Who can fix compliance problems inside a New Zealand financial system?

Most compliance failures in financial services are not policy failures. The policy is usually right, but the system has quietly drifted away from it. Terms changed and the calculation did not. A disclosure requirement was added and one code path missed it. A retention rule was written and nothing enforces it. Auditors find the gap; the fix is engineering, not another document.

The gap between the policy and the system

When your terms changed, did you remember to update your system?

Where the drift shows up

Interest and fee calculations. Disclosure timing. Data retention. Access controls that were correct three restructures ago. Manual workarounds that became the process.

Policy drift rarely affects every path at once. A main workflow may use the new calculation or disclosure while an exception path, manual override or batch process continues using the old rule. The system can appear correct until an auditor follows one of those less common routes. The engineering task is to find every implementation of the rule, align it and leave a versioned record of the change.

Why documentation trails matter more than the fix

An auditor asking "show me when this changed and who approved it?" is asking a system question.

Regulation anchor

Requirements under the CCCFA and AML/CFT regime can have direct system consequences: what is calculated, what is disclosed, which checks must complete, what is retained and what evidence can be produced later. Dark Arts does not provide legal or compliance advice. Your advisers define the obligation; we trace it through the software, identify gaps between the approved policy and implemented behaviour, and make the agreed engineering changes.

Frequently Asked Questions

Our auditors flagged gaps in our documentation trail. Is that a systems problem?
If your system is fully automated, then yes. We build systems that know which documents are required and when. If a required document has not been received at a particular stage, our systems will not allow the process to move forward. Every document, whether uploaded manually or received through an API, is recorded in the log with the date, time and delivery method, such as email, API or scan. This gives clients a complete record in one place, so they can respond quickly and easily when an auditor asks for evidence.

We changed our terms. How do we know the system followed?
A change in terms is a policy change, so the system will comply only if its corresponding logic has also been changed. At Dark Arts, we document every system change and can tell you when it was introduced, provided we were instructed to make it.

Do you provide legal and compliance advice?
No. We look at your policies and terms and make sure the system follows them. It is up to your compliance officer to tell us about changes or gaps that may require system changes.

Can you assess without production access?
Absolutely. Our assessment is read-only. We don't make changes to your production environment or data during the assessment. Any recommendations are discussed with you before any implementation work begins.

How quickly can we know how exposed we are?
That will depend on the size and complexity of your system. A larger platform will take longer to work through. Once we have scoped the system we usually give a turnaround estimate. Spectra assesses a defined set of checks, which is why we know roughly how long an assessment will take.

Related reading: Can you prove the data hasn't been changed?