Yes, financial advisers can use ChatGPT and stay compliant, provided it's a business plan the firm controls, client data stays out of personal accounts, every client-facing output is checked by an adviser and saved in your normal records, and no advice leaves the firm without human judgement. Regulators generally don't ban the tool. They hold the firm responsible for what it produces.
So the question compliance officers ask isn't "is ChatGPT allowed?" It's closer to this: for any piece of work, could you show what went in, what came out, who checked it, and where the final version lives? If the answer is yes, most uses are manageable. If an adviser pasted a client's pension statement into a personal account on their phone, the answer is no, however good the output was.
Green, amber, red: how advice firms tend to sort ChatGPT uses
Every firm draws its own lines, but compliance teams arrive at similar lists. Use this as a starting draft for your own:
| Use | Rating | Condition |
|---|---|---|
| Explaining a concept in plain English for a client letter | Green | Adviser checks accuracy; no client data needed |
| Drafting generic newsletters and website copy | Green | Goes through your normal marketing approval |
| Summarising public documents (product brochures, fund factsheets) | Green | Figures checked against the source |
| Rewording an email the adviser has written | Green | No new facts added; final version saved to the CRM |
| Summarising client meeting notes or transcripts | Amber | Business plan only; adviser checks the summary before it goes on file |
| Drafting sections of a suitability report | Amber | Built from the fact-find and the adviser's reasons; full review |
| Extracting data from client documents (statements, policy schedules) | Amber | Business plan; every figure checked against the document |
| Client personal data in a free or personal account | Red | Never |
| Asking ChatGPT what a client should do | Red | The recommendation is the adviser's; AI can help write it up, not make it |
| Sending any AI output to a client unread | Red | Never |
| Using ChatGPT as a source of current rates, charges or rules | Red | Use your research tools and official sources; AI can be out of date or wrong |
Amber uses are where most of the time savings are, and where most of the controls go. For meeting records specifically, AI note takers for financial advisers goes into consent and accuracy checks in detail.
The reason meeting summaries are amber, not green, shows up in the first one you check. An adviser's notes from a review meeting say the client is "balanced overall, but happy to take more risk with the pot she won't touch for 15 years; nervous after last year's fall". Asked for a file summary, an illustrative draft reads:
Attitude to risk: adventurous. The client is comfortable with
higher-risk investments and wishes to increase equity exposure.
Objectives: long-term growth.
Every word of that could end up quoted back in a complaint. The client described two attitudes for two pots and mentioned being nervous; the summary flattened them into one bolder label that nobody used in the meeting. The fix is in the prompt and the check. In the prompt: "Record the client's attitude to risk in their own words, separately for each pot or goal they mention, and include any concerns they raised." In the check: the adviser compares the risk wording line by line with the fact-find and their notes before the summary is saved. A risk description the client didn't give is a red flag, however plausible it looks.
Data extraction needs a different check, because the errors are in single figures. When an administrator uses the firm workspace to pull figures from a pension schedule, have the output come back as a table with the page each figure came from, then tick each one against the document. A filled-in check for an illustrative schedule:
| Field | AI extracted | Page | Document says | Match |
|---|---|---|---|---|
| Plan start date | 1 March 2009 | 1 | 1 March 2009 | Yes |
| Current fund value | $212,480 | 2 | $212,480 | Yes |
| Transfer value | $228,900 | 2 | $205,300 (the $228,900 is a projection at age 65) | No |
| Annual charge | 0.85% | 3 | 0.85% | Yes |
| Guaranteed features | None | n/a | Guaranteed annuity rate, page 4 | No |
Two misses in five fields is not unusual on a first run. One figure was lifted from the wrong column, and a valuable guarantee was missed because it sat in a paragraph rather than a table. Both would matter to a transfer recommendation, which is why "every figure checked against the document" sits in the amber condition and why the page column is worth asking for: it turns a slow re-read into a quick tick.
