16 Modules · 1,000+ Templates · One Platform

Built by compliance professionals.
So you don’t have to be one.

Sixteen regulatory-anchored modules with the expertise built in — step-by-step guidance on every screen, 1,000+ ready-made templates, and Otto, your AI compliance analyst, one question away. Bundled into three simple plans so you pick the one that fits your firm. For FCA-regulated firms that need supervisory-grade evidence — fast.

Book a Consultation

14-day free trial · Take the tour

Bank-Grade Encryption
SOC 2 Infrastructure
ISO 27001 Infrastructure
UK & EU Hosted
ICO Registered
Platform Modules

Sixteen modules, plus Otto. See inside every one.

Every module maps to its FCA sourcebook, comes pre-loaded with expert templates and is wired into Otto for live MI and board-ready reports. Pick a module — the live screen first, the full detail beneath it. Click any screenshot to enlarge: this is the live product, not a mock-up.

16
Modules
1,139
Expert Templates
72
Categories
7
Regulators Mapped
12,000+
Handbook Provisions
Starter
Growth
Pro
The Compliance Monitoring Plan: a twelve-month schedule heat grid above the list of monitoring areas with category, frequency, owner, last review and next due date
Starter plan

Compliance Hub

Your whole compliance monitoring programme in one place

The Compliance Hub runs the firm's entire compliance monitoring programme from one surface: 1,139 expert-built templates across 72 categories spanning seven regulators, plus a unified register for attestations, breaches, complaints, conflicts and custom forms, and every rule a check cites opens its current wording from the FCA Handbook. Handbook attestations walk eight sourcebooks chapter by chapter, MCOB and CONC included. A dual-mode calendar sets the firm's own tasks alongside 27 pre-loaded FCA regulatory events, and the Reports module builds a 12-section Compliance Monitoring Report from the plan's live data, with Otto writing the commentary. It is where the Compliance Officer runs the monitoring plan day to day.

Who it’s forCompliance Officers and SMF16 holders running a SYSC 6.1 monitoring programme, and consultants switching between several client firms from one login.

What it does

  • 1,139 templates, 72 categories, 7 regulators
  • Unified register: attestations, breaches, complaints, conflicts, gifts
  • Rule references on every check open their live FCA Handbook wording
  • Handbook attestations for eight sourcebooks: COBS, ICOBS, CONC, MCOB, FPCOB, MIFIDPRU, FUND and Payment Services, one tab per Handbook chapter
  • Dual-mode calendar: firm tasks plus 27 FCA events
  • Form Builder with 14 field types for custom forms
  • MI dashboard: completion, coverage, findings by severity
  • Switch between client firms from one login

What it produces

  • 12-section Compliance Monitoring Report, built in Reports
  • Report exports to Word and PDF
  • Live registers: complaints (DISP), breaches (SUP 15.3), conflicts, G&E
  • MI dashboard of plan coverage and findings by severity
  • CSV export of any register
Regulatory coverage
SYSC 6.1SYSC 6.2PRIN 2ADISPSUP 15.3MLR 2017UK GDPR
The People Compliance register: total people, senior managers, certified persons, other staff, fit and proper reviews outstanding and due diligence completion, above the list of people records with job title and role type
Starter plan

People Compliance

Every regulated individual, evidenced and certified

The SM&CR, APER and IDD operating system: a register of regulated individuals where each record opens a regime-aware editor covering the SMF Statement of Responsibilities, the FCA Form A Section 5 fit-and-proper assessment, annual certification, due diligence and CPD. It models who does the regulated work, and applies to every authorised firm — SM&CR has had no proportionality exemption since December 2019.

Who it’s forThe SMF16, Head of Compliance or HR-compliance lead at any FCA-authorised firm — universal, since every firm has at least one Senior Manager and certified staff.

