Protecting Client Information at a Leading UK Wealth Manager
The Challenge
As a prominent UK wealth manager, overseeing nearly £20 billion in assets, the Client recognised their investment analysts and portfolio managers were increasingly turning to GenAI tools to synthesise market data and draft investment memos to remain competitive in their sector. As an FCA-regulated entity, the key challenges were:
- Shadow AI: 71% of employees typically use unsanctioned tools (Microsoft Research). For the Client, this meant proprietary fund data and PII potentially entering public training models via personal ChatGPT or Gemini accounts.
- Audit Readiness: With tightening UK and EU AI regulations, the firm lacked a granular trail of AI activity to present to auditors or internal compliance committees.
- An Appropriate Solution: A blanket block on AI using traditional tools would stifle innovation needed to remain competitive in the London market.
The Solution: Light-Touch Guardrails
Fendr Security deployed its browser-based protection across the organisation via their existing MDM in under 5 minutes. Unlike heavy-handed network blockers that users often bypass, Fendr Security provided:
AI Lens
Total visibility into which "Shadow" platforms were being used — ranging from ChatGPT to specialised tools like Jenni AI, Elicit, DeepSeek, Grok and HeyGen — without invading employee privacy.
Contextual Nudges
Instead of a hard block, users attempting to paste sensitive data into unapproved tools were "nudged" toward the firm's sanctioned AI environment.
Governance on Autopilot
Automated weekly intelligence reports allowed the CISO to identify "Power Users" and track top prompt themes like "exit and liquidity events," and "financial planning".
The Impact: Data-Driven Governance
Within the first 141 days of deployment, the Client achieved:
Identified and governed across the organisation, detected through Fendr's database.
Successfully blocked attempted pastes and file uploads of potentially sensitive investment documentation to public models.
The firm now holds a definitive log fulfilling "evidence of control" requirements for ISO 27001 and future regulatory alignment.
Rapid time-to-value with measurable security and compliance outcomes from day one.
The Verdict
The results lead to 100% visibility and "evidence of control", boost in Microsoft Copilot usage requiring evidence of AI usage controls, achieved through light-touch "nudges" rather than hard blocks.
Ready to Achieve Similar Results?
See how Fendr Security can help your organisation enable AI safely.
Book a Demo