Service · Software development

Custom financial sector software development.

Custom software for banks, insurers, pension funds, asset managers and fintech start-ups. Client portals, KYC flows, compliance platforms, risk and portfolio tooling, financial modelling apps and white-label tools, built around the regulation you know, alongside the packages you already run.

Client portalsKYC / AMLDORA & WftQuant & modelling

We do not replace Temenos or Mambu.

Let us be clear from the outset: an enterprise bank looking to replace its entire core, or an insurer rebuilding its policy administration from scratch, is a multi-year, multi-million-euro undertaking. That is the territory of Temenos, FIS, Finastra, Mambu, SS&C, Avaloq and their peers. We do not do that. The same applies to the standard suites Wolters Kluwer OneSumX, ING Tools or the Adyen platform: buy the package, and we will connect to it.

What we do instead is build the software that is missing alongside those standard packages. A modern client portal for account access, transactions or policies. Digital onboarding with KYC and Wwft checks. A platform on which your compliance team records DORA incidents and third-party risk. Risk and portfolio management tooling that runs your own models, rather than the generic version from a Bloomberg add-on. Quant apps for financial modelling, treasury tools for corporates, claims platforms for insurers, and fintech MVPs for start-ups that do not yet even have a core.

Our clients: banks wanting to renew a specific flow, insurers needing digital claims or policy portals, pension funds modernising participant environments, asset managers whose client reporting still goes out as PDF, payment institutions launching a product under PSD2 or PSD3, family offices that no longer want to consolidate their reporting in Excel, asset managers with factor models, trust offices digitising their client files, and accountants or tax advisers developing a fintech arm. The common thread: you know the regulation and the market, and we build the software that makes it work.

What we build.

Three types of projects where our experience with regulated financial platforms, custom fintech and compliance software comes into its own. In the first conversation, we determine which path fits your scope, your existing IT landscape and the regulator keeping an eye on things.

Customer-facing application · alongside your existing core

Client portal, onboarding app or policy environment

Your core systems work well: it's only the layer your customers use every day that feels outdated. We build the modern client portal for account access and transactions, the member portal for a pension fund, a policy and claims environment for an insurer, or an onboarding app with integrated KYC and Wwft checks. With SSO via your IdP, iDIN or DigiD for identity, push notifications for every status change, and an API layer that connects cleanly with your existing core rather than replacing it.

Client portaliDIN / DigiDKYC / AMLMobile & web
Compliance and risk platform · operational tooling

Custom compliance, DORA or risk platform

For teams working with regulation and risk: a platform where you record DORA incidents, third-party risk and ICT resilience, a KYC and AML environment that supports your onboarding, a DORA platform (see also DORA compliance software), or a risk management tool where you track limits, exposures and stress scenarios without replacing your core system. With auditable logging, dashboards for your board, and a data model that can feed AFM, DNB or internal audit reports directly.

DORA registerRisk dashboardsWwft & AMLAudit trail
Fintech platform or quant app · scale-up or corporate

Fintech MVP, modelling app or white-label platform

For fintech start-ups, asset managers, family offices and quant teams that need their MVP, V2 or a specific modelling application. Financial modelling software that takes Python models from research into production, a treasury tool for corporates that consolidates liquidity across multiple banks, a white-label platform for financial tools that you supply to partners under your own brand, or a wealth platform with client reporting and portfolio analytics. Open Banking integrations via PSD2, a calculation engine that scales, and all DORA, GDPR and MiFID II requirements built in.

Some financial entities are designated for threat-led penetration testing, with their own role separation and delivery. See the page on TLPT software.

Quant & modellingOpen BankingWhite-labelPortfolio analytics

What we do and don't deliver.

The financial sector draws a sharp distinction between standard suites, licensing and custom software. We deliberately operate in the latter domain, and we are transparent about that.

For packaged solutions (a new core, a Solvency II reporting engine, an EMIR transaction reporter), you work with specialist vendors. For licences, you work with a Wft lawyer or compliance adviser. We connect technically to these and build the part where the existing offering falls short.

