The product can serve customers in more than one country.

  1. 1

    Name the product and the partners

    Which entity is regulated, if any, and which suppliers touch the data.

  2. 2

    Choose the question

    A supplier review, an API review, a cloud review, or preparation for an external attestation.

  3. 3

    Collect evidence

    What you can show today, and what a partner would reject.

  4. 4

    Hand back the gaps

    In an order a small team can actually finish.

What you receive

  • A supplier and asset view for the product in scope.
  • Findings on the APIs or cloud accounts that were included.
  • A note of which duties apply, and which do not.
  • A gap list. No claim that a regulator or a partner has accepted it.

What we will not do

F Creative Studio 360 does not file a notice with a regulator, does not hold itself out as the fintech’s statutory officer, and does not certify the product.

Common questions

We are not a licensed bank. Is this still useful?+

Yes. Most of the work is the product, the APIs and the suppliers. A prudential rule is added only when you, or the institution you serve, are actually subject to it.

Will you certify us for open banking?+

No. Where a data-sharing scheme applies, we can assess the controls in scope. The accreditation, where one exists, is issued by the scheme.

Where do you deliver this?+

For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.

How much does it cost, and how long does it take?+

It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.

Show a partner the evidence, not the slide.

F Creative Studio 360 will look at the product and the suppliers, then say what a sensible review includes.