Section 09

Compliance Roadmap

Two certifications, at two different scopes, both central to winning and retaining enterprise customers in these sectors.

Why compliance certification matters commercially

In fintech, security certification is table stakes and customers assume it exists. In the sectors Arridex serves, particularly when selling to international operators, formal security and quality certification is often a hard gate in procurement, not a nice-to-have. An IOC's IT security and vendor adoption teams will typically ask for evidence of a recognised certification, or a credible plan and timeline toward one, before a third-party platform is approved for use. Both certifications below should be understood in that light: they are not purely internal risk management exercises, they directly affect what Arridex can sell and to whom.

ISO 27001, holding company level

ISO 27001 is an international standard for information security management systems. Arridex is pursuing certification across the entire holding company, not just for a single product. This is a substantial undertaking, typically spanning many months from gap assessment through to external audit, covering policies, processes, and controls across the organisation, not just technical configuration.

Ownership

This programme is led by the QHSE team, who manage certification and management systems activity across the organisation, with support from IT Strategy & Architecture (IT Services). It is not something a Technical Product Manager can or should attempt to drive alone, a holding-company-wide gap analysis requires organisational reach beyond any single product team. Your role is to track the programme's progress and flag implications specific to Velidon, since Velidon's SaaS ambitions are directly affected by what the certification requires around data handling and residency.

SOC2, Velidon-specific

SOC2 is an audit standard assessing how a service organisation handles customer data, covering security, availability, and related trust criteria. Unlike ISO 27001, SOC2 here is scoped specifically to Velidon, since it is the customer-facing SaaS product being sold to external operators. This is realistically your programme to drive, with support from IT Services, and it should be approached as a first step of readiness assessment and gap identification, not a claim of certification achieved within a single quarter.

What "readiness" actually means in the near term

The ISO 27001 certification cannot be completed in 90 days, but SOC2 can be pursued aggressively. What is needed first is a gap assessment and remediation roadmap for each, alongside a security posture package for Velidon built from controls that already exist today (multi-tenant isolation, role-scoped access, audit trail), so IOC conversations can proceed on real evidence while the certification work continues in parallel.