AI compliance obligations for a wealth management firm in the UK

AI compliance obligations for a wealth management firm in the UK

4 AI-adoption compliance obligations apply, each cited to primary law.

AI-assisted service must still deliver good outcomes and avoid foreseeable harm

Rule: FCA Consumer Duty (PRIN 2A)

What it requires: The Consumer Duty requires firms to act to deliver good outcomes for retail customers, including avoiding foreseeable harm and enabling customers to pursue their financial objectives. An AI tool in the wealth-management chain does not lower that standard; the firm owns the outcome.

Do this: Before deploying an AI tool in an advice, portfolio or client-communications workflow, test it against the four outcomes (products and services, price and value, consumer understanding, consumer support) and record how you checked it does not create foreseeable harm.

Source: FCA Handbook, PRIN 2A (Consumer Duty); FCA FG22/5.

Confidence: Sourced

A named senior manager is accountable for the AI you deploy

Rule: SM&CR (SYSC 5 / COCON)

What it requires: Under the Senior Managers and Certification Regime, responsibility for the firm's activities must be allocated to identified senior managers and staff must be competent for their roles. Introducing AI does not diffuse accountability; a senior manager remains answerable for it.

Do this: Name the senior manager accountable for each AI tool in the wealth-management chain and add its use to their Statement of Responsibilities and the firm's governance map.

Source: FCA Handbook, SYSC 24-27 (Senior Managers & Certification Regime, incl. allocation of responsibilities and Statements of Responsibilities) and SYSC 5.1 (competent-employees rule); Code of Conduct (COCON).

Confidence: Sourced

Keep orderly records of AI-assisted business

Rule: SYSC 9.1

What it requires: A firm must keep orderly records of its business and internal organisation, sufficient to enable the FCA to monitor compliance, including business carried out with the assistance of AI tools.

Do this: Ensure any AI that drafts portfolio commentary, suitability reports, client emails or meeting notes writes into your retained record-keeping system, capturing the input, the output and the reviewer, for the applicable retention period.

Source: FCA Handbook, SYSC 9.1 (general record-keeping).

Confidence: Sourced

Run a data-protection impact assessment before high-risk AI processing

Rule: UK GDPR / ICO DPIA

What it requires: Where AI processing is likely to result in a high risk to individuals — for example profiling clients or processing at scale — UK GDPR requires a Data Protection Impact Assessment before processing begins, and clients must not be subject to solely-automated significant decisions without safeguards.

Do this: Complete a DPIA (the ICO template is a fine starting point) before putting client personal data through a new AI tool, and keep a human decision-maker on any significant client outcome.

Source: UK GDPR Articles 22 and 35; ICO guidance on AI and data protection / DPIAs. (Art 22 automated-decision provisions are reframed as Arts 22A-22D by the Data (Use and Access) Act 2025, in force 5 Feb 2026.)

Confidence: Sourced