Aveni was selected as one of 22 fintechs for the Financial Regulation Innovation Lab’s Future of Wealth Innovation Call.
Over nine weeks, we worked with some of the UK’s largest banks, wealth managers and consultancies to explore a practical question facing firms under the new advice regime: what compliance tools will they need to deliver targeted support safely and at scale?
The discussions covered customer segmentation, vulnerability, real-time monitoring, auditability and senior management accountability. They also helped us define more precisely what firms need from technology when AI starts making or supporting customer-facing decisions.
This is what we learned.
What is FCA targeted support?
The Advice Guidance Boundary Review introduced targeted support as a new form of consumer support.
Non-advised guidance provides factual information without making recommendations. Regulated financial advice, by contrast, involves a personalised recommendation based on an individual customer’s circumstances and carries full suitability requirements.
Targeted support allows firms to give actionable steers to groups of customers who share relevant characteristics, without making a personalised recommendation to an individual. A firm might tell someone that “customers like you often choose…” while stopping short of telling that individual what they personally should do.
The targeted support rules came into force on 6 April 2026, after the FCA opened its Authorisations gateway in March. The FCA has also opened its consultation on simplifying the wider investment advice rules.
For firms, this creates an operational challenge. They need to work out how targeted support will function in real customer journeys while maintaining a clear boundary between support and regulated advice.
FRIL set seven challenges across the Innovation Call, supported by different partner institutions. Aveni took on Use Case 5: Compliance Tools to Support Advice Boundaries.
The challenge focused on how technology could help frontline teams and digital platform owners monitor customer interactions, provide appropriate support and identify when an interaction risks crossing the advice boundary.
Assure was designed around that problem.
Across the nine-week programme, we worked through the challenge in weekly sessions with M&G, NatWest, Lloyds, Barclays, PwC, BNP Paribas, Wesleyan, Standard Life, Sopra Steria and Dudley Building Society.
The advice continuum after AGBR
The new framework creates three distinct categories of customer interaction, each with different limits and responsibilities.
Non-advised guidance
Non-advised guidance provides factual information without recommendations, nudges or steers.
Firms limit the customer information they use so that the interaction does not inadvertently become advice.
Status: Existing regime
Targeted support
Targeted support allows firms to give steers to groups of customers who share relevant characteristics.
A firm might say, for example, “Customers in your situation often choose X.”
Segment-level customer data can make that support more relevant, but the firm does not make an individual recommendation. The firm remains responsible for customer outcomes under Consumer Duty without taking on individual suitability obligations.
Status: Live from 6 April 2026
Regulated financial advice
Regulated financial advice considers an individual customer’s circumstances and results in a specific recommendation.
The firm is responsible for the suitability of that recommendation, bringing the interaction within the full FCA conduct regime.
Status: Existing regime
What partners told us they need
The partner sessions covered different customer journeys, technologies and operating models. Despite those differences, three requirements came up repeatedly.
Real-time enforcement of the advice boundary
Firms need to identify potential boundary breaches while the customer interaction is taking place and intervene before an inappropriate steer reaches the customer.
Several partners described the same underlying risk.
A journey can begin within targeted support and become progressively more personalised as the customer provides additional information. At some point, the nature of the interaction can change enough that it starts to resemble regulated advice.
If the system fails to recognise that change, the customer may receive a steer that crosses the regulatory boundary.
The problem becomes harder to manage when the firm cannot explain why the system produced that response. A compliance team might only identify the issue days or weeks later during a retrospective review, by which point the interaction has happened and the evidence may need to be reconstructed manually.
M&G use case
M&G asked for an AI system capable of detecting boundary risk during the interaction and responding immediately.
They also wanted it to recognise vulnerability indicators, including signs of financial stress or hesitation, while the customer journey was still in progress.
At the same time, the system would need to create a complete, timestamped audit trail. That record should give the firm evidence it could provide to a regulator without requiring compliance teams to reconstruct the interaction afterwards.
PwC approached the same problem from a governance perspective.
Firms need to demonstrate how an output was generated, which controls applied to it and how the interaction was monitored at the time. Rebuilding that explanation later from system logs creates additional work and can leave gaps in the evidence.
Much of traditional conduct monitoring takes place after the event and examines only a sample of customer interactions. That model provides limited oversight when an AI system can generate or influence customer-facing decisions continuously.
For customer-facing AI, firms need monitoring that operates at the same pace as the system itself. Every interaction needs to be assessed, with the relevant evidence captured as part of the process.
Vulnerability throughout the customer journey
Firms need to identify vulnerability as the interaction develops and allow new information to change the customer journey when required.
Targeted support relies on grouping customers according to shared characteristics. Firms therefore need clear rules for deciding which customers belong in each segment and evidence explaining how those decisions were made.
One of the risks is misclassification.
A vulnerable customer may initially appear to fit a particular segment. If the system treats that first decision as fixed, it may fail to recognise information that emerges later in the conversation and changes the customer’s circumstances or support needs.
The customer can then continue through a journey that is no longer appropriate for them.
NatWest use case
NatWest focused on building segments around clear and measurable customer characteristics without relying on lengthy questionnaires that create friction before a customer receives useful support.
Their session also highlighted the importance of behavioural factors alongside quantitative data.
Older or vulnerable customers, for example, may have less access to digital channels or respond poorly to excessive messaging. NatWest therefore emphasised factors such as financial literacy, risk tolerance and propensity to invest alongside transactional information.
M&G focused on what should happen when relevant information emerges during the interaction.
They asked for customer journeys that could respond to changing circumstances, identify when someone may need regulated advice and provide a clear route into that advice.
This changes the role of segmentation. A customer cannot simply be classified once at the beginning of a journey and treated according to that initial decision from then on.
