DDutyDesk
FeaturesPricingFAQSign inStart free trial
Built for FCA Consumer Duty · UK data residency

Stop wrestling with spreadsheets at 11pm before the board meeting.

DutyDesk is the focused Consumer Duty workspace for 1–15 adviser firms. Vulnerable customer register, fair-value assessments, outcome monitoring, and AI-drafted board reports — with the audit trail an FCA inspector expects.

Start a 14-day trialBook a 20-minute demo

No credit cardUK / EU hostingTenant-isolated at the database

dutydesk.co.uk/dashboard

Good morning, Pippa.

Vulnerable
23
+2 this month
Reviews due
4
2 overdue
Products
7
all approved
Board report
Q2
due 30 Jun
Action requiredView all →
Review overdue: Mr P. Davies (Health · High)Overdue 6d
Annual fair-value: Pension Transfer ServiceDue 14d
Built in Canterbury for small UK advice firmsEngineering pedigree: PIMCO · S&P Global · JPMorgan

The four duties, one workspace

Each FCA obligation, with the audit trail an inspector expects

Each module covers one of the four Consumer Duty outcomes. They share the same audit log, the same sign-off pattern, and the same firm-wide view — no plugin sprawl, no spreadsheets, no Word docs.

Module A

Vulnerable customer register

Reviews chase themselves. PDF on demand.

Record drivers, severity, and adjustments. Six-month review reminders. Soft delete keeps the audit trail intact. Export PDF or CSV the moment an inspector asks.

Module B

Fair-value assessments

The job we built this for

A practice principal who doubles as compliance officer loses two to three full days to every Consumer Duty board report — evenings reconciling spreadsheets, reformatting Word documents, second-guessing what the FCA expects to see.

DutyDesk turns that into about forty-five minutes of review and edit: the register, assessments and metrics are already structured, and the report drafts itself from your firm's real numbers — never invented ones.

Built for a regulated audience

Trust signals are the product, not the marketing

Compliance buyers are risk-averse for a reason. Every line below is enforced in code, not asserted in copy.

eu-west-1

UK / EU data residency

Hosted on Supabase in Ireland. Customer records never leave the perimeter.

100%

Mutations audited

Every create, update, sign-off and delete is in the audit log — automatically.

2

Person sign-off

Drafter ≠ approver enforced at the database. Solo-tier firms get a single-signature record.

Daily

Encrypted backups

Point-in-time recovery up to 7 days. RPO < 24h, RTO < 4h.

Pricing

Built for a small-firm budget

14-day free trial on every plan. No per-customer charges. Cancel any time.

Solo

Single principal · self-employed adviser

£79/month

Billed monthly

  • All four modules
  • Single-signature sign-off
  • 100 fair-value and 50 board-report AI section drafts a month
  • UK email support · 1 working day
  • Two-person sign-off (single user)
Start trial
Most popular

Practice

2–5 advisers + a compliance officer

£199/month

Billed monthly

  • Everything in Solo, plus:
  • Two-person sign-off on assessments & reports
  • Up to 5 user seats
  • Unlimited fair-value and 200 board-report AI section drafts a month
  • Read-only auditor seat included
  • Priority support · 4-hour response
Start trial

Practice+

6–15 advisers · multi-office

£499/month

Billed monthly

  • Everything in Practice, plus:
  • Up to 15 user seats
  • Unlimited AI section drafts
  • SLA-backed support · 1-hour response
  • Dedicated onboarding call
Start trial