What it does

  • Six regime-native record types across SM&CR
  • 57-question FCA Form A fit-and-proper with RAG summary
  • Statement of Responsibilities: 31 Prescribed Responsibilities
  • 8 Certification Functions mapped to SYSC 27.8
  • CPD tracked against each person’s annual target
  • 9-document due-diligence onboarding checklist
  • PA dealing accounts and annual declaration per person
  • IRN look-up on the FCA Register: roles, disciplinary history, past firms

What it produces

  • Certificate of Competence PDF, 12-month validity, per certified person
  • FCA Form A Section 5 fit-and-proper assessment record
  • Statement of Responsibilities record for each SMF and NED
  • Every people register as CSV, in one ZIP download
  • F&P renewal reminder tasks into the Hub task list
Regulatory coverage
SYSC 10CCOCONFIT 1.3SYSC 27Form A s.5APERIDD
The Regulatory Intelligence live feed: publications from the FCA, PRA, HMRC, CMA, NCA and others, filtered by source, type and sector, with firm relevance and saved and read views
Starter plan

Regulatory Intelligence

Thirteen UK regulators, filtered to your firm

Regulatory Intelligence unifies 13 UK regulators — FCA, PRA, ICO, OFSI and nine more — into a single feed refreshed hourly, holding around 2,600 live articles pre-classified by source, type and sector. Otto's firm-relevance filter narrows the feed to what affects your permissions and products, you assess each item in a regulatory change register with a full audit trail, and Otto drafts a board-ready report exported to Word or PDF.

Who it’s forFor UK FCA-regulated SME firms — compliance officers, MLROs and Heads of Compliance who need to track multiple regulators and evidence regulatory awareness.

What it does

  • One hourly feed across 13 UK regulators
  • Otto AI firm-relevance filter, keyword-transparent and editable
  • Source, Type and Sector filters (8 FCA taxonomies)
  • Regulatory change register with full audit trail
  • Task register plus 30-day deadline calendar
  • Otto plain-English summaries of any update
  • Per-user Saved and Read lists

What it produces

  • Otto board-ready report — saved items, change register, tasks or combined pack — to Word or PDF
  • Regulatory change register with relevance, impact, owner and action logged
  • Otto plain-English update summaries (what it is, what it means, suggested actions)
  • Task register with owners, frequencies and due dates
  • Deadline calendar of consultation closes, go-live dates and reporting windows
Regulatory coverage
FCAPRAICOOFSIHMRCCOBSMCOBCONC
The Consumer Duty app: monthly MI headlines, the MI trend, the filing position for the year and the monthly MI capture table, with registers for products, outcomes, assessments, feedback, distribution, training and the board record
Growth plan

Consumer Duty

You attest, Otto drafts, your board signs

A complete operating layer for FCA Consumer Duty covering all four outcomes, the three cross-cutting rules and vulnerable-customer obligations. Humans attest on one firm attestation and a product review per product, and the Reports module builds the 13-section Annual Board Report from that live record, with Otto writing the commentary — the split of human input and sign-off the FCA expects to see. Every assertion in the report traces back to a named attestation, a register entry or a logged event.

Who it’s forThe roughly 80% of FCA-regulated firms with retail customers — retail banks, IFAs, wealth managers, consumer credit firms, insurance intermediaries and mortgage brokers subject to PRIN 2A.9.

What it does

  • 65-question firm attestation across 13 sections
  • 60-question product review and fair value assessment
  • Every attestation named, dated and owned
  • Documents attached to the register entry they support
  • Board Challenge Record: challenge, response, status
  • Year-locked records, one set per year
  • 21 A8 CMP monitoring checks

What it produces

  • 13-section PRIN 2A.9 Annual Board Report in Reports (PDF + Word)
  • Per-product fair value assessments
  • Board Challenge Record — dated, named log
Regulatory coverage
PRIN 12PRIN 2APS22/9FG22/5FG21/1PRODDISPSM&CR
The Financial Crime app: the MLRO board reporting log with presentations, board cadence and the most recent reports, and registers for MLRO oversight, transaction monitoring, sanctions, suspicious activity, anti-bribery and fraud
Growth plan

