Fixology builds software for FCA-regulated firms: case management with tamper-evident audit trails, Consumer Duty MI captured during normal work, broker and customer portals, open banking and credit data integrations, and staged replacement of legacy administration systems. A Consumer Duty dashboard typically takes 6 to 10 weeks and case management or a customer portal 3 to 5 months. Code, hosting and documentation sit in your name from day one, which supports your outsourcing and operational resilience obligations.
Packaged platforms and the work that happens outside them
Most regulated firms run on a sector platform: Acturis, Open GI, SSP or Applied Epic for insurance broking, Mortgage Brain or Twenty7tec for mortgage sourcing, Intelliflo or Iress for financial advice, and a loan management system for lenders. These platforms are good at the transactions they were built for and are often hard to change.
The work that sits outside them is where the compliance risk builds up. Vulnerable customer flags held in a spreadsheet. File reviews tracked in a shared workbook. Complaints logged in a separate tool with no link to the case. MI for the board assembled by hand each quarter from four exports. A regulator, or your own compliance monitoring, will eventually ask how you know your customers get good outcomes, and the honest answer should not be "we rebuild a spreadsheet".
Consumer Duty: evidence, not assertions
The Consumer Duty has applied to open products since 31 July 2023 and to closed products since 31 July 2024. It asks firms to deliver good outcomes across four areas, covering products and services, fair value, consumer understanding and consumer support, and to monitor and evidence those outcomes, including for customers with characteristics of vulnerability. Boards review the evidence at least once a year.
Good MI comes from data captured during normal work, not collected afterwards. A system that records vulnerability at fact find, tracks how long customers wait at each stage, logs every communication sent, and links complaints to the case they came from can produce outcome reporting by product and customer group on demand. That is a far stronger position than a slide deck built from samples.
Audit trails, SM&CR and complaints handling
Regulated software needs to answer three questions about every important record: who changed it, when, and what it looked like before. We build audit logs that cannot be edited by users, including administrators, and that are kept for as long as your record-keeping obligations require.
Under the Senior Managers and Certification Regime, firms hold Statements of Responsibilities for senior managers, assess certified staff as fit and proper at least once a year, and train staff on the Conduct Rules. A small internal system can hold those records, schedule the assessments and produce the evidence quickly. Complaints are similar: under DISP, most complaints need a final response within eight weeks, with shorter limits for many payment services complaints. A complaints log that counts the days and escalates before a deadline protects both the customer and the firm.
Open banking, credit data and affordability
Open banking lets a customer share their bank transactions with your firm in seconds, which transforms affordability and income checks for lenders and brokers. Most firms access it through an FCA-authorised provider such as TrueLayer or Yapily rather than seeking their own permissions, and the same providers can initiate payments.
The design detail matters. Consent has to be clear, the customer must understand what is being shared and for how long, and the data you keep should be the minimum needed for the decision. We usually store the derived figures, such as verified income and committed spending, alongside a copy of the raw statement only for as long as your policy requires.
Combining that with credit reference data from Experian, Equifax or TransUnion, and with your own policy rules, gives an underwriter or adviser a clear picture and a recorded reason for every decision. These connections are a standard part of our API integration work, with the consent journeys and data retention rules designed in from the start.
Replacing legacy administration systems safely
Many lenders, MGAs and life and pensions administrators still run core systems written fifteen or twenty years ago, often in a language few developers want to work in. They usually work, which is the problem: replacing them feels riskier than living with them, until the last person who understands the code retires.
We approach this through legacy modernisation in stages. First a new layer reads from the old system and gives staff and customers modern screens. Then functions move across one at a time, with reconciliation reports proving the old and new systems agree, until the old one is only a read-only archive. It is slower than a big bang switch, and much less likely to appear in a regulator's letter. Our guide to why software projects fail explains why the big bang approach goes wrong so often.
Example: a specialist lender with 25 staff
Imagine a hypothetical specialist lender writing bridging and buy-to-let loans through brokers. Applications arrive by email, underwriting notes live in Word documents, and the board pack takes a week to build. A broker portal, case tracking with a full audit trail, open banking statements pulled at application, and automated MI would be a sensible first scope.
Built as a web application on top of the existing loan servicing system, it would go live in phases over three to five months. The servicing system keeps the accounts; the new tool owns the journey up to completion and the evidence around it.
Operational resilience, outsourcing and security
If a system supports an important business service or a critical function, your firm stays responsible for it even when we build and support it. FCA rules on outsourcing and operational resilience expect you to understand the risks, have exit plans, and be able to keep operating within impact tolerances if something fails. We make that easier by putting the code in your repository, the hosting in your cloud account in UK or EU regions, and the documentation in your hands from day one.
Every regulated build gets independent penetration testing, role-based access, encryption at rest and in transit, and tested backups and restores. The detail is on our security page, and we provide the supplier information your due diligence and outsourcing register need.
Why regulated firms choose Fixology
We aim to be the UK's leading financial services software development company, and in a regulated market that ambition is earned through discipline: written specifications, traceable decisions and software that produces its own evidence. Discovery includes time with compliance, operations and the people who handle cases every day, and ends with a specification and a phased delivery plan your board can review.
A senior UK team then builds in two-week sprints with a working demo on a test link, and nothing reaches customers until it has been tested against real scenarios. After launch we support the system under clear service levels, and because you own the code and the hosting, your exit plan is real rather than theoretical.