An AI policy for a financial advice firm: five things to write down
The FCA regulates AI through its existing rules, so an AI policy is a governance document, not a technology one. Five sections, and what goes in each.
The Financial Conduct Authority's position on AI is, so far, technology-neutral: it expects firms to apply the rules they already have, the Consumer Duty, the Senior Managers and Certification Regime, operational resilience and outsourcing requirements, to whatever technology they use. There is no AI rulebook to comply with. There is a regulator that will ask how your existing obligations are met when a model is involved.
This is not legal advice, and your compliance consultant should review whatever you write. But a usable AI policy for a small advice firm is five sections, and here is what belongs in each.
1. A register of what runs
Every AI use in the firm, in a table: the purpose, the data it touches, the product and deployment model, the vendor terms, the owner, and the date it was last reviewed. If it is not in the register, it is not sanctioned. Shadow AI is what the register is for.
2. Data classification and where each class may go
Three or four classes are enough: public, internal, client-confidential, special category. For each, which deployment models are permitted: an enterprise API under commercial terms, a model inside your own cloud subscription and region, AI inside the Microsoft tenant, or nothing at all. The point is that "can we use AI with client data?" has an answer that depends on the data, not on the mood of the person asking.
3. Human oversight, written down
Which decisions a model may draft and which a person must make. Suitability, advice, anything with a legal or similarly significant effect on a client: a person decides, with the model's output as an input they can see and override. Record who approved what. This is where the Consumer Duty's outcomes and the data-protection rules on automated decisions meet, and it should be the shortest, clearest section.
4. Third-party risk
A firm remains fully responsible for what it outsources. So: which AI vendors are processors, under which contract, with which sub-processors, and where processing happens. Transfer risk assessments where data leaves the UK. Concentration: the hyperscalers are now designated critical third parties, which is a reminder that dependence on a small number of providers is a resilience question as well as a contractual one.
5. Evidence
What is logged (prompts, retrievals, actions, approvals), where (a store the firm owns), for how long (your retention policy), and who can produce it. A data protection impact assessment for anything touching client data, with the "less risky alternatives considered" section actually filled in. A review cadence.
What the policy is for
Not to slow AI down. To let the firm adopt it with a straight face: to a client, to an insurer, to a network, to the regulator. A firm with these five sections written down and a technology partner who can implement them can say "we use AI, and here is how". A firm without them can only say "we use AI".
Want help with this in your business?
Talk to Foundry — we’ll talk through your situation, no obligation.