Financial Crime

The MLRO's financial-crime operating system

Financial Crime is a complete MLRO workflow that turns every FCA and statutory financial-crime obligation into structured data capture, registers, evidence and Otto-drafted regulatory reports. It spans eight regimes — AML, transaction monitoring, sanctions, anti-bribery, SAR/STOR, market abuse, tax evasion and fraud — with customer due diligence in the Due Diligence module, and one Financial Crime score across 12 pillars. It replaces the MLRO's spreadsheet stack and much of an outsourced AML consultant.

Who it’s forFor the MLRO or Nominated Officer at an FCA-regulated firm running and evidencing a full financial-crime programme.

What it does

  • 12 pillars show completion behind one score
  • MLRO annual report as its own record, chapter by chapter
  • One Financial Crime attestation on the Attestations tab
  • Financial-crime risk assessments register
  • Live registers: SARs, sanctions, TM alerts, fraud, market abuse
  • Restricted and watch list register
  • Per-field audit trail, multi-year year-lock

What it produces

  • MLRO Annual Report in Reports, from the MLRO’s own record
  • FCA Readiness mock supervisory interview, RAG-graded
  • FCA REP-CRIM data return
  • Every register as CSV, one folder per workflow
Regulatory coverage
MLR 2017POCA 2002SAMLA 2018Bribery Act 2010CFA 2017UK MARJMLSGSYSC 6.3
The Due Diligence app: customers on file with their risk rating and next review date, the due diligence checks recorded against a customer, and the documents held on file
Growth plan

Due Diligence

Customer and third-party due diligence, on registers of your own

Twenty-three due-diligence registers that belong to the module outright. On the customer side: reviews, beneficial ownership, client categorisation, enhanced due-diligence cases, exits, and screening split into sanctions, adverse media, criminal records and politically exposed persons so each can be run and dated separately. On the third-party side: investment platforms, providers and products, outsourcing arrangements and introducers and distributors, each with the same separate screening checks, recorded as they are done. Each record can be linked back to the New Business entry that raised it through a searchable dropdown — a reference, not a dependency, so removing the New Business entry never removes the due-diligence file. Each customer and third party carries one next review date for the whole file, and it feeds the overdue list.

Who it’s forFirms that onboard customers or rely on third parties — advisers, brokers, platforms and any firm with outsourcing, introducer or distribution arrangements to evidence.

What it does

  • Eleven customer registers: the customer record, reviews, ownership, sanctions screening, adverse media, criminal record checks, PEPs, enhanced DD, exits, categorisation, sign-offs
  • Twelve third-party registers: third-party records, platform, provider, outsourcing and introducer assessments, sanctions, adverse media, criminal records, PEPs, ownership, enhanced DD, sign-off
  • Unlimited beneficial owners per customer — no fixed number of slots
  • Referrals raised automatically when new business needs due diligence
  • Searchable link to the New Business entry, held as a reference only
  • PEP records with country of exposure, role held, justification and enhanced monitoring
  • One next review date per customer and third party
  • The monitoring tasks for customer and third-party due diligence, in the module

What it produces

  • A dated due-diligence file per customer, with its next review on the record
  • A beneficial-ownership record that stands up to the follow-up questions
  • A PEP register carrying the justification and the approval, not just the flag
  • Due Diligence Review report in Reports, with Otto commentary
Regulatory coverage
MLR 2017JMLSGPOCA 2002COBS 3SYSC 8FCA Financial Crime Guide
The Risk Management app: risk register headlines, a residual heat map and the top five residual risks against appetite, with the risk register, appetite, controls, KRIs, scenarios, campaigns and third parties alongside
Growth plan

Risk Management

Enterprise-grade risk governance at SME pricing

An eleven-register FCA risk governance module built on a 5×5 register that scores inherent, residual and appetite separately, backed by mirrored controls, KRIs, loss events, action plans and stress scenarios. It adds a third-party register aligned to the Critical Third Parties regime, a force-directed risk network with concentration alerts, and RCSA attestation campaigns that produce signed-off, versioned audit snapshots. The Reports module builds a 15-section Risk Committee Report from the firm's live data, with Otto writing the commentary.

