An AI governance checklist for a financial advice firm should cover eight areas: a named accountable person, an approved-tools register, client-data rules, supervision of AI output that feeds advice, record-keeping, vendor due diligence, staff competence, and incident handling with regular review. Each item needs evidence you could show your compliance adviser, network or regulator.
What separates an advice firm from any other small business is that AI output ends up in regulated documents: file notes, fact finds, suitability letters, review packs. A general AI policy that says "check the output" isn't enough. You need to show who checked which output, against what, and what happened when it was wrong. For the general principles of ownership and approval, see AI governance for a small business; the checklist below is the advice-firm layer on top.
A. Ownership and scope
- One named person is accountable for AI use. Why: without a name, approvals default to whoever is keenest. Evidence: a board or partners' minute naming them and their authority to approve or refuse tools.
- A written scope statement. Why: it draws the line regulators care about. Evidence: a short statement such as "AI may draft and summarise; it does not make or change recommendations, and every client-facing output is reviewed by an authorised adviser."
- An inventory of current use, including unofficial use. Why: advisers and paraplanners are often using free assistants already. Evidence: a dated survey of staff asking which tools they use and for what, with no penalty for honest answers.
The survey usually surprises the partners. An illustrative result from a firm of seven people, and the decision taken on each:
| Tool named | Used for | Decision |
|---|---|---|
| Free ChatGPT on a personal phone | Summarising pension transfer reports | Stop; move the task to the firm's business plan |
| A browser extension that summarises PDFs | Reading provider factsheets | Remove; its terms allow training on uploads |
| AI email summaries in the CRM | Nobody chose it; arrived in an update | Switch off pending vendor answers |
| Copilot Chat in Outlook | Drafting admin emails | Approve for non-client content |
| Meeting note taker | File notes | Approve with conditions (register entry below) |
The scope statement then settles borderline requests. A paraplanner asks an assistant: "Which of these three funds is best for a cautious client?" That's a recommendation, so it's outside scope. The in-scope version of the same task: "From these three factsheets, put each fund's ongoing charge, stated risk rating and largest five holdings in a table, quoting the factsheet date." The adviser still decides; the AI saved the reading.
B. The approved-tools register
Every AI tool, and every AI feature switched on inside existing software, gets one entry. An illustrative filled-in entry for a three-adviser firm:
| Field | Entry |
|---|---|
| Tool and plan | Adviser-built meeting note taker, Essentials plan, 3 seats |
| Approved uses | Transcribing and drafting file notes for client meetings where consent is recorded |
| Not approved for | Internal meetings about complaints; meetings with clients who decline; drafting recommendations |
| Client data involved | Names, financial circumstances, health where discussed |
| Training on our data | No (confirmed in terms, 12 Aug) |
| Retention setting | Notes synced to CRM; tool copy deleted after 90 days |
| Human check | Adviser signs note within one working day; monthly 10% sample by compliance lead |
| Owner / review date | Compliance lead / every six months, next February |
Keep the register in the same place as your other compliance records. It doubles as the risk register for AI; if you want a fuller template, the simple AI risk register has columns you can merge in.
Built-in features are how the register goes out of date without anyone noticing. In the survey above, the CRM's email summaries came to light because a paraplanner saw a two-line summary above a client's email about a cancer diagnosis and asked where it came from. The register response took a morning: switch the feature off at admin level, ask the vendor in writing which model provider processes the emails and whether content is retained, and add a register entry marked "suspended". When the vendor answered, the partners approved it for everything except emails flagged as vulnerable-client correspondence. The entry now records both the answer and the date it was given.
C. Client data rules
- Business plans only for client data. Why: business and enterprise plans from the main providers don't train on your content by default; consumer accounts often do unless someone flips the switch. Evidence: register entries showing the plan for each tool.
- A list of data that never goes into AI tools. Why: some categories carry more harm if exposed. Evidence: a written list, for example full account numbers, passwords, identity documents, and health details unless the tool is approved for them.
- A data protection impact assessment for any tool processing health or vulnerability information. Why: data-protection law such as the GDPR requires an impact assessment where processing is likely to be high risk, and health information often tips it that way. Evidence: the completed assessment, reviewed by whoever advises you on data protection.
- An updated client privacy notice. Why: clients should know AI tools process their information. Evidence: the current notice, with the date it changed.
The mistake this section exists to prevent usually looks mundane. A paraplanner, pressed for time on a protection case, pastes a client's letter from their consultant into a free chatbot on a personal account and asks for a plain-English summary of the diagnosis. The summary is accurate. The problem is that a medical letter with the client's name and date of birth now sits in a consumer account, possibly used for training, outside anything the firm controls or can delete. Nobody would call it a breach until someone asks where the data went. The fix is a list of approved tools, plus an approved place to do exactly that task, so the shortcut is never needed.
