[ NS ] Navigation
UK AI studio · Regulated operations

Governance before
automation,
every time.

Who we are[ NS · FILM ]

Their problem isn't the technology.It's trust.

Buying an AI licence is easy. Being able to say who is accountable for what it decides, which rules apply, and what you would show a regulator who asked, is the part nobody has solved. So that is where we start.

[ 02 ] Where we workSECTORS / 02

Built for regulated,operationally complex industries.

One pattern. Six rulebooks. Only the rulebook changes.

[ 03 ] Regulatory & governance[ NS · 03 ]

The map comes first.Everything else is built on it.

Mapping is what you're buying — not a hub, not a licence: the regulations, policies, controls and systems specific to your operation, brought into one model you own. It shows you what applies, where the evidence lives, and exactly what a rule change would touch, before we build anything.

01

Map

Regulations, policies, controls, processes, evidence and owners — one model, built from your systems. This is the deliverable, not a preview of one.

02

Score

Every gap and obligation scored for impact, so what matters first is obvious — and what doesn't pay back gets said in writing.

03

Build

The governed pipeline, built only once the map and the score have proven it's worth it.

Watching UK SRS · FCA · ICO · Ofgem · EU AI Act

Continuous monitoringEvery regulatory update, read on arrival
Your landscape
Regulations
Policies
Controls
Processes
Evidence
Owners
Your map

Every obligation joined to the data that evidences it

Full audit trail · human sign-off

When the rulebook moves
Gap identified
Impact assessed
Actions recommended
Owner notified
Priority set

Regulation is usually where it starts.

The same approach extends to policies, controls and risk — mapped first, every time, and built only once it's proven.

[ 04 ] One change, mapped[ NS · 04 ]

A rule lands. You already know what it costs you.

Change detectedICO/FCA joint code on automated decision-making4 obligations touched
ObligationYour controlOwnerStatus
Automated decision reviewHuman review gateHead of ComplianceGap
Customer notificationComms templateOps DirectorEvidence missing
Model documentationDecision logCTOIn place
Senior accountabilityNamed SMFCEOIn place
Two gaps, two owners, priority set. Before the deadline.Illustrative
Tom Brown

North Stack's understanding of regulation, and how systems can be built with this in mind, is exceptional. I felt in safe hands throughout.

Tom BrownManaging Director, PMD Finance
[ 05 ] Questions a serious buyer asks[ NS · 05 ]

The questions that actually matter.

The things a COO, operations director or compliance lead needs answered before they'd let us near the operation.

01What does North Stack actually do, in one sentence?

We take the regulated, document-heavy work your systems can't touch — inbound claims, case files, compliance reporting — and turn it into a governed AI pipeline: extraction, a human review queue for anything uncertain, and a full audit trail into the systems you already run. For ongoing regulatory and governance work, we build that same model bespoke to your setup — mapped to your regulations, your systems, your controls.

02How do you approach regulatory and governance work?

We map the regulations, policies, controls and systems specific to your operation into one model — covering what applies, where the evidence lives, and who owns each obligation. Every regulatory update is read against that model, so you see the gap, the impact and who needs to act. It's built to your setup, not sold as a template.

03How is that different from a GRC platform?

A GRC platform gives you a register you update by hand, built for any sector so it fits none of them precisely, and you own a licence. We build the model around your actual regulations, systems and controls, and it reads change continuously — not a template, and not something you're left to configure yourself.

04Most of our people already use ChatGPT. Isn't that the same thing?

It isn't, and the gap is the interesting part. Buying a licence is easy; being able to say who is accountable for how it gets used is not. Before automating anything we help you answer that: which rules apply, where the data behind them lives, and who owns the answer when a regulator, a client or a court asks.

05How do you make sure this is safe in a regulated environment?

Human sign-off on every disclosure, field-level confidence scores, role-based access, a complete exportable audit trail from source to statement, permanent red lines (no automated payments or bank-detail changes), and a hard human gate before any regulator submission. Your data stays in your tenant.

Our security posture, sub-processors and corporate details
06How does an engagement start, and how do you price it?

It starts with a fixed-fee review: we map the regulations that apply, trace where the data that evidences them actually comes from, and hand you a costed, sequenced plan that includes the workflows we would advise you not to touch. No build is priced before the hard part is proven on your real data.

07Will you rip out our core system?

No. We build on top of what you already run — your CRM, case system, policy or claims platform — and the hub sits above them rather than replacing them. Where a system has no usable API, that is the boundary where supervised agents take over, rather than a rip-and-replace.

08What if AI isn't the right answer for a workflow?

Then we'll tell you, in writing. Anything scoring below our threshold gets a documented 'do not automate' recommendation. Telling you not to build is a successful review, and it is how you know to trust us when we say something will pay back.

09Who actually builds this, and what's the regulatory pedigree?

A small senior team with backgrounds at Lloyds, HSBC, the Association of British Insurers and UK Parliament. Regulatory and operational experience sits on the team rather than in a sub-contractor, which is the whole reason we can start with the regulatory layer instead of the tooling.

10Where are you based?

We're a UK studio, remote-first across the UK and Europe. Engagements are delivered remotely with no drop in responsiveness. Contact: [email protected].

[ → ] Next step[ NS · 07 ]

Start with the audit,not the build.

A fixed-fee operations review: we map the workflows draining time and control, score each one, and hand you a costed plan that includes the work we'd tell you not to automate. No build is priced before the hard part is proven.

Remote-first · United Kingdom · [email protected]