AI systems for financial services firms
The question in a regulated firm is never “can AI do this?”. It's “can we evidence how it did it, and who is accountable when it's wrong?”. That's a design problem, and it's one we'd rather solve at the start than retrofit after your compliance team sees a demo.
Where regulated firms actually lose time
Not to the advice, the underwriting or the audit — to the assembling, chasing and evidencing wrapped around them.
Client onboarding that stalls between steps
Engagement terms, identity verification, source-of-funds evidence, screening, risk rating, agent authorisations. Every step is quick and every step waits on someone else, so a two-hour job takes a fortnight.
We cut exactly this to 4 hours at a 22-person practiceQuarterly reporting turned an annual peak into a permanent one
Making Tax Digital for Income Tax became mandatory from 6 April 2026 above £50,000 of qualifying gross income, dropping to £30,000 in 2027 and £20,000 in 2028. Chasing clients for records stopped being a January problem and became a quarterly one.
Suitability and file preparation
Fact-finds, meeting notes, research, and the report that ties it together. Independent research suggests advisers spend only around a third of their time client-facing, and would like it closer to half.
Evidencing outcomes across everything you say to customers
Consumer Duty asks firms to demonstrate outcomes, not just document processes. Reviewing calls, correspondence and complaints at scale to show what's actually happening to customers is a genuinely unsolved manual problem in most firms.
What we'd build for a regulated firm
Everything below assists a person who remains accountable. None of it decides anything about a customer on its own.
Client onboarding orchestration
Runs the sequence end to end — terms out and chased, identity documents collected, screening run, evidence assembled, authorisations tracked — with a live view of what's outstanding and where a file is stuck.
Our proven build. 3 days → 4 hours.Records chasing for quarterly cycles
Tracks what each client owes you, escalates the chase, accepts records in any format, extracts them into your bookkeeping system and gives the partner a daily at-risk list before a deadline becomes a problem.
Document extraction and coding
Bank statements, invoices, receipts and contracts read and structured, with anything ambiguous queued rather than guessed. Exceptions surface early instead of at review.
Consumer Duty outcomes monitoring
Thematic analysis across calls, complaints and correspondence at a scale humans can't sample manually — surfacing patterns for your compliance team to investigate. It produces evidence for review, never a conclusion.
Surfaces patterns. Does not label customers.Suitability and file assembly
Structures fact-find and meeting content into your report template, with research and rationale in the right sections. The recommendation, and the sign-off, stay with the adviser who owns it.
Client-facing AML file assembly
Collates identity, screening output and source-of-funds evidence into a structured file with a gap checklist, and chases what's missing. Screening runs deterministically against official lists.
Assembles and chases. Your MLRO decides.The regulatory position, stated precisely
Financial services is the sector where vague compliance claims do the most damage. Here is what is actually true as of August 2026.
- <strong>The FCA is not writing AI-specific rules — and reconfirmed that in July 2026.</strong> The Mills Review, published 6 July 2026, is the first regulator-led review of its kind globally. It makes seven recommendations to the FCA Board while holding the line that the principles-based approach — the Consumer Duty, SM&CR and operational resilience — has been what kept the regulator moving at the pace of the technology. That isn't a free pass: it means your existing obligations already cover AI and a Senior Manager is already accountable. Note that the first recommendation is to <em>secure and adapt the regulatory perimeter</em>, so “no new rules” describes today, not permanently.
- <strong>Accountability maps to a named individual.</strong> Under SM&CR a Senior Manager is personally accountable for outcomes. Our practice of assigning a named accountable owner to every workflow exists precisely so that mapping is obvious rather than argued about after an incident.
- <strong>Automated decision-making law changed on 5 February 2026.</strong> The Data (Use and Access) Act 2025 replaced the old Article 22 prohibition with Articles 22A–22D — a permission-with-safeguards regime. Where a significant decision is made without meaningful human involvement, the individual must be given information about it, be able to make representations, obtain human intervention and contest the outcome. Special category data keeps tighter treatment.
- <strong>Some uses are high-risk under the EU AI Act, and most are not.</strong> Credit scoring and creditworthiness evaluation of individuals (Annex III 5(b), with an exception for fraud detection) and risk assessment and pricing in life and health insurance (Annex III 5(c)) are high-risk. Following Regulation (EU) 2026/1744, those obligations now apply from 2 December 2027. Back-office document processing and meeting summarisation are not high-risk. For UK firms the Act applies where the output is used in the EU.
