Across the financial advice industry, compliance is structured as a separate and retrospective function. Advice is given first, then checked afterwards through file reviews, periodic audits and sampled assessments. This model is so established that it is rarely questioned. It should be. The separation of advice from its assurance is a design choice, and it is one the industry now has the technology to reverse.
One process, performed twice
Consider what actually happens in an advice firm today. An adviser gathers a client’s circumstances, assesses suitability, forms a recommendation and records the rationale. A compliance function then takes that same work and re-verifies the inputs, re-assesses the suitability, re-derives the recommendation and re-reads the rationale.
These are not two distinct disciplines. They are a single process performed twice. Good advice is, by definition, compliant advice: a suitability assessment done properly is a compliance activity, and a compliance review done properly is an exercise in advice. The industry has arranged the two in sequence, with assurance following delivery, and that sequencing is the source of significant cost, risk and friction.
The limitations of retrospective assurance
When compliance follows the advice, it can only confirm or condemn decisions that have already been made. If a recommendation is found to be unsuitable, the risk has already been incurred. The client may already be invested and the recommendation already acted upon. Mitigation then depends on remediation, redress and, in the most serious cases, regulatory consequences that documentation alone cannot resolve.
Retrospective assurance is also, by necessity, partial. No firm can afford to re-perform every piece of advice in full, so files are reviewed on a sampled basis at a point in time, and the remainder is assumed to be sound. The industry has normalised a model in which most advice is never actually reviewed, and the advice that is reviewed is checked only after the window for prevention has closed.
The operational consequences follow predictably. Because compliance is experienced as a delayed verdict on completed work, advisers rationally minimise their exposure to it. The function that exists to protect clients and firms becomes under-resourced, deferred and completed as late as possible. This is a structural outcome of the model, and it will persist for as long as the model does.
Embedding compliance at the point of capture
The alternative is to embed compliance into the advice process itself, so that assurance stops being a review of the workflow and becomes a property of the work.
In practice, this means moving verification to the moment of capture. When a client’s date of birth is validated against a source document as it enters the record, its presence in the record is evidence of its soundness. When income figures carry their source and context from the outset, they do not need to be re-verified later. When suitability logic operates alongside the adviser rather than behind them, a recommendation that would fail a review is prevented before it is made.
Modern data architecture and AI make this achievable at scale in a way it was not five years ago. Client information that currently sits fragmented across documents, calls, emails and disconnected systems can be consolidated into a single source of truth, validated on arrival and enriched with the context a reviewer would otherwise reconstruct manually. Once the data carries its own validated state, compliance can be read from that state continuously, across every piece of advice, rather than sampled from a filing system after the fact.
Alignment with the regulatory direction of travel
The regulatory environment increasingly favours this model. Consumer Duty requires firms to evidence good client outcomes, not merely well-ordered files, and outcomes are materially easier to evidence when compliance is continuous and complete than when it is periodic and partial. A model that provides assurance across all advice, all of the time, is a stronger answer to the regulator than one that covers a sample of advice some of the time.
From remediation to prevention
Embedded compliance does not reduce rigour. It relocates it, distributing verification throughout the advice process rather than concentrating it in a retrospective event. For advisers, compliance becomes part of how the work is done rather than a judgement delivered on work already completed. For firms and networks, sampling gives way to full coverage, and remediation gives way to prevention. For clients, every piece of advice carries the same assurance, rather than a sampled fraction of it.
This is the standard Rimbal is building towards, and the standard we believe the industry should hold itself to: financial advice that is compliant at the point it is created, evidenced continuously, and delivering better client outcomes as a result.