For firms with retail-facing funds, platforms, or genuine distribution influence over retail outcomes, testing AI functions against a customer who's struggling with poor eyesight, low financial confidence, or a cognitive condition that makes long digital forms genuinely hard to complete is an essential step.

It's worth knowing that "vulnerable customer" isn't the edge case most firms treat it as. The FCA's Financial Lives survey found that 53% of UK adults display characteristics of vulnerability.

What Consumer Duty actually asks of you

Under the FCA's guidance on fair treatment of vulnerable customers, firms need to do four things. Understand the vulnerability characteristics present in your customer base. Build staff capability to recognise them. Put practical measures in place, including offering multiple channels so customers actually have a choice in how they engage. And monitor outcomes on an ongoing basis, not just at launch.

That "multiple channels" requirement is the one most AI-first rollouts quietly skip. It's easy to build a single, efficient, AI-mediated journey and assume it works for everyone because it works for you, sitting at your desk, testing it yourself.

Where the FCA found firms actually getting this wrong

The FCA's own review of good and poor practice on vulnerable customers turned up some uncomfortable patterns. Customers with low digital skills struggling with journeys that were purely digital, with no consistent phone or postal alternative offered. Self-service systems creating new barriers rather than removing old ones: online forms with no guidance built in, phone menu systems that exhaust customers who can't stay on hold, digital-only account updates that are simply inaccessible if you have a disability that affects how you use a screen.

Two numbers from that review are worth sitting with. Only 4 in 10 customers with characteristics of vulnerability have actually disclosed their circumstances to any provider, which tells you disclosure isn't something you can rely on as your safety net. And only 29% of firms had tested how their products actually affect vulnerable customers at all. Most firms, in other words, are designing and shipping without checking.

What good actually looks like

The same review pointed to real examples worth copying. AI speech analytics being used to flag vulnerability indicators in real time during calls, so a human can step in, not to replace the conversation but to support it. Centralised systems that stop a customer having to repeat sensitive information every time they contact the firm. Video calls with sign language interpretation offered as a genuine channel, not an afterthought. The pattern across all of these is that AI is doing the noticing, and a person is still doing the caring.

The picture just got more current

The FCA published its long-awaited Mills Review into AI and the future of retail financial services in July 2026, and it goes further than "be careful." The review explicitly names the risk that AI-driven financial services could create new forms of exclusion, particularly for people who lack reliable access to AI tools or the digital literacy to use them, and warns that market-led solutions won't automatically close that gap on their own. Its response is a recommendation for a free, inclusively designed, trusted AI-enabled financial capability service, essentially a public-interest backstop for people the market might otherwise leave behind.

The review also pushes back on a comfortable assumption: that a better, more capable AI model reduces the need for human control. It doesn't. Capable models still need controls for reliability, consistency and accountability, arguably more so as they take on more autonomous decisions rather than less. And in consumer research for the review, 67% of people said they were highly concerned about having no protection if an AI system gets something wrong for them. That's the majority of your customer base telling you directly what they need reassurance about.

A short list worth running against your own rollout

Does this journey have a genuine non-digital fallback, not just a phone number that rings out? Has it actually been tested against a vulnerable-customer persona, or just against your own team? Is there a real escalation path to a person, one that gets used and reviewed, not a checkbox in a project document? And is any of this logged in a way that actually feeds your Consumer Duty outcomes monitoring, rather than living in a spreadsheet nobody revisits?

If you can't answer all four with confidence, that's not a reason to panic. It's a reason to get it properly assessed before the next AI-mediated customer journey goes live, rather than after the FCA asks you the same four questions.

Sources: Guidance for firms on the fair treatment of vulnerable customers (FG21/1), FCA, Delivering good outcomes for customers in vulnerable circumstances, FCA, FCA publishes landmark review into impact of AI on retail financial services (Mills Review), From assistant to decision-maker: the FCA's Mills Review, Freshfields