- <strong>Anti-money-laundering rules changed on 30 June 2026.</strong> The Money Laundering and Terrorist Financing (Amendment) Regulations 2026 converted several euro thresholds to sterling, including the occasional-transaction threshold to £800. Systems that hard-code thresholds need to be built so those values are configuration, not code.
- <strong>There is no UK AI Act.</strong> Anyone telling you that you need to comply with UK AI legislation is selling you something. AI is governed here through existing regimes and sector regulators.
New client onboarding at a 22-person accountancy practice. The time didn't come out of the work — it came out of the waiting between steps, which is where almost all elapsed time in a regulated onboarding process actually sits.
What we won't automate in a regulated firm
Each of these is a decision a regulator would expect a named human to have made, with reasoning they can inspect.
The final personal recommendation
Suitability is owned by the adviser. A system can assemble the file, structure the research and draft the report. The recommendation is made by a person with the right permissions, who signs it.
Credit and affordability decisions
Even under the relaxed 2026 regime, a firm must understand how a model reaches its conclusions, evidence that it assesses affordability rather than just credit risk, and monitor for drift and bias. We won't build a credit decision that a human can't explain and contest.
Labelling customers as vulnerable
A system can surface indicators for a human to consider. Treating a customer differently on the basis of an algorithmic vulnerability score is a fairness problem and a Consumer Duty problem waiting to happen.
Suspicious activity reporting decisions
The MLRO decides whether to report. A system prepares the file and highlights the pattern. It does not form the suspicion.
Anything that becomes unregulated financial guidance
A customer-facing assistant that drifts from information into anything resembling advice creates a perimeter problem. We design that boundary explicitly and test against it.
Common questions.
Does the FCA regulate AI?
+
Not with AI-specific rules. The FCA reconfirmed this in the Mills Review of 6 July 2026: it will not introduce AI-specific regulation, relying instead on existing frameworks — the Consumer Duty, the Senior Managers and Certification Regime, and operational resilience. The Review does recommend the FCA secure and adapt the regulatory perimeter over time, so treat the current position as settled rather than permanent. Practically, that means the compliance question isn't “is our AI approved?” but “can we evidence that our existing obligations are met, and is it clear which Senior Manager is accountable?”. Both of those are design decisions best made before the build, not after.
Who is accountable when an AI system gets something wrong?
+
A named Senior Manager, exactly as with any other part of the business. SM&CR attributes responsibility to individuals rather than systems, so “the model did it” is not an available answer. Every workflow we build has a named accountable owner, a documented description of what the system does and doesn't decide, and a log of what it did — so that when the question is asked, the answer is already written down.
Can AI make credit or affordability decisions in the UK?
+
Legally the position loosened in February 2026, but the safeguards make full automation a poor idea for most firms. The Data (Use and Access) Act replaced the old blanket prohibition on solely automated decisions with a permission-plus-safeguards regime: individuals must be told about the decision, be able to make representations, obtain human intervention and contest the outcome. Consumer credit rules separately require the firm to understand how the model decides, evidence that it assesses affordability rather than just credit risk, and monitor for drift and bias. We build these as human-in-the-loop systems by default.
Is credit scoring high-risk under the EU AI Act?
+
Yes — creditworthiness evaluation and credit scoring of natural persons sits in Annex III, point 5(b), with an explicit exception for AI used to detect financial fraud. Risk assessment and pricing in life and health insurance is separately listed at 5(c). Following Regulation (EU) 2026/1744, which came into force in July 2026, those obligations apply from 2 December 2027 rather than 2026. For a UK firm the Act only applies where the system's output is used in the EU — so the first question is scope, not compliance.
Can we keep client data inside our own perimeter?
+
Yes, and in this sector we usually recommend it. We deploy in your own tenancy or on your own infrastructure, so client data stays within the boundary your existing controls already cover — which makes the conversation with your compliance team, your auditors and your professional indemnity insurer considerably shorter.
Bring your compliance team to the first call.
It's the fastest way to find out whether a build is viable. We'd rather have the hard conversation about accountability and evidence at the start than three weeks in.