Why financial services
Wealth managers, advisers, brokers, lenders and fund managers are under the same pressure as everyone else to use AI. They also work under closer supervision. FCA-regulated firms are generally expected to manage operational risk, protect client data, treat customers fairly and be able to explain the systems and controls behind what they do. “An employee pasted it into a chatbot” is not an explanation any firm wants to give.
Kroy gives a firm a governed route between AI and its systems: who asked, which agent acted, what it could see, what it did, and who approved it.
Least privilege, by design
Kroy scopes AI to the smallest set of information a task needs. An adviser’s AI sees that adviser’s clients. A Skill that prepares a board pack reads the reporting database through named queries, not the whole warehouse. Sensitive fields — account numbers, identity documents, health information — can be excluded from AI entirely.
Where AI helps, and where Kroy draws the line
| Area | AI can | Kroy boundary |
|---|---|---|
| Client reviews | Prepare a review pack from CRM and portfolio data | Only for the adviser’s own clients |
| CRM | Log meetings and propose record updates | Changes approved by the record owner |
| Board and management reporting | Draft the pack from named queries | Figures are traced to their source; issue is approved |
| Client communications | Draft letters and replies | Drafts, not sends; client-facing wording is reviewed |
| Onboarding | Assemble the onboarding file | KYC and AML decisions stay with people |
| Complaints | Summarise the case history | Outcomes are decided by people |
| Recommendations | — | AI does not issue advice to clients |
| Payments and trading | — | Excluded by default |
Evidence, not assurances
Every AI request through Kroy is recorded: the person, the agent, the delegation, the policy that applied, the data returned, any approval and any refusal. When compliance, internal audit or a reviewer asks how AI is used, the firm can show them — rather than describe what it believes happens.
Kroy Observe shows how AI is actually being used across the firm: which tools, which Skills, which systems, and where requests are being refused.
Sharing with clients
Give a client, or their other advisers, a projection of what they need — a document room, a report, outstanding requests — and let them use it directly or through their own AI. Internal notes, other clients and firm data never leave the firm.
AI policy first
A regulated firm usually needs an agreed AI policy before it can enforce one. PolicyHQ helps firms write an AI policy, a staff quick guide and an access matrix.
Define the rules with PolicyHQ. Put them into practice with Kroy.
London
London is home to a great many financial services firms, from global institutions in the City to small advisory practices across the capital. Kroy is designed with those firms in mind, and the same controls apply wherever a firm is based.
Frequently asked questions
Does using Kroy make our AI use compliant? No tool can do that on its own. Kroy helps a firm enforce and evidence its own controls; the firm remains responsible for its regulatory obligations. Nothing here is legal or regulatory advice.
Can the AI give advice to clients? Not through Kroy by default. AI can prepare material for an adviser; client-facing output is reviewed and sent by a person.
Can we keep certain data away from AI altogether? Yes. Systems, record types and individual fields can be excluded, and Kroy refuses requests for them.
Do our credentials go to the AI provider? No. Kroy holds the connections and returns only the results of authorised requests.