Screening exposure is real, and badly served for teams without a large compliance department. That is the product we set out to build.
OUR STORY
We did not guess at this problem.
We have sat on both sides of it.
MatchAudit began as a sanctions screening company. What kept surfacing in screening conversations was not the screening result. It was the assessment their regulated buyer had to finish before a contract could be signed at all.
So we moved to the vendor's side of that gate, and we built it with people who run the other side of it for a living: vendor managers inside a bank who decide whether a supplier's evidence is good enough to put to signature.
- Built from real banking vendor-management practice
- Vendor-side by design
“They chose us in March. We still cannot sign.”
The deal is won and still not closed. Nobody can tell us what is outstanding, or when it clears.
- Asked for proofs nobody told us to keep
- Same facts, a different format every time
- A rejection that arrives weeks after we sent it
“We cannot put this to signature on this evidence.”
The business has already chosen this supplier. Our own policy still puts the assessment in front of the contract.
- The policy sent does not cover what was asked
- The report is expired, or names a different entity
- Back it goes, and the queue starts again
The assessment is not paperwork that follows the deal. It is the gate in front of it. A regulated institution generally cannot execute the contract until its third-party assessment is complete. Due diligence before entering the arrangement is what its own policy, and the supervisory expectations behind that policy, require. Until the assessment clears, there is nothing to sign, nothing to onboard and nothing to invoice.
Screening was the door. The onboarding queue was the room.
In screening conversations, the recurring blocker was not the result. Companies had won the business and still faced a buyer-controlled third-party assessment before a contract could progress.
We moved to the vendor's side of that gate and built the preparation, the sourced answers and the record of what was sent.
THE PROBLEM WE DECIDED TO SOLVE
Two queues, a deal that cannot close,
and a rejection that arrives too late to help.
In some institutions the stretch between being chosen and being contracted ran months rather than weeks. That is our own observation from these conversations, not a published benchmark, but it was consistent enough to change what we were building.
Delay on the customer side
The institution's assessment team has a queue, a review cycle and its own internal approvals. The vendor cannot see into any of it, and no contract can be executed until it closes.
Delay on the vendor side
The documents exist, somewhere. They sit with security, legal, finance and operations, in versions nobody has reconciled, and every new request restarts the hunt.
And then the rejection
The wrong document, an expired report, the wrong legal entity named, a policy that does not cover the question. The answer can come back long after it was sent.
- DEAL WONThe institution chooses you and agrees commercial terms. Nothing is signed yet.
- ASSESSMENT OPENSGATEThird-party due diligence has to complete before the contract can be executed.
- EVIDENCE GOES BACK AND FORTHDocuments are requested, hunted down, submitted, queued, and sometimes returned as wrong.
- ONLY THEN: SIGNATUREContract, onboarding, go-live and the first invoice all wait on the step before them.
So the cost is not a late invoice. It is a won deal that cannot be closed, carried across quarter boundaries in a forecast, while the person who chose you keeps defending that choice internally and their own project cannot start.
BUILT FROM INSIDE THE BANK, TOO
We know what gets rejected,
because we have rejected it.
MatchAudit is built with a vendor manager who runs suppliers through their complete lifecycle inside a bank: selection, assessment, approval, contracting, ongoing monitoring, re-assessment and exit. Not a consultant's view of the process. The daily work of it.
That is an unusual vantage point, because it sees the failure from both ends at once. The supplier chasing colleagues for a document it did not know it needed. The reviewer who cannot send a file to approval when the evidence does not answer the question, and who knows a signature is waiting on that decision.
- Why submissions actually come backRarely because the supplier is unsafe. Usually because the evidence does not match the requirement, is out of date, or describes a different legal entity.
- What a reviewer needs to close an itemThe specific document, current, attributable and clearly tied to the requirement being asked about.
- That the assessment comes back after signature tooMonitoring and periodic re-assessment keep returning for as long as the account exists, which is why the product keeps your evidence current rather than filing it away.
The contract cannot be signed until stage 2 clears. And stage 2 comes back, as stage 6, for as long as you hold the account.
- 1Selection and commercial terms
- 2Third-party assessment
- 3Approval and contract signature
- 4Onboarding and go-live
- 5Ongoing monitoring
- 6Periodic re-assessment
- 7Renewal or exit
THE INSIGHT
The questionnaires differ.
The requirements underneath largely do not.
Many regulated institutions publish their third-party risk management framework. We started collecting them and reading them side by side.
What the questionnaire looks like depends on the tool it is run in, Coupa, Ariba, another third-party risk platform or a template the institution wrote itself, and on the house style of whoever drafted it. Same question, different words, different order, different boxes.
What sits underneath is far more consistent, because the institutions are discharging the same underlying regulatory requirements. So we used those published frameworks to derive a base set of the proofs and documents a vendor is likely to be asked for, and the form each one has to take to be accepted.
