“Is this platform compliant?” sounds like a prudent evaluation question and is too broad to answer responsibly. UK financial-services requirements depend on the firm, permissions, activities, clients, service materiality, data and intended use. A product does not carry a transferable compliance status.
The stronger method is to involve compliance, risk, security, privacy, records and operational owners at the start, translate applicable duties into testable controls and assess the complete service throughout its life.
This article is an evaluation framework, not legal or regulatory advice. Firms should confirm current requirements with accountable specialists and the latest regulator material.
Start with the firm and the service
Define the platform’s role. A public content site, authenticated client service and system supporting an important business service create different risk and oversight questions.
Record:
- legal entities, permissions and relevant rules;
- client and product types;
- information processed and its sensitivity;
- business services and impact tolerances affected;
- users, administrators and approvers;
- suppliers, sub-outsourcing and hosting;
- integrations and authoritative data;
- geographic processing and access;
- required operation, recovery and exit.
Then determine materiality and risk. Avoid copying controls from a wealth manager, insurer or lender without establishing that their obligations and service match yours.
Cloud is a third-party risk question
Cloud hosting is not prohibited merely because it is cloud. The FCA’s guidance on outsourcing to cloud and other third-party IT services addresses oversight across decision, selection, monitoring and exit. The current FCA Handbook SYSC 8 also makes clear that firms retain responsibility when relevant functions are outsourced.
PRA-regulated firms must consider applicable PRA requirements. A March 2026 update to SS2/21 on outsourcing and third-party risk states an effective date of 18 March 2027 and covers risk-based controls for material third-party arrangements. The current and future versions must be distinguished during transition.
Assessment should cover governance, due diligence, concentration, contract, access and audit, security, data, service continuity, monitoring, incident reporting, sub-contracting, change, exit and record obligations. A provider’s certification can support evidence and does not discharge the firm’s own responsibility.
“UK region” is not a complete data-location answer. Establish primary, backup, support, telemetry and onward processing, along with legal transfer mechanisms and supplier change notification.
Connect the platform to operational resilience
Identify whether the platform supports an important business service and map the people, processes, technology, facilities, information and third parties required to deliver it.
Test failure against the firm’s current operational-resilience obligations and impact tolerances. Examine loss of the platform, identity provider, network, integration, data feed or critical supplier support. Include plausible data corruption and cyber scenarios, not only clean unavailability.
The service needs detection, response, communication, recovery and learning. High availability in a vendor brochure is not evidence that the firm can remain within its tolerance.
Build exit planning into selection. Data export, configuration, content, logs, interfaces, knowledge, transition assistance and parallel operation may all matter. An exit clause without a tested route can leave the firm locked in operationally.
Make communications governance testable
Applicable FCA rules on client communications and financial promotions vary. The current COBS 4.10 material, for example, discusses systems and controls for approving and monitoring relevant promotions. Other sourcebooks may impose different record and retention conditions.
Map the firm’s actual approval responsibilities into the content service:
- which items require review and by whom;
- competence and authority of approvers;
- separation of drafting, approval and publication where needed;
- treatment of amendments and reusable content;
- effective dates, withdrawal and continuing review;
- evidence of version, decision, user and time;
- emergency correction and incident handling;
- production of records in a usable form.
Do not assume a CMS must contain every control. A governed workflow may span a records service, approval tool and deployment process. The end-to-end evidence matters.
Test attempts to bypass controls, role change, absence, imported content and publication through APIs. A workflow visible in a demonstration may fail under actual permission and integration conditions.
Avoid universal retention claims such as “six years for all content”. Determine the applicable rule, record type, trigger and format with legal and records specialists.
Evaluate identity, access and accountability
Define roles by task and consequence. Apply least privilege, strong authentication, joiner-mover-leaver controls, protected administration and review of dormant or exceptional access.
Check whether the platform can distinguish authors, approvers, publishers, developers, support suppliers and emergency administrators. Shared accounts destroy attribution. Supplier access should be authorised, time-bounded, monitored and removed.
Audit evidence needs integrity, time, user, action and relevant context. Determine who can alter or delete logs, how they are retained and whether the firm can retrieve them without prolonged supplier dependence.
Access control also includes content and data visibility. Ethical walls, client confidentiality, internal sensitivity and personal data may require more than a basic editor-versus-publisher model.
Assess data and security as a lifecycle
Document purpose, lawful basis, classification, location, access, encryption, retention, correction, deletion and incident routes. Minimise data rather than collecting it because the platform supports additional fields.
Review secure development, vulnerability management, configuration, dependencies, penetration testing, monitoring and disclosure. Decide how product updates or SaaS changes are evaluated before they alter a regulated process.
The FCA’s current data-security themes include governance and monitoring of outsourced suppliers. Use applicable regulatory material alongside recognised security practice and firm-specific threat assessment.
Security evidence must cover the configured implementation and its operation, not only the vendor’s corporate controls.
Turn obligations into evaluation scenarios
Create a requirements register with source, interpretation, owner, control, evidence and review date. Mark uncertainty and obtain specialist resolution.
Use realistic scenarios:
- an authorised person drafts and routes a regulated communication;
- an amendment changes a previously approved claim;
- an approver is unavailable or loses authority;
- a supplier administrator requests urgent access;
- a platform or integration fails during a client task;
- the firm must produce the decision and published version;
- data needs correction, export or deletion;
- the supplier changes a sub-processor or service feature;
- the firm executes a controlled exit.
Define pass, qualified pass and fail before testing. Capture assistance, workarounds and custom development required.
The platform shortlist should also compare usability, accessibility, cost, skills and strategic fit. A system that can be configured compliantly and is too difficult to operate may decay into unsafe workarounds.
Involve compliance as a co-author
Late sign-off creates an asymmetric decision: compliance inherits the downside of approval after others have committed to the solution. Early participation lets specialists shape requirements and evidence before products acquire political momentum.
Keep roles clear. Compliance advises and owns defined judgements; technology explains architecture; security and privacy assess their domains; service owners state operational need; accountable executives accept decisions within authority. Vendor statements remain inputs.
The downloadable regulated-platform evaluation tool should be reviewed against current firm duties before use. A regulated platform review can facilitate the work, but cannot replace the firm’s legal, compliance or regulatory accountability.
The goal is not to find a product branded as compliant. It is to select and operate a service whose duties, controls, evidence and exit are understood well enough for the firm to remain accountable.



