AI framework best practices

See how firms like yours can use artificial intelligence (AI) to enhance the quality of human judgement in the advice process rather than replacing it.

See how firms like yours can use artificial intelligence (AI) to enhance the quality of human judgement in the advice process rather than replacing it.

This framework sets out how a regulated advice firm can use artificial intelligence (AI) thoughtfully and responsibly — enhancing the quality of human judgement in the advice process rather than replacing it. It defines how AI tools are used across the firm, the boundaries that apply, and the controls in place to protect clients, staff, and the firm's regulatory standing.

It is designed to be consistent with the FCA's principles-based approach and a firm's obligations under Consumer Duty (PS22/9), the FCA's Principles for Businesses, SM&CR, and the UK General Data Protection Regulation (UK GDPR).

This framework is a practical starting point, not legal advice. Firms should review it with their compliance adviser or network before adoption.

At a glance

Applies to

All staff, contractors and third-party partners who use or interact with AI tools in connection with the firm's business activities.

Regulatory context

FCA Consumer Duty (PS22/9), UK GDPR, SM&CR, and the FCA's Principles for Businesses.

Version

1.0

01 Purpose and Scope

1.1 Purpose

A regulated advice firm should be committed to using AI thoughtfully, responsibly, and in a way that enhances the quality of human judgement in the advice process. This framework sets out how AI tools are used across the firm, the boundaries applied, and the controls in place to protect clients, the team, and the firm's regulatory standing.

Use of AI must be consistent with the firm's obligations under Consumer Duty (PS22/9), the FCA's Principles for Businesses, SM&CR, and the UK GDPR.

The FCA's Mills Review is examining how AI will transform retail financial services. The FCA has confirmed it does not plan to introduce AI-specific regulations, relying instead on existing principles-based frameworks. This framework is designed to be consistent with that approach.

Our guiding principle

AI augments advisers. It does not replace them. Every AI output that touches a client — directly or indirectly — is reviewed, validated and owned by a qualified human being before it is used.

1.2 Scope

This framework applies to:

• All employees, directors and contractors of the firm

• Any third-party service providers processing data on the firm's behalf

• All AI tools, platforms and models used in connection with the firm's business activities

• Both client-facing AI outputs and internal operational uses of AI

1.3 What we mean by AI

For the purposes of this framework, "AI" includes any system that uses machine learning, large language models (LLMs), natural language processing, generative AI, algorithmic decision-support tools, or automation features embedded within software platforms. This includes:

• Standalone AI tools (e.g. Claude, ChatGPT, Microsoft Copilot)

• AI features embedded within platforms in use (e.g. back-office system AI features, document generation tools, transcription services)

• AI-assisted meeting recording and transcription

• Any tool that generates, summarises, analyses, or recommends based on data inputs

1.4 AI maturity stage

Firms typically sit at one of three stages of AI adoption:

• Exploring — evaluating AI tools but not yet adopted any for business use

• Piloting — trialling AI tools with a limited group of staff or use cases

• Embedded — AI tools are part of standard operating procedures across the firm

02 Approved Uses of AI

AI may be used for the following purposes, subject to the controls set out in this framework.

2.1 Internal operations and administration

☐ Drafting and editing internal communications, reports, policy documents and templates

☐ Research and summarisation of publicly available information

☐ Preparing meeting notes, agendas and action logs from internal meetings

☐ Generating first drafts of compliance documents and internal frameworks

☐ Operational planning, strategy documents and board materials

☐ Email drafting and document summarisation

2.2 Content creation and marketing

☐ Drafting educational content, articles, newsletters and social media posts

☐ Creating scripts for video, podcast and speaking engagements

☐ Generating ideas, structures and outlines for written materials

☐ Proofreading and editing content before publication

Note: All client-facing and published content must be reviewed and approved by a senior team member before use. AI-generated content must not be published without human oversight.

