Skip to content
Atlas
GET IN TOUCH

INDUSTRIESI04Financial Services

Controls you can
actually evidence.

IT for financial advisers, fund managers, lenders, and insurers. In this sector the question is never whether you have a control. It is whether you can produce the evidence when somebody asks, and that is a very different question.

The four sentences we hear most in your sector.

  • 01
    We think we are compliant. We could not prove it this week.

    The gap between believing and evidencing is where almost every finding lands. Controls that exist but are not recorded count for very little under examination.

  • 02
    Our AML records are spread across three systems.

    Customer due diligence, transaction records, and the reasoning behind a decision often live in different places, which makes reconstructing a file slow and the process fragile.

  • 03
    Advisers keep client information on their own devices.

    Usually for entirely practical reasons. It is still an exposure, and it is one that becomes visible at exactly the wrong moment.

  • 04
    Our outsourced providers are now our problem.

    Regulators and clients increasingly expect you to evidence oversight of your suppliers as well as of yourself, and most firms have never assembled that.

The systems you actually run.

Not a list of logos. These are the platforms we support, migrate, and get called about in this sector. If yours is missing, it usually means we have not worked with it, and we will say so rather than nod along.

Bring one group of systems forward
  • Advice and client management

    The system holding advice records, which are the ones that have to be reconstructible years later.

    • Xplan
    • Trail
    • Adviser Logic
    • Salesforce Financial Services Cloud
    • HubSpot
    • Microsoft Dynamics 365
  • AML and verification

    Customer due diligence evidence has to be retained and retrievable, which is a records problem as much as a compliance one.

    • Electronic identity verification
    • PEP and sanctions screening
    • Transaction monitoring
    • Customer due diligence records
  • Records and retention

    Retention periods here are set by statute rather than by preference, and applying them automatically is the only version that survives scrutiny.

    • Microsoft 365 retention policies
    • SharePoint
    • Immutable archives
    • Email journaling
    • Call recording
  • Access and identity

    Who can see what, and the record of who did see what. This is the first thing an examiner asks for and the first thing most firms cannot produce.

    • Microsoft Entra ID
    • Conditional access
    • Privileged access management
    • Sign-in and audit logs

Four things we do for financial services specifically.

  1. 01

    Evidence assembled once, kept current

    An evidence pack covering access control, retention, backup, incident response, and supplier oversight, written so you can hand it to an auditor, a regulator, or a client without translating it first. The value is that it stays current rather than being reconstructed under a deadline.

  2. 02

    Access control you can demonstrate

    Multi-factor authentication everywhere including service and administrator accounts, access granted by role, privileged rights held only when needed, and sign-in records retained long enough to be useful. The last part is the one firms usually discover they are missing.

  3. 03

    Retention applied, not documented

    Statutory retention periods enforced by the platform rather than by a policy document somebody signed. A retention schedule that depends on people remembering is not a control, and it will not be treated as one.

  4. 04

    Supplier and outsourcing oversight

    A register of who holds your data, where, under what terms, and what happens if they fail. Increasingly expected, rarely assembled until it is asked for.

The obligations that shape the work.

We make the systems match your obligations. We are not your lawyer or your compliance adviser, and where a question turns on interpretation we will tell you to take advice rather than guess on your behalf.

  • AML/CFT Act 2009

    Reporting entities must conduct customer due diligence, keep records, monitor transactions, and report suspicious activity. The records duty is the one with the most direct technology consequence, because it is a retention and retrievability problem.

  • Privacy Act 2020

    Thirteen information privacy principles governing collection, storage, use, disclosure, and disposal of personal information, plus mandatory notification of a privacy breach causing serious harm, and responsibility for information sent overseas.

  • FMA licensing conditions

    Licensed firms carry standard conditions covering business continuity, technology systems, record keeping, and outsourcing. These are explicit about the need to demonstrate rather than assert.

  • Client and scheme contracts

    Fund managers, platforms, and institutional clients flow their own requirements down through contract. Many firms have agreed to controls they have never evidenced.

Per user, per month, plus a scoped compliance engagement

Ongoing support is per user per month. The compliance work is scoped separately as a defined engagement, because the size of it depends entirely on where you are starting and we would rather establish that than average it. We quote the assessment up front so the first number you see is a real one. Nothing here is priced against a percentage of funds or of revenue.

Questions from your sector

01What do AML/CFT record-keeping obligations mean for our IT?

In practice they turn into a records problem. You have to retain customer due diligence records, transaction records, and the reasoning behind decisions, and be able to produce them on request years later. That means retention applied automatically rather than by habit, storage that cannot be quietly altered, and an access log showing who reached what. Most firms have the documents. Fewer can produce them quickly and prove they have not changed.

02Our FMA licence conditions mention technology and business continuity. What is actually expected?

Broadly, that you have thought about it, written it down, and can show it works. A documented continuity plan with recovery objectives agreed by the business, evidence that backups restore, a named owner for technology risk, and a record of incidents and how they were handled. The recurring failure is a plan that exists and has never been tested, because an untested plan tends not to be accepted as evidence of anything. For a view on your specific conditions, take advice from your compliance adviser or lawyer.

03How long do we have to keep client records?

It varies by record type and by which statute applies, and several overlap in this sector. Rather than guess, we build a retention schedule with your compliance adviser that reflects the obligations applying to you, then apply it automatically in the platform. The technology part is straightforward once the legal question is settled, and it is worth settling properly.

04Can we use cloud services, or does our data need to stay in New Zealand?

Generally you can. The Privacy Act does not mandate onshore storage, but it does make you responsible for information you send overseas and requires comparable safeguards wherever it lands. The stricter requirements usually come from a client contract, a scheme agreement, or a licence condition rather than from statute. We establish which of those actually apply to you, and where onshore hosting is genuinely required we can deliver that.

05What happens if we have a privacy breach?

If it has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and the affected people as soon as practicable. That means the useful work happens before an incident: knowing what you hold and where, having a process that does not need inventing under pressure, and having logs detailed enough to establish what was actually reached rather than what might have been. Firms without that end up over-notifying, which carries its own cost.

06Do you work with our compliance adviser rather than around them?

Yes, and it works considerably better that way. They own the interpretation of your obligations and we own making the systems match. We are not a substitute for legal or compliance advice and will say so whenever a question crosses that line.

Start with the evidence gap.

Tell us what you would be asked for in an examination, and we will tell you honestly which of it you could produce this week.

← All industries