  • Customer-facing applicationsClient portals, mobile apps, policy and claims environments, member portals for pension funds, and wealth reporting for private clients.
  • Compliance and risk softwareDORA registers, third-party risk modules, KYC/AML onboarding, transaction monitoring dashboards, Wwft controls, audit trail. Not a separate procedural layer, but built into the software itself.
  • Quant and modelling appsFinancial modelling software that takes Python or R models from research into a production-grade environment, with version control, reproducible runs and explainable results.
  • Integrations with core and standard packagesIntegrations with Temenos, FIS, Finastra, Mambu, SS&C, Avaloq, OneSumX, Adyen, ING Tools and aggregators such as Tink or Yapily. Via REST, SOAP, ISO 20022 or file, depending on what the vendor offers.
  • What we do NOT deliverNo replacement for your core administration or policy system. No DNB or AFM licence applications. No in-house Solvency II or EMIR reporting engine. No accounting engine that produces IFRS ledgers or tax returns.

Compliance & regulation in software.

The financial sector is a layered stack of regulation, and the software you deploy there must support that layering properly. We build software with the Wft, DORA, MiFID II, IDD, EMIR, PSD2 and, in the near term, PSD3, GDPR, Wwft, Solvency II, IFRS and, for parties under direct DNB supervision, BIO as the framework. We build the controls into the software rather than adding them as a separate procedural layer on top, so every transaction and every user action is automatically checked against the rules your compliance team has defined.

In practice, this means: an immutable audit trail for every change, recording who, what, when and why. A role and authorisation model that demonstrably enforces segregation of duties. KYC and Wwft checks that apply the right level of due diligence for each client category. Transaction monitoring with rules your compliance officer can adjust personally, plus alert flows to AFM notifications or FIU reports where relevant. And for DORA: a register of ICT third parties, an incident classification scheme, and exportable overviews for your supervisor.

On the privacy and data side: encryption in transit and at rest as standard, secret management via an HSM or cloud equivalent (AWS CloudHSM, Azure Key Vault Managed HSM), pseudonymisation wherever the business allows, and retention periods derived from the legal regime rather than an arbitrary default. We document the controls in a way your compliance or internal audit team can reuse directly for DNB, AFM or EBA reporting. Not a loose spreadsheet, but output generated by the system itself.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

When an engagement suits us.

Four recognisable patterns in which we often become involved in the financial sector. If one of these sounds familiar, we would be happy to talk further.

Modernisation

Your client portal feels outdated

Your core administration works well, but the client environment hasn't been touched in years. Account access, policy changes or transaction history sit on a legacy interface that is unusable on mobile. A new portal alongside the core system, with an API layer that leaves the core untouched, is then the smartest route.

Compliance deadline

DORA, Wwft or MiFID II requires action

The DORA deadline is approaching and your incident management lives in a shared mailbox. Your Wwft onboarding consists of loose Word forms. Or MiFID II requires call recordings and suitability checks that your current stack cannot handle properly. A modular compliance app that digitises this workflow tightly, without having to replace your core system.

Fintech MVP

You are launching a new proposition

You have a fintech idea (a savings product, a payments app for a community, a wealth tool for a niche group) and the first version needs to reach the market on a sound foundation. With a BaaS rail underneath, integrations to Adyen or a PSP, and an architecture that scales towards V2 without starting over.

Quant & data

Your models deserve a production platform

Your quant or research team runs financial models in Python or R, in notebooks that nobody else can reproduce. A modelling app that takes those same models into production in a reproducible way, with version control, governance and explainable results, for risk management or client reporting, and also suited to supervisors who ask for model explanations.

How an engagement works.

1

Introduction and scope

A conversation to understand which product you are bringing to market, which standard packages you already run, which regulations apply, and what your own team can already take on. By the end we have a shared picture of the scope and an initial split between packaged and custom development.

2

Architecture & compliance mapping

A workshop with your tech and compliance team. We map the relevant requirements (DORA, Wft, MiFID II, GDPR, Wwft, and possibly Solvency II or PSD2) onto concrete software controls. This leads to an architecture document, a data model and the first screen flow for the highest-priority use case.

3

Building in sprints

A working build every two weeks in a feature-flagged staging environment, so compliance and security reviews can run in parallel with development. We schedule a penetration test well before go-live and involve your internal audit early, so there are no endless control rounds at the end.

4

Production & ongoing maintenance

A phased go-live, with a controlled rollout to a first group of customers or teams. After that, ongoing management: monitoring, security patches, regulatory change (PSD3, the AI Act, revised DORA RTS), and further development based on what your customers and compliance team actually need.

Frequently asked questions.

The questions we are asked most often before starting a project for the financial sector.