Who it’s forHeads of Risk, CROs and SMF holders at FCA-regulated firms, plus consultants and principals running multiple client or AR risk registers from one login.

What it does

  • 5×5 register scoring inherent, residual and appetite separately
  • 100 FCA-anchored templates across 8 risk categories
  • Third-party register aligned to SYSC 8, CTP regime
  • Force-directed risk network with concentration alerts
  • RCSA attestation campaigns with named sign-off
  • Append-only audit trail on every risk change
  • KRIs, loss events, action plans, stress scenarios

What it produces

  • 15-section Risk Committee Report in Reports (PDF + Word)
  • Risk Network Board-pack PDF
  • Closed-campaign RCSA audit snapshot PDF
  • Field-level risk audit trail (who changed what, when)
  • CSV exports: register, appetite, controls, third parties
Regulatory coverage
SYSC 7.1SYSC 7.1.4RSYSC 8SYSC 15ACTP regimePRIN 2AMIFIDPRU 7MLR 2017
Policy Studio: the firm's documents with their type, owner, last modified date and approval status
Growth plan

Policy Studio

Drafts, reviews and operationalises every policy

A five-stage policy lifecycle that takes a document to FCA-ready evidence: start from a Template Vault document or your own upload, Otto assesses, improves or rewrites it, then turns its key commitments into tracked tasks. Each task quotes the policy wording it came from, so a written obligation ties to an evidenced operation. The finished library exports as a Policy Register PDF for supervisors.

Who it’s forFCA-regulated firms and compliance consultancies that need to draft, maintain, approve and evidence their policy suite without outsourcing to consultants.

What it does

  • Start from any Template Vault policy or your own document
  • Assess & Improve scores each policy out of 10, then adds the fixes
  • Operationalise turns key commitments into tasks, quoting the source wording
  • Accepted tasks flow into the Compliance Hub with frequency
  • Board approval workflow with full audit trail
  • Upload your own docs; save refined versions as templates

What it produces

  • An FCA-grade policy, assessed and improved by Otto
  • Policy Register PDF (cover, schedule, per-policy control record)
  • Operationalised task list feeding the Compliance Hub
  • Otto quality score out of 10 with improvement suggestions
Regulatory coverage
PRIN 2AMLR 2017UK GDPRSM&CRCASSCOBSICOBSSYSC
The Operational Resilience app: critical business activities with criticality against workaround and recovery readiness, and registers for dependencies, assurance, governance, insurance, testing and recovery
Pro plan

Operational Resilience

SYSC 15A resilience, from planning to live incident

A complete SYSC 15A operational-resilience system covering the full programme: business impact analysis, dependency mapping, recovery planning, live incident management and board-ready reporting. A Resilience Health Score measures how complete the programme is across every register, attestation and monitoring check, so the number shows what is actually done. Incident Mode runs a live FCA 4-hour notification countdown during a real disruption, and every closed incident auto-feeds the stress-testing register.

Who it’s forFor Heads of Operational Resilience, COOs and BCP coordinators at FCA-authorised firms meeting SYSC 15A obligations — from proportionate small-firm BCP through to full PS21/3 enhanced scope.

