New guide: assessing organisational readiness for Microsoft 365 Copilot. Read the guide

Regional Financial Services Group ยท Financial Services

Establishing a Power Platform Centre of Excellence in a regulated environment

A tiered governance model that permits low-code delivery to continue while satisfying regulatory control expectations.

9 December 2025 Financial Services

Technologies

  • Power Platform
  • Dataverse
  • Microsoft Entra ID
  • Power BI
  • Microsoft Purview

Outcome themes

  • Controlled enablement
  • Ownership clarity
  • Auditable change

Client context

A financial services group has several hundred Power Platform makers who built solutions organically during a period of rapid remote-working change. Some solutions have become operationally important. Internal audit has raised concerns about ownership, change control and data movement.

The challenge

Shutting down low-code delivery would remove capability the business now depends on. Applying full change control to every app would be disproportionate and would push makers towards unmanaged alternatives. Control expectations must nevertheless be satisfied with evidence.

Objectives

  • Satisfy audit expectations without stopping low-code delivery
  • Establish ownership and succession for business-important solutions
  • Prevent business data reaching non-business connectors
  • Provide an application lifecycle path for solutions that need one
  • Give the platform team visibility of the estate

The solution

A three-tier model is introduced, with governance proportional to consequence: personal productivity, team solution, and business critical. Data loss prevention policies separating business and non-business connectors are applied first as a hard boundary. Managed environments provide visibility, and automated registration prompts makers for owner and tier. A starter solution with connection references, environment variables and a working pipeline makes the compliant path the fastest one. Business-critical solutions receive architecture review, formal lifecycle management and a defined support model.

Architecture

  • Environment strategy separating personal, team and business-critical workloads
  • Data loss prevention policies applied per environment group
  • Managed environments with maker welcome content and sharing limits
  • Centre of Excellence starter components for inventory, ownership and usage telemetry
  • Azure DevOps pipelines for solution deployment in the business-critical tier
  • Power BI governance reporting on estate, ownership attestation and policy exceptions

Delivery approach

How the work ran

  1. Assess

    Estate inventory, business impact classification and identification of orphaned solutions.

    Estate inventory Impact classification Risk register
  2. Design

    Tier definitions, environment strategy, policy set, exception process and support model.

    Governance model Policy set Exception process
  3. Implement

    Policies, managed environments, registration automation, starter solution and pipelines.

    Configured platform Starter solution Pipelines
  4. Enable

    Maker communications, guidance, office hours and champion network establishment.

    Maker guidance Enablement sessions Champion network
  5. Operate

    Attestation cycles, governance reporting and a standing platform backlog.

    Attestation cycle Governance dashboard Platform backlog

Outcomes

What changed

Delivery continued under control

Low-code delivery was not suspended; scrutiny was made proportionate to consequence.

Ownership recorded and attested

Business-important solutions have named owners, co-owners and periodic attestation.

Data boundary enforced

Connector policies prevent business data reaching non-business destinations.

Auditable change path

Business-critical solutions deploy through pipelines with a recorded change history.

Lessons learned

What we would tell the next organisation

Every engagement produces something worth carrying forward. These are the points that mattered most in this one.

  • Data loss prevention should be the first control implemented. It addresses the incidents governance is usually created for.
  • A starter solution that saves makers time achieves more compliance than a policy document.
  • Orphaned business-critical applications, not security incidents, are the most common failure discovered during assessment.

More customer stories

Next step

Start with the problem, not the platform

The first conversation is about what is not working today. Product selection comes later, and sometimes the answer is that you do not need a new one.

Talk to an expert Solutions