management
Written by

Alan Gurung
Co-Founder & CEO
Sharing links



Last updated •
Summarize with AI
TL;DR: Financial advice firms face a challenge: advisers may use unapproved AI tools for documentation efficiency, potentially creating regulatory exposure. Without a formal AI policy, firms risk losing visibility over which tools staff are using and how client data is being handled. To meet regulatory standards, firms need a formal AI policy that classifies tools by risk level, High, Medium, or Low, and sets clear rules for what each tier is permitted to do. By implementing compliant, structured documentation capabilities within AdvisoryAI's platform, firms can safely reduce documentation time by 50-80% while maintaining the human-in-the-loop oversight that Consumer Duty requires. AdvisoryAI's free AI framework for advice firms gives firms a ready-to-adopt template covering every section of this guide.
If you do not have a written AI policy today, your advisers may already be using public tools like ChatGPT to cut their post-meeting admin. That behaviour can create regulatory exposure under UK GDPR and FCA Consumer Duty frameworks, yet banning AI outright does not necessarily prevent it. A formal policy provides the visibility and controls needed to manage these risks.
AdvisoryAI's research shows 71.9% of UK firms spend one to seven hours producing a single suitability report. Advisers are not trying to cut corners. They are trying to survive a documentation burden that has grown beyond what manual processes can handle. A formal AI policy channels that pressure into a compliant, governed framework rather than letting it create regulatory exposure. This guide gives you the practical, FCA-aligned framework to draft that policy for your firm, and AdvisoryAI's AI framework for advice firms puts that structure into a ready-to-adopt document: purpose and scope, approved and prohibited uses, GDPR controls, Consumer Duty mapping, an approved tools register, roles and responsibilities, incident reporting, audit trail requirements, and a 30-60-90 day implementation roadmap.
Mitigating Firm Risk with AI Usage Policies
FCA Expectations Under Consumer Duty
The FCA's Consumer Duty framework, introduced in July 2023, applies directly to how firms use AI. Under the Duty, firms must act in good faith and avoid foreseeable harm, and that obligation extends to how AI models are designed, trained, and used to influence advice outcomes. The FCA's approach to AI is outcomes-focused, relying on existing frameworks including Consumer Duty, SM&CR, and operational resilience rules rather than prescriptive AI regulations.
The most critical implication for your AI policy is the human-in-the-loop requirement. AI must shift the adviser from author to editor, not replace professional judgment. Every AI-generated output, whether a meeting note, suitability report, or client letter, must be reviewed, edited, and approved by a qualified adviser before it reaches the client.
AdvisoryAI's AI framework for advice firms sets out a practical test for this: before using any AI-generated output with a client, ask whether you could explain the recommendation in your own words without referring to the AI. If the answer is no, the output needs further review. Relying on the AI's say-so does not meet Consumer Duty's professional standards.
Securing Firm Data from Unapproved AI
When an adviser pastes client information into the free consumer version of ChatGPT without appropriate governance, your firm loses control over data residency and retention, and no Data Processing Agreement governs that transfer. The Italian data protection authority levied a €15 million fine against OpenAI in December 2024 for GDPR violations including transparency failures and insufficient age verification, though the decision was subsequently annulled by the Court of Rome in March 2026.
The case remains significant as an illustration of the regulatory scrutiny consumer AI tools attract under European data protection law, and the underlying concerns (no Data Processing Agreement, no confirmed data residency, no safeguards against training on personal data) are the same ones that create exposure for UK advice firms using unapproved tools today.
Managing AI Usage Records and Logs
When AI assists with any part of the advice process, the FCA expects the suitability record to capture the same information regardless of whether a human adviser or an AI tool produced the draft. That means meeting transcripts, generated drafts, and compliance checks all need to be logged, stored, and retrievable.
