QuestionAI GovernanceImplementationLegal Services

Where does client data go when UK consultants use AI, and what controls should firms require?

28 September 2026
Answered by Rohit Parmar-Mistry

Short answer

A quick answer first, then the fuller context below.

Before using AI on client work, verify the exact product and plan’s data use, retention and access settings, then record the permitted data, controls and human review. This gives professional-services partners an auditable basis to approve a use case, restrict it or keep client information out until gaps are resolved.

What this points to

This usually points to AI governance consulting

If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.

Detailed answer

The fuller context, trade-offs and practical steps behind the short answer.

UK consulting, accountancy, legal and advisory firms should not approve an AI tool for client work based only on a product label or a general assurance about data protection. For each proposed use, check the engagement terms, identify the information involved and verify the settings and terms for the exact product and plan. If permission or a necessary control is unclear, keep the information out until the engagement owner resolves the question.

Start with the engagement and information

Check the signed engagement terms and any client-specific restrictions. Classify the material staff propose to use-for example, public information, internal material, confidential client records, personal data or information subject to heightened duties. A use that is suitable for public research may not be suitable for a confidential transaction or regulated advice. Where terms are silent or unclear, record the uncertainty and ask the engagement owner to decide.

Trace data through the exact product and plan

Record the product, plan, model provider and enabled features. Verify what may be sent through prompts, files, connectors and generated outputs; whether inputs may be used for training or service improvement; how long prompts and logs are retained; where processing occurs; and which provider personnel or subprocessors may have access. Check the applicable contractual terms and live administrative settings for that specific plan. Treat training, retention and access as separate questions.

Set proportionate controls before use

For each approved use case, document the purpose, permitted data categories, approved product and plan, accountable owner, access restrictions, any redaction or minimisation steps, retention requirements and response if information is entered into an unapproved service. Do not treat removing names as proof that a document is anonymous; surrounding context may still identify a person or engagement.

Keep professional judgement and review visible

Assign a qualified reviewer before use and match the review to the consequences of an error. Preserve enough evidence to reconstruct the work: the approved use case, product and data class, checks performed, reviewer, changes made and final decision. Apply any partner or specialist sign-off required by the firm’s own policies, client commitments and applicable obligations.

Make the decision repeatable

A concise register can connect each use case to its purpose, data class, verified product and plan, contractual basis, controls, reviewer, evidence location and next review date. Recheck it when a provider changes terms or features, an engagement changes or an incident occurs. This gives partners a practical basis to approve, restrict or stop a use case rather than relying on informal assumptions.

When to get help

If your firm cannot map data flows, verify supplier terms, assign owners or set meaningful review points, map the work and exposure before buying another tool. Pattrn Data’s AI Risk & Efficiency Audit can help identify where AI may help or add risk, and which controls and decisions need to be made visible. For a defined implementation, see Pattrn Data implementation services.

Source and provenance

Adapted from the source question, “Where does your data go when a consultant uses AI?”, and the source article Protecting your data when consultants use AI. Product terms, settings and client obligations should be verified for the specific engagement and product before use.

Frequently asked questions

Direct follow-up answers written for searchers, buyers and internal decision makers.

Does an enterprise AI plan automatically make client data safe?

No. Verify the terms and settings for the exact plan, including data use, retention, access and enabled features, then assess them against the engagement and the firm’s requirements.

Can we use a tool if its data terms are unclear?

Do not put the affected client information into the tool while permission or a required control remains unresolved. Ask the engagement owner to decide what evidence or change would close the gap.

Is removing names enough to make a client document anonymous?

Not necessarily. Context and combinations of details may still identify a person or engagement. Assess the information and use case before sharing it.

What should we record for an approved use case?

Record the purpose, data class, exact product and plan, verified terms and settings, controls, accountable owner, reviewer, decision and evidence location. Set a review date and revisit the decision when circumstances change.

Need More Specific Guidance?

Every organisation's situation is different. If you need help applying this guidance to a specific process, book a discovery call or take the assessment first.