The reading list
a tech-due-diligence team
works through.
Five canonical long-form references — written for the architects, risk officers and AI leads on the buyer side. Each one is a load-bearing document we link from sales conversations and regulator briefings.
Five canonical references.
Designing a ledger that survives an audit.
Why double-entry beats single-entry under concurrency, what a posting actually looks like, and how zero reconciliation drift falls out of the design — not out of a Friday cleanup job.
Anatomy of a card auth, hop by hop.
A real production card-auth trace, with timing, ledger postings, and decision rationale at every hop. The same view an analyst sees in the operator workspace.
Three lines of defense, written down as configuration.
How the 1L/2L/3L model becomes diffable, reviewable artefacts in the same git history as the code — including who can change what, who has to approve, and how the regulator reads it.
Bounded AI: agents inside a replay-safe perimeter.
How operator AI suggests, never decides; how every prompt is journaled; how a regulator pulls the input hash, the output, and the human override seven years later.
The 90-day Wave-1 runbook, in detail.
Day-by-day deliverables for a telco × bank Wave-1 deployment. Phases, owners, named outputs, dependencies, gates. The artefact a programme manager hands to the steering committee.
The executive brief: embedded finance for telecom.
What a telecom CEO, CFO and CTO need to know about embedded finance — in one document. Business case, compliance posture, integration footprint and the 90-day path to first revenue.