Flagship program
Field Audit Path for Fintech Resilience
A hands-on lab for risk, operations, and engineering leads who must produce an operational resilience audit trail that stands up to internal audit and external questions alike.
At a glance
- Duration: 6 modules over 8 weeks (cohort) or self-paced with weekly office hours
- Best for: payments, lending, and brokerage teams with multi-vendor stacks
- Output: service map, scenario pack, evidence index, board briefing draft
- Informational fee: from KRW 2,850,000 per seat — see pricing
Modules
Critical service inventory
Define outcomes customers notice within minutes, then attach owning teams and recovery expectations.
Dependency tracing
Map ICT, third parties, and facilities without pretending every node is equally critical.
Severe-but-plausible design
Write scenarios that stress concentration risk and vendor lock-in, not cartoon disasters.
Live tabletop facilitation
Run a facilitated exercise with decision clocks, injects, and a recorded action log.
Evidence pack assembly
Index policies, tickets, and test results so a reviewer can follow the story without a guided tour.
Board briefing craft
Compress residual risk into options, costs, and open questions for directors.
Learning outcomes
- Produce a service-level resilience statement that engineering and compliance both recognize.
- Facilitate a tabletop that yields named owners and dated follow-ups.
- Assemble an evidence index that distinguishes design intent from demonstrated performance.
- Explain residual risk to a board without hiding behind framework jargon.
Instructor — Hana Park
Former operational risk lead at a Korea-licensed payments firm. Hana has coached 40+ fintech audit cycles and focuses on making evidence packs navigable rather than voluminous.
What participants noted
Module 4’s inject timing exposed that our vendor escalation tree still pointed at a departed account manager. Awkward, and exactly why we enrolled.
★★★★☆ — Solid facilitation. The board briefing templates are dense; we trimmed them for our smaller governance forum.
FAQ
Do we need a mature GRC tool before starting?
No. Spreadsheets and ticketing exports are fine. You do need someone who can pull configuration and incident history without waiting weeks.
Is the pricing a checkout?
No. Fees on this site are informational. Enrollment is arranged through contact; there is no online payment flow.
What is a real limitation of this lab?
We do not perform penetration testing or certify compliance against any specific supervisory handbook. If you need a formal attestation letter, you will still need your auditor of record.
Can Korea-based teams join remote cohorts?
Yes. Live sessions are scheduled for KST evenings, with recordings for teammates across regions.