Frequently asked

The questions a compliance buyer always asks

Is DutyDesk FCA-approved or endorsed?
No software is "FCA-approved" — that’s not how the FCA works. What DutyDesk does is implement the obligations of PRIN 12 (Consumer Duty) faithfully, with the evidentiary controls (audit trail, sign-off, version history) an FCA supervisor would expect to see when reviewing your firm’s records. The regulator regulates firms, not their tools.
Where is our customer data held?
Your records are stored in the EU, on Supabase’s eu-west-1 (Ireland) region, isolated from every other firm by database-level row security rather than by application code. AI drafting is the one exception, and we handle it by not sending the data at all: your customers’ names and reference numbers are never passed to the AI provider. Drafting works from aggregate counts and your own written text, so a named individual’s vulnerability record never leaves the EU perimeter. Inference itself runs on Anthropic’s US infrastructure, which we set out in full in our privacy policy rather than gloss over.
Can my external auditor view our records without a paid seat?
KM

Khuram Masood, Founder & Engineer

AppstackX Ltd · ex-PIMCO · ex-S&P Global · ex-JPMorgan · Canterbury, UK

I built DutyDesk because every small adviser firm I spoke to was running Consumer Duty out of two spreadsheets and a folder of Word docs. The work is necessary; the tooling is wrong. You shouldn't be reformatting a board report at 11pm.

DutyDesk is a single, opinionated product — not a CRM, not a regtech platform. The four obligations, with the audit trail. If you'd like a 20-minute walkthrough before signing up, send me an email and I'll show you the product personally.

Get your first board report drafted by Friday

Set up takes about 20 minutes. The 14-day trial is the full product, no card needed.

Start a 14-day trialBook a demo with Khuram
DDutyDesk

Consumer Duty compliance, built for small UK financial advice firms.

Product

FeaturesPricingFAQStart a trial

Company

ContactFounder

Legal

PrivacyTermsData processing

Trust

UK / EU hostingPrivacyData processing
DutyDesk is operated by AppstackX Ltd, registered in England & Wales. Made in Canterbury, UK.Built for the UK adviser, not the US
Complaints (per 1000) trending up — Q2
Amber
Outcome trend · ComplaintsRAG · Amber

Six FCA-aligned sections, two-person sign-off.

Cost summary, benefit summary, comparator data, vulnerable impact, governance, conclusion. AI drafts prose from your bullets. Drafter ≠ approver, enforced at the database. Prior versions auto-supersede on approval.

Module C

Outcome monitoring

Ten ready metrics. RAG dots. Trend charts.

A curated library across the four FCA pillars, plus your own. Threshold bands, target lines, RAG dots that respect direction. Log monthly readings — that’s it.

Module D · the killer feature

AI board report

Three days of work in 45 minutes.

Quarterly or annual. Nine sections, each drafted from your real numbers across A/B/C — never invented. Export to PDF or Word with the cover sign-off block already filled. Anti-hallucination contract on every prompt.

Yes — the Practice and Practice+ tiers include a read-only auditor seat, and it sits on top of your adviser seats rather than using one up. Invite them from Settings with the read-only role: they are emailed a single-use link to set their own password, so no password is shared with anyone — not even with you. They then see everything an FCA reviewer would see and can’t change a thing. Settings → Users & roles shows you when each person last signed in, and you can remove the seat the day the audit ends.
What happens to our records if we leave?
Export everything at any time from Settings — a complete JSON archive of every record, or per-table CSV, including the audit log. Take that export before you close the account: closing ends access for everyone at the firm, so the export has to come first. Nothing is deleted on the day you close — we keep your records for 90 days in case you change your mind, and inside that window an email to khuram@appstackx.co.uk will reopen the account or send you a copy of your data. After 90 days it is permanently deleted.
Do we need to migrate from our spreadsheet workflow?
Most firms onboard cold — fresh records from the start of a new quarter. That’s fine for compliance: the obligation is forward-looking. If you need to import historic vulnerable-customer records or product assessments, we’ll do a one-off migration call and import from your CSV.
What if the AI gets something wrong in our board report?
Every AI-drafted section is editable, marked "AI-drafted · review before submitting", and rolled into the two-person sign-off — your compliance officer reads and approves before anything reaches the board. The prompts are version-controlled and have an explicit anti-hallucination contract: use only provided data, cite specific numbers, no vague quantifiers.