2.3 Financial planning support

☐ Meeting transcription and structured note generation

☐ Suitability report drafting (with full adviser review before use)

☐ Annual review report preparation

☐ LOA pack summaries and provider data extraction

☐ Scenario modelling support and calculations (not primary advice outputs)

☐ Preparation of cashflow model inputs and data structuring

☐ Generating initial summaries of client situations for adviser review

☐ Research into financial planning strategies, tax rules and regulations

☐ Compliance checking of documents against FCA standards

Note: AI must not be used to generate regulated financial advice outputs directly. Any AI-assisted analysis, report, or recommendation must be reviewed and validated by a qualified adviser or paraplanner before use with a client.

2.4 Client-facing tools

☐ Client-facing tools that incorporate AI (e.g. discovery questionnaires, retirement planning tools, spending assessments)

☐ AI-assisted client communications (reviewed before sending)

Where AI is used in client-facing tools:

• The tool's purpose and use of AI must be documented in this framework or a tool-specific addendum

• Clients must be informed that AI is used, in plain language, within the tool itself

• Outputs must be framed as informational or exploratory, not as regulated financial advice

• No personally identifiable client data should be processed by a third-party AI provider without appropriate data processing agreements and client notification

2.5 Training and professional development

☐ AI-assisted CPD content and learning materials

☐ Knowledge assessment and competency testing

☐ Role-play scenarios for adviser training

03 Prohibited Uses of AI (Hard Limits)

Red: never, no exceptions

These apply regardless of time pressure, convenience, or commercial considerations.

1. AI must not generate suitability reports, investment recommendations, pension transfer analysis, DB transfer reports, or any other regulated financial advice output without full adviser review and sign-off.

2. No client personal data (names, addresses, financial details, NI numbers, health information) may be entered into a public or free-tier AI tool without explicit authorisation from the policy owner.

3. AI outputs must not be shared with clients as if they were adviser-produced documents without review, disclosure and amendment as appropriate.

4. AI must not be used to misrepresent the nature of the firm's services, qualifications, or regulatory status.

5. Staff must not use AI to bypass, circumvent, or shortcut any compliance process.

6. AI tools must not be connected to client data systems (back-office system, document management, client portal) without prior IT and compliance sign-off.

7. AI-generated communications must not appear to come from a named adviser without that adviser's explicit review and approval.

8. AI must not auto-populate regulatory submissions (FCA returns, pension transfer reports) without compliance sign-off.

9. Staff must not use personal AI accounts (free ChatGPT, personal Claude, personal Copilot) for any firm business, even if no client data is involved. All AI use for firm business must use firm-approved tools.

Amber: only with specific authorisation

10. Use of AI with vulnerable client data requires additional safeguards and policy owner approval.

04 Data Protection and GDPR

4.1 UK GDPR obligations

Use of AI is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. When processing personal data using AI tools, a firm must ensure:

• A lawful basis exists for the processing (most commonly legitimate interests or consent)

• Data subjects are informed of how their data is used (through the firm's Privacy Notice)

• Data minimisation principles are applied: only the data necessary for the specific task is input

• Appropriate technical and organisational security measures are in place

• Data is not transferred outside the UK without adequate safeguards

4.2 Third-party AI providers

Before using any third-party AI tool that will process client personal data, the following must be confirmed:

☐ A Data Processing Agreement (DPA) is in place with the provider

☐ The provider's data retention and training policies have been reviewed and are acceptable

☐ The tool is listed in the firm's Approved Tools Register (Section 06)

☐ The policy owner has approved its use

☐ Data residency has been confirmed (where is data stored and processed?)

☐ The provider can confirm whether inputs are used for model training, and if so, that this has been disabled

General rule: Free or consumer-grade versions of AI tools must not be used with client data. Only commercial-grade, enterprise, or API-based versions with contractual data protection commitments are permitted.

4.3 Data retention by AI tools

Some AI tools may use inputs to train their models by default. Before using any AI tool with sensitive data, staff must confirm whether data retention and training can be disabled, and take the necessary steps to do so. This information must be recorded in the Approved Tools Register.

