Rhys Llewellyn
Oversees hosting, infrastructure and AI automation, focused on operational efficiency and practical AI adoption.
Qualifications- ✓MBA (in progress), University of Gloucestershire
- ✓Marketing, operations & tech entrepreneurship
If you are a regulated business in the UK, by the FCA, the SRA, the ICAEW or a sector body, “IT compliance” is rarely a single thing. It is more accurately a set of overlapping frameworks that each ask for slightly different evidence on different timelines. This article maps the main frameworks required of a UK SME, what a compliance-ready IT partner should provide, and the kinds of evidence an auditor will ask for.
FCA operational resilience requirements
Every FCA-regulated firm has to identify its “important business services”, set impact tolerances for how long services can be disrupted, and demonstrate that it can operate within those tolerances during severe disruption. The requirements applied to all in-scope firms from March 2025 and are now audited routinely rather than treated as a set of best-effort principles.
Meaning the business needs to know which specific systems support the important business services, how those systems fail, how long each takes to recover, whether the recovery time meets the impact tolerance and whether the arrangement has been tested at least annually. A business that cannot produce a written impact tolerance for its client portal or its trading platform is unlikely to pass an FCA review, regardless of how technically advanced the underlying platform actually is.
The practical implication for regulated businesses is that IT support needs to include a documented service catalogue, tested disaster recovery plans, and change control that produces audit-ready evidence. Our companion guide to disaster recovery planning for small businesses covers the SME version of this in more detail.
ICO and UK GDPR obligations
Every business in the UK that processes personal data has ICO obligations, and for regulated firms that hold sensitive personal or financial data those obligations bite harder; a breach involving data triggers a mandatory notification within 72 hours of becoming aware.
The IT baseline for UK GDPR compliance typically includes a documented data flow map showing where personal data is housed, who has access and how long it is retained; access controls that follow the principle of least privilege; encryption both at rest and in transit for sensitive personal data; backup and recovery capability that includes recovery from ransomware specifically; and an incident response process capable of identifying, assessing and notifying a breach within the 72-hour window.
The ICO fined businesses over £15m in 2024 for breaches that were preventable with basic controls, the direct fine tends to be only part of the overall cost, since reputational damage and client attrition typically outweigh the penalty itself.
ISO 27001 as the enterprise standard
ISO 27001 is a full information security management system standard and a substantial commitment: six to twelve months to implement, an annual external audit, and ongoing internal audits thereafter. For most UK SMEs it is more than the business genuinely needs, but for regulated firms with enterprise clients it can be a client-side contractual requirement, particularly for firms doing outsourced work for banks, insurers or public bodies.
Sentinel is ISO 27001 aligned rather than certified, which tends to be honest positioning for an SME managed service provider, and full certification is worth pursuing when a specific client contract makes it a hard requirement or when the firm has grown to the point where the annual audit cost is proportionate to the benefit.
What a compliance-ready IT partner looks like
For a regulated business, IT support without compliance is a liability rather than an advantage. A compliance-ready partner should produce, on demand, an asset register listing device, user account and cloud service in use (with owner, purpose and criticality), an access control log showing who has admin rights to what (refreshed at least quarterly), a patching schedule with evidence that critical patches have been applied within a defined SLA, backup logs proving both that backups have run and that restores have been tested, an incident response process tested at least annually, and their own accreditations (Cyber Essentials Plus, ISO 27001 or equivalent, ICO registration and evidence of staff training).
If your current provider struggles to produce most of this within a working day, the firm is probably carrying more compliance risk than it should be. Our related article on why external vulnerability scans miss the most important issues covers a common failure mode where businesses think they have compliance evidence but actually only have automated scan output.
The audit trail question every regulator asks
Every compliance audit, whether from the FCA, the ICO, a client’s procurement team or an insurer, eventually asks the same question in different words: show me the evidence. Not a description of the process, not an account of what usually happens, but the actual log, the actual signed report, the actual date and time.
Building the evidence layer is unglamorous work, and it is also what separates a firm that passes an audit in a day from a firm that spends three weeks reconstructing history under pressure. A compliance-ready IT partner tends to treat the evidence layer as part of the service rather than as something billed separately after the fact.
The application and compliance audit case study documents exactly this pattern: a UK regulated broker where a code-level compliance audit surfaced exposures that the annual external vulnerability scan had missed entirely. The exposures were closed within the audit window, and the audit trail produced during remediation went on to serve as the firm’s evidence for its next FCA review.
Compliance-ready IT support for UK regulated firms. Sentinel Infrastructure supports UK firms with FCA, ICO, Cyber Essentials Plus and ISO 27001 requirements as part of managed IT support, documented and audit-ready, from a UK team. Book a compliance review by calling 01452 881 471.
Application & Compliance Audit for a Regulated Broker
A code-level review that caught exposures an external scan walked straight past. The audit trail produced during remediation became the firm’s evidence for its next FCA review.