Skip to content
_COMPLIANCE/

Audited, certified, and continuously monitored

SOC 2 Type II with zero exceptions, ISO 27001:2022, and DORA alignment: the certifications your auditors ask for, backed by evidence you can hand them.

Compliance at Formance is a program, not a page: independent audits on a fixed cadence, 16 formal security policies reviewed annually, continuous control monitoring in Vanta, and contracts already aligned with EU operational-resilience requirements. Everything below is documented and available under NDA through the trust center.

_01/

SOC 2 Type II

_Clean opinion/

Audited by Johanson Group LLP; all 33 Common Criteria tested with no exceptions noted.

_Full scope/

Control environment, risk assessment, access, operations, change management, and vendor risk (CC1 through CC9).

_Annual cadence/

Re-audited on a rolling annual period, with the current report available under NDA.

_02/

ISO 27001:2022

_Certified ISMS/

Information security management system certified against the 2022 revision.

_Policy suite/

16 formal policies (access, cryptography, incident response, BC/DR, secure development, and more) reviewed and renewed annually.

_Annual audits/

External audit plus annual risk assessments based on ISO 27005 and NIST 800-30.

_03/

DORA

_Assessed, no material deficiencies/

Full assessment across Articles 5 to 30 and Article 45, covering governance, resilience testing, incident reporting, and third-party risk.

_Financial-entity ready/

Contracts aligned with DORA requirements out of the box, and a maintained register of ICT arrangements.

_Resilience testing/

Critical systems tested at least yearly; threat-led penetration testing at least every 3 years by external testers.

_TRUST/

Built for regulated money.

Enterprise controls, the certifications auditors ask for, and an immutable record, out of the box.

See our trust center
THE COMPLIANCE STACK
IAM, RBAC & SSO
Non-repudiation
Audit logs
Observability & monitoring
Real-time events
Admin console
_AUDIT-LOG/ NON-REPUDIATION

09:41:07Z AUDIT gateway POST /api/ledger/v2/main/transactions 200 sub:ops@acme.io

09:41:09Z LOG id:4093 NEW_TRANSACTION ledger:main

09:41:12Z LOG id:4094 SET_METADATA ledger:main

09:41:15Z LOG id:4095 REVERTED_TRANSACTION ledger:main

09:41:18Z AUDIT gateway GET /api/ledger/v2/main/logs 200 sub:audit@acme.io

CERTIFICATIONS
AICPA SOC IICERTIFIED
ISO 27001CERTIFIED
DORACOMPLIANT
REGULATORY FRAMEWORKS
EMIFCAMTLNYDFS Trust CharterOCC CharterMiCAGENIUS
_ATTESTED/
_PREV/

Security

_NEXT/

Regulatory

FAQ

Questions, answered

01 / HOW DO WE GET THE REPORTS?

Through the trust center under NDA, or alongside your RFP. The latest audit reports ship with security questionnaire responses as standard.

02 / WE ARE IN SCOPE FOR DORA. WHAT DOES THAT MEAN FOR YOU AS OUR ICT PROVIDER?

Formance maintains DORA-aligned contract terms, a register of ICT arrangements, incident classification aligned with Articles 13 and 14, and a resilience testing program, so your third-party risk file is ready.

03 / WHAT ABOUT GDPR?

Formance processes data under a DPA with GDPR-aligned safeguards, EU hosting options, jurisdiction-bound backups, and a published sub-processor list.

04 / DO YOU SUPPORT CUSTOMER AUDITS?

Yes, audit rights are part of the contractual framework, and continuous monitoring evidence (Vanta) plus annual external audits back the paper.

GET STARTED

Evidence, not assurances

Request the reports or bring your compliance team to a session.