4.4 Meeting recordings

Where AI is used to record and transcribe client meetings:

• Client consent must be obtained before recording begins, using the firm's standard consent script

• Recordings must be stored securely and access restricted to authorised staff

• Recordings must be retained for a defined period and then securely deleted

• The transcription provider must have a DPA in place and must not use recordings for model training

• Meeting notes generated from recordings must be reviewed by the adviser before being added to the client file

4.5 Data Protection Impact Assessment (DPIA)

A DPIA will be conducted before deploying any AI tool that meets one or more of the following criteria:

1. The tool processes special category data (health information, religious beliefs, ethnicity)

2. The tool involves systematic monitoring or profiling of individuals

3. The tool processes data of vulnerable individuals

4. The tool uses new or novel technology to process personal data

5. The processing could prevent individuals from exercising a right or accessing a service

If any of these criteria are met, a DPIA must be completed and reviewed by the policy owner before the tool is approved for use. DPIAs should be reviewed annually or when the tool's capabilities change materially.

05 Consumer Duty and Regulatory Standards

A firm's use of AI must be consistent with the FCA's Consumer Duty (PS22/9), which requires firms to act to deliver good outcomes for retail customers.

5.1 Mapping AI use to the four Consumer Duty outcomes

Outcome
How AI can support
How AI could undermine
Our controls
Products and Services

AI helps deliver advice services more efficiently, matching recommendations to client needs.

AI could recommend unsuitable products if data is incomplete or the model hallucinates.

Human review of all AI-generated advice outputs before client use.

Price and Value

AI reduces the cost of service delivery, potentially enabling the firm to serve more clients.

Over-reliance on AI could reduce quality, undermining the value proposition.

Regular quality audits comparing AI-assisted and manual outputs.

Consumer Understanding

AI can generate clearer, more structured client communications.

AI-generated language may not be appropriate for all literacy levels.

Vulnerability screening before sending AI-drafted communications.

Consumer Support

AI enables faster response times and more consistent service delivery.

AI may not handle complex, emotional, or unusual client situations.

Clear escalation path from AI-assisted to human-only support.

5.2 Explainability and the "own words" test

Where AI has materially contributed to advice, a recommendation, or a client communication, the adviser or paraplanner responsible must be able to explain the basis for any output or decision in their own words.

Reliance on "the AI said so" is not acceptable and does not meet professional standards or obligations under Consumer Duty.

Practical test: Before using any AI-generated output with a client, ask — "If the client asked me why I recommended this, could I explain it without referring to the AI?" If the answer is no, the output needs further review.

5.3 Disclosure

A firm should maintain a clear and accessible disclosure to clients that AI tools are used in its operations.

Terms of business wording

"[Firm] uses artificial intelligence tools to support our advice process. These tools assist with tasks such as meeting transcription, document preparation and compliance checking. All AI-generated outputs are reviewed and approved by a qualified member of our team before they are used in connection with your financial plan. Your data is processed in accordance with our Privacy Notice and applicable data protection legislation."

Case-specific disclosure

"This document was prepared with the assistance of AI tools and has been reviewed and approved by [the adviser]."

5.4 Algorithmic bias and fair treatment

A firm should take reasonable steps to ensure AI tools do not produce outputs that are biased, discriminatory, or that treat groups of clients unfairly based on protected characteristics. Where AI is used in client-facing tools or in the advice process, outputs should be reviewed for consistency and fairness as part of Consumer Duty monitoring.

5.5 Mills Review

The FCA's Mills Review is examining how AI interacts with Consumer Duty obligations across retail financial services. A firm should review this framework within 30 days of any Mills Review recommendations being published.

06 Approved Tools Register

Every AI tool a firm uses should be recorded in a register like the one below. Review it quarterly for High-risk tools and annually for Medium and Low-risk tools. The example rows show the structure; firms complete the DPA, training, review-date and owner columns for each tool.

Tool / platform
Provider
Approved uses
Risk level
DPA?
Training off?
Last reviewed
Owner

Meeting transcription tool

Provider

Meeting recording and transcription

High

Document generation tool

Provider

Suitability reports, annual reviews

High

Compliance checking tool

Provider

Document review against FCA standards

High

Microsoft Copilot

Microsoft

Email drafting, document summarisation

Medium

Claude / ChatGPT

Provider

Internal drafting, research

Medium

Risk classification

• High — processes client personal data or produces client-facing outputs

• Medium — processes firm data only (no client personal data)

• Low — no data processing (e.g. general research with no firm-specific inputs)

Review cadence

• High-risk tools — review quarterly

• Medium-risk tools — review annually

• Low-risk tools — review annually

Shadow AI detection

Conduct a quarterly staff survey: "Are you using any AI tools for firm business that are not listed in this register?" Unapproved tools must be either added to the register (with appropriate controls) or prohibited.

