top of page

Turning the ICOs AI Workplan into a Checklist for Regulated Firms

  • Jun 1
  • 3 min read

Updated: 3 days ago

The Information Commissioner’s Office (ICO) recently published its AI workplan for 2026/27, highlighting key areas such as AI codes of practice, automated decision making, biometrics, and consumer support in personalised AI environments. This workplan signals clear expectations for firms handling client, employee, or operational data through AI tools.


This post translates the ICO’s plans into a practical checklist for boards and senior leaders. It explains what regulated firms must do to meet data protection requirements, manage risks, and maintain trust when using AI. The goal is to help boards ask the right questions, document essential checks, and assign clear ownership for AI governance.



Understanding the ICO’s AI Workplan and Its Relevance


The ICO’s 2026/27 workplan focuses on three main areas:


  • Developing an AI code of practice to guide responsible AI use.

  • Providing guidance on agentic AI, which can make autonomous decisions.

  • Supporting consumers in personalised AI environments, where AI tailors services or decisions.


For regulated firms, this means the ICO expects clear controls around AI systems that process personal data. The workplan reinforces existing data protection laws and adds focus on transparency, fairness, and accountability in AI-driven decisions.


Firms using AI tools that handle client or employee data must prepare for increased scrutiny. Boards need to ensure AI use aligns with legal requirements and ethical standards, avoiding risks like bias, errors, or data breaches.



Key Leadership Questions for Boards


Boards should lead the conversation on AI governance by asking practical questions that clarify responsibility and risk management:


Who owns AI governance in the firm?

Identify a senior leader or committee responsible for overseeing AI use and compliance.


What AI systems process personal data?

Map out all AI tools in use, including those for client services, HR, or operations.


How is data protection ensured in AI processes?

Check if AI systems comply with UK GDPR principles such as lawfulness, fairness, transparency, and data minimisation.


Are AI decisions explainable and auditable?

Confirm that automated decisions can be reviewed and justified to clients or regulators.


What controls exist to prevent bias or discrimination?

Ensure AI models are tested regularly for fairness and do not unfairly impact protected groups.


How are data subjects informed about AI use?

Review client and employee communications to confirm transparency about AI processing.


What ongoing monitoring and review processes are in place?

Establish regular audits and updates for AI systems to maintain compliance and performance.



Practical Checks to Document


Boards should require documented evidence of the following checks to demonstrate due diligence:


  • Data Protection Impact Assessments (DPIAs) for AI tools that process sensitive or large-scale personal data.


  • Vendor and third-party AI tool reviews to verify compliance with data protection and security standards.


  • Training records showing staff understand AI risks and data protection obligations.


  • Incident response plans tailored to AI-related data breaches or errors.


  • Records of AI decision audits to track accuracy, fairness, and explainability.


  • Consumer feedback mechanisms to capture concerns about AI-driven services.


Documenting these checks supports accountability and helps firms respond to ICO enquiries or investigations.



Risks of Moving Ahead Without Clear Ownership and Controls


Ignoring the ICO’s guidance or failing to assign clear AI governance can expose firms to serious risks:


  • Regulatory penalties for breaches of data protection laws or unfair automated decision making.


  • Reputational damage if clients or employees lose trust due to opaque or biased AI decisions.


  • Operational failures caused by unchecked AI errors or security vulnerabilities.


  • Legal challenges from individuals affected by unfair or incorrect AI outcomes.


Boards must treat AI governance as a priority risk area, not just a technical issue. Clear ownership, documented controls, and regular reviews reduce these risks and build confidence in AI use.



Eye-level view of a boardroom table with documents and a laptop showing data charts



Steps Your Firm Can Take Now


To align with the ICO’s AI workplan, boards should:


  • Assign a named AI governance lead or committee.

  • Conduct a full inventory of AI tools and data processed.

  • Require DPIAs for all significant AI projects.

  • Review and update client and employee privacy notices to include AI use.

  • Implement regular AI audits focusing on fairness, accuracy, and transparency.

  • Establish clear escalation paths for AI-related incidents.

  • Provide ongoing training on AI risks and data protection for relevant staff.


These steps create a strong foundation for responsible AI use and prepare firms for future ICO guidance and enforcement.


AI is reshaping how regulated firms operate, but it also brings new responsibilities. The ICO’s 2026/27 workplan offers a roadmap for managing these challenges. Boards that take practical action now will protect their firms, clients, and employees while building trust in AI-powered services.





Prime Signal helps accountancy, legal and finance firms review AI use, client data, cyber risk, recovery and IT support quality. Request a no-fee IT Risk Review

 
 
Prime-New-Logo-Light.png
ico.1b4b71e0ec72.webp
image.png
tps.57326048e40a.webp

Prime Signal Group Ltd provides B2B data, prospect research and lead generation services. Information submitted through this site is used to respond to enquiries, prepare quotes or samples, and deliver requested services.

©2026 Prime Signal Group Ltd  

Business registration: 17181178

ICO registration: ZC134554

General Enquiries

info@primesignal.co.uk

 

Data Enquiries

data@primesignal.co.uk​​​​​

MSP Enquiries

msp@primesignal.co.uk​​​​​

telephone.png

020 4600 7340

pin.png

167-169 Great Portland Street

London, W1W 5PF

linkedin.png
bottom of page