Examination support
What we can put in front of your examiner, what we cannot, and what we need from you before an exam rather than during one.
Last updated 23 July 2026 · Trust Center
1. Whose examination this is
It is yours. We are a service provider, and in most frameworks that makes us subject to your vendor-management programme and potentially to review as part of your examination — not a party to it. Our job is to make your evidence easy to produce and hard to dispute.
2. Before an exam
Three things are worth doing while nothing is urgent:
- Map your policy library to enforced configuration. For each control in your written programme, identify the configuration that enforces it and the evidence it produces. Gaps found here are cheap; gaps found by an examiner are not.
- Produce every report end to end once, against test data. An information return that has never been generated is a finding waiting to happen.
- Rehearse an evidence request. Pick a transaction at random and produce its full decision history. If that takes a week, fix it before it matters.
3. Evidence we can produce
- Data-element decision history — for a given record, every access and change decision with acting identity, purpose, delegation relied on, decision, time and policy version.
- Delegation history — who held authority over an account, granted by whom, from when, revoked when and by whom.
- Approval history — which transactions required approval, who approved, and which were blocked.
- Configuration history — what a rule was, when it changed and who changed it.
- Access reviews — entitlements held, by whom, and when last reviewed.
4. Look-back
The question an examiner actually asks is not “what is your rule” but “what was your rule in March, and did this transaction comply with it.” Because each decision records the policy version in force, that is a query rather than an archaeology project. This is the single most useful property of the evidence model and the reason configuration is versioned rather than simply edited.
5. Control mapping
On request we will provide the technical and organisational measures for your deployment as Exhibit B to the DPA, cross-referenced to our security policy. Send your own control framework and we will map to yours rather than asking you to translate ours — a reviewer comparing two vocabularies is a reviewer finding differences that are not there.
6. Examiner access
Because A8 Core is metered on data and usage rather than per seat, giving an examiner or an internal auditor read access carries no licence cost. Access is scoped and time-boxed like any other, and the examiner’s own reads are themselves authorized and recorded — which is usually the first thing an examiner tests.
7. What we cannot do
- We cannot respond to your regulator on your behalf, or interpret a rule for you.
- We cannot make a suitability, permissibility or acceptance-of-risk determination.
- We do not yet publish a third-party audit report. Where a current report or completed questionnaire exists we offer it first; where it does not, we say so.
- We cannot produce evidence for a control that was never configured. This is the reason clause 2 exists.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice. Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.