info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo
    Business Outcome

    Preparing a Financial Services Business for AI

    AI readiness is not an AI-tool procurement exercise. LOOKUP helps Australian financial services businesses prepare the right governance, information, security and workflow foundations before implementing AI — so projects deliver measurable business value rather than expensive experimentation.

    The two-minute answer

    How should a financial services business prepare for AI? Start by understanding the current business environment before selecting AI tools. This means reviewing business use cases, existing workflows, information quality, permissions, cyber security, privacy obligations, approved tools, governance, human oversight, vendor assessment, monitoring and staff capability.

    Once the business environment is understood, identify specific AI use cases where AI can genuinely assist — such as meeting administration, information summarisation, knowledge retrieval or draft communications. Then establish governance, approved tools and human review processes before deployment.

    AI should never autonomously provide regulated financial advice, make credit decisions, approve claims or determine suitability. It should support human decision-makers, not replace them.

    Where AI may help financial services businesses

    AI can potentially assist with several activities common to financial services businesses. Not every use case should be automated, and AI should support — not replace — professional judgement, regulatory obligations and client-facing decisions.

    Meeting administration

    Summarising notes and extracting action items.

    Information summarisation

    Summarising documents, policies and research.

    Knowledge retrieval

    Finding information across documents and systems.

    Draft communications

    Drafting emails and administrative correspondence.

    Workflow support

    Assisting with task creation and notifications.

    Administrative classification

    Helping categorise documents and information.

    Document review assistance

    Supporting review of large documents.

    Internal reporting assistance

    Summarising operational data and exceptions.

    Client-service administration

    Supporting follow-ups and scheduling.

    AI should not be implied to autonomously provide regulated financial advice, make credit decisions, approve claims, determine suitability or make other regulated or high-impact decisions.

    Start with the business process, not the AI product

    The most common mistake is buying an AI tool before understanding the underlying workflow. An AI summarisation tool cannot help if the underlying document management process is inconsistent or poorly understood. Similarly, reducing administrative overhead should be addressed before introducing AI — not after.

    Before introducing AI, map the workflow from client engagement through to delivery:

    Business Purpose
    Process
    Information
    Security
    Governance
    People
    Use Case
    Control
    LOOKUP Perspective

    Technology should follow process understanding. Buying an AI tool before understanding your business workflow creates complexity, not efficiency. AI readiness is a business and governance exercise, not a procurement exercise.

    ASIC's AI governance findings

    ASIC's REP 798 — Beware the gap: AI governance in financial services and licensees (2024) examined how Australian financial services licensees were adopting AI. ASIC found that many licensees lacked mature governance frameworks for AI use, and identified areas including risk management, human oversight, accountability and monitoring as important for responsible AI adoption.

    These are ASIC's findings and observations based on its review. REP 798 does not create a standalone universal AI law. However, it signals that ASIC expects financial services licensees to approach AI adoption with appropriate governance, oversight and accountability — consistent with existing regulatory obligations.

    LOOKUP's recommendation is that financial services businesses treat AI governance as a business priority before broad deployment — not as an afterthought. This is a LOOKUP professional recommendation, not a statement of universal legal obligation.

    APRA-regulated entities require separate consideration

    APRA-regulated entities — such as banks, insurers and superannuation trustees — are subject to specific prudential standards and technology risk expectations. APRA has published guidance on information security and technology risk that is relevant to how these entities should approach AI adoption.

    APRA's expectations apply to specific entity types. They do not automatically apply to every financial adviser, credit business or professional financial-services firm. If your organisation is APRA-regulated, you should review current APRA guidance and seek professional advice regarding your specific obligations.

    If your organisation is not APRA-regulated, you should still consider governance, security and privacy obligations under ASIC, the Privacy Act and other applicable frameworks — but APRA prudential standards should not be assumed to apply.

    Information quality and permissions

    AI is only as useful as the information it can access. For financial services businesses, this includes client information, documents, CRM records, advice and practice systems, Microsoft 365, email, shared drives and knowledge repositories.

    Poorly structured information — scattered across email, spreadsheets and disconnected systems — limits what AI can do. Before investing in AI, assess whether your business information is:

    Structured and consistent
    Stored in known locations
    Accessible to the right people
    Accurate and reasonably current
    Connected to business workflows
    Governed by appropriate permissions

    Improving information quality is one of the highest-value investments a financial services business can make before AI adoption. For a practical framework, see our guide to improving information and document governance in financial services.

