What had to be solved
A microfinance bank handling card and customer data has to show certification bodies and regulators that its controls meet the standard, and keep meeting it.
Scope of the engagement
ISO/IEC 27001 certification support
PCI DSS v4.0.1 certification support
How we approached it
Certification support follows a fixed sequence, from an honest baseline to an audit-ready management system.
- Gap assessment
- Baseline the bank's controls against the standard and record the gaps.
- Risk assessment
- Identify, analyse and treat information-security risks.
- Documentation
- Policies, procedures and the Statement of Applicability.
- Implementation and training
- Close the gaps and train staff.
- Internal audit
- Test the management system before the certification audit.
Security and compliance
- ISO/IEC 27001
- The international standard for information-security management systems.
- PCI DSS v4.0.1
- The payment card industry's data security standard. The bank's digital banking and agency banking payment services were assessed against it.
How it was delivered
Deliverables, as defined in the SOP:
Gap report
Where the bank stood against the standard.
Risk register
Risks identified and how each is treated.
ISMS documentation
Policies, procedures and the Statement of Applicability.
Internal audit report
Evidence the system works before certification.
Results and status
Digital banking and agency banking payment services assessed against PCI DSS v4.0.1 and found compliant.
Evidence · Certificate of compliance issued 25 August 2026 by 386konsult, valid for one year