
This article was written by Jonathan Sowler, Chief Technology Officer, Insignis
Insignis has been assessed against, and certified to, ISO/IEC 27001:2022 by Amtivo, the UKAS-accredited certification body. It is the kind of announcement that risks sounding procedural. I want to explain why, in our particular business, it is not.
Insignis does not hold deposits in the way a bank does. We operate further up the chain, as the connective layer between our personal and business clients and the panel of banks with which their funds are ultimately placed, under an introducer, agent and client authority model. That position is precisely why information security is not a peripheral concern for us. It is the substance of what we are asking our banking counterparties to trust us with.
A bank assessing a relationship with an intermediary is not principally evaluating a brand. It is asking questions that are hard to answer from the outside: how instructions are authenticated and transmitted, and how a third party's technology is kept secure and recoverable if something goes wrong. Historically, banks have had to take much of this on trust, or extract assurance through lengthy bilateral due diligence: questionnaires and site visits, backed by contractual warranties that are only as good as the processes behind them. ISO 27001 does not replace that scrutiny, but it changes its character. It gives a bank an externally audited, internationally recognised statement that our information security management system has been examined against a common standard, by an independent, UKAS-accredited assessor, and found to meet it — not asserted by us but tested by someone with no commercial interest in the answer.
This matters more, not less, as our panel of banking relationships grows. Each additional counterparty is another institution whose own risk committee must satisfy itself about us. A certification that is recognised and understood across the banking sector reduces the marginal cost of that assurance for every one of them, and for us. It is, in effect, a shared reference point that lets a due diligence conversation start from a higher baseline than a blank page.
None of this diminishes what the certification means for our personal and business clients, or for our regulator. The obligations are the same whoever is asking. We manage information according to risk and make sure that access and third-party suppliers are held to consistent standards. When something goes wrong, we need to detect it and respond to it in a way that is documented and auditable. What differs is simply who is best placed to rely on the answer at any given moment, and for a firm built on introduced trust rather than direct custody, the banks holding the funds are very often that first audience.
ISO 27001 requires continual improvement and periodic surveillance audits, and our information security management system will keep being tested and revised well beyond our receipt of the certificate in July 2026. I would rather that be true than pretend otherwise. We live in a world where the threats posed by AI and advances in quantum computing continue grow. What we can say with confidence today is that an independent assessor has looked closely at how we handle the information entrusted to us and how we seek to assess risk and manage our security controls to address that risk – and they have been satisfied by what they found.