Last week, an adviser confided in me that he personally knew of several UK advisers uploading client fact finds straight into ChatGPT. No clear AI governance plan. No compliance process. No audit trail. The client data was flowing across the ocean to US data centres, without the client’ knowledge.

So far, I’ve met three types of advisers when it comes to AI. The first is like the above – charging head-first into the likes of ChatGPT, Claude and other consumer-facing apps, often with little thought to compliance. The second carries on as normal, largely ignoring AI and assumes that the technology has no real impact on their business. 

The third, however, is more thoughtful. They see the potential for AI to transform their business model, but don’t want to leave their staff behind, alienate clients or end up in a compliance nightmare situation.

This approach is absolutely possible, and there are some great firms already doing this (see my First Wealth case study). I also wrote a book about it. The key takeaway is to treat AI like any other outsourced or automated process – using:

  • Named ownership
  • A documented governance framework, and 
  • A clear line of human sign-off before anything reaches a client

Who this is for

If you’re a managing partner or director at a small-medium UK advice firm, you’ve probably had the same thought more than once:

AI could genuinely help me with suitability reports, meeting notes and admin, but I can’t find anything that tells me, in plain terms, what’s actually allowed.

The compliance guidance is minimal, even from the FCA itself. The Mills Review brought a bit more clarity, but didn’t bring in significant reforms. Moreover, a lof the AI guidance on LinkedIn is either US-focused or written by a vendor trying to sell you a piece of software.

You’re not looking for permission to be excited about AI. (If you’re reading this, you already are!). You’re looking for a framework you could show an FCA reviewer or a compliance officer, without flinching.

What the FCA actually expects from AI use

The FCA has repeatedly positioned itself as “technology neutral” when it comes to AI. It’s current focus is on regulating outcomes, not tools.

That means there’s no separate “AI rulebook” waiting to catch you out. What applies is what already applies to any judgement, process or communication that touches a client:

  • SM&CR. The senior manager responsible for a function remains accountable for it. This applies regardless of whether a human, a spreadsheet or an AI model produced the output. Delegating a task to a tool doesn’t delegate the liability. If an AI-drafted suitability report is wrong, that’s the same accountability chain as if a paraplanner had drafted it incorrectly and nobody checked it.
  • Consumer Duty. You need to evidence that AI use is producing good outcomes for clients, not just efficiency for you. That means monitoring outputs, not just deploying a tool and hoping.
  • UK GDPR and data protection. Client data fed into an AI tool needs a lawful basis. It needs to be handled in line with your privacy notice, and needs to sit with a processor whose data handling, hosting location and retention policy you understand. This is where firms trip up fastest – usually because a staff member has quietly started pasting client details into a free consumer AI tool that was never assessed for this purpose.
  • SYSC and record-keeping. You need to be able to show how a decision was reached. An AI tool that produces an output with no audit trail, no version history and no explanation is a record-keeping problem before it’s anything else.

None of this requires you to understand how a large language model (LLM) works. The point is to make the same governance decisions you’d make about any new process: who’s allowed to use it, for what, with what checks, and how you’d prove it if asked.

A practical framework: sort by risk, not by tool

I often meet advisers who treat AI as a single risk category, but it isn’t that simple. You cannot assume: “This adviser tool is compliant, but this AI tool is not”. Rather, you need a framework that categorises AI based on what it can do, what data it can see, where it lives and other factors.

Here is a starting point for building out your own AI compliance framework:

  1. Low risk, internal only. This might include the drafting of internal meeting notes, summarising a document you’ve already written, or generating a first pass at a LinkedIn post. Here, there’s no client data, no client-facing output and no suitability judgement. This can be governed lightly: an approved tools list and a simple usage policy is usually enough.
  2. Medium risk, client-facing but human-reviewed. This is where you start approaching the client – e.g. crafting client communications, first-pass suitability report text and meeting summaries drawn from client conversations. Client data is involved, but nothing goes out the door without a named adviser reading, editing and approving it. This needs data protection sign-off on the specific tool, a documented review step, and a record of who approved what.
  3. High risk, judgement or advice generation. This is where the AI starts touching anything that could be construed as generating the substance of advice, or that removes a human from the suitability decision itself. At this point, it’s best to be conservative. “AI-assisted” needs to mean genuinely assisted, with the adviser’s professional judgement doing the actual work.

