Retention map
How we examine a fintech recordkeeping programme — from retention clocks to archives that stand up in review.
Inventory what you claim to keep
We start with policies, retention schedules, system lists, and the record types named in customer agreements — onboarding packs, transaction journals, complaints, and board materials. The goal is one inventory of retention claims, not a tool catalogue.
Map clocks, owners, and retrieval paths
Each record class needs a retention clock, a named owner, a storage location, and a way to retrieve a complete file on demand. Gaps here are the most common findings in Hong Kong fintech reviews.
Sample live archives
We sample closed and active customer files across product lines. Sampling reveals whether retention clocks are enforced, whether metadata survives migrations, and whether reviewers can reconstruct a history without tribal knowledge.
Stress the handoffs
Recordkeeping fails at boundaries: vendor archives to internal drives, operations to compliance, leavers’ mailboxes to legal holds. We walk those handoffs with the people who actually move files.
Sequence remediation
Findings are ranked by reconstructability risk and operational feasibility. You receive a sequenced plan — quick stabilisers first, structural redesigns next — so teams are not asked to fix everything at once.