Skip to content

Regulatory compliance

Banking-Grade Compliance

BlueUP designs its platforms with regulatory compliance as a foundational requirement. It is not an afterthought: every architectural decision responds to a specific regulatory requirement.

Covered regulations

DORA: Regulation (EU) 2022/2554

Digital Operational Resilience Act for the EU financial sector. Mandatory since January 2025.

DORA RequirementHow we comply
ICT incident management (Art. 17)Automatic classification (Minor/Significant/Major) per DR (EU) 2024/1772 Art. 8
Supervisor notificationDeadlines of DR (EU) 2025/301 with ITS (EU) 2025/302 templates: Initial Report (≤4h), Intermediate (≤72h), Final (≤1 month)
Operational resilienceLocal spooling during network outages with autonomous reconnection and backpressure
Resilience testingCircuit breaker with controlled degradation (CLOSED → OPEN → HALF_OPEN)
ICT risk managementTwo-level alerts: WARNING (5 min) and CRITICAL (2h) with CSIRT escalation

SEPBLAC: Law 10/2010

Prevention of Money Laundering and Terrorist Financing. Supervised by Spain's Executive Service (SEPBLAC (Servicio Ejecutivo de la Comisión de Prevención del Blanqueo de Capitales e Infracciones Monetarias) is Spain's Financial Intelligence Unit and its supervisor for the prevention of money laundering and terrorist financing. Obliged entities file suspicious transaction reports with it (Law 10/2010).Read more → SEPBLAC).

SEPBLAC RequirementHow we comply
Special Examination (Art. 17)10-state workflow with immutable cryptographic audit trail
SEPBLAC CommunicationAutomatic F19/CXI form generation
Due diligence360° KYC profiles with 8-factor risk analysis
Sanctions screeningVerification against EU, OFAC and UN lists with fuzzy matching (Dice coefficient)
Segregation of dutiesFour-Eyes principle — high-risk approvals require two distinct persons

GDPR: Regulation (EU) 2016/679

GDPR RequirementHow we comply
Data minimizationOntological pre-validation at the Edge — only structured, necessary data leaves
Privacy by design (Art. 25)End-to-end mTLS encryption, configurable PII masking
Data residencyGoogle Cloud Europe infrastructure. Data never leaves authorized jurisdiction
Right of accessImmutable audit trail with full traceability

AI Act: Regulation (EU) 2024/1689

AI Act RequirementHow we comply
TransparencyAuditable LLM reasoning logs (in design, not deployed today)
Human oversightHuman-in-the-Loop for decisions affecting PII or financial data
Data governanceSovereign processing with vLLM/Ollama — data never leaves controlled infrastructure

Standards we follow

The table lists standards BlueUP applies in the product and on the portal. They are not certifications issued by a third party.

StandardUse at BlueUP
FINOS CDMStandardized banking data model
EIAC V06Insurance data model (TIREA standard)
WCAG 2.1 AAConformance target for the public portal, verified with axe-core on every deployment. No formal accessibility statement and no external audit
OAuth2 + OIDCStandard authentication with Keycloak

Resources and application by industry

Operational application by regulated industry:


Need a compliance assessment?

We analyze your current situation and show you how BlueUPALM can cover your regulatory obligations.

Request assessment

Self-assess your DORA/SEPBLAC maturity

Answer 18 questions and get your per-pillar score with recommendations, in 2 minutes.

Open the DORA Calculator

Last updated: