Five questions reveal whether your firm can defend its AI use to a regulator, a client, or a court. Used by solicitors, IFAs, accountants and HR firms across the UK.
This is not a documentation check. It tests whether your firm can defend its AI decisions — not whether a policy exists.
No email required to see your results
Think of it as the person a regulator would call first — not the person who happens to know most about AI. In FCA-regulated firms this maps to a named Senior Manager under SM&CR. In law firms, the equivalent is the Compliance Officer for Legal Practice (COLP). In accountancy practices, the responsible principal. The role has different names across sectors — the requirement for one named, board-recognised individual does not.
This includes AI features built into software you already use (such as Microsoft 365 Copilot or your case management system), and tools your staff may be using on their own initiative — including browser extensions, ChatGPT, or similar tools installed without firm approval. It also includes your obligations as a deployer of general-purpose AI models such as ChatGPT, Microsoft Copilot, or Claude — which carry specific obligations under Articles 25 and 26 of the EU AI Act. This should also identify what kind of data passes through each tool: client personal data, commercially sensitive material, or special category data such as health or financial records. The exposure depends on what is being processed, not only which tool is doing the processing.
This includes how AI tools should be prompted, who must review the output at each stage, and whether sign-off is recorded — not just assumed. This assumes the tool has been formally approved by the firm for its users. If your AI tools only draft or suggest, meaning you read the output and then act, this question is about that review step. If any AI tool at your firm can take actions on its own, such as sending client communications, updating records, or initiating payments, without a person approving each action first, the bar is higher. Has your firm defined which actions it can take unsupervised, and which always need sign-off, even for an action type it has been approved to do before?
If a regulator or client raised a concern today, could this function produce a record of which AI tools were used, by whom, on what tasks, and what human review took place? The Data Use and Access Act 2025 Section 80 requires meaningful human oversight of automated decisions affecting individuals — under UK law, now, regardless of EU AI Act timing. Separately, the ICO is required by SI 2026/425 (in force 12 May 2026) to publish a statutory Automated Decision-Making Code, not expected until 2027, which will set out how that oversight must be evidenced. Where AI tools act autonomously rather than only assisting, oversight needs to cover not just whether AI was used, but which actions it was allowed to take unsupervised, and whether that boundary is actually enforced and not just documented.
The EU AI Act is already in force. From 2 August 2026, new transparency obligations apply — including informing clients and candidates when AI is used in decisions affecting them. Separately, UK regulators including the ICO, FCA, and SRA already require documented AI governance under existing frameworks. Firms that have not assessed their position are exposed on both fronts regardless of EU AI Act enforcement timing.
Each gap below shows what you cannot currently defend — and what fixes it.
These five foundations are drawn from overlapping UK and EU regulatory frameworks already in force, plus one forthcoming ICO code:
SM&CR (FCA) · FCA Consumer Duty · Data Use and Access Act 2025 · EU AI Act Article 50 (in force 2 August 2026) · ISO 42001 · forthcoming ICO Statutory ADM Code (required by SI 2026/425, in force 12 May 2026; Code itself not expected until 2027, not yet published)
They also align with SP1–SP10 of the FSB's June 2026 consultation on Sound Practices for Responsible AI Adoption in Finance.
There are general-purpose self-assessment tools, and there are enterprise-grade compliance platforms built for large, engineering-led organisations. Neither is built for a regulated professional services firm with no in-house engineering team and specific SRA, FCA, or ICAEW/ACCA obligations to answer to. TrustProof is where a firm like that should start: sector-specific, plain English, mapped to the obligations you actually carry.
Regulatory basis last verified: September 2026. Reflects the Data (Use and Access) Act 2025, the duty created by SI 2026/425 (in force 12 May 2026) for the ICO to produce a statutory AI and automated-decision-making code, still forthcoming and not yet published, and the EU AI Act Digital Omnibus timeline (Annex III: 2 December 2027; Annex I: 2 August 2028). Provisional items are marked as such throughout.