There is a persistent misunderstanding among smaller advice firms about AI regulation in the UK: that because the FCA has not published an AI rulebook, AI use is somehow ungoverned until one arrives. The opposite is true. The FCA has been explicit that it does not plan to introduce extra regulations for AI, relying instead on its existing framework — Consumer Duty, the Senior Managers and Certification Regime, the SYSC sourcebook and the rest [1]. The logic, set out in its April 2024 AI Update and maintained since, is that AI is a technology, not a regulated activity: the obligations that apply when your firm uses AI are the same ones that apply to everything else it does [2].
That position has consequences. There is no future compliance date to wait for. If an adviser in your firm is using a large language model to draft suitability reports today, your regulatory obligations for that activity crystallised the moment they started. The question is not “what will the AI rules say?” but “which of our existing obligations does this tool now touch, and can we evidence that we are meeting them?”
This piece maps that question out for UK IFAs and wealth managers: five governance controls, each anchored to the regulatory hook that demands it. It is a companion to my broader piece on automation governance for regulated firms; this one is specifically about AI in UK advice businesses.
A brief note on where the landscape sits in mid-2026. The FCA’s AI Lab is running: the Supercharged Sandbox completed its first cohort (showcased in January 2026) and opened a second, and AI Live Testing is into its second cohort [3][4]. In January 2026 the FCA also reportedly launched a longer-term review into how AI could reshape retail financial services. None of this changes the core position — no bespoke rulebook — but commentary around the review suggests firmer guidance on how Consumer Duty and SM&CR apply to AI may follow. Firms with proportionate governance already in place should find it confirms what they are doing rather than upends it.
Consumer Duty: the hook for outcomes evidence
The Consumer Duty is outcomes-based, and that framing fits AI uncomfortably well. It does not matter to the FCA whether a poor outcome came from a tired adviser or a confabulating model — the firm owns the outcome either way. All four Duty outcomes apply to AI-assisted work, and consumer understanding bites hardest: if an AI tool drafted the explanation a client received, the firm must still be able to show the communication was likely to be understood by that client.
The control this demands is outcomes monitoring that covers AI-assisted work specifically. For an advice firm, that means:
- Knowing which client-facing outputs involved AI at any stage — you cannot monitor what you have not tagged.
- Reviewing a meaningful sample of AI-assisted outputs against the same suitability and clarity standards you apply to human work. There is a reasonable industry argument that AI-assisted output warrants a higher sampling rate, because errors can be systematic rather than idiosyncratic — one bad prompt template can misfire across every client it touches.
- Feeding what you find into the Duty’s annual board-level outcomes assessment, where AI-assisted processes should appear as a distinct line of enquiry, not be silently absorbed.
Ten years in advice and banking operations taught me that firms are generally good at doing the work and poor at proving they did it. The Duty inverts the burden: the absence of evidence of good outcomes is itself the finding.
SM&CR: the hook for a named accountable owner
Under SM&CR, accountability for outcomes sits with a named senior manager whose Statement of Responsibilities covers the relevant area — and it does not transfer to a model, a vendor or “the system”. The FCA has not created a dedicated senior management function for AI and has said it does not intend to; responsibility sits within the existing regime [1]. FCA executives have reportedly been blunt in Parliamentary evidence during 2026 that individuals remain “on the hook” for consumer harm caused through AI.
The control is straightforward to state: one named senior manager owns AI use, and their Statement of Responsibilities reflects it. In a 5–30 person firm this will usually be the SMF16 (compliance oversight) or an SMF3/SMF1 who already owns operations — the point is not a new role but making an existing one explicit. To discharge the “reasonable steps” expectation, that person needs:
- A current inventory of AI tools in use — including the unofficial ones. Advisers pasting client details into consumer chatbots is a live risk in every firm I have seen, and a data protection incident waiting to happen as much as a conduct one.
- Approval authority: new AI use cases go through them before adoption, not after.
- Sight of the outcomes monitoring described above, on a defined cadence.
The uncomfortable corollary: a senior manager who cannot describe what AI their firm uses and how it is checked is not in a strong position to demonstrate reasonable steps if something goes wrong.
UK GDPR and the DUAA: the hook for DPIAs and automated-decision safeguards
Data protection is the one area where the law itself — not just guidance — has recently changed. The Data (Use and Access) Act 2025 reformed the UK’s automated decision-making regime: the old Article 22 of UK GDPR, effectively a prohibition with narrow exceptions on solely automated decisions with significant effects, has been replaced by new Articles 22A–22D, which permit such decisions for most personal data subject to safeguards — meaningful information about the decision logic, the ability to obtain human intervention, and the right to contest. Commentary records the new regime taking effect in early February 2026, with the ICO consulting through spring 2026 on updated guidance and a statutory code of practice on AI and ADM in preparation. The direction is more permissive, but the safeguards are now the compliance surface.
Two controls follow. First, a DPIA for any AI processing of client personal data — advice-firm client files contain financial, health and family information, and AI processing of them will almost always meet the threshold where a DPIA is required. The ICO’s recurring criticism of the DPIAs it reviews is that they are generic; one that names the specific tool, data fields, vendor retention behaviour and lawful basis is worth doing, and one that could describe any firm’s use of any tool is not.
Second, an honest classification of where your AI sits on the automation spectrum. Most advice-firm AI use in 2026 is assistive — drafting, summarising, transcribing — with an adviser genuinely reviewing the output, which keeps it outside the solely-automated regime. But “a human clicks approve” is not meaningful human involvement, and the ICO has signalled attention to rubber-stamping. If the human check has drifted to nominal, the Articles 22A–D safeguards are engaged whether you have documented them or not.
