Financial Services

FCA, DORA and PCI-DSS compliance.
Evidence on demand.

ZAP was built for regulated financial services. Self-hosted — your infrastructure data, compliance findings and evidence packs never leave your environment. FCA PS21/3, DORA and PCI-DSS monitored continuously.

FCA PS21/3 DORA PCI-DSS v4.0 CIS Azure 2.0 CIS AWS 2.0 ISO 27001
Book a session 30 minutes · No commitment
Seconds
FCA evidence generated
vs 3–4 weeks manually
Minutes
DORA drift detected
vs days at next audit
Zero
Data egress
FCA PS21/3 data residency satisfied
Day 1
Compliant foundation
vs 6–12 months SI-led
FCA PS21/3

Cloud outsourcing compliance.
Evidenced continuously.

FCA PS21/3 requires regulated firms to maintain oversight and control of material cloud outsourcing arrangements. ZAP provides the continuous monitoring, documentation and evidence that FCA examiners require.

Data residency — ZAP self-hosted, your data never leaves your regulated environment
Access controls — RBAC enforced, every action logged with approver identity
Operational resilience — backup monitoring, DR replication compliance evidenced
Exit planning documentation — IaC-based deployment enables recovery to alternative provider
Audit trail — immutable record from deployment approval through every change
Evidence pack — FCA PS21/3 section on demand in seconds
What FCA examiners ask for

ZAP generates all of this

Evidence of material outsourcing register
Access control logs for cloud environments
Operational resilience testing records
Exit strategy and portability documentation
Incident reporting records
Business continuity and DR evidence
ZAP evidence pack includes all FCA PS21/3 required documentation — generated from live estate data in seconds. Every item timestamped, tamper-evident and available on demand.
DORA

DORA ICT resilience.
Monitored continuously.

DORA entered into force in January 2025. ICT risk management, incident reporting, DR testing and third-party risk are monitored by ZAP continuously — not just at each annual assessment.

ICT risk management — all cloud assets catalogued, vulnerabilities surfaced
Incident reporting — HIGH findings auto-raised in ITSM with full context
Operational resilience — backup monitoring, DR replication compliance
Third-party AI risk — shadow AI detection surfaces unapproved AI vendors
DR evidence — replication compliance verified, evidence generated
DORA evidence pack on demand — seconds, not weeks
Art. 5–10
ICT risk management
Full asset inventory. Continuous vulnerability monitoring. Drift detected within minutes.
Art. 17–23
ICT incident reporting
HIGH findings auto-raise ITSM incidents with RCA context. ICT incident register maintained automatically.
Art. 24–27
Digital operational resilience testing
ZAP Compliant Scan validates post-DR replication. Evidence generated automatically.
Art. 28–44
ICT third-party risk
Shadow AI detection identifies unapproved third-party AI. Vendor documentation required for whitelist approval.
Art. 45
Information sharing
Audit trail exports. Evidence packs support supervisory information sharing requirements.
Data sovereignty

Your financial data never
leaves your regulated environment.

FCA PS21/3 and DORA both contain data residency and governance requirements. ZAP satisfies them structurally — not through contractual assurances.

Self-hosted by design

ZAP runs inside your Azure, AWS or GCP subscription. Every scan result, finding, evidence pack and audit trail lives in your environment. Zentej has zero access — not limited access, not audited access. Zero.

No telemetry, no callbacks

ZAP does not send telemetry, usage data or infrastructure data to Zentej. There are no data sharing agreements, no product analytics integrations and no third-party data processors for your ZAP instance.

Air-gapped deployment supported

For financial services environments with strict network isolation requirements, ZAP supports fully air-gapped deployment with no internet connectivity requirements.

FCA and DORA data residency

ZAP deployment in a UK or EU Azure region satisfies FCA PS21/3 data residency requirements and DORA ICT data governance requirements. Evidence pack generation confirms data remains in your tenancy.

Shadow AI in financial services

AI in your trading environment.
Detected before it becomes a regulatory finding.

FinTech and data engineering teams deploy AI workloads faster than compliance teams can track them. ZAP surfaces every unapproved AI container — before the FCA or DORA examiner does.

AI trading models or analytics tools deployed without material outsourcing documentation
AI models processing customer data without GDPR Article 30 records
Shadow LLMs connected to customer data stores without DPIA
AI fraud detection or credit scoring models without model risk management documentation
Unapproved AI tools processing PCI-DSS cardholder data
ZAP detects all of the above. AKS, EKS and GKE clusters scanned every cycle. HIGH ITSM auto-raised. ZAP AI generates Remove · Quarantine · Whitelist options. Full audit trail built.
Customer outcomes

What financial services firms
achieve with ZAP.

Microsoft Azure
UK FinTech · FCA regulated
Day 1

FCA PS21/3-compliant Azure foundation live on day one. DORA evidence ready before first workload deployed. Shadow AI in analytics cluster detected and contained before regulatory examination.

Amazon AWS
Investment Management · PCI-DSS
6 weeks

PCI-DSS v4.0 continuous compliance in 6 weeks. 3 weeks of compliance team time per quarter recovered. Evidence pack on demand — not assembled manually.

Azure + AWS
Multi-cloud · DORA
One pack

DORA, FCA PS21/3 and PCI-DSS evidence from one ZAP instance spanning two cloud providers. ITSM auto-raised on all ICT incidents. DR compliance evidenced on replication.

Frequently asked questions

Financial services questions answered.

Yes. ZAP generates a complete FCA PS21/3 evidence pack from live estate data — cloud outsourcing arrangements, access controls, operational resilience, exit planning documentation and audit trail. Generated in seconds on demand.
ZAP monitors DORA ICT risk management controls continuously. Drift detected within minutes. Evidence packs generated automatically. ICT incident reporting documentation built in. DR replication compliance evidenced post-replication.
No. ZAP is self-hosted — it runs entirely within your Azure, AWS or GCP subscription. Your infrastructure data, compliance findings and financial records never leave your regulated environment. This directly satisfies FCA PS21/3 data residency and DORA ICT data governance requirements.
ZAP IPAM eliminates IP address conflicts across cloud accounts — a critical operational resilience requirement. IP conflicts cause network outages that must be disclosed to regulators. ZAP IPAM prevents them at source.
Yes. ZAP integrates natively with ServiceNow — the most common ITSM platform in financial services. Incidents auto-raised, change requests created, CMDB updated and tickets auto-closed with full audit trail.
ZAP continuously monitors PCI-DSS v4.0 controls across your cardholder data environment. Network segmentation, access controls, logging and encryption requirements monitored and evidenced continuously.
Yes. A single ZAP instance governs Azure, AWS and GCP simultaneously — one compliance score, one evidence pack, one audit trail. Critical for financial services firms running workloads across multiple cloud providers.
Yes. ZAP scans all AKS, EKS and GKE clusters for unapproved AI containers. HIGH severity ITSM auto-raised on detection. Particularly relevant for FinTech firms where AI workloads proliferate quickly across data science and engineering teams.
ZAP provides continuous ICT health monitoring, backup job status, patch compliance and DR replication compliance. All DORA ICT continuity evidence generated automatically. DR sites arrive compliant when built with ZAP.
Yes. Zentej is a Crown Commercial Service supplier — relevant for financial services firms procuring through Government frameworks or with public sector relationships.
Free · 30 minutes · No commitment

See FCA and DORA evidence
generation live.

30 minutes. We generate a compliance evidence pack from a live estate — FCA PS21/3, DORA, PCI-DSS. Seconds.

Book a session
No commitment· 30 minutes· [email protected]