Most of the AI Compliance Fears I hear from managing partners collapse once they see their own use cases sorted this way.

That suitability report drafting they’re excited about? It’s most likely medium risk, not high risk – and it’s entirely manageable with the right review step built in.

The technical bit that isn’t actually technical

If you’re on Intelliflo, Xplan or a similar UK-specific back-office system, the AI question usually isn’t “can I connect a tool to my CRM,” it’s “should I, and under what terms.”

Direct integrations exist for some workflows, and Microsoft 365 environments can usually be connected through Azure-based tooling. However, OneDrive’s permission structure often needs a proper workaround rather than a plug-and-play connector.

None of this requires you to write code. It requires someone who understands both the compliance boundary and the integration path to make the connection safely, which is a specification and oversight job, not an engineering one.

The false belief this creates

Yes, there are compliance risks to an adviser using AI. But the false belief is to assume the safe option is to do nothing: no policy, no approved tools, wait until the picture is clearer.

That’s backwards. The actual risk in most small advice firms right now isn’t AI adoption, it’s ungoverned AI use that’s already happening.

Staff are already pasting client details into ChatGPT on their personal accounts. After all, it’s useful and nobody told them not to. A firm with no AI policy doesn’t have less AI exposure than a firm with one. It has the same exposure, minus the audit trail.

The safe path isn’t avoidance. It’s a documented framework that names what’s allowed, what isn’t, and who signs off on what, before you roll anything out further.

That’s a governance exercise, not a technical one,. And it’s exactly the kind of decision a managing partner is already equipped to make.

Best Practices for Ethical and Compliant AI Adoption

I’ve seen advisers rush into AI adoption only to backtrack months later when compliance issues surface. The pattern is always the same: they skip the foundations.

Start with clear governance. Document every AI tool your firm uses, who has access and what client data flows through it. Build incrementally. Layer your intelligence architecture before attempting advanced automation like RAG pipelines. Quick wins matter, but sustainable infrastructure matters more.

Bring your team along deliberately. The best AI implementation I’ve seen included monthly team workshops where staff could voice concerns and shape how tools were deployed.

Finally, avoid vendor lock-in. Prioritise tools with strong API capabilities that let you build intellectual property within your own practice rather than renting someone else’s black box forever.

Invitation

Curious to know where your advice firm sits right now in the profession’s Great AI Transition?

Take our AI Transition Diagnostic – six questions, two minutes. It’ll give you a great starting insight into where your firm currently stands.

FAQs

Can I use ChatGPT or other public AI tools with client data?

No, not without significant risk. Public AI platforms may use inputs to train their models, which creates data protection breaches under UK GDPR. You need enterprise versions with contractual guarantees that client data won’t be retained or used for training, plus documented processes showing how you maintain oversight of any AI-generated outputs.

What’s the biggest compliance mistake advice firms make with AI?

Failing to maintain audit trails. The FCA expects you to demonstrate how AI-generated content was reviewed, approved and quality-controlled before reaching clients. Most firms can’t show that chain of accountability because they’ve bolted on AI tools without updating their compliance documentation or workflows.

How long should AI implementation take for a small advice firm?

Plan for 6-12 months if you’re building properly. That gives you time to establish governance, pilot tools in controlled environments, train your team and layer capabilities incrementally. Firms that rush implementation in 4-6 weeks typically face compliance issues or staff resistance that force them to backtrack anyway.

Should I wait for FCA-specific AI guidance before adopting these tools?

No. The FCA has been clear that existing regulations around Consumer Duty, data protection and record-keeping already apply to AI. Waiting for specific AI rules means falling behind competitors who are building compliant systems now. Focus on demonstrating human oversight, maintaining audit trails and ensuring data security within current regulatory frameworks.