07 Roles and Responsibilities

Responsibilities scale with firm size. For smaller firms the principal often holds several of these roles; for larger firms they are distributed. A named individual should always be accountable for the firm's use of AI.

Small firm (1–10 advisers)

Role
Responsibilities
Policy owner & AI lead

Overall ownership of this framework; approving new AI tools and use cases; setting the tone for responsible AI adoption; conducting quarterly tool-register reviews.

Compliance oversight

Ensuring AI use aligns with FCA and UK GDPR obligations; reviewing and updating this framework annually; acting as escalation point for AI-related concerns; conducting or commissioning DPIAs where required.

All staff

Reading and adhering to this framework; completing required AI training; reporting concerns, errors or unexpected AI behaviour; not using unapproved AI tools for firm business.

IT / systems

Maintaining the Approved Tools Register; managing technical controls around data access and AI tool integrations; reviewing vendor security and DPA documentation.

Larger firm (10+ advisers)

Role
Responsibilities
Managing Director / CEO

Overall ownership of this framework; approving new AI tools and use cases; setting the tone for responsible AI adoption across the firm.

Compliance Officer

Ensuring AI use aligns with FCA and UK GDPR obligations; reviewing and updating this framework annually; escalation point for AI-related concerns; Consumer Duty monitoring of AI outputs.

AI Champion / Systems Lead

Day-to-day management of AI tools; staff training and support; maintaining the Approved Tools Register; first point of contact for AI questions.

All staff

Reading and adhering to this framework; completing required AI training; reporting concerns, errors or unexpected AI behaviour; not using unapproved AI tools.

IT / Systems Lead

Technical controls around data access and AI tool integrations; vendor security and DPA documentation; shadow AI detection.

Third-party AI vendors

Complying with the firm's data protection requirements; providing DPAs, data residency confirmation, and incident notification.

SM&CR mapping

Under the Senior Managers and Certification Regime, a Senior Manager Function holder should be identified as accountable for the firm's use of AI.

SM&CR function
AI governance responsibility
SMF holder (as applicable)

Accountable for the firm's AI governance framework and its compliance with FCA expectations.

SMF 16 (Compliance Oversight) or equivalent

Responsible for monitoring AI use against Consumer Duty obligations.

08 Incidents, Errors and Reporting

AI tools can produce errors, hallucinations (plausible but incorrect outputs), and biased responses. Staff must treat all AI outputs with professional scepticism and report any issues promptly.

8.1 Incident types and severity

Incident type
Example
Severity
Expected response
Hallucination

AI references a fund, product, or regulation that does not exist.

High

Stop using the output immediately; report to the policy owner; review all outputs from that session.

Data leakage

AI includes another client's data in a document, or client data entered into an unapproved tool.

Critical

Invoke the data-breach procedure; assess ICO reporting within 72 hours; notify affected client(s).

Inconsistency

Same inputs produce materially different outputs on two separate runs.

Medium

Document both outputs; report to the policy owner; pause use of the tool for that task pending investigation.

Bias

AI systematically produces different-quality outputs for certain client demographics.

High

Report to compliance; conduct an equality impact assessment; escalate to the AI vendor.

Vendor breach

AI provider reports a data breach affecting firm data.

Critical

Invoke the data-breach procedure; contact the provider for details; assess ICO reporting within 72 hours.

Near miss

AI nearly produced a harmful output but was caught during human review.

Low

Log the near miss; no escalation required unless a pattern emerges. Near misses indicate controls are working.

8.2 How to report

Incidents should be reported to the policy owner or compliance officer as soon as reasonably practicable. Where there is any possibility of a data breach, the firm's standard data-breach response procedure applies, including assessment of ICO reporting obligations within 72 hours.

