ChallengeA Melbourne regtech startup (founded by two former compliance executives from a Big 4 bank) had identified a market opportunity: mid-tier Australian financial services companies (financial advisers, mortgage brokers, wealth managers, small insurers — businesses with 50-500 employees) were struggling with compliance management. These companies faced obligations from multiple regulators: ASIC (Australian Financial Services Licence conditions, financial adviser registration, breach reporting, design and distribution obligations), AUSTRAC (AML/CTF program, customer due diligence, suspicious matter reporting), OAIC (Privacy Act compliance, data breach notification), and APRA (for those with banking or insurance authorisations — prudential requirements). Mid-tier firms managed compliance using: spreadsheets (obligation registers in Excel, due dates tracked manually, evidence stored in email folders), general-purpose tools (Trello boards for compliance tasks, SharePoint for document storage, Outlook calendar for due dates — none designed for regulatory compliance), and external consultants (engaged periodically to conduct compliance reviews — expensive, episodic, and providing a point-in-time assessment rather than continuous compliance management). The result: compliance work consumed 15-25% of senior management time. Regulatory changes were missed or implemented late. Breach reporting was reactive rather than proactive. And when ASIC conducted surveillance visits, firms scrambled to compile evidence from disparate systems. The startup had pre-seed funding of A$350,000, customer validation from 40+ interviews, and commitment from 5 firms to pay for a beta product. They needed a production SaaS platform — not a prototype, but a product that compliance professionals would trust with their regulatory obligations.
SolutionWe built the compliance management SaaS in 16 weeks, structured in four phases. Phase 1 (weeks 1-4): obligation management engine. The core feature: a regulatory obligation register that tracks every obligation for each customer. Obligation library: we built a curated library of 2,400+ regulatory obligations across ASIC, AUSTRAC, OAIC, and APRA — each obligation with: the source regulation (act, section, subsection), the obligation description (what the firm must do), the frequency (ongoing, annual, quarterly, monthly, event-triggered), the evidence requirements (what documentation demonstrates compliance), the consequence of non-compliance (penalties, licence conditions, enforcement action), and the obligation owner role (compliance officer, CEO, responsible manager, board). Obligation mapping: when a new customer onboards, the system maps applicable obligations based on: their AFSL authorisation conditions (what financial services they are authorised to provide), their AUSTRAC registration (what designated services they provide), their business activities (advice, dealing, arranging, claims handling — each triggering different obligations), and their customer types (retail, wholesale, sophisticated — different obligations apply). The system produces a tailored obligation register — typically 200-600 obligations for a mid-tier financial services firm — with due dates, owner assignments, and evidence requirements. Regulatory change tracking: the system monitors regulatory sources (ASIC regulatory guides, AUSTRAC guidance, OAIC determinations, new legislation) and flags changes that affect the customer's obligation register — "ASIC has updated RG 271 (Internal Dispute Resolution). This affects your IDR obligations. Review required by [date]." Phase 2 (weeks 3-8): compliance workflow and evidence management. Task management: each obligation generates compliance tasks — recurring tasks (annual compliance plan review, quarterly breach register review, monthly AML transaction monitoring) and event-triggered tasks (new staff onboarding requires FSR training record, client complaint triggers IDR process). Tasks are assigned to responsible individuals with: due dates, priority, dependency tracking, escalation rules (overdue tasks escalate to the compliance officer, then to the CEO), and evidence attachment (documents, screenshots, sign-offs that demonstrate the task was completed). Evidence repository: a structured document management system where compliance evidence is stored, categorised by obligation, and timestamped. When ASIC conducts a surveillance visit or requests evidence, the firm can produce a complete compliance evidence package for any obligation — document, date completed, who completed it, approval chain. Workflow templates: pre-built workflows for common compliance processes — breach reporting (detection, assessment, notification to ASIC if significant, remediation, root cause analysis), complaints handling (IDR process aligned with RG 271 — acknowledgement within 24 hours, investigation, determination, communication, internal dispute resolution