Proven Duty

How to anonymise a suitability report in five minutes

“I'm not putting client files through a tool” — the right instinct, and five minutes to satisfy it.

Why anonymisation is a file-review topic

There is no FCA rule called “anonymisation”. The legal frame for moving personal data through a process is data protection — UK GDPR and the Data Protection Act 2018. Anonymisation lets a client's suitability content move through a file review without personal data moving with it. The reviewable content must survive; the identity must not.

The FCA's Consumer Duty pages make outcomes monitoring a firm duty. A review that cannot happen because the file cannot be moved safely is a monitoring failure — the anonymisation protocol exists so the two do not collapse into each other.

In Enforcement Watch 2 the FCA describes firms that could not demonstrate what they did, for whom, and to what effect — a record-keeping failure as much as a product one. A file fit for review is one that can be moved, scored, and kept.

The protocol: four steps

Four actions, in order, every time. Each maps to the type of personal data the report carries.

  1. 1

    Names

    Names become CLIENT A. National Insurance, DOB, and account numbers are removed entirely.

  2. 2

    Amounts

    Round them. £183,427 becomes £180,000. The compliance logic does not care about the exact figure.

  3. 3

    Addresses

    Reduce to region only — 'South East', not the full address.

  4. 4

    Keep

    The structure, the reasoning, the disclosures, and the recommendation. Everything a file review checks survives anonymisation.

Everything a file review checks survives anonymisation. Everything a fraudster wants does not.

Worked example: the same report, anonymised

Before

“Recommendation for James Whitfield, NI number AB 12 34 56 C, of 14 Acacia Avenue, Leeds LS1 2AB: £183,427 to be invested in the growth portfolio, which reflects James's objectives.”

After

“Recommendation for CLIENT A (identifiers removed), South East region: £180,000 to be invested in the growth portfolio, which reflects the client's objectives.” The name is gone, the identifiers are gone, the address is a region, the amount is rounded — the reasoning a review checks survives word for word.

Common mistakes in anonymisation

The protocol, step by step

StepDoWhy
NamesReplace with CLIENT A.The name is the first identifier.
IdentifiersRemove NI, DOB and account numbers.They identify the client more strongly than a name.
AmountsRound to a sensible figure.Exact figures re-identify; rounded ones do not.
AddressesReduce to a region.Location context survives without identity.
Final passStrip metadata; check cross-references.Anonymisation is verified, not assumed.

Related reads

Anonymisation is the gate into the workflow. See the file review and suitability hub for the whole pipeline, the AI tool explainer for what happens next, and the 12-point file-review checklist for the checks the anonymised file still has to pass.

Frequently asked questions

Isn't anonymisation a data protection matter, not an FCA one?

There is no FCA rule called 'anonymisation' — UK GDPR and the Data Protection Act 2018 are the legal frame for how personal data moves through a process. Anonymisation is what makes a file-review process compliant with both.

Does anonymisation take long?

About five minutes once the pattern is fixed: names to CLIENT A, identifiers removed, amounts rounded, addresses to a region, and a final pass for metadata. The first file is the slowest.

Does anything a review checks get lost?

No. Structure, reasoning, disclosures and the recommendation all survive intact. The reviewable content is deliberately preserved; what is removed is only what would identify the client.

Your next step

Anonymise one real file today, end to end, and time it. When the objection is “client data through AI”, the answer is a five-minute protocol that leaves the reviewable content intact. Proven Duty reviews files prepared exactly this way. Start a free trial or see pricing.