Proving AI governance at a UK wealth manager
Advisers were using AI to prepare client reviews and draft communications. The firm needed the productivity, and evidence of control it could stand behind in a regulatory review.
reduction in client data exposure to AI tools
more AI tools in use than the approved list
of AI interactions captured in the audit trail
The challenge
Client portfolios, suitability reports and personal financial data were flowing into AI tools the firm had never assessed, from adviser desktops the proxy could not meaningfully inspect.
The compliance team’s question was sharper than most: not "can we block this?" but "can we evidence control?" A written AI policy would not survive a regulatory conversation without proof it was being followed.
The approach
Discover, control, detect, prove
Discover
The two-week AI Risk Assessment surfaced three times more AI tools than the approved list, and showed exactly where client data was travelling.
Control
Real-time policies warn advisers when client-identifiable data appears in a prompt and block submission to unapproved destinations.
Detect
Context-aware models recognised client data in prompts, pastes and screenshots without a classification project.
Prove
Every AI interaction is logged with its risk assessment, giving compliance an evidence base built for regulatory review, not just an incident log.
The results
- Client data exposure to AI tools fell 91% within a quarter, with advisers guided to compliant alternatives in the moment.
- Compliance now holds an interaction-level audit trail, turning "we have a policy" into "we can prove it is working".
- AI adoption continued across the firm; governance became an enabler of the productivity case rather than the blocker.
“When we are asked how we manage AI risk, we no longer point at a policy document. We show the data.”
Uncover hidden AI risk
Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.