BEYOND THE FCA

Compliance Isn’t Just for Banks.

AML, UK GDPR, risk — if you’re in business, you carry compliance obligations, and RegTechPRO runs them all from one platform built to regulator standard.

Start free trial Book a Consultation

14-day free trial · Take the tour

MLR 2017 Coverage

AML, CDD & sanctions for supervised sectors

UK GDPR & PECR

ICO accountability, 72-hour breach clock

Enterprise-Grade Risk

5×5 register plus vendor risk

AML & Sanctions Registers
ROPA & DSR Tracking
72-Hour Breach Workflow
5×5 Risk Register
Vendor & Third-Party Risk
Policy Library

Sound Familiar?

Compliance obligations don't disappear just because you're not FCA-regulated.

We Don't Have Any Policies

HMRC, ICO, or a client audit is coming — and you've got nothing documented. Panic mode activated.

We'll Get Around to It

AML training? Risk assessments? Data audits? Always on the to-do list. Never actually done.

Is This Even Our Problem?

You know there are rules. You're just not sure which ones apply to your business — or how to comply.

It's All in Spreadsheets

Risk registers, training logs, client due diligence — scattered across drives and inboxes. No audit trail.

One Person Knows Everything

Your compliance knowledge lives in one person's head. When they leave or get sick, you're exposed.

Clients Are Asking Questions

Enterprise clients want to see your compliance framework before they'll work with you. Can you show them?

MLR 2017 Compliance You Can Prove on Demand

If HMRC, the SRA or another supervisor oversees you for anti-money laundering, MLR 2017 applies in full. Run risk assessments, customer due diligence and sanctions evidence from one workspace — and show your working.

MLR 2017 registers

Customer risk assessments, a PEP register and EDD case files — risk-rated, review-tracked and evidence-attached.

Sanctions workspace

Your screening programme documented in one place, a hit log with dispositions, and the OFSI reporting routes built in.

27 high-risk jurisdictions

The high-risk jurisdictions register arrives pre-seeded with 27 countries — you challenge a structured starting point, not a blank page.

Gap analysis

A 137-question gap analysis mapped to MLR 2017 and JMLSG — every weakness becomes a tracked action with an owner and a deadline.

Financial Crime dashboard — health score, live operations across every regime, KPIs, review calendar and SLAs

The money-laundering officer’s morning glance. A Financial Crime Health score, live operations across every regime, KPIs, the review calendar and SLAs — the whole AML function on one screen, every weakness one click from the work that fixes it.

Customer Risk and PEP registers — risk-rated, review-tracked and evidence-attached with sanctions and EDD flags

Every customer, PEP and EDD case in one register. Risk-rated, review-tracked and evidence-attached, with next-review dates and sanctions flags — so a stale file never reaches your supervisor’s eye first.

Sanctions workspace — screening programme, hit log, frozen-assets and OFSI licence registers and a breach log

The sanctions workspace: your screening programme — lists, thresholds, cadence — documented in one place, a hit log with dispositions, frozen-assets and OFSI licence registers, and a breach log with the reporting route named from the start.

Financial crime control checklist and 137-question gap analysis mapped to MLR 2017 and JMLSG

Mapped to statute, attested by name. The control checklist and 137-question gap analysis — mapped to MLR 2017 and JMLSG — turn weaknesses into tracked actions with named owners, deadlines and attached evidence.

Explore Financial Crime →

Run UK GDPR Like You Have a Full-Time DPO

Every UK business processes personal data. ROPA, subject requests, breaches, DPIAs and PECR marketing — structured the way the ICO inspects them, with the accountability trail already built.

Article 30 ROPA

Purposes, lawful basis, recipients, retention and transfers — every processing activity in one exportable register.

DSR register with SLA

Every subject request tracked against the one-month statutory deadline, with escalation before the clock runs out.

72-hour breach mode

Log an incident and a live 72-hour ICO countdown starts (Article 33) — risk assessment, notifications and remediation on one record.

ICO accountability

A 30-control accountability checklist, plus DPIAs, international transfers and PECR marketing consents — and an Otto-drafted DPO Annual Report.

Data Protection dashboard — health score, 10-pillar RAG breakdown, ICO accountability checklist and upcoming review dates

The 30-second data-protection view: a composite Health score, 10 weighted pillars with RAG bars, your ICO checklist position, and every DPIA, DSR and review due. Click any tile to drill in; lock the year for sign-off with a full attestor trail.

