Resilience, regulation and modernisation, held together.
Regulated firms carry an obligation most businesses do not: they have to prove their controls work, on demand, to someone with the power to penalise them. We operate the technology, evidence the controls continuously and keep modernisation moving without adding regulatory risk.
- 24/7
- DORA
- Qtr

One partner across operations, cyber and the evidence pack.
Most firms have the controls somewhere. What they lack is a single accountable team that runs them, tests them and produces the artefacts on demand. We hold all three, so a regulator, insurer or institutional client gets the same answer as your operating board.
Four missions in financial services.
Operational and cyber resilience
Impact tolerances, dependency mapping, 24/7 detection and response, and restore procedures that are rehearsed rather than assumed.
Regulatory evidence, maintained
Controls, artefacts and audit trails kept current for FCA, PRA, DORA and POPIA style review, not assembled in a panic before an assessment.
Data protection and retention
Client data classified, retained and deleted defensibly, with backup and recovery tested to an agreed schedule.
AI adoption with governance
A use-case register, human-in-the-loop controls and literacy tiers so AI enters the firm through a governed door.
What financial services leaders are contending with.
Financial services leaders rarely open with technology. They open with the supervisory expectation, the client due diligence questionnaire or the incident they cannot afford. These are the pressures that shape every engagement.
Supervisory expectation
DORA, FCA and PRA expectations turn resilience from a good practice into a demonstrable obligation with named accountability.
Third-party concentration
Critical providers must be tiered, reviewed and exit-tested. Concentration risk is now a board-level question.
Client due diligence
Institutional clients audit their suppliers. Slow or incomplete evidence loses mandates before price is discussed.
Legacy under load
Core platforms cannot simply be replaced. Modernisation has to happen around live regulated processes.
Financial crime and fraud
Social engineering targets payments and client onboarding, so identity controls carry commercial as well as security weight.
Talent scarcity
Specialist security and compliance skills are hard to hire and harder to retain at mid-market scale.
From supervisory exposure to evidenced resilience in five deliberate steps.
Assess
Business Technology Assessment across estate, risk, cost and capability.
Stabilise
Close critical exposure and bring monitoring, backup and support to a known-good standard.
Standardise
Common platforms, identity and images. Reduce variability before adding capability.
Optimise
Automation and governed AI applied where they measurably earn their keep.
Run
24/7 service, quarterly business reviews and a costed roadmap the business signs off.
The evidence the business can point to.
Resilience mapped
Important business services, impact tolerances and dependencies documented and tested against real scenarios.
Evidence on demand
A maintained control library and artefact pack, ready when an auditor, insurer or client asks.
Third-party register
Vendor tiering, review cadence and exit playbooks held as a live record rather than a spreadsheet.
Governed AI
Every AI use case has an owner, guardrails and a measurable business case before it goes near client data.
- FCA
- PRA
- DORA
- GDPR
- POPIA
- FSCA
- ISO 27001
One methodology, applied to financial services.
Six categories, delivered as one. Every engagement is scoped and governed through the same framework we apply across every vertical we support.
IT Strategy, Risk & Compliance
Cyber Resilience
Data Protection
IT Operations
Modern Work Enablement
AI & Data Enablement
Work we have delivered in and around financial services.
Anonymised, evidence-led accounts of the engagement, the decisions taken and the measured result.

A financial services group builds a governed AI adoption engine.
A South African financial services group wanted the benefit of AI across investment banking, corporate finance, securities, compliance and reporting without loosening its grip on governance. Numata replaced fragmented experimentation with a managed adoption model: executive alignment, secure onboarding, AI Champions, departmental workshops and finance-specific agents.
Managed AI · Financial services group · South Africa

Governance, risk visibility and cyber resilience in a regulated business.
A regulated financial services organisation needed to move IT risk management out of fragmented technical activity and into a structured governance rhythm. Numata delivered a Managed IT GRC programme that gave leadership clearer visibility of risks, priorities, evidence requirements and security improvement actions, then expanded into broader managed security services.
Managed IT GRC · Regulated financial services · Anonymised

Multi-site separation from a shared legacy estate.
A family office and investment group separating from two shared Active Directory forests and a legacy on-premises estate spanning offices and rural estates, evolving into an eight-year strategic partnership.
Corporate restructure · Family office / investment group · UK & Southern Africa
Common questions from financial services.
Do you work with FCA and PRA regulated firms?
Yes. We support regulated firms in the United Kingdom and Ireland alongside FSCA regulated businesses in South Africa, and our control library is maintained against the expectations that apply in each jurisdiction.
How do you support DORA readiness?
We map important business services and their technology dependencies, set impact tolerances with the business, test restore and failover against those tolerances, and maintain the register of information and third-party evidence that sits behind the regime.
Can you answer client due diligence questionnaires on our behalf?
We provide the technology and security evidence that sits behind them, including control descriptions, penetration test summaries, resilience testing records and policy artefacts. Your compliance team retains ownership of the response.
What happens during an incident?
Monitoring and triage run 24/7/365. A named incident lead owns communication, we work to the response targets in your service agreement, and you receive a written post-incident review with the actions tracked to closure.
Can you modernise without disrupting regulated processes?
Yes, by sequencing. We stabilise and standardise first, then change one thing at a time behind tested rollback, with change records that satisfy your own governance.
How do you handle AI in a regulated firm?
Through a use-case register with an accountable owner per case, data controls that keep client information out of ungoverned tools, human review on anything customer or credit facing, and reporting into your existing risk forum.
Who reports to our board or risk committee?
Your Business Technology Strategist, quarterly, against a scorecard covering posture, incidents, resilience testing, third-party risk and roadmap progress.
The same standard, in the sectors beside yours.
Private Equity
Technology diligence turned into Day One execution, then value creation across the holding period.
Legal
Matter confidentiality, secure client collaboration and practice productivity.
Audit and Accounting
Client data protection, engagement security and efficiency through busy season.
Healthcare and Life Sciences
Patient and study data protected, clinical systems available, privacy evidenced.
Manufacturing
Production uptime, OT and IT separated properly, and cyber resilience on the plant floor.
Engineering and Construction
Project sites connected quickly, design data protected, mobile teams supported.
Bring the evidence pack up to the standard your regulator already assumes.
A short conversation to map your important business services, your current evidence position and the two or three moves that most reduce supervisory and operational risk.
