Get ready
before the request arrives
Compare your company against the supplier requirements an institution has published itself. Each gap becomes a task, with the colleague who can close it.
FOR COMPANIES SELLING INTO REGULATED INDUSTRIES
AI works through the assessment, the contract promises and every review after — your team approves everything before it goes out. A bank, insurer or payment institution cannot sign with you until its risk team is satisfied, and it keeps asking for years after that.
Invented example
Complimentary assessment review · Limited availability.
No card. No subscription.
Evaluate without sending us anything: work in the sandbox on fictional data. Your own documents move only after a mutual NDA.
Ready to use MatchAudit now? Start your workspace — €299/month
“How is customer data encrypted at rest, and how are the keys managed?”
Customer data at rest is encrypted with AES-256. Keys are held in a managed key service and rotated every 12 months.
The source stays visible. Missing evidence is surfaced instead of guessed.
WHAT A REGULATED CUSTOMER ACTUALLY COSTS YOU
Most tools help you with one questionnaire. That is stage two of four. The other three never finish.
Across every regulated customer
Health, actions, renewals, contract dates and operational notifications.
Action queue
3 open internal requests
Quarterly service report due
Contract dates not set
Next reassessment scheduled
Notifications
Notice period starts in 14 days
Alpine Payments · contract renewal
New evidence linked
Penetration-test report v2 · Northstar Bank AG
8 dates to manage this quarter
Renewals, notice periods and scheduled reassessments in one view.
before the request arrives
Compare your company against the supplier requirements an institution has published itself. Each gap becomes a task, with the colleague who can close it.
the questions they actually sent
AI writes a first answer from facts you have already approved, and shows the document it used. A person approves it. What you send is then saved exactly as you sent it.
the promises inside the contract
Upload the signed agreement. Each promise is pulled out with the clause it came from, approved by a person, then tracked as repeating work with an owner and a date.
every month, once you are live
Incidents, the reports you owe your customer, review dates and renewals — all on the same customer page you answered the assessment from.
Stage one is preparation written by MatchAudit from documents an institution has published itself. Public requirements help you prepare; the institution still decides what it accepts, and what it sends you directly may differ.
One customer. One place for all four stages. You pay for each customer relationship, not for each user. See what it costs
Every institution asks about a different mix of these, and each uses its own words. Requests shaped by DORA, the EBA outsourcing guidelines, an ISO 27001-based template, CAIQ, SIG or an institution’s own format all meet the same profile of your company.
WHAT YOU ARE DOING INSTEAD TODAY
HASthe sales deal
DOES NOT HAVEthe assessment that is blocking it, or anything you owe after signing
HASyour standard answers
DOES NOT HAVEthe customer, or the promises you made to that customer
HASthe documents
DOES NOT HAVEwhich version of a document your approved answer used
HASthe dates
DOES NOT HAVEwho is responsible, the evidence, or what has just changed
MatchAudit does not replace your CRM or your answer library. It keeps what neither of them can: the customer, and everything you owe them.
SEE IT BEFORE YOU TRUST IT
Banks, insurers, card networks, payment institutions and investment firms across the EU, UK, US, Canada and India. For each one, its own published supplier-control document is turned into a single preparation checklist.
One published source per institution — for example JPMorgan Chase’s “Supplier Minimum Control Requirements” — plus EU DORA as its own regulatory baseline. 34 published sources in total.
Each source becomes one checklist: the evidence and documents to have ready, and the control areas that institution typically assesses — governance, access, encryption, resilience, incidents, subcontractors.
Each source is automatically re-checked for changes on a 30-day cycle. A detected change is reviewed by a person before the checklist is republished.
IN THE LIBRARY TODAY
Checklists are written by MatchAudit from publicly available documents. MatchAudit is not affiliated with or endorsed by the institutions listed. Public requirements help you prepare; the institution still decides what it accepts, and what it sends you directly may differ.
CLARITY FOR EVERY CUSTOMER
Three questions. One shared view. What is blocking this customer?
Who needs to act? What is due next?
Aster Bank · Cloud services
WHAT NEEDS ATTENTION?
Updated insurance certificateAction needed to move forwardWHO NEEDS TO ACT?
FinanceAssigned teamWHAT’S DUE NEXT?