Evie records and transcribes client meetings via Microsoft Teams, Zoom, or Google Meet, then produces structured notes with action items, a draft follow-up email, and the soft facts that matter most: tone shifts, hesitations, anxieties, and reactions that standard transcription tools miss. Evie connects directly with back-office systems including Intelliflo, Plannr, Curo, and Iress Xplan, populating specific fact-find fields such as personal information, investment details, employment details, and other structured client data fields without manual re-entry. The Intelliflo integration supports structured documentation from meeting to file note, and you can see how Evie generates compliant meeting notes directly from the recording.
Core Components of a Compliant AI Framework
Defining AI Usage for Your Firm
Your policy must define what AI means within your firm's operations. A working definition covers any software that generates, summarises, checks, or classifies content using machine learning models, including AdvisoryAI's meeting notes capability (Evie), suitability report drafting capability (Emma), compliance checking capability (Colin), and general-purpose writing assistants. Evie, Emma, and Colin are capabilities within Atlas, AdvisoryAI's platform, which connects meeting data, documents, client records, and back-office systems in one place. The key operational principle is the author-to-editor shift: advisers and paraplanners review AI-generated drafts, they do not sign off on unreviewed outputs.
Approved vs. Banned AI Software
Not all AI tools carry the same risk. Your policy needs a clear classification system that tells staff exactly which tools they may use, under what conditions, and which are prohibited outright. Tools designed specifically for FCA-regulated advice firms, built on UK data residency, and configured to your firm's own document templates carry a fundamentally different risk profile from general-purpose tools.
Emma generates suitability reports from multiple input sources including meeting notes, fact-finds, LOA pack summaries, ceding information, cashflow modelling outputs, and risk profile assessments, working from your firm's existing templates rather than a standardised vendor format, so your established compliance-checked document structure stays intact. Watch the Emma suitability letter demo to see how template-matching works in practice, and see the Emma feature page for the full breakdown of report types supported. Across all three capabilities, Atlas provides the platform layer, enabling advisers to query meeting transcripts, suitability reports, and client data in plain English and retrieve cited answers across the full client file.
Protecting Client Data in AI Workflows
Any approved AI tool must meet a minimum data security baseline. For UK financial advice firms, that means:
UK data residency: All client data must remain within the UK. AdvisoryAI holds Cyber Essentials certification, stores all data within the UK, and has ISO 27001 in progress.
Data Processing Agreement: A signed DPA should be in place with every AI vendor before any client data is processed.
No model training on firm data: Your vendor contract should confirm that client data is not used to train or improve the provider's models, and that those models run within UK or EEA infrastructure rather than being processed by a third-party provider outside your agreed controls.
Review AdvisoryAI's privacy policy for a detailed breakdown of how client data is handled across the platform.
Monitoring AI Usage for Compliance
A defensible advice file lets a reviewer check every statement back to its source, the record an FCA file review actually needs. Emma cites every statement in a suitability report back to its source document, so the output is verifiable by construction rather than a result the reviewer must take on trust. Atlas reinforces this through Adaptive Thinking, a capability that displays each step of its reasoning as it happens, from analysing the request to searching for a client to loading their profile.
A collapsible thinking block reveals the full step-by-step reasoning behind every response, and the input field locks during processing to prevent accidental duplicate sends. That reasoning persists across sessions, which means Atlas remembers context from previous queries and older conversations remain auditable when files are reviewed. This cross-session memory changes everything: advisers can ask follow-up questions days later without re-entering context, and compliance officers can reconstruct how a conclusion was reached well after the original query. The AdvisoryAI platform walkthrough shows Atlas operating live across meeting data, documents, and back-office records.
Atlas's roadmap includes fund and product research capabilities, alongside DFM and model-portfolio comparison, designed to extend the same cited, auditable approach to investment research within the advice process. Firms should confirm current availability directly with AdvisoryAI.
Defining AI Roles and User Access
Your policy must specify which staff roles can access which AI tools, and those access levels should mirror existing back-office permissions. Atlas supports role-based access controls, so users can only access the synced client data and documents that align with their existing back-office permissions.
