Skip to content
Case study · Financial services

ISO/IEC 27001 and PCI DSS certification support

Compliance support for the bank's ISO/IEC 27001 and PCI DSS certification. The bank's digital banking and agency banking payment services were assessed against PCI DSS v4.0.1 and found compliant.

Client
Emaar Microfinance Bank
Outcome
Certified compliant with PCI DSS v4.0.1, August 2026.
CERTIFICATION SCOPECONTROLSINFORMATION & CARDHOLDER DATASCOPEGAPREMEDIATEEVIDENCEAUDIT
Fig. · Illustrative diagram, not the client’s system
The challenge

What had to be solved

A microfinance bank handling card and customer data has to show certification bodies and regulators that its controls meet the standard, and keep meeting it.

Scope

Scope of the engagement

  1. ISO/IEC 27001 certification support

  2. PCI DSS v4.0.1 certification support

Approach

How we approached it

Certification support follows a fixed sequence, from an honest baseline to an audit-ready management system.

Gap assessment
Baseline the bank's controls against the standard and record the gaps.
Risk assessment
Identify, analyse and treat information-security risks.
Documentation
Policies, procedures and the Statement of Applicability.
Implementation and training
Close the gaps and train staff.
Internal audit
Test the management system before the certification audit.
Security

Security and compliance

ISO/IEC 27001
The international standard for information-security management systems.
PCI DSS v4.0.1
The payment card industry's data security standard. The bank's digital banking and agency banking payment services were assessed against it.
Delivery

How it was delivered

Deliverables, as defined in the SOP:

  1. Gap report

    Where the bank stood against the standard.

  2. Risk register

    Risks identified and how each is treated.

  3. ISMS documentation

    Policies, procedures and the Statement of Applicability.

  4. Internal audit report

    Evidence the system works before certification.

Results

Results and status

  • Digital banking and agency banking payment services assessed against PCI DSS v4.0.1 and found compliant.

    Evidence · Certificate of compliance issued 25 August 2026 by 386konsult, valid for one year

Related work

Engagements in the same field.

  1. NRS (formerly FIRS)

    Awarded October 2025 · three-year engagement

    Secure API submission of EMTL, withholding tax and VAT transaction data by financial institutions, validated against compliance rules, with reporting, audit and secure storage, bringing banks and fintechs onto the RevAssured platform.

    StatusOngoing.

    Government & public institutionsFinancial servicesDigital Engineering

  2. NRS (formerly FIRS)

    Awarded October 2025

    Engaged as independent consultant for assurance testing of the Merchant Buyer Solution (MBS) e-invoicing system: penetration testing and vulnerability assessment, a privacy impact assessment, performance and stress testing, functional and integration testing, and audit-trail and disaster-recovery assurance.

    OutcomeAssurance testing completed.

    Government & public institutionsIdentity & E-invoicingCybersecurity & Data Protection

Facing a similar problem?

Tell us what has to work and what it has to connect to. We will tell you plainly what it involves.