management
Written by

Alan Gurung
Co-Founder & CEO
Sharing links



Last updated •
Summarize with AI
TL;DR: AI governance is not about restricting what advisers can use. It replaces risky, unapproved tools with structured, audit-ready documentation that evidences Consumer Duty outcomes from the first meeting note to the final suitability report. A named senior manager owns the framework under SM&CR, every AI draft carries a logged interaction record from transcript to approval, and defined benefit transfers and vulnerable client cases always escalate to manual sign-off. Brooks Macdonald freed 6,000 hours a year across 60 advisers on this model, with meeting write-up time cut from 2.5 hours to a 30-minute review.
When an adviser opens a generic AI tool to draft a meeting note, they do more than save time. They create a data silo with no audit trail, no FCA Consumer Duty alignment, and no firm oversight. Firms using Evie and Emma report reductions of 50% to 80% in suitability report drafting time, but that productivity gain only holds when the AI operates under a structured governance framework. Without one, the compliance risk outweighs the time saving.
This article provides a practical, FCA-aligned governance blueprint for Operations Directors and Heads of Advice at large advice networks, consolidators, and investment management firms. The goal is to eliminate shadow AI, standardise documentation workflows, and establish audit trails that hold up under regulatory scrutiny.
How Governance Secures Your Firm's AI Adoption
The capacity bottleneck in most UK advice firms comes from paperwork, not insufficient client demand. The AdvisoryAI whitepaper shows that 43.3% of UK advisers report admin directly reduces their client-facing time, and 71.9% of firms spend one to seven hours producing a single suitability report. That ceiling caps firm growth.
A structured AI governance framework removes it by replacing manual, error-prone documentation with template-locked, auditable tools. Firms that reduce documentation time can choose to serve more clients with the same headcount, deepen service quality for existing clients, or reclaim strategic capacity for leadership. All three paths require governance first, and establishing that framework before deploying AI removes operational risk while unlocking capacity.
Table 1: Documentation Time and Firm-Wide Impact
Firm | Capability | Before | After | Firm-wide outcome |
|---|---|---|---|---|
Brooks Macdonald | Evie (annual review workflow) | 2.5 hours per write-up | 30-minute review | 6,000 hours freed annually across 60 advisers |
TFP Financial Planning Ltd | Emma and Evie | 1 report per day | 6 reports per day | 10% editing rate on generated reports, full rollout in 7 months |
Finsource Partners | Emma | Not published | 80% less time reviewing LOA packs | Not published |
Timothy James and Partners | Evie | Not published | 50% less post-meeting documentation time | Support teams access notes significantly faster |
The outcomes above come from published case studies at Brooks Macdonald, TFP Financial Planning Ltd, Finsource Partners and Timothy James and Partners. They reflect what structured governance produces: consistent documentation quality across every adviser rather than per-adviser variation.
Table 2: Documentation Time and Cost Comparison, Manual vs AI-Governed
Metric | Manual | AI-Governed |
|---|---|---|
Time per suitability report | 4 hours 45 minutes | 1 hour 38 minutes |
Time per meeting write-up | 2.5 hours | 30-minute review |
Paraplanner cost, per head per month | £2,500 to £3,333 (paraplanner salary allocated) | Evie £99/user/month, Emma £299/user/month, Colin £99/user/month. Bundle pricing available. |
Audit trail completeness | Variable by adviser | Automated, cited |
Aligning AI Tools With Consumer Duty
The FCA's Consumer Duty, effective July 2023, requires firms to deliver good outcomes across four areas: products and services, price and value, consumer understanding, and consumer support. AI tools used in the advice process must demonstrably support these outcomes. The AdvisoryAI compliance blog confirms Consumer Duty requires firms to avoid causing foreseeable harm by act or omission, whether in direct client relationships or through the firm's role in the distribution chain.
The table below maps common AI usage scenarios directly to Consumer Duty requirements.
