Governance beforeautomation,every time.
Their problem isn't the technology.It's trust.
Buying an AI licence is easy. Being able to say who is accountable for what it decides, which rules apply, and what you would show a regulator who asked, is the part nobody has solved. So that is where we start.
Real operations,measured results.
Built for regulated,operationally complex industries.
One pattern. Six rulebooks. Only the rulebook changes.
Financial Services
Consumer Duty · SM&CR · operational resilience
Document-heavy workflows across lending, deal flow and compliance reporting.
Insurance
Consumer Duty · SM&CR · ICOBS
Claims, underwriting and portal work, without the re-keying.
Energy & Utilities
Ofgem guidance · SECR · ESOS
Licence-condition reporting and regulator-format returns, produced from your own systems.
Construction
Building Safety Act · UK SRS
Golden-thread evidence, bid management and estimating, with leadership oversight of timelines and compliance.
Legal & Insolvency
SRA guidance · confidentiality duties
Intake, document processing and case analysis on the practice-management systems you already run.
Public Sector
Non-waivable accountability
Board packs, closed legacy systems and decisions that have to be defensible after the fact.
The map comes first.Everything else is built on it.
Mapping is what you're buying — not a hub, not a licence: the regulations, policies, controls and systems specific to your operation, brought into one model you own. It shows you what applies, where the evidence lives, and exactly what a rule change would touch, before we build anything.
Map
Regulations, policies, controls, processes, evidence and owners — one model, built from your systems. This is the deliverable, not a preview of one.
Score
Every gap and obligation scored for impact, so what matters first is obvious — and what doesn't pay back gets said in writing.
Build
The governed pipeline, built only once the map and the score have proven it's worth it.
Watching UK SRS · FCA · ICO · Ofgem · EU AI Act
Every obligation joined to the data that evidences it
Full audit trail · human sign-off
Regulation is usually where it starts.
The same approach extends to policies, controls and risk — mapped first, every time, and built only once it's proven.
A rule lands. You already know what it costs you.
| Obligation | Your control | Owner | Status |
|---|---|---|---|
| Automated decision review | Human review gate | Head of Compliance | Gap |
| Customer notification | Comms template | Ops Director | Evidence missing |
| Model documentation | Decision log | CTO | In place |
| Senior accountability | Named SMF | CEO | In place |

“North Stack's understanding of regulation, and how systems can be built with this in mind, is exceptional. I felt in safe hands throughout.”
The questions that actually matter.
The things a COO, operations director or compliance lead needs answered before they'd let us near the operation.
01What does North Stack actually do, in one sentence?
We take the regulated, document-heavy work your systems can't touch — inbound claims, case files, compliance reporting — and turn it into a governed AI pipeline: extraction, a human review queue for anything uncertain, and a full audit trail into the systems you already run. For ongoing regulatory and governance work, we build that same model bespoke to your setup — mapped to your regulations, your systems, your controls.
02How do you approach regulatory and governance work?
We map the regulations, policies, controls and systems specific to your operation into one model — covering what applies, where the evidence lives, and who owns each obligation. Every regulatory update is read against that model, so you see the gap, the impact and who needs to act. It's built to your setup, not sold as a template.
03How is that different from a GRC platform?
A GRC platform gives you a register you update by hand, built for any sector so it fits none of them precisely, and you own a licence. We build the model around your actual regulations, systems and controls, and it reads change continuously — not a template, and not something you're left to configure yourself.
04Most of our people already use ChatGPT. Isn't that the same thing?
It isn't, and the gap is the interesting part. Buying a licence is easy; being able to say who is accountable for how it gets used is not. Before automating anything we help you answer that: which rules apply, where the data behind them lives, and who owns the answer when a regulator, a client or a court asks.
05How do you make sure this is safe in a regulated environment?
Human sign-off on every disclosure, field-level confidence scores, role-based access, a complete exportable audit trail from source to statement, permanent red lines (no automated payments or bank-detail changes), and a hard human gate before any regulator submission. Your data stays in your tenant.
Our security posture, sub-processors and corporate details06How does an engagement start, and how do you price it?
It starts with a fixed-fee review: we map the regulations that apply, trace where the data that evidences them actually comes from, and hand you a costed, sequenced plan that includes the workflows we would advise you not to touch. No build is priced before the hard part is proven on your real data.
07Will you rip out our core system?
No. We build on top of what you already run — your CRM, case system, policy or claims platform — and the hub sits above them rather than replacing them. Where a system has no usable API, that is the boundary where supervised agents take over, rather than a rip-and-replace.
08What if AI isn't the right answer for a workflow?
Then we'll tell you, in writing. Anything scoring below our threshold gets a documented 'do not automate' recommendation. Telling you not to build is a successful review, and it is how you know to trust us when we say something will pay back.
09Who actually builds this, and what's the regulatory pedigree?
A small senior team with backgrounds at Lloyds, HSBC, the Association of British Insurers and UK Parliament. Regulatory and operational experience sits on the team rather than in a sub-contractor, which is the whole reason we can start with the regulatory layer instead of the tooling.
10Where are you based?
We're a UK studio, remote-first across the UK and Europe. Engagements are delivered remotely with no drop in responsiveness. Contact: [email protected].
Latest insights
On AI adoption, regulation and what actually works in regulated operations.
Start with the audit,not the build.
A fixed-fee operations review: we map the workflows draining time and control, score each one, and hand you a costed plan that includes the work we'd tell you not to automate. No build is priced before the hard part is proven.
Remote-first · United Kingdom · [email protected]









