30th July 2025

Creating an Internal AI Policy for Your Advice Firm

What to consider before advisers and support staff use AI in regulated environments
 
AI tools are becoming part of daily workflows in financial advice firms, whether drafting reports, generating marketing content or summarising client conversations. But before advisers and support staff dive in, firms must set clear boundaries.
 
That’s not just best practice - it’s a regulatory imperative.
 
Why This Matters: The Regulatory Landscape Is Catching Up
 
The FCA hasn’t yet fined any firms specifically for improper use of AI, but the regulator has made its position clear: AI use must comply with existing rules. In a joint discussion paper with the Bank of England, the FCA stated:
 
“Firms remain responsible for ensuring their use of AI complies with existing legal and regulatory requirements, including those relating to governance, accountability, operational resilience and data protection.”
– FCA/BoE Discussion Paper DP5/22
 
This means that any use of AI by regulated firms is already subject to:
  • Principle 2 – skill, care, and diligence
  • Principle 3 – effective governance and risk management
  • Consumer Duty – ensuring all communications (even AI-generated) are clear, fair, and not misleading
  • SMCR – senior managers remain fully accountable for oversight and decision-making around AI use
So while there is no AI-specific rulebook (yet), firms must evidence the same level of compliance, control, and oversight as with any other regulated activity.
 
Meanwhile, across the Atlantic, enforcement has already begun. In 2024, the US SEC fined two firms - Delphia (USA) Inc. and Global Predictions Inc. - a combined $400,000 for “AI washing”: falsely claiming they used AI to power investment decisions when they hadn’t. The case was a clear signal that misrepresenting your AI capabilities is a serious regulatory risk.
 
While the UK has not yet followed with similar action, the FCA has warned that it is closely monitoring AI adoption, especially where explainability, model governance, and third-party dependencies are concerned.
 
In short: AI doesn’t lower the bar for compliance, if anything, it raises it.
 
What Should an AI Policy Include?
 
Once the regulatory context is understood, the next step is putting the right guardrails in place. A good internal AI policy sets out what’s allowed, what isn’t, and who is accountable. Here’s what to include:
 
1. Clarify Permitted Use Cases
 
Start by mapping out which tasks AI can support, and which it can’t. For example:
 
  • Allowed: Drafting internal reports, summarising meeting notes, supporting marketing content (with oversight)
  • Prohibited: Making personalised financial recommendations, interpreting suitability requirements, handling client data directly
Make it clear that AI is a tool to support human judgement, not replace it.
 
2. Address Data Privacy and Client Confidentiality
 
Client data must never be entered into public AI platforms that lack robust UK data protection safeguards.  Ensure all AI use is:
 
  • UK GDPR-compliant
  • Free from data retention for model training
  • Hosted in secure, approved environments
Enterprise-grade or private models offer safer options than free, open platforms.
 
3. Define Oversight and Accountability
 
Advisers remain responsible for outputs, even if AI was used to generate them. Your policy should require that:
 
  • All AI-generated content is reviewed before use
  • No client-facing material is sent without human validation
  • Staff understand who signs off what, and when
Consider mapping this to your SMCR structure.
 
4. Training and Education
 
All staff should receive practical guidance on:
 
  • Which tools they can use
  • How to use them ethically and securely
  • Risks and limitations of AI outputs
  • Case studies of inappropriate use (e.g. AI washing)
Build this into onboarding and CPD frameworks.
 
5. Record-Keeping and Audit Trails
 
If AI tools contribute to advice processes, communications, or investment recommendations, logs and approvals should be retained. This provides a clear audit trail should the FCA request evidence.
 
6. Update Regularly
 
AI is a moving target. Your internal policy must be reviewed quarterly or biannually, with ownership assigned to a nominated compliance lead or governance team.
 
In Summary
 
AI can help firms move faster, scale smarter, and improve consistency, but in a regulated environment, innovation without structure is a risk. The FCA’s stance may still be evolving, but the direction is clear: firms will be held accountable for how they use AI.
 
Now is the time to establish a robust internal policy, before the enforcement begins.
 
Sarah Paul
Chief Operating Officer
Panacea Adviser

Business Development

Registration

Free Registration and CPD

Related Articles_

Business Development Manager 2026: Salary Trends and Industry Insights


Paul Harper Search is proud to present the 2026 BDM Salary Survey an essential resource for BDMs, Strategic Partnership Managers, Telephone Account Managers, and the businesses that employ them across the financial services intermediary distribution market.

Read More

Fidelity Adviser Solutions: Helping clients with their financial wellness


If you’ve ever felt that clients’ money worries run deeper than the numbers, this five part video series from Fidelity Adviser Solutions is for you. Each short session shares practical, real-world ideas you can use straight away to spark better conversations, boost confidence, and make planning feel clearer and more human for you and your clients. Watch now

Read More

Client Centred Advisers: Why money is never just about money


Perhaps one of the most important things to understand about money is that people don’t experience it rationally. They experience it psychologically.

Read More

Login

Not yet registered?

Please complete this form to join our community

Name
Email
Company
Select your role:
Password
Confirm Password