timeframes), AML/CTF customer due diligence (identification, verification, ongoing monitoring, enhanced due diligence for high-risk customers), and annual compliance plan (the structured annual compliance review that ASIC expects licensed firms to conduct). Phase 3 (weeks 6-12): reporting, dashboards, and board reporting. Compliance dashboard: real-time view of compliance status — obligations by status (compliant, due soon, overdue, not assessed), tasks by status (completed, in progress, overdue, upcoming), risk heat map (which regulatory areas have the most overdue or incomplete obligations), and trend analysis (compliance posture improving or deteriorating over time). Board reporting: automated generation of quarterly compliance reports for the board — regulatory obligation summary, breach register summary, key compliance risks, upcoming regulatory changes, and compliance team activity summary. Australian boards have specific governance obligations for compliance oversight — these reports satisfy ASIC's expectations for board-level compliance reporting. ASIC surveillance preparation: a "surveillance pack" generator that compiles all evidence for a selected set of obligations — producing a structured, indexed package that can be provided to ASIC when they conduct a surveillance visit. Firms that previously spent 2-4 weeks preparing for ASIC surveillance could produce the pack in hours. Phase 4 (weeks 10-16): multi-tenancy, billing, and launch. Multi-tenancy: shared database with RLS — appropriate for the target market (mid-tier financial services, not APRA-regulated banks). Each customer's data is isolated at the database level. Australian billing: Stripe Australia integration with: AUD pricing (three tiers — A$499/month for up to 10 users, A$999/month for up to 50 users, A$1,999/month for enterprise with unlimited users), annual contracts with monthly BECS direct debit billing, GST-inclusive pricing with compliant tax invoices, and Xero integration for automatic accounting synchronisation. Security: ISO 27001-aligned controls (full certification planned for 6 months post-launch), ACSC Essential Eight Maturity Level 2, MFA mandatory for all users, SOC 2 Type I (with Type II planned for 12 months post-launch), and penetration testing by an Australian CREST-certified firm. Onboarding: self-service onboarding for the A$499 tier (guided setup wizard mapping obligations based on AFSL conditions), assisted onboarding for A$999+ tiers (compliance consultant reviews the obligation mapping and customises workflows).
OutcomeThe SaaS platform launched on schedule and immediately onboarded the 5 committed beta customers. Beta results (3 months, 5 customers): all 5 customers completed obligation mapping — average 380 obligations per firm (range 210-580). Compliance task completion rate: 94% on-time (compared to self-reported 60-70% with previous manual tracking). Time spent on compliance administration: reduced by an estimated 40% — the system automated task scheduling, evidence management, and reporting that previously consumed hours of spreadsheet work weekly. One customer underwent an ASIC surveillance visit during the beta period — they produced the surveillance evidence pack in 2 hours using the system (previously estimated 3 weeks of preparation). ASIC noted the quality and organisation of the evidence positively. Post-launch growth (12 months): the platform grew to 48 paying customers (A$620,000 ARR) within 12 months. Customer acquisition was driven by: compliance consultant referrals (consultants who had previously spent their time helping clients maintain spreadsheets now recommended the SaaS and focused on higher-value advisory work), word of mouth within the financial services compliance community (Melbourne's compliance professional network is tightly connected), and ASIC surveillance events (firms that had poor surveillance experiences sought better compliance management tools — each ASIC surveillance cycle generated a wave of inbound enquiries). Seed round: the startup raised A$3.2 million in seed funding from an institutional VC at 12 months post-launch — with 48 paying customers, A$620,000 ARR, 95% gross retention, and 112% net revenue retention (existing customers upgrading tiers as they added users and modules). The investors cited: proven product-market fit with paying Australian customers, strong retention metrics indicating genuine value delivery, a clear expansion pathway (additional modules: incident management, policy management, training management), and regulatory tailwinds (increasing ASIC enforcement activity driving compliance technology adoption). Platform cost: A$385,000 development. Monthly infrastructure cost: A$2,800 (AWS ap-southeast-2). Monthly LLM cost for regulatory change analysis: A$400. ROI for the startup: the A$385,000 investment produced a platform generating A$620,000 ARR within 12 months and attracting A$3.2 million in seed funding.