23 vendor demos to one workflow in 9 weeks
A 40-staff Tauranga accounting firm pruned 23 AI vendor pitches to one deployed workflow. Audit + selection + implementation, 9 weeks end-to-end.
A 12-adviser NZ financial advice firm, FAP-licensed and regulated by the FMA, asked us to map their existing AI use against the rules. We found four risk categories, recommended two vendor changes, drafted an FMA-ready acceptable use policy, and certified all 12 advisers on safe AI use. Compliance-first, build-second.
All figures illustrative until a real engagement is published with client consent
FMA guidance, Code of Professional Conduct, FAP licence conditions, record-keeping rules. The non-negotiables before any tool selection.
Three highest-value workflows targeted. Tool selection focused on data residency (NZ), provider audit access, and integration with the existing CRM.
Every prompt, every AI output, every adviser sign-off captured in a tamper-evident log. FMA-ready evidence by design, not afterthought.
"Where does generic information end and personalised advice begin?" Worked through with the FAP licence-holder and documented as a workflow rule.
Workshops + supervised SOAs + supervised meetings. No solo use until each adviser had completed 5 supervised drafts.
Live. SOA drafting time down 81%. File-note coverage 100%. The practice can show the FMA, on demand, every prompt and every adviser decision behind every piece of advice.
The firm is a 12-adviser NZ financial advice practice, FAP-licensed and regulated under the Financial Markets Conduct Act. Their work spans retirement planning, KiwiSaver advice, life and disability insurance, and investment portfolio construction for retail clients. They have a strong compliance culture, a designated compliance officer, and a clean record across two FMA monitoring cycles.
The firm came to us with a problem that's becoming common across FAP-licensed practices. AI tools had quietly become part of how the team works, without ever being explicitly approved. Three of the 12 advisers were using ChatGPT to draft client letters. Two were using an AI meeting note-taker that joined client video calls automatically. One was using an AI research summarisation tool for product research. The compliance officer hadn't approved any of these. The advisers hadn't disclosed their AI use to the compliance officer because they weren't sure whether they needed to.
The trigger to call us was an informal conversation at an industry event where an FMA representative had mentioned, without naming firms, that the regulator was paying attention to AI use in financial advice. Two specific concerns had been raised: client data sitting on offshore servers without disclosure, and the risk of AI-generated text being treated by clients as advice when no advice had been given. Neither was a formal warning. Both were enough to spook the directors into wanting an independent review.
The brief was unusually specific. "We're not asking you to build us an AI strategy. We're asking you to tell us what we're doing right now that's risky, what we should stop, what we can keep doing safely, and to leave us with a written policy we can take to a future FMA conversation with confidence. Treat us like a regulator would." That's exactly the brief our practice was set up for.
Craig led this engagement personally. The CFP designation and his FAP-licensed practice (Wealth Health, separate brand, same person) meant we could move at speed: no need to learn what a SOA is, no need to explain why suitability matters, no need to translate FAP obligations into AI language. We could go straight to the practical questions.
We started by mapping every AI tool currently being used by any adviser or staff member, formally or informally. The compliance officer surveyed all 12 advisers in writing. We interviewed each adviser individually for 30 minutes, in confidence, to ensure people felt safe to disclose informal usage. The total list came to seven distinct tools across the team, four of which the compliance officer had been unaware of.
For each tool, we documented: what data was being uploaded (client identifying details, financial information, advice content), where that data sat (NZ, Australia, US, EU), whether the tool's terms permitted use of data for training, what disclosure (if any) was being made to clients, and whether the use was advice-output or advice-adjacent. The advice-output distinction mattered. AI that drafts a client letter that explains an adviser's recommendation is in a different regulatory category from AI that summarises a product PDS for the adviser's own research.
We mapped the inventory against four risk categories, agreed in advance with the compliance officer:
Across the seven tools and 12 advisers, we found six material issues. Two tools had a data residency footprint that included US servers without an explicit data-processing addendum acceptable for retail client financial data. One tool was being used to draft direct client communications without an adviser-review step, which we flagged as advice-output risk under the FAP code. Two advisers had been pasting client identifiers into a public AI chat interface, which we flagged as a Privacy Act issue. One process gap meant AI-drafted material wasn't being archived alongside the final advice record, breaking the audit trail.
