Legal & trust

Governance Framework

Last updated: 18 April 2026

Overview

Adviser IQ's governance framework ensures the platform is built, operated, and evolved with appropriate oversight. This page summarises board structure, committees, policies, and the cadence at which risk and change are reviewed.

Board & leadership

Adviser IQ Ltd is a UK-registered private limited company. Responsibility for performance, risk and strategy sits with the company's directors. Adviser IQ does not currently have independent non-executive directors.

Committees

Adviser IQ does not currently operate standing committees. Product-safety, risk, compliance and security matters are reviewed by the company's directors as part of ongoing operations. Formal committee structures will be introduced as the team grows.

Risk management

Enterprise risk register maintained and reviewed periodically. Risks categorised: technical, regulatory, commercial, operational, reputational. Each with named owner, mitigation plan, residual-risk score. See Risk Map for the customer-facing summary.

Change control

All production changes pass through code review, CI test suite, automated security scanning, and staged rollout. High-risk changes require explicit CTO sign-off. Customer-facing breaking changes communicated 30 days in advance where possible.

Vendor management

All sub-processors onboarded via a documented due-diligence process: security review, DPA, SLA, financial health. Reviewed annually. List at /sub-processors.

Policy framework

Internal policies: information security, access control, data classification, acceptable use, incident response, business continuity, vendor management, recruitment, confidentiality, whistleblowing. Each policy has a documented owner and review cycle.

Training & awareness

Adviser IQ does not currently run a formal training programme with retained records. Secure development practice is enforced in the change process itself: code review, automated security scanning on every change, and an OWASP Top 10 checklist applied per change. A formal training and records programme will be introduced as the team grows.

Whistleblowing

Protected disclosure channels available to staff, contractors, and customers. Email admin@adviseriq.co.uk or write to the Managing Director. Anonymous disclosure option provided.

Framework review

This framework is reviewed annually and after any material change to the business or regulatory environment. Next scheduled review: April 2027.