I am a...
FCA Compliance Software for AR Networks

AR compliance, mastered.
SUP12, evidenced.

The FCA's SUP12 regime holds Principal firms to a higher standard. RegTechPRO gives you complete oversight of your AR network, from each AR’s FRN to every rule change that reaches it. Each AR gets a login to a dedicated space, making supervision simple.

Trusted by 250+ UK-regulated firms · Built for the FCA’s enhanced AR regime

SUP12 FIT 1.3 PRIN 2A SUP 15 +more
Book a Consultation Take the Health Check

14-day free trial · No long-term contract · Take the tour

TLS 1.2+ Encryption
SOC 2 Infrastructure
ISO 27001 Infrastructure
ICO Registered

Principal firm responsibility is not delegable.

You answer for what your Appointed Representatives do. The rules got tighter in December 2022, the FCA has been reviewing principals ever since, and the question it asks is always the same one: show us how you supervised them.

A Spreadsheet Per AR Is Not Oversight

One tab per firm, due dates in a calendar, evidence in an inbox. Nothing tells you which AR is drifting, which review is overdue, or where the network stands this morning.

The Regime Got Tougher in December 2022

An annual self-assessment your board signs off. Deeper due diligence before you appoint. More notifications, on tighter deadlines. The FCA reviewed principals in 2024 and was not impressed by what it found.

When the FCA Asks, You Produce the Record

An information request does not wait while you rebuild two years of supervision from email threads. If the monitoring visit, the review decision and the sign-off are not on file, they did not happen.

If you recognise your network in any of these, this page was built for you.

Two-minute check Not sure where you stand? Take the two-minute AR Oversight Health Check Start the check
The Solution

Meet RegTechPRO for principal firms

Supervision your ARs take part in, evidence that builds as the work happens, and a network view that tells you where you stand before the regulator asks.

The ongoing oversight SUP 12 expects, recorded as it happens. Intensified monitoring plans for higher-risk ARs, audits and supervisory meetings with a RAG conclusion on every one, second-line reviews and customer file sampling.

The appointment due diligence pack for every AR. What has been received, what is due for renewal and what has expired, a review and expiry runway, and a history kept for every document.

The portal your appointed representatives sign in to. Their own monitoring plan, attestations, registers and task calendar, their people records, and the documents you choose to share with them.

Each AR’s position at a glance. Its SUP 12 health score and exactly what drives it, the fit-and-proper position, a defensibility radar, the latest attestation and the monitoring cadence across the year.

Every conversation with your ARs, kept on the record and linked to the work it is about. An AR can raise a question with you directly, approvals wait in one place, and only the people named on a conversation can read it.

Board packs, MLRO annuals, Consumer Duty reviews, BCPs and FCA dry-runs — Otto drafts every regulator-grade report from your live data, cited to the source rule.

Exportable board-ready management information that meets the regulator's oversight expectations — live RAG status, drill-through to the underlying evidence, and clear ownership so issues get spotted and actioned quickly, not buried in a spreadsheet.

1,139 expert-built templates across seven regulators, with the registers, attestations and assessments to evidence every FCA obligation.

Build any form your firm needs in minutes. Drag-and-drop fields, conditional logic, named owners and evidence attachments — no code, no consultants, no waiting list.

Otto is built into every module — answering compliance questions from your firm's live records with handbook citations, drafting, scoring and rewriting your policies, and writing the commentary for board-ready reports. AI drafts, humans decide.

Inside SUP 12

A whole operating system for AR oversight.

SUP 12 is not a register bolted onto the side. It is a full module built around supervising firms you are responsible for, with the rest of the platform running per AR underneath it.

33
tracked oversight areas per AR
25
item SUP 12 checklist
80
question gap analysis
4
AI report formats
The network view Across every AR

Network health

One score across the whole network, the mean of every AR’s own composite, with complete, partial and not-started counts behind it.

