Every firm on your financial services shortlist says yes to compliance: the mapping test that separates them

Judge a custom application development firm against what the rules require of the application, not against how the firm describes itself. For a financial institution the Safeguards Rule already names the controls a custom application has to carry: secure development practices for in-house developed applications, encryption of customer information in transit and at rest, multi-factor authentication, procedures for change management, and logging that detects unauthorized access. Broker-dealers add a recordkeeping requirement most development shops have never read, which is that an electronic recordkeeping system must maintain a complete time-stamped audit trail of every modification and deletion, or preserve the records in a non-rewriteable, non-erasable format. A firm that cannot map its own delivery process onto those clauses is not a compliant-solutions firm no matter what its capabilities page says. Ask for the mapping first and the portfolio second.

The regulation, not the vendor, sets the specification

Most shortlists start from portfolio screenshots. That gets the order wrong, because for a financial institution the specification is already written down and it is enforceable. The FTC Safeguards Rule, which implements the Gramm-Leach-Bliley Act for non-bank financial institutions, requires you to “Adopt secure development practices for in-house developed applications utilized by you for transmitting, accessing, or storing customer information” (16 CFR 314.4(c)(4), govinfo.gov). The same section requires “procedures for evaluating, assessing, or testing the security of externally developed applications you utilize to transmit, access, or store customer information.”

Read those two clauses together and the buying question changes shape. Whatever a vendor builds for you becomes your in-house developed application the moment it lands in your estate, and whatever the vendor pulls in from elsewhere becomes an externally developed application you now owe an evaluation procedure for. The compliance obligation does not transfer with the invoice.

Four more clauses in the same rule land directly on application design. Access controls must “Authenticate and permit access only to authorized users” and “Limit authorized users’ access only to customer information that they need to perform their duties and functions.” Customer information must be protected “by encryption … both in transit over external networks and at rest.” Multi-factor authentication is required “for any individual accessing any information system, unless your Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.” And the rule asks for “policies, procedures, and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by such users.” Paragraph (c)(7) adds a one-line requirement that quietly governs everything a development partner does after go-live: “Adopt procedures for change management.”

Registered firms carry a parallel obligation under the SEC. Every broker, dealer, investment company, and Commission-registered investment adviser “must adopt written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer records and information” (17 CFR 248.30(a), govinfo.gov). Written is the operative word. A control that exists in the code and nowhere in a document is not evidence when an examiner asks.

The recordkeeping clause that reshapes the data model

Broker-dealers hit a requirement that decides architecture rather than configuration. An electronic recordkeeping system must “Preserve a record for the duration of its applicable retention period in a manner that maintains a complete time-stamped audit trail,” and that trail has to capture “All modifications to and deletions of the record or any part thereof,” the date and time of every create, modify, or delete action, and “If applicable, the identity of the individual creating, modifying, or deleting the record” (17 CFR 240.17a-4(f)(2)(i)(A), govinfo.gov). The alternative the rule permits is starker: “Preserve the records exclusively in a non-rewriteable, non-erasable format.”

Either branch is an early design decision, not a late one. A system must also “Verify automatically the completeness and accuracy of the processes for storing and retaining records electronically” and be able to “readily download and transfer copies of a record and its audit trail (if applicable) in both a human readable format and in a reasonably usable electronic format.” Export in a human readable format is the clause that catches teams late, because an audit trail living only inside a platform’s internal tables satisfies nobody at examination time.

Bring this up in the first technical conversation. A firm that treats append-only history, retention windows, and examiner-ready export as a phase-two backlog item is telling you it will rebuild your data model later at your expense.

Choosing the firm is itself a regulated act

Vendor selection is not adjacent to your compliance program. It is inside it. The Safeguards Rule requires you to oversee service providers by “Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue,” by “Requiring your service providers by contract to implement and maintain such safeguards,” and by “Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.”

