# Fintech controls survey — instrument 2.0

The questionnaire has 13 questions and no responses. The existing questionnaire-v1.csv URL now serves version 2.0; inspect its version column before reuse.

## Unit and period
One legal entity and named product/business unit per response. Choose entity or unit sampling before recruitment; never count a parent and the same units together. Use a completed calendar year with recorded start/end dates. period_end questions describe the final day; reporting_period questions describe events within the year. Fieldwork dates are separate.

## Respondent and answers
One designated respondent gathers control-owner input and signs off the scoped answer file. Yes requires every applicable item; No means at least one fails; Unknown means records cannot establish the answer; Not applicable requires the exact row rule and a reason. Unresolved owner conflicts become Unknown. Preserve correction history and lock answers at closing.

## Private response fields
unit_id, legal_entity, product_scope, control_register_version, respondent_role, instrument_version, period_start, period_end, submission_date, question_id, answer, applicability_reason, evidence_status, evidence_reference, evidence_date, reviewer_id, review_date, covered_scope, review_reason.

Evidence statuses: self_report_only (nothing inspected); evidence_supports (dated scoped evidence covers all parts); evidence_conflicts (record contradicts answer); evidence_insufficient (record lacks date/scope/proof). Store answer and status separately. A one-route test cannot support Yes across three routes. These labels do not certify a system.

## Version changes from 1.0
Q02 now covers client retry only; Q13 covers webhook duplicates. Q05 covers payment vendors; Q14 covers identity vendors. Q04 covers the dated timeline test; Q10 is retired as its duplicate. Q12 measures expiry only. All rows gain period, definitions, N/A rules, and evidence prompts. Do not treat changed questions as comparable annual measures without validation.

## Pilot and release
Pilot with payment, security, and operations roles in several units; record interpretations, conflicts, blank items, evidence availability, and time. Revise and version before main fieldwork. Exclude pilot data unless wording/period/consent match final study. Publish exact questions, recruitment, eligibility/invitation counts, dates, unit mix, missing answers, evidence counts, and limitations. Consent controls sharing and quotations.

Synthetic example: 20 units invited; Q02 has 4 Yes, 2 No, 1 Unknown, 1 N/A, 12 missing. State 4/6 applicable known answers or 4/8 respondent Yes answers with the chosen denominator. Neither estimates every Nigerian fintech.

Sources: https://aapor.org/standards-and-ethics/transparency-initiative/ ; https://cheatsheetseries.owasp.org/cheatsheets/Logging_Cheat_Sheet.html

License: CC BY 4.0. Credit Simpa Labs and identify changes. Updated 2026-10-01.

## Freeze eligibility and scope
Record study_id, release_id, eligibility rule, recruitment route, contact dates, fieldwork start/end, closing date, and named study owner before invitations. Define the target population by legal entity type, geography, payment activity, and unit rule. A voluntary invitation list must be described as that list. Do not label its answers representative of all fintech firms.

Give each eligible unit a stable unit_id. Keep one final response per unit, question, instrument version, and reporting period. Resolve duplicate submissions with the designated respondent and retain earlier copies. Keep invited, ineligible, declined, unreachable, partial, and complete unit counts. A partial response supplies at least one valid question answer; a complete response supplies all 13, including justified Not applicable answers. Unknown is a valid response, not a blank.

Freeze a scope inventory with path IDs, endpoints, providers, devices, approval routes, control IDs, and exception records. period_end questions use items active on the last day. reporting_period questions use items active at any point in the year, including systems retired before year end. Newly connected vendors are vendors receiving their first production access during that year. Control changes must be dated; a current screenshot alone cannot establish a prior-year state.

## Decide Yes, No, Unknown, or Not applicable
Apply the row's Not applicable rule first only when the scope inventory proves no applicable items. An empty or missing inventory cannot establish Not applicable. For an applicable question, any established failure gives No, even if other items are unknown. With no established failure, incomplete knowledge gives Unknown. Yes requires all stated parts for every applicable item. For a question asking if a test occurred, a record showing no test gives No; a missing history gives Unknown. An unapproved or missing control register cannot establish that Q06 has no key controls.

For synthetic Q07, three approval routes are in scope. Two pass both field-change tests; the third accepts a changed destination. The answer is No. If no failure is known but the third route has no record, the answer is Unknown. If the respondent reports Yes anyway, retain that answer separately from evidence_insufficient and request a correction before closing. Evidence review does not silently change a reported answer.

## Response field rules
Add scope_inventory_version, applicability_count, item_answer_notes, response_state, answer_revision, consent_scope, and retention_end to the private response fields above. response_state is answered, missing, or withdrawn. For answered rows, answer must be Yes, No, Unknown, or Not applicable. A missing or withdrawn row has a blank answer and no evidence status. Not applicable requires a reason and scope reference. applicability_count is the known number of relevant items; use a blank with a reason when the inventory cannot establish it.

For evidence_supports, the record must support the actual answer. A dated failed approval test supports No; an inventory showing zero new vendors supports Not applicable. A Yes needs full coverage. An inspected record that proves the opposite answer is evidence_conflicts. A record that lacks needed scope, date, or proof is evidence_insufficient. With no inspection, use self_report_only. Unknown can be supported by a dated review showing a specific unresolved gap; it is not evidence of a working control.

Evidence references point to private redacted records, not public links to customer data. Collect the minimum needed fields; record who can access them, the retention end, and how deletion will be checked. Get separate consent for participation, anonymous aggregates, attributable quotes, and any shared record. A participant's permission to answer is not permission to publish the evidence.

## Validate counts and report changes
Require 13 final question slots per invited eligible unit. Q10 is retired and must not appear. Reject duplicate final keys, unknown question IDs, wrong versions, invalid answers, and Not applicable without a reason. For each question, Yes + No + Unknown + Not applicable + missing + withdrawn must equal eligible invited units. Report missing and withdrawn separately. For answered rows, the four evidence-status counts must equal the answer count.

Report unweighted counts first. The known applicable Yes share is Yes / (Yes + No); the respondent Yes share is Yes / (Yes + No + Unknown + Not applicable). State which one is used and publish its counts. If a denominator is zero, report no estimate. A verified Yes count is Yes rows marked evidence_supports; report its count and denominator separately from self-reports. Do not replace unknowns or missing answers with No or calculate one overall maturity score from these questions.

For annual changes, compare the same question wording, unit rule, scope, and evidence method. Publish both the full annual sample and a matched-unit comparison when the units change. State departures and additions. Changed questions need a bridge study before a trend claim. Keep a release log with each correction and the report tables it changes.
