Skip to content
Last updated: Sep 25, 2026

Framework & Certification Register ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. Records which compliance frameworks Finaisse maps to its control set, which it certifies, in what sequence, and the applicability of those excluded. Supports customer security-questionnaire responses and audit planning.

Operating principle: map broadly, certify selectively ​

  • Mapping adds one lens (maps_to) to each control and makes the programme answerable to that framework immediately.
  • Certification is a scheduled, audited engagement pursued only where the market requires it, in priority order.
  • One control set answers every mapped framework → a customer questionnaire becomes a lookup rather than a project.

Certification driver: SOC 1 is required ​

  • Finaisse performs straight-through processing — automated posting of validated journals and invoices to the customer's books under approval rules.
  • This places Finaisse within the customer's internal control over financial reporting (ICFR), for which their external auditors require SOC 1 assurance.

Peer benchmark (finance-automation platforms that post to the books):

VendorSOC 1 Type 2SOC 2 Type 2ISO 27001ISO 42001Source confidence
BlackLineYesYesYes (+27017/18/701)YesPrimary (vendor + investor sources)
EskerYesReportedYes—Primary (press release; 2012/2014 exams — verify current)
FloQastReported (secondary)YesYes (+27701)Reported (secondary)SOC 2 / ISO primary; SOC 1 / 42001 unconfirmed
HighRadiusNot confirmedYesYes (27001:2022)—ISO / SOC via trust centre; SOC 1 unconfirmed
  • Category baseline: SOC 1 Type 2 · SOC 2 Type 2 · ISO 27001, with ISO 42001 emerging as the AI differentiator.
  • Current vendor status should be confirmed from each provider's trust centre before external citation.

Certification track (priority order) ​

#CertificationAttestsTriggerSequenceStatus
1SOC 2 Type 2 (incl. Processing Integrity)Security, availability, confidentiality, processing accuracyCustomer security requirementNow — primary targetIn preparation
2SOC 1 Type 2Controls over customer financial reporting (ICFR)Straight-through posting to customer booksAfter STP live plus 6–12-month observation; combine with SOC 2Required, unscheduled
3ISO 27001Information Security Management SystemInternational / enterprise demandOn demandMap now, certify on demand
4ISO/IEC 42001AI management systemAI-native platform differentiationEarlyMap now

SOC 3 (public summary of SOC 2) is optional and low-effort once SOC 2 is held.

Mapped frameworks (answerability, not certification) ​

FrameworkPurposeNotes
GDPREU personal-data lawfulness and data-subject rightsDelivered via DPA; overlaps Domain 2 and SOC 2
DPDP (India)Primary regulatory regimeMapped alongside GDPR; selected by customer geography
EU AI ActAI risk and transparency obligationsPaired with ISO 42001
CIS v8 / OWASPEngineering baselinesPresent in the coverage crosswalk

Designed-in, not yet applicable ​

  • Both are data-type-triggered regimes.
  • The majority of each is satisfied by the generic Restricted-data controls (Domains 2, 4, 11), engineered to the union of all data-regime requirements.
  • Data-type-specific controls are documented as activation triggers, not implemented ahead of the data.
FrameworkApplicabilityActivation trigger and unique requirements
PCI-DSSNot applicableActivates on card PAN acceptance. Keep PAN out of scope via a processor (SAQ A). Additional requirements: cardholder-data-environment scoping and segmentation, no storage of sensitive authentication data, PAN masking, dedicated key management, ASV scans.
HIPAANot applicableActivates if a healthcare tenant transmits PHI. Technical safeguards already met by SOC 2 / ISO 27001. Additional requirements: business associate agreement, breach-notification rule, minimum-necessary. No formal HIPAA certification exists; HITRUST is the certifiable proxy.

Straight-through-processing control objectives (SOC 1) ​

Design the following into the STP implementation from the outset. Mapped to Domains 16 (financial-data integrity), 17 (business logic), and 4 (identity and access):

  • Approval-rule change management under authorisation and change control.
  • Enforcement with no bypass of required approval.
  • Completeness and accuracy: each approved item posts once and only once; ingress-to-egress reconciliation.
  • Segregation of duties in the approval workflow.
  • Immutable audit trail of approver, rule fired, and posting.
  • Access control over rule configuration and the posting path.
  • Complementary user-entity controls (customer review of configuration; general-ledger reconciliation).

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial register; certification track and applicability decisions.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.