AI for brokers

AI-assisted replies under Consumer Duty: a governance checklist for broker firms

A governance checklist for broker firms using AI-assisted WhatsApp replies under Consumer Duty: sign-off, escalation, records and SM&CR accountability.

Published on 5 min readFCB.ai
Contents
  1. Why the Duty reaches into your message drafts
  2. The governance checklist
  3. What good monitoring looks like in practice
  4. How ORIS actually behaves — as a worked example
  5. Frequently asked questions

AI that drafts or sends client replies is no longer hypothetical for UK brokerages: it is a feature in ordinary tools, switched on with a toggle. The FCA has been clear that it does not plan an AI rulebook — existing frameworks apply, as set out in its AI update for financial services. That is not a reprieve. It means every AI-assisted message a firm sends to a retail client already sits inside the Consumer Duty, the FCA Handbook's record-keeping rules and, for accountability, the Senior Managers and Certification Regime. The question for a broking firm is not “are we allowed to use AI?” but “can we evidence that we govern it?”

Why the Duty reaches into your message drafts

Two Consumer Duty outcomes bite directly on automated or AI-assisted messaging. Consumer understanding makes the firm responsible for communications being clear, fair and likely to be understood — authorship is irrelevant, so a misleading sentence drafted by a model is the firm's misleading sentence. Consumer support requires that clients get effective help; an automated reply that deflects a vulnerable client or buries a complaint is a support failure the firm owns.

The consequence is that AI-assisted replies need the same treatment as a new financial promotion process or a new outsourced function: defined scope, named accountability, controls, monitoring and records. None of that is exotic. It fits on one page — and it should, because a policy nobody can remember is a policy nobody follows.

The governance checklist

  1. Define where AI may act alone. List the message types an automated reply may handle without human review (acknowledgements, document confirmations, opening-hours questions) and the types it may never touch alone (advice, complaints, claims decisions, anything about price or cover).
  2. Set a sentiment and topic gate. Decide in writing which signals force a human into the loop: negative sentiment, mention of a complaint, mention of the FOS, a vulnerable-client flag, any request the model is uncertain about.
  3. Require draft-first for everything else. Between “fully automated” and “forbidden” sits the safe default: the AI drafts, a named human reads, edits and sends. The human's edit is your quality control and your training signal.
  4. Cap the machine. Limit how many automated replies a single client can receive, and how quickly. A cooldown between auto-replies prevents the failure mode regulators and clients hate most: a bot arguing with a frustrated customer.
  5. Forbid promises. The system prompt or rule set must prohibit statements about premium, cover, claim outcomes or timescales. If it cannot be found in the policy documents, the machine must not say it.
  6. Log everything. For each AI-assisted message: what was sent, to whom, when, whether it was auto-sent or human-approved, and why the routing decision was made. These records live with your other conversation archives — the same discipline described in archiving WhatsApp under SYSC and ICOBS.
  7. Name the SMF owner. Under SM&CR, a Senior Management Function holder must be able to say “this is mine”: they approved the scope, they see the monitoring, they can switch it off. The FCA's SM&CR pages are explicit that accountability cannot be delegated to a vendor.
  8. Review outcomes, not just outputs. Sample AI-handled conversations monthly. Ask the Consumer Duty question — did the client get a good outcome? — not merely “was the grammar right?”. Feed failures back into the rules.

What good monitoring looks like in practice

A workable monitoring pack for a small or mid-size brokerage is four numbers and one sample. The numbers: share of inbound messages answered automatically, share escalated to a human, average time-to-human on escalated messages, and complaints referencing an automated reply. The sample: ten AI-involved conversations a month, read end-to-end by someone who did not handle them. Firms that do this discover quickly where the boundary between “safe to automate” and “needs a person” actually lies in their own book — it is rarely where the vendor's demo suggested.

Be honest in client-facing terms too: nothing in the Duty requires you to pretend a human wrote every message, and clients who discover otherwise trust the firm less. The comparison between an unsupervised chatbot and supervised AI is worth reading if the firm is still deciding which side of that line to build on.

How ORIS actually behaves — as a worked example

It helps to see the checklist mapped onto a real system. In ORIS, auto-reply is off until a firm enables it, and it runs under rules: a cooldown between automated replies and a maximum number of auto-replies per client. Every incoming message is analysed for sentiment; an automated reply can only be sent when sentiment is positive (or neutral, if the firm allows it). Negative sentiment never gets an automated answer — the AI produces a draft instead, and a handler is notified that a draft reply is ready to review in the shared inbox. The drafting prompt itself forbids promises about price or cover. Messages the system cannot classify safely are flagged for a human. Every message, automated or not, is stored and exportable to CSV, so the audit trail the checklist demands exists by construction rather than by memo.

Whatever tool you use, insist on those same properties: rules you set, a sentiment gate you can see, drafts by default, and records you can export. If a vendor cannot show you where the human enters the loop, that is your answer.

Frequently asked questions

Does the FCA require pre-approval before a firm uses AI in client messaging?

No. There is no authorisation gate specific to AI. The firm remains responsible under existing rules — Consumer Duty, ICOBS, SYSC and SM&CR — for the outcomes its communications produce, however they are generated.

Who should own AI-assisted messaging under SM&CR?

A Senior Management Function holder whose statement of responsibilities plausibly covers client communications or operations. What matters is that one named person approved the scope, reviews the monitoring and can stop the system — not the job title.

Can AI answer questions about a client's premium or cover?

It should not answer them autonomously. Premium and cover statements carry advice and misrepresentation risk; route these to a human, with the AI at most preparing a draft from the policy record for the handler to verify.

What records should we keep of AI involvement?

The message content, timestamps, recipient, whether it was auto-sent or human-approved, and the escalation signals detected. Keep them in the same archive and for the same period as the rest of the client conversation.

Is a monthly human review really necessary if complaint numbers are low?

Yes. Complaints are a lagging and heavily filtered signal — most poor outcomes never become complaints. Sampling conversations is the only way to see how the system behaves with real clients before the annual Consumer Duty board report asks you to evidence it.

See ORIS in action

Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.

Book a demo
Book a demo