Do you replace Temenos, Mambu or another core banking or policy administration package?
No. A complete core replacement in the banking or insurance sector is work for specialist vendors: Temenos, FIS, Finastra, Mambu, SS&C and Avaloq on the banking side, and large suites such as Guidewire, Sapiens or the Wolters Kluwer stack on the insurance side. We build the layers on top and the modules alongside: customer portals, onboarding flows, compliance platforms, claims portals, risk tooling. That is where our added value lies, in the software your customers see and that defines your competitive edge. For a bank, you can refer to our page on building a core banking platform; for an insurer, see our page on custom insurance software development.
Which compliance frameworks do you build into software?
The usual set for digital financial services in the Netherlands and the EU: the Wft as the overarching framework, DORA for ICT resilience, MiFID II and IDD for investment and insurance advice respectively, EMIR for derivatives reporting, PSD2 (and soon PSD3) for payments, the GDPR and, for parties supervised by DNB, BIO as the security framework, the Wwft for anti-money laundering, Solvency II for insurers and IFRS for financial reporting. We build the controls into the system: audit trails, segregation of duties, transaction monitoring, KYC flows and the associated reporting. The legal interpretation remains the work of your compliance or legal department, sometimes in collaboration with an external Wft lawyer.
Can you help with DORA compliance?
Yes, on the software side. We build registers for ICT third parties, classification schemes for incidents, exportable reports for your supervisor, and the monitoring layer that makes incident detection demonstrable. For the substantive DORA gap analysis and governance questions, you work with a specialised adviser or your own compliance officer; we turn their output into working software. See also our dedicated page on DORA compliance software.
How do we handle Wwft and KYC checks during onboarding?
We build an onboarding flow in which Wwft and KYC checks trigger the appropriate level of due diligence per customer category: simple for low-risk customers, enhanced for PEPs or complex structures. Identity verification via iDIN or a KYC provider such as Onfido, Veriff or Signicat, UBO extracts via the KvK, sanctions list screening and PEP checks via parties such as ComplyAdvantage or Refinitiv. For the software layer around this, see KYC/AML compliance software. We do not choose the vendor you contract on your behalf; we align with what fits your risk appetite and budget.
Can you help with a DNB or AFM licence application?
No, for that you'll need a Wft lawyer or compliance consultant who knows the application procedure in detail. We connect technically to the requirements that come out of that process: ensuring the software demonstrably delivers the required controls, that the logging architecture is DNB-proof, and that your licence-holder status remains intact after go-live. For the legal files and conversations with the regulator, you're in better hands with a specialist than with us.
Do you also build financial modelling software and quant apps?
Yes. Many finance teams have models in Python or R notebooks that work, but that nobody else can reproduce and that sit outside any governance. We bring those models into a production-grade environment: version control in Git, reproducible runs with pinned dependencies, a compute service that can scale, dashboards for risk or portfolio managers, and an audit trail per model version and per result. For regulators asking about model explainability, or for internal model validation, the system is ready — no more black-box notebook.
Can you integrate with our existing packages or legacy systems?
Yes. We have experience with the REST APIs of modern cores and BaaS providers, with SOAP services, with ISO 20022 messages, with SWIFT files, batch exchanges and, not infrequently, message queues on mainframes. For insurers: integrations with policy and claims packages, loss adjusters and reinsurers. For banks: SWIFT, SEPA, Adyen and ING tools. Where needed, we build an anti-corruption layer, so the new application does not inherit the quirks of the legacy system and a later replacement does not break through your new shell. For larger projects, we also work alongside our enterprise software team.
What determines the lead time and cost?
Scope is by far the biggest factor: a standalone module alongside an existing core is a different project from a full customer portal with onboarding, transactions, KYC and compliance reporting built in. Other factors include the number of integrations with existing packages, the complexity of your business logic, how much compliance evidence your regulator expects, and whether you serve one or several entities or countries. After an initial workshop, we give a concrete estimate with several scope options, so you can choose based on risk, priority and investment, rather than on a price that has nothing to do with your situation.

Talk to us about your financial platform.

A no-obligation introductory call of half an hour. Tell us about your product, the packages you already run and the regulation that applies — we'll give you direction you can use, even if you ultimately go ahead with someone else. For larger fintech, insurance or compliance questions, we also involve our enterprise software team.

Would you like to look at this challenge from the custom software side? On applatenmaken.com you'll find a detailed look at Financial software and insurance.

Edit content