Proven Duty
File reviews & suitability

Can AI Review Suitability Reports? What It Catches and What It Can't

AI scores suitability reports against COBS 9.2.1R and Consumer Duty outcomes; judgement and sign-off stay human. What the checks catch, and what they miss.

Nick Thorp6 min read

Can AI review suitability reports today?

Regarding AI file reviews, the honest answer splits in two. Reviewing a finished report is a scoring task: the document exists, the words are fixed, and the question is whether the file shows what COBS 9.2.1R requires — a personal recommendation suitable for that client, with the reasons recorded. UK tools now run automated checks across categories such as client profiling, risk assessment, recommendation suitability and report quality, returning pass/fail verdicts with remediation notes. Proven Duty works on the same principle: the firm uploads a report it has already produced, and the AI scores it against a Consumer Duty rubric with line-level citations to COBS, PROD and PRIN 2A.

Drafting is the separate question. AI can prepare a first draft from the fact-find, and the adviser must still select the recommendation, judge suitability and sign the file. The FCA's position around the Mills Review is that the existing regulatory framework can accommodate AI, with no standalone AI rulebook at present. Accountability sits with the firm either way, and the FCA's Consumer Duty publications hub collects the source material.

The framework accommodates the tool; the Duty still names the firm. (Source: FCA FG22/5)

What does AI catch in a suitability report?

Regarding suitability checking, the catches sit in pattern territory. A scoring engine compares the report against the rubric used in Consumer Duty file reviews and against the client record, then flags:

  • recommendations that do not match the recorded risk profile or the stated objectives;
  • missing prescribed content under the suitability report rules (COBS 9.4.7R);
  • stale data — an out-of-date fact-find, an overdue review against the service tracker;
  • charges and ongoing-service figures absent from the document;
  • vulnerability references missing where the client log records one (FG21/1);
  • jargon density, measured against the consumer understanding outcome in PRIN 2A.3.

Consumer Duty requires firms to communicate information in a way clients are likely to understand, and a language check is a pattern task. The table draws the line between the two halves of a review.

What AI catchesWhat stays with a human
Recommendation vs recorded risk profileWhether the profile itself was right for this client
Missing prescribed report content (COBS 9.4.7R)Which trade-offs matter to this client
Overdue reviews and stale fact-find dataWhether ongoing charges still earn their place (PRIN 2A.4)
Vulnerability flag with no FG21/1 referenceThe client's actual circumstances and support needs
Jargon measured against PRIN 2A.3Whether the client genuinely understood
Missing sign-off evidenceThe sign-off itself

Table: Pattern checks a scoring engine performs, and the judgements that remain with the reviewer.

Suitability is judged against the client in the file, not the average client in the model. (Source: FCA COBS 9.2.1R)

What can AI not judge in an advice file?

Regarding vulnerability, the limit shows most clearly. FG21/1 expects a firm to understand a client's individual circumstances and to record the support the client needs. A scanner flags the absence of the reference; a human reads the person. The same gap runs through the rest of the file:

  • Risk attitude: whether the profile in the fact-find was genuinely the client's, or a default carried through.
  • Trade-offs: whether the costs and risks were explained in terms this client recognises.
  • Fair value: whether price is fair for the benefit delivered — PRIN 2A.4 asks for a value judgement, and a tool verifies disclosure without reaching the fairness question.
  • Understanding: an outcome in PRIN 2A.3, not a feature of the document.

Pattern-matching answers one question: is the record complete? Judgement answers the other: is the advice right for this person? Consumer Duty supervision reaches for both, and only one of them is automatable.

The scanner reads the record; the Duty asks about the client. (Source: FCA FG21/1)

Where does the human sign-off sit under Consumer Duty?

Regarding sign-off, the position is settled. The adviser selects the recommendation, judges suitability and signs the file; the tool scores and drafts, and the human decides. Consumer Duty accountability runs to the firm, not the software: PRIN 2A sets the outcomes the firm must evidence, and FG22/5 is the guidance firms work from when demonstrating compliance. A named human overriding an AI flag is a feature of serious tools, not a failure of them — the override record is itself evidence that review happened.

Records carry the weight here. Supervision tests what the file shows: the report, the reasons, the review, the reviewer. An AI-assisted review leaves a stronger trail than a memory of a conversation, because the score, the cited lines and the human decision sit in one document. Compliance officers and boards read the same evidence, which is the file-level end of outcomes monitoring.

The signature is the record of accountability; the override note is the record of judgement. (Source: FCA PRIN 2A)

How do small firms combine AI checks with reviewer judgement?

Regarding workflow, the pattern in the market is consistent. Automated checks enable pre-review coverage of every advice file, so the reviewer starts from flagged lines rather than a blank page. The human reads each flag, agrees or overrides with a reason, and the file ends the process with both layers recorded. Machine first pass, human second pass, one evidence trail — I built Proven Duty around that split.

Regarding ongoing service, the same division holds. A tracker flags the overdue review; the adviser decides what the review covers. PRIN 2A.6 and TR24/1 para 1.40 cover ongoing service, COBS 9A.3.3R covers ongoing suitability assessments, and the file must show delivery, not intention. Data sprawl is the practical obstacle — client evidence sits across CRMs, platforms and cashflow tools, and a review is only as strong as the records it can reach.

Rubric versioning keeps the standard consistent as FCA publications evolve, so the check a file faces matches the guidance in force when the report was written.

Coverage of every file changes what the evidence trail shows. (Source: FCA FG22/5)

About the Author: Nick Thorp is the founder of Proven Duty and writes about what Consumer Duty means at file level. He built Proven Duty's scoring engine around a simple split: machines check patterns, people carry judgement.

Frequently asked questions

Can AI review suitability reports today?

Yes, as a scoring task. AI checks a finished report against a rubric and flags gaps against COBS 9.2.1R and the Consumer Duty outcomes. Drafting is separate: the adviser must still select the recommendation, judge suitability and sign the file, with accountability resting on the firm.

What does AI catch in a suitability report?

Pattern-level gaps: recommendations that do not match the recorded risk profile, missing prescribed report content, stale fact-find data, overdue reviews, vulnerability references absent from the client log, and jargon measured against the consumer understanding outcome. Each catch is a mismatch between the document and the standard.

What can AI not judge in an advice file?

Judgement. Whether the recorded risk attitude was genuinely the client's, whether trade-offs were explained in terms this client recognises, whether price is fair for the benefit delivered under PRIN 2A.4, and whether the client understood. A scanner tests the record; the Duty asks about the person.

Where does the human sign-off sit under Consumer Duty?

With the adviser and the firm. The tool scores and drafts; a named human decides, overrides where needed, and signs. PRIN 2A sets the outcomes the firm must evidence, and the file must show the report, the reasons, the review and the reviewer.

How do small firms combine AI checks with reviewer judgement?

Machine first pass, human second pass, one evidence trail. Automated checks give pre-review coverage of every file; the reviewer agrees or overrides each flag with a reason. Ongoing service follows the same split: the tracker flags overdue reviews, the adviser decides what the review covers.

Guidance based on published FCA material. This article is not regulatory advice.

See what your files are missing

Run one suitability report through the AI file review and get a Pass / Amber / Fail score against Consumer Duty checks.

Try the free file review