ChatGPT will write you a suitability report. That's the problem, not the selling point. A general assistant produces confident prose with no access to your client record, no trail of what it used, and no way to show that the same case would produce the same output tomorrow. It's genuinely useful for thinking out loud, sharpening an email and explaining a concept in plainer English. It isn't a place to put client data, and it isn't a system you can evidence to a regulator. Know which of those 2 jobs you're doing before you paste anything into it.
Key takeaways
- A general assistant is a writing tool, not a system of record, and the gap between those is where firms get into trouble.
- The 5 things it can't do for a regulated firm: connect to your client data, show provenance, reproduce output, enforce sign-off, or give you evidence.
- The data terms differ by tier. Which account you use decides whether client data is a problem.
- Purpose-built adviser software is worth paying for when it removes re-keying and produces a trail, not because its writing is better.
- Firms use these tools anyway, so a written policy beats a ban nobody follows.
Can financial advisers use ChatGPT?
Yes, for some things, and plenty of advisers already do. The question worth answering is which things.
The honest split is between work where the output is a draft you'll rewrite, and work that touches a client's file. General assistants are strong at the first and structurally unsuited to the second. Not because the writing is poor, it often isn't, but because a regulated firm needs to show how something was produced, and a chat window can't show you that.
What a general assistant is good for
Real uses, worth having:
- Thinking out loud. Arguing with a model about how to structure a difficult explanation is a good use of 10 minutes.
- Plain English. Turning a technical paragraph into something a client can follow, then checking it kept the meaning.
- Emails and marketing. Prospect follow-ups, newsletter drafts, website copy. Low risk, immediate payback.
- Summarising public documents. A policy statement, a consultation paper, a provider's terms. Verify anything you'll rely on.
- Learning. Explaining a rule you half remember, with the source checked afterwards.
Nothing on that list touches a client record, and that's the pattern.
The 5 things it can't do for a regulated firm
1. Connect to your client data. It doesn't know your client. Everything it produces about them comes from what you paste in, which means either a generic document or a manual transfer of the data you were trying to stop re-keying. Neither is capacity.
2. Show provenance. A suitability report needs every figure traceable to a source. A chat response has no sources, and asking it to cite them produces citations it generated, which is a different thing.
3. Reproduce its output. Run the same prompt twice and you'll get 2 different documents. That means you can't tell your compliance oversight how your firm's reports are produced, and every file has to be reviewed cold because none of them share a structure.
4. Enforce a sign-off. There's no step that can't be skipped, no record of who checked what, and no difference between a draft an adviser read carefully and one they didn't.
5. Give you evidence. After the fact, you can't show what was used, what was changed, or who approved it. The document exists and the story of how it came to exist doesn't.
None of these are criticisms of the tool. It was built to be a general assistant, and it's an excellent one. They're the reasons a general assistant isn't advice infrastructure.
The client data question
This is the one that ends most firm policies, and it deserves precision rather than panic.
The consumer, business and API tiers of these products have different data terms, and the tier you use decides whether this is a problem. Some train on your inputs by default, some don't, some let you turn it off. Read the terms for the account you're on, not the terms you read about somewhere.
Then, whichever tier you're on, you still need to answer for your own records: what personal data left the firm, on what lawful basis, to which processor, in which country, and for how long it's retained. A member of staff pasting a fact find into a personal account has made your firm's data protection decisions on your behalf, and you'll be the one explaining it.
The safest working rule for a small firm: no client identifying data in a general assistant. Anonymised scenarios are fine. A real fact find isn't.
What "AI financial adviser software" means instead
Purpose-built adviser software isn't a better writer. In some cases the underlying models are the same ones. What it adds is everything around the writing:
- It reads your client record, so a draft starts from what you already hold rather than what you paste.
- It keeps provenance, so each figure points at where it came from.
- It produces the same output from the same case, so the file is consistent and review is fast.
- It holds a sign-off step that's recorded and can't be skipped.
- It writes the audit trail as the work happens, so the evidence exists without anyone assembling it.
- It handles data under terms your firm can evidence, in a processor relationship you can document.
That list is what you're paying for. If a vendor's pitch is about writing quality alone, they're selling you something you can get for £20 a month.
If your firm uses it anyway, do these 4 things
Bans don't work. People have these tools on their phones. Write the policy instead:
- Name the accounts. Which product, which tier, paid for by the firm. Personal accounts are where the data risk lives.
- Draw the client data line in writing. Anonymised scenarios yes, client identifying information no, and say what counts as identifying.
- Require verification for anything factual. Rules, figures, product features, all checked against source before use. Treat model output as a confident colleague who is sometimes wrong.
- Keep it away from the advice file. Marketing, learning and drafting explanations are fine. The suitability report is produced in a system that leaves a trail.
That's a policy a small firm can write in an afternoon and stick to.
Frequently asked questions
Is it safe to use ChatGPT for financial advice work?
It's safe for work that doesn't involve client identifying data and doesn't go on the advice file: marketing copy, plain English explanations, summarising public documents. It isn't suitable for producing client documents, because you can't evidence how the output was made and you can't reproduce it. Check the data terms for the specific tier your firm is on.
Can I put client information into ChatGPT?
Treat that as no unless your firm has documented otherwise. Even on tiers that don't train on your inputs, you've sent personal data to a third party and you need a lawful basis, a processor relationship and a retention position you can explain. Anonymised scenarios give you most of the benefit with almost none of the exposure.
Will ChatGPT write a compliant suitability report?
It will write something that looks like one, which is the risk. It has no access to your client record, so the detail is either generic or pasted in by you, and it can't show where any figure came from. A report that reads well and can't be traced is harder to defend than an untidy one that can.
What's the difference between ChatGPT and AI adviser software?
The writing is the smallest part. Adviser software connects to your client data, keeps provenance for every figure, produces consistent output from the same case, enforces a recorded human sign-off, and leaves an audit trail. A general assistant does none of those, because none of them were the problem it was built to solve.
Is purpose-built AI software worth the cost over a £20 subscription?
Compare them on hours removed per case rather than on writing quality. A general assistant saves you drafting time and gives back nothing on re-keying, checking or evidence. If a platform removes hours from every case and produces the trail as a by-product, the comparison isn't close, and if it doesn't, don't buy it.