A practical control sequence
- Define the use case. Record what the tool will do, what it will not do and whether personal data is necessary.
- Approve the service. Check the exact plan, contract, data location, retention, subprocessors, access controls and provider commitments.
- Assess the processing. Confirm roles, lawful basis, transparency, minimisation, security and whether a DPIA is required.
- Agree it with the firm. Put permitted use, restrictions, incidents, audit evidence and deletion into the engagement framework.
- Keep a human in control. Verify source facts, calculations, citations, suitability logic and every final output.
- Monitor. Review access, incidents, service or contract changes, error themes and continuing necessity.
What AI must not decide for Compliant
AI does not establish suitability, approve a recommendation, replace missing evidence, infer client consent, make a Pension Transfer Specialist decision or sign off a regulated file. Efficiency is useful only inside the firm’s agreed advice and control framework.
Why the exact service and contract matter
Business-data protections are plan- and configuration-specific. A personal or consumer subscription is not an approved case environment; the business service and intended use must be assessed and agreed first.
Current rule: live client data may enter AI only when the approved service, assessment, contractual terms, access controls and adviser-firm agreement are in place.
Frequently asked questions
Does AI remove the need for human checking?
No. Source checking, calculation review, professional judgement and adviser approval remain necessary. AI output can be incomplete, inaccurate or inappropriate to the case.
What must be agreed with an adviser firm before AI is used?
The approved use cases, data types, system and tenant, subprocessors, retention, access, human checks, incident route and contractual responsibilities should be documented before live work.
Can live client data be entered into a personal Copilot or consumer AI account?
No. Live client data must not enter a personal or consumer AI account. Any permitted use requires an approved business environment, appropriate contractual and data-protection assessment, adviser-firm agreement and human checking.
Primary sources
- ICO: Guidance on AI and data protection
- Microsoft: Data, privacy and security for Microsoft 365 Copilot
- Microsoft: Enterprise data protection
- FCA: Outsourcing and operational resilience
This is an operating position and general guidance, not a vendor certification, legal opinion or firm-specific DPIA.