30th July 2025
Creating an Internal AI Policy for Your Advice Firm
What to consider before advisers and support staff use AI in regulated environments
AI tools are becoming part of daily workflows in financial advice firms, whether drafting reports, generating marketing content or summarising client conversations. But before advisers and support staff dive in, firms must set clear boundaries.
That’s not just best practice - it’s a regulatory imperative.
Why This Matters: The Regulatory Landscape Is Catching Up
The FCA hasn’t yet fined any firms specifically for improper use of AI, but the regulator has made its position clear: AI use must comply with existing rules. In a joint discussion paper with the Bank of England, the FCA stated:
“Firms remain responsible for ensuring their use of AI complies with existing legal and regulatory requirements, including those relating to governance, accountability, operational resilience and data protection.”
– FCA/BoE Discussion Paper DP5/22
This means that any use of AI by regulated firms is already subject to:
- Principle 2 – skill, care, and diligence
- Principle 3 – effective governance and risk management
- Consumer Duty – ensuring all communications (even AI-generated) are clear, fair, and not misleading
- SMCR – senior managers remain fully accountable for oversight and decision-making around AI use
So while there is no AI-specific rulebook (yet), firms must evidence the same level of compliance, control, and oversight as with any other regulated activity.
Meanwhile, across the Atlantic, enforcement has already begun. In 2024, the US SEC fined two firms - Delphia (USA) Inc. and Global Predictions Inc. - a combined $400,000 for “AI washing”: falsely claiming they used AI to power investment decisions when they hadn’t. The case was a clear signal that misrepresenting your AI capabilities is a serious regulatory risk.
While the UK has not yet followed with similar action, the FCA has warned that it is closely monitoring AI adoption, especially where explainability, model governance, and third-party dependencies are concerned.
In short: AI doesn’t lower the bar for compliance, if anything, it raises it.
What Should an AI Policy Include?
Once the regulatory context is understood, the next step is putting the right guardrails in place. A good internal AI policy sets out what’s allowed, what isn’t, and who is accountable. Here’s what to include:
1. Clarify Permitted Use Cases
Start by mapping out which tasks AI can support, and which it can’t. For example:
- Allowed: Drafting internal reports, summarising meeting notes, supporting marketing content (with oversight)
- Prohibited: Making personalised financial recommendations, interpreting suitability requirements, handling client data directly
Make it clear that AI is a tool to support human judgement, not replace it.
2. Address Data Privacy and Client Confidentiality
Client data must never be entered into public AI platforms that lack robust UK data protection safeguards. Ensure all AI use is:
- UK GDPR-compliant
- Free from data retention for model training
- Hosted in secure, approved environments
Enterprise-grade or private models offer safer options than free, open platforms.
3. Define Oversight and Accountability
Advisers remain responsible for outputs, even if AI was used to generate them. Your policy should require that:
- All AI-generated content is reviewed before use
- No client-facing material is sent without human validation
- Staff understand who signs off what, and when
Consider mapping this to your SMCR structure.
4. Training and Education
All staff should receive practical guidance on:
- Which tools they can use
- How to use them ethically and securely
- Risks and limitations of AI outputs
- Case studies of inappropriate use (e.g. AI washing)
Build this into onboarding and CPD frameworks.
5. Record-Keeping and Audit Trails
If AI tools contribute to advice processes, communications, or investment recommendations, logs and approvals should be retained. This provides a clear audit trail should the FCA request evidence.
6. Update Regularly
AI is a moving target. Your internal policy must be reviewed quarterly or biannually, with ownership assigned to a nominated compliance lead or governance team.
In Summary
AI can help firms move faster, scale smarter, and improve consistency, but in a regulated environment, innovation without structure is a risk. The FCA’s stance may still be evolving, but the direction is clear: firms will be held accountable for how they use AI.
Now is the time to establish a robust internal policy, before the enforcement begins.
Sarah Paul
Chief Operating Officer
Panacea Adviser
Business Development
Not yet registered?
Please complete this form to join our community