Know where your firm
actually stands — not where you assume it does
Varde is a self-assessment platform covering the regulatory obligations UK organisations actually face. Answer plain-English questions and get a RAG-rated report in around 10–15 minutes — no account, no sales call, no jargon.
SYSC 10A and UK GDPR are both fully built assessments, live today. DORA is in early access — register your interest below and we'll be in touch.
Pick the area you need checking
Each assessment is scoped to a single regulatory area, so you only spend time on what's relevant to you. SYSC 10A and UK GDPR are both ready today, with a full RAG-rated report and gap report each (SYSC 10A also has a policy builder). DORA is in early access — register your interest below and we'll let you know as soon as you can get started.
Communications Recording
For UK IFA firms, wealth managers, and discretionary fund managers with MiFID II-derived recording obligations. Covers what must be recorded, how long it must be kept, and what happens when a recording doesn't happen.
Operational Resilience
For UK financial services firms with EU exposure under the Digital Operational Resilience Act. Covers ICT risk management, incident reporting, and third-party resilience.
Thanks — we'll notify you when DORA is ready.
UK GDPR — pricing tiers
Same assessment, same coverage — priced for your organisation. Eligibility for Community/Club & Charity pricing is confirmed by a short declaration once you sign up, so start with whichever fits.
Data Protection
For any UK organisation processing personal data — not sector-specific, unlike SYSC 10A or DORA. Covers lawful basis, data subject rights, ROPA, DPIAs, and breach notification.
Data Protection — Community
For microbusinesses and small not-for-profits not currently regulated by the FCA — the same UK GDPR assessment and gap report as our standard tier.
Data Protection — Club / Charity
For unincorporated clubs, societies, and charities not currently regulated by the FCA — the same UK GDPR assessment and gap report as our standard tier, in one straightforward purchase.
From question to report, in order
Answer in plain English
A guided conversation asks about your firm's actual practices — no regulatory text to decode first.
Get a RAG-rated report
Each category is scored red, amber, or green, with a downloadable PDF you can keep on file or share internally.
Act on what it finds
Amber and red findings come with a plain explanation of the gap — and, where available, a path to close it.
Not an enterprise GRC platform
Varde is sized for organisations that need a real answer, not a procurement process.
Before you start
Yes. Every assessment is free to complete, and you get the RAG-rated report and PDF without creating an account or speaking to anyone.
SYSC 10A applies specifically to UK IFA firms, wealth managers, and discretionary fund managers with call-recording obligations. UK GDPR applies far more broadly — to any UK organisation processing personal data, regardless of sector. DORA applies only if your firm has EU-connected clients, operations, or regulated activities. If you're not sure, start with SYSC 10A — it's our most complete assessment today.
SYSC 10A and UK GDPR are both fully live today, each with a complete assessment and gap report (SYSC 10A also has a policy builder). DORA is in early access — register your interest on the card above and we'll let you know as soon as you can get started.
If you don't provide an email, nothing is linked to you. If you do, your personal details are encrypted and can be erased on request at any time — the anonymised compliance record itself may be kept for the retention period the relevant regulation requires.
Yes — each one is independent. SYSC 10A and UK GDPR are both available now; once DORA opens up to everyone who's registered interest, you'll be able to complete any combination that's relevant to your firm.
Ready to find out where the gaps are?
Pick an assessment above, or jump straight into one below.