QuestionAI GovernanceLegal ServicesImplementation

How should firms disclose AI use to clients across RICS, SRA, ICAEW and ICO rules?

4 August 2026
Answered by Rohit Parmar-Mistry

Short answer

A quick answer first, then the fuller context below.

Firms should disclose AI use to clients when it affects advice, judgement, confidentiality or service delivery. The safest approach is a clear policy, matter-level judgement and an audit trail that shows human review.

What this points to

This usually points to AI governance consulting

If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.

Detailed answer

The fuller context, trade-offs and practical steps behind the short answer.

Why AI disclosure is now a conduct question

Professional services firms should treat AI disclosure as a conduct, governance and client trust decision, not as a generic technology notice. The question is whether the use of an AI-enabled tool affects the client's matter, the firm's judgement, the handling of confidential data or the quality evidence behind the advice.

RICS, SRA, ICAEW and ICO expectations differ in language, but they point in the same direction: be transparent where transparency matters, protect confidential information, keep professional accountability with the firm and retain enough evidence to explain how a decision or output was reached.

The safest answer is selective, documented disclosure

Firms do not need to announce every internal productivity tool in every client conversation. They do need a clear route for deciding when AI use must be disclosed, agreed or recorded. If AI touches client data, contributes materially to advice, changes who reviews the work, or introduces a new third-party processing risk, the firm should assess disclosure before the work proceeds.

A practical policy should set three levels. Low-risk internal admin can usually sit under a general technology and confidentiality policy. Matter-support use, such as summarising documents or drafting first-pass analysis, should require human review and a matter record. High-risk use, such as automated judgement, regulated advice support or special-category personal data processing, should require client-facing disclosure, senior sign-off and a documented data protection assessment.

Check where AI disclosure and audit trail risk sits in your firm

How the regulatory threads fit together

The SRA lens is supervision, confidentiality, competence and client best interests. A solicitor cannot delegate judgement to a tool and then treat the output as self-validating. If AI is used on client work, the firm needs a competent reviewer, clear responsibility and a record showing the advice was checked.

The RICS lens is professional standards, transparency, conflicts and evidence. If AI affects valuation, survey, assurance or client reporting work, the firm should be able to explain the source data, assumptions, limitations and human review behind the final output.

The ICAEW lens is professional scepticism, integrity, quality management and documentation. Accountancy and audit work needs evidence that AI-assisted steps did not weaken review, independence or the audit trail. The ICO lens is lawful basis, fairness, transparency, minimisation, processor due diligence and security. If personal data is processed by an AI system, the firm must understand what data leaves its environment, where it is stored and whether individuals have been given the required information.

A client disclosure policy that works in practice

Start with a short firm-wide position that says where AI may be used, where it is banned, and who owns approval. Then add matter-level questions for teams:

  • Will any client, employee or third-party personal data enter the tool?
  • Will the AI output influence advice, valuation, audit work, claims handling or a client recommendation?
  • Is the tool approved, contracted and checked for retention, training and security terms?
  • Does the client engagement letter, privacy notice or matter plan already cover this use?
  • Who reviews the output, and what evidence will prove that review happened?

This turns disclosure from a vague principle into a repeatable control. It also helps partners, managers and compliance leads make similar decisions across legal, property, accountancy, insurance and advisory work.

Build a practical AI governance operating model

What to say to clients

Client wording should be plain and specific. Avoid broad claims that AI is always safe or always supervised. A better disclosure says what type of tool may be used, what it may be used for, what data controls apply, who remains accountable and how the client can ask questions or restrict use.

For sensitive matters, regulated advice, personal data, privileged material or confidential commercial information, the firm should record the client's position and keep the record with the matter file. Where disclosure is not required, the firm should still keep internal evidence of the assessment. That evidence is useful if a regulator, insurer, client or internal reviewer later asks why the firm thought the use was acceptable.

Implementation checklist

  • Map the approved AI tools and the data each one may process.
  • Define disclosure triggers for client data, regulated judgement and third-party processing.
  • Update engagement letters, privacy notices or service descriptions where needed.
  • Create a matter-level AI use record for higher-risk work.
  • Train reviewers to check outputs for accuracy, bias, missing context and unsupported assumptions.
  • Review insurance, supplier contracts and processor terms before scaling use.

Turn AI disclosure rules into working controls

Conclusion

The right disclosure standard is neither silence nor blanket warnings. It is a controlled process that links each AI use case to client impact, confidentiality, data protection, professional accountability and evidence. Firms that can show that process will be in a stronger position with clients, regulators and insurers.

FAQs

Direct follow-up answers written for searchers, buyers and internal decision makers.

Do we need to disclose every use of AI?

No. Low-risk internal use may not need matter-specific disclosure, but the firm should still have an approved-tool policy and a record of its risk assessment.

When is client-facing disclosure most likely needed?

Disclosure is most likely needed when AI processes client data, affects professional judgement, supports regulated advice or changes the way the service is delivered.

Can we rely on human review instead of disclosure?

Human review is essential, but it does not replace disclosure where the client, regulator, contract or privacy position requires transparency or consent.

What evidence should we keep?

Keep the tool used, purpose, data category, reviewer, quality checks, disclosure decision and any client instruction or approval linked to the matter.

Need More Specific Guidance?

Every organisation's situation is different. If you need help applying this guidance to a specific process, book a discovery call or take the assessment first.