AI compliance obligations for a multi-family office in the UK

AI compliance obligations for a multi-family office in the UK

4 AI-adoption compliance obligations apply, each cited to primary law.

Serving external families brings the Consumer Duty back in full

Rule: FCA Consumer Duty (PRIN 2A)

What it requires: Because an MFO acts for multiple client families by way of business, it is an authorised firm inside the FCA perimeter and owes the Consumer Duty — to deliver good outcomes and avoid foreseeable harm. An AI tool in the client chain does not lower that standard.

Do this: Test each AI tool in the advice, reporting or client-communications workflow against the four Consumer Duty outcomes and record how you checked it does not create foreseeable harm for any client family.

Source: FCA Handbook, PRIN 2A (Consumer Duty); FCA FG22/5.

Confidence: Sourced

A named senior manager is accountable for the AI across client families

Rule: SM&CR (SYSC 5 / COCON)

What it requires: Under SM&CR, responsibility for the firm's activities must sit with identified senior managers and staff must be competent. Serving multiple families does not spread that accountability across the office; a senior manager remains answerable for each AI tool.

Do this: Name the senior manager accountable for each AI tool used in client work and record it in their Statement of Responsibilities and the firm's governance map.

Source: FCA Handbook, SYSC 5 and COCON; Senior Managers and Certification Regime.

Confidence: Sourced

Keep orderly records of AI-assisted business for every client family

Rule: SYSC 9.1

What it requires: A firm must keep orderly records of its business sufficient for the FCA to monitor compliance, including work carried out with AI tools for each client family.

Do this: Ensure any AI that drafts reports, client emails or meeting notes writes into your retained record-keeping system — input, output and reviewer — against the relevant client family's file.

Source: FCA Handbook, SYSC 9.1 (general record-keeping).

Confidence: Sourced

Run a data-protection impact assessment before high-risk AI processing

Rule: UK GDPR / ICO DPIA

What it requires: Where AI processing is likely to result in a high risk to individuals — profiling client-family members or processing at scale — UK GDPR requires a DPIA before processing begins, and clients must not face solely-automated significant decisions without safeguards.

Do this: Complete a DPIA before putting client-family personal data through a new AI tool, and keep a human decision-maker on any significant client outcome.

Source: UK GDPR Articles 22 and 35; ICO guidance on AI and data protection / DPIAs. (Art 22 automated-decision provisions are reframed as Arts 22A-22D by the Data (Use and Access) Act 2025, in force 5 Feb 2026.)

Confidence: Sourced