FrameOne — Regulated Businesses

You have the same compliance obligations as the firm ten times your size. You don't have their budget, their architecture team, or their tolerance for tools that take six months to implement.

Regulatory frameworks — FCA PS21/3, ISO 22301, NIS2, DSPT, Cyber Essentials — were written for enterprises. The evidence they require is the same regardless of how many people you employ. Most SMEs in regulated sectors are producing that evidence through a combination of consultants, spreadsheets, and Word documents that are out of date before they leave the printer.

The problem

Where compliance breaks down for regulated SMEs

01

Compliance evidence is a point-in-time snapshot

Regulators and auditors increasingly expect a live, continuously maintained posture. A self-assessment document produced in advance of a review is not the same as being able to demonstrate operational resilience on any given day. The gap between those two things is where regulatory risk lives.

02

Your business continuity plan doesn't reflect how your business actually works

BC plans maintained separately from your operational environment go out of sync the moment something changes. A new system, a new supplier, a restructured team — the plan doesn't know. When you need it most, it describes a business that no longer exists.

03

Critical periods carry disproportionate risk

Month-end, peak trading windows, regulatory submission deadlines — these periods carry materially higher operational risk than ordinary business days. Your current tools and plans treat every day the same. Regulators increasingly do not.

04

One consultant engagement doesn't solve the ongoing problem

A consultancy can produce a gap analysis or a BC plan. It cannot keep it current. The ongoing cost of maintaining regulatory evidence through periodic consultant engagements is significant — and the result is still a document, not a live capability.

What FrameOne delivers

What changes when evidence is always ready

FrameOne is a Resilience Operating Platform designed for businesses that carry real regulatory obligations but not the enterprise resources to manage them. It produces compliance evidence as a continuous byproduct of how you run — not as a periodic exercise that happens before someone asks.

Live compliance evidence — not a document you produce before a review

Your FCA PS21/3 self-assessment, ISO 22301 gap report, and business continuity documentation are outputs of the system you use every day. Regulators see a continuously maintained posture, not a snapshot assembled under time pressure.

Impact tolerance tracking built in

Define your maximum tolerable disruption periods per service, record your tolerance testing, and maintain an evidenceable audit trail — in the format regulators recognise. Impact tolerance is not an annual exercise; it is a continuously updated record.

Business continuity plans that stay current automatically

Plans are connected to the live operational model, not maintained as separate documents. When your environment changes — a new system, a new supplier, a restructured team — your continuity documentation reflects it without a manual update cycle.

Incident response that works regardless of who is available

The knowledge your best people carry is captured in the system, not lost when they are unreachable. Whoever responds to an incident has access to current runbooks, dependencies, and escalation paths — not a playbook that was accurate eighteen months ago.

An audit trail that is immutable, searchable, and available on demand

When a regulator or auditor asks, the evidence is already there. Not assembled from emails and spreadsheets, but maintained continuously as part of how you operate — searchable, timestamped, and ready to present.

Getting started from what you already have

You do not need a blank-sheet exercise or a dedicated architecture programme to get started. FrameOne can read your existing documentation — Word files, PDFs, spreadsheets — and propose an initial operational model from what you already have. Operational clarity in days, not months. You start from where you are, not from zero.

Who this is for

Regulated businesses that need to demonstrate what enterprise firms take for granted

Financial services under FCA

Wealth managers, boutique asset managers, payment processors, and financial services firms facing FCA PS21/3 operational resilience obligations — where the regulator expects a live, evidenceable posture and the cost of non-compliance is existential.

Professional services under supply chain pressure

Professional services firms facing ISO 22301 compliance requirements from larger clients — where an inability to demonstrate operational resilience risks losing the contract, regardless of whether a regulator is directly involved.

Healthcare providers and NHS managed service providers

DSPT assessment is annual across ten data security standards. CQC Well-led inspections can arrive unannounced and now explicitly cover digital maturity and information governance. The evidence expected — continuity plans, risk registers, supplier assurance records, incident logs — is the same evidence FrameOne produces continuously from your operational model. When an inspector arrives or the assessment window opens, you are not assembling documents under pressure.

Built by someone who has been through the examination

FrameOne was built by someone who ran technology and assurance at a major UK managed service provider. As CTO and CIO at Redcentric, regulatory examinations, client audits, and the evidence collation that preceded them were a direct operational responsibility.

The gap between what compliance documents said and what systems actually looked like was a problem I watched create risk — and cost — repeatedly. FrameOne exists because that problem has a consistent solution that most organisations cannot currently afford to build for themselves.

Register your interest

Apply for the pilot programme

FrameOne is currently available through a structured pilot programme. We're working with a small number of regulated businesses who want to get ahead of their compliance obligations and help shape the platform in the process.

Pilot places are limited. Tell us which framework is most pressing and we'll confirm whether the fit is right.

This helps us confirm the pilot is the right fit for your organisation.