Skip to content
Houtini.
Contact
Our Work

Compliance monitoring software for FCA-regulated networks

An FCA-authorised principal firm approached me to see if I could help them cut the time it takes to compliance-check the broker websites in their appointed-representative network - around three hours a site, by hand.

42
FCA controls per audit
3 hrs → 2-5 min
per site, cold URL to evidence-backed decisions
Assure's reviewer console: one finding with its cited FCA rules and the officer's four-state decision
One real finding, the rules it cites, and the officer's decision - client identifiers removed.

A compliance officer opening every page, reading it against the financial-promotions rulebook, screenshotting the evidence, checking the firm's FRN against the live FCA Register, writing it all up. Most of those three hours weren't judgement. They were a waste of a qualified consultant's time.

And, of course, a site could change the day after evaluation and sign-off with nobody the wiser.

How I thought about it

The design principle I based this project on: decide everything that can be decided mechanically in code (deterministic findings), and only send the judgement calls to an AI. Judgement was then evaluated by a separate model acting as a jury, to improve confidence levels in the monitored output. Of the 42 controls we check - each tied to a named rule in the FCA Handbook or UK statute - 30 resolve deterministically. Same input, same output, no AI involved, nothing to drift. The remaining grey areas go to an AI reviewer, and every finding carries the exact line from the page it rests on.

The firm itself gets cross-checked live against two registers on every audit: the FCA Register and Companies House. In testing, that live check caught an appointed representative running financial promotions while citing an FRN the Register showed was no longer authorised - on a page a homepage-only review would never have opened.

One thing the tool deliberately does not do: file a verdict. The officer sees every decision with its evidence, and accepts, overrides or annotates. Four states, none of them "compliant". That's a design position, not a limitation - in this domain the machine collects and proposes; the human decides.

Where it stands

Proven end-to-end on real websites: a cold URL to a reviewable, evidence-backed decision on every control in 2-5 minutes, and the same audit re-runs on a schedule, so a change made after sign-off gets caught on the next pass. We ran roughly 1,650 automated equivalence checks between the reference engine and the deployed version - zero divergences, because a number a firm relies on has to be reproducible, not a model's opinion that varies between runs.

There's a chat assistant over the audit record too. Ask why a control flagged and it answers from the audit and the verbatim FCA Handbook, citing the rule it rests on every time - and a question outside the record gets "not in the audit record", never a guess. Advisory, human-in-the-loop; the officer still makes the decision.

The compliance assistant answering why an FCA authorisation check flagged, citing GEN 4 Annex 1R and CONC 3.7.5R
Ask the audit a question - the answer cites the Handbook rule it rests on, or says "not in the audit record".
Method

Firecrawl site capture → deterministic rules engine + live FCA Register & Companies House checks → AI judge on the grey areas → reviewer console.

If this looks familiar

Regulated-industry data collection has the same shape everywhere: hours of gathering wrapped around minutes of judgement. If your team's week looks like that - compliance, onboarding, due diligence - we should speak.