Virtual Assistants for UK Financial Advisers: A Compliance-First Guide
It is 9:40 p.m. on a Wednesday in Guildford, and a chartered financial planner with 118 clients is doing the only thing he has time to do at 9:40 p.m., which is admin.
There is a review pack due Friday for a client whose drawdown position changed in April. There is a letter of authority sent to a provider nineteen days ago that has produced nothing but an automated acknowledgement. There is a client — a retired GP, £740,000 across two SIPPs and an ISA — whose annual review was booked in March, moved in April, moved again in May, and has now quietly slipped eleven weeks past the date on the service agreement she pays 0.75% a year for. And there is a note in the CRM, sitting under her record, which reads in full: chased — no answer.
No date. No channel. No indication of who wrote it or what they actually did.
That note is the problem. Not the workload, not the diary, not the provider. The note. Because if the Financial Conduct Authority asked this firm tomorrow to evidence that it had delivered — or made proportionate, good-faith attempts to deliver — every ongoing service it had charged for since 2018, that note is what the firm would hand over. A regulator reading it learns nothing about whether a client was served or abandoned.
That is the shape of the problem in UK financial advice in 2026. Advisers are not doing bad work. The evidence of good work is being produced late at night, by the most expensive person in the building, in the fifteen minutes before they give up and go to bed.
The Arithmetic Nobody Puts in the Business Plan
Start with where an adviser’s week actually goes, because the numbers are more brutal than most principals admit out loud.
Fidelity Adviser Solutions’ research into the adviser working day found that roughly 20% of it goes on preparing reports and plans, and a further 18% on compliance and administration. That leaves about a third of the day — 20% in-person, 13% remote — for the thing clients are paying for. Nearly two full days a week disappear into paperwork before anyone has picked up a telephone.
Practitioner estimates run higher still. Elevate AI, founded by someone who spent seven years inside UK wealth management firms, puts the typical adviser at 15 to 20 hours a week on administrative and compliance tasks — close to half the working week on work that is genuinely essential and generates no revenue whatsoever.
Intelliflo’s 2026 UK Advice Efficiency report, based on a survey of 209 UK advisers conducted in April 2026, sharpens the picture. Report writing remains the single most time-intensive administrative task: 30% of advisers spend three or more hours per report, and one in ten spends more than five. Asked to rate the efficiency of their current advice-journey workflows on a scale of one to ten, advisers averaged 6.23. Only a quarter rated their workflows at eight or above. Three-quarters said their current processes limited their ability to deliver good client outcomes to some degree.
The infrastructure underneath is fragmented in a way that compounds everything. Three-fifths of firms — 60.7% — run five or more core systems, and 57% juggle four or more investment platforms. Every one of those is a separate login, a separate export format, a separate place where a piece of client information can be correct in one system and eleven weeks stale in another.
Three-quarters of UK advisers say their own processes are limiting the outcomes they can deliver to clients. Not the market. Not the regulator. The processes.
This is happening inside a consolidating sector. More than 1,000 advice firms have left the UK market in three years — roughly 15.6% down, from around 6,280 firms in early 2022 to about 5,300 today — while adviser headcount has held broadly steady near 27,500. Small firms are being absorbed rather than vanishing, and around 87% still have five or fewer advisers. The administrative burden described above is landing, overwhelmingly, on businesses with no operations function at all.
The instinct in most of those firms is to hire. That instinct is correct. The assumption that hiring means hiring locally is the part worth interrogating.
What the FCA Actually Says About Outsourcing (And What It Doesn’t)
Here is where most articles on this subject go quiet, and where this one is going to be tediously specific, because the specificity is the point.
No FCA rule prohibits a UK advice firm from using offshore administrative support. No rule requires support staff to be UK-resident. Nothing prohibits a South African assistant from accessing a UK client file.
What exists instead is SYSC 8 of the FCA Handbook — the outsourcing chapter — and a central proposition short enough to memorise. Where a firm outsources critical or important operational functions, it remains fully responsible for discharging all of its obligations under the regulatory system. The firm’s relationship and obligations towards its clients must not be altered. The conditions under which it was authorised must not be undermined.
For most small and medium advice firms, which are not common platform firms, SYSC 8.1.4R and 8.1.5R apply as guidance rather than binding rules, to be applied proportionately to the nature, scale and complexity of the business. That proportionality is real relief. It is not an exemption. The regulators attach significant weight to guidance, and the Consumer Duty and the Senior Managers and Certification Regime sit above all of it regardless.