    Privacy and sensitive information

    Financial services businesses handle sensitive client information, including personal, financial and identity-related information. The Office of the Australian Information Commissioner provides guidance on Australian privacy obligations under the Privacy Act 1988 and the Australian Privacy Principles.

    Whether and how the Privacy Act applies depends on the organisation, its activities and the information it handles. Not all financial information automatically has the same legal classification. Organisations should obtain professional advice regarding their specific privacy obligations.

    This page provides business technology and governance information and is not legal, privacy or regulatory advice.

    Cyber security is an AI dependency

    Before staff are given broad access to AI tools, the business should review identity, MFA coverage, least-privilege access, Microsoft 365 permissions, device security, third-party AI services and shadow AI usage.

    AI tools can make information easier to discover. If permissions are excessive or poorly governed, AI may surface information more broadly than intended. Strengthening security before AI deployment is a prerequisite, not an afterthought.

    For deeper guidance on protecting client and financial information, see our guide to protecting client information in a financial services business and our guide to strengthening cyber and operational resilience. You can also explore our Cyber Security Services and Essential Eight pages.

    Microsoft 365 and Copilot

    Many financial services businesses already own Microsoft 365, which includes platforms that can support AI readiness: Teams for communication, SharePoint for document collaboration, OneDrive for file storage, Outlook for email and Power Automate for workflow automation.

    Microsoft Copilot can assist with drafting communications, summarising meetings, searching information and automating tasks within Microsoft 365. According to official Microsoft documentation, Copilot works within a user's existing Microsoft 365 permissions — it does not grant access to information a user is not already authorised to see.

    However, if permissions are broader than intended, Copilot may make information a user already has access to easier to discover. Reviewing permissions and governance before deployment is therefore important. Not all Copilot capabilities are available in every Microsoft 365 licence — check your current licensing before planning deployment.

    Human oversight and accountability

    Responsible AI adoption in financial services requires human oversight. This means defining review processes, escalation pathways, approved use cases, rules for AI-generated content, client-facing output standards, professional judgement boundaries and ongoing monitoring.

    Review

    AI-generated content is reviewed before use.

    Escalation

    Staff know how to report concerns or unexpected AI outputs.

    Approved use cases

    Clear guidance on what AI may and may not be used for.

    AI-generated content

    Drafts are verified before client-facing use.

    Client-facing output

    Regulated advice and recommendations remain human-led.

    Professional judgement

    AI assists — it does not replace professional responsibility.

    Responsibility

    Humans remain accountable for outcomes.

    Monitoring

    AI usage is monitored for effectiveness and risk.

    Third-party AI vendors

    Financial services businesses should assess third-party AI vendors before adoption. This includes reviewing data handling, security, access controls, retention, contractual terms, integration capabilities, vendor dependency and human controls.

    Data handling — where information is stored and processed
    Security — vendor security posture and certifications
    Access — who can access your business information
    Retention — how long data is retained by the vendor
    Contractual terms — data protection and liability
    Integration — how the tool connects to your systems
    Vendor dependency — what happens if the vendor changes terms
    Human controls — whether the tool supports human review

    This page does not provide legal procurement advice. Organisations should obtain appropriate professional advice regarding vendor contracts and regulatory obligations.

    How well are you governing AI?

    Find out in 60 seconds with LOOKUP's free AI Governance Check.

    Take the 60-Second AI Governance Check

    A financial services AI readiness assessment

    Before deploying AI, assess the business across these dimensions:

    Business Purpose

    What business problem is AI meant to solve?

    Process Maturity

    Are workflows consistent enough to support AI?

    Information Quality

    Is business information structured and accessible?

    Security

    Are identity, access and devices secured?

    Privacy

    Are privacy obligations understood and addressed?

    Governance

    Are policies and approved tools defined?

    Vendor Risk

    Have third-party AI vendors been assessed?

    People

    Are staff trained and ready for AI adoption?

    Human Oversight

    Are review and escalation processes defined?

    How this maps to the LOOKUP Business Modernisation Framework™

    AI readiness for financial services businesses follows the same structured methodology that guides every LOOKUP engagement. Learn more about the Business Modernisation Framework™.

    Stage 1

    Discover

    Map current workflows, systems, information and AI use cases.

    Stage 2

    Secure

    Review identity, MFA, permissions and device security.

    Stage 3

    Modernise

    Address legacy systems and improve Microsoft 365 foundations.

    Stage 4

    Standardise

    Create consistent processes for advice, administration and documentation.

    Stage 5

    Optimise

    Improve information quality, client data and workflow efficiency.

