Every rule you answer to, and how you meet it.
The FCA does not mandate a specific compliance tool for AI-assisted advice. What it does mandate, through the Consumer Duty, SM&CR, SYSC and data protection law, is a standard of evidence, accountability, and oversight that most firms cannot meet with existing systems. This page pairs each Handbook requirement with the specific feature that addresses it, with direct references to FCA rules and guidance.
All FCA references are drawn from the FCA AI Update (2024), the FCA Handbook, and the BoE/FCA AI Survey (2024).
How you evidence it.
The requirements below are the obligations. You meet them with your own controls, mapped to the provisions they satisfy across Consumer Duty, the Senior Managers and Certification Regime, suitability, and systems and controls.
Your controls
You define what the firm does to meet each obligation, and who owns it.
Mapped to provisions
Each control names the provisions it satisfies, across all four frameworks.
Evidence from the record
Signals draw on the reviews and decisions already held, not a separate upload.
Signed assurance
Each period, every control is rated and signed off, and shortfalls become actions.
What is covered.
11 areas where FCA regulation creates obligations for firms using AI-assisted advice, each paired with the feature that addresses it.
Consumer Duty
Data-backed evidence of good outcomes
The requirement
The Consumer Duty requires firms to produce an annual assessment, evidenced with data, of whether they are delivering good outcomes for retail customers. For firms using AI to assist with advice, this means demonstrating, with hard evidence, not just process documentation, that AI-assisted advice actually led to suitable outcomes. A written policy stating "we review AI outputs" is not sufficient; firms need measurable proof.
FCA references
- PRIN 2A, The Consumer Duty
- Requires firms to act to deliver good outcomes for retail customers.
- FCA AI Update, Para 3.43
- "At least annually, a firm's board, or equivalent governing body, should review and approve an assessment, evidenced with data, of whether the firm is delivering good outcomes for its customers."
- PS22/9, Consumer Duty Policy Statement
- Firms must be able to demonstrate that they are meeting the Duty's requirements, including through monitoring data.
The risk
Without structured outcome data, the annual board assessment becomes a box-ticking exercise based on anecdotal evidence. If the FCA challenges it, the firm cannot prove its AI-assisted advice was suitable.
How the platform covers it
The annual Consumer Duty board assessment is produced from the record itself, in one click: a board-ready report with approval, modification, and rejection rates, SLA compliance, reviewer workload, document-type breakdowns, and period-on-period trends, every figure traceable to the advice it came from. Before a new AI use case reaches a client, the firm records a structured Consumer Duty impact assessment across all four PRIN 2A outcome areas, signed off by a senior person, so the same board pack shows each use case was assessed before it went live.
- Annual Consumer Duty board assessment, produced from the record
- A board-ready report with an executive summary and the evidence behind each control
- Approval, modification, and rejection rates over any reporting period
- SLA compliance and average time to completion across every review
- Reviewer workload and coverage, per person
- Document-type and category breakdowns for the board narrative
- Comparison against the previous period, with trend signals
- A Consumer Duty impact assessment for every AI use case, before it goes live
- A versioned assessment template covering the four PRIN 2A outcome areas
- Senior sign-off required, and recorded against the person who gave it
Consumer Duty & Principles
Human-in-the-loop for AI-generated advice
The requirement
While the FCA does not use the phrase "human-in-the-loop," the combined effect of the Consumer Duty, Principle 2 (due skill, care and diligence), and Principle 9 (suitability of advice) creates an effective requirement for human oversight of AI-generated financial advice. AI cannot be the sole decision-maker on suitability, a qualified human must review the advice before it reaches the client. Critically, this review must be evidenced, not assumed.
FCA references
- Principle 2, Skill, Care and Diligence
- A firm must conduct its business with due skill, care and diligence.
- Principle 9, Customers: Relationships of Trust (Suitability)
- A firm must take reasonable care to ensure the suitability of its advice.
- PRIN 2A.2.2R, Consumer Duty (Good Faith)
- Firms must act in good faith toward retail customers, characterised by honesty, fair and open dealing.
- FCA AI Update, Para 3.45
- "Firms that use AI as part of their business operations remain responsible for ensuring compliance with our rules, including in relation to consumer protection."
The risk
If AI-generated advice reaches a client without documented human review and the advice turns out to be unsuitable, the firm has no defence. The FCA will ask: "Who reviewed this? When? What did they check?" Without evidence, the firm is exposed.