SYSC and operational resilience: the hook for vendor due diligence and incident response
Nearly every advice firm consumes AI as a third-party service, which places it squarely in existing outsourcing and operational-resilience territory. SYSC’s outsourcing provisions and the FCA’s operational resilience framework expect firms to understand material third-party dependencies, perform due diligence, maintain oversight, and plan for failure [5]. At the systemic level, the critical third parties regime now allows major technology providers to be designated for direct regulatory oversight [6] — a signal of how seriously regulators take concentration in a handful of AI and cloud providers.
Scaled to an advice firm, the controls are:
- Proportionate vendor due diligence before adoption. Where does client data go, is it used for model training, where is it stored, what certifications does the vendor hold, what happens on exit? For an AI vendor, add: what model underlies the product, and what happens to your workflow when the vendor swaps it?
- AI failure in your incident thinking. If a tool that has become load-bearing for your advice process fails — an outage, a model update that degrades output quality, a vendor security incident touching client data — what does the firm do that week? If AI supports anything you would consider an important business service, “severe but plausible” failure scenarios should include it.
- Concentration awareness. If the same underlying provider sits behind your transcription tool, your report writer and your CRM’s new AI features, one upstream incident hits all three.
This is one area where being small helps: a 15-person firm can genuinely know every vendor it depends on — more than most banks can say.
Record-keeping: the hook for an audit trail of AI-assisted outputs
The FCA’s record-keeping rules were written long before generative AI, and they need no amendment to cover it. SYSC 9 requires orderly records sufficient for the FCA to monitor compliance, and COBS 9A requires suitability records to be retained — for at least five years — in a form the FCA can access, reconstitute, and inspect for changes and amendments [7][8]. The suitability record must show what the client told you, what you recommended and why — regardless of whether a human or a machine produced the first draft.
The control is an audit trail capturing the AI’s role in each client-facing output: which tool was used, what it produced, what the adviser changed, and who approved the final version. If you cannot trace the path from client information, through AI output, through adviser review, to the record the client relies on, the suitability evidence chain has a gap in it — and that is a firm problem, not a technology problem. Most firms can get 90% of this from tools they already have: version history in the document system plus a one-line client-file entry noting AI involvement and reviewer. The discipline is doing it every time, not building anything sophisticated.
A right-sized governance pack for a 5–30 person firm
Everything above can be run by a firm with no risk department and no GRC budget. A proportionate pack — perhaps eight to twelve pages in total, reviewed annually and after any significant new tool — looks like this:
- AI register (one page). Every tool in use, its purpose, the data it touches, the vendor, and whether it is client-facing. Reviewed quarterly; anything not on it is not approved.
- AI use policy (two to three pages). Approved tools and uses; prohibited uses (client personal data in unapproved consumer tools, unreviewed AI output reaching clients); the review-before-use rule; how staff propose new uses.
- Named owner. One senior manager, Statement of Responsibilities updated, approval authority documented in the policy.
- DPIA(s) for tools processing client personal data — specific, not generic — plus a privacy-notice line reflecting AI processing.
- Vendor due-diligence notes (one page per material vendor) covering data handling, training use, exit, and the underlying model. Refreshed at renewal.
- Monitoring record. A simple log of sampled reviews of AI-assisted outputs, findings and fixes — your Consumer Duty outcomes evidence, feeding the annual board assessment.
- Audit-trail convention. The agreed note format recording AI involvement and reviewer on each client-facing output, so your COBS 9A records tell the whole story.
- A two-paragraph incident playbook: what the firm does if a material AI vendor fails or an AI-related data incident occurs, and who calls the ICO if notification thresholds are met.
That is the whole programme. It is deliberately not an enterprise framework — model risk committees, red-teaming schedules and algorithmic ethics boards solve problems a 12-person IFA does not have. What the FCA’s principles-based approach asks of a small firm is proportionate, evidenced control by named humans; what it will not accept is the absence of all three.
Firms advising clients across borders have a further layer to think about — the EU AI Act and other regimes do take a rulebook approach. I cover that in the companion piece on AI governance for international financial advisers.
This article is for informational purposes only and does not constitute regulated financial advice, legal advice, or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.
Sources
[1] Financial Conduct Authority, ‘AI and the FCA: our approach’, updated 13 February 2026. Available at: https://www.fca.org.uk/firms/innovation/ai-approach
[2] Financial Conduct Authority, ‘AI Update’, 22 April 2024. Available at: https://www.fca.org.uk/publication/corporate/ai-update.pdf
[3] Financial Conduct Authority, ‘AI Lab’. Available at: https://www.fca.org.uk/firms/innovation/ai-lab
[4] Financial Conduct Authority, ‘Supercharged Sandbox’. Available at: https://www.fca.org.uk/firms/innovation/supercharged-sandbox
[5] Financial Conduct Authority, ‘Outsourcing and operational resilience’. Available at: https://www.fca.org.uk/firms/outsourcing-and-operational-resilience
[6] Bank of England / PRA, ‘PS16/24 — Operational resilience: Critical third parties to the UK financial sector’, November 2024. Available at: https://www.bankofengland.co.uk/prudential-regulation/publication/2024/november/operational-resilience-critical-third-parties-to-the-uk-financial-sector-policy-statement
[7] FCA Handbook, ‘SYSC 9.1 — General rules on record-keeping’. Available at: https://www.handbook.fca.org.uk/handbook/SYSC/9/
[8] FCA Handbook, ‘COBS 9A.4 — Record keeping and retention periods for suitability records’. Available at: https://www.handbook.fca.org.uk/handbook/COBS/9A/4.html