What it does

  • Resilience Health Score across registers, attestations and checks
  • SYSC 15A attestation on the Attestations tab
  • Live Incident Mode, FCA 4-hour notification countdown
  • 20-step response runbook, 18-item Recovery Box
  • SPOF flags plus a shared-resource concentration map
  • Tabletop exercise programme, 8 pre-loaded scenarios
  • 14 integrated registers feeding one score

What it produces

  • Operational Resilience Report, in the Reports module
  • FCA Readiness mock supervisory interview
  • Register data export (CSV ZIP); reports export to PDF and Word
Regulatory coverage
SYSC 15A.2SYSC 15A.3SYSC 15A.5SYSC 15A.6SYSC 15A.7SYSC 15A.8PS21/3SUP 15.3
The Data Protection app: cookie consent records charted month by month and the cookies and tracking consent register, with registers organised under the UK GDPR principles
Pro plan

Data Protection

When the ICO calls, every answer is ready

A UK GDPR, DPA 2018 and PECR operating layer for the data protection officer. It runs the working registers — ROPA, data-subject rights, breaches, DPIAs and international transfers — and measures how complete the programme is across its registers, attestation and monitoring checks. A live 72-hour breach clock and reports in the Reports module keep the DPO audit-ready.

Who it’s forAny firm processing personal data, run by the DPO or whoever carries data-protection responsibility; for FCA firms it also meets SYSC 3.2.20.

What it does

  • Record of Processing register under Art 30
  • Data-subject rights tracker with deadline auto-escalation
  • Live breach mode with running 72-hour ICO clock
  • DPIAs plus lawful-basis and special-category mapping
  • Transfer register: TIA, SCC, IDTA, approval regulations
  • PECR cookies, consent and marketing-list compliance
  • 63-question Data Protection Attestation

What it produces

  • DPO Annual Report (UK GDPR Art 39), in Reports
  • ICO Accountability Pack, in Reports
  • Post-Incident Review (PIR) export
  • Data Protection completion score, RAG-rated
Regulatory coverage
UK GDPRDPA 2018PECRICO AccountabilitySYSC 3.2.20UK GDPR Art 30UK GDPR Art 33/34UK GDPR Art 35
FCA Applications — the application lifecycle with its document checklist
Growth plan

FCA Applications

From first draft to FCA authorisation

A guided FCA authorisation and MLR registration tracker. Pick a regulated activity and Otto generates an 8-section requirements blueprint and an activity-scoped document checklist against live FCA guidance, then you work the application through a 4-stage lifecycle with a live 180-day assessment countdown. Variations of permission run as a linked path off the original application, so the full history is kept.

Who it’s forFirms preparing an FCA authorisation, variation of permission or MLR registration — and consultancies running applications for multiple client firms.

What it does

  • Otto-drafted 8-section Application Requirements Report per activity
  • 74 activity types, including MLR 2017 registrations
  • Activity-scoped document checklist with per-item upload
  • Live 180-day FCA assessment countdown
  • Variations of Permission as linked child applications
  • SMF and firm data pre-populated, no re-entry

What it produces

  • Otto 8-section Application Requirements Report with verbatim FCA citations
  • Activity-scoped document checklist with upload slots
  • 180-day FCA Status record with case officer and progress bar
Regulatory coverage
SUP 6FEES 3 Annex 1RAOCONDPERGSM&CRMLR 2017
SUP 12 — AR Oversight — the AR breaches register with issues auto-suggested from attestation flags
Pro plan

SUP 12 — AR Oversight

The operating system for appointed-representative oversight

A complete operating layer for FCA SUP 12 oversight of appointed representatives, built for the post-Dec 2022 enhanced regime and the 2024 FCA Multi-Firm Review of principal firms. Each AR gets its own onboarding, due-diligence, monitoring and annual-review record, scored on completion across registers, attestations and monitoring checks, and rolled up into a network view. The Reports module builds a full SUP 12 Report and an FCA Readiness mock supervisory interview from your live records.

Who it’s forFCA-authorised principal firms supervising appointed representatives or IARs — IFA, wealth, mortgage, consumer-credit and insurance intermediary networks.