Which ChatGPT plan passes a compliance review
The plan decides who controls the data, whether it trains models, and what records exist. Prices are USD list prices as of September 2026.
| Plan | Training on your content | Firm control and records | Fit for an advice firm |
|---|---|---|---|
| Free, Go ($8), Plus ($20), Pro ($100 or $200) | On by default; each user can switch it off in data controls | None. The account belongs to the individual, not the firm | Not for any client data. Tolerable only for green uses with nothing identifying |
| ChatGPT Business ($25 a seat monthly, $20 annually; minimum two seats) | Off by default | Admin console, firm-owned workspace, shared Projects | The usual choice for a small firm |
| ChatGPT Enterprise (custom quote) | Off by default | Adds OpenAI's Compliance API, which exports conversation logs to archiving and eDiscovery tools | Worth pricing if your regulator or network expects chats to be archived |
If the firm already runs Microsoft 365, compare Microsoft 365 Copilot Business ($21 a user a month on annual billing): prompts and responses are stored within your Microsoft 365 environment and can be brought under Microsoft Purview retention policies and eDiscovery, which answers the "where does the record live?" question neatly. For a wider comparison of general assistants against tools built for advice firms, see advice-specific AI or ChatGPT. And for the training question in more detail, whether ChatGPT trains on client data sets out the settings plan by plan.
The same client email, done two ways
Before (red): An adviser on the train opens ChatGPT Plus on their phone and types: "Write a friendly email to [the client's full name] explaining why I'm recommending he moves his $80,000 pension..." along with his date of birth, current provider, health condition and the new fund names. The email that comes back is good. But the client's personal and health data now sits in a personal account the firm can't see or delete, the draft isn't recorded anywhere, and the reasons in the email were partly written by the AI.
After (green to amber): The adviser writes the two sentences that are the recommendation themselves. In the firm's ChatGPT Business workspace, they ask for help with the rest, using a placeholder instead of the name and no health data: "Rewrite this as a clear, warm email to a client aged around 60. Keep my recommendation paragraph word for word. Explain in plain English what happens next and what the client needs to sign." They check the draft, add the client's name in the CRM, send it from there, and the sent version is the record.
The second version took perhaps five minutes longer. It's the only one that would survive a file review. Anonymising client data before it goes into AI has practical techniques for the placeholder step.
Record-keeping: what to keep, and where
Most financial regulators expect firms to keep records of client communications and of the basis for their advice. ChatGPT doesn't change that duty; it adds a question about which version is the record. A workable set of rules:
- The final version lives in your system of record. Client emails are sent from, or saved to, the CRM. Reports live in the client file. The chat that produced a draft is not the record.
- Keep chats that shaped advice. If ChatGPT was used to analyse a client's documents or compare options that fed a recommendation, save the relevant exchange to the client file, or use a plan whose logs can be archived.
- Know your retention settings. Find out how long your chosen plan keeps conversations and whether users can delete them. If your firm must be able to produce chats later, a plan with archiving (Enterprise's Compliance API, or Copilot with Purview) is the safer route.
- No off-channel client contact. Regulators have fined firms heavily for business communications on unapproved channels. Anything that reaches a client goes through approved channels only.
Checking what ChatGPT tells you: a sample
Even green uses need a real check. An illustrative prompt and output:
Prompt: Explain sequence-of-returns risk to a recently retired
client who is drawing an income from their investments. Plain
English, under 150 words, no jargon.
Illustrative output: Sequence-of-returns risk means that the
order in which investment returns arrive matters when you are
taking money out. If markets fall early in retirement while you
are withdrawing income, you sell more units at low prices, and
your pot may not recover even if markets rise later. A common
rule of thumb is that withdrawing 4% a year is generally safe.
Keeping some cash to draw on in bad years can help.