We drafted an AI Acceptable Use Policy for the firm, designed specifically to a FAP-licensed standard. The policy covered: approved tools list and process for approving new tools, prohibited uses (paste of client identifiers into public AI tools, AI-only client communications, AI-generated advice outputs without explicit adviser review and signoff), data residency requirements for any retained tool, audit trail and record-keeping obligations, mandatory disclosure language to be added to the firm's disclosure document and engagement letters, incident response if a breach were to occur, and the supervision protocol for AI use across the team.
The policy was reviewed by the firm's external compliance counsel before signoff, and ratified by the board. It deliberately reads more like a code of conduct than a tool manual: the rules apply to any AI tool, current or future, not to specific products. The compliance officer keeps a separate, current approved-tools list as an annex, which can be updated without a full board re-ratification.
Two of the seven inventoried tools needed to go. We recommended replacements with appropriate data residency, advice-output suitability, and contractual terms. The firm made both switches inside week three. Migration was minor: each tool replacement was a like-for-like swap, and the advisers using them transitioned in a single working day each.
All 12 advisers were then certified on the new policy. Certification involved a 90-minute training session, a written test of policy comprehension, and a signoff acknowledging the rules. The compliance officer now keeps the certification register and refreshes annually as part of the firm's standard CPD cycle.
Craig knew the FAP code and the FMA's posture better than my external compliance counsel did. That's not common in AI consulting. We got a policy I'd actually be willing to put on the table in an FMA conversation.Compliance Officer · NZ FAP-licensed advice firm · 12 advisers · illustrative quote
Three months after policy ratification, the firm reports the following:
Defensible compliance posture. The firm now has a board-ratified, external-counsel-reviewed Acceptable Use Policy specifically for AI, mapped against the FAP code of conduct and the Privacy Act 2020. The policy is referenced explicitly in the firm's disclosure document and engagement letters. If the FMA were to ask, the firm has documentation, a certification register, an approved-tools list, and an audit trail.
Lower vendor risk. The two tool changes removed the two clearest data-residency exposures. Both replacements have AU/NZ data processing footprints and contractual data-processing addenda the firm is comfortable with. The remaining five tools are operating under the new policy without changes.
No reduction in productivity. Worth naming explicitly. The compliance review didn't slow the firm down or reduce AI use. The same advisers using AI tools before are still using AI tools after, just within a defined framework. The two tool switches were transparent to the advisers using them.
Higher adviser confidence. The 12 advisers now have explicit clarity about what they can and can't do with AI. The previous ambiguity (where individual advisers were quietly using tools and hoping it was okay) has been replaced with a written policy and a certified training. Several advisers commented in their certification feedback that they would now use AI more, not less, because the rules were clear.
Annual refresh built in. The policy includes a built-in annual review point. AI tooling moves quickly. The firm has booked Craig under a Fractional AI Director retainer to handle the annual review and any in-year approvals of new tools, so the policy stays current without the compliance officer having to become an AI specialist.
What didn't happen. The firm didn't ban AI. That was on the table early on, and the directors had genuinely considered it. The review concluded that a ban would have been a self-inflicted competitive disadvantage, given that competing firms were already using AI safely. We didn't recommend a custom-built compliance platform. The firm's existing practice management and compliance tooling, with the AUP layered on top, was sufficient. And we didn't try to upsell into Workflow Integration or Tool Stack Selection. The brief was a compliance review, and that's what we delivered. Future workflow work may come, but that's the firm's decision when they're ready.
Industry. NZ financial advice firm, 12 advisers, FAP-licensed, FMA-regulated.
Lead consultant. Craig Coupland, CFP, FSP 105424. FAP-licensed practice in parallel.
Engagement. Risk + Compliance Review + Acceptable Use Policy drafting + adviser certification.
Duration. 3 weeks start to ratified policy + 100% adviser certification.
Investment. Engagement fees, plus ongoing Fractional AI Director retainer for annual review.
Illustrative engagement · real client outcomes published with consent only
A 40-staff Tauranga accounting firm pruned 23 AI vendor pitches to one deployed workflow. Audit + selection + implementation, 9 weeks end-to-end.
An 18-lawyer NZ practice rebuilt their contract review workflow with AI assistance. Per-contract time fell from 42 minutes to 8, error rate fell 67%.
How we approach AI engagements for FAP-licensed advice firms. FMA expectations on AI in advice, what AI can and cannot do in a regulated context, and where to start.
Book a 30-min call to discuss your situation. Craig will speak FAP, FMA, and Privacy Act fluently. No translation tax.