What it does

  • Own onboarding and due-diligence pack per AR
  • 25-item SUP 12 oversight checklist
  • Dated, RAG-rated monitoring visits and second-line audits
  • Intensified monitoring plans for elevated-risk ARs
  • Network pre-issue financial-promotion approval queue
  • Board Sign-Off artefact under SUP 12.6A.1R
  • SUP 15 breach prep pack with FCA field launcher

What it produces

  • SUP 12 Report, built from live records in Reports
  • FCA Readiness mock interview — 12 questions, RAG-graded
Regulatory coverage
SUP 12.4SUP 12.5SUP 12.6ASUP 12.7SUP 12.9SUP 15COBS 4PRIN 2A
The CASS Client Money and Assets app: the acknowledgement letter register with each letter tracked from draft to countersigned and on file, and registers for client money, custody assets, collateral and mandates
Pro plan

CASS — Client Money & Assets

The FCA Client Assets sourcebook as an operating system

Turns the FCA Client Assets sourcebook into structured registers, calculators, reconciliation engines and evidence, covering the 14 CASS chapters (1A–15) plus SUP 3.10 audit prep. A CASS 1 applicability engine switches on only the chapters that bind your firm by type, and a Client Assets Health score tracks completion across every register, attestation and monitoring check. It replaces CASS spreadsheets, much of a CASS-consultant retainer and the bulk of annual CASS-audit preparation.

Who it’s forFCA-regulated firms that hold or control client money or safe custody assets, and the CASS oversight officer (CASS 1A.3) accountable for them.

What it does

  • CASS 1 applicability engine switches on your chapters
  • CASS 1A calculator sizes firm and CMAR obligation
  • CASS 7.16 client-money calculation with same-day top-up
  • Client money and custody reconciliation engines
  • Acknowledgement-letter generator plus countersignature tracker
  • 48-hour CASS 10 resolution pack builder
  • Client Assets Health score out of 100, RAG-rated

What it produces

  • CASS Annual Report to the governing body
  • FCA Readiness mock supervisory interview, RAG-graded
  • CASS 10 resolution-pack master document (48-hour index)
  • CASS Board Pack (CASS 1A.3)
  • CMAR data return
Regulatory coverage
CASS 1ACASS 6CASS 7 / 7ACASS 5CASS 10CASS 15SUP 3.10SUP 16.14
Firm Record — the due-diligence file, with a document requirement open and its version history
Starter plan

Firm Record

Your firm’s identity, permissions and due diligence, on file

One record per firm, holding the things every principal, auditor and regulator asks for about the firm itself: registered and trading name, FRN and company number, contact details and addresses, and a description of what the firm actually does. Beside it sit the two things nobody usually has written down — every regulated activity with its customer type, limitation and effective date, and a due-diligence file that versions each document and derives its own status from the review date.

Who it’s forEvery firm on the platform. Directly authorised firms keep one record; principals keep one per appointed representative; consultancies keep one per client firm.

What it does

  • Four record types — Firm, Appointed Representative, Tied Agent, User Group
  • Eight lifecycle statuses, from Prospect through to Terminated
  • FRN, company number, addresses and contact, filled in from the FCA Register
  • Permissions register: activity, customer type, limitation, effective from
  • Ten-point due-diligence checklist you can rename, extend or clear
  • Version history on every document — v1, v2, v3, never overwritten
  • Status derived from the review date: Expired, Renewal due, Received
  • Shared with AR Oversight — the same permissions and DD, not a copy

What it produces

  • A complete firm file per workflow, ready to hand to a principal or auditor
  • A permissions and scope register that states what the firm may actually do
  • A dated due-diligence position, with what expires next
  • The business description Otto reads for its policy gap analysis
Regulatory coverage
FSMA Part 4ASUP 12SYSCDISPMLR 2017FCA RegisterCompanies House
The Document Library: folders and files for the workflow, with every document grouped by the module it came from, recent items and an AR Library tab
Starter plan

Document Library

Every document the firm holds, filed as the work happens

A file browser for the firm’s evidence — folders, icon and list views, search, tags and export — with one difference that matters: it fills itself. When a module records a document, a copy is filed here under the name of the module that produced it, so the library is complete without anyone maintaining it. Documents are held centrally, and policies written in Policy Studio open in the full Google Docs editor, with the revision history an auditor will ask for and no Google subscription of your own to buy. A second tab holds the AR Library: only what a principal has deliberately shared with an appointed representative, plus that representative’s own uploads.

