Know where your firm
actually stands — not where you assume it does
Varde is a self-assessment platform covering the regulatory obligations UK organisations actually face. Answer plain-English questions and get a RAG-rated report — usually 10-20 minutes, depending on how much applies to your organisation — no account, no sales call, no jargon.
SYSC 10A and UK GDPR are both fully built assessments, live today. DORA is in early access — register your interest below and we'll be in touch.
Pick the area you need checking
Each assessment is scoped to a single regulatory area, so you only spend time on what's relevant to you. SYSC 10A and UK GDPR are both ready today — a free assessment with a RAG-rated report, plus a paid gap report and guided help to close what it finds (SYSC 10A also has a policy builder). DORA is in early access — register your interest below and we'll let you know as soon as you can get started.
Communications Recording
For UK IFA firms, wealth managers, and discretionary fund managers with MiFID II-derived recording obligations. Covers what must be recorded, how long it must be kept, and what happens when a recording doesn't happen.
Operational Resilience
For UK financial services firms with EU exposure under the Digital Operational Resilience Act. Covers ICT risk management, incident reporting, and third-party resilience.
Thanks — we'll notify you when DORA is ready.
UK GDPR — pricing tiers
The same free assessment and coverage for everyone — only the paid gap-report stage is priced by organisation type. Eligibility for Community/Club & Charity pricing is confirmed by a short declaration once you sign up, so start with whichever fits.
Data Protection
For any UK organisation processing personal data — not sector-specific, unlike SYSC 10A or DORA. Covers lawful basis, data subject rights, ROPA, DPIAs, and breach notification.
Data Protection — Community
For microbusinesses and small not-for-profits not currently regulated by the FCA — the same free UK GDPR assessment as our standard tier, with lower pricing for the gap report and remediation stage.
Data Protection — Club / Charity
For unincorporated clubs, societies, and charities not currently regulated by the FCA — the same free UK GDPR assessment as our standard tier, with lower pricing for the gap report and remediation stage.
From question to report, in order
Answer in plain English
A guided conversation asks about your firm's actual practices — no regulatory text to decode first.
Get a RAG-rated report
Each category is scored red, amber, or green, with a downloadable PDF you can keep on file or share internally.
Act on what it finds
Amber and red findings come with a plain explanation of the gap — and, where available, a path to close it.
Guides from the team
Longer-form guides on compliance, written by the same team behind the assessment.
Not an enterprise GRC platform
Varde is sized for organisations that need a real answer, not a procurement process.
Before you start
Yes — the assessment and RAG-rated report are free for everyone, with no account needed. Closing the gaps it finds (the gap report and remediation stage) is a separate paid step.
SYSC 10A applies specifically to UK IFA firms, wealth managers, and discretionary fund managers with call-recording obligations. UK GDPR applies far more broadly — to any UK organisation processing personal data, regardless of sector. DORA applies only if your firm has EU-connected clients, operations, or regulated activities. If you're not sure, start with SYSC 10A — it's our most complete assessment today.
SYSC 10A and UK GDPR are both fully live today, each with a complete free assessment and a paid gap-report stage to close what it finds (SYSC 10A also has a policy builder). DORA is in early access — register your interest on the card above and we'll let you know as soon as you can get started.
If you don't provide an email, nothing is linked to you. If you do, your personal details are encrypted and can be erased on request at any time — the anonymised compliance record itself may be kept for the retention period the relevant regulation requires.
Yes — each one is independent. SYSC 10A and UK GDPR are both available now; once DORA opens up to everyone who's registered interest, you'll be able to complete any combination that's relevant to your firm.
Ready to find out where the gaps are?
Pick an assessment above, or jump straight into one below.