Team planning around documents on a table

Audit process

A clear sequence from access request to remediation briefing—built for acquiring platforms, not generic consulting theatre.

Merchant onboarding audits succeed when scope, sample design, and deliverables are agreed before anyone opens a case file. This page is the working model we use with Hong Kong–based acquiring platforms and payment facilitators.

01

Scope the stack and period

We name the systems in play—intake forms, document vault, screening provider, underwriting queue, merchant master—and the review window. Access owners and data-handling rules are confirmed in writing before fieldwork.

02

Design the sample

Sample size follows volume and risk mix, not a fixed percentage. We propose strata for SME, mid-market, and restricted MCC cohorts, then agree severity definitions so findings are comparable across files.

03

Walk controls and score files

Fieldwork combines workflow walkthroughs with file-level scoring. We look for missing artefacts, undocumented overrides, skipped gates, and policy-to-config drift—not just absent ID scans.

04

Deliver for ops and the board

You receive an exception register, a prioritized fix backlog with owners, and a residual-risk summary suitable for risk committees. One evidence pack, two audiences.

What you need ready

  • Current acquiring risk policy and MCC restrictions
  • Read access (or exports) for the agreed sample period
  • A named ops and compliance contact for walkthroughs
  • Clarity on which partner or internal audit question is driving the work

Schedule a scoping conversation Browse services