The FCA’s own outsourcing material makes a further point that is easy to skim past and expensive to ignore: intra-group outsourcing, including cross-border arrangements with a parent or sibling company outside the UK, is held to the same standard as outsourcing to an external third party. Firms should not treat it as less risky. If the regulator will not let you relax the standard for your own subsidiary, it is not going to let you relax it for a freelancer you found on a marketplace.
What SYSC 8 actually asks for, translated into things a small advice firm can do on a Tuesday afternoon:
- A written agreement that defines the rights and responsibilities of both sides, service levels, data security obligations, and termination provisions.
- Effective access to data relating to the outsourced activity — for the firm and for the FCA. The provider must be prepared to co-operate with the regulator, including on-site inspection where relevant.
- A documented exit plan. What happens if the provider fails, folds, or underperforms? How does the function come back in-house or move elsewhere without disrupting clients?
- Ongoing oversight, not a one-off due diligence file that was assembled at onboarding and never opened again.
- Notification where the arrangement is material, under SYSC 8.1.12 and Principle 11.
You can outsource the task. You cannot outsource the accountability. Every serious conversation about VA support in a regulated firm has to start from that sentence, not arrive at it as an afterthought.
None of this is exotic. Most advice firms already do a version of it for their compliance consultant, their back-office software provider, and their outsourced paraplanning. The mistake is treating administrative support as somehow outside the framework because the person doing it is titled “assistant” rather than “supplier”.
The Data Question: UK GDPR, the IDTA, and the POPIA Overlay
This is the section that decides whether a South African VA arrangement is defensible or merely convenient.
Financial advice files are dense with exactly the categories of personal data that attract the most scrutiny: financial position, health information used for protection advice, family circumstances, and in many cases special category data. Sending that data outside the UK is a restricted transfer under Chapter V of the UK GDPR, and Articles 44 to 50 apply whether the recipient is a multinational processor or one assistant working from a home office in Durbanville.
South Africa does not hold UK adequacy status. That single fact determines the entire compliance architecture.
Where no adequacy regulation applies, the transfer needs an appropriate safeguard. In practice, for a UK firm, that means either the ICO’s International Data Transfer Agreement (IDTA) or the EU standard contractual clauses with the UK Addendum. Firms with both UK and EU exposure often prefer the SCC-plus-Addendum route; the IDTA is the cleaner standalone instrument for UK-only flows. Contracts entered into after 21 September 2022 must use one or the other to be effective.
Signing the IDTA is necessary and not sufficient. A transfer risk assessment — now referred to in UK legislation as a “data protection test” following the Data (Use and Access) Act 2025, though the ICO still uses TRA in its guidance — must be completed before you rely on the safeguard. The TRA asks whether the destination country’s laws and practices would undermine the protection the contract promises. The ICO publishes a TRA tool. Use it, and keep the completed assessment.
Then record everything: every transfer mapped in the record of processing activities, with the destination, the mechanism relied on, and the date it was put in place. Retain the signed IDTA and the TRA together. Adequacy positions and safeguards can shift, and the ICO expects them to be monitored rather than filed and forgotten. Layer the Article 28 processor terms underneath — instructions, confidentiality, security measures, sub-processor controls, deletion or return at the end of the arrangement.
Now the part that most UK firms do not know, and which is genuinely a point in South Africa’s favour.
South Africa’s Protection of Personal Information Act (POPIA) is not a light-touch regime. Fully in force since 30 June 2021, enforced by an active Information Regulator, it is structurally similar to the GDPR on scope, definitions and data subject rights — and where it differs, not always in the more relaxed direction. Its maximum administrative fine of R10 million sits far below the GDPR ceiling, but POPIA carries criminal sanction, with imprisonment of up to ten years for the most serious offences. Section 19 requires appropriate technical and organisational security measures; section 21 requires a written contract with any operator processing on a responsible party’s behalf; section 72 governs transborder flows out of South Africa on a closed list of grounds.
Enforcement is not theoretical. The Information Regulator has issued enforcement notices against the South African Police Service, the Department of Justice, Dis-Chem Pharmacies, the Department of Basic Education — a R5 million fine in that case — and, in April 2025, WhatsApp, for applying weaker privacy terms to South African users than European ones. For 2026/27 the Regulator has said it will prioritise targeted assessments in high-risk sectors, with banking and financial services named first.
