management
Written by

Ben Glass
Product Marketing Manager
Sharing links



Last updated •
Summarize with AI
TL;DR: Passing an FCA file review requires moving from retrospective auditing to pre-submission verification. Reviewers assess files against the Investment Advice Assessment Tool (IAAT), the primary framework for investment advice files excluding retirement income and defined benefit transfer advice, looking for personalised justification, complete client profiling, and a clear audit trail linking every recommendation to a specific client need. Consumer Duty adds requirements to evidence value for money and client comprehension. Firms managing documentation quality across multiple advisers face compliance risk when standards vary between advisers, making pre-submission checks essential. Emma builds reports from the firm's own templates, and Colin checks every file at the adviser desk before auditors ever see them.
For operations leaders managing documentation quality across multiple advisers, under COBS 9A, firms are required to evidence ongoing suitability review delivery to clients and document cases where clients decline or do not respond to review offers. Most firms treat compliance as a retrospective activity, discovering gaps after advice is delivered. Firms that consistently pass FCA scrutiny do something different: they build compliance into the documentation process at the adviser's desk before the file leaves the building.
The Mechanics of an FCA Advice File Audit
How FCA Reviewers Assess Suitability
FCA reviewers reconstruct the advice journey from the file, assessing whether documentation can independently support that reconstruction. When documentation gaps exist, the quality of the underlying recommendation may become difficult to demonstrate during review.
Documentation quality operates as a proxy for advice quality. In practice, a recommendation that cannot be traced to a specific, documented client need becomes difficult to defend during review. This matters operationally because 43.3% of UK advisers report that paperwork and admin reduce time devoted to advice itself, which means the files most likely to be under-documented come from advisers already stretched across a full client book. Firms treat source-traceability as the working standard: every recommendation should link back to a specific client statement captured in the meeting record.
FCA Assessment Criteria for Advice Files
The FCA's Investment Advice Assessment Tool (IAAT), first issued on 11 June 2025, is the primary framework reviewers use to grade investment advice files, excluding retirement income and defined benefit transfer advice. The IAAT covers information gathering, suitability of advice, treatment of insistent clients, disclosure obligations, and Consumer Duty adherence. The FCA also uses specialist frameworks for specific advice types, including the Defined Benefit Advice Assessment Tool (DBAAT) for pension transfer cases.
The IAAT's grading logic is unambiguous: according to the FCA's official IAAT guidance, you cannot assess advice as suitable if there is a Material Information Gap, and in this case, you can only conclude that advice is unsuitable. Material Information Gaps may include missing risk assessments, absent investment objectives, or incomplete client profiling. This creates a documentation standard that firms must meet by construction, not by retrospective judgement.
Why Timing Matters in Your Audit Trail
FCA thematic reviews and remediation plans can extend over many months. The operational implication is clear: your internal audit trail must show compliance checks occurred before you delivered advice, not reconstructed afterward.
What FCA Reviewers Check in Every Advice File
Client Fact-Find Completeness
An incomplete fact-find raises immediate compliance concerns. Reviewers look for complete client profiling including identity verification, assessment of whether customers understand the complexity and risks of the recommendation, foreseeable life changes, and health details where relevant to the advice. Under COBS 9.4.7, the minimum suitability report content covers the client's demands and needs, an explanation of why the recommendation is suitable, and any possible disadvantages.
The prior suitability assessment under COBS 9.2 is where investment term, knowledge and experience, attitude to risk, and capacity for loss must be established and documented. Missing relevant information prevents reviewers from confirming the adviser understood the client's full circumstances before recommending anything. The Colin compliance checker flags these gaps before a file closes.
How to Justify Advice File Decisions
Reviewers need a clear, personalised justification for why you chose a specific product or strategy over alternatives. Generic rationales fail. A suitability report stating a pension transfer is suitable without explicitly justifying it against retaining the existing arrangement will not pass IAAT assessment.
The justification should reference documented client objectives, risk profile, and constraints such as tax position and liquidity needs. See how Emma produces personalised suitability letters from firm-specific templates, and watch Emma generate reports using multiple input sources including meeting notes, fact-finds, LOA pack summaries, ceding information, cashflow modelling, and risk profile assessments in practice.
