FCA GenAI Exposure Audit:
Consumer Duty, Market-Sensitive Data, and Shadow AI
Most FCA-regulated firms now have an AI policy. Far fewer can show that GenAI in customer-facing or conduct-sensitive work is tested, monitored, and proved — not only written down. That gap is where Shadow AI, data leakage, and Consumer Duty risk quietly grow.
This free FCA-aligned GenAI exposure self-audit maps where ChatGPT, Claude, Gemini, Copilot, and similar tools can expose customer data, market-sensitive information, Consumer Duty outcomes, and SM&CR accountability.
Twelve questions · Yes / Partial / No / Unknown · about 3–4 minutes.
You receive an exposure band and a six-axis control-strength profile — a plain-English snapshot for CCOs, Heads of Compliance, Risk, SMFs, and advisers. It scores exposure only.

Start the self-audit
Twelve questions. Answer Yes / Partial / No / Unknown. Then unlock your exposure band and six-axis control-strength profile.
Also available: SRA GenAI Exposure Self-Audit
Scores exposure only. Not FCA approval, not regulated advice, and not a funding eligibility check. Does not intercept a live prompt.
Also available: SRA GenAI Exposure Self-Audit · EU AI Act Exposure Check · UK GDPR GenAI Exposure Check
What to do next
Your exposure band is a starting point. Keep the snapshot, share it with Compliance / Risk / SMFs, then close gaps on paper — or move to a board-ready review and, where needed, runtime proof that GenAI use is tested, monitored, and proved.
FCA AI governance, Consumer Duty, and Shadow AI
This pillar section gives search engines and human readers the plain-English context behind the audit above. It explains where GenAI exposure sits for FCA-regulated firms, why Consumer Duty and market-sensitive data still dominate the risk picture, and why policy alone is not proof.
Why FCA AI governance is an exposure problem
FCA-regulated firms are adopting generative AI for research, communications, suitability support, and internal analysis. The tools move faster than most governance packs.
The sharper question for Compliance, Risk, and SMFs is simple: can you show that GenAI use affecting customers or market-sensitive workflows is tested, monitored, and proved — or only that a policy says it should be?
Paper controls catalogue risk. They do not sit between a browser and a large language model at the moment a risky prompt is about to leave the firm. That is why this page starts with a free exposure audit, then explains the conduct, data, and accountability issues behind the score.
Shadow AI in financial services
Shadow AI means staff using public or semi-public GenAI tools for firm work without a clear approved list, supervision model, or evidence trail.
Common patterns include pasting customer details into ChatGPT to rewrite a letter, feeding research notes containing market-sensitive figures into a consumer LLM, or drafting advice-adjacent content without a human review gate.
A ban without visibility is not control. If Compliance, Risk, and IT cannot see which tools touch which workflows, the firm cannot evidence customer-outcome duties or information barriers when a supervisor, auditor, or insurer asks.
Consumer Duty and generative AI
Consumer Duty asks firms to act to deliver good outcomes for retail customers. GenAI can help, and it can also create foreseeable harm through unclear or misleading wording, inconsistent treatment of vulnerable customers, and advice-boundary drift in AI-assisted drafts.
If GenAI touches customer communications or advice-adjacent content, human review before material leaves the firm is a conduct control, not an optional polish step.
Market-sensitive data and information leakage
Feeding restricted, confidential, or market-sensitive data into an external model is not a hypothetical IT issue. It is an information-leakage and market-abuse exposure.
Firms need plain-English rules for what must never be pasted, real examples in training, and evidence that controls hold when tested — not only that principles were circulated.
SM&CR accountability for AI risk
Under SM&CR, someone senior owns this risk whether or not it has been formally assigned. Unclear accountability weakens challenge and makes decision traceability harder to evidence.
Practical questions
Is an SMF, CCO, or Risk owner named for GenAI risk? Has the board or ExCo been briefed in the last year? Can you show which AI tools were used on a material workflow if asked?
Why IT dashboards fail on GenAI execution
DLP, email security, endpoint tools, and Microsoft Purview-class controls matter. They are still not the same as pre-execution governance of LLM prompts.
An acceptable-use policy does not stop a prompt at the moment it is sent. Conduct training does not produce evidence that a bad prompt was blocked. Copilot dashboards do not automatically prove a risky customer-data prompt was refused.
The missing layer is often execution: what crossed the perimeter, whether policy survived run-time, and whether you can prove it afterwards.
Hallucinations, advice-boundary drift, and customer outcomes
Even when no customer data leaves the firm, GenAI can still create harm through hallucination: confident false statements, invented product features, or misleading procedural steps.
For FCA firms, that is a Consumer Duty and communications risk. Controls that only focus on data leakage miss half the problem.
What tested, monitored, and proved means for an FCA firm
For most firms, it means a deliberate bad-prompt exercise with Risk, Compliance, and IT present, ongoing visibility of tools and material GenAI use, and evidence of allow, block, or escalate decisions you can show a supervisor or auditor.
A free exposure audit is step zero: honesty about gaps. A board pack turns that into an accountable plan. Runtime controls are where proof becomes technical rather than aspirational.
How to use this free FCA GenAI exposure audit
Complete the 12-question self-audit above, unlock your exposure band and six-axis profile, and share the snapshot with Compliance, Risk, and IT.
If Evidence or Assurance scores weakly, treat that as a priority. If you need something board-ready, the next step is a facilitated review, board pack, and one-hour consultation. If you need run-time proof, discuss an inline intercept and ledger path.
Frequently asked questions
Is this an official FCA assessment?
No. It is an educational exposure self-assessment. It is not FCA approval, authorisation evidence, or regulated advice.
Does completing the audit make my firm compliant?
No. It maps gaps. Closing gaps — and proving controls at run-time where needed — is a separate programme of work.
Will the audit see our live prompts?
No. The interactive tool does not intercept LLM traffic or write an audit ledger. That is a product and pilot capability, not part of the free quiz.
Related GenAI exposure checks
Also see SRA GenAI Exposure Self-Audit, EU AI Act Exposure Check, and UK GDPR GenAI Exposure Check.
