The month before every assessment
Ledgerline passed its assessments. It just paid for them twice: once in the assessment itself, and once in the four weeks beforehand, when four people stopped doing their jobs and went looking for documents.
The evidence existed. It was in a mail thread from fourteen months ago, or on a shared drive under a filename with somebody’s initials, or — often enough to matter — only in the memory of a person who had since moved teams. Every assessment started by rebuilding a picture that had been complete once already.
Collect once, at the review
Nothing about what Ledgerline collects changed. What changed is when, and where it lands.
Evidence is now attached to the vendor at the moment of the review, with its issue date, its expiry and the control it answers. When a SOC 2 report expires the review reopens on its own; when a sub-processor list changes, the vendor’s PCI scope flag is re-evaluated. By the time an assessor asks, the answer is a filter, not a search.
“The assessor asked for the pen test on our tokenisation vendor. It took about eleven seconds. Last year that question cost us two days.”
The 2026 assessment
- Zero findings against third-party management, against three observations the year before.
- The evidence-gathering window fell from thirty days to four, and three of those four were scheduling.
- 96% of requested artefacts came out of the vault on the first ask. The remaining 4% were two vendors onboarded the month before the assessment.
What’s next
Ledgerline is mapping the same vault against DORA, which shares most of its evidence with PCI and almost none of its vocabulary. The mapping is the work; the documents are already there.
About Ledgerline
Ledgerline builds payment orchestration for European merchants. 310 people across Stockholm and London, PCI DSS Level 1 and SOC 2 Type II. Tomas Ek heads the compliance function and owns the third-party programme.