Risk Profiling and Capacity for Loss
The FCA requires firms to distinguish between attitude to risk (ATR), which reflects how a client feels about risk, and capacity for loss, which measures how much capital they can afford to lose without impacting their standard of living. Both require separate documentation, and your recommendation must align with both. Files showing moderate ATR alongside a high drawdown risk portfolio require documented rationale for the deviation, including evidence that you identified and addressed behavioural biases such as overconfidence following strong recent market performance.
Validating Client Product Recommendations
Generic product descriptions fail reviews. Recommendations must be tailored to the individual client's circumstances, and the file must show you considered alternative products or strategies and documented why the chosen recommendation was preferable. For firms with a Centralised Investment Proposition (CIP), the file should still demonstrate how the model portfolio maps to the specific client's documented risk profile and objectives.
Evidence Required for Charge Disclosures
Reviewers require clear, itemised evidence of all charges (initial, ongoing, and product costs) along with documentation of how those charges impact the client's overall return. Vague references to "adviser fees" without specifying amounts, frequency, and total cost over the advice horizon may trigger scrutiny. Under Consumer Duty, the disclosure must also show the client understood what they were paying and why the charges represent fair value.
Auditing Ongoing Advice Records
For ongoing service clients, reviewers look for proof that the annual review took place, that client circumstances were re-assessed, and that the ongoing service proposition remains suitable. Under COBS 9A, firms must also document the offer itself and any follow-up attempts when clients decline or do not respond to review offers. Brooks Macdonald addressed this systematically using Evie for their annual review workflow, reducing meeting write-up time from 2.5 hours to a 30-minute review across 60 advisers and freeing 6,000 hours annually firm-wide.
How to Evidence Consumer Duty in Client Records
Evidence of Consumer Duty Delivery
The FCA's Consumer Duty framework establishes four outcomes: products and services, price and value, consumer understanding, and consumer support. Files must contain evidence of delivery against each relevant outcome for each client. Build this evidence using three checkpoints: document the client's baseline understanding and financial position before advice, map advice fees to specific measurable benefits the client receives, and verify comprehension by recording the client's questions or feedback during the meeting.
The FCA's own review of outcomes monitoring found that some firms collect the right management information but 'could not show how it helped them make decisions or improve customer outcomes,' with unclear audit trails between identified issues, decisions, and actual improvements (FCA, Outcomes Monitoring: Good Practice and Areas for Improvement). The AdvisoryAI AI Framework for Advice Firms maps AI use against the four Consumer Duty outcomes, covering human-review checkpoints and incident management.
Proving Avoidance of Foreseeable Harm
Files must show you actively considered and mitigated risks that could harm the client: tax implications, product lock-in periods, and market volatility exposure. Files must document what you recommended to manage those risks and why that approach suited the individual client's circumstances.
Proving Consumer Comprehension
Suitability reports must be readable by the client, not just defensible to a reviewer. Reports should prioritise upfront summaries that allow clients to understand key recommendations before reading full technical justification, with detailed analysis placed in appendices. Leading with the executive summary is both consistent with FCA expectations for clear communication and a practical way to reduce the risk of clients signing documents they did not understand. The FCA Financial Lives 2024 survey found that just 9% of UK adults received financial advice on pensions or investments in the 12 months to May 2024. See this webinar on suitability report structure for practical guidance.
Core Requirements for FCA Compliant Records
Essential Proof for FCA File Reviews
Every advice file must contain the following as a minimum:
Complete fact-find with no blank sections for required fields
Risk questionnaire documenting ATR and capacity for loss separately
Suitability report referencing the client's specific objectives and circumstances
Itemised fee disclosure covering initial, ongoing, and product charges with client comprehension evidence
Structured meeting notes capturing objectives, circumstances, recommendations, next steps, actions, and soft facts including client anxieties, family dynamics, and health concerns where relevant
AML documentation confirming identity verification
Evidence Requirements for Advice Files
Reviewers require objective evidence: structured meeting transcripts capturing the client's actual words alongside how clients are responding through tone and reactions, signed declarations, or documented questions and responses confirming comprehension. Notes written days after a meeting may carry less credibility than structured notes generated directly from a meeting recording, and firms where documentation delays are systemic carry structural compliance risk that manual processes cannot resolve.
