Security for fintechs, and for the institutions that rely on them.
F Creative Studio 360 helps fintechs in any country show how APIs, cloud platforms and suppliers are controlled. A prudential duty applies only when that fintech, or its partner, is actually subject to it.
The partner’s rule can become yours.
A fintech may not hold a banking licence and still process data for an institution that does. That partner’s prudential rule, whether DORA, an FFIEC expectation or another supervisor’s standard, often reaches the suppliers that manage information assets.
Open-banking and data-sharing duties are in scope only when the product is actually subject to that scheme. Examples include the UK Open Banking Standard and, where it applies, the Consumer Data Right.
- Suppliers are part of the product
- Cloud platforms, API partners and outsourced processors are assessed because they hold or move the data. A questionnaire with no evidence is not an assessment.
- APIs are tested only when authorised
- Payment, open-banking and customer APIs are tested with written permission. The work is not a surprise, and it is not a denial-of-service test.
- Cloud is the client’s account
- We review the accounts you run. We do not require a named cloud-security product.
- We do not issue the attestation
- Support for SOC 2 or ISO/IEC 27001 is preparation. The certificate or report is issued by someone else.
What can be in scope
A fintech engagement is sized to the product, not to a package.
- API and product security
- The interfaces customers and partners call, including authorisation and data returned in error.
- Supplier oversight
- Who holds data, what evidence you have, and what you will do if that evidence is thin.
- Cloud configuration
- The accounts the product runs in, against the control set you name.
- Duties you actually have
- The partner’s prudential rule, or a data-sharing scheme, and only when the product is subject to it.
How an engagement runs
Remote or on site. The product can serve customers in more than one country.
- 1
Name the product and the partners
Which entity is regulated, if any, and which suppliers touch the data.
- 2
Choose the question
A supplier review, an API review, a cloud review, or preparation for an external attestation.
- 3
Collect evidence
What you can show today, and what a partner would reject.
- 4
Hand back the gaps
In an order a small team can actually finish.
What you receive
- A supplier and asset view for the product in scope.
- Findings on the APIs or cloud accounts that were included.
- A note of which duties apply, and which do not.
- A gap list. No claim that a regulator or a partner has accepted it.
What we will not do
F Creative Studio 360 does not file a notice with a regulator, does not hold itself out as the fintech’s statutory officer, and does not certify the product.
Common questions
We are not a licensed bank. Is this still useful?+
Yes. Most of the work is the product, the APIs and the suppliers. A prudential rule is added only when you, or the institution you serve, are actually subject to it.
Will you certify us for open banking?+
No. Where a data-sharing scheme applies, we can assess the controls in scope. The accreditation, where one exists, is issued by the scheme.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Show a partner the evidence, not the slide.
F Creative Studio 360 will look at the product and the suppliers, then say what a sensible review includes.
