Statement of Applicability
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. Records which frameworks and controls apply, which are excluded, and the rationale for each exclusion. A reasoned exclusion is an auditable decision; this page is the authoritative source for scope questions from auditors and customers.
How to read
Each decision carries a rationale and a revisit trigger — the condition that would change the decision. The full framework strategy is held in the Framework & Cert Register.
Applicability decisions
| Framework / control | Decision | Rationale | Revisit trigger |
|---|---|---|---|
| SOC 1 Type 2 | Required | Straight-through posting places Finaisse in customer ICFR | In plan |
| PCI-DSS | Not applicable (designed-in) | Bank-account data only; no cardholder PAN in scope | Card payment acceptance |
| HIPAA | Not applicable (designed-in) | No protected health information processed | A healthcare tenant transmits PHI |
| SOC 1 Type 1 | Excluded | Design-only assurance provides limited reliance; proceed to Type 2 | — |
| SOC 3 | Optional | Public summary of SOC 2 | Post-SOC 2, if required |
Related
- → Framework & Cert Register — map-versus-certify strategy
- → Control Register — per-control applicability feeds this page
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial applicability decisions. |
Finaisse Internal — Confidential. Not for external distribution.