Related frameworks and standards
The framework that applies depends on the organisation, service, jurisdiction, licence, data, and outsourcing arrangement. Use this page to identify relevant Finsaku controls, then confirm scope and evidence with the organisation's legal, compliance, security, and audit owners.
NIS2
The NIS2 Directive sets cybersecurity risk-management and incident-reporting requirements for covered essential and important entities. For financial entities covered by DORA, DORA acts as sector-specific EU law for areas including ICT risk management, incident reporting, resilience testing, and ICT third-party risk.
Finsaku access controls, tenant scope, audit history, provider inventory, and execution evidence can support the organisation's cybersecurity records. They do not replace its NIS2 scope assessment, security programme, supply-chain controls, incident reporting, or national-law obligations.
ISO/IEC 27001
ISO/IEC 27001:2022 specifies requirements for an information security management system. Finsaku controls can be mapped to parts of an organisation's access control, change accountability, supplier, and operational evidence, but product functionality is not certification.
Do not state that Finserio, Finsaku, a customer, or a deployment is certified unless a current certificate from an accredited certification body covers that exact organisation, service, location, and period. Request the certificate, scope statement, exclusions, and current surveillance status during assurance review.
AML and counter-terrorist financing
Finsaku can store private-person and legal-person records, collect configured due-diligence fields, retain dated enrichment results, and use a configured PEP provider to maintain a label. The audit trail records supported changes and checks.
These features do not complete customer identification, beneficial-owner verification, sanctions screening, risk classification, enhanced due diligence, ongoing monitoring, or suspicious-activity reporting by themselves. A provider error or unavailable PEP result is not a confirmed negative result. The obliged entity must apply the EU and national AML/CFT regime in force for its activities. The EU AML Regulation is one part of that framework and applies from the dates stated in its final provisions.
Use Person records, Credit reports and enrichments, Labels, and Integrations to configure and verify the supported evidence.
Lending and consumer-protection rules
Products, calculators, versions, collected fields, decisions, templates, and event actions can implement an approved lending process. Finsaku keeps the application separate from the resulting loan and records supported decisions and changes.
The customer remains responsible for applicable affordability rules, disclosures, interest and fee limits, approval authority, adverse-action notices, contract terms, accounting treatment, and regulatory reporting. Test the configured product against the approved legal and credit-policy specification before using it for live lending.
Before making a compliance statement
Check the exact legal entity, product, tenant, environment, geography, control period, and evidence owner. A defensible statement should identify:
- the requirement or control being assessed;
- the Finsaku configuration and evidence that support it;
- the deployment, contractual, and organisational controls outside Finsaku;
- the test performed and its result;
- open exceptions, compensating controls, owner, and due date;
- the reviewer qualified to approve the conclusion.
Use Compliance as the starting point for the shared-responsibility boundary.