8.3 Evidence preservation

When an AI error occurs, staff should:

1. Screenshot the AI output immediately (AI outputs can be ephemeral)

2. Record what inputs were provided to the AI

3. Note the date, time, and which tool was used

4. Save all evidence to a designated location (e.g. the incident log or a shared drive)

This evidence may be required for regulatory purposes, vendor escalation, or internal learning.

09 Staff Training and Awareness

9.1 Training requirements

All staff using AI tools in connection with firm business must:

• Read and acknowledge this framework on joining, and annually thereafter

• Understand the difference between approved and prohibited AI uses

• Know how to identify AI hallucinations and apply appropriate scepticism to AI outputs

• Complete any AI-specific training modules the firm introduces

9.2 Training topics

☐ What AI is and how it works (a non-technical overview appropriate to the role)

☐ The firm's approved uses and hard limits (Sections 02 and 03)

☐ How to review AI outputs critically (hallucination detection, fact-checking, consistency testing)

☐ Data protection: what can and cannot be entered into AI tools (Section 04)

☐ Prompt hygiene: how to get better outputs without exposing sensitive data

☐ Incident reporting: what to do when something goes wrong (Section 08)

☐ Consumer Duty implications of AI use (Section 05)

☐ Tool-specific training for each approved AI tool (Section 06)

9.3 Onboarding

New joiners should receive AI training within their first week, before being given access to any AI tools. This training should be documented as part of the standard onboarding process.

9.4 T&C scheme integration

Where AI tools are used in connection with regulated activities, competence in using those tools safely and effectively should be assessed as part of the firm's Training and Competence scheme. This includes the ability to:

• Review and validate AI-generated outputs before client use

• Identify and escalate AI errors

• Explain AI-assisted outputs in their own words (the "own words" test, Section 5.2)

9.5 Annual attestation

All staff should confirm annually that they have read, understood, and are complying with this framework. This attestation should be recorded alongside existing compliance attestations.

10 AI Documentation Audit Trails

As firms adopt AI for documentation, regulators expect a clear chain of evidence from meeting to final file. This audit trail is what makes AI adoption defensible at file review.

10.1 Minimum record per AI-generated document

Every AI-generated or AI-assisted document saved to the client file should include the following metadata:

Record
Description
Original meeting transcript

The unedited source recording or transcript as captured by the transcription tool.

AI-generated draft with timestamp

The draft as first produced, before any adviser edits.

Record of the adviser's edits

A logged difference between the AI draft and the final document.

Compliance check result

Pass/fail status with percentage score and timestamp (if applicable).

Final approved document

Marked as reviewed and approved by the named qualified adviser, with approval date.

Not all items apply to every document type — meeting notes may not require a compliance-check result, whereas suitability reports should include all five.

10.2 Retention periods

AI transcripts, drafts and reasoning trails form part of the advice file and inherit the retention tier that applies to the advice they document.

Category
Retention period
Regulatory basis

Pension transfers, conversions, opt-outs and FSAVCs

Indefinitely

COBS 9.5.2R

Life policies, personal and stakeholder pensions, DC occupational schemes

Five years

COBS 9.5.2R

Any other case

Three years

COBS 9.5.2R

Firms should define these retention policies in their AI governance documentation before deployment, so storage configurations match regulatory requirements from day one, and update them within 30 days whenever relevant FCA guidance changes.

10.3 Back-office integration

Where AI tools connect directly with back-office systems, structured meeting outputs (including fact-find fields, action items and next steps) should populate the client file without manual re-entry. Confirm with the AI vendor that data flows directly into the back-office system and is stored within UK-based data centres.

11 Escalation Paths

11.1 Mandatory manual review triggers

The following case types require mandatory manual compliance sign-off in addition to any automated AI checks:

☐ Defined benefit pension transfers

☐ Vulnerable client interactions identified during the meeting

☐ Any case where the adviser has overridden an AI-generated recommendation

☐ Clients with complex multi-wrapper arrangements where the AI draft may not capture the full advice rationale

For these cases, any automated compliance check is a floor, not a ceiling. The standard human-in-the-loop review process applies before the file progresses.

