From Paper to Proof: How Magnus Group Revolutionized Regulatory Compliance with Process Street

In the high-stakes world of fintech, the distance between "compliance on paper" and "compliance in practice" is often the difference between a thriving business and a shuttered operation. For Magnus 1265 Ltd, a specialized payment facilitator and card-present payment gateway provider, this gap was not just a theoretical concern—it was the primary hurdle in their quest to secure a Payment Institution licence for their regulated arm, Elgar Payments Ltd.

As the fintech sector faces unprecedented regulatory scrutiny, firms are moving away from the traditional, static documentation models that once satisfied oversight bodies. Magnus Group chose a more radical path: they transformed their operational backbone into a living, breathing digital framework. By leveraging Process Street to turn their Standard Operating Procedures (SOPs) into mandatory, trackable workflows, they achieved more than just a licence—they built a blueprint for modern, audit-proof operations.

The Business: A Commitment to Security

Magnus 1265 Ltd operates at the intersection of complex payment infrastructure and stringent security standards. As a provider of back-office software for payment facilitators, the group’s reputation is built on reliability and safety. The company is already a high-bar entity, holding both PCI DSS (Payment Card Industry Data Security Standard) and PCI PIN certifications. These are among the most demanding benchmarks in the global financial services industry, requiring constant vigilance and absolute adherence to data protection protocols.

Elgar Payments Ltd, the group’s regulated arm based in Gibraltar, serves as the vehicle for their expansion into authorized payment services. To operate, Elgar had to satisfy the Gibraltar regulator that its internal controls were not merely present in theory, but robust in daily execution.

The Challenge: The "Word Document" Trap

The regulatory application process for a payment institution is notoriously rigorous. Regulators are no longer content with receiving a glossy manual of policies and procedures. They ask granular questions: Who authorized this specific transaction? What was the basis for this risk assessment? Where is the audit trail for this KYC (Know Your Customer) review?

Chris Jamieson, CTO of Magnus Group, recognized that the traditional approach—drafting policies in Word or PDF—was fundamentally flawed.

"We didn’t want to fall into the trap that I think we’ve fallen into before, of getting lots of written processes down in a Word document," Jamieson explains. "And then that Word document sits in a folder somewhere and nobody ever looks at it, and people just do the processes from memory anyway."

This "memory-based" work culture is the silent killer of compliance. When processes are stored in static files, they become disconnected from the actual work. Human error, cognitive bias, and the pressure of daily operations mean that even the most well-intentioned teams drift from the documented procedure. For a regulator, a policy that is not followed is equivalent to no policy at all.

The Approach: Engineering Operational Integrity

To bridge the gap between policy and practice, Magnus Group moved away from static documentation and adopted Process Street as their primary operational engine. The strategy was simple but transformative: if the work happens in the workflow, the evidence is generated as an automatic byproduct.

A Dedicated Implementation Project

Magnus did not treat the migration as a secondary IT task. They recognized that a tool is only as good as the process it supports. The group engaged third-party consultants to audit their existing, often informal or undocumented practices. These consultants worked with the team to map out the "real" workflows—not the idealized versions, but the actual steps required to complete tasks like:

  • Customer Onboarding: Ensuring every required document is collected and verified.
  • KYC/AML Review: Standardizing the decision-making process for client verification.
  • Transaction Monitoring: Creating a repeatable, high-fidelity audit trail for suspicious activity reports.
  • Vendor and Partner Management: Formalizing the oversight of third-party risk.

By turning these into mandatory, step-by-step digital workflows, the firm removed the option for staff to "work from memory."

The "By-Product" Evidence Model

The brilliance of this approach lies in the passive collection of audit data. In a manual system, gathering evidence for an audit is a massive, stressful project involving weeks of retrospective documentation. At Magnus, the documentation is the work.

When a team member completes a task, the platform automatically logs the timestamp, the individual who performed the action, the specific managerial approval provided, and the outcome of the process. This creates a forensic record that is inherently accurate because it was created in real-time, during the natural course of business.

Official Responses: Navigating the Regulatory Assessment

The true test of this strategy came during the on-site assessment by the regulator. This is the moment where many fintech firms stumble, as the "live" reality of their office is compared against their written documentation.

For Elgar Payments Ltd, the experience was markedly different. When the regulator requested proof of how they handled critical processes, the team did not reach for a dusty policy book. They pulled up the live, active workflows. They demonstrated that for every client onboarded, the specific steps—including risk assessment and KYC validation—had been followed in the exact sequence required.

"We’ve got these processes formalised within Process Street," Jamieson noted after the successful assessment. "We were able to show the timestamps, the separation of duties and the managerial approvals. It certainly helped us move through the process, and to demonstrate to the regulator that we’ve got our head screwed on."

Yael Massias, Head of Compliance at Elgar Payments Ltd, emphasized that this approach fundamentally shifted the dynamic of the regulatory conversation:

"An application of this kind is really a sustained test of whether your controls are genuine. Having onboarding, risk assessment, KYC review and transaction monitoring running as live workflows meant that when we were asked a question, we could answer it with the actual record rather than a description of what should have happened. That changes the character of the conversation with a regulator."

Implications: The Future of Audit-Proof Operations

In April 2026, Elgar Payments Ltd was granted its licence. The success of this application stands as a testament to the fact that compliance is a technical and operational discipline, not a clerical one.

Closing the Gap

For any organization subject to certification or regulation, the "audit risk" lives exactly where the documented process ends and the human action begins. By using Process Street, Magnus Group has successfully closed this gap. They have moved from a reactive model—where evidence is "reconstructed" after a request—to a proactive model where evidence is a natural byproduct of business operations.

Efficiency Beyond Compliance

While the license was the primary goal, the secondary benefits of this system have been equally profound. By forcing staff to interact with a structured checklist, the company has seen a significant reduction in operational errors.

"You’ve got to work through the checklist. You’ve got no option," says Jamieson. "You’ve got to tick the boxes, you’ve got to follow the steps. We definitely find that it reduces error and makes the team a lot more focused on the task at hand."

The Strategic Lesson

The journey of Magnus Group offers a blueprint for other fintech firms. The lesson is that regulatory compliance should not be an "add-on" or a project that happens in the weeks leading up to an audit. It must be woven into the fabric of daily productivity.

By prioritizing the "how" of work, Magnus has achieved a state of "continuous compliance." They are no longer scrambling to prove they are following the rules, because their entire operational model is designed to make it impossible to do anything else. As the financial sector continues to evolve, firms that adopt this "process-as-code" mentality will likely find themselves at a significant competitive advantage, characterized by higher operational resilience, lower audit risk, and a more sustainable, scalable growth trajectory.

In the final analysis, Magnus Group’s success proves that the best way to satisfy a regulator is not to tell them what you do, but to show them how you do it, every single day, without exception.