Table 3: AI Policy Template and Consumer Duty Alignment
AI Use Case | Consumer Duty Requirement | Policy Requirement | Capability |
|---|---|---|---|
Meeting note generation | Consumer understanding | Adviser reviews and approves before client delivery | Evie |
Suitability report drafting | Products and services | Firm templates only, no generic AI formats | Emma |
Pre-submission compliance check | Cross-cutting obligation: avoid causing foreseeable harm | All reports checked before leaving adviser's desk | Colin |
Client book queries | Consumer support | Cited answers only, adviser verifies the source | Atlas |
Annual review documentation | Price and value | Files must evidence what the client received for the ongoing fee | Evie and Emma |
Evie, Emma, and Colin are capabilities within Atlas, AdvisoryAI's intelligence layer. Colin automates 42 checks on suitability reports against COBS and Consumer Duty requirements before a document leaves the adviser's desk, delivering firm-wide consistency rather than depending on individual adviser diligence.
Preventing Compliance Gaps in AI Tools
The most significant compliance risk with AI comes from invisibility, not hallucination. When an adviser cannot see how an AI reached a conclusion, they cannot verify whether the output meets COBS standards or Consumer Duty requirements, and your compliance team cannot verify it either.
Atlas addresses this directly through Adaptive Thinking, released May 2026. Every response shows the step-by-step logic behind the answer, from analysing the request to loading the client profile, so the adviser verifies how a conclusion was reached rather than trusting a black-box output.
Ensuring Compliance in AI Documentation
Consistent document formats are a compliance requirement, not a preference. When different advisers generate suitability reports in different structures, your compliance team spends review time reconciling format rather than auditing content quality, fragmenting your audit trail across document styles.
Emma generates suitability reports, annual review reports, LOA pack summaries, and provider summaries using the firm's own templates, configured by a dedicated team of ex-paraplanners and advisers, typically within two weeks of onboarding, as detailed in AdvisoryAI's comparison with generic AI tools. The firm's established compliance-checked document formats remain intact because Emma works from the existing blueprint rather than building a new structure. Every statement in the generated report is cited back to its source document, giving the reviewing paraplanner or compliance officer a clear evidence trail.
Atlas: The Intelligence Layer
Atlas is the intelligence layer of AdvisoryAI, acting as a Chief of Staff, COO, and co-partner in running the firm's advice operations. Ask a question in plain English and Atlas returns cited answers drawn from meeting transcripts, suitability reports, client files, and back-office data from Intelliflo and Plannr.
Every answer references its source so the adviser can verify the basis before acting on it. Adaptive Thinking makes that reasoning visible as it runs and persists it across sessions, so a compliance officer can retrieve the full logic behind any answer during file review. No competitor offers this capability.
Atlas also reads meeting sentiment and updates back-office fields directly from chat. It remembers client preferences and instructions across sessions, so context compounds and Atlas becomes more useful the longer a firm uses it, the way a good employee does. Fund and product research, Atlas Workflows, DFM and model-portfolio comparison, and Xplan and Curo chat querying are on the roadmap. Firms should confirm current availability directly with AdvisoryAI.
Selecting AI Tools for Advice Operations
Before allowing any AI tool to process client data at your firm, run a structured evaluation covering regulatory alignment, data security, back-office compatibility, and Human-in-the-Loop controls.
Auditability is the thread running through all four. An audit trail in the AI context means preserving the full interaction record, not just the final document. The minimum required fields for each client file are set out in the "Key Metadata for AI Documentation Trails" section below. Evie, Emma, Colin, and Atlas maintain reasoning and audit information so compliance officers reviewing a specific interaction can retrieve the logic used to generate an answer, not just the output itself.
FCA Standards for AI Tool Approval
The FCA's approach to AI remains outcomes-based and technology-neutral, embedding oversight within existing Consumer Duty, SM&CR, and operational resilience rules rather than introducing AI-specific regulation. When evaluating AI tools for firm-wide use, firms should consider: pre-deployment risk assessment aligned with Consumer Duty outcomes, senior manager accountability under SM&CR, documented intervention thresholds, comprehensive audit trails, and third-party resilience documentation where the tool is vendor-provided.
On data security, AdvisoryAI holds Cyber Essentials certification, has ISO 27001 in progress, and stores all client data within the UK.
