South West wealth SECTOR

IT and AI leadership for South West wealth, IFA and SIPP firms.

A tenant full of other people's money. An insurer and a regulator who know it.

Advice firms, SIPP operators and wealth managers around Bristol and the wider South West. The FD has become the IT department, the cyber form has landed, and the FCA has put a date on incident and third-party reporting.

A named Head of IT and AI, one or two days a week. You keep the MSP. We sit above it.

Six services, published prices · fixed fees, and a monthly seat
MARCH 2026 FINAL RULES 18 MARCH 2027 IN FORCE THE PREPARATION YEAR THE REGISTER IS IT WORK WITH A DEADLINE

2026 IS THE YEAR THE FCA GAVE FIRMS TO PREPARE

01

Who this is for

Advice firms, operators, buyers
The firm

IFA networks and independents. SIPP and SSAS operators. Discretionary and advisory wealth firms. Usually 50-200 people, or a smaller firm whose client book already carries a 200-person risk.

Bristol first, then Bath, Exeter and the wider South West. A London wealth firm with a South West book is welcome too. And the firms doing the buying: consolidators and PE-backed platforms landing estate after estate, deal by deal.

If yours is a law firm, the sharper page is law firm IT security. The broader page for firms of 50-200 people is professional services IT.

The signs
  • The FD is carrying IT on top of the day job.
  • The next cyber form has landed, and the premium listens to the answers.
  • Copilot is waiting on a tenant that still shares a drive called "Clients".
  • The FCA put a date on incident and third-party reporting.
02

The FCA clock

In force 18 March 2027
The 2027 deadline

FCA incident and third-party reporting rules: final rules March 2026, in force 18 March 2027.

The standard tier of the new rules reaches most FCA-authorised firms, advice firms included. Qualifying operational incidents are reported through the FCA's Connect portal, and a register of material third-party arrangements is kept and stays current.

Your MSP contract, your platform, your back-office system: that register is IT work with a regulatory deadline, and 2026 is the preparation year the FCA gave firms. It is a bounded, board-readable project, and it belongs to whoever owns IT. If nobody does, that is the seat on this page.

The insurer
  • MFA, patching, backups, access control: the questions on this year's form.
  • The premium listens to the answers, and to the evidence behind them.
  • CE+ from £2,950 answers most forms; ISO 27001 from £15,000 sits at the top end.
  • The CE+ / ISO 27001 sprint builds the pack. We implement; an accredited assessor certifies.
03

The buyers

Consolidators and platforms
Consolidators

Every deal lands an estate somebody has to integrate.

Consolidators and PE-backed platforms are buying advice books at pace, and each completion hands the platform another tenant, another MSP contract, another back-office system. Integration is where the record sits: 250+ servers moved to Azure, and ISO 27001 and PCI DSS implemented in 12 months alongside.

If the platform needs a named senior inside an acquired firm, that is the Head of IT seat. If the acquired estate needs folding in on a deadline, the work is scoped to that deadline.

04

The AI angle

Saying yes, safely
AI, with the controls real

A wealth firm can say yes to AI once the tenant and the controls are real.

The blockers are real: client data in open shares, permissions nobody has reviewed, a regulator who will ask how the firm governs the tools it adopts. None of them is an argument for waiting. Each is a piece of work with a name on it.

The AI Opportunity Audit finds where AI pays in an advice business and what must be true first. Microsoft Copilot readiness closes oversharing before a 30-day pilot touches client files. And ISO 42001 readiness, part of the CE+ / ISO 27001 sprint from £6,500, gives the board a governance frame it can point to when the FCA, an insurer or a platform asks how AI is run.

05

Routes in

Six services, published prices
Pick the door

All six services, and the framework they belong to, are on one page.

06

How it runs

Diagnose. Deliver. Decide.
01

Diagnose

We sit with the FD, the compliance lead and whoever holds the MSP contract. The insurer form, the register and the tenant come first.

02

Deliver

The board has an operating model, the insurer has evidence, and the register has an owner. You stop being the IT department.

03

Decide

Estates drift when nobody owns them. The fix is one or two days a week from someone who already knows your firm. Or keep the gains and run it yourselves: either way the firm is stronger.

07

What you leave with

Documents, owners, decisions
The pack
A named senior

Someone the MD can put in front of the board.

An insurer pack

Documents for the cyber questionnaire, owned.

The register, owned

Third-party arrangements mapped, ahead of the 2027 deadline.

A safe yes to AI

A tenant and controls that let the firm adopt, with evidence.

08

The record

Six facts, on the record
Proof
  • 20+ years as Head of IT.
  • 90% fewer incidents, service levels from 45% to 98%.
  • ISO 27001 and PCI DSS implemented in 12 months.
  • 80% off a live cloud bill, 250+ servers to Azure.
  • The agent answering our phone line (0117 456 5486) is ours, in production.
  • £130k for a full-time IT director. The seat here starts at £4,750 a month.

The detail sits on the proof page.

09

FAQs

Asked before, answered here

Do you understand IFA and SIPP IT security?

Yes. In an IFA or SIPP firm the job is client data, access, the tenant, and the evidence pack the insurer asks for, each with a named owner. We implement the controls. We do not pretend to be your compliance officer or your certification body.

Are you a Bristol IT support company?

No. We do not sell helpdesk or MSP tickets. The number is 0117, and the voice that answers it is our own AI call agent, in production. The offer is a named Head of IT plus the evidence.

Will this help with FCA or insurer questions?

The CE+ / ISO 27001 sprint is built for the insurance cyber questionnaire and for buyers who ask for CE+ or ISO 27001. FCA permissions stay with you and your compliance lead.

What are the FCA incident and third-party reporting rules?

Final rules land in March 2026 and take force on 18 March 2027. Most FCA-authorised firms, advice firms included, will report qualifying operational incidents and keep a register of material third-party arrangements. Building that register is a bounded piece of IT work, and 2026 is the year to do it.

Can a smaller IFA start the conversation?

Yes, when the risk is the client book rather than the headcount. The usual range is 50-200 people, and we say honestly at diagnose whether the fit is real.

Do you replace our outsourced IT?

You keep the MSP if it works. We sit above it, for the decisions, the evidence and the register.

We are a consolidator integrating acquired firms. Is this the right page?

Yes. The integration record is on the proof page. If you want a named senior inside a platform firm, that is the seat.

Can a wealth firm say yes to AI safely?

Yes, once the tenant and the controls are real. The AI Opportunity Audit finds where AI pays and what must be true first. Copilot readiness closes oversharing before a pilot touches client files. ISO 42001 readiness gives the board a governance frame it can point to.

10

Start the conversation

Bring the insurer form
Contact

Start the conversation.

The first conversation costs nothing and changes what happens next. Bring the insurer form, the platform questionnaire, or the register nobody has started.

Proof you can dial

Call 0117 456 5486. The voice that answers is our own AI call agent, in production, on our own line. We run our practice on what we sell. Hear it running.

The call button dials the line above.

Talk to us