Network Pulse

Active ARs split between AR and IAR, approved persons across the network, open issues by severity, and attestations approved, pending or missing.

RAG muster

How many of your ARs sit red, amber, green or unrated, at a glance, so the shape of the network is never a surprise.

Risk triage queue

The network’s sharpest live signals, severity-ranked, so you work top-down instead of hunting.

Attestation chase-list

Which ARs still owe you an attestation, which are awaiting your approval and for how long. Self-certification is your evidence of oversight.

Viability and PI sentinel

A red-first watch strip for financial viability and professional indemnity cover across every AR.

Complaints and redress flow

Received through to open, upheld and redress paid, with open Ombudsman cases surfaced per AR.

Per-AR drill-down

One row per AR with a toggle for whether a firm counts toward the aggregate, shared by everyone at your firm.

AR Scorecard

A two-page board pack for any AR: current rating, open issues, last annual review and a sign-off block, in one click.

Every AR, a complete record One record per AR, per year

Onboarding and due diligence

The pack the FCA expects before you appoint: register extract, incorporation, structure chart, key individuals, PI certificate, complaints and AML policies, financials and the agreement.

Appointment decision and SMF sign-off

The senior manager who approved the appointment is recorded against it. Miss it on a live AR and the dashboard flags the gap rather than letting it pass.

Documents that expire themselves

Every requirement carries a status and a review date. Requested becomes renewal due, then expired, without anyone remembering to check.

Fit and proper, worst first

Every person at the AR ranked by how overdue they are, with their role, their assessment dates and any disclosure flagged against them.

Audits and supervisory meetings

Visits, thematic reviews and desk-based work, each with its lead, its RAG, whether findings were material, and the remediation actions raised from it.

Intensified monitoring

When an AR is running hot: the trigger, the new visit cadence, file-review and financial-promotion percentages, the owning senior manager and a deadline to resolve.

Breaches, with SUP 15 prep

A qualifying breach opens a pack carrying every field the FCA form asks for, ready to copy across, then records the reference against the AR.

Reviews, agreements and exits

A formal continue, continue-with-conditions or terminate decision each year, the signed agreement on file, and a structured exit pack when a relationship ends.

Financial and commercial monitoring

Revenue, profit, capital adequacy and solvency period by period, alongside the fees and lifetime value of the relationship and the split of its customer base.

Guidance from people who have done it

Every monitoring task carries expert guidance on what to test and why. Not generic text: the judgement of a compliance professional, at the point of work.

Where each AR stands Scoring and early warning

AR risk tier

Set an AR to Standard or Heightened and its supervisory cadence and intensity move with it. Saved the moment you choose.

A score you can defend

A pillar-weighted composite per AR, with a drill-in that shows every section behind the number and lets you click straight to the work.

Weighted your way

Tune what the score is made of, and how much each individual section counts. Your firm decides what good supervision looks like.

Defensibility radar

Six spokes covering due diligence, fit and proper, financial cover, unresolved issues, attestation currency and monitoring cadence, naming the weakest side in plain English.

Health trajectory

Every score kept as a snapshot, plotted against the green line, so you can see whether an AR is recovering or drifting.

Critical controls cap the score

A lapsed PI policy holds an AR in the red band however good the rest of the record looks. Nothing important can be averaged away.

Monitoring cadence

A rolling twelve months of supervisory visits and second-line reviews per AR, so gaps in your own coverage are visible.

Why this rating?

Every RAG explains itself: what drove the colour, and what would change it.

Your ARs do their part Their own secure logins

Passwordless access

Your AR’s people sign in with a single-use email code. No passwords to issue, reset or leak.

The AR Library

Share documents as deliberate copies, to one AR or all of them. They upload back and notify you in a single action.

A restricted view

Restrict an AR user to the documents you have shared. The restriction is enforced on the server, not just hidden on screen.

Attestations flow in

ARs report their own complaints, redress, Ombudsman referrals, headcount, turnover and PI cover. It lands in your view the moment they file.