The first three sentences are clear and correct. The fourth is the problem: a "4% is generally safe" rule of thumb is contested, depends heavily on assumptions and time horizon, and in a client letter it reads like advice about that client's withdrawals. Delete it and replace it with something tied to their own plan: "We'll look at how this applies to your income level when we review your cashflow plan." The fifth sentence is fine as a general point but should match whatever strategy you've actually agreed with the client.
Marketing, financial promotions and the AI-washing trap
AI-drafted marketing is still marketing. Anything that promotes your services or products goes through the same approval as before, and AI's habit of confident, upbeat phrasing ("secure your future", "guaranteed peace of mind") can drift into claims you'd never approve if a person had written them. Read AI copy specifically for promises, performance claims and anything that implies certainty.
A before and after from an illustrative newsletter intro shows the kind of edit to expect:
AI draft: "With markets recovering strongly, now is the perfect time to review your pension. Our expert, AI-powered planning ensures your retirement is on track."
Approved version: "Markets have moved a lot this year, so it's a sensible time to check your pension is still set up the way you want. If you'd like a review, reply to this email and we'll arrange a time."
The draft made three claims the firm couldn't stand behind: a market view dressed up as a timing call, a claim that the firm's planning is "AI-powered", and a promise that retirement will be on track. The approved version keeps the prompt to act and drops all three.
A separate trap is overstating your own use of AI. In March 2024, a financial regulator fined two investment advisory firms a combined $400,000 for making false and misleading statements about their use of artificial intelligence. If your website says your service is "AI-powered", be able to show exactly how, and don't imply AI makes decisions that advisers make.
A one-page ChatGPT policy for an advice firm
Here's a filled-in example for an illustrative six-adviser firm. Adapt it with your compliance lead:
AI USE POLICY - ADVICE AND ADMINISTRATION STAFF
Approved tool: ChatGPT Business (firm workspace) only.
Personal AI accounts must not be used for firm work.
1. Client data: may be entered only in the firm workspace, and
only what the task needs. No health data or ID documents
unless the compliance lead has approved the use case.
2. Advice: AI must not decide or recommend. Advisers write the
recommendation; AI may help structure and word it.
3. Checking: every client-facing output is read in full by the
adviser, who checks all figures against source documents.
4. Records: final versions are sent from or saved to the CRM.
Chats used to analyse client documents are saved to the file.
5. Marketing: AI-drafted promotional content follows normal
approval. No claims about our AI use without sign-off.
6. Custom GPTs: do not create. Use shared Projects for firm
context (house style, approved research summaries).
7. Incidents: report any wrong data entry or AI error that
reached a client to the compliance lead the same day.
8. Review: this policy is reviewed every six months.
Owner: Compliance lead Approved: [date]
This sits under a wider governance framework: who approves new tools, how risks are logged, how staff are trained. The AI governance checklist for advice firms covers that layer.
What the rollout costs a small firm
For a sense of scale, take the illustrative firm above: six advisers, two paraplanners and an administrator, so nine seats. On ChatGPT Business billed annually at $20 a seat, that's $180 a month, or $225 a month on monthly billing at $25 a seat. The money is the small part. The time looks more like this:
- Writing and approving the policy: four to six hours for the compliance lead, including sorting the firm's own uses into green, amber and red.
- Setting up the workspace: an hour or two to invite users, create shared Projects for house style and approved templates, and check the data settings. The house-style Project's instructions can be short. For this firm: "You help advisers and paraplanners at a financial advice firm word client letters. Use plain English, short paragraphs and 'we' for the firm. Never recommend a product, a fund or a course of action. Never state current rates, allowances or charges; leave [check: figure] instead. Keep any paragraph the adviser marks KEEP word for word." The last two lines do more compliance work than the rest put together.
- Training: an hour per person, built around the firm's real tasks rather than a generic demo. Include the before-and-after email above; it teaches the data rule faster than any slide.
- Ongoing supervision: two or three hours a month for the sample checks and admin review below.