A South African assistant handling UK client data sits under two regimes at once: UK GDPR flowing in, POPIA applying locally. That is not a complication. Compared with jurisdictions where the local regime is ornamental, it is a second floor under the same building.
The practical consequence for an advice firm: your VA provider should already be able to produce a POPIA-compliant operator agreement, documented security measures, and a named contact for data protection. If a provider cannot, that is not a paperwork gap. That is the answer to your due diligence question.
The Delegation Boundary: What a VA Can Touch and What They Cannot
The compliance-first approach to VA support in an advice firm starts with a line drawn clearly, in writing, before anyone gets a system login.
A virtual assistant cannot give advice. They cannot make or influence a suitability judgement, select a product, interpret a risk profile, or say anything to a client that a reasonable person would construe as a personal recommendation. They cannot hold a controlled function. They cannot carry any part of an SMF holder’s accountability. If a task requires regulated judgement, it stays with the adviser, full stop, and the workflow should make it structurally impossible for it to drift.
A virtual assistant can carry most of the work that surrounds the advice. In a typical UK advice firm that means:
- Letters of authority and provider chasing. Issuing LOAs, logging submission dates, following up on a defined cadence, and — critically — recording every contact attempt with a date, a channel and an outcome.
- Review scheduling and the contact trail. Booking annual and periodic reviews, sending reminders, rebooking, escalating non-responders, and building the evidence record that a review was offered even when it was declined.
- Pre-meeting data gathering. Assembling valuations, updating fact-find data and pulling platform statements, so the adviser opens a complete file rather than assembling one.
- CRM hygiene. Reconciling records across the five-plus systems most firms run, closing the gap where a client’s details are right in one place and wrong in three others.
- Post-meeting administration. Tidying meeting notes into the house template for adviser review, drafting correspondence for approval, chasing outstanding documents, tracking applications to completion.
- Management information. Maintaining the registers that make a Consumer Duty board report possible: who sits on which service tier, when they were last reviewed, who has not engaged, and what was tried.
- Complaints and vulnerability logging. Recording, routing and tracking against DISP timescales — administration of the process, never the assessment.
- Compliance calendar administration. CPD records, fee disclosures, annual attestations, file-review sampling schedules.
Notice how much of that list is not about doing work. It is about evidencing work. Which brings us to the reason this matters more in 2026 than it did in 2021.
Evidence Is the Product: The Ongoing Advice Problem
In February 2024 the FCA wrote to 22 of the largest UK advice firms and asked them to account for seven years of ongoing advice delivery. The findings, published on 24 February 2025, focused specifically on the delivery of suitability reviews.
The headline was reassuring. Suitability reviews had been delivered in 83% of the cases examined. In a further 15%, clients had declined the offer of a review or had not responded to it. In 2% of cases, no attempt to contact the client had been made at all. The FCA concluded there was no systemic failure.
Read the second and third figures again, because that is where the operational lesson lives.
The 15% were fine — provided the firm could show it had made proportionate, good-faith attempts to contact the client. The FCA indicated that where a firm was willing to deliver a review and the customer declined it, redress is less likely to be due. The same broadly applies where genuine contact attempts were made and documented. The distinction between the 15% and the 2% is not effort. It is recorded effort.
The FCA then asked every advice firm in the market to review the findings, consider whether they could evidence delivery of everything they were contractually and regulatorily required to deliver, and — where firms undertake proactive reviews — to look back to 2018.
St James’s Place set aside £426 million as a provision for potential client refunds relating to ongoing advice. Quilter signalled it might face remedial costs. Neither figure was driven by a finding that advice had been bad. They were driven by questions about what could be proved.
The regulatory direction has since softened in one respect and hardened in another. In March 2025 the FCA consulted on replacing the fixed annual review obligation with a flexible, periodic model matched to individual client circumstances — a sensible loosening that could widen access for clients with simpler needs. But flexibility raises the evidential bar rather than lowering it. Under a fixed annual rule, the question is simply whether the review happened. Under a flexible model, the firm must be able to justify the frequency it chose for each client and show it delivered on that choice.
Meanwhile the FCA’s 2025 financial advice firms survey, published on 23 April 2026, found that compliance oversight varies considerably: firms reported reviewing around 30% of initial and replacement advice files and around 20% of ongoing advice files, with some conducting no internal or third-party reviews at all for certain advice types.