    Stage 6

    Prepare

    Establish governance, AI policies and approved use cases.

    Stage 7

    Implement

    Deploy AI tools deliberately with training and human oversight.

    Stage 8

    Improve

    Measure outcomes, review usage and continuously refine.

    What success looks like

    Successful AI readiness is measured by business outcomes, not technology deployment.

    Clearer AI Use Cases

    AI investment aligned to genuine business needs, not hype.

    Stronger Governance

    Approved tools, use cases and policies before broad deployment.

    Better Information Foundations

    Cleaner client, document and practice data supporting AI usefulness.

    Controlled Experimentation

    Controlled pilots with human review and clear escalation.

    Clearer Human Oversight

    AI-generated content is reviewed. Humans remain accountable.

    Reduced Shadow-AI Risk

    Fewer unmanaged tools and shadow AI usage across the business.

    Better AI-Business Alignment

    AI used where it adds measurable value, not everywhere.

    Research and regulatory context

    The Australian Securities and Investments Commission (ASIC) published REP 798 in 2024 examining AI governance among financial services licensees. ASIC's findings highlight the importance of governance, human oversight and accountability in AI adoption.

    The Australian Prudential Regulation Authority (APRA) has published guidance on information security and technology risk relevant to APRA-regulated entities considering AI adoption. This guidance applies to specific entity types, not every financial services business.

    The Office of the Australian Information Commissioner (OAIC) provides guidance on privacy obligations relevant to client information handling and AI adoption.

    The Australian Cyber Security Centre provides guidance on baseline security controls that strengthen the foundations for responsible AI use.

    Microsoft's official documentation explains how Microsoft 365 Copilot works within existing user permissions, which is important for understanding AI information access in a business environment.

    Illustrative business outcome

    This is an illustrative scenario, not a LOOKUP client case study. It reflects common challenges financial services businesses may encounter and demonstrates how a structured technology approach could be applied.

    A growing financial advice business has a Microsoft 365 environment, a practice and CRM platform, staff experimenting with AI tools informally, client information distributed across multiple systems, and no agreed AI governance or approved tools.

    A structured approach might involve:

    Discover
    Map current workflows, information sources and AI usage.
    Secure
    Review MFA, identity, permissions and device security.
    Standardise
    Create consistent processes for advice, documentation and client communication.
    Optimise
    Improve information quality in the CRM platform and Microsoft 365.
    Govern
    Establish an AI policy, approved tools and human review requirements.
    Pilot
    Trial one or two use cases — such as meeting summaries or knowledge search — with a small group.
    Measure
    Assess whether the pilot delivered business value before expanding.
    Potential Business Outcomes
    Clearer understanding of where AI adds value
    Better information foundations for AI
    Reduced unmanaged AI tool usage
    Stronger security before AI deployment
    More consistent processes ready for automation
    A governed, measurable approach to AI adoption

    Frequently asked questions

    How can financial services businesses use AI?

    Financial services businesses can use AI to assist with meeting administration, information summarisation, knowledge retrieval, draft communications, workflow support, document review assistance and internal reporting. AI should support — not replace — professional judgement, regulated advice and client-facing decisions.

    How should a financial advice practice prepare for AI?

    A financial advice practice should first understand its workflows, improve information quality, review cyber security, establish governance and identify genuine use cases. AI works best when the underlying business processes and information are well structured and appropriately governed.

    What is AI governance in financial services?

    AI governance in financial services means defining approved tools, approved use cases, rules for sensitive client information, human review processes, escalation pathways and staff training. It ensures AI is used responsibly and that humans remain accountable for regulated outcomes.

    What did ASIC find about AI governance?

    ASIC's REP 798 examined how Australian financial services licensees were adopting AI and found that many lacked mature governance frameworks. ASIC identified areas including risk management, human oversight, accountability and monitoring as important for responsible AI adoption. These are findings and observations, not a standalone universal AI law.

    Does APRA regulate AI use?

    APRA-regulated entities — such as banks, insurers and superannuation trustees — should review current APRA guidance concerning technology and AI risk. APRA's expectations apply to specific entity types and do not automatically apply to every financial adviser or financial-services business. Confirm your regulatory obligations with appropriate professional advisers.

    Does APRA guidance apply to every financial adviser?

    No. APRA regulates specific entity types including banks, insurers and superannuation trustees. Many financial advice practices, credit businesses and other professional financial-services firms are not APRA-regulated. Regulatory obligations depend on the entity type, licence and activities.

    Can financial advisers use Microsoft Copilot?

