CAIS Background Watermark
SOVEREIGN AI · FCA EXPOSURE

FCA GenAI Exposure Audit:
Consumer Duty, Market-Sensitive Data, and Shadow AI

Most FCA-regulated firms now have an AI policy. Far fewer can show that GenAI in customer-facing or conduct-sensitive work is tested, monitored, and proved — not only written down. That gap is where Shadow AI, data leakage, and Consumer Duty risk quietly grow.

This free FCA-aligned GenAI exposure self-audit maps where ChatGPT, Claude, Gemini, Copilot, and similar tools can expose customer data, market-sensitive information, Consumer Duty outcomes, and SM&CR accountability.

Twelve questions · Yes / Partial / No / Unknown · about 3–4 minutes.

You receive an exposure band and a six-axis control-strength profile — a plain-English snapshot for CCOs, Heads of Compliance, Risk, SMFs, and advisers. It scores exposure only.

Compliance AI Shield
FCA-aligned · UK financial services
Compliance AI Shield
Compliance AI Shield
complianceaishield.co.uk
Self-auditSovereign AI12 questions~3–4 minutes

Start the self-audit

Twelve questions. Answer Yes / Partial / No / Unknown. Then unlock your exposure band and six-axis control-strength profile.

This scores exposure, not eligibility for any government funding scheme. It does not intercept a live prompt, block a model call, or produce a cryptographic audit receipt. Paper policies catalogue risk — they do not eliminate runtime leakage.
Educational self-assessment only. Not regulatory advice or FCA authorisation evidence.
Also available: SRA GenAI Exposure Self-Audit

Scores exposure only. Not FCA approval, not regulated advice, and not a funding eligibility check. Does not intercept a live prompt.

Also available: SRA GenAI Exposure Self-Audit · EU AI Act Exposure Check · UK GDPR GenAI Exposure Check

What to do next

Your exposure band is a starting point. Keep the snapshot, share it with Compliance / Risk / SMFs, then close gaps on paper — or move to a board-ready review and, where needed, runtime proof that GenAI use is tested, monitored, and proved.

FCA AI governance, Consumer Duty, and Shadow AI

This pillar section gives search engines and human readers the plain-English context behind the audit above. It explains where GenAI exposure sits for FCA-regulated firms, why Consumer Duty and market-sensitive data still dominate the risk picture, and why policy alone is not proof.

Why FCA AI governance is an exposure problem

FCA-regulated firms are adopting generative AI for research, communications, suitability support, and internal analysis. The tools move faster than most governance packs.

The sharper question for Compliance, Risk, and SMFs is simple: can you show that GenAI use affecting customers or market-sensitive workflows is tested, monitored, and proved — or only that a policy says it should be?

Paper controls catalogue risk. They do not sit between a browser and a large language model at the moment a risky prompt is about to leave the firm. That is why this page starts with a free exposure audit, then explains the conduct, data, and accountability issues behind the score.

Shadow AI in financial services

Shadow AI means staff using public or semi-public GenAI tools for firm work without a clear approved list, supervision model, or evidence trail.

Common patterns include pasting customer details into ChatGPT to rewrite a letter, feeding research notes containing market-sensitive figures into a consumer LLM, or drafting advice-adjacent content without a human review gate.

A ban without visibility is not control. If Compliance, Risk, and IT cannot see which tools touch which workflows, the firm cannot evidence customer-outcome duties or information barriers when a supervisor, auditor, or insurer asks.

Consumer Duty and generative AI

Consumer Duty asks firms to act to deliver good outcomes for retail customers. GenAI can help, and it can also create foreseeable harm through unclear or misleading wording, inconsistent treatment of vulnerable customers, and advice-boundary drift in AI-assisted drafts.

If GenAI touches customer communications or advice-adjacent content, human review before material leaves the firm is a conduct control, not an optional polish step.

Market-sensitive data and information leakage

Feeding restricted, confidential, or market-sensitive data into an external model is not a hypothetical IT issue. It is an information-leakage and market-abuse exposure.

Firms need plain-English rules for what must never be pasted, real examples in training, and evidence that controls hold when tested — not only that principles were circulated.

SM&CR accountability for AI risk

Under SM&CR, someone senior owns this risk whether or not it has been formally assigned. Unclear accountability weakens challenge and makes decision traceability harder to evidence.

Practical questions

Is an SMF, CCO, or Risk owner named for GenAI risk? Has the board or ExCo been briefed in the last year? Can you show which AI tools were used on a material workflow if asked?

Why IT dashboards fail on GenAI execution

DLP, email security, endpoint tools, and Microsoft Purview-class controls matter. They are still not the same as pre-execution governance of LLM prompts.

An acceptable-use policy does not stop a prompt at the moment it is sent. Conduct training does not produce evidence that a bad prompt was blocked. Copilot dashboards do not automatically prove a risky customer-data prompt was refused.

The missing layer is often execution: what crossed the perimeter, whether policy survived run-time, and whether you can prove it afterwards.

Hallucinations, advice-boundary drift, and customer outcomes

Even when no customer data leaves the firm, GenAI can still create harm through hallucination: confident false statements, invented product features, or misleading procedural steps.

For FCA firms, that is a Consumer Duty and communications risk. Controls that only focus on data leakage miss half the problem.

What tested, monitored, and proved means for an FCA firm

For most firms, it means a deliberate bad-prompt exercise with Risk, Compliance, and IT present, ongoing visibility of tools and material GenAI use, and evidence of allow, block, or escalate decisions you can show a supervisor or auditor.

A free exposure audit is step zero: honesty about gaps. A board pack turns that into an accountable plan. Runtime controls are where proof becomes technical rather than aspirational.

How to use this free FCA GenAI exposure audit

Complete the 12-question self-audit above, unlock your exposure band and six-axis profile, and share the snapshot with Compliance, Risk, and IT.

If Evidence or Assurance scores weakly, treat that as a priority. If you need something board-ready, the next step is a facilitated review, board pack, and one-hour consultation. If you need run-time proof, discuss an inline intercept and ledger path.

Frequently asked questions

Is this an official FCA assessment?

No. It is an educational exposure self-assessment. It is not FCA approval, authorisation evidence, or regulated advice.

Does completing the audit make my firm compliant?

No. It maps gaps. Closing gaps — and proving controls at run-time where needed — is a separate programme of work.

Will the audit see our live prompts?

No. The interactive tool does not intercept LLM traffic or write an audit ledger. That is a product and pilot capability, not part of the free quiz.