Sector: FCA
A step-by-step guide to capturing, recording and presenting evidence of AI use that stands up to file reviews, FCA queries and PI insurers.
16 June 2026 · 7 min read
Most FCA-regulated advice firms now have staff using AI tools, whether the firm has formally adopted them or not. The question a supervisor, file reviewer or PI insurer will eventually ask is not "do you use AI?" but "show me how you use it, and how you know that's what's happening." If the honest answer is a policy document and a verbal assurance, that is not evidence. This is a practical guide to building evidence that holds up.
A policy states an intention. Evidence shows the intention was met. The FCA's expectations under the Consumer Duty and SYSC 9 both turn on demonstrable practice: you need to show oversight is real and that records exist. The same gap appears under SM&CR, where a senior manager is expected to be able to evidence reasonable steps, not simply describe them.
The goal is to be able to answer three questions on demand, with records rather than recollection:
This has only become more pressing since the FCA published its Mills Review into AI and the future of retail financial services in July 2026. The Review describes retail financial services "moving from human-led, towards AI-enabled, continuous and delegated services", with more work handed to AI that acts on a firm's behalf. The more of your AI activity that runs autonomously, the harder it is to evidence by asking a member of staff, and the more the record has to come from the system itself.
Start with coverage. Evidence is only as good as the blind spots it leaves. A defensible picture spans three layers:
A firm that can only see one of these layers has an evidence gap, and gaps are exactly what reviewers probe.
Raw usage logs are necessary but not sufficient. What turns them into oversight is flagging the use that matters. The signals worth surfacing are:
The point of flagging is not to assume wrongdoing. It is to make the small number of higher-risk interactions visible, so a compliance function can review them rather than trawl everything.
Detection after the fact is one half of the story; the FCA will also want to see controls that reduce harm before it happens. A gateway sitting between staff and the models can enforce this. Evaident's gateway can block UK PII, common secrets and credentials, and customer-defined blocked terms — for example client names or account references — before a request leaves the firm. It can also enforce approved vendors and models, apply out-of-hours rules, and hold an organisation-wide spend cap.
One caveat to record honestly: customer-defined terms are matched as case-insensitive substrings, not full data-loss-prevention. It is a meaningful guardrail, not a guarantee, and your evidence should describe it as such.
SYSC 9 is about adequate record-keeping, not maximal surveillance. You do not need to read every employee's prompts to evidence oversight, and over-collection creates its own data-protection problem.
A sensible default is metadata capture — who, what tool, when, and which risk flags fired — without storing the content of prompts. Preview or fuller content can be turned on where a firm decides it is justified, on an opt-in basis. Full verbatim capture is heavier still: in Evaident it is the approval-gated Enhanced Content Capture add-on, not part of the standard plans. Match the depth of capture to the risk, and document why you chose the level you did.
Evidence that cannot be trusted is not evidence. When you hand a file reviewer, the FCA or a PI insurer a record of AI use, they need confidence it reflects what actually happened and has not been edited since.
Evaident produces tamper-evident evidence packs using an HMAC-SHA256 hash chain, accompanied by a chain-integrity certificate. That lets you demonstrate the record is intact, which is the difference between a log and a piece of evidence.
Retention should match your review and complaints horizon. On the Control plan, records are held for 24 months; on Assure, up to 84 months — long enough to cover most look-back periods a reviewer or insurer will apply.
Use this as a starting structure for your own evidence file:
None of this is legal advice, and tooling supports compliance rather than delivering it — the judgement about what is adequate for your firm remains yours. But moving from "we have a policy" to "here is the dated, tamper-evident record of who did what" is the step that turns an awkward FCA query into a short one.
If you want to see where your firm stands today, start with your /exposure and read more on how this maps to the rules at /fca.
The free AI Exposure Check gives you an instant score across visibility, shadow AI, evidence, governance and data-leak risk — no data connection needed.