AI compliance obligations for a multi-family office in the UK
4 AI-adoption compliance obligations apply, each cited to primary law.
Serving external families brings the Consumer Duty back in full
Rule: FCA Consumer Duty (PRIN 2A)
What it requires: Because an MFO acts for multiple client families by way of business, it is an authorised firm inside the FCA perimeter and owes the Consumer Duty — to deliver good outcomes and avoid foreseeable harm. An AI tool in the client chain does not lower that standard.
Do this: Test each AI tool in the advice, reporting or client-communications workflow against the four Consumer Duty outcomes and record how you checked it does not create foreseeable harm for any client family.
Source: FCA Handbook, PRIN 2A (Consumer Duty); FCA FG22/5.
Confidence: Sourced
A named senior manager is accountable for the AI across client families
Rule: SM&CR (SYSC 5 / COCON)
What it requires: Under SM&CR, responsibility for the firm's activities must sit with identified senior managers and staff must be competent. Serving multiple families does not spread that accountability across the office; a senior manager remains answerable for each AI tool.
Do this: Name the senior manager accountable for each AI tool used in client work and record it in their Statement of Responsibilities and the firm's governance map.
Source: FCA Handbook, SYSC 5 and COCON; Senior Managers and Certification Regime.
Confidence: Sourced
Keep orderly records of AI-assisted business for every client family
Rule: SYSC 9.1
What it requires: A firm must keep orderly records of its business sufficient for the FCA to monitor compliance, including work carried out with AI tools for each client family.
Do this: Ensure any AI that drafts reports, client emails or meeting notes writes into your retained record-keeping system — input, output and reviewer — against the relevant client family's file.
Source: FCA Handbook, SYSC 9.1 (general record-keeping).
Confidence: Sourced
Run a data-protection impact assessment before high-risk AI processing
Rule: UK GDPR / ICO DPIA
What it requires: Where AI processing is likely to result in a high risk to individuals — profiling client-family members or processing at scale — UK GDPR requires a DPIA before processing begins, and clients must not face solely-automated significant decisions without safeguards.
Do this: Complete a DPIA before putting client-family personal data through a new AI tool, and keep a human decision-maker on any significant client outcome.
Source: UK GDPR Articles 22 and 35; ICO guidance on AI and data protection / DPIAs. (Art 22 automated-decision provisions are reframed as Arts 22A-22D by the Data (Use and Access) Act 2025, in force 5 Feb 2026.)
Confidence: Sourced