How to Classify AI Tools by Risk Level
Table 1: AI Tool Risk Classification
Category | Definition | Review Cadence |
|---|---|---|
High | Processes client personal data or produces client-facing outputs | Quarterly |
Medium | Processes firm data only, no client personal data | Annually |
Low | No data processing, for example general research with no firm-specific inputs | Annually |
Defining Permitted AI Use Cases
Safe and approved use cases for a regulated advice firm include:
Meeting transcription and notes: Recording and transcribing client meetings via approved platforms, with structured outputs pushed to the back office.
Suitability report drafting: Generating first-draft suitability reports using the firm's own templates for adviser review.
Compliance pre-checking: Running automated checks against Consumer Duty and COBS standards before reports leave the adviser's desk.
Document summarisation: Summarising LOA packs, provider summaries, and fact-finds where client data remains within approved systems.
The Evie meeting notes page details how structured outputs populate specific fact-find fields directly in back-office systems. For handling client recording consent within this framework, see our guidance on navigating recording opt-outs.
Red Lines for Firm AI Adoption
The following uses of AI must be explicitly prohibited in your policy:
Autonomous investment recommendations without human review and sign-off
Client-facing documents generated and sent without professional review, regardless of the tool used
Consumer AI tools on personal devices with any client-identifiable information
Personal AI accounts (free ChatGPT, personal Claude, personal Copilot) used for any firm business, even where no client data is involved: all AI use for firm business must go through firm-approved tools
Unrecorded human overrides of AI recommendations: when an adviser adjusts or rejects an AI output, that decision should be documented in the file note
Safeguarding Client Data in Your AI Usage Policy
Meeting GDPR Standards for AI Tools
Every AI vendor your firm uses must have a signed Data Processing Agreement in place before you process any client data through their systems. Under UK GDPR, your firm acts as the data controller and bears responsibility for the lawfulness of processing carried out by vendors. Your policy should require the legal or compliance team to review and sign off on every vendor DPA before onboarding.
Defining Permissible Client Data Inputs
Your policy should include an explicit table specifying what can and cannot be entered into each tool classification:
Data Type | High | Medium | Low |
|---|---|---|---|
Client name and address | Subject to governance controls | None permitted | None permitted |
Portfolio values and fund details | Subject to governance controls | None permitted | None permitted |
Health and vulnerability information | Subject to governance controls | None permitted | None permitted |
Anonymised scenario data | Permitted | Permitted | Permitted |
Generic regulatory questions | Permitted | Permitted | Permitted |
Defining Anonymisation for Advice Records
If advisers use Medium or Low-risk tools for any purpose, your policy should define what anonymisation means in practice: typically removing identifiers such as the client's name, NI number, date of birth, address, employer details, and any portfolio or account identifiers, and replacing them with generic labels such as "Client A" or "Scenario 1." Your compliance team may wish to test samples of anonymised prompts periodically to confirm no PII has been inadvertently included.
Vetting AI Software for Compliance
Use the following checklist when evaluating any new AI tool for firm approval:
UK data residency confirmed with vendor
Data Processing Agreement in place
Vendor commitment that client data will not be used for model training
Role-based access controls aligned to existing back-office permissions
Audit log functionality for all AI interactions
Additional certifications such as Cyber Essentials or ISO 27001 may provide further assurance but are not mandated by the FCA. For High-risk tools, ask the vendor for a fuller security and AI governance due-diligence pack, covering encryption and access controls, sub-processors, incident response, and how the vendor prevents and monitors AI hallucinations, rather than relying on the five checks above alone.
Colin is entirely system-agnostic. It runs 42 automated compliance checks against FCA Consumer Duty requirements and COBS standards on any suitability report, meeting note, or fact-find, regardless of which system produced it. See the Colin compliance checker page for the full breakdown of check categories.