How the platform covers it
AI-generated advice is routed to a qualified reviewer before it can reach a client, and it cannot be delivered until a named person has reviewed and approved it. Every review action, opening the document, working through the checklist, annotations, and the final decision, is recorded with a timestamp and the reviewer’s identity, so the whole chain of oversight is preserved and cannot be altered afterwards.
- Automatic routing of AI advice to qualified reviewers
- Reviewer identity verified against the FCA register
- Every review action timestamped and recorded
- Approve, request changes, or reject on every case
- Advice cannot reach a client without review
- Review checklists configurable per document type
- Sensible defaults out of the box, customise only what you need
SM&CR
Senior manager personal accountability for AI
The requirement
The Senior Managers and Certification Regime requires that one or more Senior Management Function holders have overall responsibility for each activity, business area, and management function of the firm. AI use in relation to any of these falls within scope. Senior managers are subject to the Conduct Rule requiring them to take reasonable steps to ensure the business they are responsible for is effectively controlled. This means a named individual is personally liable for AI failures, and they need evidence that controls were in place.
FCA references
- FCA AI Update, Para 3.40
- "The Senior Managers and Certification Regime (SM&CR) emphasises senior management accountability and is relevant to the safe and responsible use of AI."
- FCA AI Update, Para 3.41
- "All Senior Managers in SM&CR firms are required to have a Statement of Responsibilities... They are also subject to the Senior Manager Conduct Rules, including requiring Senior Managers to take reasonable steps to ensure that the business of the firm, for which they are responsible, is effectively controlled."
- SMF24, Chief Operations Function
- Technology systems, including AI, are normally under the responsibility of SMF24.
- SMF4, Chief Risk Function
- Has responsibility for overall management of risk controls, including AI risk exposures.
The risk
When an AI system produces unsuitable advice, the FCA will ask which senior manager was responsible and what steps they took to control the risk. If the answer is "we had a policy" but no evidence of enforcement, the senior manager is personally exposed under the Conduct Rules.
How the platform covers it
A senior manager gets a real-time view of every piece of AI-assisted advice and a registry of every model in use, with the provider, version, and configuration behind each record. Drift detection compares recent outcome rates against a model’s approved baseline and flags material moves in rejection, modification, or annotation rates, graded by severity, so the accountable person can see at a glance which models are running, when each was introduced, and whether its quality is slipping. The record then stands as evidence that the controls were not just written down but enforced.
- A senior manager dashboard with real-time oversight metrics
- A registry of every model, with provider, version, and configuration on each record
- A per-model view: usage, approval rates, and first and last seen
- Drift detection on rejection, modification, and annotation rates against an approved baseline
- Severity-graded alerts when a model starts to misbehave
- A per-model quality timeline, exportable for the regulator
- Which model version produced any given piece of advice
- Evidence that review controls were enforced, not just documented
- Proof that records have not been altered
SYSC & Consumer Duty
Audit trail for AI-assisted decisions
The requirement
The SYSC sourcebook requires firms to have "sound administrative and accounting procedures and effective control and safeguard arrangements for information processing systems." For AI-assisted advice, this means maintaining a complete audit trail of: what data the AI used, which model or system produced the advice, who reviewed the output, what modifications were made, and the rationale for the final decision. This trail must be reliable, meaning it cannot be retroactively altered.
FCA references
- SYSC 4.1.1R, General Organisational Requirements
- "A firm must have robust governance arrangements, which include a clear organisational structure with well defined, transparent and consistent lines of responsibility, effective processes to identify, manage, monitor, and report the risks it is or might be exposed to, and internal control mechanisms, including sound administrative and accounting procedures and effective control and safeguard arrangements for information processing systems."
- SYSC 9.1.1R, Record-Keeping
- A firm must arrange for orderly records to be kept of its business and internal organisation, including all services and transactions undertaken by it.
- FCA AI Update, Para 3.9
- Notes "a range of high-level principles-based rules, as well as more detailed rules and guidance, that will be relevant to a firm's safe, secure and robust use of AI systems."
The risk
Most firms store compliance records in CRM systems, shared drives, and email threads. These records are editable, can be backdated, and cannot be independently verified. In an FCA investigation, the integrity of these records can be challenged, undermining the firm's entire defence.
How the platform covers it
Every record is permanent once written: it cannot be changed, deleted, or backdated. Each one is linked to the record before it, and the whole chain is checked continuously, on a schedule and on demand. If anyone alters a past record, the links stop matching and the firm is alerted. From there an administrator can compare the altered record against its protected backup copy and restore it in one click, and that recovery is itself written to the record, for a complete, tamper-evident history.