Record of Processing Activities under UK GDPR Article 30 — purposes, lawful basis, recipients, retention and transfers

Your Article 30 ROPA, structured as the ICO inspects it — purposes, data categories, lawful basis, recipients, retention and transfers, every activity in one exportable register. Each row links to its lawful basis and legitimate-interest assessment.

Personal data breach record — 72-hour ICO notification workflow, subject communication and risk assessment

The 72-hour breach workflow, end to end. Log the incident, assess risk to subjects, notify the ICO within 72 hours under Article 33, communicate to subjects under Article 34 where required, capture remediation — every breach with a full evidence trail.

Otto AI DPO Annual Report under UK GDPR Article 39, drafted from live registers

The DPO Annual Report under UK GDPR Article 39, drafted by Otto from your live data — ROPA from the register, DSRs from the request log, breaches by incident ID, DPIAs by project, training from the matrix. Export to PDF, sign, file.

Explore Data Protection →

Enterprise-Grade Risk, Without the Enterprise

The 5×5 register, heat map and vendor-risk framework your biggest clients expect to see when they audit a supplier — running in your firm from day one.

5×5 scored register

Every risk scored three ways — inherent, residual and appetite — so the board sees not just the risk, but whether you’re inside your own tolerance.

100 risk templates

Start from 100 pre-built risk templates rather than a blank register — adapt, score and own them in an afternoon.

Vendor & third-party risk

A dedicated third-party register — the ready answer when a client’s due-diligence questionnaire asks who you rely on.

Risk network + audit trail

A force-directed risk network with concentration alerts surfaces systemic exposure — and a field-level audit trail records every change.

Risk Management dashboard — KPI strip, Risk Health Score, 5×5 residual heat map, appetite breaches by category and top residual risks

A 30-second read on the firm’s risk posture: a KPI strip (Total Risks, High/Critical, Overdue Reviews, Control Gaps), an overall Risk Health Score, a live 5×5 residual heat map, Appetite Breaches by Category and the Top 5 residual risks. One screen — the board pack writes itself.

Risk Register — inherent, residual, owner and next review, with an Emerging Risk Watchlist

The register at the heart of it all: ID · Title · Category · Inherent · Residual · Owner · Next Review · Status. Colour-coded residual pills match the heat-map cell a risk lives in, and an Emerging Risk Watchlist tracks what’s heading your way.

Interactive Risk Network — force-directed graph of causal links, shared third parties and shared owners with concentration alerts

The force-directed Risk Network. Causal links between risks, shared third parties, shared owners — with concentration alerts that surface the systemic risks no register-only view can show. Toggle the lens, export to PDF, brief the board.

Explore Risk Management →

Built for Businesses Like Yours

You don't need FCA authorisation to need proper compliance. If any of these apply, RegTechPRO is for you.

AML

Accountants & Tax Advisers

HMRC-supervised for AML. Need risk assessments, client due diligence, and training records.

SRA

Law Firms & Solicitors

SRA-regulated with AML obligations. CDD, source of funds checks, and risk-based approach.

PROPERTY

Estate Agents

HMRC-supervised for AML under MLR 2017. Customer due diligence is mandatory.

GDPR

Tech & SaaS Companies

GDPR compliance, data processing agreements, and security frameworks for enterprise sales.

LETTINGS

Letting Agents

Right to rent checks, client money handling, and AML for high-value transactions.

RECRUITMENT

Recruitment Agencies

Right to work verification, GDPR compliance, and contractor due diligence frameworks.

Otto Reads Your Live Data — Then Drafts the Report

Otto is the platform’s built-in compliance advisor, grounded in 150+ expert-authored documents. She reads your live registers — not a generic template — and drafts the reports your board, your supervisor and your biggest clients expect to see.

DPO Annual Report

The UK GDPR Article 39 annual report, drafted from your live ROPA, DSR log, breach records and training matrix.

AML Reporting

MLRO-style anti-money-laundering reporting drafted from your risk assessments, registers and screening evidence.

Risk Committee Report

A board-ready risk report from the live 5×5 register — appetite breaches, top residual risks and control gaps.

Gap Analyses

Module-by-module gap analyses with a prioritised remediation plan — each action with an owner and a target date.

AI drafts, humans decide — nothing is auto-submitted, and every fact traces to your live data.

Doing Nothing vs RegTechPRO

The cost of non-compliance is far greater than the cost of getting it right.

