Rakuten International Commercial Bank

Three years inside a licensed bank.

Regulator-set rules, five vendors I could not manage, and an audit at the end. Here is what my team shipped anyway.

  • KYC CDD/EDD with IBMaccepted
  • Mobile ID device binding4 modules
  • PwC security findings15 closed
  • Quarterly delivery100% on time

Building with rules you did not write

A licensed bank is a building with rules you did not write. Everything you ship has to survive an audit at the end of it.

Constraint 1 The regulator Taiwan's FSC sets what the system has to do. Not how, and not on a timetable that suits you.
Constraint 2 The operations department Operations owns the requirements, and hands them over in the language of regulation rather than features.
Constraint 3 Five vendors, one of them IBM They deliver pieces you depend on and do not manage. You carry the deadline either way.

Three critical production deliverables

FSC accepted IBM vendor delivery

KYC re-verification with IBM

My main job was KYC re-verification, the check a bank has to repeat on customers it onboarded years ago. When I joined, staff still chased those customers by hand. I built the system that sorts them into 1, 3, or 5-year cycles based on their money-laundering risk score, and it passed Taiwan's FSC review and went live. That “accepted into production” line sounds boring until you have tried to get there.

Reused across 4 modules Mobile ID gateway

Device binding security gate

Engineered the gate that unlocks fund transfers by verifying handset SIM against the registered account number via telco Mobile ID. Built once with clean abstraction, then reused across four core transfer modules rather than reimplemented.

15/15 PwC findings closed IndexedDB migration

PwC external security audit

An external PwC assessment flagged sensitive client storage in browser cookies. Migrated storage to encrypted IndexedDB and systematically resolved all 15 audit findings to full sign-off.

Leading the delivery

9engineers
5vendors
100%on-time quarters
2 daysto first PR
✗ Before (Ad-hoc Process)

3 weeks for new engineers to ship first pull request · No standardized review practice for vendor code · Vulnerable to specification mismatch.

✓ After (Engineering Governance)

2 days to first PR via Confluence runbooks · Standardized vendor code-review SOP in active use · 100% on-time delivery across every quarter.

Why this matters for Forward Deployed roles

FDE Challenge How I Handled It Inside the Bank Tangible Proof
Non-Technical Stakeholders Translated regulatory and operations requirements into production software architecture. FSC-compliant KYC with IBM
External Vendor Dependencies Managed 5 vendor teams without direct authority through clear SOPs and quality gates. 100% on-time delivery track
Strict Audit & Compliance Led security hardening and architectural compliance under strict scrutiny. 15/15 PwC audit closures