The never-list needs a matching "do this instead" for each item, or people route around it. When a client emails a scanned passport and utility bill for identity checks, the quick idea is to ask an assistant to pull out the name, address and document number. Identity documents are on the never-list, so the answer is the firm's existing identity-verification service, or the administrator typing the three fields. Write the alternative next to each banned item, and the list reads as a process rather than a prohibition.
D. AI output that feeds advice
Not all AI use carries the same risk. Grade it, and match the supervision to the grade:
| Use | Risk | Minimum supervision |
|---|---|---|
| Internal emails, marketing drafts, admin | Low | Author reads before sending |
| Meeting file notes and fact-find pre-fills | Medium | Adviser checks and signs; monthly sample |
| Review packs and client letters | Medium to high | Adviser checks every figure; compliance sample |
| Suitability report drafts | High | Full adviser review plus your normal pre-issue check |
| Risk profiling, affordability or creditworthiness scoring | High | Only through approved, documented tools; the adviser's judgement recorded |
If you advise customers in the EU, note that the EU AI Act lists AI used to assess the creditworthiness of individuals, and AI used for risk assessment and pricing of life and health insurance, as high-risk. Obligations for stand-alone high-risk systems were deferred to 2 December 2027. Most of those duties sit with the provider, but deployers must assign competent human oversight, monitor the system and keep its logs for at least six months. If any tool in your stack scores or prices individuals, ask the provider in writing how it classifies the system.
For the medium and high rows, keep a sample log. How that works for meeting notes is set out in AI note takers for financial advisers; apply the same idea to letters and reports.
E. Records and retention
- The signed record lives in your system, not the AI tool. Why: if you cancel the tool, the file must survive. Evidence: a sample of client files showing signed notes stored in the CRM or back office.
- A decision on drafts and transcripts. Why: if a complaint arises, you may want the transcript that supports the note, or you may prefer not to hold one. Evidence: a written decision on what's kept and for how long, matching each tool's retention setting.
- AI-assisted documents are marked. Why: a reviewer years later should know a draft came from AI and who checked it. Evidence: a standard line such as "AI-assisted draft, reviewed by [adviser], [date]".
F. Vendor due diligence
- Security evidence. SOC 2 Type II or ISO 27001 for anything holding client data; and ask for the report itself rather than a badge on the website.
- A data processing agreement with sub-processors listed, including which AI model providers the vendor sends data to.
- Training and retention terms in writing, not only on a marketing page.
- Exit terms: how you get your records out, in what format, and how fast they delete your data.
Exit terms aren't theoretical. Clockwise, an AI calendar tool, shut down in March 2026 and deleted its users' data rather than transferring it. For a calendar, that's an inconvenience. For a note taker holding the transcripts behind signed file notes, it could leave gaps in client files that a complaint later exposes. So test the exit once, at approval: export one test client's notes and transcripts, open them in your CRM or document store, and confirm the dates, speaker labels and adviser sign-off survive the trip. Record the result on the register entry.
AI can help read the paperwork, as long as you verify what it finds. A prompt run in an approved assistant against a vendor's data processing agreement:
From the attached data processing agreement, answer each question
with a quote and clause number. If the document doesn't answer it,
write "Not stated".
1. Is customer content used to train any AI model?
2. Which sub-processors receive customer content?
3. How long is content retained after deletion or termination?
4. How can we export our data, and in what format?
5. How quickly are we told about a security incident?
An illustrative answer to question 1 might read: "No. Clause 4.3: 'Provider will not use Customer Content to train generalised models.'" That looks settled until you read clause 4.4, which the model didn't quote: "Provider may use de-identified usage data to improve the Services." Whether that matters depends on what "usage data" means, so it becomes a question for the vendor. The prompt shortens the reading; it doesn't replace it. More on this in questions to ask before buying AI that touches client data.
G. Staff competence and conduct
- Everyone using AI has had short, role-specific training. Why: advisers need to know how AI notes fail; admin staff need the data rules. If you serve EU customers, the AI Act's literacy duty, as softened by the Digital Omnibus in July 2026, expects firms to take measures supporting staff AI literacy. Evidence: a training log.
- An acceptable use policy each person has read. Evidence: a signed or acknowledged copy; this template for professional firms is a starting point.
- New joiners get the same briefing in their first week. Evidence: it's on the onboarding checklist.
A training log doesn't need to be elaborate. One filled-in line: "4 June. Adviser B. 40 minutes. Covered: approved tools, consent script, checking AI file notes for merged joint-client views and missing warnings. Tested on two sample notes; found both errors." The last sentence is the useful part: evidence that the person can spot the failure, not only that they sat through a session.
H. Incidents and regular review
- An AI incident log. Why: near misses show where controls are weak. Evidence: entries such as wrong figures reaching a client, data pasted into an unapproved tool, or a note recording advice not given, each with the fix.
- A quarterly review of the register and sample results. Evidence: short minutes with decisions.
