Regulatory horizon scanning
Continuous monitoring across regulatory, enforcement and news sources, drafted into a
weekly briefing by AI and written against your own open risks and outstanding tasks —
not a generic newsletter. Reviewed and published by your own super admin or second
line before it reaches your inbox.
Risk register
A structured register covering inherent and residual exposure, treatment plans, and
periodic review. Every risk has an owner, a signed-off assessment, and a clear
connection to the controls that mitigate it.
Compliance monitoring
Recurring assessments mapped to the frameworks that apply to your licence and
jurisdiction. Questions are structured to surface genuine gaps rather than generate
compliance-theatre paperwork.
Incidents and near misses
A register for reporting, investigating and closing incidents, with a direct link to
the underlying risk. Patterns across reporting periods become visible rather than
buried in individual files.
Policy library
Versioned policies with named owners, scheduled review dates, and a record of staff
acknowledgements you can produce on request.
Third-party register
Suppliers catalogued and tiered by criticality, with due diligence requirements that
scale to the tier. A supplier handling customer data is assessed considerably more
rigorously than a stationery supplier.
Annual assessments
Risk maturity, compliance, and a business-wide financial crime risk assessment
following the FATF Recommendation 1 methodology, which is what regulators look for.
Board reporting
A board pack assembled from your live data, with follow-up actions tracked to
closure. Produced from the same records rather than retyped from them.
Full audit trail
A complete record of who changed what and when, visible to your own administrators.
This includes any access by our own staff, so you are never asked to take our word
for it.