Three practical consequences follow. Your selection process has to produce a written record of why you judged the firm capable, so a shortlist assembled on reputation alone leaves a gap in your own file. The contract has to carry the safeguards obligations forward, which means the firm’s willingness to accept those clauses is a selection criterion and not a legal afterthought. And because assessment is periodic, a firm that disappears after go-live leaves you holding an obligation you cannot discharge.

Six questions that separate the shortlist

  1. Map your delivery process to the clauses. Ask the firm to show, for a prior regulated build, where encryption at rest, least-privilege access, multi-factor authentication, change management, and user-activity logging were decided and who approved each one. A firm that answers with product names rather than decisions has not done this work.
  2. Ask who writes the evidence. Controls in code do not satisfy an examiner. Someone has to produce access control documentation and the audit trail record. Establish whether that is the firm’s deliverable or an unowned assumption.
  3. Test the recordkeeping answer specifically. If you are a broker-dealer, ask which branch of 17 CFR 240.17a-4(f)(2)(i) the design will use and what the export path looks like. Vagueness here is expensive later.
  4. Check what happens on day 400. Change management and periodic service-provider assessment are recurring obligations. A firm structured only to build and hand off cannot support either.
  5. Separate compliance literacy from certification claims. A development firm holding its own certificate tells you about the firm’s internal operations. What you actually need is a team that can build to your regime and produce your evidence. Those are different things, and vendors blur them constantly.
  6. Ask what the firm will not claim. The fastest disqualifier in this category is a vendor that answers every compliance question yes. Regulated delivery is full of boundaries, and a partner who names them is easier to plan around than one who does not.

What i3solutions brings to regulated financial services work

i3solutions builds custom applications on Microsoft platforms for organizations where a technology decision carries operational and regulatory consequence, and the compliance apparatus around the build is the part worth examining. Our teams maintain dedicated compliance specialists who understand CMMC, HIPAA, SOC 2, and financial services regulations within Microsoft environments, providing audit trail documentation and access control frameworks that reduce audit preparation time by 60%. That documentation is the deliverable question raised above, answered: the artifacts an examiner asks for are produced as part of delivery rather than reconstructed under time pressure afterwards.

Financial services work in this portfolio runs across integration and modernization rather than a single product line. i3solutions has delivered Dynamics 365 integration engagements for regulated enterprises across healthcare, defense and aerospace manufacturing, and financial services. The pattern that shows up most often in this sector is narrower and more familiar: a business process that grew up inside spreadsheets, became load-bearing, and now has to move into a governed application with real access control and a real history. i3solutions has delivered this transition for IT teams in aerospace, defense, and financial services.

Financial services outcomes anchor to SOC 2 trust services criteria closure and decision-velocity improvement for client reporting; time-recovered ranges 10 to 18 hours per week per analyst; error reduction 75 to 90 percent. The outcomes from enterprise Excel modernization set out how those numbers arise, and the same governance-first sequencing applied to collaboration estates is covered in governance-first SharePoint modernization.

Cost of neglect belongs in the same conversation. Financial services firms report average compliance remediation costs of $150K to $300K annually for SharePoint environments that were never properly governed. Governance is not a phase that gets added to an estate afterwards; it is a set of decisions taken at the start. The access model, the retention rule and the audit trail get settled in week one, written down, and carried through the build, instead of being reconstructed in year two when somebody asks for the evidence.

For adjacent regulated delivery, our approach to federally scoped Power Platform work is set out under Power Apps federal compliance consultants, the arithmetic of a compliance program is worked through in CMMC compliance cost, and the platform-selection trade-offs that precede a build are compared in Dynamics 365 versus SAP. The full service is described on the custom application development services hub.

Where the obligation stays with you

Applying the sixth question to ourselves. Two boundaries are worth stating plainly, because a partner who names them is easier to plan around than one who answers every compliance question yes.

