Software for finance that has to hold up under scrutiny cover
Audit trailRetentionAccess control

Software for finance that has to hold up under scrutiny

Client onboarding still moves through email attachments, a spreadsheet, and four approvals before anyone can act on it. Every one of those steps has to be reconstructable two years later. We build the systems that carry that work with the audit trail, retention rules, and access control already in them.

What we see in finance

Onboarding and client checks that live in inboxes

Client files are assembled from email, scanned PDFs, and a shared drive. Nobody can say who approved what without opening five systems and asking a colleague.

Audit trails reconstructed after the fact

The evidence a supervisor or an internal audit asks for is rebuilt by hand each time, because the underlying system never recorded which field changed, by whom, and when.

Retention handled as a manual chore

Records that should have been deleted are still there, and records that must be kept for years sit in someone's personal drive. Both are findings waiting to happen.

What we build for it

Onboarding and servicing portals with the trail built in

Every state change recorded, role-based access throughout, and integration with the identity checks and core systems you already run, so the audit trail is a by-product of the work rather than a project of its own.

AI assistants that stay inside your controls

Retrieve policy and client context, summarise a case, draft a response. Human approval before anything leaves the organisation, and a record of what the model was given.

Reporting that assembles itself

Scheduled, reproducible exports with retention and data minimisation applied at the source, so a review request becomes a query instead of three weeks of collation.

What your supervisor will ask

A financial institution is not judged on whether its software is modern. It is judged on whether a file can be reconstructed, a decision explained, and a record produced on request. Three obligations shape that, and all three are cheaper to answer in the data model than in a project afterwards.

Supervision by DNB and the AFM

Client files and the decisions behind them have to be reconstructable on request, without notice.

Every state change is recorded as it happens: which field, by whom, on what basis. Nothing has to be rebuilt from application logs once the request has landed.

The Wwft, against the GDPR

Client due diligence records kept five years after a relationship ends, while data protection law requires you to hold nothing longer than necessary.

The two rules are resolved where they collide: retention set per record category, minimisation at the point of capture, and deletion that actually runs rather than being scheduled and forgotten.

DORA

In force since January 2025: managing technology risk, reporting incidents, overseeing suppliers, and being able to leave one.

We document per project where your data is processed, what we can reach, and how you would move away from us before the build, because that is when it is cheap.

This is how we design against these obligations. It is not legal advice: your compliance officer owns the interpretation, and we make sure the software can answer them.

Compliance and data

Your data model has to satisfy the GDPR and your sector's retention obligations at the same time, and a supervisor can ask about either without notice. Here is how we set that up.

Related case

Let’s build your next solution

Bring your industry challenges and we’ll pair them with the right mix of AI, engineering, and design to launch fast without sacrificing quality.