Put these together and the operational requirement is unambiguous. Somebody in your firm needs to own the contact trail, the review register, the file-sampling schedule and the management information that makes a Consumer Duty board report a report rather than an assertion. That person does not need to be qualified to give advice. They need to be reliable, trained, supervised, and there every day.
That is a job description. It is not, in most firms with fewer than five advisers, an affordable local job description.
The Human in the Loop: Why AI Alone Fails the Audit
The obvious 2026 objection is that this is all solved by software. It is not, and the reason is regulatory rather than technical.
Adoption has moved fast. Intelliflo found AI use inside UK advice firms rose from 43% in 2025 to 74% in 2026 — a 31 percentage point jump in twelve months. Among users, note-taking and transcription is the most common application at 87%, followed by report writing at 44%. The Bank of England and FCA’s 2024 survey had already found 75% of financial services firms using AI, with a further 10% planning adoption within three years.
The same Bank of England and FCA survey found that 46% of respondent firms had only a partial understanding of the AI technologies they were using, largely because those technologies sat inside third-party products. Firms expected third-party dependency, model complexity and hidden models to grow as risks.
The FCA’s position on all this has been consistent and is worth stating plainly, because it disposes of the “the tool did it” defence entirely. The regulator has repeatedly confirmed it does not intend to introduce an AI-specific rulebook, and will supervise AI through the frameworks that already exist — the Consumer Duty, SM&CR, SYSC and operational resilience. In January 2026 it launched the Mills Review into how AI could reshape retail financial services, and has committed to practical guidance by the end of 2026 on how existing consumer protection rules apply to AI, including senior manager accountability. FCA Executive Director David Geale told the Treasury Committee that individuals are “on the hook” for AI harm under SM&CR. Handing a decision to an algorithm does not transfer liability.
What that means in a small advice firm is concrete. An AI note-taker produces a meeting summary. Somebody still has to read it, catch the point where the transcription rendered “capped drawdown” as “capital drawdown”, check the client’s objective was recorded as stated, file it against the right record, and flag the vulnerability indicator the model did not register as significant. An AI drafting tool produces a suitability report. Somebody still has to verify the figures and confirm the recommendation matches the adviser’s actual reasoning.
Practitioner guidance for advice firms adopting AI lists the same controls every time: human oversight of all client-facing content before use, an audit trail of overrides, piloting on limited datasets, monitoring for accuracy and drift, checking third-party dependencies. Every one of those is a person doing something. The technology reduces drafting time and increases the review and documentation load.
AI did not eliminate the administrative job in a regulated firm. It changed it from typing into checking. Checking is harder to automate, and it is the part the regulator will ask about.
This is the strongest argument for a trained assistant rather than a subscription. A capable VA operating your AI stack — running the transcription, applying your house template, doing first-pass verification, escalating anything ambiguous to the adviser, logging the overrides — captures the speed benefit while keeping a named, accountable human between the model and the client file. A subscription with nobody assigned to it produces faster output and a thinner audit trail.
The South African Advantage
Given that the compliance framework applies wherever the assistant sits, the question becomes purely practical: from which country do you get the best combination of capability, communication, cost and coverage?
Time zone. South Africa runs at GMT+2 — one hour ahead of the UK in winter, two in summer. An assistant starting at 8 a.m. Johannesburg time is at their desk before most UK offices open, and work handed over at the end of a South African day lands with hours of UK afternoon still remaining. That is a different arrangement entirely from the seven-to-eight hour gap of South and Southeast Asian delivery, where the assistant’s day ends as the adviser’s begins. For work that involves chasing UK providers during UK business hours — which is most advice-firm administration — the overlap is not a nicety. It is the job.
Language and legal orientation. English is a primary business language in South Africa, and South Africa consistently ranks among the strongest non-native English markets in Education First’s English Proficiency Index. More usefully for this sector, South African law is rooted in a common-law tradition with direct historical alignment to English law, and South African business documentation follows British conventions rather than American ones. The practical result is an assistant who writes “adviser” not “advisor”, “organisation” not “organization”, who dates a file 04/08/2026 and means the fourth of August, and who does not need the difference between the ICO and the FTC explained.
Regulatory literacy. The POPIA point made earlier is the substantive one. A South African professional working in a business-services environment has operated under a comprehensive data protection statute since 2021. The concepts — lawful basis, data subject rights, security safeguards, operator agreements, cross-border restriction — are familiar rather than foreign. That shortens the training curve on the part of the job where mistakes are most expensive.