Ensuring FCA Compliance in Your AI Policy
Recording AI Prompts for Audits
When AI contributes to the advice process, the prompt used to generate the output should be logged alongside the generated draft and the final reviewed version. This creates a three-stage audit trail: input, draft, and approved output. Retention should follow the same rule as the underlying advice file under COBS 9.5.2R: indefinitely for pension transfers, conversions, opt-outs and FSAVCs, five years for life policies, personal and stakeholder pensions and DC occupational schemes, and three years for any other case. AdvisoryAI's AI framework for advice firms sets out this retention table in full, so your policy does not need to define it from scratch.
FCA Standards for AI Activity Logs
Your AI activity logs should capture key information including the tool used, the date and time, the user who generated the output, the prompt or instruction provided, the generated output before human review, the reviewed and approved final version, and the name of the adviser or paraplanner who approved it.
Ensuring AI Output Meets FCA Standards
Colin runs 42 automated checks on every suitability report, covering AML documentation, client profiling completeness, risk assessment adequacy (including behavioural bias identification and capacity for loss), recommendation suitability, and report quality. Compliance reports show colour-coded pass/fail status per category with a percentage score, and every failed check includes specific remediation guidance such as "Add AML check documentation" or "Include executive summary with key recommendations."
This happens before the document leaves the adviser's desk, catching inconsistencies at first-line control rather than at audit. Colin is one of the capabilities inside Atlas, alongside Evie and Emma, and sits within the same platform where advisers can query meeting transcripts, suitability reports, and client data in plain English through Atlas's chat layer.
Steps for Firm-Wide AI Policy Adoption
Driving Adviser Adherence to AI Policies
The fastest route to adviser adoption is demonstrating that approved tools are faster than the workarounds advisers have already found. At Brooks Macdonald, advisers reported significant reductions in meeting write-up time in their annual review workflow. When advisers see that an approved tool saves substantial time per meeting rather than adding a compliance step, adherence follows naturally.
Timothy James and Partners achieved a 50% reduction in post-meeting documentation time, with support teams accessing structured notes significantly faster after each meeting, and Finsource Partners reduced time reviewing LOA packs by 80%. These are the numbers that convert a policy mandate into something advisers actively want to use. Alan Gurung, AdvisoryAI's CEO and former financial adviser, explains this directly in his interview with Nick Eatock at Intelliflo: AI will not replace advisers, but it will change how they work.
Essential Training for AI Compliance
Your training programme for AI policy compliance should cover:
Prompt security: What constitutes client PII and why it must never enter a Medium or Low-risk tool.
Output verification: How to review an AI-generated draft against the source transcript or documents, not just for style but for accuracy and FCA suitability standards.
Audit trail procedures: How to log prompts, drafts, and approved outputs in the firm's document management system.
Incident reporting: How to report a suspected shadow AI incident or data breach through the firm's escalation process.
Managing Unauthorised AI Tool Usage
Your policy should establish a clear, non-punitive process for when shadow AI is detected. A graduated response works better than immediate disciplinary action because it preserves trust while reinforcing the boundary:
First occurrence: Mandatory policy refresher and written acknowledgement may be appropriate.
Second occurrence: Compliance officer review and formal written warning may follow.
Third occurrence: Disciplinary process per the firm's HR policy and potential FCA notification if a data breach occurred may be required.
Establishing Your AI Policy Review Cycle
Your AI policy should be reviewed regularly, and more frequently when specific triggers occur. Build the following into the policy document itself:
New FCA guidance publication
Addition of any new AI tool to the firm's technology stack
Any internal incident or near-miss involving AI-assisted documentation
Firms may also wish to review their policy when regulatory enforcement actions involving AI usage occur or when approved vendors make significant changes to their infrastructure.
Navigating AI Policy Compliance and Oversight
Securing Board Buy-In for AI Policy
Build your board business case around operational risk reduction and capacity recovery, not technology features. Jigsaw Tree Research, referenced in AdvisoryAI's whitepaper From Paperwork to Peoplework, shows annual review time dropping by 59.8% and suitability letter time dropping by 65.48% with automated documentation workflows.