The system needs to keep testing whether the customer still fits the original segment as new information becomes available. Vulnerability detection therefore needs to operate throughout the interaction and influence what happens next.
SMCR oversight of AI agents
Senior managers need evidence showing what an AI agent has done, why it made a particular decision and which controls governed its behaviour.
This issue surfaced throughout the programme.
Under the Senior Managers and Certification Regime, named individuals are accountable for defined areas of conduct within a firm. When an AI agent gives a customer an inappropriate steer, the organisation still needs to explain who was responsible for the system, which controls applied and how that decision was reached.
PwC use case
PwC asked how senior management could demonstrate continuous oversight of AI behaviour in a form that would stand up to FCA scrutiny.
A quarterly governance committee reviewing a small sample of historic outputs gives senior managers only a partial view of a system that may be making customer-facing decisions every day.
They need current information about what the AI has done. They also need to understand why particular decisions were made, which alternatives were considered and who approved the rules or parameters governing the system.
Without that evidence, an SMF holder has a much harder task demonstrating effective oversight of customer-facing AI.
How FRIL shaped Assure
Development of Assure began before the FRIL programme.
The product was built around three core principles:
- assessing AI-agent activity in real time
- using independent, fine-tuned small language models to detect boundary and conduct risk
- applying Human-in-the-Loop controls that can block, rewrite, escalate or approve an action
The partner sessions reinforced those principles, but they also gave us much more detail about how the controls would need to work in practice.
Three requirements became particularly important.
Explicit regulatory state classification
We needed the boundary assessment to identify the regulatory category that applied to each interaction, rather than simply flagging an interaction as potentially risky.
Targeted support, simplified advice and full regulated advice operate under different rules and place different limits on what a firm can say or do.
Assure now classifies the regulatory state of an interaction in real time and identifies when that state changes.
That gives firms evidence showing both whether an interaction stayed within the intended boundary and which regulatory rules applied at different points in the journey.
Reasoning-chain audit trails
Recording the final output was not enough. Firms also needed evidence explaining how the system reached its decision.
The audit trail captures:
- which segment the customer was assigned to
- which signals influenced that decision
- which other options the system considered
- why those alternatives were rejected
M&G’s requirement for a regulator-ready audit trail, generated in real time without manual reconstruction, helped us define this capability more precisely.
The resulting audit trail gives firms a record of the decision process alongside the conversation itself, making it easier for compliance teams and senior managers to understand what happened and why.
Continuous vulnerability re-evaluation
The programme also strengthened our approach to vulnerability.
Detecting a vulnerability signal has limited value if it does not affect the journey. The system needs to use new information as it appears and reconsider earlier decisions when appropriate.
NatWest’s focus on dynamic segmentation reinforced this requirement.
Assure now continues to assess whether a customer fits their original segment throughout the interaction. When vulnerability signals or other relevant information suggest that the initial classification may no longer be appropriate, the system can respond accordingly.
Assure roadmap
The roadmap at the time of the programme covered three stages.
MVP testing
Status: In progress as of May 2026
Assure is live with launch partners and is being A/B tested against existing compliance controls.
Closed beta
Status: Opening to a limited group of prospects
Sandbox access is opening to a limited number of prospects so they can validate performance against historic interaction traces.
Production deployment
Status: Planned
The planned production deployment will operate within agent systems, with VPC, on-premise and hosted deployment options available.
What the rules mean for firms now
The targeted support rules are in force. The Authorisations gateway has been open since March, the rules took effect on 6 April and the FCA has published its Policy Statement.
The FCA has also signalled that firms should use its Pre Application Support Service when seeking the relevant permissions before going live.
For firms preparing to deliver targeted support, four practical compliance requirements stand out.
1. Monitor the boundary in real time
Firms need to recognise when an interaction moves from targeted support towards regulated advice while that interaction is still taking place.
They also need evidence showing how the system monitored the interaction and how the boundary was enforced.
2. Explain and revisit customer segmentation
Firms need to explain how customers are assigned to segments and which information informed those decisions.
Those classifications also need to change when vulnerability signals or other relevant information emerge during the customer journey.
3. Give senior managers usable evidence
Senior Managers under SMCR need evidence showing how they oversee AI agents involved in customer-facing decisions.
A record of the final output alone gives them limited visibility. They need to understand how the system reached the decision, which controls applied and how its behaviour was governed.
4. Maintain regulator-ready audit trails
Firms need to capture and retain evidence that can be retrieved when required, whether the request comes from the FCA, the Financial Ombudsman or through a Section 166 review.
Assure was designed around these requirements.
The nine weeks at FRIL gave us the opportunity to test those assumptions directly with firms dealing with the advice boundary in practice. The programme helped us sharpen the requirements, identify where firms need stronger evidence and decide which product capabilities should take priority.
Working on targeted support?
Assure is in MVP testing with launch partners, with a closed beta opening shortly.
If you are working on targeted support, simplified advice or another use case where AI makes customer-facing decisions, and you need to demonstrate how those decisions are governed, monitored and evidenced, we would like to hear about the problem you are trying to solve.
Acknowledgements
FRIL’s Future of Wealth Innovation Call was led by FinTech Scotland in partnership with the University of Strathclyde and the University of Glasgow, with SuperTech WM, and funded through Innovate UK as part of the Glasgow City Region Innovation Accelerator.
The strategic partners across the programme were PwC, Barclays, Lloyds Banking Group, Sopra Steria Financial Services, NatWest Group, M&G, BNP Paribas, Dudley Building Society, Wesleyan and Standard Life.
The FCA’s Consumer Investments Policy and Market Analysis team provided guidance throughout.
Our thanks go to everyone involved, including the academics at the Adam Smith Business School who supported the consumer research framing.