Anomalies surface themselves

A lapsed PI policy, a reported data breach or a sharp jump in complaints on an AR’s attestation is suggested to you as an issue to log, in one click.

Control, and proof of it Who can do what, on the record

Per-person, per-AR access

Grant each colleague access AR by AR. The separation between firms is structural, not a display filter.

A real approver role

Only the people you nominate can approve or reject, enforced on the server, for the ARs you nominated them on.

Sign-offs that hold up

A due diligence sign-off is stamped from the signer’s own verified session, so it cannot be recorded in someone else’s name.

One bell for the network

Overdue and due-today items from every AR on a single bell, with an email digest grouped by firm.

Every module, per AR

Consumer Duty, Financial Crime, Risk, Policy Studio and the rest all run per AR, each with its own records, scores and reports.

Isolation by design

Each AR’s data sits in its own space, and every read and write is checked against your access rights before it is served.

What sets RegTechPRO apart

The FCA’s rulebook and register,
wired into every AR.

Start each AR with its FRN, not a blank form. RegTechPRO reads the FCA Handbook and the Financial Services Register for you, and sets each rule beside the checks that evidence your oversight, to help you find the gaps.

  • 12,000+ Handbook provisions
  • Your chapters checked every day
  • Changes dated to the day
  1. 01 · FCA Register

    Enter an AR’s FRN. Its record fills itself in.

    The AR’s details arrive from the Financial Services Register, ready to save, and an adviser’s IRN brings in the roles they hold. Anything out of step with the Register is flagged.

  2. 02 · FCA Handbook

    Each AR’s permissions become its rulebook.

    Rule Map suggests the Handbook chapters that come with each AR’s permissions and sets every rule beside the checks on its plan that test it. A rule nothing tests shows up as a gap, with a check to add.

  3. 03 · Rule changes

    A rule changes. See which ARs it touches.

    You see the wording before and after, the day it takes effect and the ARs whose permissions it reaches, each with a task to add to its own plan.

Evidence, rule by ruleOne pack per rule: the checks that test it, their results and your attestation answers.
Every citation checkedOtto quotes a rule’s current wording and checks every reference it gives.
Every reference, liveAny rule reference on the platform opens its current wording and where it is used.

Illustrative example. Handbook wording © Financial Conduct Authority.

One plan runs the whole network.

No per-AR licence. No per-seat charge. Appoint a new Appointed Representative and the price does not move.

1

Pick Pro

SUP 12 sits on the Pro plan, alongside every other module in the platform.

2

Add every AR

Each AR gets its own complete record. Every AR you appoint is included. Nothing per AR, ever.

3

Bring everyone

Unlimited users on every plan. Your team and your ARs’ people, with no per-seat charges.

Every AR included, on one subscription, whatever the size of your network.
SUP 12 is included in the Pro plan. For larger networks we will map your firms onto the platform before you commit to anything.
Regulatory Coverage

Every sourcebook. Every framework. Every regulation.

RegTechPRO isn't just an FCA tool — it's a corporate compliance OS. From FCA sourcebooks to UK statutes, data & cyber to cross-regulator obligations, every framework your firm is on the hook for — built in, evidenced, kept current.

50+
Frameworks
13
Regulators
1,139
Pre-Built Checks

The AI compliance partner built by compliance experts.

Trained on senior compliance expertise and 150+ expert documents. Working across every module of RegTechPRO. You supervise your ARs, and Otto produces the regulator-ready output.

EXPERT COMPLIANCE ASSISTANT

The bridge between your oversight record and regulator-ready output.

Otto reads what you have actually recorded about each AR, from due diligence and monitoring visits to breaches, reviews, people and outcomes, and writes the documents a supervisor expects to see. Every fact traces back to your own records, and every Handbook rule it cites is checked against the FCA Handbook itself.