Managing Regulatory Risk in AI
NIST AI RMF 1.0 organises AI risk management around four functions: Govern, Map, Measure, and Manage. For UK advice firms, this means establishing named accountability for AI outputs, mapping each tool to the specific client interactions it touches, tracking error rates and compliance scores over time, and allocating clear remediation paths when a tool produces a non-compliant draft.
ISO/IEC 42001, the international standard for AI Management Systems, emphasises the need to continually improve the governance framework as tools and regulations evolve. Both NIST AI RMF and ISO/IEC 42001 frameworks align with the principle that Human-in-the-Loop (HITL) oversight is critical for responsible AI deployment. In practice, this means shifting the adviser from author to editor: Emma generates the draft and the adviser reviews, adjusts, and approves. The professional judgment stays with the adviser. Every Emma-generated report requires final sign-off by a qualified adviser before it reaches the client.
Managing Shadow AI and Unapproved Tools
Shadow AI, generic tools like ChatGPT or Otter used without governance, creates three parallel risks: client data processed outside the firm's approved and contracted infrastructure, no audit trail for the advice process, and outputs with no Consumer Duty or COBS checking. Generic AI tools transcribe words but cannot produce an FCA-compliant suitability report in the firm's format, meaning advisers using these tools still face the same manual drafting work afterwards.
A faster, approved tool removes the incentive to use unapproved alternatives. Evie records via Microsoft Teams, Zoom, or Google Meet, captures financial terminology and UK dialects, and pushes structured notes directly into Intelliflo, Plannr, Curo, or Xplan within minutes of the meeting ending. See also client consent and recording opt-outs to understand how to manage edge cases in the meeting capture workflow.
How to Monitor Your AI Implementation
Governance does not end at rollout. The framework needs a post-deployment monitoring cycle tied to the firm's compliance calendar.
30-60-90 Day Implementation Roadmap
Day 1-30 - Foundation: Designate a named AI governance lead. Configure firm templates in Emma and Evie with AdvisoryAI's ex-paraplanner setup team. Establish the baseline documentation time per adviser and per report type. Block unapproved AI tools at the network level where technically feasible.
Day 31-60 - Integration: Run Colin on a sample of existing suitability reports to establish current compliance baseline scores. Connect Evie to back-office systems and verify that structured meeting outputs populate client files correctly. Train all advisers and paraplanners on the HITL model.
Day 61-90 - Review: Compare documentation time, Colin compliance scores, and adviser adoption rates against the Day 1 baseline. Address any advisers still using unapproved tools and document the intervention. Set the quarterly review cycle and assign the next review date to the AI governance lead.
Establishing Internal AI Authority
Every firm deploying AI in client-facing documentation needs a named AI governance lead. In most multi-practice firms, this sits with the Operations Director or a designated Senior Compliance Officer with a direct reporting line to the Board. Their responsibilities include maintaining the approved tools register, reviewing quarterly compliance scores, managing escalation paths, and updating the governance framework when FCA guidance changes. SM&CR holds senior managers accountable for their firm's activities, including its use of technology and AI, so allocate this responsibility explicitly rather than leaving it distributed informally.
Approved Tools Register: Minimum Required Fields
Field | Description |
|---|---|
Tool name | The specific tool or platform approved for use, for example Evie, Emma, Colin, or Atlas |
Responsible owner | Named senior manager accountable under SM&CR |
Data location | Confirmed data residency (for example, UK-based data centres) |
Approval date | Date the pre-deployment risk assessment was signed off |
Next review date | Scheduled quarterly review date assigned to the AI governance lead |
Auditing AI Activity for Compliance
Consumer Duty requires an evidence base that demonstrates good outcomes at file review. Log every AI-generated draft at the interaction level, not sampled.
Colin's compliance reports show colour-coded pass/fail status per category with a percentage score, alongside specific remediation guidance for any failed check. This structure lets compliance officers review a week's worth of reports in a fraction of the time a manual file review requires, and the remediation guidance tells the adviser exactly what to fix rather than leaving them to interpret a generic flag. Each quarter, the AI governance lead should review Colin scores across the adviser team, documentation turnaround times versus the pre-AI baseline, adviser adoption rates for approved tools, and Atlas query logs to confirm cited answers are being verified by advisers before use.