Compared with the cost of one file review finding a client's data in a personal account, that's cheap. It's also the difference between a firm where advisers use AI quietly on their own phones, which happens whether or not it's allowed, and one where they use it in the open, on terms compliance can defend.
Supervising use without reading every chat
A small firm can't read every conversation, and doesn't need to. A proportionate routine:
- Monthly sample. The compliance lead picks five client files that used AI and checks the output against the source and the final version.
- Quarterly attestation. Each adviser confirms in writing that they've used only the firm workspace for firm work.
- Training record. Note who has been through the policy and when, and refresh it when tools change.
- Admin checks. In the Business admin console, review who has seats and remove leavers the day they go.
The sample earns its place the first time it catches something like this. At a routine file check, a reviewer notices that a recommendation refers to a transfer value that doesn't appear in any document on the client file. It turns out the adviser had asked a personal ChatGPT account to read a provider letter from a photo, and it had misread one digit. The figure was wrong, the letter wasn't on file, and neither was the chat. The error was caught before the client acted, but only because someone looked. The fix was procedural: documents are scanned into the client file first, then analysed in the firm workspace, so the source is always on record.
ChatGPT in advice firms: follow-up questions
Is Claude or Microsoft 365 Copilot a safer choice than ChatGPT for an advice firm?
None is automatically safer; what matters is the plan and your controls. Claude Team, ChatGPT Business and Microsoft 365 Copilot all avoid training on business content by default. Copilot has an advantage for record-keeping if you already use Microsoft 365, because prompts and responses sit in your tenant and can fall under Microsoft Purview retention and eDiscovery. Choose the tool your records and supervision can cover.
Do we need to tell clients that we use ChatGPT?
There is no single rule, but clients should never be misled. Many firms add a short line to their privacy notice or terms explaining that AI tools help with drafting and administration under adviser supervision, and that client data stays within approved business systems. If AI is used in a way that affects the advice itself, such as analysing their documents, being open about it is the safer course. Ask your compliance adviser for wording.
Can we build a custom GPT for our house investment view?
No, and not only for compliance reasons. OpenAI is retiring custom GPTs, and existing ones stop running on 11 December 2026. For shared firm context, such as your house style or approved research summaries, use a shared Project in ChatGPT Business, which keeps files and instructions together for the team.
What about ChatGPT Work, which can act across apps and files?
ChatGPT Work replaced the old agent mode in July 2026 and can carry out longer, multi-step tasks across connected apps and files. For an advice firm, keep it away from client systems and back-office platforms until compliance has approved a specific, tested use, because an agent that acts on your behalf raises harder supervision and record-keeping questions than a chat that only drafts.
Further reads
- Can AI Draft a Suitability Report That Passes Compliance Review? — The next question: AI drafting the report itself.
- Paraplanning With AI: What to Automate and What to Keep Human — Which paraplanning jobs AI can take, and which it can't.
- How Advisers Use AI to Prepare for Annual Client Reviews — A well-contained first use case for most firms.
- AI Acceptable Use Policy for a Small Professional Firm — A fuller acceptable-use policy to build on.
- How to Roll Out an AI Policy So Staff Actually Follow It — Getting advisers to actually follow the policy.
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the main assistants handle personal data.
- What Mortgage Brokers Can Automate With AI, and What Stays Advice — The line between admin and advice across a mortgage case, with wording that stays on the right side of it and three automations that quietly cross it.
- How to Write a House Style Guide Your Team and AI Both Follow — Turn house style into testable rules with examples, keep a short AI version in a shared project, and prove it works on real drafts.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI help articles (Compliance API for ChatGPT Enterprise and Edu; custom GPT retirement FAQ); Microsoft Learn, retention for Copilot and AI apps; published regulatory enforcement notice (March 2024) on AI claims by two investment advisers; vendor pricing as listed September 2026. Not legal or regulatory advice.