Upload certificateDue tomorrowExample workspace with invented data. Switch between onboarding and ongoing commitments to see how the work continues after go-live.
WHERE THE NEXT REVENUE COMES FROM
Go-live is not the end of the relationship. Keep follow-up questions, renewals, new services and scheduled reviews in one place, and start preparing when a supported institution changes its supplier requirements.
Follow the renewal dates for insurance, policies, certificates and other evidence.
Compare the new requirement with what you already have, and see what you will probably need to prepare.
Give every performance report, fix, review and contract date an owner, so the renewal conversation starts from a clean record.
INSIDE STAGE TWO
The workflow interprets the request, retrieves the relevant evidence and prepares a traceable draft. A person decides what leaves the workspace.
Invented exampleMatched an approved statement to the current policy source.
Customer data at rest is encrypted with AES-256.
Information Security Policy v4 · §2.3HOW MATCHAUDIT WORKS
More than autocomplete: the work stays connected from the incoming question to its evidence and the final human decision.
The assessment is broken into the questions and evidence requests that need a response.
MatchAudit searches the information available to your workspace for relevant material.
AI drafts responses grounded in available evidence and links the supporting source.
Your team sees what is supported, what needs editing and where evidence is missing before anything is approved.
TYPING IT INTO THEIR PORTAL
A Manifest V3 extension for Chrome, supporting SAP Ariba and Coupa question fields today. It is paired and installed with our help rather than downloaded from a public store, and it suggests — a person confirms every insertion and submits the portal form.
Supplier questionnaire · question 19 of 42
CUSTOMER PORTALState your recovery time objective for the service in scope.
No credentials
Portal passwords are never read or stored.
Never submits
It fills a field. It does not press send.
Stale is blocked
A source past its review date cannot be inserted.
WHAT THE WAIT ACTUALLY COSTS
Use your own deal value and timeline to understand what remains deferred while the assessment is open. The calculation is illustrative and is not a promised MatchAudit outcome.

EXPERT-LED REVIEW
Led by Emmi Jose, Founder & CEO. MatchAudit brings practical experience to evidence-heavy supplier assessments and the work surrounding them.
COMPLIMENTARY ASSESSMENT REVIEW
Available to a limited number of companies with a live supplier assessment from a regulated customer.
Nothing is uploaded on this website. Tell us which assessment is open, and we work through a sequence your own compliance team can sign off on.
The form beside this: who is asking, roughly how many questions, when it is due. No documents, no card.
Optional, and available straight away. The 5-day sandbox lets your team use the workspace before any of your own material is involved.
Your customer’s questionnaire, your policies and your evidence stay with you until it is in place.
You upload them into your own workspace, and we return a reviewable draft pack with sourced answers, visible evidence gaps and a clear list of decisions for your team.
A 30-minute review call is included so your team can walk through the draft, sources and outstanding items with us.
No card. No subscription.WHY ONBOARDING STALLS
Policies sit in folders, old answers sit in old questionnaires, the current version sits in someone’s inbox, and the colleagues who can confirm any of it are already busy. Every institution then asks for the same facts in its own words, and rarely only about security.
SEE HOW ONE CUSTOMER REQUEST IS ANSWERED
Reuse what your team knows. Find what is missing. Keep a person in control of every answer. Explore three examples with fictional customer data.
THE CUSTOMER CONTEXT
Aster Bank · Business continuity questionnaire
Recovery time objective: 4 hours. Recovery point objective: 1 hour.
Example only · invented documents and customer
MATCHAUDIT AI
Our documented recovery time objective is 4 hours, with a recovery point objective of 1 hour for the service covered by this plan.
Before you send this answer, check that the plan covers the service Aster Bank is buying.
Security reviews the draft and its source.
Example with invented data. Look at an answer, a missing document and a changed requirement. This example does not use a live AI model and does not send any data.
CONNECT ONCE. ADAPT FOR EVERY REGULATED CLIENT.
AI reads the request, matches it to your evidence and proposes an answer. Your team checks the evidence and decides what the customer receives.
Upload the questionnaire, document request or supplier requirements as PDF, Word, Excel or CSV, whatever topic they cover, and compare them with the facts and evidence your team already trusts.