Escalation Paths for AI Risk Issues
Define the escalation path before you need it: when Colin flags a failed check or an Atlas response is queried by a compliance officer, the adviser corrects the specific flagged item, Colin re-checks the amended document, and the compliance officer signs off on the revised file. If a document has already been sent to the client before a compliance gap is discovered, the firm's standard advice error and complaints procedure applies. AI feeds into the existing advice error process rather than creating a separate escalation track.
Creating Audit Trails for AI-Generated Documentation
Key Metadata for AI Documentation Trails
This is the canonical minimum record for every AI-generated document saved to the client file. For Emma-generated suitability reports, the source record may draw on any combination of the following inputs: the meeting transcript, the completed fact-find, LOA pack summaries, ceding scheme information, cashflow modelling outputs, and the client's risk profile. The audit trail should record which inputs were used for each report so the reviewing paraplanner or compliance officer can verify the basis of every statement.
Original meeting transcript: the unedited source recording or transcript as captured by Evie
AI-generated draft with version timestamp: the draft as first produced, before any adviser edits
Record of the adviser's edits: a logged difference between the AI draft and the final document
Colin compliance check result: pass/fail status with percentage score and timestamp
Final approved document: marked as reviewed and approved by the named qualified adviser, with approval date
Retention follows the suitability record tiers in COBS 9.5.2R: indefinitely for pension transfers, pension conversions, pension opt-outs and FSAVCs, five years for life policies and personal, stakeholder or defined contribution occupational pension schemes, and three years in any other case. AI transcripts, drafts and reasoning trails form part of the advice file, so they inherit the tier that applies to the advice they document.
Best Practices for AI Data Storage
Evie connects directly with back-office systems including Intelliflo, Plannr, Curo, and Xplan, pushing structured meeting outputs, including fact-find fields covering personal information, investment details, and employment details populated from the meeting transcript, directly into the client file without manual re-entry. AdvisoryAI stores client data in UK-based data centres.
Cutting Internal Document Sign-Off Time
The sequential bottleneck in most advice firms works like a queue at a single point: paraplanners and support teams cannot begin processing until the adviser submits notes, which typically takes hours or days. Evie removes the wait by making structured notes, including action items, objectives, and next steps, available to the whole team within minutes of the meeting ending. Parallel workflows replace sequential ones, and client follow-up moves from days to hours.
Setting AI Document Expiry Policies
Align AI data retention with FCA record-keeping rules and GDPR. Define these policies in your AI governance documentation before deployment so storage configurations match regulatory requirements from day one, and update them within 30 days whenever relevant FCA guidance changes.
Best Practices for Rolling Out AI to Advisers
Essential AI Policies for Advisers
Keep the adviser-facing policy brief and actionable. Four rules, written for advisers, cover the majority of governance requirements:
Never copy-paste client data into unapproved browser-based tools. Use only firm-approved platforms.
Every AI-generated draft requires your review and approval before it goes to a client or into the file.
Flag any AI output that misrepresents the actual client conversation to your compliance lead within 24 hours.
Use Colin to check every suitability report before submitting it to the paraplanner or compliance team.
When to Trigger Manual Compliance Reviews
Trigger mandatory manual compliance sign-off for: defined benefit pension transfers, vulnerable client interactions identified during the meeting, any case where the adviser has overridden an AI-generated recommendation, and clients with complex multi-wrapper arrangements where the AI draft may not capture the full advice rationale. For these cases, the standard Colin check is a floor, not a ceiling. The pension transfer suitability guidance details specific considerations for high-risk file types.
Standardising AI Records for Compliance
Every adviser in the firm must use the same approved templates in Emma and Evie. Template standardisation makes cross-adviser audit trails meaningful because the compliance team can compare like-for-like documentation rather than reconciling structural differences between advisers. Emma's setup includes advice style and tonality customisation per firm, so standardisation does not mean every adviser sounds identical. Standardisation means every file meets the same structural and evidential standard regardless of which adviser created it. The AdvisoryAI suitability letter guide covers how template customisation works in practice.
