Built for UK regulated financial services

Governance that works
as hard as your regulators do.

Cautara connects your DORA obligations, FCA requirements, supplier risk, operational resilience and board reporting into one auditable platform. From exception to evidence — in minutes, not months.

Covers DORA Art. 9 & 30 FCA PS21/3 PSD2 Operational Resilience Third-Party Risk
20+
Integrated modules
£2.5k
From per month
3
Regulatory frameworks
2wk
To go live on your data

Regulated firms face a
governance crisis — and they know it.

Risk in spreadsheets. Exceptions in email. Supplier data in SharePoint. No single source of truth — and auditors know it.

DORA is mandatory

The Digital Operational Resilience Act is live. Article 9 and 30 obligations apply now. Most mid-tier firms are behind — and regulators are watching.

📋

Fragmented tooling

Your risk team uses one tool. Compliance uses another. IT uses a third. Nothing talks to anything. When the FCA asks for evidence, someone spends three weeks pulling it together.

🏛️

FCA scrutiny is rising

PS21/3 operational resilience requirements demand documented, tested and auditable governance. Manual processes are no longer a defensible position.

💷

The cost is unsustainable

Firms spend £500k–£2M a year on GRC consultants, manual reporting and regulatory remediation. There is a better way — and it starts at £2,500 a month.

One platform.
Every governance obligation.

Twenty integrated modules covering every aspect of governance, risk and compliance — built specifically for regulated financial institutions.

📊

Executive Dashboard

Real-time governance posture across all modules. Red-to-green visibility for your CRO, CISO, CTO and board in one view.

Core
🛡️

GRC & Compliance

DORA, NIST, FCA PS21/3 and PSD2 framework tracking with live control ratings and remediation workflows.

Compliance
⚠️

Risk Register

Heat-mapped risk register linked directly to services, suppliers and exceptions. Open, mitigated, retired — fully auditable.

Risk
🏢

Supplier Management

TPRA scoring, DORA Article 30, contract values and concentration risk. Every supplier, every obligation — one register.

Third-Party
📁

Exceptions Register

Policy exceptions tracked, escalated and closed with a full audit trail. Never face an FCA review with an expired exception again.

Governance
💡

Ideas & PMO

From idea to board-approved programme — all in GOVARA. Connect your investment decisions directly to the risks they retire.

Strategy

From governance failure
to compliance certainty.

Watch a single non-compliant service go from red to green — across eight modules, with a full audit trail throughout.

01
Discover

Identify the problem

The dashboard flags your non-compliant service — low DORA score, expired exception, open risk, EOL software — across five modules simultaneously. Nothing gets missed.

02
Respond

Govern the response

An idea is raised, assessed and approved. A programme is funded in the PMO. Vendor sourcing goes through a DORA-compliant pipeline. Every step governed and documented.

03
Resolve

Close the loop

Compliance scores update. Exception closes with audit trail. Risk retires. GRC controls go green. The board dashboard reflects the improvement. All in one platform.

Built for the people
who carry the responsibility.

Cautara is used daily by the senior leadership teams at UK regulated financial institutions. Role-based access means every user sees exactly what they need.

Mid-tier banks and building societies
Insurers and asset managers
FCA-authorised payment institutions
Challenger banks and fintech under DORA
🎯

Chief Risk Officer

Risk register, exceptions, board reporting — everything in one view.

DORA Art.9 Risk heat map
🔐

CISO

Supplier TPRA, DORA Article 30, cybersecurity posture and third-party risk.

DORA Art.30 TPRA
⚙️

Chief Technology Officer

Service lifecycle, infrastructure register, obsolescence and EOL tracking.

Services Infrastructure
📈

Chief Financial Officer

TCO modelling, finance module, budget vs actuals and supplier spend.

TCO Finance

Every obligation.
One platform.

Cautara is built around the regulatory frameworks your firm must comply with — not adapted from a generic GRC tool.

EU Regulation

Digital Operational Resilience Act (DORA)

Full coverage of ICT risk management, incident reporting, third-party risk management and digital operational resilience testing obligations.

Article 5–10 Article 17–23 Article 28–30
FCA & PRA

FCA PS21/3 Operational Resilience

Important business services identification, impact tolerances, scenario testing, self-assessment and board reporting — fully documented and auditable.

IBS mapping Impact tolerances Self-assessment
EU Directive

Payment Services Directive (PSD2)

Operational and security risk management for payment service providers. Strong customer authentication, incident notification and third-party oversight.

Operational risk SCA controls Incident reporting

Institution-based.
No per-seat surprises.

Pay for the institution, not the headcount. Add your CRO, CISO, CTO and board without the bill changing.

Essentials
For smaller firms
Boutique banks, credit unions, smaller building societies getting governance in order.
£2,500/month
+ £5,000 implementation · 5 users
  • All core modules
  • Dashboard, GRC & Compliance
  • Risk & Exceptions register
  • Supplier management
  • Standard onboarding
  • Email support
Get started →
Enterprise
For larger institutions
Tier 2 banks, large insurers and systemically important firms with complex needs.
£20,000/month
+ £20,000 implementation · Unlimited users
  • Everything in Professional
  • On-premise deployment option
  • Custom regulatory frameworks
  • Named account director
  • Board reporting pack
  • Annual regulatory update briefings
Talk to us →

Annual contracts · 15% discount for upfront payment · ISO 27001 certified · DORA Article 30 compliant vendor

See Cautara in action.
20 minutes. Your obligations.

We tailor every demo to your specific regulatory position — DORA, FCA PS21/3, PSD2, operational resilience. No generic walkthrough.

1

20-minute
platform demo

2

We map to your
specific obligations

3

Pilot on your
data in 2 weeks