Skip to content
Last updated: Sep 25, 2026

Statement of Applicability ​

OwnerClassificationVersionEffectiveNext reviewStatus
Sekhar PrakashInternal0.12026-08-272026-11-27Draft

Purpose. Records which frameworks and controls apply, which are excluded, and the rationale for each exclusion. A reasoned exclusion is an auditable decision; this page is the authoritative source for scope questions from auditors and customers.

How to read ​

Each decision carries a rationale and a revisit trigger — the condition that would change the decision. The full framework strategy is held in the Framework & Cert Register.

Applicability decisions ​

Framework / controlDecisionRationaleRevisit trigger
SOC 1 Type 2RequiredStraight-through posting places Finaisse in customer ICFRIn plan
PCI-DSSNot applicable (designed-in)Bank-account data only; no cardholder PAN in scopeCard payment acceptance
HIPAANot applicable (designed-in)No protected health information processedA healthcare tenant transmits PHI
SOC 1 Type 1ExcludedDesign-only assurance provides limited reliance; proceed to Type 2—
SOC 3OptionalPublic summary of SOC 2Post-SOC 2, if required

Revision history ​

VersionDateAuthorChange
0.12026-08-27Sekhar PrakashInitial applicability decisions.

Finaisse Internal — Confidential. Not for external distribution.

Finaisse Internal — Confidential. Access-restricted; not for external distribution.