Who it’s forEvery firm on the platform. Principals get the second library for sharing a defined document set with each appointed representative, without opening up the rest of the file.

What it does

  • Finder-style browser — folders, icon and list views, back and forward
  • Evidence from across the platform files itself here, grouped by source module
  • Colour-tagged folders, free-text tags and a favourites rail by source
  • Search by name; sort by name, date modified or kind
  • Policy Studio documents open in the full Google Docs editor
  • A separate AR Library holding only what the principal has shared
  • Scoped to the firm you have selected — nothing crosses between workflows

What it produces

  • One place to answer “show me the records”, in the meeting
  • An evidence trail that builds itself as the firm does the work
  • A defined, auditable document set for each appointed representative
  • An exportable document register for the file or the auditor
Regulatory coverage
SYSC 9SUP 12MLR 2017UK GDPRDISPCOBS
The Template Vault: ready-made policies listed by category, with tabs for registers, general documents and compliance monitoring plans, each ready to download
Growth plan

Template Vault

173 ready-to-tailor policies, registers and monitoring-plan chapters

A library of 173 editable Word documents written in-house: 43 FCA-aligned policies across 23 categories, 44 registers designed against the obligation they evidence, 12 standalone forms and notices, and a complete 73-chapter Compliance Monitoring Plan grouped into five parts. Search by name or category, download in one click, tailor it to your firm. No blank page, no per-document consultant fee, no watermarked PDFs.

Who it’s forFirms building or refreshing a compliance framework, firms preparing for authorisation, and consultancies that would otherwise draft the same policy suite for every client.

What it does

  • 43 FCA-aligned policies across 23 regulatory categories
  • 44 register templates across 16 categories
  • 73-chapter Compliance Monitoring Plan, Parts A to E, plus a master
  • 12 standalone forms and notices — privacy notices, DPA, DPIA and more
  • Permission-specific cover: CASS, funeral plans, cryptoassets, crowdfunding
  • Search by document name or category across every tab
  • Editable .docx throughout — never a locked PDF
  • Unmetered: no per-document, per-user or per-client download charge

What it produces

  • A tailored policy suite, adopted into your Document Library as evidence
  • Registers that already carry the columns the rule expects
  • A written Compliance Monitoring Plan scoped to your permissions
  • Board-ready forms: MLRO annual report, Statement of Responsibilities
Regulatory coverage
PRIN 2AMLR 2017UK GDPRCASSSM&CRDISPCOBSICOBSSYSCMAR
Otto AI — the compliance assistant answering from the firm’s live task and register data
Starter plan

Otto AI

Your compliance analyst, on every page

Otto is the platform’s built-in compliance analyst, and the answer is always drawn from your own records rather than a general summary of the Handbook. Ask what is overdue, where the file is thin or what a rule actually requires, and Otto reads the firm’s live tasks, registers, attestations and findings to answer — naming the module it is reading at the foot of the chat so you can check it. The same engine writes the commentary on every report in Reports: Compliance Monitoring, MLRO annual, DPO annual, Consumer Duty board, Risk Committee and an FCA Readiness mock interview. Otto drafts; a person decides. Nothing is filed, submitted or signed off automatically.

Who it’s forEveryone, on every plan. Otto is included from Starter upwards and behaves the same on every module the firm has switched on.

