AML, UK GDPR, risk — if you’re in business, you carry compliance obligations, and RegTechPRO runs them all from one platform built to regulator standard.
14-day free trial · Take the tour
AML, CDD & sanctions for supervised sectors
ICO accountability, 72-hour breach clock
5×5 register plus vendor risk
Compliance obligations don't disappear just because you're not FCA-regulated.
HMRC, ICO, or a client audit is coming — and you've got nothing documented. Panic mode activated.
AML training? Risk assessments? Data audits? Always on the to-do list. Never actually done.
You know there are rules. You're just not sure which ones apply to your business — or how to comply.
Risk registers, training logs, client due diligence — scattered across drives and inboxes. No audit trail.
Your compliance knowledge lives in one person's head. When they leave or get sick, you're exposed.
Enterprise clients want to see your compliance framework before they'll work with you. Can you show them?
If HMRC, the SRA or another supervisor oversees you for anti-money laundering, MLR 2017 applies in full. Run risk assessments, customer due diligence and sanctions evidence from one workspace — and show your working.
Customer risk assessments, a PEP register and EDD case files — risk-rated, review-tracked and evidence-attached.
Your screening programme documented in one place, a hit log with dispositions, and the OFSI reporting routes built in.
The high-risk jurisdictions register arrives pre-seeded with 27 countries — you challenge a structured starting point, not a blank page.
A 137-question gap analysis mapped to MLR 2017 and JMLSG — every weakness becomes a tracked action with an owner and a deadline.
The money-laundering officer’s morning glance. A Financial Crime Health score, live operations across every regime, KPIs, the review calendar and SLAs — the whole AML function on one screen, every weakness one click from the work that fixes it.
Every customer, PEP and EDD case in one register. Risk-rated, review-tracked and evidence-attached, with next-review dates and sanctions flags — so a stale file never reaches your supervisor’s eye first.
The sanctions workspace: your screening programme — lists, thresholds, cadence — documented in one place, a hit log with dispositions, frozen-assets and OFSI licence registers, and a breach log with the reporting route named from the start.
Mapped to statute, attested by name. The control checklist and 137-question gap analysis — mapped to MLR 2017 and JMLSG — turn weaknesses into tracked actions with named owners, deadlines and attached evidence.
Every UK business processes personal data. ROPA, subject requests, breaches, DPIAs and PECR marketing — structured the way the ICO inspects them, with the accountability trail already built.
Purposes, lawful basis, recipients, retention and transfers — every processing activity in one exportable register.
Every subject request tracked against the one-month statutory deadline, with escalation before the clock runs out.
Log an incident and a live 72-hour ICO countdown starts (Article 33) — risk assessment, notifications and remediation on one record.
A 30-control accountability checklist, plus DPIAs, international transfers and PECR marketing consents — and an Otto-drafted DPO Annual Report.
The 30-second data-protection view: a composite Health score, 10 weighted pillars with RAG bars, your ICO checklist position, and every DPIA, DSR and review due. Click any tile to drill in; lock the year for sign-off with a full attestor trail.
Your Article 30 ROPA, structured as the ICO inspects it — purposes, data categories, lawful basis, recipients, retention and transfers, every activity in one exportable register. Each row links to its lawful basis and legitimate-interest assessment.
The 72-hour breach workflow, end to end. Log the incident, assess risk to subjects, notify the ICO within 72 hours under Article 33, communicate to subjects under Article 34 where required, capture remediation — every breach with a full evidence trail.
The DPO Annual Report under UK GDPR Article 39, drafted by Otto from your live data — ROPA from the register, DSRs from the request log, breaches by incident ID, DPIAs by project, training from the matrix. Export to PDF, sign, file.
The 5×5 register, heat map and vendor-risk framework your biggest clients expect to see when they audit a supplier — running in your firm from day one.
Every risk scored three ways — inherent, residual and appetite — so the board sees not just the risk, but whether you’re inside your own tolerance.
Start from 100 pre-built risk templates rather than a blank register — adapt, score and own them in an afternoon.
A dedicated third-party register — the ready answer when a client’s due-diligence questionnaire asks who you rely on.
A force-directed risk network with concentration alerts surfaces systemic exposure — and a field-level audit trail records every change.
A 30-second read on the firm’s risk posture: a KPI strip (Total Risks, High/Critical, Overdue Reviews, Control Gaps), an overall Risk Health Score, a live 5×5 residual heat map, Appetite Breaches by Category and the Top 5 residual risks. One screen — the board pack writes itself.
The register at the heart of it all: ID · Title · Category · Inherent · Residual · Owner · Next Review · Status. Colour-coded residual pills match the heat-map cell a risk lives in, and an Emerging Risk Watchlist tracks what’s heading your way.
The force-directed Risk Network. Causal links between risks, shared third parties, shared owners — with concentration alerts that surface the systemic risks no register-only view can show. Toggle the lens, export to PDF, brief the board.
You don't need FCA authorisation to need proper compliance. If any of these apply, RegTechPRO is for you.
HMRC-supervised for AML. Need risk assessments, client due diligence, and training records.
SRA-regulated with AML obligations. CDD, source of funds checks, and risk-based approach.
HMRC-supervised for AML under MLR 2017. Customer due diligence is mandatory.
GDPR compliance, data processing agreements, and security frameworks for enterprise sales.
Right to rent checks, client money handling, and AML for high-value transactions.
Right to work verification, GDPR compliance, and contractor due diligence frameworks.
Otto is the platform’s built-in compliance advisor, grounded in 150+ expert-authored documents. She reads your live registers — not a generic template — and drafts the reports your board, your supervisor and your biggest clients expect to see.
The UK GDPR Article 39 annual report, drafted from your live ROPA, DSR log, breach records and training matrix.
MLRO-style anti-money-laundering reporting drafted from your risk assessments, registers and screening evidence.
A board-ready risk report from the live 5×5 register — appetite breaches, top residual risks and control gaps.
Module-by-module gap analyses with a prioritised remediation plan — each action with an owner and a target date.
AI drafts, humans decide — nothing is auto-submitted, and every fact traces to your live data.
The cost of non-compliance is far greater than the cost of getting it right.
What a non-FCA UK firm wants to know about ICO, AML, GDPR and procurement-grade compliance evidence.
We use essential cookies to make the site work, and optional analytics cookies to understand how it's used. See our Cookie Policy.