AI readiness and risk assessment
What AI is actually in use across your firm — including the tools nobody asked permission for — what data flows into them, and where your real exposure sits.
Practical AI governance for regulated and professional firms: an honest picture of what is in use, a policy people can follow, technical controls that enforce it, and evidence a board or regulator can rely on.
Fixed-price engagements · Aligned to existing FCA obligations · Governed adoption, not blanket bans.
Most firms start with copilots, chat tools and AI-enabled SaaS features before deciding what data can be used, which connectors should be allowed, or how outputs should be checked. In regulated firms that gap matters more, because AI can touch customer communications, privileged data and regulated processes very quickly.
The risks are concrete: sensitive data pasted into public tools, over-permissioned copilots, prompt injection through content AI systems read, supplier concentration, and confident outputs that are simply wrong. Governance is how you take the productivity without taking all of that with it.
Scoped from these building blocks after the readiness assessment — proportionate to your firm, not a bank's compliance department transplanted into an SME.
What AI is actually in use across your firm — including the tools nobody asked permission for — what data flows into them, and where your real exposure sits.
A clear, practical policy: which tools are approved, what data may be used with them, which teams can use which capabilities, and where human sign-off is mandatory.
Policy backed by enforcement: identity and access hardening, connector and plugin permissions reviewed, data classification and logging — AI tools treated like the privileged applications they are.
How your AI suppliers store, isolate, log and retain data; model-provider dependencies; geographic processing — assessed like any other critical provider.
Enough telemetry to investigate misuse and unexpected outputs, AI scenarios included in incident response, and evidence you can show a board, client or regulator.
Staff who know what safe AI use looks like day to day, and reporting that lets senior managers answer for AI risk with confidence — because under SM&CR, someone has to.
Audit what AI is in use — sanctioned and shadow — what data it touches, and which processes it has quietly become part of.
Agree the usage policy: approved tools, permitted data, sign-off points and supplier requirements, proportionate to your firm.
Enforce it technically — access, connectors, logging and data boundaries — so the policy is real rather than aspirational.
Keep watch as tools and models change: usage review, supplier reassessment, staff training and board reporting on a sensible cadence.
If your staff have access to the internet, your firm is almost certainly using AI already — the only question is whether it is governed. Customer records pasted into public chatbots, AI features switched on inside SaaS tools, and copilots connected to mailboxes all create data protection and regulatory exposure. A policy, backed by technical controls, is how you get the productivity without the uncontrolled risk.
You can, but blanket bans mostly drive usage underground — staff switch to personal devices and accounts, and the firm loses what visibility it had. In our experience the safer position is governed adoption: a short list of approved tools with clear data rules, so people have a legitimate route that is genuinely easier than the workaround.
The FCA has deliberately chosen not to write a single AI rulebook. Instead it expects firms to govern AI under existing obligations — the Consumer Duty, the Senior Managers regime, operational resilience and data protection. The practical message is to build security and accountability into AI use now, rather than wait for bespoke rules: a named senior manager can already be held accountable for AI-related harm.
It can. The EU AI Act applies to firms with EU operations or EU customers, and can impose obligations on 'high-risk' uses regardless of the UK's lighter-touch approach. Part of the readiness assessment is establishing whether any of your AI use falls into scope — and making sure your governance framework covers both regimes rather than treating them separately.
Engagements are fixed-price, quoted after the readiness assessment shows the size and shape of your AI footprint. Most firms start with the assessment and policy, then add technical controls and monitoring in a second phase. No long tie-in contracts.
A no-obligation call to map your AI footprint, your obligations and the proportionate way to govern it — before a client, insurer or regulator asks.
Prefer to talk? Call 0330 223 7404