- An annual re-approval of every tool. Why: plans, terms and features change. Evidence: each register entry re-dated.
An incident entry doesn't need to be long, but it needs all five parts. The review-letter slip mentioned in the quarterly hour below, written up:
Date found: 9 May Found by: client (phoned to query)
What happened: annual review letter quoted portfolio value "as at
31 March last year". AI drafted the letter from the prior year's
letter plus new figures; the date line wasn't in the new data.
Harm: none financial; client confused, apology given same day.
Fix: letter prompt now requires the valuation date from the
platform report; [CHECK] marker if missing. Adviser re-read
checklist updated to include dates.
Owner / closed: compliance lead / 16 May
The re-approval item earns its place because vendors change defaults between renewals. A real example from a neighbouring profession: SimplePractice, a practice-management system for therapists, began opting new users of its AI note taker in by default to keeping de-identified transcripts in June 2026. A firm that approved a tool a year earlier on the strength of its old defaults would only find out by re-reading the terms. At re-approval, check four things against the register entry: training terms, retention default, sub-processors, and any feature added since.
What the quarterly hour looks like in a four-adviser firm
In a firm of four advisers, a paraplanner and two administrators, the whole quarterly review can fit into an hour with the accountable partner and the compliance lead. A workable agenda: ten minutes on changes to the register (one new tool requested, one feature switched on by a software update); twenty minutes on the sample log (24 notes sampled across the quarter, three corrections, one repeated pattern of missing capacity-for-loss warnings from one adviser); ten minutes on incidents (one: a review letter sent with last year's valuation date); ten minutes on vendor changes (a note-taker vendor added a new model sub-processor); ten minutes on decisions and owners. The minutes of that hour, with the register and sample log, are most of the evidence a reviewer would ask for.
Signs the governance exists only on paper
- The register lists three tools but staff survey answers mention seven.
- Every sampled note passes, every month. Real sampling finds errors; a perfect record usually means the sample isn't looking hard.
- Notes are signed within minutes of the meeting ending, every time, including long ones.
- Nobody can say where transcripts are stored or when they're deleted.
- The incident log is empty after a year of daily AI use.
If you're still settling which general assistants advisers may use at all, what compliance allows for ChatGPT in advice firms covers that decision; the checklist then governs whatever you approve.
Governance questions small advice firms raise
Do we need ISO/IEC 42001 certification?
Almost certainly not at the size of a small advice firm. ISO/IEC 42001, published in December 2023, is a management-system standard for organisations that want a certifiable AI framework. Its structure is a useful reference for your own checklist, and a vendor holding it is a point in their favour, but certification itself is costly and rarely expected of a firm with a handful of advisers.
Does Copilot inside Outlook count as an AI tool for the register?
Yes. Anything that reads or generates content with AI goes on the register, including features switched on inside software you already use: Copilot in Outlook, AI summaries in your CRM, a platform's AI assistant. Built-in features are the ones most often missed, because nobody made a decision to buy them.
Our network or compliance consultancy has an AI policy. Is that enough?
It's a good base, but it can't know which tools your advisers use or how your file notes are reviewed. Keep their policy, then add your own register, data rules and sampling log underneath it. The evidence that supervision happens has to come from your firm, not from a template.
Further reads
- How to Roll Out an AI Policy So Staff Actually Follow It — Getting advisers and admin staff to follow the rules in practice.
- What to Check in an AI Vendor's Data Processing Agreement — The contract clauses behind section F of the checklist.
- What to Check in an AI Tool's Privacy Policy and Terms — Reading a tool's privacy terms before it goes on the register.
- Can AI Draft a Suitability Report That Passes Compliance Review? — Supervising the highest-stakes AI output an advice firm produces.
- What If Your AI Vendor Shuts Down? Checks Before You Commit — Exit planning for tools that hold client records.
- SOC 2 and ISO 27001 Explained: Checking an AI Vendor's Security — What a vendor's SOC 2 or ISO 27001 report actually tells you.
- How Advisers Use AI to Prepare for Annual Client Reviews — A review-prep process that fits inside these rules.
- Advice-Specific AI or ChatGPT: Which Should an Advice Firm Use? — What adviser-specific AI adds over a business ChatGPT plan, one meeting written up both ways, and how a four-adviser firm split its budget.
- Using AI to Spot Remortgage Opportunities in Your Client Bank — Turn an untidy client bank into a watchlist of deal-end dates, early-repayment-charge dates and loan-to-value moves, with AI filling the gaps.
- Paraplanning With AI: What to Automate and What to Keep Human — Twelve paraplanning tasks sorted into automate, assist and keep human, with worked examples of data extraction, chasers and the checks that keep it safe.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: EU AI Act text (Article 4, Article 26 and Annex III) via the AI Act Explorer; Digital Omnibus on AI timetable; ISO/IEC 42001 publication details; vendor plan terms for ChatGPT Business, Claude Team and Microsoft 365 Copilot.