- Every record permanent once written, no edits, deletions, or backdating
- Each record digitally signed, so its authorship and integrity can be proven
- Records linked in sequence, so any tampering is obvious
- Continuous integrity checks, on a schedule and on demand
- An alert the moment any record fails verification
- A field-by-field comparison of any flagged record against its protected backup
- One-click restore from the backup copy, senior roles only
- Every recovery recorded, for a complete tamper-evident history
- Independent verification available to any party
- A public verification tool, check any record without an account
Consumer Duty & Vulnerability Guidance
Protecting vulnerable customers in AI interactions
The requirement
The Consumer Duty requires firms to take account of the different needs of their customers, including those with characteristics of vulnerability. The FCA's Vulnerability Guidance expects firms to consider vulnerable consumers at all stages of product and service design, including where the service relies on AI. In practice, this means AI systems must not inadvertently disadvantage vulnerable customers, and where AI identifies potential vulnerability indicators, the interaction should be escalated to a human.
FCA references
- PRIN 2A, Consumer Duty
- Requires firms to take account of the different needs of their customers, including those with characteristics of vulnerability and protected characteristics.
- FG21/1, Guidance for firms on fair treatment of vulnerable customers
- "Firms should implement processes to evaluate where they have not met the needs of vulnerable consumers so that they can make improvements."
- FCA AI Update, Para 3.28-3.29
- "This includes where the product or service is heavily reliant on an AI or data solution. The Guidance sets out that firms should implement processes to evaluate where they have not met the needs of vulnerable consumers."
The risk
AI systems may produce advice that is technically suitable but fails to account for a client's vulnerability, for example, recommending a complex product to someone who has indicated they find financial decisions stressful. If the firm cannot show it had processes to catch this, it breaches the Duty.
How the platform covers it
Advice can be tagged with the FCA's four vulnerability drivers, health, life event, capability, and financial resilience, when it is submitted. Once a case carries a flag, only a specialist reviewer or a senior can pick it up, non-specialists are blocked, and senior sign-off is required to complete the review. The record keeps the full chain, so the firm can show the FCA that a vulnerability was identified, routed to the right person, and given closer oversight.
- Vulnerability flags aligned to the four FG21/1 drivers
- Specialist routing, only a specialist or senior can pick up a flagged case
- Senior sign-off required to complete a flagged review
- A vulnerability view: case volume, outcomes, and what is awaiting sign-off
- Recent flagged cases with their category and status
- A vulnerability handling report for the Consumer Duty assessment
- An evidence trail showing the vulnerability was identified and addressed
Consumer Duty & Fairness
Bias and fair treatment across customer segments
The requirement
The FCA has explicitly stated that firms using AI in ways that "embed or amplify bias, leading to worse outcomes for some groups of consumers" may breach the Consumer Duty. Firms are expected to actively monitor outcomes across customer segments, not just at the point of advice but across the lifecycle, and to be able to demonstrate to the regulator that they are looking for and acting on signs of unfair treatment. The FG22/5 guidance reinforces that fairness is a Duty requirement, not an optional extra.
FCA references
- PRIN 2A, Consumer Duty
- Requires firms to deliver good outcomes for retail customers, including across different customer segments.
- FCA AI Update, Para 3.26
- "Firms using AI technologies in a way that embeds or amplifies bias, leading to worse outcomes for some groups of consumers, might not be acting in good faith."
- FG22/5, Consumer Duty Guidance
- Sets out the FCA's expectations on fairness and good outcomes across customer segments.
- Equality Act 2010
- Prohibition on discrimination based on protected characteristics.
The risk
If outcome rates diverge materially between customer segments and the firm cannot show it was monitoring for that, the FCA will conclude the firm was not acting in good faith. Bias-related complaints are particularly sensitive, they can trigger broader supervisory interest.
How the platform covers it
Approval, modification, and rejection rates are broken down across anonymised customer segments, and any material divergence from a segment's baseline is flagged, with configurable alerts for the worst cases. Monthly trend lines show whether a gap is widening or closing. No personal data is held, the segments are anonymised buckets, so the firm gets the monitoring without the data-protection burden.
- Optional anonymised segments: age band, risk profile, product type, whatever fits
- Outcome rates per segment, side by side
- A flag when a segment moves beyond your threshold
- Configurable rejection-rate alerts
- Monthly trend lines showing whether a gap is widening or closing
- An exportable bias-audit report for compliance review
- No personal data required, only anonymised segment buckets
Transparency & Consumer Duty
Explainability of AI-driven decisions
The requirement
The FCA expects firms to be able to explain the basis of their AI-driven decisions. While the Consumer Duty does not prescribe technical explainability requirements, the obligation to act in good faith (PRIN 2A.2.2R) and to communicate clearly with customers (Principle 7) means firms must be able to articulate why AI-assisted advice was given. A "black box" defence, claiming the firm does not understand why its AI reached a conclusion, is incompatible with the Duty and the suitability requirement under Principle 9.
