Skip to content
Zorix Systems — software that powers your business

Industries

Software for regulated firms, built so the audit trail comes as standard

In financial services the software problem is rarely the feature list. It is evidence. A firm can usually do the right thing; proving to a regulator, an auditor or an ombudsman that it did the right thing, on a specific date, for a specific client, is what the systems fail at.

We build client portals, onboarding and KYC workflow, adviser and broker back office, reconciliation tooling and regulatory reporting pipelines for firms that have outgrown configured platforms — with immutable history, versioned communications and access logging designed in from the first sprint rather than retrofitted before an inspection.

Where it breaks

Where regulated operations lose control of their own record

Onboarding is a relay across four disconnected tools

Identity verification runs in one vendor, sanctions and PEP screening in another, source-of-funds evidence arrives by email, and the CRM records only that onboarding 'completed'. When a case is reviewed two years later the individual screening results and the reason a hit was discounted cannot be produced without a manual hunt.

Consumer Duty outcomes cannot be evidenced at scale

Firms can describe their approach to fair value, comprehension and vulnerability. What they cannot do is produce, per client, the version of the communication that was sent, whether a vulnerability was flagged, what adjustment followed and what the outcome was — because none of it was captured as structured data.

Reconciliation is a spreadsheet with a monthly deadline

Commission statements, provider payments, client account movements and ledger entries are matched by hand. Breaks are chased by email, resolutions are not recorded against the item, and the same systematic underpayment recurs for months because nobody can see the pattern across statements.

Client communication is unversioned

Documents are generated from templates that are edited in place. Once a template changes, the firm can no longer show what a client actually received, which converts a routine complaint into an indefensible one.

Access to client data is unlogged

Most line-of-business systems log writes and ignore reads. For a firm handling sensitive financial and personal data, being unable to say who viewed a client record is both a data protection weakness and an internal-fraud blind spot.

Regulatory reporting is assembled by hand

Returns are compiled from extracts, adjusted in a workbook and submitted, with the adjustments living only in that workbook. Restating a prior period, or explaining why two returns disagree, then becomes archaeology.

Regulatory context

What the sector has to satisfy

FCA Consumer Duty
Products and services, price and value, consumer understanding and consumer support outcomes, with monitoring evidence and board reporting that has to be produced from data rather than narrative.
SM&CR accountability
Named senior manager responsibility mapped to system actions, so approvals, overrides and exceptions are attributable to an individual with a timestamp.
AML, KYC and sanctions
Customer due diligence and enhanced due diligence records, PEP and sanctions screening results retained with the decision rationale, and ongoing monitoring triggers under the Money Laundering Regulations.
Client money and assets
Where CASS applies, segregation, reconciliation frequency and breach recording have to be supported by the system rather than by a parallel spreadsheet.
UK GDPR and DPA 2018
Lawful basis recorded per processing purpose, retention schedules enforced in the data model, subject access requests answerable from the system, and read-access audit logging on client records.
Operational resilience and PCI DSS
Important business services mapped with impact tolerances and tested failure scenarios; card data kept out of scope by tokenising at the acquirer wherever payments are taken.

Integration surface

The systems we connect to, named

Identity, screening and signing

OnfidoComplyAdvantageExperianEquifaxDocuSignCompanies House API

Banking and payments

Open Banking AISPOpen Banking PISPBacsGoCardlessStripeModulr

Back office and accounting

IntellifloIressXeroSageSalesforce Financial Services CloudDynamics 365

Data and reporting

SQL ServerPostgreSQLAzure Data FactoryPower BImarket data feeds

Solutions

What we build in this sector

Client and adviser portals

Secure portals for clients, advisers and introducers with document exchange, e-signature, task tracking and versioned communications that survive a complaint review.

Explore client and adviser portals

Onboarding and KYC workflow

Case-managed onboarding that orchestrates identity, screening and source-of-funds evidence, records each decision with its rationale, and escalates by risk rating rather than by inbox.

Explore onboarding and kyc workflow

Reconciliation and reporting pipelines

Automated matching of commission, provider and ledger data with exception queues, break ageing and reportable audit history, plus regulatory return preparation from source data.

Explore reconciliation and reporting pipelines

Core system integration

Integration between back-office platforms, Open Banking providers, screening vendors and the general ledger, with idempotent processing and replayable message history.

Explore core system integration

Engagement shapes

Typical scope, duration and budget band

Discovery and control mapping
Four to six weeks covering the record model, the control points that must be evidenced, data residency and retention, and the integration surface across vendors.
Phase one build
Typically four to seven months for a portal plus onboarding workflow with screening integration, audit logging and document versioning in place from launch.
Subsequent phases
Reconciliation, Consumer Duty monitoring, regulatory reporting and adviser back-office consolidation, delivered in two-week iterations.
Budget band
Quoted per engagement following discovery. The main drivers are the number of regulated processes in scope and the volume of vendor integration, not user count.
How discovery and scoping works

Questions

Frequently asked

Do you build regulated products or the systems around them?

The systems around them. We are software engineers, not a regulated firm, so we do not hold permissions and we do not advise on whether a permission is required. We build the client portals, onboarding and KYC workflow, adviser back office, reconciliation tooling and reporting pipelines that a regulated firm operates under its own permissions, and we build them so the firm's compliance team can evidence what happened.

How do you handle Consumer Duty evidence?

By making outcomes recordable rather than asserted. Communication versions and the exact wording a client saw, comprehension checkpoints, vulnerability flags and the adjustments made, fee disclosure at point of sale and the timeline of contact all become first-class records with immutable history, so a board report or an FCA request can be answered from the system rather than from a reconstruction exercise.

Can you integrate with Open Banking and payment providers?

Yes. Account information and payment initiation through an FCA-registered AISP or PISP provider, plus direct debit through Bacs bureaux or providers such as GoCardless, and card acquiring where PCI DSS scope can be kept out of your own estate by tokenising at the provider.

Where does client data sit?

In your tenancy or a UK or EU region of your choosing, with encryption at rest and in transit, role-based access, and audit logging of read as well as write access to client records. Data residency, retention schedules and deletion behaviour are agreed in discovery and written into the architecture document rather than left to defaults.

Do you work with brokers, IFAs, lenders or insurers?

All four, with the caveat that the record model differs sharply between them. Broking and advice work centres on the client, the fact-find and the recommendation; lending centres on the application, the decision and the servicing schedule; insurance centres on the policy, the endorsement and the claim. We model whichever is actually yours rather than forcing a generic CRM shape onto it.

Tell us what your systems are doing wrong.

Send the problem, not a brief. We will tell you whether it is a project we should be involved in.

Talk to us