    Microsoft Copilot can assist with drafting communications, summarising meetings, searching information and automating tasks within Microsoft 365. According to official Microsoft documentation, Copilot works within a user's existing Microsoft 365 permissions. Its usefulness depends on information quality, permissions and governance.

    Can AI draft client communications?

    AI can help draft client communications such as emails, meeting follow-ups and administrative letters. However, communications involving regulated advice, product recommendations, suitability assessments or sensitive client information should be reviewed and approved by an authorised human before sending.

    Can AI summarise client meetings?

    Yes. AI can assist with summarising meeting notes, extracting action items and preparing follow-up documentation. A human reviewer should verify accuracy, particularly where meeting content involves advice, commitments or sensitive client information.

    Can AI provide financial advice?

    No. AI should not autonomously provide regulated financial advice, make suitability determinations, recommend products or make other regulated decisions. AI can assist with information retrieval and drafting, but professional judgement, licensing obligations and regulatory responsibility remain with authorised humans.

    How should client information be protected when using AI?

    Client information should be protected through identity controls, MFA, least-privilege access, governed Microsoft 365 permissions and clear policies on what may be entered into AI tools. Sensitive client data should not be entered into public AI tools without appropriate governance and assessment.

    What is shadow AI?

    Shadow AI refers to staff using unapproved, unmanaged AI tools for business tasks without governance. This can create risks around data exposure, compliance, information security and accountability. An AI policy and approved tools help reduce shadow-AI risk.

    Should financial services firms assess AI vendors?

    Yes. Firms should assess AI vendors for data handling, security, access controls, retention, contractual terms, integration and vendor dependency. Third-party AI services that process client or business information require appropriate due diligence.

    Does an organisation need an AI policy?

    An AI policy helps staff understand which tools are approved, what information may be used, what requires human review and how to report concerns. A simple policy reduces risk and supports responsible experimentation, particularly in regulated environments.

    Where should a financial services business start with AI?

    Start by understanding your current workflows, information quality and security posture. Identify one or two high-value, low-risk use cases. Establish basic governance, pilot with a small group, measure the outcome and expand from there. Seek professional advice on your specific regulatory obligations.

    What business leaders should do next

    1
    Identify high-volume administrative processes consuming staff time.
    2
    Assess information quality across client records, documents and practice systems.
    3
    Review cyber security — MFA, identity, permissions and devices.
    4
    Review Microsoft 365 configuration and existing capabilities.
    5
    Assess whether current AI usage is governed or informal (shadow AI).
    6
    Identify one or two genuine AI use cases to pilot.
    7
    Establish a simple AI policy covering approved tools and information rules.
    8
    Train staff on responsible AI use before deployment.
    9
    Review vendor security and data handling for any third-party AI tools.
    10
    Pilot with a small group, measure the outcome and expand deliberately.

    For guidance on bringing AI readiness into a coordinated technology strategy, see our guide to building a technology roadmap for a financial services business.

    Sources & Further Reading

    Australian Securities and Investments Commission
    REP 798 — Beware the gap: AI governance in financial services (2024)

    ASIC's review of AI adoption and governance practices among financial services licensees.

    View Source
    Australian Prudential Regulation Authority
    Information Security and Technology Risk Guidance (2024)

    APRA guidance on technology risk, information security and operational resilience relevant to APRA-regulated entities.

    View Source
    Office of the Australian Information Commissioner
    Australian Privacy Principles Guidelines (2024)

    Guidance on privacy obligations relevant to client information handling and AI adoption.

    View Source
    Australian Cyber Security Centre
    Essential Eight Maturity Model (2023)

    Australian Government guidance on baseline cyber security controls relevant to AI readiness.

    View Source
    Microsoft
    Microsoft 365 Copilot Documentation (2024)

    Official documentation on how Copilot works within Microsoft 365 permissions and environments.

    View Source
    Australian Government
    Australia's AI Ethics Framework (2019)

    Voluntary framework providing ethical principles for responsible AI adoption.

    View Source
    Microsoft
    Work Trend Index 2024 (2024)

    Research examining how AI-assisted activities affect knowledge worker productivity.

    View Source
    Evidence Standard

    LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    This page provides general business technology and governance information and is not financial, legal, regulatory, privacy or compliance advice. Businesses should obtain appropriate professional advice regarding their specific obligations.

    Prepare Your Financial Services Business for AI with Confidence

    LOOKUP helps financial services businesses understand their workflows, improve information quality, strengthen security and build the governance foundations for responsible AI adoption.

    Avatar
    Hi there! Have a question? Chat with us here.