AI compliance obligations for a single family office in the UK
4 AI-adoption compliance obligations apply, each cited to primary law.
A single family office is generally outside the FCA regulated-activity perimeter
Rule: RAO exclusions / FCA perimeter (PERG)
What it requires: The Consumer Duty and SM&CR apply to authorised firms carrying on regulated activities for clients. An SFO acting only for its own family's capital, not by way of business for third parties, can generally rely on exclusions in the Regulated Activities Order and is not an authorised person — so those conduct regimes do not attach to it.
Do this: Confirm and document that the office acts for one family only and holds no permissions to deal with external clients, and re-check the boundary before taking on any outside capital — external clients pull the office back into the FCA perimeter (and the MFO obligations).
Source: Financial Services and Markets Act 2000 (Regulated Activities) Order 2001; FCA Perimeter Guidance (PERG).
Confidence: Sourced
Run a data-protection impact assessment before high-risk AI processing
Rule: UK GDPR / ICO DPIA
What it requires: Outside the conduct perimeter an SFO still processes personal data of family members, beneficiaries and counterparties. Where AI processing is likely to result in a high risk to individuals, UK GDPR requires a Data Protection Impact Assessment before processing begins.
Do this: Complete a DPIA (the ICO template is a good start) before putting family or beneficiary data through a new AI tool, and keep a human decision-maker on any significant outcome. This duty applies whether or not the office is FCA-authorised.
Source: UK GDPR Articles 22 and 35; ICO guidance on AI and data protection / DPIAs. (Art 22 automated-decision provisions are reframed as Arts 22A-22D by the Data (Use and Access) Act 2025, in force 5 Feb 2026.)
Confidence: Sourced
Keep a person on any significant automated decision and disclose AI use
Rule: ICO guidance on AI & automated decisions
What it requires: The ICO's AI and data-protection guidance requires transparency about AI-assisted processing and meaningful human involvement before a solely-automated decision produces a significant effect on an individual. This binds any organisation processing UK personal data, regulated or not.
Do this: Add an AI-use note where a model interacts with family members or processes their data, and ensure a person, not the model alone, makes any decision that significantly affects an individual.
Source: UK GDPR Article 22 (reframed as Arts 22A-22D by the Data (Use and Access) Act 2025, in force 5 Feb 2026); ICO guidance on AI and data protection (explaining decisions made with AI).
Confidence: Sourced
Keep orderly AI records even without a conduct regulator
Rule: Records & governance (prudential)
What it requires: An SFO has no SYSC 9.1 record-keeping duty, but audit trails still matter for tax, trust and succession governance and to evidence its DPIA and AI-transparency steps. AI drafting or summarising should not happen in an unretained way.
Do this: Point AI tools that draft memos, summarise meetings or process family data at a retained store, capturing input, output and reviewer, so the office can evidence its own governance and UK GDPR accountability.
Source: UK GDPR Article 5(2) (accountability principle); ICO accountability framework.
Confidence: Sourced