Cost, without the quality trade. South African virtual assistants working for UK firms typically command in the region of £10 to £20 an hour, which represents strong professional compensation locally while delivering meaningful savings against UK equivalents.
VAConnect, founded in 2014 by Karen van Zyl, built its business specifically on the managed model rather than the marketplace model. The firm employs South African professionals directly, vets them before they reach a client shortlist — skills testing, background checks, cultural fit assessment — and trains them continuously through VAVarsity, its proprietary upskilling platform. It reports 98% client retention and replaces non-performing placements at no additional cost.
For a regulated firm, the managed structure matters more than it would for a marketing agency. Marketplace hiring puts vetting, background checking, supervision, continuity planning and data protection assurance entirely on the advice firm — the same firm that, under SYSC 8, remains fully responsible and needs a documented exit plan. A managed provider brings recruitment risk, quality assurance and continuity inside its own perimeter, and can produce the documentation your compliance file requires. That is the difference between a supplier you can evidence and a contractor you can only hope about.
What It Actually Costs
The comparison most firms run is against the salary line, which understates the real number considerably.
Glassdoor puts the UK average for an IFA administrator at £25,361 as of June 2026, with a typical range of roughly £20,200 to £31,900. Paraplanner advertisements through 2025 and into 2026 cluster between £30,000 and £50,000 depending on qualification and region — a Woking role advertised in March 2026 at £40,000 to £50,000 for Level 4 and Level 6 candidates, an Inverness hybrid role at £45,000, Birmingham and Newcastle-under-Lyme roles in the £30,000 to £38,000 band.
Then add employment costs, which changed materially in April 2025. Employer National Insurance now runs at 15% on earnings above a £5,000 secondary threshold, up from 13.8% above £9,100 — £4,500 on a £35,000 salary, on top of the salary. Auto-enrolment adds a minimum 3% employer pension contribution on qualifying earnings, roughly £1,050 more. The true cost of a £35,000 administrator sits around £40,550 before recruitment fees, equipment, holiday cover, or the management time absorbed by a hire that does not work out. The Employment Allowance, at £10,500 for 2026/27, offsets part of the NI bill for eligible employers. It does not offset the recruitment risk, the notice period, or the fact that in a five-adviser firm one administrator leaving takes the institutional memory of the review register out of the door with them.
Against that, a managed VA arrangement converts a fixed employment liability into a contracted service with defined replacement provisions — while, done correctly, producing better compliance documentation than an informal local hire, because the contractual apparatus that SYSC 8 wants is built in from the start rather than retrofitted.
Thirty Days: A Compliance-First Onboarding Sequence
Days 1–5: Paperwork before access. Execute the service agreement with SYSC-aligned terms — service levels, data security, audit and access rights, termination and exit. Put the IDTA or SCCs-plus-Addendum in place. Complete and file the transfer risk assessment using the ICO tool. Execute Article 28 processor terms and confirm the provider’s POPIA operator agreement and security measures. Update the ROPA. Sign the NDA and confidentiality undertakings. Nobody touches a system in week one.
Days 6–10: Scoped access, not general access. Provision named accounts with least-privilege permissions on the systems the role actually requires. Enforce multi-factor authentication. Confirm device security standards and where data will be stored. Write the out-of-scope tasks into the role description — anything touching advice, suitability or recommendations — and have the assistant acknowledge them.
Days 11–20: One workflow, properly. Do not hand over five processes at once. Take the one where evidence is weakest — usually the review contact trail — and build it end to end: cadence, contact log format, escalation trigger, adviser handoff point. Review every record produced in the first fortnight.
Days 21–30: Widen and formalise oversight. Add the second and third workflows. Set the supervision rhythm: a weekly sample review of records, a monthly service review against agreed levels. Record the arrangement in your compliance register and, where material, consider notification under SYSC 8.1.12 and Principle 11. Write the exit plan and file it where the next person will find it.
Thirty days is not slow. It is the difference between an arrangement that strengthens your compliance file and one that becomes a finding.
The Gap Is Now Structural
What is striking, looking at the 2026 data together, is how wide the difference has become between firms that solved the administration problem and firms that are still absorbing it personally.
One group has an adviser who spends 38% of the working day on reports, compliance and administration, whose review register lives partly in a CRM and partly in their head, whose evidence of client contact is a note reading chased — no answer, and who is bolting AI tools onto fragmented infrastructure in the hope that speed will substitute for structure.