  • A fourteen-section SUP 12 report, written section by section
  • Or a mock FCA interview, a board summary, or one report across the network
  • Names the people, cites the rule, and says “not recorded” where nothing is on file
  • AI drafts, humans decide — nothing auto-submitted
Full SUP 12 Report
14 sections

Scope, due diligence, permissions, monitoring, fit and proper, records, policies, attestations, complaints, breaches, risk rating, termination and a forward look.

FCA Dry-Run
12 sections

A mock supervisory interview. Twelve questions a supervisor would ask, answered from your record, with an examiner’s observation on each.

Executive Summary
3 sections

The board version. What the position is, what is outstanding, and what needs a decision.

Network Summary
4 sections

One report across every AR you supervise, built from each AR’s own report rather than a fresh guess.

The report builder

You stay the author

The report is built a section at a time, and every section is yours to control. Set it verbose, balanced or concise. Run the report again to rebuild every section from your data. Rewrite any of it by hand. Then export the report, or the whole pack as a file with every register alongside it.

  • Verbose, balanced or concise, per section
  • Regenerate or rewrite any section
  • Export the report or the full pack
  • Keeps running if you leave the page
SUP 12 Report Builder Full SUP 12 Report · 14 sections
3. Due Diligence
4. AR Permissions & Scope
5. Ongoing Monitoring
6. Fit & Proper
7. Records & Agreements
6. Fit & Proper · extract

Of the six senior manager and certification roles on file, one carries a current assessment date. The remainder show no assessment date, no certification and no conduct training record.

One disclosure is recorded and the disclosure bank is not fully answered. It must be completed and signed off before that individual undertakes regulated activity.

Every figure traced to your own record. Nothing on file reads “not recorded”, never a guess.
Grounded in your data

An AI that knows each AR

Generic AI can quote the Handbook. Otto does that too, but that is not the point. Otto reads the record you hold on the AR in front of you, its due diligence, its reviews, its breaches and its people, and answers from that. Ask where an AR stands and you get its position, not a summary of the rules.

  • Reads the selected AR’s live record
  • Flags gaps instead of filling them
  • Cites the rule behind the answer
  • Drafts the board pack when you are ready
Otto AI
Online · AI Compliance Advisor
Where does Aldergate Insurance stand on its annual review?

The review is recorded, but two things need your attention:

  • Outcome logged as continue with conditions on 14 May, conditions not yet closed out
  • Professional indemnity certificate on the due diligence pack expired last month
  • One breach still open from the February monitoring visit

No fit and proper date on file for one approved person, so I have not treated that as complete.

Drawn from: SUP 12 · People Compliance · Document Library
Ask Otto about this AR…
→

Start free. Stay because it works.

A fortnight to try it, a day to set it up, and a monthly plan you can leave whenever you like.

14-day free trial

Start on any plan and put the whole platform to work for a fortnight — your firm, your data, your workflows.

Easy set-up

The template library arrives pre-seeded. Most firms are running their monitoring programme the day they join.

Full support

Comprehensive onboarding, video tutorials and live support — from people who speak compliance.

No long-term contracts

Simple monthly billing. No minimum term and no setup fees.

Pro plan · White-label

Your logo. Your colours. Your platform.

White-label branding comes with Pro — add your logo, accent colour and sidebar palette once, and every screen your team or your clients open looks like it was built in-house.

Set once by your admin — live for every workflow and every user.