The Risk
Doing Nothing
Unlimited liability
  • No policies when HMRC or the ICO comes calling
  • Compliance knowledge in one person’s head
  • Enterprise clients walk away at the due-diligence stage
  • Fines for AML or UK GDPR breaches
  • Reputational damage that can’t be undone
The RegTechPRO Way
RegTechPRO
Three simple plans, no long-term contract
  • AML, UK GDPR & risk frameworks ready on day one
  • A Policy Register PDF that answers procurement’s three questions — do you have policies, are they approved, what’s being done
  • Evidence ready for HMRC, the ICO or a client audit
  • Any FCA-only areas simply stay dormant — nothing to configure away
  • Unlimited users — no per-seat fees
The Stack Way
5+ Separate RegTech Platforms
£20,000–£50,000/year across the stack
  • Separate logins for data protection, AML, risk and reporting
  • Each platform built for a different regulator
  • Manual reconciliation across data silos
  • Per-seat pricing inflates as headcount grows
  • No unified board report — rebuilt manually every cycle
FAQs

Non-FCA UK firms. Questions Answered.

What a non-FCA UK firm wants to know about ICO, AML, GDPR and procurement-grade compliance evidence.

Why use RegTechPRO if I’m not FCA-regulated?
Every UK firm has regulators. ICO for data protection. HMRC for tax and PAYE. Companies House for filings. NCSC for cyber. The Pensions Regulator. AML obligations under MLR 2017 apply to many non-FCA firms (estate agents, accountants, lawyers, gambling operators). RegTechPRO’s coverage is grounded in POCA, the Terrorism Act 2000, MLR 2017 and JMLSG guidance — plus the regulator feeds in Regulatory Intelligence’s 13-regulator scope — non-FCA firms see ICO, HMRC, Companies House, NCSC, TPR, OFSI, FRC and the rest as their core surface.
How does it cover ICO / GDPR / Data Protection?
The Data Protection module is built on the UK GDPR + DPA 2018 framework and ships 15 Board-ready policy templates covering the full GDPR suite — Data Protection Policy, Cookie Policy, SAR Manual, Data Retention, International Transfers, Cyber Security Risk, CCTV and the rest — approved on a Board-dated tracker. Every policy is operationalised by Otto with page-referenced tasks. The CMP includes ICO-aligned monitoring activities. ICO-registered firms get a defensible audit trail by design.
What about AML / PEP / Sanctions?
The Financial Crime Suite covers AML, ABC, Anti-Fraud, Market Abuse, Sanctions, Tax Evasion, SAR Manual, CDD/EDD and Gifts & Entertainment. The Risk Register tracks financial-crime exposure with a three-score appetite framework (inherent · residual · appetite). Otto draws on POCA, SAMLA, the Bribery Act, MLR 2017 and the Terrorism Act 2000 — the legal spine non-FCA AML-regulated firms answer to.
How does the platform handle B2B clients asking for compliance evidence?
SOC 2 and ISO 27001 certified infrastructure, ICO-registered, UK/EU-hosted, multi-tenant data isolation by architecture. Document Library exports an inventory CSV. Policy Studio’s FCA-ready Policy Register PDF doubles as a B2B procurement evidence pack — it answers the three questions every enterprise procurement asks: do you have policies, are they approved, and what tasks have been created to discharge the commitments. One PDF, signed by your SMF or compliance lead.
Do I get the full platform without FCA modules I don’t need?
Yes. RegTechPRO comes as three simple plans, billed monthly. Every plan includes the Compliance Monitoring Hub, People Compliance, Regulatory Intelligence, the Document Library, Otto AI and unlimited users & workflows — see the pricing page for what each plan adds and costs. Any FCA-only areas you don’t need — such as SUP 12 / AR oversight — simply stay dormant.
What about Companies House / HMRC notifications?
Regulatory Intelligence includes Companies House, HMRC, ICO, NCSC, OFSI, Pensions Regulator, FRC and HM Treasury alongside the FCA and PRA. Each source is independently toggleable; non-FCA firms typically toggle FCA off and rely on the rest. The Upcoming Deadlines register surfaces dated obligations across every source you’ve turned on — with a countdown on each dated item, board-pack-ready.

Start free, or talk to us first.

See how RegTechPRO can simplify AML, GDPR and risk compliance for your firm — and prove it in just a few clicks.

14-day free trial · Take the tour

Contact Us

Thank you!

We've received your enquiry and will be in touch shortly.