Financial services software faces a dense regulatory environment. Relevant frameworks typically include:
- PCI DSS: Required for any system that stores, processes, or transmits payment card data. PCI DSS v4.0.1 is the current active standard as of 2025.
- SOC 2: Required by most enterprise customers and financial institutions as a baseline for third-party vendors.
- SOX (Sarbanes-Oxley): Requires public companies to maintain effective internal controls over financial reporting, which extends to the software that supports those processes.
- GLBA (Gramm-Leach-Bliley Act): Requires financial institutions to protect customer financial information.
- NIST standards: Widely referenced as best practices across financial services.
A code audit maps your software against the specific controls each applicable framework requires and identifies the gaps that pose the most risk.
Reference
PCI DSS Document Library – PCI Security Standards Council – pcisecuritystandards.org