Frequently Asked Questions

Everything you need to know about running an AR network on RegTechPRO

How long does it take to set up an AR network?
Minutes per AR, not weeks. You add your firm, then add each AR as its own record, so your first AR can be on file the same day. Set-up help and full support are included on every plan.
We already keep AR records in spreadsheets. Can we migrate?
Yes. The registers are built for direct entry, and our support team helps you move existing due diligence, agreements and review history across as you go.
Will our ARs need training?
No formal training required. An AR’s people only see what you grant them, and what they do see is forms and tables rather than compliance jargon.
We are a mortgage network. Is the platform built for MCOB firms?
Yes. Mortgage and home finance is covered in its own right, not treated as a variation of investment business. Rule Map sets out the MCOB rules that come with each AR’s mortgage permissions, each beside the checks that test it, and your ARs get the MCOB Handbook attestation, one tab per Handbook chapter, 19 mortgage-specific monitoring checks covering advice, affordability, product transfers, fees, arrears and equity release, a dedicated MCOB financial promotions register for the promotions you approve on their behalf, and a mortgage file review checklist you can use on an AR’s advice files. Regulatory Intelligence carries a mortgage filter, so what reaches you is MCOB news rather than everything.
How does RegTechPRO handle more than one AR?
Each AR gets its own complete record, kept separate from every other AR and from your own firm. You move between them from the selector at the top of every page, and the Network Dashboard reads across all of them at once.
Can we set up our ARs from the FCA Register?
Yes. Enter an AR’s FRN and its details arrive from the Financial Services Register, ready to save, and an adviser’s IRN brings in the roles they hold. When the FCA changes a rule, Rule Map shows which of your ARs it reaches, with a task to add to each AR’s plan.
What does an AR see when they log in?
Whatever you grant. You can restrict an AR user to the documents you have shared with them in the AR Library, or give fuller access so they keep their own registers. Either way the restriction is enforced on the server, not just hidden on screen.
Can our ARs complete their own attestations?
Yes. ARs attest in their own workspace and the submission appears in your Attestations view as soon as they file, with a rating and the full history behind it. A new filing reopens the section so a fresh submission cannot sit unnoticed.
Does it cover the FCA’s enhanced AR regime?
Yes. The module is built around SUP 12.4 to 12.9 and FIT 1.3: the annual self-assessment with board sign-off, deeper due diligence before appointment, appointment and termination notifications, and records retention. A 25-item checklist carries the rule references and an 80-question gap analysis shows where you stand.
Can we share policies and documents with our ARs?
Yes. The AR Library is a separate space for each AR. You copy a document across deliberately, to one AR or to all of them, and they are notified. What they hold is the version you shared, so nothing changes under their feet.
What happens when we terminate an AR?
The termination register carries the exit as a structured pack: notifications, agreement wind-up, an eight-item customer-protection checklist, post-termination monitoring and lessons learned. The AR’s record and its evidence stay on file afterwards.
How does pricing work for an AR network?
One Pro subscription runs the whole network. Every plan includes unlimited users and workflows, so every AR you appoint is included, with nothing per AR and nothing per seat. For larger networks we recommend a short call so we can map your firms onto the platform first.
What happens when we appoint a new AR?
Add them in minutes and the price does not move. The record starts at onboarding, so the due diligence and the agreement are on file from day one.
Which plan includes SUP 12?
SUP 12 is included in the Pro plan, together with every other module in the platform. See the plans for what sits in each one.
Is each AR’s data really separate?
Yes, structurally. Every AR’s records live in their own isolated space, and every read and every write is checked against your access rights before it is served.
Who can approve things?
Only the people you nominate as approvers, on the ARs you nominate them for, enforced on the server. Due diligence sign-offs are stamped from the signer’s own verified session, so a sign-off cannot be recorded in someone else’s name.
How do logins work?
Single-use email passcodes. A six-digit code, valid for ten minutes, then a device session that lasts 90 days. There are no passwords to issue, reset or leak.
Can we control what each colleague sees?
Yes. Access is granted per person and per AR, so a colleague who looks after four firms sees those four and nothing else.

Book a Consultation

Pick a date and time to discuss how RegTechPRO can help you meet your compliance obligations and prove it in just a few clicks.

1. Select Date & Time

Mon Tue Wed Thu Fri Sat Sun

Select a date first

Choose a date above to see available times

2. Your Details

No date & time selected yet

Demo Booked!

We've received your booking request and you'll receive your meeting link via email. We look forward to speaking with you about RegTechPRO.

Message Us

Thank you!

We've received your enquiry and will be in touch shortly.