INDUSTRIESI04Financial Services
Controls you can
actually evidence.
IT for financial advisers, fund managers, lenders, and insurers. In this sector the question is never whether you have a control. It is whether you can produce the evidence when somebody asks, and that is a very different question.
WHAT WE HEAR
The four sentences we hear most in your sector.
- 01
We think we are compliant. We could not prove it this week.
The gap between believing and evidencing is where almost every finding lands. Controls that exist but are not recorded count for very little under examination.
- 02
Our AML records are spread across three systems.
Customer due diligence, transaction records, and the reasoning behind a decision often live in different places, which makes reconstructing a file slow and the process fragile.
- 03
Advisers keep client information on their own devices.
Usually for entirely practical reasons. It is still an exposure, and it is one that becomes visible at exactly the wrong moment.
- 04
Our outsourced providers are now our problem.
Regulators and clients increasingly expect you to evidence oversight of your suppliers as well as of yourself, and most firms have never assembled that.
THE STACK
The systems you actually run.
Not a list of logos. These are the platforms we support, migrate, and get called about in this sector. If yours is missing, it usually means we have not worked with it, and we will say so rather than nod along.
Advice and client management
The system holding advice records, which are the ones that have to be reconstructible years later.
- Xplan
- Trail
- Adviser Logic
- Salesforce Financial Services Cloud
- HubSpot
- Microsoft Dynamics 365
AML and verification
Customer due diligence evidence has to be retained and retrievable, which is a records problem as much as a compliance one.
- Electronic identity verification
- PEP and sanctions screening
- Transaction monitoring
- Customer due diligence records
Records and retention
Retention periods here are set by statute rather than by preference, and applying them automatically is the only version that survives scrutiny.
- Microsoft 365 retention policies
- SharePoint
- Immutable archives
- Email journaling
- Call recording
Access and identity
Who can see what, and the record of who did see what. This is the first thing an examiner asks for and the first thing most firms cannot produce.
- Microsoft Entra ID
- Conditional access
- Privileged access management
- Sign-in and audit logs
WHERE WE HELP
Four things we do for financial services specifically.
- 01
Evidence assembled once, kept current
An evidence pack covering access control, retention, backup, incident response, and supplier oversight, written so you can hand it to an auditor, a regulator, or a client without translating it first. The value is that it stays current rather than being reconstructed under a deadline.
- 02
Access control you can demonstrate
Multi-factor authentication everywhere including service and administrator accounts, access granted by role, privileged rights held only when needed, and sign-in records retained long enough to be useful. The last part is the one firms usually discover they are missing.
- 03
Retention applied, not documented
Statutory retention periods enforced by the platform rather than by a policy document somebody signed. A retention schedule that depends on people remembering is not a control, and it will not be treated as one.
- 04
Supplier and outsourcing oversight
A register of who holds your data, where, under what terms, and what happens if they fail. Increasingly expected, rarely assembled until it is asked for.
WHAT YOU ANSWER TO
The obligations that shape the work.
We make the systems match your obligations. We are not your lawyer or your compliance adviser, and where a question turns on interpretation we will tell you to take advice rather than guess on your behalf.
AML/CFT Act 2009
Reporting entities must conduct customer due diligence, keep records, monitor transactions, and report suspicious activity. The records duty is the one with the most direct technology consequence, because it is a retention and retrievability problem.
Privacy Act 2020
Thirteen information privacy principles governing collection, storage, use, disclosure, and disposal of personal information, plus mandatory notification of a privacy breach causing serious harm, and responsibility for information sent overseas.
FMA licensing conditions
Licensed firms carry standard conditions covering business continuity, technology systems, record keeping, and outsourcing. These are explicit about the need to demonstrate rather than assert.
Client and scheme contracts
Fund managers, platforms, and institutional clients flow their own requirements down through contract. Many firms have agreed to controls they have never evidenced.
WHAT IT COSTS
Per user, per month, plus a scoped compliance engagement
Ongoing support is per user per month. The compliance work is scoped separately as a defined engagement, because the size of it depends entirely on where you are starting and we would rather establish that than average it. We quote the assessment up front so the first number you see is a real one. Nothing here is priced against a percentage of funds or of revenue.
WHERE TO START
The services that matter most here.
FAQ
Questions from your sector
01What do AML/CFT record-keeping obligations mean for our IT?
In practice they turn into a records problem. You have to retain customer due diligence records, transaction records, and the reasoning behind decisions, and be able to produce them on request years later. That means retention applied automatically rather than by habit, storage that cannot be quietly altered, and an access log showing who reached what. Most firms have the documents. Fewer can produce them quickly and prove they have not changed.
02Our FMA licence conditions mention technology and business continuity. What is actually expected?
Broadly, that you have thought about it, written it down, and can show it works. A documented continuity plan with recovery objectives agreed by the business, evidence that backups restore, a named owner for technology risk, and a record of incidents and how they were handled. The recurring failure is a plan that exists and has never been tested, because an untested plan tends not to be accepted as evidence of anything. For a view on your specific conditions, take advice from your compliance adviser or lawyer.
03How long do we have to keep client records?
It varies by record type and by which statute applies, and several overlap in this sector. Rather than guess, we build a retention schedule with your compliance adviser that reflects the obligations applying to you, then apply it automatically in the platform. The technology part is straightforward once the legal question is settled, and it is worth settling properly.
04Can we use cloud services, or does our data need to stay in New Zealand?
Generally you can. The Privacy Act does not mandate onshore storage, but it does make you responsible for information you send overseas and requires comparable safeguards wherever it lands. The stricter requirements usually come from a client contract, a scheme agreement, or a licence condition rather than from statute. We establish which of those actually apply to you, and where onshore hosting is genuinely required we can deliver that.
05What happens if we have a privacy breach?
If it has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and the affected people as soon as practicable. That means the useful work happens before an incident: knowing what you hold and where, having a process that does not need inventing under pressure, and having logs detailed enough to establish what was actually reached rather than what might have been. Firms without that end up over-notifying, which carries its own cost.
06Do you work with our compliance adviser rather than around them?
Yes, and it works considerably better that way. They own the interpretation of your obligations and we own making the systems match. We are not a substitute for legal or compliance advice and will say so whenever a question crosses that line.
Start with the evidence gap.
Tell us what you would be asked for in an examination, and we will tell you honestly which of it you could produce this week.
← All industries