Teams often ask whether we ‘do security’ or ‘do compliance’. The honest answer is that we do neither as a product. We open the application the customer uses and the tools the operations team uses, then we write down where those two views of the same transfer disagree.
Week one is almost always the same shape. We agree a handful of journeys — top-up, send, withdraw, refund, new-customer KYC. We collect staging access, a sample of anonymised logs, and one person who can explain a messy ticket from last month. If that person does not exist, that is already a finding.
We do not run a scanner and paste the output into a slide. Scanners have a place; they do not tell you that a failed bill payment still decrements a display balance for six minutes. That kind of fact only shows up if someone follows the money with the app in their hand.
The write-up is ordered by harm. Money that can vanish or double sits above copy that confuses. Copy that confuses sits above tidy-ups. We include reproduce steps so an engineer who was not in the room can try the same path on Monday.