Back

AI Training for Financial Services: What Actually Changes

In a regulated firm the hard part of AI training is the practice material and the approval gate, not the curriculum.

Date

Reading time

10

min

Amelia Miller

Co-founder and CEO

AI training for financial services is the work of teaching people at a regulated firm to use AI tools on their real job, inside the constraints their compliance function has already set.

Three things change, and none of them is the curriculum. The practice material changes, because the team cannot rehearse on the client data that makes up most of their actual work. The tool changes, because the firm has already licensed one and that is not up for discussion. And the timeline changes, because an internal risk group has to clear the programme, and that conversation is part of the work rather than admin that happens before it.

Everything else a generic AI course teaches transfers fine. The reason those courses fail in regulated firms is narrower and more fixable than most buyers assume: people are handed prompts they are not permitted to run, on data they are not permitted to paste, in a tool the firm has not sanctioned. Nothing survives contact with Monday. This is how to design a programme that does.

What needs to be true before you start

Four preconditions, and a programme designed without them tends to get built twice. You need a sanctioned tool that people can already reach, a named person in the risk or vendor-approval function who will engage, a realistic view of which work is actually restricted rather than assumed to be, and a budget holder who understands the cost will be counted in staff hours rather than fees.

The adoption question is largely settled at firm level. In the Bank of England and FCA's 2024 survey of UK financial services firms, 75% reported already using AI, with a further 10% planning to within three years. What that figure does not tell you is whether anyone in those firms can do anything useful with it, and that gap is the reason you are reading this.

One thing to settle early, because it changes the shape of everything after it: rolling a tool out to everyone is a licence position, not adoption. A firm where every desk has Copilot and nobody has changed how they work has bought software, not capability.

Step 1: Open the risk conversation before you design the programme

Talk to the risk or vendor-approval function first, six to eight weeks before you want the first cohort to run. The common failure is treating approval as a rubber stamp applied to a finished programme, which guarantees a rebuild when the group asks a question the design cannot answer.

What they will ask for is fairly predictable: which tool the training uses and whether the firm has already approved it, what data participants will handle during exercises, whether an external trainer sees anything confidential, where any material produced in the session is stored, what happens to the trainer's own access afterwards, and what record exists that a given person completed the training.

It helps to know what the regulator has actually said, because a surprising amount of internal caution is inherited rather than sourced. The FCA states plainly that it does not plan to introduce extra regulations for AI, relying instead on existing frameworks including the Consumer Duty and the Senior Managers and Certification Regime. That is not permission to skip anything, and this post is not compliance advice. It does reframe the conversation: the question in the room is how existing obligations apply to a training exercise, not whether some separate AI rulebook forbids it.

Effort: two or three meetings, plus a written summary they can circulate. What goes wrong: opening the conversation with a supplier's brochure. Open it with the data flows.

Step 2: Choose the use cases that clear compliance first

Start with internal work that touches no client and leaves the firm's own perimeter untouched. In practice that means document review and summarisation, internal reporting, desk research, and meeting notes. These clear approval faster than anything else because the failure mode is embarrassment rather than a reportable incident.

Leave client-facing work out of the first programme entirely. Anything that drafts client communications, touches advice, or produces output a customer sees carries a different level of scrutiny, and putting it in cohort one means the whole programme moves at the speed of its most contested component.

This ordering annoys people, because the client-facing use cases are usually where the money is. The argument for going second is practical: a cohort that has already shipped something useful on internal work is a much stronger case for the next approval than a slide deck about what might be possible.

Effort: a half-day workshop with team leads to name the three tasks per team that repeat weekly, stay inside the firm, and already pass under a human eye. What goes wrong: letting the most enthusiastic team pick the most exciting use case.

Step 3: Build practice material that is not client data

Build a dummy data set that behaves like the firm's real work, and budget properly for it, because this is the step that decides whether the training transfers. Generic courses fail here: they hand a team exercises built on invented companies with tidy numbers, and the skills learned do not survive contact with a real file.

Behaving like the real work means carrying the awkwardness of the real work. Real documents are inconsistent, badly scanned, full of internal abbreviations nobody outside the firm would recognise, and often contradict each other. A practice set that is too clean teaches people that AI is reliable, which is the opposite of the lesson that keeps a regulated firm safe. Build in the ambiguity, the missing field, the document that says one thing in the summary and another in the appendix.

Three ways to source it, in descending order of effort and quality: write a set from scratch with two subject-matter experts, which is the best and costs a few days of expensive people's time; take real historic files and have the owning team redact and mangle them past recognition, which is faster but needs its own sign-off; or use published material such as public filings and regulatory documents, which is free, involves no internal data at all, and is a good fallback where the risk conversation is slow.

Whichever route, the exercises are built so people literally cannot breach policy while learning, which is also the single most persuasive thing you can tell the risk group.

Effort: three to five days of subject-matter expert time for a set that serves several cohorts and gets reused. What goes wrong: making it too easy, so the cohort finishes feeling confident about a tool they have not actually stress-tested.