Table 2: Manual vs. AI-Assisted Documentation Hours
Workflow Step | Manual Hours | AI-Assisted Hours | Time Saved |
|---|---|---|---|
Post-meeting note writing (Brooks Macdonald) | 2h 30m | 30-minute review | 2h (80%) |
Suitability report generation | 4h 45m | 1h 38m | 3h 7m (65.48%) |
Annual review documentation | 5h 47m | 2h 19m | 3h 28m (59.8%) |
Compliance checking (Colin) | Manual review time varies | Automated, before the report leaves the desk | Significant time reduction |
Present these figures alongside the cost of paraplanning staff (£30,000 to £40,000 per year, per hire) and your current documentation backlog. The board question is not "should we adopt AI" but "what is the cost of remaining manual while our advisers hit a capacity ceiling?" For board members who want to understand the technical foundation, AdvisoryAI's CTO Roshan Tamil Selvan holds a Masters in AI/ML from MIT, and the firm counts Rupert Curtis of Curtis Banks Group among its investors. The advice gap is an operational problem, not a marketing one, and that argument lands well at board level.
How Do We Handle Advisers Already Using ChatGPT?
Do not open with sanctions. Open with a question: "What are you using it for, and what would make an approved tool more useful?" The answer almost always reveals a documentation bottleneck that an approved tool solves faster and more safely than the workaround.
Run a structured transition:
Identify which advisers are using unapproved tools and for which tasks.
Match those tasks to capabilities within approved tools already in the firm's stack.
Run a comparison with one adviser for two weeks, measuring time taken with the approved tool versus their current approach.
Share those results with the wider team before enforcing the prohibition formally.
Drafting Your Firm's AI Disclosure
Your client-facing disclosure should explain that AI tools assist in preparing documentation for adviser review, that no AI-generated output is delivered to clients without professional sign-off, and that the firm maintains UK data residency for all client data processed through AI tools. This disclosure sits naturally within your client agreement or ongoing service documentation. AdvisoryAI's guide to simplifying suitability letters covers how to frame AI assistance in client communications without undermining adviser credibility.
AdvisoryAI's AI framework for advice firms provides ready-to-use wording for both levels of disclosure.
Terms of business: "[Firm] uses artificial intelligence tools to support our advice process. These tools assist with tasks such as meeting transcription, document preparation and compliance checking. All AI-generated outputs are reviewed and approved by a qualified member of our team before they are used in connection with your financial plan. Your data is processed in accordance with our Privacy Notice and applicable data protection legislation."
Individual documents: "This document was prepared with the assistance of AI tools and has been reviewed and approved by [the adviser]."
When to Update Your AI Policy
Beyond regular review cycles, the policy requires immediate revision when the FCA publishes new AI-specific guidance, when an approved vendor changes its data residency or training practices, or when the firm adopts any new AI capability. The FCA's ongoing Mills Review, examining how AI will transform retail financial services, is a named trigger in AdvisoryAI's AI framework for advice firms: the FCA has confirmed it does not plan to introduce AI-specific regulations and will rely on existing principles-based frameworks instead, but any recommendations it publishes should prompt a policy review within 30 days. Building a standing agenda item into quarterly compliance reviews ensures the policy does not drift out of date as the regulatory environment evolves. Alan Gurung discusses this evolving landscape in his conversation with Philip Calvert at LifeTalk.
Policy Readiness Self-Assessment
Rate your firm on each of the following. One point for each "Yes." Four points means your policy is FCA-ready.
Does your firm have a written AI policy that classifies tools by risk level (High, Medium, or Low)? (Yes / No)
Do you have signed Data Processing Agreements with every AI vendor your advisers currently use? (Yes / No)
Does every AI-generated document pass through professional review before client delivery or filing? (Yes / No)
Do you maintain an audit trail of AI-generated drafts, prompts, and approved outputs as part of the client file? (Yes / No)
Score 0-1: Lacking Guardrails. Your firm has significant shadow AI exposure. Download the policy template below and schedule a vendor audit within 30 days. Implement an interim prohibition on unapproved tools while drafting the formal policy.
