How Nium scaled compliance and audit prep with Sprinto

Nium is a San Francisco and Singapore-based cross-border payments company. A leader in global real-time money movement, numerous financial institutions, platforms, and businesses rely on Nium’s payments infrastructure to collect, convert, and disburse funds around the world instantly to accounts, cards, and wallets.

nium hero image
8 months Time to complete SOC 2 Type 2 audit
97% automation Degree of automation in compliance management
3 controls Of 100+ controls needing manual evidence
Sprinto white-logo
Before Sprinto
After Sprinto
Already ISO 27001 and PCI-DSS compliant, Nium increasingly needed SOC 2 compliance and an audit report as it engaged prospective customers in the US.
Nium received its SOC 2 Type 2 audit report in under 8 months, following 6 months of observation, the fastest audit Raj had ever completed.
SOC 2’s demanding, evidence-focused audit meant manual control maintenance and evidence collection would add significant burden to IT teams, where missing tracking even for a day results in control failure.
Of the 100+ controls, no more than 3 required manual evidence, and the technology team didn’t receive a single request during the audit.
Compliance programs across SOC 2, PCI-DSS, and ISO 27001 were managed separately, with no unified control baseline.
Nium transitioned PCI-DSS and ISO 27001 program management to Sprinto on the SOC 2 controls baseline, with common control mapping ensuring testing efficiencies.
“Our existing control environment was strong, but SOC 2 demands more controls and a greater burden in terms of maintenance and evidence collection. The manual approach would have held us back”


– Raj Viswanathan
CISO, Nium

“We are more comfortable responding to due diligence requirements asking for independent attestations. With Sprinto’s ongoing maintenance, compliance is ensured as automation handles testing, evidence collection, and more, eliminating the need for a lot of manual work.”


– Raj Viswanathan
CISO, Nium

Introduction

Nium is a San Francisco and Singapore-based cross-border payments company and a leader in global real-time money movement. Numerous financial institutions, platforms, and businesses rely on Nium’s payments infrastructure to collect, convert, and disburse funds around the world instantly to accounts, cards, and wallets.

Already ISO 27001 and PCI-DSS compliant, Nium found the need for SOC 2 compliance and an audit report growing steadily as it began engaging prospective customers in the US. Meeting that need without adding headcount shaped how Nium approached the program. “Automation is a capability that helps us do more with less,” says Raj Viswanathan, CISO at Nium.

The Problem

SOC 2 is a more aggressive compliance framework with a demanding audit, and Nium wanted to meet the control maintenance and evidence requirements that come with it without relying on an IT team to fulfill them.

“SOC 2 is an intense, evidence-focused audit. If controls are not automated, it adds more burden to IT teams to ensure we do not miss something. If we miss tracking controls even for a day, it results in control failure, and it will be captured in the report,” remarks Raj. Moving towards a clean audit report made comprehensive control coverage, continuous monitoring, and accurate evidence the priorities.

“Our existing control environment was strong, but SOC 2 demands more controls and a greater burden in terms of maintenance and evidence collection. The manual approach would have held us back,” recalls Raj.

Alongside that coverage, Nium needed to complete the SOC 2 audit swiftly, without disrupting teams and bandwidth. “Automation was crucial,” says Raj. “Instead of adding more people to complete specific tasks like incident monitoring and response, we preferred a solution to automate monitoring, track compliance, and collect evidence at once.”

Nium therefore sought a solutions partner capable of deep integration with its cloud stack and able to automate control testing and evidence collection. Since this was a major undertaking and part of a broader practice shift from manual to automated compliance management, Nium was keen to collaborate with someone who shared its vision, because effort needs to be applied in the right way and stakeholders need to be brought together effectively.

“Sprinto’s was not a scope-led approach but rather a commitment to working together to find solutions—a shared vision aimed at achieving a clean compliance report,” recalls Raj. “The team was dedicated to the path leading to a clean compliance report and worked backward, identifying the necessary integrations and required changes, ensuring alignment throughout.”

The Solution

Nium’s stack was immediately compatible with Sprinto, so Nium got the platform up and running fast. “Together, we found workarounds for cases where Sprinto couldn’t integrate instead of waiting for full development. Our tech team didn’t need to invest a lot of effort either,” Raj notes. With its cloud stack connected through Sprinto’s integrations, entities defined and classified, and roles configured, Nium jumped right into action.

Responsive integration meant all the right information was pulled in, highlighting misconfigurations and anomalies without false positives or false negatives. “During this exercise, we realized that we needed to address certain infrastructure-level controls to fulfill specific SOC 2 criteria, such as providing evidence for security controls on endpoints. Fortunately, Sprinto’s automation had us covered,” recalls Raj.

With the dashboard active, Nium used real-time alerts and contextual cues to address instances of non-compliance, holding momentum and continuity against its audit goals and getting ready for SOC 2 observation in a matter of weeks. “The dashboard informed us about the controls we needed to address, and these were the only ones for which we didn’t have integrations,” recalls Raj.

Continuous monitoring carried the rest of the load: “Of the 100+ controls, there were no more than 3 controls for which we had to provide evidence manually,” he says.

With SOC 2 implementation completed, Nium used this controls baseline to transition its PCI-DSS and ISO 27001 program management to Sprinto, where common control mapping ensures testing efficiencies. “Sprinto has consolidated all our compliance efforts into one place. There’s control harmony now!” says Raj.

Post implementation, Nium used Sprinto’s auditor dashboard for evidence review. With samples selected and shared in one place, Nium completed reviews in under two meetings, needing only to “provide our auditor with an overview and share a few additional pieces of evidence related to our HR function,” as Raj describes it. Evidence was ready when the auditor asked for it.

“From the auditor’s point of view, if there’s no evidence, then there is no control. Sprinto greatly helps with the evidence part of things,” he notes. Internally, the preparation burden stayed just as light: “The best thing about using Sprinto for our audit preparation was that the technology team didn’t even realize we had an audit occurring because they didn’t receive a single request from us,” says Raj.

Impact

Nium received its SOC 2 Type 2 audit report in under 8 months, following 6 months of observation. Says Raj, “This is the fastest I have ever completed an audit!” Among other upshots, Raj notes the positive influence of a clean audit report on security due diligence. “It’s a lighter due diligence now,” he says.

“We are more comfortable responding to due diligence requirements asking for independent attestations. With Sprinto’s ongoing maintenance, compliance is ensured as automation handles testing, evidence collection, and more, eliminating the need for a lot of manual work.”

With Sprinto running in the background, Raj takes comfort in the fact that best practices are upheld, and real-time alerts give Nium a responsive process to stay on top of compliance drift and maintain robust security. “I’m not too concerned about the next audit. It doesn’t keep me awake because we’re aware that most of our controls are in check, addressed, and we maintain compliance,” he says.

With automation-first machinery in place, Raj also feels more confident taking on further compliance mandates, starting with vendor risk. “We have a lot of vendors but limited intelligence on them. We are excited to rely on automation to track risk against vendors. Building on an existing solution is easy now,” he says.

Got questions? Talk to our experts!

AI-CTA-bg
AI-CTA-bg
nium logo
Industry Type

Cross-border payments

Employees

Regions

Singapore

Modules used
Continuous Monitoring Integrations Auditor Dashboard Real-time Alerts
Frameworks used
SOC 2 Type II
ISO 27001
PCI DSS