Show whether your evidence is enough, out of date, incomplete, contradictory or missing, and explain what is needed and who should provide it.
Write the response for that customer together with its sources, let your team approve it, export the approved answers and their sources as CSV or JSON, then keep a record of what you sent, the follow-up questions and what you promised.
AI prepares. Your team approves. Review answers and sources before anything is shared with your customer, then place the approved response into your customer’s own portal or template. See a finished response pack Try the enterprise sandbox
VENDOR-SIDE BY DESIGN
Answer libraries and trust centres keep your standard content. MatchAudit keeps your customers — each one’s requirements, contract promises, incidents, reports, review dates and owners — so the work that wins an institution is the same record that keeps it.
ONE APPROVED FACT, USED FOR EVERY CUSTOMER.
See how ready you are against the supplier requirements an institution publishes. This preparation stays separate from the real questionnaire your customer sends you.
Know what to prepare before the deadline.Link approved facts and documents to several customers and services. Before you use an answer again, check that it still fits, with its source next to it.
Ask your experts the same question less often.Keep the answers and the exact document versions behind everything you sent. New documents are used for new work and do not change the old record.
Answer follow-up questions with the right facts.Your team approves every answer you share. Your customer decides when you are approved.
Review securityINSTITUTION READINESS
The library maps 33 regulated institutions across 34 published requirement sources. Summaries are written by MatchAudit from publicly available documents.
MatchAudit is not affiliated with or endorsed by the institutions listed. Public requirements support preparation; the institution still decides what it accepts.
BEFORE YOU UPLOAD A SINGLE DOCUMENT
Your policies, architecture descriptions and audit reports are among the most sensitive files your company holds. This website never accepts one: documents are uploaded inside your own workspace, after a mutual NDA. These are the answers your own security team will ask for, stated plainly.
What we do not claim. MatchAudit does not hold a SOC 2 report or an ISO 27001 certificate. Our managed infrastructure provider holds both for its own hosted platform, which is not the same thing. The Security page sets out which controls are ours, which are the provider’s, how long your data is kept and how you export it if you leave.
BEFORE YOU SUBSCRIBE
Start wherever you are comfortable. None of these requires a card.
A complete pack for an invented customer: sourced answers, the evidence each one came from, visible gaps and the approval record.
Instant · no email requiredSee the sample packHands-on access to the Assurance Workspace using a fictional vendor-and-customer scenario. Open a questionnaire, draft a sourced answer from approved facts and approve it, without exposing anything of your own.
Work email · reviewed by our team · 5 days · fictional data onlyRequest sandbox accessStart with the form — no documents at that point. We arrange a mutual NDA first, and your questionnaire, policies and evidence move only after it is signed. You get back a reviewable draft pack with sourced answers and visible gaps, plus a 30-minute review call.
Limited availability · no card, no subscriptionRequest a complimentary draftONE PRICE. NOTHING HIDDEN.
Add colleagues without a per-seat charge, keep prospects without increasing the customer count, and set the growth limit your team approves. The workspace opens once a subscription is active; before that, read a finished response pack or tell us about the assessment you are working on now.
€299/month
Per workspace, excluding tax. Your first five billable customers are included.
Monthly billing · no annual commitment · no per-seat charge · cancel renewal online
| Customer number | Monthly rate |
|---|---|
| 1–5 | Included in €299 |
| 6–20 | €25 each |
| 21–50 | €20 each |
| 51+ | €15 each |
REMOVE THE UNCERTAINTY
Companies that sell technology, products or services to banks, payment institutions, insurers, fintechs and other regulated enterprises, especially in Europe. It brings sales, customer success, security, legal, finance and operations together around the work needed to onboard and support each customer.
No, and it is not only about security. MatchAudit works for the vendor, not for the institution. The institution runs its assessment. That assessment covers ownership and control, financial standing, information security, architecture and hosting, data protection, operational resilience, business continuity, subcontractors and contractual commitments. MatchAudit helps the vendor understand each request, use approved information again, close gaps, prepare a response and manage what happens next.