Evie generates compliant meeting notes from client conversations after the meeting, capturing all required fields without relying on adviser recall. Timothy James and Partners reduced post-meeting documentation time by 50% using Evie, with support teams able to access structured notes significantly faster than before.
Proving Client Suitability for the FCA
A reviewer must be able to reconstruct the entire advice journey from the file alone. The chain from client need (captured in the fact-find and meeting notes) through risk assessment to recommendation and charge disclosure must be complete and consistent. Any break in that chain creates doubt about whether the advice was genuinely personalised rather than templated.
Top 5 Mistakes That Trigger FCA Review Failures
Fixing Fact-Find Omissions
Missing client data, particularly health status, partner financial details, and foreseeable life changes, is a common failure trigger in FCA file reviews. Under the IAAT framework, Material Information Gaps may prevent reviewers from assessing advice as suitable. Automated checks that flag incomplete fields before file closure prevent discovery at audit rather than before it.
Fixing Frequent Suitability Report Errors
Generic templates that do not reflect the client's actual voice or objectives fail reviews. A report applicable to any client in a similar risk band does not meet the personalisation standard. Jigsaw Tree Research data, covered in AdvisoryAI's advice capacity whitepaper, shows manual suitability letter production averages 4 hours 45 minutes, reduced to 1 hour 38 minutes with automation, a 65.48% saving. Emma generates reports from the firm's own templates, so established document formats and the compliance-checked structures built around them stay intact. Watch suitability report automation in practice to see how this works across different report types.
Documenting Evidence for FCA Reviews
Inconsistent documentation across advisers is a primary trigger for regulatory scrutiny. Your firm's compliance risk profile tracks your weakest adviser's documentation standards, not your strongest. Three mitigation strategies operations leaders can implement immediately:
Standardise meeting note capture at the point of recording, using structured templates requiring the same fields from every adviser.
Implement automated pre-submission compliance checks on every suitability report before it leaves the adviser's desk.
Conduct regular, system-agnostic spot-checks on all active files, not just those flagged in annual audits.
Closing Gaps in Risk Evidence
When a client's documented risk profile does not match the recommended portfolio, the file must contain clear, specific rationale for the deviation. Without it, the file fails IAAT risk assessment criteria regardless of how reasonable the underlying decision was.
Meeting FCA Standards for Client Notes
Vague notes fail reviews. "Discussed retirement plans" is not an adequate record. Notes must capture objectives, current circumstances, recommendations made, any client concerns, and agreed next steps. Achieving this structure manually across every meeting is difficult and creates the kind of inconsistency that triggers scrutiny. Evie generates structured output directly from meeting recordings, covering all required fields without relying on adviser recall.
Standardising Files for Consistent FCA Compliance
Designing FCA Compliant Templates
Standardisation does not mean losing your firm's unique advice style. Emma builds reports directly from your existing bespoke templates, preserving established document structures while generating consistent output across every adviser. TFP Financial Planning Ltd scaled suitability report output from one to six per day using Emma and Evie together, with a 10% editing rate on generated reports.
Implement Pre-Submission File Checks
Pre-submission compliance checking catches documentation gaps before files reach clients or auditors, not after. Colin delivers this by running 42 automated checks on any suitability report and multi-category checks on fact-finds, producing colour-coded pass/fail verdicts and specific remediation guidance before files leave the adviser's desk. This allows firms to move from spot-checking a sample (commonly around 15% of files) to reviewing 100% of cases before submission. Because Colin is system-agnostic, it works on reports generated by Emma, written manually, or produced in any other system. You do not need to rebuild existing document workflows to apply consistent compliance standards across every file.
The checks cover AML documentation, client profiling completeness, risk assessment adequacy (including capacity for loss), recommendation suitability, and report quality including executive summary presence. Colin completes these checks in approximately five minutes.
