We will:
We will:
We provide:
Vendor Assessments
Evaluating compliance issues around AI and other new technology vendors as they are introduced into your ecosystem.
Governance & Oversight Structures
Establishment of internal controls and oversight mechanisms to monitor AI use over time while ensuring your AI use complies with the GDPR, the DUA, safety, and sector-specific regulations.
Regulatory Monitoring
Monitoring and regular reporting on all jurisdictions relevant to your organisation for changes in compliance requirements.
Risk & Impact Assessment
Evaluation of the potential risks of AI systems, including bias, security, and operational impact.
Please reach us here if you cannot find an answer to your question.
Vendor due diligence for AI tools needs to go further than a standard supplier review. The questions below reflect what a well-run FCA-regulated firm should be asking before deploying any AI tool in a client-facing or advice-adjacent context.
On the model itself: What data was the model trained on? Has it been tested for accuracy and bias? What are its known limitations? How does the vendor handle hallucinations or incorrect outputs?
On data protection: Where is client data processed and stored? Is it used to train or improve the vendor's models? What is the vendor's lawful basis for processing personal data? Do they have a Data Processing Agreement in place, and does it meet UK GDPR requirements?
On operational resilience: What is the vendor's uptime guarantee and incident history? What happens to your data if the vendor is acquired, goes into administration, or discontinues the product? Do they meet the FCA's expectations around third-party risk management?
On regulatory awareness: Does the vendor understand the regulatory environment you operate in? Can they provide documentation that supports your own compliance obligations, for example, an explanation of how their model works suitable for inclusion in your governance framework?
On accountability: Who at the vendor is responsible for compliance and data protection? How do they communicate changes to the model that could affect the outputs your firm relies on?
A vendor that cannot answer these questions clearly is not ready to be a supplier to an FCA-regulated firm. Difficulty or vagueness in responding is itself a due diligence finding, and should be documented as such.
The FCA has not published a single definitive checklist, but its expectations are set out in the FCA's paper titled 'The FCA's approach to AI' that explains the HMG' AI Principles and reiterates outcomes- focused approach to the technology and innovation. In practice, a well-governed firm should be able to produce documentation covering the following:
What the tool does and how it works. Not a technical manual, but a clear description of the tool's purpose, the data it processes, and how it produces its outputs. If you cannot explain how a tool reaches its conclusions, that is itself a governance concern.
Why you selected it. Evidence that you conducted appropriate due diligence before adopting the tool, including consideration of its accuracy, limitations, and regulatory compliance.
How you oversee it. The controls you have in place to monitor the tool's outputs on an ongoing basis, including who is responsible, how errors are identified, and what your escalation process looks like.
How it handles personal data. Your lawful basis for processing client data through the tool, where that data goes, whether it is used to train the vendor's models, and how it is protected.
What happens when it goes wrong. Your contingency arrangements if the tool is unavailable, produces inaccurate outputs, or is withdrawn by the vendor.
Firms that cannot produce this documentation are exposed, not just to regulatory risk, but to the practical risk of being unable to defend a client complaint where AI played a role in the advice process.
Yes. Consumer Duty applies to outcomes, not to the method used to deliver them. If your firm uses AI tools to support, inform, or generate advice, whether that's a suitability report writer, a cash flow modelling tool, or an AI-assisted research platform, the Duty still requires you to demonstrate that the outcomes for your clients are good ones.
In practice, this means you remain responsible for the quality of the advice even when AI contributes to it. You cannot delegate accountability to the tool or its vendor. The FCA's four outcome areas, products and services, price and value, consumer understanding, and consumer support, all apply, and your firm needs to be able to show how your use of AI supports rather than undermines each of them.
The most immediate risk area is consumer understanding. AI-generated content, such as suitability letters or client-facing summaries, must still meet the standard of being clear, fair, and not misleading. If a client receives output that was produced or shaped by AI, your firm is responsible for ensuring that content is accurate, appropriate, and tailored to that client's circumstances.
You may need to comply, even if your business is based outside the EU.
The EU AI Act has extraterritorial scope, meaning it applies not only to organisations established within the EU, but also to those outside the EU, including UK organisations, if the AI systems that they use or develop are either placed on the EU market; used within the EU, or produce outputs that affect individuals in the EU. So, if you are a UK company selling your product in the EU, and that product is generated with the help of AI, you are within the scope of the AI Act.
As of 2025, the UK does not have a dedicated AI law in force, unlike the EU’s AI Act. Instead, the UK government has opted for a flexible, principles-based approach to AI regulation, focusing on sector-specific guidance and voluntary frameworks. The UK government continues to promote a light-touch regulatory stance to encourage innovation and investment. The AI Action Plan and pro-innovation framework guide current policy, emphasising adaptability over strict legal controls. It is not certain though that this will remain the case as there have been attempts to introduce more robust legal frameworks. The most recent was the Artificial Intelligence (Regulation) Bill 2025- a Private Member's Bill introduced in the House of Lords.