Founder | | 6 min read
Doing compliance without a compliance team
How a small company turns regulatory obligations into owned tasks, evidence and review without inventing a department.
JEMA Software Ltd does not have a compliance department. That does not make compliance optional, and it does not make the founder a substitute for every specialist.
The practical problem is to turn obligations into work that somebody actually performs. A policy document cannot monitor an incident, remove database access or check whether a new screen changes the account information service. People and systems have to do those things.
In a small company, the structure is simpler, but the evidence still has to be real.
Start with the service, not a policy library
Generic templates are tempting because regulated documents use unfamiliar language. The problem is that a template often assumes departments, committees and products that do not exist.
We began by mapping the actual service. A user selects a supported bank. Finexer provides the regulated account information connection. The bank authenticates the user. Approved information returns through the connection and is stored for the budgeting features. Support, monitoring and deletion processes sit around that path.
Once the flow is visible, compliance questions become concrete. Who can access the database? Which fields enter an error report? What tells support that a connection has expired? Who contacts Finexer if a regulated incident occurs?
The resulting policies describe the company we have, not a larger company we would like to resemble.
Give each control an owner
A control without an owner is a sentence. The small-company version of a responsibility matrix can be a short record naming the person, task, frequency and evidence.
Access reviews have an owner. Provider checks have an owner. Customer complaints have a route. Security updates and dependency alerts have a route. Changes to consent wording cannot be approved by nobody.
Many owners are currently the same person. Recording that concentration is more useful than hiding it. It shows where continuity planning or an external review is needed and where a second person needs enough access to respond.
Keep evidence while doing the work
Compliance is difficult to reconstruct after the event. A claim that access is reviewed needs a record of the review. A claim that a release was tested needs the test result. A provider decision needs the information considered at the time.
Evidence does not require a complex platform. It can be a controlled register, a dated review, a change record or a retained test result. What matters is that the record is consistent, protected and connected to the control it supports.
The company also needs to avoid collecting evidence in unsafe ways. Copying customer transaction data into a general project board would prove that someone looked at a problem while creating a second privacy problem.
Use the principal relationship properly
Finexer is not only an API provider. It is the authorised principal for the account information service and has oversight responsibilities for its agent.
That relationship provides a route for questions, review and escalation. Product changes that affect the regulated service can be raised before release. Incidents can follow an agreed path. Customer wording can be checked against the actual role of each company.
Oversight does not remove JEMA's responsibility to operate its systems. It adds another control around the regulated activity. Treating the principal as a logo would waste the most important part of the arrangement.
Separate legal wording from operational truth
It is possible for a privacy notice to say access is restricted while an old administrator account remains active. It is possible for a complaint policy to name an inbox nobody monitors. It is possible for a change process to exist only in a document.
We check the statement against the system. The account list is the evidence for access. The tested mailbox is the evidence for the contact route. The release record is the evidence for change review.
Where the statement and system disagree, changing the sentence is not always the answer. Sometimes the control needs fixing. Sometimes the public claim was too broad and needs narrowing. Both cases need an honest record.
Know when internal work is not enough
A founder can read guidance, maintain registers and operate controls. Some questions still need professional interpretation or independent review.
Legal scope, complex incidents and material changes are examples where confidence is not evidence of competence. The company can use official guidance, principal oversight and specialist advice without pretending to employ a full internal team.
The decision to ask for help also needs timing. A review after a feature is live has less room to influence the architecture than a review while it is being designed.
Keep communication inside the control system
Website copy is part of regulated operations. Describing the agent as authorised would be wrong even if the database were perfectly secured. Describing an estimate as certain would create an expectation the data cannot support.
That means content changes need the same attention as code changes. Public claims are checked against permissions, providers and live product behaviour. Old copy has to be removed when the product changes rather than left in a forgotten static page.
The limitation remains
Operating without a dedicated team creates concentration risk and pressure on time. Documentation can become stale. The same person can design a control and assess whether it works. Those are real limitations.
The response is not to claim that a small company is naturally more careful. It is to keep the scope narrow, make ownership visible, use principal oversight, retain evidence and obtain external review where independence or expertise is required.
Compliance without a compliance team is possible only when compliance becomes ordinary operating work. It lives in access removal, release decisions, support routes and accurate sentences, not in a folder opened once before registration.
For current service details, read the company's open banking explanation and Privacy Policy.