Score 2-3: Partially Compliant. Your firm has some controls in place but gaps in vendor vetting, audit trails, or human-in-the-loop procedures. Colin's 42 compliance checks close those gaps.
Score 4: FCA-Ready. Your framework meets current regulatory expectations. Focus now on regular review cycles and preparing for evolving FCA AI guidance.
AdvisoryAI lists its pricing publicly. Monthly rolling agreements apply, with a 30-day money-back guarantee and a 10% discount on annual commitments. Start a 14-day free trial (no credit card required) or request a demo to see how Colin and Atlas enforce compliance in your documentation workflow. Or start today with AdvisoryAI's AI framework for advice firms, the free downloadable template this guide is built on.
FAQs
Does the FCA Permit the Use of AI in Generating Suitability Reports?
Yes. The FCA's approach is technology-neutral and outcomes-focused, meaning it does not prohibit AI-assisted documentation. Firms must maintain strict human-in-the-loop oversight, where a qualified professional reviews, edits, and approves every AI-generated output before it reaches the client or enters the file.
What Is the Penalty for an Adviser Using Unapproved ChatGPT in a Regulated Firm?
Using unapproved consumer AI tools can create significant regulatory exposure under UK GDPR if client data is involved, alongside FCA disciplinary action for Consumer Duty failures where advice documentation quality is affected.
How Long Does It Take to Implement an Approved Capability Like Emma?
AdvisoryAI's dedicated team of ex-paraplanners and advisers configures Emma to your firm's exact suitability report templates within two weeks. Firms have successfully scaled their suitability report output using Emma's template-based approach.
Can Colin Check Suitability Reports Generated Outside of AdvisoryAI?
Yes. Colin is entirely system-agnostic. It runs 42 automated compliance checks on any suitability report, meeting note, fact-find, or file note regardless of which platform produced it. See the Colin compliance checker page for the full list of check categories.
What Happens if an Adviser Overrides an AI Recommendation?
When an adviser adjusts or rejects an AI-generated output, that decision must be documented in the client file. Your policy should require a brief note explaining why the human judgment differed from the AI draft, creating an auditable record for FCA supervision.
When Should We Update Our AI Policy Beyond the Annual Review?
Immediate updates are required when the FCA publishes new AI-specific guidance, including any recommendations from the FCA's Mills Review, when an approved vendor changes its data residency or model training practices, when the firm adopts any new AI capability, or when an internal incident or near-miss involving AI-assisted documentation occurs.
Key Terms Glossary
Shadow AI: The use of unapproved AI tools by employees without appropriate governance or compliance oversight.
Human-in-the-loop (HITL): The operational principle that a qualified professional must review, edit, and approve all AI-generated outputs before they are delivered to a client or filed as part of the advice record.
Adaptive Thinking: An Atlas capability that displays the step-by-step reasoning trail behind every AI response, allowing compliance officers to audit how a conclusion was reached and ensuring older queries remain auditable.
Consumer Duty: The FCA regulatory framework implemented in July 2023 requiring UK financial firms to deliver good outcomes for retail customers.
Data Processing Agreement (DPA): A legally binding contract between a data controller and a data processor that should be in place before client personal data is processed by a third-party AI vendor, in line with UK GDPR requirements.
Cyber Essentials: The UK Government-backed minimum cyber security standard developed with the National Cyber Security Centre, designed to prevent the most common internet-based cyber threats. AdvisoryAI holds this certification.

Subscribe to our newsletter
Get an AI summary of AdvisoryAI
For questions or partnerships,
contact us at team@advisoryai.com
For product support, help, contact us at support@advisoryai.com
Solutions
Compare












