Skip to content
UVS

Industry

9 offerings apply

Fintech, neobanks & web3

Fintechs, neobanks, payment platforms and web3 companies growing faster than their compliance function can hire.

The pressure

Do they understand what is actually going wrong?

What makes this business type hard to run.

Growth and compliance scale on different curves. Sign-ups can multiply in a quarter; a trained KYC reviewer takes months to bring up and cannot be hired on the day a campaign lands. Meanwhile every new market adds a regulator, and the onboarding queue that used to take an hour becomes the reason users churn before they ever fund an account.

Signals — recognise two and it is worth a conversation

  • Onboarding backlog grows during exactly the weeks acquisition is working
  • Verification SLA is measured in days and quoted to users in minutes
  • Alert review is done by whoever on the ops team is free that afternoon
  • A new market launch is blocked on headcount rather than on product
  • Nobody can reconstruct, for a regulator, why a specific account was cleared

Vendor due diligence

Can I put them in my outsourcing register?

What a regulated client actually needs from us.

We are not a regulated entity and we do not hold your licence — your obligations under supervision stay yours. Our job is to be a vendor you can put in your outsourcing register without a fight.

  • GDPRArticle 28

    We handle personal data as your processor, on your DPA and your documented instructions. Sub-processors are disclosed before they are used, never after.

  • 5AMLD · 6AMLDAML operations

    Onboarding review and alert disposition worked to your AML policy and your risk appetite — not to a generic checklist we brought with us.

  • MiCA · PSAN / DASPCrypto onboarding

    Fiat-to-crypto onboarding, travel-rule counterparty data and wallet-side alert review, worked to the policy a registered crypto firm is required to hold.

  • DORAICT third party

    We contract as an ICT third-party provider: audit and regulator access, notice before sub-outsourcing, breach notification and a written exit plan.

  • ACPR · AMF · FCAYour supervision

    The authorisation is yours and stays yours. Our job is to be the vendor you can place under it — and to hold the outsourcing terms your supervisor expects to see.

  • 01

    Processor, not controller

    We handle personal data under Article 28 as your processor, on your DPA and your documented instructions. Sub-processors are listed and disclosed before they are used, never after.

  • 02

    Where your data sits

    Agents work inside your systems under role-based access scoped to the queue they are on — we do not export customer records to ours, so there is no shadow copy of your data for anyone to ask about. Personal data is processed from Pakistan and Australia. Neither holds an EU adequacy decision, so those transfers rest on Standard Contractual Clauses with a transfer impact assessment on file. We would rather you heard that from us on this page than found it in week three of a questionnaire, and we share both documents during due diligence rather than after signature.

  • 03

    Terms that survive an audit

    Audit and access rights for you and for your regulator, notice before any sub-outsourcing, breach notification without undue delay, and a written exit plan — the clauses the EBA outsourcing guidelines and DORA Article 30 require you to hold with any ICT third party.

  • 04

    Reconstructable decisions

    Every onboarding approval, escalation and alert disposition is recorded against the policy version it was made under, with the evidence the reviewer actually saw. The disposition is always a person’s.

What we do not have yet

We do not hold ISO 27001 or SOC 2, and we will not dress up something adjacent to look like one. If a certificate is a hard requirement for this engagement, say so on the first call and we will tell you honestly whether to wait for us or go elsewhere. Otherwise we will show you our controls, our access logs and our sub-processor list instead — and tell you plainly which lines of your questionnaire we cannot answer.

This describes contractual position, not certification. No vendor can be “ACPR compliant” — that supervision applies to you, not to us — and there is no general GDPR certificate to hold. Ask us for the documents; they are the only thing worth checking.

The underlying documents live with the engagement, not on this page. Our security practices and privacy notice set out the standing position; the DPA, sub-processor list and transfer documentation are shared during due diligence.

What we build

What exactly would I be buying?

What we would build for a business like this.

Each of these is written for this business type specifically. If a line reads like it could apply to any sector, it should not be here.

AI Engineering

AI Development

What we see

Onboarding documents arrive in a dozen formats and half a dozen languages, and a trained reviewer opens every one before an account can be funded.

What we build

Document extraction with a confidence score on every field, validated against the issuing format, holding anything uncertain for a reviewer rather than guessing it.

The detail that matters

Every extracted field carries its evidence and the policy version it was checked against, so a decision is reconstructable for a regulator years later.

AI Engineering

AI Agents

What we see

Monitoring fires thousands of alerts a month and analysts open every one, even though most clear on the first check.

What we build

An agent that gathers the evidence a first-pass review needs, classifies the obvious clears and routes the rest to an analyst with the investigation already started.

The detail that matters

It gathers and classifies. The disposition is always a person’s, because a machine-made compliance decision is a liability with a delay on it.

What we see

Sign-up drop-off is highest at the verification step, and nobody can say which screen loses them because the funnel is not instrumented.

What we build

Onboarding flows built to a mobile performance budget with the verification step instrumented per screen, so abandonment is a number rather than a theory.

The detail that matters

Regulated copy and disclosures are content, versioned with the page — so what a user was shown on a given date is recoverable.

Start

What is the next step?

Recognise two signals? That is enough to talk.

The most useful first call is a description of what is going wrong. We will tell you which half of the business it belongs to, roughly what it costs, and whether it is worth doing.