FCA references
- PRIN 2A.2.2R, Good Faith
- Characterised by honesty, fair and open dealing with retail consumers.
- Principle 7, Communications
- A firm must pay due regard to the information needs of its clients and communicate in a way that is clear, fair and not misleading.
- FCA AI Update, Para 3.34-3.36
- "AI systems should be appropriately transparent and explainable... Related rules under the Consumer Duty on consumer understanding refer to meeting the information needs of retail customers."
- UK GDPR, Articles 13-14
- Data controllers must provide information about automated decision-making, including "meaningful information about the logic involved."
The risk
If a client or the FCA asks why a particular piece of advice was given, the firm needs to explain the reasoning chain. If all they have is "the AI recommended it," they cannot meet the explainability standard.
How the platform covers it
Making the model itself explainable is the AI provider’s job. What the record captures is the human layer of explainability. One click on any piece of advice produces a board-ready report with the full reasoning chain: the submission, every review action, checklist completion (which items, by whom, and when), the reviewer’s annotations, the reason for any change or rejection, engagement metrics, and the proof that the record is genuine and unaltered. Batch export by client reference covers a full-client investigation. When the FCA asks "why was this advice given?", the answer takes minutes, not days.
- A one-click explainability report for any piece of advice
- The full chain, from submission through review to decision and certificate
- Reviewer annotations and rationale, captured verbatim
- The reason for any change or rejection
- Checklist completion: which items, by whom, and when
- Engagement metrics: time on document, scroll depth, read-completion
- Proof that the record is genuine and unaltered
- A report formatted for regulatory correspondence
- Batch export by client reference for a full-client investigation
Data Protection
Automated decision-making safeguards
The requirement
Under Article 22 of the UK GDPR, data subjects have the right not to be subject to decisions based solely on automated processing which produce legal or similarly significant effects. For AI-assisted financial advice, this means firms must ensure that a human is meaningfully involved in the decision, not just rubber-stamping an AI output. The firm must also be able to provide "meaningful information about the logic involved" in the automated processing.
FCA references
- UK GDPR, Article 22
- Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects.
- FCA AI Update, Para 3.32
- "The safeguards on automated decision making under Article 22 UK GDPR... provides data subjects with the right not to be subject to decisions based solely on automated processing."
- FCA AI Update, Para 3.37
- "Data controllers must provide data subjects with certain information about their processing activities, including the existence of automated decision-making and profiling."
The risk
If AI advice is delivered without meaningful human involvement, the firm may breach Article 22. "Meaningful" means the human actually reviewed the substance, not just clicked "approve." Without evidence of the review's depth, the firm is vulnerable.
How the platform covers it
Meaningful human review is enforced: a reviewer has to work through a structured checklist, show genuine engagement with the document (time spent, scroll depth), and give a written rationale for the decision. All of it is recorded, which is the evidence that the human involvement was substantive rather than nominal, exactly what Article 22 requires of a decision that is not solely automated.
- Structured review checklists that require substantive engagement
- Time on document and scroll depth recorded
- A written rationale required for every decision
- Evidence that distinguishes real review from rubber-stamping
- Exportable review-depth metrics for data-protection compliance
Operational Resilience
Operational resilience for AI-dependent services
The requirement
Under SYSC 15A, firms must ensure their Important Business Services remain within impact tolerances under severe but plausible scenarios. If a firm's advice process depends on AI, that AI system supports an Important Business Service. Firms need to plan for: AI model failures, third-party AI provider outages, and situations where AI outputs are unreliable. The advice process must continue to function even when the AI does not.
FCA references
- SYSC 15A, Operational Resilience
- Requires firms to ensure Important Business Services remain within impact tolerances under severe but plausible scenarios.
- FCA AI Update, Para 3.13-3.14
- "The FCA's work on operational resilience, outsourcing and CTPs is also of particular relevance... The requirements under SYSC 15A would include a firm's use of AI where it supports an IBS."
- FCA AI Update, Para 4.4
- "Recent developments, such as the rapid rise of Large Language Models (LLMs), for example, put resilience at the heart of what we do."
The risk
If the firm's AI system fails and they have no way to process, record, or review advice without it, they are operationally exposed. The FCA expects firms to have identified this as a risk and planned for it.