11.2 Escalation workflow

When a compliance check flags a failed item or an AI response is queried:

1. The adviser corrects the specific flagged item

2. The compliance tool re-checks the amended document

3. The compliance officer signs off on the revised file

If a document has already been sent to the client before a compliance gap is discovered, the firm's standard advice-error and complaints procedure applies. AI feeds into the existing advice-error process rather than creating a separate escalation track.

12 Policy Review and Version Control

12.1 Review schedule

This framework should be reviewed at least annually — or sooner if triggered by any of the events below — with the next review date recorded.

12.2 Review triggers

An out-of-cycle review should be conducted if any of the following occurs:

1. Publication of Mills Review recommendations

2. Any new FCA guidance on AI in financial services

3. Adoption of a new AI tool by the firm

4. A significant AI-related incident

5. A change in firm size or structure (merger, acquisition, new adviser team)

6. A material change in an existing AI tool's capabilities or terms of service

7. New ICO guidance on AI and data protection

8. A tool in the Approved Register has not been reviewed in 12 months (sunset clause)

12.3 Version control

This is version 1.0 — the initial framework. Each revision should record the version number, date, a summary of changes, and the author.

Appendix A · 30-60-90 Day Implementation Roadmap

Use this roadmap to move from framework to live, operational AI governance. Each phase builds on the previous one.

Day 1–30: Foundation

☐ Designate a named AI governance lead (policy owner)

☐ Complete the Approved Uses checklist (Section 02)

☐ Review the hard limits (Section 03) and add any firm-specific prohibitions

☐ Complete the Approved Tools Register (Section 06) for every AI tool in use

☐ Configure firm templates with your document-generation provider

☐ Establish the baseline documentation time per adviser and per report type

☐ Block unapproved AI tools at the network level where technically feasible

Day 31–60: Integration

☐ Run automated compliance checks on a sample of existing suitability reports to establish baseline scores

☐ Connect meeting-transcription tools to back-office systems and verify structured outputs populate client files correctly

☐ Assign roles and responsibilities (Section 07), including SM&CR mapping

☐ Conduct a DPIA for any High-risk tools (Section 4.5)

☐ Add AI disclosure wording to your Terms of Business (Section 5.3)

☐ Train all advisers and paraplanners on the human-in-the-loop model

Day 61–90: Review

☐ Compare documentation time, compliance scores and adviser adoption rates against the Day 1 baseline

☐ Address any advisers still using unapproved tools and document the intervention

☐ Deliver staff training covering all topics in Section 9.2

☐ Set the quarterly review cycle and assign the next review date to the AI governance lead

☐ Have the framework reviewed by your compliance adviser or network, then formally adopt it

Appendix B · Quick Start Checklist

If the 30-60-90 roadmap is more than you need right now, these ten essentials cover the basics. Aim to complete them within 30 days.

☐ Replace firm details throughout with your firm's information

☐ Complete the Approved Uses checklist (Section 02) for your firm

☐ Review the hard limits (Section 03) and add any firm-specific prohibitions

☐ Complete the Approved Tools Register (Section 06) for every AI tool in use

☐ Assign roles and responsibilities (Section 07), including SM&CR mapping

☐ Conduct a DPIA for any High-risk tools (Section 4.5)

☐ Add AI disclosure wording to your Terms of Business (Section 5.3)

☐ Deliver staff training covering all topics in Section 9.2

☐ Set the review date and diarise it (Section 12.1)

☐ Have the framework reviewed by your compliance adviser or network, then formally adopt it

AI is a powerful tool. Used well, it helps a firm serve clients better, think more clearly, and spend more time on the work that matters most — the human relationships at the heart of good advice.

This framework is not here to discourage anyone from using AI. It is here to make sure it is used with the same care and professionalism that defines everything else a good firm does.

Produced by AdvisoryAI

Serve twice the clients. Give each better advice.

Serve twice the clients. Give each better advice.

✔ Reports from your templates

✔ Reports from your templates

✔ 14-day free trial

✔ No credit card

✔ Reports from your templates

✔ 14-day free trial

✔ No credit card