You upload the request your customer sent and the documents behind your answers as PDF, Word, Excel, CSV or images. MatchAudit reads the requirements, drafts each answer from your approved facts and documents, and shows the source next to every answer. Your team approves. You then keep a submission record of exactly what was sent, in which document version, through which channel and on which date, and you can export an approved report as CSV or JSON. MatchAudit does not fill in your customer’s own portal or template for you: your approved answers are there for your team to place into it.
MatchAudit does not assume one framework. It reads the requirements your customer actually sent, whether the request is shaped by DORA, the EBA outsourcing guidelines, an ISO 27001-based template, an industry questionnaire such as CAIQ or SIG, or a template the institution wrote itself. Each requirement is matched to your own facts and evidence, so the same approved information can answer differently worded questions from different customers.
The MatchAudit workspace and its AI assistance work in English, and most European institutions send their supplier assessments in English. If a customer sends you a request in another language, talk to our team before you subscribe so you know what to expect.
Your documents are not used to train AI models. Every AI call MatchAudit makes runs with provider-side storage switched off, and our model provider does not train on content sent through its API. The database, authentication and file storage run in the EU on Supabase in eu-west-1, Ireland. Evidence files are stored privately and downloaded through short-lived signed links. Subprocessors, and any processing outside the EEA, are listed on the Subprocessors page.
Yes. Send us the supplier assessment your company runs, or the one your customer has sent you about us, and our team will complete it. We do not hold a SOC 2 report or an ISO 27001 certificate and will not claim otherwise. The Security page states which controls are ours and which belong to our infrastructure provider.
€299 per month per workspace, excluding tax, including your first five billable customers. Billing is monthly with no annual commitment and no per-seat charge. Creating an account does not start a paid subscription: you review the price and approve a growth limit before authorizing payment. An owner or administrator can cancel renewal online at any time, and paid access continues to the end of the billing period.
Yes, and without sending us anything. Start with the hands-on sandbox, which uses fictional data only and must not be used for real customer information, or read the complete sample response pack. There is no self-service trial on your own data. Subject to availability, a company with a live supplier assessment can also request a complimentary sourced draft; that runs behind a mutual NDA before any of your documents move.
No, and this website does not accept document uploads at all. The request form takes your work email, your company, who is asking and when it is due. We reply within one business day and arrange a mutual NDA; your customer’s questionnaire, your policies and your evidence stay with you until it is signed, and they are then uploaded into your own workspace rather than emailed to us. If you want to see the product before any of that, the sandbox runs on fictional data.
Assume yes. Once you hold customer-related information in MatchAudit we are a subprocessor under your own customer agreements, and most banks and insurers expect to be told and to see us named in your subprocessor list. We publish our subprocessors, and the Security page sets out which controls are ours and which belong to our infrastructure provider. If your customer sends you a questionnaire about us, our team completes it. We do not hold a SOC 2 report or an ISO 27001 certificate, and we will not claim that your customer will accept us.
Keep them. Those are built around the answer: text to reuse, a page to publish, a form to fill in faster. MatchAudit is built around the customer relationship the answer belongs to — whether the answer is still correct for this institution, which document version you sent, who owes the missing item, what you promised and what that customer expects next. It reads facts from Vanta, OneTrust and ServiceNow, so information you already maintain keeps the record, field and date it came from, and the next questionnaire starts from approved information instead of asking your colleagues again.
AI reads the requirements, finds missing information and writes draft answers from your facts and documents. Your team checks the sources, approves the answers and decides what is shared. People still give the final approval and send the response to the customer. Public supplier requirements help you prepare. They are not the same as a request your customer sends you directly.
Keep them. MatchAudit connects today to Vanta, OneTrust and ServiceNow. Facts you map are read from those systems and keep the record, the field and the date they came from. An owner or administrator starts the synchronization; it does not run by itself in the background. Anything held in another system is uploaded or entered by hand and then behaves the same way. If the system your team relies on is not one of those three, tell us which one it is.
Create your account, confirm your workspace subscription, then add one customer and the information you already have. Use that customer’s request to find the first missing document or answer, and give it an owner. Setup time depends on how much information you add first, so start with the request that is open now. You can contact our team before you subscribe if you want to discuss how your team works.
A REVIEWABLE RESPONSE PACK
Start with the customer request that is open now. No documents until an NDA is signed.
Then see what is supported, what is missing and what needs a decision.