Workflow step | Manual time | Automated time (Evie, Emma, Colin) | Operational impact |
|---|---|---|---|
Meeting notes (Evie) | 1.5-2.5 hours | 30-minute review | Notes available to whole team within minutes |
Suitability report (Emma) | 4-6 hours | Under 1 hour | Paraplanner output increases from ~1 to 6 per day |
Compliance check (Colin) | 2 hours or more | ~5 minutes | Pre-submission, not post-audit discovery |
Define Mandatory Advice File Evidence
Operations leaders can set firm-wide rules for what must be uploaded to the back office (Intelliflo, Plannr, Curo, Xplan) before a file is marked as complete. Tying file completion to mandatory field population in the back office, rather than relying on adviser discretion, removes the inconsistency creating compliance risk. AdvisoryAI's Intelliflo integration pushes structured meeting outputs directly into client files without manual re-entry, populating specific fields in the fact-find section including personal information, investment details, and employment details.
Conduct Regular Internal File Audits
Surfacing compliance patterns across your entire book without pulling individual files for manual review changes how internal audits work. Atlas does this by reading meeting data, client records, and documents synced from Intelliflo, Plannr, and Curo, letting you query the whole book in plain English. Atlas is the platform within which Evie, Emma, and Colin operate, meaning meeting outputs, suitability reports, and compliance checks are all queryable in one place in plain English.
Atlas's Adaptive Thinking feature makes its reasoning visible as it works, showing each step of its analysis and keeping reasoning persistent across sessions, so every query is auditable rather than a black-box result. Fund and product research capability is on the Atlas roadmap. Firms interested in this feature should confirm current availability directly with AdvisoryAI. AdvisoryAI is Cyber Essentials Plus certified, undergoes annual Predatech penetration testing, maintains a SecurityScorecard Grade A, and carries £2m cyber insurance.
The Business Case for Automated Pre-Submission Compliance Checking
The economics of manual compliance checking are difficult to justify at scale. Senior compliance officers can carry significant salary costs, and their file review time scales directly with file volume. Colin is available on a monthly rolling agreement with a 30-day money-back guarantee and an annual plan option. Contact AdvisoryAI for current pricing.
Compliance area | Colin's automated check | Output |
|---|---|---|
Client profiling completeness | AML documentation, identity verification, financial literacy, foreseeable life changes | Pass/Fail with specific gap identified |
Risk assessment adequacy | Capacity for loss, behavioural bias identification | Pass/Fail with remediation guidance |
Recommendation suitability | Justification for transfers vs. retaining existing arrangements | Pass/Fail with specific wording guidance |
Report quality | Executive summary presence, recommendation clarity | Percentage compliance score |
62% of investors would welcome more help managing their investments, rising to 68% when reviewing them (FCA Advice Guidance Boundary Review, June 2025), confirming that unmet demand exists but adviser capacity, constrained by documentation workload, is the binding constraint, not client appetite.
Reduce the Paraplanner Bottleneck with Back-Office Integration
Manual documentation is the single biggest bottleneck in the advice chain. When paraplanners wait days for adviser notes, client follow-up stalls and compliance risk increases. Standardising your back-office integration (Intelliflo, Plannr, Curo, Xplan) reduces paraplanner workload and shortens the time from meeting to completed file.
How to Handle FCA Feedback and Required Changes
Addressing Identified File Gaps
When you identify gaps during internal or external review, remediate systematically rather than file-by-file. Categorise each gap by root cause: missing fact-find data, inadequate risk justification, absent charge disclosure, or vague meeting notes. Categorising failures by type lets you identify whether the issue is adviser-specific, template-related, or a process failure across the whole firm.
Action Plan for Compliance Failures
The FCA expects genuine remediation: structural changes to governance, controls, and processes addressing root causes, not just corrected individual files. A workable framework for operations leaders:
Root cause analysis: Identify whether failures are isolated to specific advisers or systemic across your documentation process.
Template review: Check whether your suitability report templates and fact-find structures prompt required information capture or allow gaps to persist.
Process adjustment: Implement pre-submission compliance checks for all files, not just those flagged in the initial review.
Verification: Run the revised process on a sample of historical files to confirm changes address identified gaps before presenting your remediation plan to the regulator.