What it does

  • Answers from your firm’s live records, not a generic handbook summary
  • Names the module it has read, so every answer can be checked
  • Says plainly when the data does not support the question asked
  • Writes the commentary on the Compliance Monitoring Report
  • Reports module — MLRO annual, DPO annual, board and committee papers
  • FCA Readiness: a mock supervisory interview run against your own file
  • Filters the regulatory newsfeed to your permissions and products
  • Conversations are kept, and any answer exports to PDF

What it produces

  • Board-ready reports built from live data, with Otto’s commentary
  • A straight answer to “where do we actually stand?”, with the records behind it
  • Policies scored out of 10, with the fixes added on request
Regulatory coverage
SYSCPRIN 2AMLR 2017UK GDPRSM&CRSUP 12CASS
On every plan

Connected to the Handbook and the Register. And to your team.

Three parts of the platform that work across every app, whichever plan you choose.

FCA Handbook

Rule Map

The rules your permissions bring, read from the FCA Handbook and set beside the checks on your plan that test them.

  • Every amendment shown before and after
  • Dated to the day it takes effect
  • Evidence packs, rule by rule
FCA Register

FRN and IRN look-ups

Your FRN fills in your firm’s details and permissions from the Financial Services Register, and a person’s IRN brings in their roles.

  • Differences with the Register flagged
  • Disciplinary history on the fit and proper record
  • Six years of past firms, for references
Messages

Conversations on the record

Every ask, answer and attachment kept on the record and linked to the check or record it is about.

  • Turn a message into a task
  • Approve or send back what is waiting on you
  • Only the people named on it can read it
See them in the tour →
Otto AI

And Otto works across all of it.

Otto is the platform’s built-in compliance analyst — she reads your live data across every module, not a generic handbook summary.

Compliance Monitoring Report

A 12-section Compliance Monitoring Report built from the firm’s live monitoring data, with Otto’s commentary on each section.

Module Report Suites

MLRO annual, DPO annual, Risk Committee and Consumer Duty board reports in the Reports module, each built from that module’s live records.

Ask Otto

The in-platform assistant answers from your own registers, with sources cited — which reviews are overdue, where the file is thin, what closes the gap.

Policies Drafted & Operationalised

Otto assesses and rewrites a policy, then turns its key commitments into tracked tasks.

AI drafts, humans decide — nothing is auto-submitted.

See how it works →
FAQs

Modules and plans. Questions answered.

The short answers before you open a module — or a call.

Which modules are in which plan?
Starter carries the Compliance Hub, People Compliance, Regulatory Intelligence, Firm Record and the Document Library, with Otto on every page. Growth adds Risk Management, Consumer Duty, Financial Crime, Due Diligence, Policy Studio, FCA Applications and the Template Vault. Pro adds Operational Resilience, Data Protection, SUP 12 and CASS.
Can I move up a plan later?
Yes. Billing is monthly, and a higher plan switches more modules on — your existing workflows, records and evidence carry straight over.
Do modules work standalone or together?
Each module is complete in its own right, with its own registers, monitoring and insights. Reports draws them together, and the Flight Deck shows everything overdue or due across every module — so firm-wide compliance posture lives on one screen.
What comes with every plan?
Otto on every page, the Document Library, step-by-step guidance on every screen and unlimited users — the foundations are the same whichever plan you pick.
How fast is onboarding?
Under a day for most firms. Each module arrives with its monitoring checks already on the plan. No migration project, no framework to design from scratch.
Pro plan · White-label

Your firm’s brand.
Our compliance engine.

White-label branding is included with Pro. Add your logo, set your accent colour and sidebar palette, and the platform your team opens every morning looks like it was built in-house — because, as far as they’re concerned, it was.

  • Your logo and logo mark, on every screen your people use
  • Your accent colour and sidebar palette, applied platform-wide
  • Set once by your admin, live for every workflow and every user
Your palette — or any hex you like

Start free, or talk to us first.

See how RegTechPRO can transform compliance across your firm — and prove it in just a few clicks.

14-day free trial · Take the tour

Message Us

Thank you!

We've received your enquiry and will be in touch shortly.