Controls & Audit

Audit and Controls

At EWM Global, we recognize that robust controls and independent assurance are essential when supporting regulated financial institutions. Our control environment is designed to protect client data, ensure service reliability, and meet the expectations of auditors, regulators, and risk professionals through a practical and proportionate approach.


Independent Assurance

Our control framework is subject to regular independent review to provide transparency and confidence in our operations:

  • Annual SOC 1 Type II (ISAE 3402) Report covering controls relevant to financial reporting
  • Annual SOC 2 Type II Report covering security, availability privacy and confidentiality controls
  • Independent Application Penetration Testing performed annually by external specialists
  • External Vulnerability Scanning to identify and remediate security weaknesses

Information Security & Data Protection

We apply industry-standard information security and privacy controls across our platform and operations:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and least-privilege principles across all user roles
  • Multi-factor authentication enforced for employees, sponsors, administrators and other privileged access, with configurable options for end users based on client requirements
  • Continuous system monitoring, centralized logging, and formal incident detection and response procedures
  • Privacy-by-design approach aligned with GDPR requirements, with EWM Global acting as a data processor

Business Continuity Management

Operational resilience is a core component of our control environment:

  • Documented Business Continuity and Disaster Recovery Plans
  • Regular backup testing and recovery validation
  • Formal Incident Response, crisis management, and pandemic policies

Our controls are designed to ensure continuity of service and timely recovery in the event of operational disruption.

Vendor & Third-Party Oversight

Key service providers are subject to risk-based due diligence prior to onboarding and ongoing review thereafter. This ensures that third parties supporting our services meet appropriate security and operational standards.

Additional audit reports, policies, and control documentation are available to existing clients and prospects upon request, subject to confidentiality obligations.

For further requests of due diligence documentation or information, please contact us directly.