Tracking Progress on FCA File Findings
Document every remediation step: what you reviewed, what you flagged, and what action you took. This audit trail gives the regulator evidence you acted systematically rather than selectively on feedback. Maintaining structured records of compliance activity over time supports this process without requiring separate manual logs.
FCA Advice File Compliance Checklist
Use this checklist to self-assess your current file review process against the pre-submission verification standard:
Pre-submission checks: Are advice files checked for compliance before they are sent to the client, or only during retrospective audits?
Consistency across advisers: Do you have an automated way to ensure your weakest adviser meets the same documentation standards as your strongest?
Source-traceability: Can an external reviewer trace every recommendation in a suitability report back to a specific, cited client statement in the meeting notes?
Consumer comprehension: Do your suitability reports feature clear, upfront summaries rather than dense technical justification at the front of the document?
Audit trail permanence: Is the reasoning behind every advice decision documented and persisted across sessions for future audits?
Fact-find completeness: Are AML documentation, financial literacy, health details, and foreseeable life changes captured in every file?
Charge disclosure: Does every file contain itemised initial, ongoing, and product charges with documented evidence of client comprehension?
Ongoing service records: Does the file evidence that the annual review was delivered, that client circumstances were re-assessed, and that the ongoing service proposition remains suitable?
Request a demo to see how Colin and Atlas fit your compliance workflow, or start a 14-day free trial with no credit card required. Monthly rolling agreements, a 30-day money-back guarantee, and annual plans with a 10% discount apply across all products.
FAQs
What Is the Scope of an FCA Advice File Audit?
Reviewers typically assess a sample of files per adviser, focusing on suitability, charge disclosures, and ongoing service delivery. Firms are generally asked to provide documents in well-organised, clearly labelled electronic format.
What Triggers an FCA File Failure?
Files fail when they lack personalised justification, contain Material Information Gaps such as missing risk assessments or health details, or fail to disclose itemised charges. Under the IAAT, reviewers cannot assess advice as suitable if there is a Material Information Gap, and can only conclude that advice is unsuitable.
How Long Does an Automated Compliance Check Take with Colin?
Colin runs 42 automated checks on a suitability report in approximately five minutes, producing a colour-coded pass/fail report with a percentage compliance score and specific remediation guidance for each failed check. Colin is system-agnostic and works on any suitability report, not only those generated within AdvisoryAI.
What Is the Difference Between a Desk-Based and an On-Site FCA Review?
A desk-based review relies on the quality of the digital file submitted, making structured, source-traceable documentation important. An on-site review typically allows for adviser interviews alongside file inspection, though the file should still independently support every recommendation.
How Can Firms Automate FCA Advice File Compliance?
Evie captures meeting notes from Teams, Zoom, or Google Meet and pushes structured outputs to your back office, Emma generates reports from your templates with every statement cited to source, and Colin runs 42 pre-submission checks before files leave the adviser's desk. Within Atlas, you can query compliance activity across your whole book in plain English, drawing on the structured outputs each capability produces.
Key Terms Glossary
Investment Advice Assessment Tool (IAAT): The official FCA framework, first issued 11 June 2025, used by reviewers to assess the suitability of financial advice and the documentation quality of advice files. Material Information Gaps under the IAAT result in advice being classed as unsuitable.
Capacity for loss: The measure of a client's ability to tolerate capital losses without impacting their standard of living, distinct from their attitude to risk (ATR). Both must be documented separately, and recommendations must be consistent with both.
Consumer Duty outcomes: The four FCA-mandated outcomes under Consumer Duty: products and services, price and value, consumer understanding, and consumer support. Files must contain evidence of delivery against each relevant outcome at the individual client level.
System-agnostic compliance check: A compliance check that works on any suitability report regardless of the system used to produce it. Colin applies its 42 COBS and Consumer Duty checks to Emma-generated drafts, manually written reports, or documents produced in any other platform.

Subscribe to our newsletter
Get an AI summary of AdvisoryAI
For questions or partnerships,
contact us at team@advisoryai.com
For product support, help, contact us at support@advisoryai.com
Solutions
Compare












