IAIS and DORA
Operational risk and resilience
A delivery platform inside a critical service falls inside your third-party risk assessment. The IAIS core principles set that expectation, and DORA in Europe, the PRA and FCA rules in the UK, and APRA's CPS 230 in Australia all carry it: manage the risk, and evidence the controls. Our delivery records what ran, under which controls, so you can show it.
ISO 27001 and NIST CSF
Information security
Whether you certify against ISO 27001, measure yourself against the NIST framework, or answer to CPS 234, the ask is the same: protect information assets and keep the controls tested and current. Your data sits apart from every other organisation's, and security standards are checked as rules, not left to memory.
IAIS ICP 19 and Consumer Duty
The software behind claims decisions
Claims handling is a regulated activity, and the systems that support it carry conduct obligations. The IAIS principles ask for fair treatment right through to settlement, and the UK's Consumer Duty holds insurers to the outcome, not just the process. When we build or change those systems, every requirement and decision is recorded, so you can show how the software you rely on came to be.
GDPR special categories
Built around sensitive data
Insurance and wealth systems hold health and financial information. GDPR treats health data as a special category, needing a stricter basis to process at all, and most privacy regimes draw a similar line. Standards for handling it are encoded as rules the work is checked against, and the record shows which controls applied.