Step 4: Design cohorts around the tool the firm already licenses

Teach the tool the firm has sanctioned, not the tool the trainer prefers. In most UK financial services firms that is Microsoft Copilot, because it arrived through an existing enterprise agreement and cleared procurement as part of something the firm had already bought. Whether it is the best tool is not the question in front of you.

This has a real cost and it should be said out loud. A trainer who works mostly in Claude or ChatGPT will teach patterns that do not map cleanly onto Copilot's behaviour, its retrieval, or where it can and cannot see the firm's own documents. Ask any external provider directly which tool they will teach in and what happens if the answer has to be the one you already own. A provider who cannot do that is selling a course rather than a programme.

Group cohorts by the work rather than by seniority. People who review documents all day need different material from people who write internal reports, and a mixed-grade cohort doing the same job outperforms a same-grade cohort doing five different ones.

Effort: one planning session per distinct job family. What goes wrong: a cohort built from an org chart instead of from a task list.

Step 5: Leave an audit trail the risk function can read

Record what was taught, to whom, on what material, and what each person could do afterwards. In a regulated firm the programme is not finished when the last session ends; it is finished when a colleague who never attended can reconstruct it from the record.

That means keeping the exercise set as a versioned artefact, keeping the attendance and completion record, and keeping a short assessed output per participant so capability is evidenced rather than asserted. The last one is the part everybody skips and the only one that answers the question a senior manager will eventually be asked about what their people are competent to do.

If the firm wants a supervised route for the AI systems themselves rather than the training, the FCA runs an AI Lab for firms developing use cases. That is a separate track from a training programme, and worth knowing exists before somebody in the room asks whether one is a substitute for the other. It is not.

Effort: a day to set up, then minutes per cohort. What goes wrong: treating the completion record as the evidence. Attendance proves scheduling, not capability.

How long does it take, and what does it actually cost?

Ten to fourteen weeks from first risk conversation to a cohort that has finished and been assessed, of which roughly half is approval and material-building rather than teaching. Six to eight weeks for the risk conversation and the practice set, running in parallel where the risk group moves quickly. Two to three weeks of scheduling around a team that bills its time. Then the delivery itself, which is the short part.

The number that gets scrutinised is not the invoice. In a firm where staff time is billable or directly revenue-generating, the cost of a 30-person programme is dominated by 30 people not doing their normal work, and that figure will be an order of magnitude larger than the training fee. Any business case that leads with the fee gets taken apart by the first person who multiplies headcount by an hourly rate. Lead with the hours, state them plainly, and make the argument against them.

This is where most programmes lose, and not for the reason people think. Across ivee's survey of 500 UK AI decision makers in August 2026, 96% could not show the numbers on their organisation's AI spend. That sample spans sectors rather than being financial services specific, but the mechanism is the same everywhere and it bites harder in a firm that measures everything else: if you cannot evidence what the last programme returned, the opportunity-cost argument has nothing to push against. Decide what you are measuring before the first cohort, not after.

Where the decision is whether to run this internally at all, that is a separate question with a genuine answer on both sides, and the in-house versus external comparison works through the costs properly. The general sequencing of a rollout once approval is settled is covered in rolling AI training out across 100 people.

What usually goes wrong

Five failures, in rough order of how often they appear.

  1. Approval treated as the last step. The programme is designed, priced and scheduled, then goes to risk, then gets rebuilt. Opening that conversation first costs two meetings and saves a quarter.

  2. A half-day sector cohort sold as a fix for a compliance blocker. It is not one. If the tool is restricted or the use case is not cleared, no amount of training makes it usable, and a provider who implies otherwise is worth less than one who says so.

  3. Practice material that is a toy. Clean invented data teaches confidence in a tool that deserves scepticism, and the skills do not transfer.

  4. Teaching the wrong tool well. Excellent training in a product the firm has not sanctioned produces a cohort that cannot practise what it learned.

  5. Counting the fee and not the hours. The business case falls over in the meeting rather than in the planning.

One more, which is less a failure than a decision worth taking early. Where the risk function will not clear an external provider at all, building the programme in-house is the right answer rather than a compromise. ivee is an external vendor and has an obvious interest in the other outcome, so take that as read: a firm whose risk appetite rules out third-party trainers should spend its budget on internal capability and the practice material, both of which it keeps.

Where to start this week

Name the person in risk or vendor approval you will talk to, and list the three internal tasks per team that are repetitive and already human-reviewed. Those two things take an afternoon and they determine most of what follows. The practice set can wait until you know what it needs to contain.

ivee builds sector programmes on the firm's own sanctioned tool and its own dummy data, and will tell you when in-house is the better call. See how bespoke corporate AI training is scoped, or book a call and bring your risk group's last set of questions.

Don't know what you don't know? Book a call.

Book a call and tell us where you're at. We'll show you how other teams are tackling AI, and, crucially, what's actually paying off.

Don't know what you don't know? Book a call.

Book a call and tell us where you're at. We'll show you how other teams are tackling AI, and, crucially, what's actually paying off.

Don't know what you don't know? Book a call.

Book a call and tell us where you're at. We'll show you how other teams are tackling AI, and, crucially, what's actually paying off.