How the platform covers it
Oversight runs independently of the firm's AI system and takes in advice however it was produced. When something does go wrong, unsuitable advice slipping through, a model failure, an SLA breach, a security incident, a structured incident log captures the full lifecycle: severity, category, timeline, root cause, and the remediation actions with owners and due dates. Every status change is recorded, so the regulator gets a tamper-evident timeline. Real-time backup monitoring runs continuously, checking that the primary and backup copies of every record still match.
- Provider-agnostic, works with any AI system or manual submission
- Keeps running if the firm's AI system is unavailable
- A structured incident log: severity, category, root cause, remediations
- A clear status lifecycle from open to closed
- Every status change recorded for a tamper-evident timeline
- Trend and severity views, exportable for a regulatory investigation
- Continuous backup monitoring with integrity checks
- Automated backups, verified against the live record
- Documented recovery-time objectives and failover procedures
Outsourcing & Third Parties
Third-party AI provider oversight
The requirement
The FCA's outsourcing requirements under SYSC 8 require firms to take reasonable steps to avoid undue operational risks when outsourcing critical functions. The 2024 BoE/FCA survey found that a third of all AI use cases are third-party implementations, up from 17% in 2022. Firms using third-party AI to generate advice must demonstrate oversight of those third-party outputs, including monitoring the quality and suitability of the AI's work product.
FCA references
- SYSC 8, Outsourcing
- Requires firms to take reasonable steps to avoid undue operational risks when outsourcing critical functions.
- FG 16/5, Cloud and Third-Party IT Services
- Guidance on firms outsourcing to cloud and other third-party IT services.
- FCA AI Update, Para 3.17-3.18
- Notes concerns about concentration of third-party technology services and risks from Big Tech partnerships.
- BoE/FCA AI Survey 2024
- "A third of all AI use cases are third-party implementations... greater than the 17% we found in the 2022 survey."
The risk
If a firm relies on a third-party AI provider to generate advice and that AI produces unsuitable recommendations, the firm, not the AI provider, is liable. The firm must show it had adequate oversight of the third party's outputs.
How the platform covers it
Every piece of advice passes through the same review and recording, whichever third party produced the AI output. That gives the firm one consistent, verifiable oversight layer across every provider, whether it uses one system or many, and if it changes provider, the audit trail carries on unbroken.
- Provider-agnostic, records advice from any AI system
- The same review standard across every third-party provider
- Advice-quality metrics tracked per provider
- An unbroken audit trail even when you switch providers
- Evidence of third-party output monitoring for SYSC 8
Contestability & Redress
Consumer complaints and redress for AI decisions
The requirement
The FCA requires firms to maintain complaints handling procedures to ensure complaints are handled fairly and promptly, including complaints about AI-driven decisions. If a client challenges the suitability of AI-assisted advice, the firm must be able to reconstruct exactly what happened: what the AI produced, who reviewed it, what was approved, and when. Without this, the firm cannot fairly investigate the complaint.
FCA references
- DISP 1, Complaints Handling
- Rules and guidance on how firms should deal with complaints, including complaints about AI decisions concerning financial services.
- FCA AI Update, Para 3.45-3.46
- "Where a firm's use of AI results in a breach of our rules... there are a range of mechanisms through which firms can be held accountable and through which consumers can get redress."
- FCA AI Update, Para 3.44
- "Where appropriate, users, impacted third parties and actors in the AI life cycle should be able to contest an AI decision or outcome that is harmful."
The risk
Client complaints about AI-assisted advice will increase as AI adoption grows. If the firm cannot reconstruct the full chain of events, from AI output to human review to client delivery, they cannot fairly investigate the complaint, leaving them exposed to FOS referrals and potential redress.
How the platform covers it
The complete chain of custody is preserved for every piece of advice. When a complaint comes in, the firm can retrieve the original advice, who reviewed it and when, what the reviewer decided, any changes made, and the certificate of completion, in seconds. That allows a fair, thorough investigation backed by verifiable evidence. If the complaint reaches the Financial Ombudsman Service, the same tamper-proof pack can be handed over directly, a defensible position that editable records can never provide.
- Instant retrieval of any record by reference or date
- A complete chain of custody from submission to certificate
- Tamper-proof evidence that cannot be disputed
- Exportable case files for a complaints investigation
- Independent verification available to the FOS
- A public verification tool for third-party validation
One platform, 11 regulatory requirements.
The platform does not replace your compliance team. It gives them the infrastructure to prove what they are already doing, with evidence that regulators, auditors, and clients can independently verify.