The other has the same adviser spending that time with clients, because a trained, supervised, contractually documented assistant owns the LOA chase, the review cadence, the contact log, the CRM reconciliation and the management information — under an IDTA, a completed TRA, a POPIA operator agreement and a written exit plan.
Both firms are subject to identical rules. Only one of them can prove it.
The FCA has said its interest in this area is not limited to the 22 firms it originally wrote to. The Consumer Duty board report is annual and is not going away. The 2018 look-back is a live expectation. And the flexible review model now under consultation will, if implemented, require firms to justify their choices client by client rather than point at a calendar.
Every one of those obligations is met with documented, day-to-day administrative discipline. Not with better intentions, and not at 9:40 p.m. on a Wednesday.
The Comparative Picture
| DIY Coordination | Generic Freelancer | VAConnect Managed VA | |
|---|---|---|---|
| Who does the admin | The adviser, in evenings and gaps between meetings | A contractor sourced from a marketplace, typically part-time and shared across clients | A dedicated, employed South African professional, matched to the firm |
| Adviser hours reclaimed weekly | None — 15–20 hrs stays with the adviser | Variable; often offset by supervision and rework | 15–20 hrs returned to client-facing and business development work |
| SYSC 8 documentation | N/A, but no defined process to evidence either | Client’s responsibility entirely; usually a basic services contract at best | Formal service agreement with service levels, audit access, termination and exit provisions |
| UK GDPR transfer mechanism | N/A | Rarely in place; TRA usually absent | IDTA or SCCs + UK Addendum, with completed transfer risk assessment and ROPA entry |
| Second data protection regime | None | Depends entirely on jurisdiction; often nominal | POPIA — enforced regime with criminal sanction, active regulator, financial services a named 2026/27 priority |
| Vetting and background checks | N/A | Client’s responsibility; frequently skipped | Skills testing, background checks and cultural fit assessment before shortlist |
| Time zone overlap with UK | Full — but only in hours the adviser does not have | Highly variable; commonly 7–8 hrs offset | GMT+2 — 1–2 hrs ahead, full UK business-day coverage |
| Continuity if the person leaves | The adviser absorbs it | Firm restarts sourcing from scratch | Replacement managed and transitioned at no additional cost |
| Ongoing training | None | Contractor’s own initiative | VAVarsity — continuous, role-specific, skills-tested |
| True annual cost | Opportunity cost of 15–20 adviser hrs weekly | Low headline rate, high supervision and rework overhead | Contracted service; typically 40–60% below a UK equivalent, with no employer NI, pension or recruitment exposure |
| Retention | N/A | Marketplace churn | 98% client retention |
| Audit position | Evidence assembled retrospectively, under pressure | Thin, informal, hard to evidence | Documented from day one — contract, transfer mechanism, TRA, access controls, exit plan, supervision records |
Ready to see what this looks like in your firm? VAConnect places rigorously vetted South African virtual assistants with UK financial advice firms — timezone-aligned, English-fluent, trained through VAVarsity, and supported by the contractual and data protection documentation a regulated business actually needs. Explore our industries page or book a call to discuss your firm’s requirements.
Sources
- Financial Conduct Authority, SYSC 8 — Outsourcing, FCA Handbook; and Outsourcing and operational resilience, fca.org.uk
- Financial Conduct Authority, Ongoing financial advice services multi-firm review findings, 24 February 2025; and Understanding the advice market: financial advice firms survey 2025, 23 April 2026
- Information Commissioner’s Office, International transfers guidance, including IDTA, UK Addendum and transfer risk assessments
- Intelliflo, 2026 UK Advice Efficiency Report (survey of 209 UK advisers, April 2026), reported in IFA Magazine and Financial Planning Today
- Fidelity Adviser Solutions, adviser working-day research, November 2025
- Bank of England and FCA, Artificial Intelligence in UK Financial Services, November 2024; and BCLP, AI Regulation in Financial Services: Turning Principles into Practice, 2026
- Protection of Personal Information Act 4 of 2013 (South Africa), ss 19, 21 and 72; Information Regulator enforcement record and 2026/27 priorities
- Glassdoor UK IFA administrator salary data, June 2026; HMRC employer National Insurance rates 2026/27
- VAConnect UK (vaconnect.co.uk) and VAConnect (vaconnect.co.za) service data
