Objectives
To reach and demonstrate the level of information security required for access to the credit risk database, and to leave in place a management system that would sustain that level over time.
Fintech
Implementation of an Information Security Management System in a consumer lending fintech, where certification was not a commercial objective but the requirement that unlocked a business capability.
Problem
The business model depended on assessing each applicant’s credit risk with reliable data. Access to that information is conditional on security and personal data processing requirements the organisation had to evidence before it could operate with it.
Solution
We implemented the management system and the information security controls needed to satisfy those requirements, focused on access control, traceability of data use, and personal data processing in line with Law 18.331.
Result
The organisation obtained access to the central bank’s credit risk database and was able to run its credit origination process on verified information, with the traceability the regulation itself demands.
Consumer lending fintechs operate with two equally critical assets: the personal and financial information of their applicants, and access to the data sources that allow their risk to be assessed. The second depends on the first: anyone who cannot demonstrate how they protect the data does not get access to it.
Objectives
To reach and demonstrate the level of information security required for access to the credit risk database, and to leave in place a management system that would sustain that level over time.
Approach
We started with a gap assessment audit to separate what was already resolved from what had to be built. The work concentrated on the controls that the regulatory requirement scrutinises most closely —access and privilege management, logging and traceability, encryption, third-party management and incident response— and on documenting the personal data life cycle within the organisation.
Results
Access was granted and the origination model was able to run on verified information. The management system was left in place as a permanent structure, so later reviews are answered with evidence that already exists rather than with an extraordinary effort.
This is the case that best illustrates an argument we keep making: information security is not always justified by the risk it avoids. Sometimes it is justified by the door it opens.
Access to credit risk information is restricted to authorised entities and subject to the confidentiality established by central bank regulation, in addition to the obligations of Law 18.331 on personal data protection. In practice it requires named user access control, traceability of every query, safeguarding of the data, and a management framework that sustains all of it verifiably.
Not always as a legal obligation, but increasingly under pressure from the chain: correspondent banks, payment processors and data sources demand evidence of a security framework. Implementing the system and certifying it are separable decisions: some organisations implement out of operational necessity and certify later, when the certificate starts to have commercial value.
your business partner