The firms most exposed to regulatory risk under Consumer Duty are those that have adopted AI without a governance framework, not those that have adopted it with one. A structured approach to approved tools, HITL oversight, and audit trails does not slow down AI adoption. It is what makes AI adoption defensible when the FCA comes to review your files.
Request a demo to see how it works with your workflow, or start a 14-day free trial. No credit card required. AdvisoryAI runs on a monthly rolling agreement with no lock-in, a 30-day money-back guarantee, and a 10% discount on annual commitment.
FAQs
When should a firm seek Board approval before deploying AI?
Firms should seek Board approval before deploying any AI tool that processes client data or generates advice drafts, particularly when the tool connects directly to core back-office systems or impacts the majority of active client files. The named SM&CR senior manager must sign off on the pre-deployment risk assessment before rollout.
How long must AI audit logs be retained under FCA rules?
Retention follows the suitability record rules in COBS 9.5.2R, which set three tiers: indefinitely for pension transfers, pension conversions, pension opt-outs and FSAVCs, five years for life policies and personal, stakeholder or defined contribution occupational pension schemes, and three years in any other case. AI transcripts, drafts and reasoning trails form part of the advice file, so they inherit the tier that applies to the advice they document.
What is the most effective way to mitigate shadow AI in an advice firm?
Block unapproved browser-based tools at the network level and simultaneously provide advisers with approved, template-locked tools like Evie and Emma that are genuinely faster than the unapproved alternative. Prohibition without an alternative does not eliminate shadow AI use.
What makes AdvisoryAI's model better suited to advice documentation than general-purpose AI?
AdvisoryAI's model was trained on thousands of sample suitability reports by ex-advisers and paraplanners, so it recognises the terminology, document structures, and regulatory standards practitioners use daily. The decisive compliance difference is source-traceability: Emma cites every statement back to its source document, and Atlas makes its reasoning visible through Adaptive Thinking, so every claim in the file is verifiable at review. The platform was ranked number one in the AI-only category for H1 2025 by AdviserSoftware, as featured in FT Adviser.
How does Emma automate suitability report drafting?
Emma generates suitability report drafts using the firm's own templates, configured within two weeks by AdvisoryAI's ex-paraplanner setup team, reducing preparation time by 50% to 80%. Every draft requires a qualified adviser's review and approval before client delivery.
Does Colin check documents created outside AdvisoryAI?
Yes. Colin runs 42 automated checks on suitability reports, plus multi-category checks on fact-finds, regardless of which platform generated the original document.
What does Atlas's Adaptive Thinking mean for compliance audits?
Adaptive Thinking makes Atlas's reasoning visible at each step, from analysing the request to retrieving the source. That reasoning persists across sessions, so a compliance officer reviewing a file weeks after the original query can retrieve the full logic behind any answer, not just the output. A defensible advice file requires every statement to be traceable back to its source, and Atlas supports that standard rather than asking a reviewer to take the output on trust.
Key Terms Glossary
Human-in-the-Loop (HITL): A compliance model where an AI tool generates drafts but a qualified professional must review, edit, and approve every output before finalising or sending it to a client.
Adaptive Thinking: A feature in Atlas that displays the step-by-step reasoning behind an AI response and persists it across sessions, so the reasoning behind any answer can be retrieved at file review.
System-agnostic checking: Compliance checking that works on any document, whether created within the host platform or uploaded from an external system, as Colin does across any FCA-regulated advice file.
Shadow AI: The unauthorised use of generic, unapproved AI tools by advisers or support staff, which exposes sensitive client data to security risks and creates unmonitored documentation with no audit trail or Consumer Duty alignment.
Consumer Duty outcomes: The four FCA-mandated standards requiring firms to deliver good outcomes across products and services, price and value, consumer understanding, and consumer support, with documented evidence that each outcome is being achieved across all client interactions. These sit alongside three cross-cutting obligations: act in good faith, avoid causing foreseeable harm, and enable and support customers to pursue their financial objectives.

Subscribe to our newsletter
Get an AI summary of AdvisoryAI
For questions or partnerships,
contact us at team@advisoryai.com
For product support, help, contact us at support@advisoryai.com
Solutions
Compare












