Skip to main content

Security and compliance

The questions your compliance team will ask, answered

Certification, data handling, the advice boundary and how we use AI. If something here does not answer your due diligence questionnaire, email hello@pillarcs.co.uk.

Certification

ISO/IEC 27001:2022

Pillar Client Services Ltd is certified to ISO/IEC 27001:2022, the international standard for information security management. Certificate 274783, issued by Amtivo on 30 September 2026, with annual surveillance audits.

Scope: outsourced, non-advised client review services and client book reconciliation software (Pillar Lens) for UK financial adviser firms.

Consumer Duty Alliance Affiliate badge

Membership

Consumer Duty Alliance Affiliate Member

Pillar has been an Affiliate Member of the Consumer Duty Alliance since April 2026. Affiliate membership is for organisations that support adviser firms. It is a membership, not an assessment or endorsement of Pillar’s services.

Client data

How we handle your clients’ data

Data processing agreement first

Nothing starts until a data processing agreement is signed. Your firm is the controller of its client data. Pillar is the processor.

Review work stays in your system

Client Review Managers work inside your Intelliflo under user access your firm grants and can withdraw. File notes and outcomes are recorded there.

Deletion on exit

Firm data is deleted within 30 days of termination or your instruction, access tokens are revoked, and we confirm in writing, except where the law requires us to keep it.

UK hosting and encryption

Data is hosted in the UK (AWS London), encrypted at rest and in transit, and separated by firm at database level. Pillar connects to Intelliflo through its official app store integration and never holds adviser logins.

The advice boundary

Pillar gives no regulated advice

Pillar is not authorised by the FCA. Client reviews run under your firm’s permissions and your compliance framework, and your firm keeps regulatory responsibility for every client.

Client Review Managers do not recommend products, do not judge suitability and do not discuss investment performance. A change in circumstances, a complaint, a vulnerability flag or a request for advice goes back to your adviser with a briefing note.

Pillar Lens reports are management information for your firm’s own Consumer Duty assessment. They are decision support, not a certification that your firm meets its obligations.

How we use AI

Where software does the work, and where people do

Pillar Lens. Reports are produced by our software from your own data. A person does not check every report before it reaches you. Each report shows its sources and method so your firm can check the figures, and the decisions stay with you.

Client reviews. Every review is run by a trained Client Review Manager. Anything that needs advice goes back to your adviser.

Inside Pillar. We use AI assistants for drafting, research and administration. A named person at Pillar is accountable for everything we send.

Client data. Client personal data is never used to train an AI model. Any tool that processes client personal data on your behalf is named in our written agreement with your firm.

Our films. Some narration is generated from Brian McLaughlin’s own recorded voice, with his consent, and is labelled wherever it is used.

Our view on AI in advice: Advice and AI.

Running supplier due diligence?

We can send our information security summary, data processing agreement and certificate on request.

Email hello@pillarcs.co.uk