That list can be assembled long before you are in a deal, which is also the most reliable way to send the right document the first time instead of learning it was wrong two months later, with the contract still unsigned.
- INSTITUTION ADescribe your controls for the secure disposal of client data at the end of the engagement.
- INSTITUTION BRetention schedule and deletion evidence for personal data processed on our behalf?
- INSTITUTION CConfirm data retention periods and provide the approved policy document.
Data retention and deletion, evidenced by a current approved policy.
Prepare it once, keep it current, and answer all three from the same approved source.Illustrative wording. Each requirement in the library keeps the source it came from, that source's version and the date it was retrieved.
WHAT WE BUILT
A workspace that belongs to the vendor,
not to the institution assessing it.
MatchAudit sits beside the systems your team already uses. It does not replace your policy management, your compliance platform or your document store. It turns what you have into answers a regulated buyer can review, and keeps the proof attached.
A library of published supplier requirements
Requirements drawn from the third-party risk frameworks regulated institutions publish, organised by topic and kept with the source, its version and the date it was retrieved.
Readiness before anyone asks
See which proofs and documents you already hold and which you do not, so the gap is found on your schedule instead of in the middle of a deal.
Gaps with an owner and a date
Each missing item carries an explanation of what is needed and who should provide it, so it becomes somebody's job rather than an open question.
Answers that show their source
Drafts built from your approved facts and documents, with the evidence shown next to each answer for your team to check before anything is shared.
Answers proposed inside the portal
For supported SAP Ariba and Coupa questionnaire fields, a browser assistant offers your approved answer with its source next to it. A person confirms every insertion, and it never submits on your behalf.
A record that outlives the submission
Which answer, in which document version, on which date. Approved facts keep their own review dates, so the next customer starts from what you already proved.
AI reads the requirements, finds what is missing and drafts each answer from your own facts and documents. Your team checks the source, approves the answer and decides what the customer receives. That is the part we will not automate away, because it is the part your name is on.
WHO IS BEHIND IT
Built by people who have been assessed,
and people who do the assessing.

“Being the smaller company on the other side of a large institution's process is a specific kind of powerless. You are asked for things nobody ever told you to keep.”
Emmi Jose is the founder and CEO of MatchAudit. Finnish by origin, German by choice, she read international relations with a focus on Eastern Europe, the geography that now sits at the centre of EU sanctions policy.
She then traded across borders herself. Running an import business into the German market meant meeting the compliance regime from the outside in: requirements arriving without context, evidence scattered across inboxes and spreadsheets, and decisions defended months later from memory. That experience produced MatchAudit's screening work.
The company that followed came from a second vantage point closer to home. Her husband manages vendors through their full lifecycle inside a bank, and the two sides of the same broken exchange turned out to be a dinner-table conversation: the supplier who cannot find out what is wrong, and the reviewer who cannot let a contract go to signature on evidence that does not hold.
The information a regulated buyer wants almost always exists inside the supplier. What does not exist is the one place where it is collected, current, owned and ready to send.
Practitioners, not an advisory board
MatchAudit is built with senior practitioners from global payments providers, Big Four consulting and Tier-1 European banking, whose careers have been spent inside third-party risk, GRC frameworks, anti-financial-crime operations and regulated product management.
Some have sat on the institution's side and sent supplier submissions back. That is why the product cares which document version was sent and whether the evidence answers the requirement. Several remain in senior industry positions and are not named publicly.
Supplier scrutiny is increasing, not easing
DORA made third-party oversight an explicit and continuing obligation for financial entities, with due diligence required before a contractual arrangement is entered into. Outsourcing expectations had already pushed institutions in the same direction.
Every one of those obligations lands on the institution. Every one of them arrives at the vendor as a request, before there is a signed contract to stand on. Somebody has to build the vendor's side of that exchange.
HOW WE THINK
Three principles we do not trade away.
Prepare before you are asked
The cheapest moment to find a missing document is before a deal depends on it.
Every answer carries its source
An answer without the document behind it is an opinion, and an assessor is entitled to reject it.
A person approves what is sent
AI prepares the work. Your team checks the evidence and decides what the customer receives.
WHERE THIS GOES
The work you do for one regulated customer should make the next one cheaper.
Today a vendor answers each institution from scratch, and the effort disappears the moment the response is sent. We think that is backwards. Every approved fact, every current document and every accepted answer should shorten the next assessment, hold its own review date, and still be there when the periodic review, the renewal or the next deal comes around. The ambition is a company that is continuously ready to be assessed, rather than one that scrambles each time it is.
START HERE
Your next regulated customer will ask.
Have the answer ready.
Add the customer whose assessment is open now, connect the documents you already have, and find the first missing item before it becomes the reason the contract cannot be signed.
- Creating an account does not start a paid subscription
- Monthly billing · no annual commitment
- Data stored in the EU