TFAS Compliance Services has been running a TechForward programme over the last few weeks and, as part of the programme, has sought adviser input, in particular around their experience of AI and technology adoption.
The headline findings are positive: advisers are engaged, open-minded, and increasingly comfortable using AI in their business. Early indications from TFAS insight suggested that 55% of advisers are already using AI, or planned to, with the most common use being to summarise client meetings. Further insight revealed that 40% of advisers felt AI is having, or would have, a positive impact, and those that didn’t, in the main, said they simply didn’t know at this stage.
So, the tension for advisers isn’t willingness, it’s choice, with firms saying they often feel overwhelmed by the sheer volume of tools now available, and unsure which to trust.
That uncertainty isn’t just a procurement headache, as it reflects a deliberate regulatory vacuum. The FCA won’t be publishing a list of approved tools or an AI rulebook to help firms choose. Chief executive Nikhil Rathi has repeatedly made the point that the technology moves too fast, reportedly every three to six months, for bespoke rules to keep pace. So, the “which tool do I trust” decision advisers are wrestling with is, in the FCA’s eyes, no different from any other business decision - firms remain responsible for the outcomes either way.
Instead, the FCA is doubling down on its existing, outcomes-focused approach: firms are expected to meet the same standards, under Consumer Duty and SMCR, whether a decision is made by a person, or informed by a machine.
That “same rules apply” stance sounds reassuring, but in practice, it puts more pressure on firms, not less. There’s no new checklist to follow, which means the burden of proof sits with advice firms to demonstrate, in the same language the FCA already uses, that their use of AI is well governed.
The FCA’s ongoing Mills Review, launched in January to examine how AI could reshape retail financial services, looked at questions firms should already be asking themselves: how SMCR accountability works when AI performs functions that sit with a named individual, and where the line falls between regulated advice and guidance when AI tools are involved in the client journey. Parliamentary scrutiny has pushed further, with MPs pressing regulators on bias, concentration risk and reliance on third-party providers, areas the FCA itself has acknowledged are “live issues,” with guidance on audit trails and human-in-the-loop protocols expected before the end of the year.
In practice, “trust” breaks down into five things a firm needs to be able to evidence:
Accountability. Under SMCR, someone is still responsible for the outcome, however the recommendation or output was generated. If a firm can’t point to who reviewed and approved an AI-assisted output, and on what basis, that’s a governance gap, not a technology problem.
Consumer Duty outcomes. AI tools that shape client communications, suitability assessments or product comparisons need to be assessed against the same fair value, understanding and support outcomes as any other process. That’s especially true for vulnerable clients, where an AI tool trained on average behaviour can quietly produce a poor outcome for someone who isn’t average.
The advice/guidance boundary. Tools designed to support the adviser can drift into producing something that looks a lot like personalised recommendation, particularly where a chatbot or generative tool is client-facing. Firms need to be clear and able to evidence where that line sits in their own client journey.
Third-party and concentration risk. Over reliance on a single AI provider embedded across multiple functions raises questions the FCA is increasingly interested in: what happens if that provider fails, changes its model, or is designated a critical third party. Due diligence on tech partners needs to sit alongside due diligence on product providers.
Record-keeping and audit trail. With FCA guidance on this specifically flagged as coming this year, firms that can already show what an AI tool was used for, what data it drew on, and who signed off the output will be far better placed than those scrambling to reconstruct it retrospectively.
None of this should discourage adoption. The TechForward findings make clear advisers don’t want it to. But it does mean governance needs to be built in from the start, not bolted on after the FCA publishes its expectations.
A simple starting point: treat every AI tool in the business like you would a new product or outsourced function. Document purpose, defined human oversight points, designate a named owner, and have a clear line back to Consumer Duty outcomes.
One final point is to make sure personal data is not uploaded into open systems. Try to anonymise when uploading into tools and add in specifics to your final reports when ready.
That’s the lens TFAS is bringing to its TechForward programme, and to the compliance support it offers advice firms more broadly, helping firms build governance that can stand up to scrutiny now, rather than waiting for rules that may never arrive in the form firms expect.