The first boundary is legal. 16 CFR 314.4 (16 CFR 314.4, govinfo.gov) and 17 CFR 240.17a-4 (17 CFR 240.17a-4, govinfo.gov) bind the financial institution, not its developer. A build partner can design the controls, produce the artifacts, and accept the contract clauses, and the obligation still sits with you at examination. That is why the mapping conversation matters more than any assurance a vendor offers about itself. What you are buying is the ability to satisfy your own rule, in your own environment, with your own evidence.

The second boundary is operational, and it describes how the work is actually done. i3solutions delivers workflow automation and development inside customers’ SOC 2-audited environments, operating under the customer’s own controls, and knows how to operate in those regulated environments. The audited perimeter stays yours, and so does the control set the work is delivered under, which keeps the evidence in the place your examiner already looks.

One more boundary, on the numbers above. The remediation range is an observation about what firms carry when SharePoint estates go ungoverned. It is not an i3solutions price, not a saving we promise, and not a figure to plan a budget around.

Frequently asked questions about custom app development for financial services

What should a financial services firm require from a custom application development vendor?

Require a mapping from the vendor’s delivery process to the specific control clauses that bind you. Under the FTC Safeguards Rule that means secure development practices for in-house developed applications, encryption of customer information in transit and at rest, multi-factor authentication, access controls limited to what a user needs to perform their duties, logging that detects unauthorized access or tampering, and procedures for change management. Require in writing who produces the documentation an examiner will ask for, because a control implemented in code and recorded nowhere is not evidence.

How does i3solutions work inside a regulated client environment?

i3solutions delivers workflow automation and development inside customers’ SOC 2-audited environments, operating under the customer’s own controls, and knows how to operate in those regulated environments. The audited perimeter stays the customer’s, and so does the control set the work is delivered under. Our teams maintain dedicated compliance specialists who understand CMMC, HIPAA, SOC 2, and financial services regulations within Microsoft environments, providing audit trail documentation and access control frameworks that reduce audit preparation time by 60%.

What audit trail does a financial services application need to keep?

For a broker-dealer, an electronic recordkeeping system must preserve a record for its retention period in a manner that maintains a complete time-stamped audit trail covering all modifications to and deletions of the record, the date and time of each action, and where applicable the identity of the person who created, modified, or deleted it. The permitted alternative is to preserve the records exclusively in a non-rewriteable, non-erasable format. The system must also be able to download and transfer a record and its audit trail in both a human readable format and a reasonably usable electronic format, which is why examiner-ready export belongs in the original design rather than a later phase.

How does choosing a development firm affect our own regulatory compliance?

Directly, because service-provider oversight is part of the program. You are required to take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to assess the provider periodically against the risk it presents. That makes three things selection criteria rather than paperwork: whether your evaluation produced a written basis for judging the firm capable, whether the firm will accept the safeguards clauses in contract, and whether it will still be available for the periodic assessment long after go-live.

What financial services delivery experience can i3solutions show?

i3solutions has delivered Dynamics 365 integration engagements for regulated enterprises across healthcare, defense and aerospace manufacturing, and financial services. On the modernization side, where a spreadsheet-grown process has to become a governed application with real access control and real history, i3solutions has delivered this transition for IT teams in aerospace, defense, and financial services. Financial services outcomes anchor to SOC 2 trust services criteria closure and decision-velocity improvement for client reporting; time-recovered ranges 10 to 18 hours per week per analyst; error reduction 75 to 90 percent.

Bring us the regime and the system, and we will show you the mapping

Tell us which rules bind you, what the application has to do, and what your examiners have asked for in the past. We will walk the control clauses with you and say plainly which parts we would own, which parts stay with your compliance function, and where the design decisions have to be made before a line of code is written. If it has to be built, we build it.

If you are the person who has to write the internal case, that mapping is what you take back to your committee before anything is signed. The Safeguards Rule already expects a written basis for judging a firm capable, so the same conversation that answers your technical question also produces the record your own file needs.

Start the conversation